Zum Inhalt der Seite gehen

Suche

Beiträge, die mit PRIVACY getaggt sind


Could any #privacy , #infosec people weigh in on whether the you tube guy Rob Braxman is legit. The usual searches don't lead to much.
https://www.youtube.com/@robbraxmantech


How Barcelona became an unlikely hub for spyware startups

Having Barcelona become a crucial regional outpost for offensive cybersecurity companies puts the spyware problem squarely on the doorstep of Europe, which has a fractious relationship with surveillance tech, due to scandals in Cyprus, Greece, Hungary, and Poland — all involving Israeli spyware makers.

#Barcelona #spain #israel #spyware #startups #business #malware #security #cybersecurity #privacy #surveillance

https://techcrunch.com/2025/01/13/how-barcelona-became-an-unlikely-hub-for-spyware-startups/


Doctolib will KI-Modelle mit Gesundheitsdaten trainieren

„Ab Ende Februar will der IT-Dienstleister #Doctolib die Daten seiner Nutzer:innen für das Training sogenannter Künstlicher Intelligenz einsetzen. Wenn sie einwilligen, sollen auch ihre #Gesundheitsdaten dafür genutzt werden. Das geht aus den aktualisierten Datenschutzhinweisen hervor….“

https://netzpolitik.org/2025/neue-datenschutzhinweise-doctolib-will-ki-modelle-mit-gesundheitsdaten-trainieren/

#Datenschutz #Privacy #Gesundheit #Kapitalismus #Antireport #KI


Abgeordnete schwärmen von fließenden Gesundheitsdaten

"Die #Bundesregierung will das Gesundheitswesen digitalisieren. In einer ersten Lesung stießen zwei Gesetzentwürfe im Bundestag auf breite Zustimmung. Kritik kam vor allem von der Linkspartei, die vor „gläsernen Patient:innen“, Datenlecks und Hacks warnte...."

https://netzpolitik.org/2023/debatte-im-bundestag-abgeordnete-schwaermen-von-fliessenden-gesundheitsdaten/

#netzpolitik #Datenschutz #Privacy #Überwachung #Deutschland


#eIDAS-Reform: Digitale Brieftasche mit Ausspähgarantie

"Jetzt steht es fest: Die europäische digitale Brieftasche kommt․ Aus Sicht von Beobachtern bringt der im Trilog erzielte Kompromiss etliche Verbesserungen im Vergleich zum ursprünglichen Kommissionsentwurf․ Bürgerrechtsgruppen und Datenschützer:innen warnen jedoch davor, dass Staaten durch die Wallet eine "panoptische Vogelperspektive" erhielten․"

https://netzpolitik.org/2023/eidas-reform-digitale-brieftasche-mit-ausspaehgarantie/

#Überwachung #Datenschutz #digitaleidentität #eidas #epicenterworks #EU #EUKommission #IDWallet #Privacy #Netzpolitik


Digitale Identitäten
​​​​​eIDAS-Trilog: Hunderte Wissenschaftler:innen und NGOs warnen vor #Massenüberwachung

"Die #EU will eine digitale Brieftasche für alle Bürger:innen einführen․ Rund 400 Forschende und 30 NGOs kritisieren in einem offenen Brief, dass die aktuellen Pläne staatlichen Behörden ermöglichen, die Kommunikation aller EU-Bürger:innen auszuspähen․"

https://netzpolitik.org/2023/eidas-trilog-hunderte-wissenschaftlerinnen-und-ngos-warnen-vor-massenueberwachung/

#eiDAS #Überwachung #EU #Surveillance #Privacy #Data


Secret #EU law threatens #Internet security #massSurveillance
Last Chance to fix #eIDAS

"New legislative articles, introduced in recent closed-door meetings and not yet public, envision that all web browsers distributed in Europe will be required to trust the certificate authorities and cryptographic keys selected by EU governments.

These changes radically expand the capability of EU governments to surveil their citizens by ensuring cryptographic keys under government control can be used to intercept encrypted web traffic across the EU. Any EU member state has the ability to designate cryptographic keys for distribution in web browsers and browsers are forbidden from revoking trust in these keys without government permission.

https://last-chance-for-eidas.org/

#Europe #Surveillance #Privacy #Data #Antireport


Online-Ausweis und #VPN-Verbot: Streit über Anonymität im Netz kocht wieder hoch....
Während andere autoritäre Staaten wie beispielsweiße #Russland bereits weiter sind, könnte sich auch in der Europäischen Union schon bald eine Verifikations- bzw Identifizierungspflicht im #Internet durchsetzen. Diese wird im Gesetzesvorhaben zur #Chatkontrolle jedenfalls für bestimmte Seiten, Inhalte und für den Download und die Nutzung bestimmter Software, wie zB Chatprogrammen wie Signal und Co., ebenso erwogen. Durch die in der #EU und ihren Mitgliedsstaaten ebenfalls vorangetriebene Einführung von "Digitalen Identitäten" (eIDAS, BundID, etc.) können derartige Kontrollen zukünftig auch leichter erfolgen und nach möglichen Einschränkungen anfangs, später mit beliebigem Anlass ausgeweitet werden. Schließlich werden die Autoritären in der #EU sich gewiss nicht gerne von Russland abhängen lassen, was ihre Visionen für digitale Überwachungs- und Kontrollgesellschaften angeht.

So dann.
"In #Frankreich und im #EU-Parlament gewinnt die Debatte über ein Ende der Online-Anonymität an Fahrt. Auch die geplante europäische #eID spielt dabei eine Rolle."
https://www.heise.de/news/Online-Ausweis-und-VPN-Verbot-Streit-ueber-Anonymitaet-im-Netz-kocht-wieder-hoch-9327812.html

https://netzpolitik.org/2023/russland-identitifikationspflicht-gegen-die-online-anonymitaet/
#EU #FightTheFortress #FightTheFortress #Überwachung #Datenschutz #Privacy


Identitifikationspflicht gegen die Online-Anonymität
"Ein neues russisches Gesetz macht Identitätsfeststellungen im Internet verpflichtend. Vor allem Online-Plattformen und Hosting-Provider unterliegen künftig strengen Auflagen. Eine anonyme Nutzung des Internets ist in Russland damit kaum noch möglich.
(...)
Doch nicht nur Online-Plattformen nimmt das neue Gesetz ins Visier, sondern auch Hosting-Provider, die Speicher für Webseiten oder Internetdienste bereitstellen.
(...)
Hosting-Provider und Online-Plattformen, welche die neuen Auflagen erfüllen, werden in Zukunft in einem staatlichen Register mit „erlaubten“ Anbietern aufgeführt. Das Register obliegt der Aufsicht einer staatlichen Behörde, die noch bis zum 1. Februar 2024 bestimmt wird.
https://netzpolitik.org/2023/russland-identitifikationspflicht-gegen-die-online-anonymitaet/

#Russland #Internet #Privacy #Data #Antireport


Dass es bei der #Chatkontrolle nicht um den behaupteten Schutz von Kindern geht, sondern um allgemeine Verschlüsselungsverbote, Identifizierungspflichten und die Errichtung neuer digitaler, erweiterbare Kontrollinfrastrukturen, dürfte längst bekannt sein.

Dass Staaten und #EU in diesem Zusammenhang jetzt sogar noch auf die Echtzeit-Überwachung von Audiokommunikation hinarbeiten, zeigt, wie weit und maßlos die autoritären Bestrebungen der Herrschenden offensichtlich reichen und wie gefährlich "digitale Vorhaben" der EU ganz allgemein sind.

Es sollte aber auch bedacht werden, dass es sich bei so etwas um taktische Maximalforderung handeln kann. Nach dem Muster, dass alles andere dann "nicht mehr so schlimm" wirkt und im Falle einer vermeintlichen Abschwächung des Vorhabens oder eines Gerichtsurteils, zwar ein "Immerhin ist das mit der Audioüberwachung nicht durchgekommen" steht und irgendwelche Seiten und Parteien sich mal wieder für irgendwelche faulen Kompromisse feiern lassen, während trotzdem die #Massenüberwachung von persönlicher Text-Kommunikation, Identifizierungspflichten für Chatprogramme, Websites und App-Stores sowie Netzsperren durchgesetzt werden.

https://www.heise.de/news/Live-Ueberwachung-Mehrheit-der-EU-Staaten-draengt-auf-Audio-Chatkontrolle-9059028.html

#Überwachung #Autoritarisierung #Digitalisierung #Staat #Herrschaft #privacy #Datenschutz


Email aliasing: Are these my "best" options?

-DuckDuckGo (big corporation, dabbling in AI)
-Simple Login (Proton, whose CEO is being weird)
-addy dot io (there were some posts on here awhile back about why the io domain is shitty but it doesn't look like I bookmarked any of them, the gist was imperialism so I like to avoid the domain)
-figuring out how to generate them using an email provider itself (clunky, usually end up with really long addresses, may not even hide your original address, may only be able to generate a limited number which kinda defeats the purpose for me because I want single-use ones)

#Email #Alias #Aliasing #Privacy


Browser (Firefox): Bitwarden, CanvasBlocker, Decentraleyes, D̶i̶s̶a̶b̶l̶e̶ ̶J̶a̶v̶a̶S̶c̶r̶i̶p̶t̶,̶ ̶D̶o̶n̶'̶t̶ ̶T̶r̶a̶c̶k̶ ̶M̶e̶ ̶G̶o̶o̶g̶l̶e̶,̶, Containers, P̶r̶i̶v̶a̶c̶y̶ ̶B̶a̶d̶g̶e̶r̶, uBlock Origin, S̶e̶a̶r̶c̶h̶ ̶b̶y̶ ̶I̶m̶a̶g̶e̶.

Self-hosted: SearXNG, Redlib, NextCloud, Immich.

Network: Pi-hole + Unbound DNS, VPN, DNS leak tests.

Email: ProtonMail, alias sign-ups.

What am I missing? Any tips?
Just go Tor 24/7 at this point?

Edit:
added strike-through

#Privacy #Anonymity #Infosec #CyberSecurity


दिल्ली विधानसभा चुनाव: कांग्रेस और बीजेपी की रणनीति बिखरे वोटों को साधने पर केंद्रित।

https://aliyesha.com/sub/articles/news/display/nd_delhi_elections_congress_bjp_vote_bank

#newdelhi #delhi #india #news #press #elections2025 #elections #bjp #aap #congress #pmmodi #kejriwal #RahulGandhi #VoteBank

Enjoy tracker free reading with us. #privacy #privacymatters


"Government must stop restricting website access with laws requiring age verification.

Some advocates of these censorship schemes argue we can nerd our way out of the many harms they cause to speech, equity, privacy, and infosec. Their silver bullet? “Age estimation” technology that scans our faces, applies an algorithm, and guesses how old we are – before letting us access online content and opportunities to communicate with others. But when confronted with age estimation face scans, many people will refrain from accessing restricted websites, even when they have a legal right to use them. Why?

Because quite simply, age estimation face scans are creepy AF – and harmful. First, age estimation is inaccurate and discriminatory. Second, its underlying technology can be used to try to estimate our other demographics, like ethnicity and gender, as well as our names. Third, law enforcement wants to use its underlying technology to guess our emotions and honesty, which in the hands of jumpy officers is likely to endanger innocent people. Fourth, age estimation face scans create privacy and infosec threats for the people scanned. In short, government should be restraining this hazardous technology, not normalizing it through age verification mandates."

https://www.eff.org/deeplinks/2025/01/face-scans-estimate-our-age-creepy-af-and-harmful

#USA #AgeVerification #AgeEstimation #Surveillance #Privacy #CyberSecurity #FaceScans


WP3.XYZ Malware attacks Add Rogue Admins to 5,000+ WordPress Sites.

Webscript security company c/side discovered during an incident response engagement for one of their clients that the malicious activity uses the wp3[.]xyz domain to exfiltrate data but have yet to determine the initial infection vector.

https://cside.dev/blog/over-5k-wordpress-sites-caught-in-wp3xyz-malware-attack

#wordpress #malicious #plugin #it #security #privacy #engineer #media #tech #news


Damit müssen die Standortdienste dauerhaft aktiv bleiben. Irgendwie auch keine tolle Idee. #privacy #grapheneos


Earlier today, Google rejected a feature request asking for the option to use DNS-over-HTTPS servers other than Google’s and Cloudflare’s in Android: https://issuetracker.google.com/issues/331250145?pli=1#comment7

According to Google’s own testing, DoH is more private, secure, and performant than DoT on Android. There is no reason whatsoever to limit it to a handful of Google-approved servers.

Just like with Manifest V3 in Chrome, this arbitrary restriction on what DNS servers can use the most modern technologies in Android is a clear example of Google abusing their position to campaign against blocking invasive trackers. One of the clearest uses for custom DNS servers is the ability to block privacy-invasive services like Google’s at the DNS level.

Further details & discussion on our forum: https://discuss.privacyguides.net/t/google-rejects-feature-request-for-arbitrary-dns-over-https-server-support/24320

#android #google #privacy #dns


"So I feel the issues here are ultimately systemic policy problems that need to be fixed with regulation (such as enact national right to repair laws, de-fang the DMCA, implement US national privacy protections, somehow limit the massive seemingly untouchable influence of big tech companies, and probably tax down tech billionaires).

That’s a big ask that feels insurmountable at this moment, but it’s a movement can start now with people who are fed up with our current de facto abusive tech business models. I think eventually we will get there anyway, because the I am not sure the current extractive model is sustainable without encountering massive social unrest within the next decade. The alternative to change, if taken to an extreme, may be the collapse of personal liberty for everyone.

In the meantime, while these lofty goals simmer and take shape, you can also continue to take personal steps to preserve your own tech liberty. Support nonprofits like the EFF that fight for privacy and user rights, strong encryption, open source, use local storage, and so on. I highly encourage it.

Ultimately I hope these thoughts can be a starting point for others to pick up the torch and build off of. I will also be thinking of constructive solutions for a future follow-up."

https://www.vintagecomputing.com/index.php/archives/3292/the-pc-is-dead-its-time-to-make-computing-personal-again

#USA #Privacy #BigTech #SurveillanceCapitalism #DMCA #RightToRepair #Oligopolies


योगी आदित्यनाथ ने दिल्ली चुनाव में किया प्रचार, आप सरकार पर साधा निशाना।

https://aliyesha.com/sub/articles/news/display/nd_yogi_campaign_delhi_elections_2025

#newdelhi #delhi #india #news #press #elections2025 #elections #bjp #aap #yogiadityanath #kejriwal #ganga #yamuna #rivers #WaterPollution #IllegalImmigrants

Enjoy tracker free reading with us. #privacy #privacymatters


The first-ever Ransomware dropped 35 Years ago disguised as a Floppy Sharing [AIDS Information].

Thirty-five years ago, as December 1989 turned into January 1990, the then-largest ever cybercrime investigation was launched in response to the world's first known example of ransomware.

https://www.heise.de/news/Missing-Link-35-Jahre-Ransomware-am-Anfang-stand-eine-unscheinbare-Diskette-10247344.html

#ransomware #history #retrocomputing #retro #it #security #privacy #engineer #media #tech #news
This first ransomware payload was secreted on a 5.25-inch floppy disk titled "AIDS Information — Introductory Diskette 2.0" [h/t Heise.de]. The pioneering ransomware was developed by one American biologist [Dr. Joseph Lewis Andrew Popp Jr.], and about 20.000 copies were distributed to subscribers of the magazine PC Business World, various mailing lists, and even to World Health Organization delegates during a conference on AIDS.

As one may be able to deduce by the years and names being thrown around, this attack's choice of target was highly intelligent and the method of delivery exploited people's existing fears of a terrifying new biological virus at a time when knowledge of regular computer viruses was at an all-time low — much less an all-new form of malware meant to extort its victims.

Compared to modern-day threat actor attacks, only file names [not the files themselves], were encrypted by this ransomware. Thanks to this, effective software countermeasures ("AIDSOUT" to remove it and "AIDSCLEAR" to check for hidden directories combined into "CLEARAID") were developed by John Sutcliffe and Jim Bates to rescue impacted parties.


"The Federal Trade Commission announced a proposed settlement agreeing that General Motors and its subsidiary, OnStar, will be banned from selling geolocation and driver behavior data to credit agencies for five years. That’s good news for G.M. owners. Every car owner and driver deserves to be protected.

Last year, a New York Times investigation highlighted how G.M. was sharing information with insurance companies without clear knowledge from the driver. This resulted in people’s insurance premiums increasing, sometimes without them realizing why that was happening. This data sharing problem was common amongst many carmakers, not just G.M., but figuring out what your car was sharing was often a Sisyphean task, somehow managing to be more complicated than trying to learn similar details about apps or websites."

https://www.eff.org/deeplinks/2025/01/ftcs-ban-gm-and-onstar-selling-driver-behavior-good-first-step

#USA #FTC #GM #OnStar #Privacy #LocationData #GeoLocation #DataProtection


"This decision sheds light on the government’s liberal use of what is essential a “finders keepers” rule regarding your communication data. As a legal authority, FISA Section 702 allows the intelligence community to collect a massive amount of communications data from overseas in the name of “national security.” But, in cases where one side of that conversation is a person on US soil, that data is still collected and retained in large databases searchable by federal law enforcement. Because the US-side of these communications is already collected and just sitting there, the government has claimed that law enforcement agencies do not need a warrant to sift through them. EFF argued for over a decade that this is unconstitutional, and now a federal court agrees with us."

https://www.eff.org/deeplinks/2025/01/victory-federal-court-finally-rules-backdoor-searches-702-data-unconstitutional

#USA #Surveillance #PoliceState #Section702 #Backdoors #CyberSecurity #Privacy


Gaaaanz toll !
Jemand, den ich gar nicht kenne ( die #Gemini KI) erfährt also, welche #Wochenendaktivitäten ich plane und auch noch, mit wem. Das ist sowas von #Anti-#Privacy.

#cybersecurity #datenkrakegoogle


Revolut's GrapheneOS Ban Bypassed Temporarily, Raises Privacy and Anti-Competition Concerns
https://friendica-leipzig.de/photo/media/480532

#IKITAO #Privacy #Tech


US Cloud soon illegal? #Trump punches first hole in EU-US Data Deal https://noyb.eu/en/us-cloud-soon-illegal-trump-punches-first-hole-eu-us-data-deal #privacy #privacidad


Vanadium version 132.0.6834.122.0 released:

https://github.com/GrapheneOS/Vanadium/releases/tag/132.0.6834.122.0

See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

Forum discussion thread:

https://discuss.grapheneos.org/d/19322-vanadium-version-132068341220-released

#GrapheneOS #privacy #security #browser


मोदी सरकार ने मिडिल क्लास को एटीएम बनाकर रख दिया: केजरीवाल।

https://aliyesha.com/sub/articles/news/display/nd_modi_government_middle_class_problems_kejri

#newdelhi #delhi #india #news #press #elections2025 #elections #MiddleClass #kejriwal #pmmodi #aap #bjp #IncomeTax #budget #retirement #EconomicJustice

Enjoy tracker free reading with us. #privacy #privacymatters


Safety reminders for these times:
- Direct messages on Fedi are not encrypted.
- If your instance is hosted in the US, the admin has to comply with US law.
- Discord text chat is not encrypted. Video is.
- Encrypted group chats are only as secure as the people with access and their security practices.

If you're interested in protecting the contents of your conversations or work, follow the #privacy tag. People posts some really interesting things on there.

Your privacy protects your friends too. Do it for all of us.

An excellent step-by-step executable guide to implementing better privacy. https://www.optoutproject.net/the-cyber-cleanse-take-back-your-digital-footprint/

Recommended privacy people:
- @Em0nM4stodon
- @techlore
- @privacyguides
- @thenewoil

More advice from smarter people:
- Passwords & General Privacy hygiene: https://infosec.exchange/@avoidthehack/113867140078775299
- VPNs: https://mas.to/@joeturner/113867181288155342

Recommended privacy communities:
- https://discuss.techlore.tech
- https://discuss.privacyguides.net

The rest of this thread describes options that I'm considering and my personal privacy journey.

(Thanks to @joeturner and everyone else in the community for your recommendations.)

Tracking bits of this migration via the #MayDeFAANGing tag.


Hey folks, unless you’re using an end-to-end encrypted messaging system, your DMs are readable (given sufficient incentive).

Please read up on whether your messaging system is *end-to-end* encrypted, not just “encrypted”, and think about whether you trust the developers to write good code and not lie to you about how things work.

Mastodon DMs are *not* end-to-end encrypted! You should not write anything on Mastodon that you don’t want published in the open (given sufficient incentive).

Some systems *can* be end-to-end encrypted but are not by default. RCS, FB Messenger, and Instagram DMs fall into this category AFAICT. Some systems don’t even offer it, like Discord.

Please consider moving your private messages to a system that is private by design! I’m partial to Signal, but feel free to choose your own.

#privacy #encryption


Check out my review of @GrapheneOS at 890.blog:

https://www.890.blog/post/my-thoughts-on-grapheneos

#GrapheneOS #Privacy #Security #TechReview #890Blog #OpenSource #Android


Die Signatur-Problematik bei F-Droid ist offenbar noch immer nicht gelöst: "We find it concerning that F-Droid constantly chooses to move the goalposts and continues to rely on a fundamentally broken approach for certificate pinning, merely patching [15] known vulnerabilities without ever addressing the underlying cause." 😵👇

https://github.com/obfusk/fdroid-fakesigner-poc?tab=readme-ov-file#update-2025-01-19

#fdroid #security #privacy #certpinning #signature