[HN Gopher] Improving your online privacy: An update
       ___________________________________________________________________
        
       Improving your online privacy: An update
        
       Author : todsacerdoti
       Score  : 127 points
       Date   : 2023-09-19 12:54 UTC (10 hours ago)
        
 (HTM) web link (blog.ovalerio.net)
 (TXT) w3m dump (blog.ovalerio.net)
        
       | egberts1 wrote:
       | Recommended Jitsu requires only Chrome or Chromium.
       | 
       | Yet, same article strongly discourages Chrome.
       | 
       | And Apple iOS does not have Chromium either.
       | 
       | :-/
        
         | benoliver999 wrote:
         | Jitsi works on Firefox just fine.
         | 
         | https://jitsi.github.io/handbook/docs/user-guide/supported-b...
        
         | Terretta wrote:
         | > _And Apple iOS does not have Chromium either._
         | 
         | Remember when Chrome (chromium) was a fork of Safari (webkit)?
        
       | MerelyMortal wrote:
       | I'm always looking for guides on how to improve physical world
       | privacy if anyone knows of any.
        
       | drunner wrote:
       | Is anyone familiar with what privacy badger does over uBlock
       | origin? Unless my information is out of date, the more extensions
       | you have installed the more unique your fingerprint is?
        
         | ghostwords wrote:
         | Privacy Badger dev here.
         | 
         | I think the biggest concern is to only install extensions from
         | developers and organizations you trust.
         | 
         | As for your browser fingerprint, on the one hand, the more
         | custom your browser setup, the more you stand out. On the other
         | hand, Privacy Badger exists to reduce pervasive, non-consensual
         | tracking. We especially aim to block pervasive fingerprinters,
         | along with other obnoxious types of trackers.
         | 
         | More about Privacy Badger below, adapted from
         | https://privacybadger.org/#Is-Privacy-Badger-compatible-with...
         | 
         | While there is a lot of overlap between the various manually-
         | edited advertising/tracker lists and Privacy Badger, unlike
         | list-based tools, Privacy Badger automatically learns to block
         | trackers based on their behavior. This means that Privacy
         | Badger may learn to block trackers your list-based tool doesn't
         | know about.
         | 
         | Besides automatic learning, Privacy Badger comes with other
         | advantages like cookie blocking, click-to-activate placeholders
         | for potentially useful tracker widgets (video players, comments
         | widgets, etc.), and outgoing link click tracking removal on
         | Facebook and Google (recently updated, see
         | https://www.eff.org/badger-link-tracking-protection-update).
         | 
         | Privacy Badger is also a political tool. Privacy Badger sends
         | the Global Privacy Control signal to opt you out of data
         | sharing and selling, and the Do Not Track signal to tell
         | companies not to track you. If trackers ignore your wishes,
         | Privacy Badger will learn to block them. By using Privacy
         | Badger, you support the Electronic Frontier Foundation and help
         | fight for a better Web for everybody.
        
       | blfr wrote:
       | The big one is
       | 
       | > Use fake profiles / identities.
       | 
       | All the journos, mods, and celebs lobbying against, complaining
       | about, and trying to eradicate anonymity/pseudonymity online are
       | acting against your interests. I would even like to see more
       | social norms against "namefagging."
       | 
       | Real names are for the most banal online activities (mostly
       | buying stuff), for everything else there are aliases with varying
       | levels of technical obscurity (alternative/temp email - VPN -
       | Tor). Give them nothing, pay Mullvad the EUR5 privacy tax.
        
       | BelleOfTheBall wrote:
       | I clicked this expecting some deep-dive ramble about moving all
       | communications to Matrix, but this is actually a very concise and
       | accessible guide. Now, I will admit I'm biased since I already
       | follow all of these steps, but it seems really simple to me. In
       | fact, the addition of the "Expected effort" bits makes me wonder
       | if I could convince some friends to follow suit and at least
       | switch to Firefox and DDG. OSM has proven a hard sell so far,
       | sadly.
        
         | nicholasjarnold wrote:
         | Regarding usage of OpenStreetMap over Google Maps - assuming
         | we're talking mobile usage - you might give OSMAnd[0] a try.
         | I've been using it exclusively on a Pixel loaded with
         | GrapheneOS for a few months now. I would never consider going
         | back to GMaps and I don't feel that I've lost anything either.
         | 
         | [0] - https://osmand.net/
        
           | thenameipicked wrote:
           | I have not had Google Maps on my phone for a couple of years
           | now, but I still think that GMaps is superior. Locations are
           | more maintained, address geocoding is near perfect, it has
           | plentiful useful reviews, and live traffic updates.
           | 
           | As far as location maintenance, this is obviously correlated
           | with usage, and so I hope this will improve over time.
           | 
           | I see very little progress on the other three.
        
       | fmajid wrote:
       | Use multiple browsers. Set your primary browser to block cookies
       | not explicitly allowlisted.
       | 
       | I use Vivaldi configured thus for general browsing, have Firefox
       | for those annoying JavaScript-backed sites that fail miserably if
       | cookies are blocked, with a one-click button to nuke all cookies
       | just after reading the article, and Safari for e-commerce sites
       | where I need autocompletion of shipping address and other
       | stickiness.
        
       | wolverine876 wrote:
       | Your ISP will have a running log of every website you visit, and
       | every website will have your personal identity (if they want it).
       | Fake identies aren't especially useful if the other side can see
       | your IP address.
       | 
       | Those are just a couple of examples. The OP is a list of
       | arbitrarily selected and often not particularly valuable advice
       | that leaves many holes. What do people see in it that they voted
       | it to the front page?
        
       | agentdrtran wrote:
       | I like the general recommendations here but think it really
       | undersells how hard it is to switch in many cases - the time
       | recommendation are comically short. Yes, going to a new site
       | instead of a Google site might only take a minute of your time to
       | sign up but moving all your data over and learning a new,
       | sometimes inferior tool can take weeks.
        
       | Joel_Mckay wrote:
       | The harsh reality is privacy became a commodity, and due to
       | overabundance it is relatively cheap. Even apparent competitors
       | sell each other marketing data in this ecosystem.
       | 
       | If you want to participate in the modern economy, than you need
       | to assume there is never any isolation. Even creeps with phones
       | will show up taking photos on private property, as some app paid
       | them $5 to risk their lives trespassing.
       | 
       | Mozilla Firefox collects beacon telemetry with a UUID by default
       | (as does most browsers). While there is a lot of community
       | goodwill around the popular browser, most are not technically
       | advanced enough to mitigate the dozens of defaults that do not
       | respect user privacy.
       | 
       | Additionally, most modern OS are just a crude sales funnel for
       | OEM products and services. Technically, tying and racketeering
       | with a computer is still illegal, but cultural norms have shifted
       | expectations on corporate conduct.
       | 
       | This is the modern web, and arguably it was a mistake =)
        
         | JohnFen wrote:
         | > This is the modern web, and arguably it was a mistake
         | 
         | Agreed. Although I say it differently: the web is dead. It has
         | been thoroughly transformed into a hostile place optimized for
         | commerce and surveillance. As such, it is no longer really
         | capable of doing the things that used to make it great.
        
           | nonrandomstring wrote:
           | Sir Tim Berners-Lee said the Web 'failed instead of served
           | humanity'. He claimed to be "devastated" by abuses of the
           | web.
           | 
           | I find this profoundly tragic. But also affirming that a
           | respected source of wisdom aligns with my own "truth". So,
           | maybe it's not too hyperbolic to say the "Web is dead" if it
           | is dead to it's own creator.
           | 
           | Some of whatever it was lives on, in ideas and values of a
           | minority. We cannot wind it back, or rebuild it on the sewer
           | it now is. For the rest, who know no better, it is a
           | horrible, horrible place.
           | 
           | What we might usefully teach children are the many other ways
           | to use computers and the internet, as local oracles, as peer
           | to peer technologies, through networks on other protocols.
        
         | troyvit wrote:
         | > The harsh reality is privacy became a commodity,
         | 
         | Yep. Almost every CMP and privacy statement accidentally
         | confirms that:
         | 
         | "We value your privacy!"
         | 
         | Yeah you value my privacy. You want to own it.
        
           | jareklupinski wrote:
           | real "to serve man" vibes
        
             | m463 wrote:
             | :)
             | 
             | https://en.wikipedia.org/wiki/To_Serve_Man
        
       | ds wrote:
       | Not mentioned:
       | 
       | Removing your information from all social media / messengers :
       | https://redact.dev (disclaimer, im on the team)
       | 
       | Removing your information from all databrokers
       | https://easyoptouts.com / incogni / deleteme / optery
        
         | autoexec wrote:
         | Probably because it doesn't work. You can remove specific
         | information from specific websites, but most of that has been
         | scraped and copied already. You can request that companies
         | delete information you have already handed over to them, but
         | you have no power to compel them to delete all the information
         | that they learned about you by analysis of that data.
         | 
         | If your phone gives Google a list of your GPS coordinates over
         | the last 30 days that's your data and you can request that
         | Google delete it. They don't care, because they've already used
         | that to learn where you live, how often you go to bars, where
         | you work, how often you go to the gym, and who you've been
         | sleeping with. That's _their_ data, not yours.
         | 
         | Data brokers don't care about deleting your data. Their data
         | about your data is what they get paid for.
        
         | danwee wrote:
         | > Removing your information from all databrokers
         | https://easyoptouts.com / incogni / deleteme / optery
         | 
         | How ironic. In order to remove my data from the internet, I
         | first need to give my data to that random website.
        
           | pc86 wrote:
           | I mean in a world where data collection is pretty explicitly
           | opt-out it makes sense. They do need to know what data to
           | remove, right?
        
         | shortcake27 wrote:
         | Where is the world collectively on outlawing data brokers? If
         | your business model revolves around selling people's data
         | without their consent, you're a nuisance. Literally nobody
         | would explicitly agree to have their data sold and used to
         | bother them. We have plenty of laws against nuisance, because
         | nuisance doesn't benefit society. Why is it taking so long to
         | ban this business model?
        
           | fmajid wrote:
           | If you are a Californian, starting 2026 you will have a one-
           | stop shop to opt out of all data brokers:
           | 
           | https://www.theregister.com/2023/09/18/california_passes_bil.
           | ..
        
             | Slow_Hand wrote:
             | I'm thrilled. This cannot come soon enough.
        
           | JohnMakin wrote:
           | > Literally nobody would explicitly agree to have their data
           | sold and used to bother them.
           | 
           | I don't think this is the case. fairly recently I've seen the
           | old "if you dont want to be tracked by facebook, then dont
           | use it!!!" take on here from people who are supposed to know
           | better.
           | 
           | Maybe not explicit, but if you told them I guarantee most
           | people do not care at all, or people would be _far_ more
           | upset than they currently are.
        
             | Terretta wrote:
             | And "But I _like_ ads that know what I want. Why would you
             | want to see ads for things you _don 't_ want?" is hard to
             | argue with until you realize there's no particular reason
             | you have to see ads.
             | 
             | The '90s web was fine without ads, in its "pamphleteering"
             | days when people spent an amount of money proportionate to
             | how badly they wanted to say something, and that was it.
             | 
             | https://en.wikipedia.org/wiki/Pamphleteer
        
         | jpsouth wrote:
         | Does redact come with account deletion as well?
        
         | gt2 wrote:
         | Has anyone experienced a drop in recruiter spam when removing
         | your information from databrokers with those services? I have
         | daily unsolicited recruiter emails in the last few years, and
         | I'm not on linkedIn since 2018-ish, so I have no idea where
         | they are getting my info from.
        
         | opteryology wrote:
         | Absolutely agree with the importance of removing information
         | from data brokers (aka People Search Sites), since they are be
         | a goldmine for bad actors.
         | 
         | Actually, Optery is a YC 2022 company and there are some good
         | discussions on Optery and its competitors here on HN, ex:
         | https://news.ycombinator.com/item?id=30605010
         | 
         | For those evaluating data removal services, a solid first step
         | is to sign up for each company's free scan and compare the
         | results.
         | 
         | Full disclosure: I am on the Optery team
        
       | rodolphoarruda wrote:
       | > "Delete cookies and site data when Firefox is closed".
       | 
       | I have adopted this for almost a year now. Once I learned that it
       | is possible to bypass Windows login, I thought that if the agent
       | could get access to my browser with all cookies in, he could
       | easily impersonate me in every possible corner of my digital
       | life. So, no thanks. I live in a place where you can get your
       | laptop stolen at any moment. So in my case, the perpetrator won't
       | get much further as he won't have my password manager's master
       | password. Local files are all inside a VeraCrypt volume so he
       | won't have any luck finding them in readable form.
       | 
       | This is the bare minimum of my threat model.
        
       | therealmarv wrote:
       | And loose everything you gained in this article by using a
       | standard smartphone and some very common apps.
        
       | vpaulus wrote:
       | I am really looking forward when this becomes a base topic in the
       | elementary schools (including tips how to use mobile apps). Right
       | now it's self-evident that children learn using Chrome and Google
        
         | rodolphoarruda wrote:
         | I have worked in that front 5 years ago. Schoolsec, that was
         | our name. Our target niche was elementary schools in southeast
         | Brazil. It didn't work. Most of the schools we spoke to didn't
         | even understand what we were talking about, so they couldn't
         | assess the risk and, finally, realize the value of our work.
         | 
         | Of course, as years pass, the need for more "digital self-
         | defense" increases at all levels. Maybe one day we'll hear of
         | someone who had pulled it off by presenting a great value prop
         | for this kind of service.
        
       ___________________________________________________________________
       (page generated 2023-09-19 23:01 UTC)