privacy

0 readers
0 users here now

Rules (WIP)

  1. No ad hominem allowed
  2. Attack the idea, not the poster

founded 1 year ago
MODERATORS
26
 
 
27
28
 
 

In a well-intentioned yet dangerous move to fight online fraud, France is on the verge of forcing browsers to create a dystopian technical capability. Article 6 (para II and III) of the SREN [sécuriser et réguler l'espace numérique] Bill would force browser providers to create the means to mandatorily block websites present on a government provided list.

--France’s browser-based website blocking proposal will set a disastrous precedent for the open internet

[Unfortunately one should no longer trust Mozilla itself as much as one did 10 years ago. If you do sign, you might want to use a fake name and a disposable email address.]

This bill is obviously disturbing. It could be that eventually they assume that .onion sites are all suspicious and block them, or something similar might happen, which would be bad news for privacy-oriented users including Monero users, for freedom of thought, and for freedom of speech itself. Note that the EU is going to ban anonymous domains too (in NIS2, Article 28).

For a regular end user, if something like this happens and if the block is domain-name-based, then one quick workaround would be using web.archive.org (or Wayback Classic), or ANONYM ÖFFNEN of metager.de (both work without JS). If this is France-specific, of course a French user could just get a clean browser from a free country too (perhaps LibreWolf or Tor Browser, or even Tails), provided that using a non-government-approved browser is not outlawed.

Mozilla, financially supported by Google, states that Google Safe Browsing is a better solution than SREN, but that too has essentially similar problems and privacy implications; especially Gmail's Enhanced Safe Browsing is yet another real-time tracking (although, those who are using Gmail have no privacy to begin with, anyway).

If it's DNS-level blocking, you can just use a better DNS rather than one provided by your local ISP, or perhaps just use Tor Browser. Even if it's browser-side, as long as it's open-source, technically you're free to modify source code and re-compile it yourself, but that may not be easy even for a programmer, since a browser is complicated, with a lot of dependencies; security- and cryptography-related minor details tend to be extremely subtle (just because it compiles doesn't mean it's safe to use), especially given that Firefox/Thunderbird themselves really love to phone home behind the user's back.

See also: Will Browsers Be Required By Law To Stop You From Visiting Infringing Sites?

29
 
 
30
31
32
 
 

In the past I’ve recommended sms-activate for easy, quick and low cost phone verification. When you want to log in, they now force you to click on a verification link send by email, meaning you are f’ed if you used a single-use email address.

Are there any alternative options that accept monero and don’t have this restriction?

33
 
 

Having free and open-source tools and a decentralized way of fighting back and reclaiming some of that power is very important. Because if we don’t resist, we’re subject to what somebody else does to us

While Tor is useful in several situations, probably we shouldn't believe in it blindly. For clearnet, LibreWolf is a great option too, and I2P might be the future.

34
 
 

Hello, fellow privacy enthusiasts!

I've been on a journey to find a VPN provider that aligns with my privacy values, and I wanted to share my experiences and concerns here, hoping for some insights and recommendations.

Primary Criteria:

  • Outside of the 14 Eyes: Ideally, I'd prefer a provider outside of the 14 Eyes intelligence-sharing countries.

  • Accepts Monero: Given its the only real privacy coin there is, I'm keen on providers that accept Monero as a payment method.

  • I need port forwarding for the services I host.

Current Options: I've considered Mullvad and IVPN, both of which I trust for their privacy focus. However, they recently disabled their port forwarding support, which I need since I host services from home. SPN by Safing sounds really interesting too but they also do not offer port forwarding sadly.

ProtonVPN seemed like a close alternative, but I've come across several red flags:

  • Logging Concerns: ProtonMail, under the same parent company, provided IP logs in response to a Swiss court order. This contradicts ProtonVPN's claim on their website that "we can’t be obligated to start logging" under Swiss law.

  • Use of Google Analytics: Despite being a privacy-focused service, ProtonMail has used Google Analytics on their website, raising questions about their commitment to user privacy.

  • No Monero Support: Proton has not added Monero as a payment option, despite numerous requests from the community over the years.

Seeking Recommendations: Given the above, I'm reaching out for advice. Are there any VPN providers you'd recommend that fit my primary criteria? Or any insights into the concerns I've raised about ProtonVPN?

Thanks in advance for your help!

35
36
 
 

The Online Safety Bill, now at the final stage before passage in the House of Lords, gives the British government the ability to force backdoors into messaging services, which will destroy end-to-end encryption.

Requiring government-approved software in peoples’ messaging services is an awful precedent. If the Online Safety Bill becomes British law, the damage it causes won’t stop at the borders of the U.K.

Random thoughts...

Even if platform-assisted end-to-end encryption (pseudo e2e) is censored, perhaps we could still use true user-to-user encryption. If "end" means the messenger software itself or a platform endpoint, then the following will be true e2e - "pre-end" to "post-end" encryption:

  1. Alice and Bob exchange their public keys. While using a secure channel for this is ideal, a monitored channel (e.g. a normal message app) is okay too for the time being.
  2. Alice prepares her plain text message locally: Alice.txt
  3. She does gpg -sea -r Bob -o ascii.txt Alice.txt
  4. Alice opens ascii.txt, pastes the ascii string in it to her messenger, sends it to Bob like normally.
  5. So Bob gets this ascii-armored GPG message, and saves it as ascii.txt
  6. gpg -d -o Alice.txt ascii.txt, and he has the original Alice.txt
  7. He types his reply locally (not directly on the messenger): Bob.txt
  8. gpg -sea -r Alice -o ascii.txt Bob.txt and sends back the new ascii string
  9. Alice gets it, so she does gpg -d -o Bob.txt ascii.txt to read Bob.txt

In theory, scanning by government-approved software can't detect anything here: Alice and Bob are simply exchanging harmless ascii strings. Binary files like photos can be ascii-armored too.

Admittedly this will be inconvenient, as you'll have to call gpg manually by yourself. But this way you don't need to trust government-approved software at all, because encryption/decryption will be done by yourself, before and after the ascii string goes through the insecure (monitored) channel.

37
1
Bad Internet Bills (www.badinternetbills.com)
submitted 1 year ago by Saki@monero.town to c/privacy@monero.town
 
 

Congress is trying to push through a swarm of harmful internet bills that would severely impact human rights, expand surveillance, and enable censorship on the internet. On July 20, we’re launching a week of action to get loud about our opposition to legislation like KOSA and EARN IT and demanding that Congress focus on passing badly needed comprehensive privacy legislation to actually protect us from the harms of big tech companies and data brokers, instead of pushing through misguided legislation before August congressional recess.

38
39
 
 

I’m currently looking at my Venmo feed. In an ideal world, I would see only a log of private payments I’ve made and received. Instead, I see a list of my friends’ business: someone paid a friend for “drinkies,” another for “rich bitch things.”

This is so terrible, I don't even know what to say about this.

40
 
 

Kown your enemy (Google)

41
42
 
 

Apple will activate the controversial image scanning feature by default & let third party apps use its scanning API.

German article