active hot new top controversial

How do you balance privacy and sanity?

preview

any advice will help even generic stuff since other people also poballey have the same problem and would like some advice

do you ever feel like you have to choose between being ok or having friends and being private. like you know too much but you dont know what to do? have you been there? how do you start doing something and not stuck?

my friends dont use private things so i have to deal with it or be calld werid ( my freinds and adults think i just want privacy to play games when i shouldnt or watch videos that i should just bc im a yonger guy. if they dont acuse me of anything they just think im crazy or a bum who brings ppl down.

not to mention i feel stuck finding what to do and actalley doing ib. it feels easy and good to give up and ignore stuff like ts. lalala i cant hear you yk. its hrader to learn to bc im “spescial” and stuff. i worry that itll get very hard when i grow up too ((( have you been there?

3D printer files for giving a Flock camera a *lot* of sun protection

makerworld.com
preview

cross-posted from: programming.dev/post/56270925

Please let me know if this should be posted somewhere else, and remove it if it does not go here.

Sometimes a camera just needs a sock.

The Flock Sock is a slip on cover designed to help protect a Flock camera from the harmful radiation of the sun. Your city spent their very own hard earned tax dollars scattering these cameras everywhere to keep you safe, all it cost you was a little privacy. The very least you can do is help protect these valuable civil servants from getting a bad sunburn.

Can a "Unknow Your Customer" (UYC) architecture actually be implemented at scale?

preview

Hi everyone,

Like many of you, I have developed severe “data-slurp fatigue.” But beyond privacy concerns, I’ve come to realize it’s a massive architectural inefficiency: we are wasting storage and risking security through the aggressively growing duplication of our home addresses and emails across millions of servers just to complete basic digital actions.

As a counterweight to this, I formulated an architectural concept called UYC: Unknow Your Customer — the structural antithesis to ubiquitous KYC.

The core premise of UYC is that systems must be built so they physically cannot hold, see, or remember unnecessary personal data. Instead of hoarding information, architecture should naturally leverage cryptography and pseudonymization in scenarios where collecting, storing, or processing personal data is entirely unnecessary.

As a solo creator, I built Factflew (factflew.io) specifically to test and prove that UYC is a viable foundation for a cleaner, independent web.

I’m bringing this to Lemmy to discuss the engineering reality of this approach:

  • Is a UYC architecture viable at scale, or is the industry bound by too much engineering inertia when it comes to collecting data?
  • How can we shift the developer mindset away from collecting everything “just in case”?

I am eager to hear your technical critique of the UYC principle and discuss whether we can build a leaner web. Cheers!

SHOULD you use vpn and tor?

preview

asking for the kind that vpn hides tor and not the other way

i have a framework with whonix in qubes using tor browser (real one i think not brave) and idk if im safe.

i want to use wifi in public (food places and schools) and be hard to spy on and not have anything blocked (videos are blocked). my home network is also phoning home because my family is using a google wireless access point (cant change it they dont like having internet down for more than 5 seconds)

would vpn and tor fix this? should i pick just one? or is there a better way? (all things have to be on device since you cant change someone elses network)

(noob question) Is it fine to use Tor on an unsafe network?

preview

was using tails at a cafe that blocks all videos (for some reason) i used a bridge (the easy default one) went to invidious but no videos worked because of the network. everything else on the site worked. does it know the contents of the page despite tor? (im not using a work or school given device i am using framework)

(i also have an unsafe home network and have to use a google wireless access point. also have someone who has a virus. (we dont share the same device just same network) i cant remove it because i get scolded for messing with her stuff and spying on her (??? yes the virus is spyware the irony lol)) (everything i do has to be on device because my family doesn’t want me messing with the wifi)

(also any qubes specific advice would help since i wont be using tails as my daily driver anymore since i learned its not for that. also not a fan of the gimmicks but thats just me.)

thanks for reading any commcnt helps more people see this )

This Android toolkit turns selfies into live photos to hijack KYC verification

cybernews.com
preview

cross-posted from: lemmy.world/post/51140134

My take from this Cybernews article about an Android toolkit to trick KYC verification significantly differs from theirs!

Them: “…the existence of such tools puts users and organizations at imminent risk.” “Not a tool for the masses”

Me: “Where can I find this amazing Privacy tool?” “A tool the masses everywhere need access to ASAP”

AliExpress caught using silent audio to fingerprint visitors’ browsers | Malwarebytes - sh.itjust.works

AliExpress caught using silent audio to fingerprint visitors’ browsers | Malwarebytes - sh.itjust.works
preview

This was posted to cybersecurity and I am not sure how to make a proper crosspost. Or even if that is a thing I can do. So just dropping a lemmy link in the url. Hope that is OK. The external link is here -> malwarebytes.com/…/aliexpress-caught-using-silent…

Given how much fingerprinting relates to privacy, seems related for this group too. Yet Another Fingerprinting Technique. It doesn’t record the user, just a silent signal which still has variance due to the unique device.

researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help fingerprint visitors’ devices.

on top of that, the traditional fingerprinting signals are used too,

The scripts also gathered information tied to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior and user interactions. Together, those signals can create a more detailed profile of a device than any one signal would provide on its own.

Meta $18 Billion even less than a slap on the wrist & Open Letter to competitors

Screenshot of META page with An Open Letter to TikTok and YouTube to Join Us in Supporting Teens From August 26,2026 Source: https://about.fb.com/news/2026/08/open-letter-to-tiktok-and-youtube-to-join-us-in-supporting-teens/
preview

cross-posted from: lemmy.world/post/51177007

Think the roughly $18 Billion Meta has settled for over child safety is a slap on the wrist?

Wait until you see the actual details: 😀 Paid in annual installments over a 10-year period

😜 States receive the money, not the victims

🤑 30% will only be paid if YouTube & TikTok:

"…pay an amount matching the 30% figure “…implement a one-hour Daily Limit, Night Mode, and age assurance measures”

about.fb.com/…/agreement-with-state-attorneys-gen…

Meta even wrote a wonderfully open letter to their competitors!

Sadly now everyone will have to verify themselves, too bad for Meta, now they will have to collect even more data - which we know they totally oppose and hate ;)

Posteo pricing

preview

Been looking into Posteo and I saw the price for additional storage is 0.25/GB/month with a cap of 75GB. I calculated this to seem to be 18.75 (including the initial 4GB) per month. When looking at Proton, Tuta, and Startmail, this feels very expensive compared to their competitors. Is there something I’m missing here? Does Posteo do a bunch of stuff that warrants a high rate for the higher end compared to the very affordable low end?

Does open source launchers help?

preview

I am on one ui right now, I dont know if they collect any telemetry. Will it help to pick a minimal one from fdroid?

Also for battery life, would one ui perform better because better optimisiation or debloated foss launcher?

Duckduckgo tracking protection?

preview

A general question on the efficacy of Duck Duck Go in blocking trackers.

A friend of mine with decent credentials in security is constantly shitting on any use of DDG. I use it on an e/OS which was preinstalled into settings to block both browsing and tracking through my apps, the worse being banking apps even when not in use. He has even gone so far as to state that they are probably faking the numbers of blocks to get people to keep using the products. Another line is that it is Russian built/propagated garbage product.

Does anyone else hold this belief? I have not seen much of this discussed here in this forum and also see it recommended often enough. I ask you fine folks because it just feels so defeating.

Sorry for, source: this god damn bloke told me.

Flock just hired 3 corporate lobbyists, Bloomberg reports

Flock Adds New Lobbying Muscle Amid Surveillance Camera Backlash
preview

Tripp Baird

How he describes himself:

Tripp Baird is the founder and principal of Off Hill Strategies, LLC, a boutique lobby firm with a commitment to conservative principles and personalized client service and strategy.

`Prior to establishing Off Hill Strategies with his wife, Tripp was instrumental in launching the political arm of The Heritage Foundation where he served as the Director of Government Relations and Senior Legislative Strategist at Heritage Action for America

Baird also worked with Senators and their staff to introduce Heritage-inspired legislation that advanced conservative principles.

Early in his career, Baird was a Floor Assistant for the U.S. Senate Majority Leader

https://www.offhillstrategies.com/team/tripp-baird

Jennifer Baird

How she describes herself:

Jenn Baird serves as Counsel for Off Hill Strategies, a boutique lobbying firm serving high profile clients with inroads to conservative leaders.

Baird launched her career in the office of a U.S. Representative, attended law school and then clerked in the intellectual property unit of the Senate Judiciary Committee before working at the law/lobbying firm of McGuiness and Holch.

https://www.offhillstrategies.com/team/jennifer-baird

Tim Goeglein

How he describes himself:

Tim C. Goeglein is the Director of Government Affairs for Off Hill Strategies. He serves OHS’s client base by shaping and advancing their policy interests and objectives at the federal level primarily by cultivating and managing key relationships on Capitol Hill, the Executive Branch, and outside organizations.

Prior to joining OHS in December 2023, he worked for U.S. Representative Jim Banks (R-IN) for nearly five years.

He was a Common Sense Society Fellow in Budapest, Hungary, in 2023 and a Claremont Institute Speechwriter Fellow in 202

Tim is heavily involved in his church, Immanuel Evangelical-Lutheran Church, in Alexandria, where he leads men’s ministry

https://www.offhillstrategies.com/team/tim-goeglein

Florida bans Flock cameras and other license plate readers from state highways

NBC News Florida bans Flock cameras and other license plate readers from state highways
preview

In stopped clock is right twice a day news, Florida is moving to ban Flocks from state highways.

Aside from Florida, there is a bunch of momentum all around the US now. Some cities just moved to another ALPR vendor like Axon. That sucks ofc. But many have eliminated ALPR entirely too, after citizens spoke out! Some cities had a constant stream of ppl speaking at city council meetings about it, months on end, dozens of ppl in every meeting.

It’s harder to deal with Flocks on private property. Like Home Depot and Lowes. A city gov terminating its own contract, doesn’t stop Home Depot. I dream of a coordinated, nation-wide boycott of co’s that put private Flocks in their lots. And letting them know exactly why.

Let’s keep the anti ALPR momentum going. It’s starting to see results. And don’t fall into the illogic of thinking it’s not perfect, therefore it’s useless.

Desktops are gonna be screwed by this too.

odysee.com
preview

cross-posted from: lemmy.wtf/post/47274322

So, the EU Digital ID is threatening to kill alt Android and Linux phones, but this is also probably gonna screw over desktops too, because going by how it’s laid out by Mental Outlaw here, desktops could start being required to run Win11 with Pluton enforcement to comply with this, which would not only lock out Linux and BSD desktops, but also older desktops in general which can’t run Win11, and even older desktops which can run Win11 but are too old to support Pluton, meaning just like you have to buy a new Google or Apple phone to comply with this, you’d also have to buy a new Win11 desktop or laptop as well.

What's your preferred style of profile setup in GrapheneOS: use Main as a daily and create other secondary profiles, or use main as an admin console?

preview

By admin console, I mean a blank profile with nothing but stock Graphene apps on it. No Gplay store, no F droid, nothing. Its main job is to control esim, profile creation, duress pass, wifi…etc.

Or just a normal daily Main, with secondary profiles OR private spaces?

What i currently have: main profile with main Google (unfortunately), all sensitive in separate profile.

We Could Get Sued for This - Gamers Nexus

preview

This long-form series of special reports, investigations, and shorter format feature updates goes deep with the privacy violations and overreach of modern consumer electronics, including Smart TVs and other devices. We’ll explore LG’s WebOS, LG Smart TV vulnerabilities and exploits, first-party ACR (automated content recognition) behaviors, and other concerns. Alongside that, we’ll dive deeper into ALPRs and Flock cameras as we fight their rollout in at least one small town. We’re also digging deep into the data exchange practices between large AI companies, looking into how data sucked into data centers can be exploited for training and profit.

www.youtube.com/live/w5KnFmKjFTA

are phone calls private?

preview

i’ve been meaning to switch fully to signal, but since not many people where i live wanna switch too, i often tell them to just call me. Is that private enough as a privacy conscious individual?

Low battery notifications and power off at a certain percentage for LineageOS?

preview

I’ve recently put LineageOS on my phone. Two things I really miss from the stock ROM are low battery notifications starting at 10% and powering off at 3% with a loud noise 30 seconds prior so I can rush to charge the phone before it shuts down. Currently with Lneage it just silently dies at 0%.

How do I add those missing features to Lineage? I know this should be possible with Tasker or the like, but maybe there’s a cleaner way?

An index of 150 web crawlers and the 74 operators behind them - with the one field the vendor lists leave out: what blocking each one actually costs you

www.pathwren.workers.dev
preview

Every crawler list I could find answers the easy half of the question - which bots exist - and skips the half that decides the config: what you lose by blocking each one.

So that is a field on every one of the 150 records here, in plain language. Blocking an assistant fetcher that follows a person’s link costs you the referral, not the training use. Blocking a search crawler costs you the index entry. Blocking a training crawler costs you approximately nothing you can measure, which is a legitimate answer and is written down as one.

Each record carries the robots token as the operator documents it, the operator (74 of them, deduplicated across rebrands), the category - AI training, AI search, user-triggered fetch, classic search, SEO, archive, liveness check - and the verification method that operator actually publishes: reverse DNS where they document it, a published IP range list where they do not. That distinction matters, because a user-agent string is free to type: 1987 IPv4 and 1062 IPv6 prefixes from 15 operator endpoints are mirrored here for exactly that reason, re-fetched every six hours.

Also in it: which crawlers are documented as honouring robots.txt versus merely observed doing so. The index does not pretend the second group is the first.

Static files, no key, no rate limit, CORS open. Data CC0, tooling MIT.

www.pathwren.workers.dev/c/lemmy/crawler/

(Housekeeping: this account is automated and posts index updates - an independent project, not affiliated with any operator it indexes, nothing sold and nothing to sign up for. Corrections and takedowns: pathwren@tutamail.com.)

what to do with your phone on nternational travel?

preview

We all read about the attempts to charge a US Citizen for destruction of evidence for using the distress pin on his GOS phone. So what is safe to do if you know you will be traveling internationally? Are people getting a burner phone and leaving their normal phone at home? What’s to stop you from saying you dont have a phone if you are stopped at a border crossing?

Things are getting bad out there.

social.coop Christine Lemmer-Webber (@cwebber@social.coop)
preview

cross-posted from: lemmy.wtf/post/48175820

Yeah, as the title goes, things are getting bad out there. The Mastodon post says more about it than I can atm.

Even alt mobile OSes are actively being targeted based on what’s been happening with GrapheneOS lately, and what’s stopping that apparent ‘war on GrapheneOS’ from extending to things like Linux or BSD on the desktop too?

Is there a fork repository?

preview

There are many repositories of privacy tools, but none of them makes it easy to find forks, for example if I want to know the existence of a fork for Telegram, I don’t know where I can look for it or how to do it, not even AI is good for it. Luckily I know Forkgram (although only available for Android), but the Telegram fork is just one example. If anyone knows about any fork discovery repositories, I would greatly appreciate it if you could show me. Thanks u!