• 0 Posts
  • 32 Comments
Joined 1 year ago
cake
Cake day: July 17th, 2025

help-circle
  • I don’t use iOS anymore, so I can’t really be more helpful with my suggestions, but apple health hasn’t had problems with sharing user’s health data (afaik), and as far as Apple’s privacy goes (not all that far tbh) they put an effort into keeping your health data private.

    If you still prefer to use a different app, fair enough and more power to you, just thought I’d let you know. Make sure to disable Siri (or I suppose apple intelligence now) learning from whatever app you decide to use though.


  • IMO, I think you’re being a little paranoid (I say as someone who was extremely paranoid when they first started getting into privacy). Take a bit of time to look into what is actually possible and how you can properly protect yourself, and hopefully that can put your mind at ease.

    I don’t mean to say all your fears are unfounded, or to just stop caring about your privacy and focus on learning, but taking a few days or weeks to understand better what Google (or any other company) is truly capable of will probably be better for you in the long run. You should also consider your threat model and what you’re willing to give up (if anything) in order to live a more private life. If you have to watch YouTube, Google will always have some sort of data, but it is possible to remove most (if not all) connections to you.





  • Would you mind sharing screenshots (or at the very least name specific examples)?

    What you’re describing is technologically and financially infeasible for Google to do at scale (or even to one specific person). If Google were able to track you that well, they wouldn’t modify the recommendations for you, they would quietly add it to an ad profile on you. The only reason the YouTube algorithm exists is to keep people on the platform for longer, when you use invidious, you are losing YouTube money, so they have no financial incentive to modify their algorithm for you.

    If you’re using a small few person instance, then what you watch can actually influence the recommendations (at least until the token rotates), but that isn’t Google tracking you specifically. If you use a more popular instance (like nerdvpn or nadeko) what you watch will do little to influence the front page algorithm.

    As I mentioned in my previous comment, I’d suggest you look into how the various privsec technologies you’re using actually work, and also look at how companies are actually able to track you. If you just assume a company can do something because they’re big, powerful, and scary, suddenly the company seems much bigger, more powerful, and scary than they really are. It’s also important to remember that just because something can be used to correlate activity with the user doing, that doesn’t mean it’s something that can be done at scale.

    Judging from your previous posts and comments, it sounds like you’re quite new to privacy. This kind of mentality (in one form or another) is very common amongst people who are new to caring about their privacy. Surveillance has been happening for your entire life, so it’s not going to hurt to take a bit to think about things with a clearer head. Of course, if you’re in a situation where lack of privacy might cause physical harm, find help ASAP, but generally you can take things at a slower pace to help on the long run. That’s not to say stop caring at all, but you don’t need to suddenly drop everything and move to a bunker in the woods. Too much change at once can lead to privacy fatigue, which only makes it less likely that you’ll escape any of the surveillance of the modern world.





  • I’ve seen a handful of your posts before. I don’t think Google is still tracking you.

    If you were to open YouTube in one tab, and Invidious in another, Google could maybe correlate the two (realistically, even that is enough seperation) but you wouldn’t notice anything. Invidious uses one token for multiple users, so if YouTube is recommending something to you, it’s recommending it to everyone using the instance. That only really applies to the frontpage though, when you watch a video, those recommendations are based on the video you’re watching.

    You describe using a lot of services that help protect your privacy, but you don’t seem to understand when, why, and how to use them properly (e.g. Qubes is security focused, and incidentally good for privacy, while Tails is privacy focused and decent for security). I’d suggest taking a look at privacyguides.org (not affiliated) for a more in depth explanation of various services.




  • The point is, saying “we need to embrace linux phones” is silly. Android uses the Linux kernel, therefore it is a Linux phone. I know that’s not the point of saying “Linux phone” but the line should be drawn better. Ideally, the Linux kernel should be completely discarded for a better kernel, but if the OS can still run “Linux apps” or “Linux desktops” under that new kernel, people will still probably call it a Linux phone.

    Android being owned by Google doesn’t really do much. It is very unlikely Google would close source the project, because any company making an “android phone” needs to modify android for their own stuff. Many features in popular android phones don’t exist upstream, and require modifying android itself. Even if Google closed AOSP, that doesn’t stop the community from working from the last release and moving forward.


  • Reminder though: If you’re on GrapheneOS, sandboxed Google play is the best you can get while using Google play. MicroG is just as, if not more, privileged than Google Play while lacking many genuine security features provided by Google Play. App stores like aurora don’t check app signatures and can fail if their “anonymous” accounts get banned. If you’re using GrapheneOS and want apps from the play store, making a seperate profile with sandboxed Google play is the best option.



  • Because you can’t run multiple accounts at once? Either I’m misunderstanding what you’re saying, or you’re missing the point of a signal backup.

    OP is referring to the GrapheneOS feature, well really the android feature heavily enhanced by GrapheneOS, that allows you to run the OS as another user with their own apps and files. OP is asking for help running signal (Molly) in both profile A and profile B as one account. This is technically possible but realistically infeasible because of the way profile switching works on android. I explained why in a different comment.


  • Bad advice. Signal has its drawbacks, and yet you managed to avoid listing all but one of them. Impressive.

    Signal has released an update recently that allows multiple devices (up to 10 I believe). Yes you still need a phone number, but newer commits suggest that is soon to change. Signal has local backups on android, and I haven’t heard of any issues restoring from them. Signal is far from perfect, but they are very trusted, battle tested, and overall a better service than what most people are using anyways. By all means, if you have a better service that works for you, go for it, but advising against using signal outright with no alternative is kinda weird.


  • I just tried with the official signal client, and I don’t think there’s a way to do it without transferring the account to another device. The second app must remain open while the first app scans the code, so while it’s possible in a private space, I think profiles are too isolated to run both at once. I’d be happy to be proven otherwise, but from what I can tell, it’s not possible on one device alone. I’d imagine Molly is the same.


  • If you have two seperate profiles on GrapheneOS, any apps inside the profile would generally assume it’s running on a completely seperate device. If the app was malicious it could technically tell that it’s installed on the same phone, but Signal is not. Using Signal across two profiles would be effectively the same as using Signal across two different phones.


  • I’ll start this by saying I do like and use proton, but their insistence to provide a hundred different services (and force you to pay for every single one in your subscription) really hurts the service. For example:

    The 2FA had an issue that leaked every single service you used by connecting to their icon server over insecure http, for a month I believe and then downplaying the severity. This wouldn’t have happened if they focused on being an email provider and pointed users to existing services like Ente Auth, instead of pushing poorly tested software to production as fast as possible. You should never store 2FA with your password manager anyways, even if it’s stored in seperate apps, so I think their choice to make a 2FA app is quite silly.

    They continue to prioritize building new services such as meet and lumo over compatibility with Linux (drive sucks, and only 9 years later do they support a buggy CLI. The VPN client is buggy as hell, and if you’re not careful could leak your VPN when it crashes for the hundredth time (crashes are less common on Gnome, which is technically the only DE it’s built for, but that doesn’t change the fact that it lacks critical features that exist exclusively on MacOS and Windows) (the killswitch works as far as I can tell, but with how poorly made the client is, you should bind it in the OS itself as well)).

    They require the use of Google Play services, arguing that they don’t want to waste people’s battery by running websocket based notifications. It’s a stupid defense as people who don’t have Google play services wouldn’t mind the extra battery usage for notifications. Not to mention, they can use unified push since they already encrypt their notifications anyways (Proton says they don’t need to add unified push, the users just need to use Google Play because the notification are encrypted, completely disregarding the invasiveness of Google Play and the metadata leakage from using them for push notifs).

    The UI for simplelogin has not changed since acquisition from what I can tell, and continues to look like it’s from 2014. Rather than adding features to simplelogin, as you would when you purchase an entire company, they almost exclusively add features to their password manager and email client instead.

    They basically force their crappy photo storage down your throat on mobile, despite being offered to join an alliance with privacy services (including Ente, an amazing photo storage service) and rejecting the offer. That’s actually a whole issue on its own. For what reason, other than greed, would a privacy company choose not to join an alliance with very respected privacy services? Is it because Tuta joined? That would be dumb and petty.

    Overall, I like and use many proton services, and I think a lot of the political controversies people like to throw at proton are FUD and/or blown out of proportion. That said, if a company could do what proton does for email (tuta is nowhere close to proton imo) and exclusively does email (fun fact, tuta is exploring the cloud drive space, because I guess people never learn) I would switch in a heartbeat. If proton separated their plans so you only pay for what you need, and let me use notifications on my phone, that would be basically all my gripes in my day to day dealt with.