• 15 Posts
  • 161 Comments
Joined 8 months ago
cake
Cake day: February 17th, 2026

help-circle
  • My guess is that it stems from the old saying “you get what you pay for”, and as such a free service without a megacorp behind it MUST be dodgy and untrustworthy.

    That’s my guess too. I think a lot of non-techie ppl have been burned by “freemium” apps that are steaming piles of shitware. It’s kind of a hard distinction to explain, between “free” as in reputable OSS, and “free” as in spyware and thinly disgused malware. So they go wtih brands with name recognition. Like, you know, Facebook. Or Google.


  • I would only send pics of my kid over signal

    One thing that would worry me in your shoes is what happens to those pics after they hit the other person’s dev. Ok there’s a secure way to send them over the network. Now they’re on somebody’s phone running a million skeevy apps they gave photo access permission.


  • 50,922 phone searches at the border in a single year

    There are about 257 million people traveling to the US to or from other countries each year. That means less than 0.02% of those encounter a device search. The article itself also notes that the social media reporting system is not even in effect.

    Is the situation is worse than in the past? Absolutely! Is it still deteriorating? Yes. Do we need to improve it? Yes! But perspective matters too. Your chance of a device search upon entering the US is really small. There are many countries around the world where dev searches happen, and some even have criminal penalties for refusing.

    I would say the US is scary-ER than in the past. But the scary-EST? Social media doesn’t do nuance, and everything is either the very best or the very worst thing ever…


  • Good question, maybe I spoke too quick. I think they might be since they extend credit and deal with connections to the banking system. But I’m NAL. At least they are going to require a real world identity when giving out credit card numbers, which is also true of traditional card companies.

    Mostly I’m OK with them knowing my IRL identity, and proving that to them. But I’m not OK with sending a digital photo of my DL to some 3rd party identity broker who tends to leak those a lot.


  • That alone is very likely enough to identify you,

    I believe you are right.

    Which cuts to something else. I do not think most ppl have an intuition, for just how little info is sufficient to ID them. It isn’t much! That unfortuntely, makes life hard for we who value privacy. And easy for those who attack privacy.

    Mathematically it isn’t an impossible fight for us. But it is an up hill fight.


  • Jurisprudence changes VERY slowly, and for good reasons. But I believe there is movement in a good direction about location data privacy.

    For a long time, the thinking was, there is no expectation of privacy in public so your location in public is not 4A protected. That was kinda reasonable 50 years ago, before massive scale data aggregation. In recent years the courts are slowly recognizing that indescriminate aggregation of loc history creates a difference in kind. The “entirety of your movements” should enjoy 4A protection, even tho a single observation of your loc is not protected.

    The courts are not a monolith. There are hundreds of thousands of judges each with their own views. The system changes slowly. There are judges still adhering to the “no expectation of privacy in public” idea. But there is a shift happening. Even SCOTUS has started to recognize that dragnet loc surveilence is a problem.





  • Ppl have been accused of crimes for pointing out, in a 100% white-hat way, that a site lets you access other ppl’s accounts just by incrementing a number in the URL. No verification against it.

    If someone abuses that maliciously? Sure, go after them. But these were honest security white-hats trying to warn, before scammers exploited it.

    To be fair, being accused for that is exceptional, not normal. But it has happened. More than once!



  • Grab llama.cpp. Self-host on your machine in a VM that has GPU permission but not network. Presto, no big-tech data collection. No fingerprinting. No profiling. No ads.

    I’ve used it like that for language translation. Sometimes I wanna read a German, Japanese or w/e page. Or say a few words to someone in their own language. Which my human brain can’t do. Local models do a more than acceptable job for me.

    You have to be really, really super careful about confabulation, sycophancy & other probs. Do not get into the habit of asking a q to the model and believing it. And don’t use it agentically. But for page translations? Other low-importance tasks? Useful.

    changes the fingerprint each session going to help

    It’s gonna be super hard to totaly defeat fingerprinting. And you’ll never know if you really have. Local model + deny network, you can be almost totally confident. “Almost”, b/c nothing is 100% perfect, ever. But you go from almost 100% chance of surveilence, to almost 0% chance of surveilence.


  • If you’re in the EU, you might be able to try some GDPR moves. I’m not so IDK much about it, but there are other things to think about about online buying privacy.

    For physical products, they’ll need some addr to send to. You can use a PO box if avail in your area. Prob is most sites have an anti-fraud system. The less info it has to pin you to a real world ID, the more likely you’ll trigger it.

    That happened to me on ebay. Had the best possible rating, literally never got less than perfect feedback in many hundreds of transactions. Despite most of a decade of good faith use, one day they locked my acct. Demanded photo ID to unlock. Which I didn’t provide, so it remains locked. I think it was b/c I used a PO box and an alias, and I block lot of browser fingerprinting. That was all fine. Until one day it wasn’t.

    This is why I hate scammers so gd much. Scammers use the same methods we want for honest privacy, but they use it to scam, which makes co’s get super aggressive about ID’ing everbody. Scammers poison the privacy well for everybody.


  • FineCoatMummy@sh.itjust.workstoPrivacy@lemmy.ml•how to use javascript safely?
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    1
    ·
    14 days ago

    I’ve always thought having javascript totally disabled / on a whitelist basis makes you identifiable more.

    It’s complicated. That can be true. But it is often not true.

    For a total JS disable, that almost certainly makes you less identifiable. I.e, improves your privacy. It is true that JS-disable is a fingerprint. But it gives the -log2(%-who-do-that) bits of identifying info. If you prevent more bits than that from being obtained via JS, it is a net win. And JS has very powerful ways to fingerprint, and collect more bits than that log2(%) value. Thus, it is normally a privacy win to fully disable JS. Despite it putting you into a small cohort. That cohort is still bigger than the cohort the JS can bucket you into.

    But your other case, disabling some JS, that might make you more ID-able. If you disable the same subset as most other ppl, it won’t. But if the set you disable is specific to you, then that can provide enough signal to overwhelm the improvement. In that case it can hurt your privacy.

    There is not a simple yes/no answer. Which everyone wants to have. “It’s true!” “No it’s not!” “Yes it it!” Really, it depends. We must consider the factors, to know the answer. Which will vary for each person and circumstance.


  • It will depend on the site.

    Some sites you can totally disable JS, and they work fine. Often better! It can avoid the annoyware in so many sites now.

    Other sites require JS for basic functionality. But also have tons of tracking JS. On those you can disable the tracking JS and run only what is required.

    Yet other sites are such a clusterfuck from many 100’s of demains and it can be hard or impossible to unravel what is needed. Those I try to avoid the site if I can.

    Someone always will say disabling JS is a fingerprint too. Which is true, but misleading, b/c you can reduce the bits of info more by disabling JS than the bits obtained by the site seeing you disabled JS.




  • One day, I logged into FB and it was suggesting my co-workers as friends.

    Yah… they do that. B/c they are sleaze weasels. FB has… (pinky to mouth) one meeellllion ways to figure out your social graph.

    You ever got lunch with a co-worker? Your phone and theirs were at the same table in the same restaurant. Boom. You know that person. Or a 3rd person adds both you as friends? Boom. Or someone took a photo and you and other person were both in it? Boom. Or they buy phone call data from a data broker? Your phone called their phone. Boom.

    It’s all but impossible to stop it. I never, NEVER, had a FB account in my whole life. I never have even loaded their page, and I block all their 3rd party scripts. I have a friend who also never had. I’m 100% sure FB knows we are friends. It maintains “shadow profiles” for ppl without accounts. Our mutual friends have linked us, and FB knows that. It still gathers enough data to link us. Despite we both did everything we could.