[HN Gopher] Improving your online privacy: An update
___________________________________________________________________
Improving your online privacy: An update
Author : todsacerdoti
Score : 127 points
Date : 2023-09-19 12:54 UTC (10 hours ago)
(HTM) web link (blog.ovalerio.net)
(TXT) w3m dump (blog.ovalerio.net)
| egberts1 wrote:
| Recommended Jitsu requires only Chrome or Chromium.
|
| Yet, same article strongly discourages Chrome.
|
| And Apple iOS does not have Chromium either.
|
| :-/
| benoliver999 wrote:
| Jitsi works on Firefox just fine.
|
| https://jitsi.github.io/handbook/docs/user-guide/supported-b...
| Terretta wrote:
| > _And Apple iOS does not have Chromium either._
|
| Remember when Chrome (chromium) was a fork of Safari (webkit)?
| MerelyMortal wrote:
| I'm always looking for guides on how to improve physical world
| privacy if anyone knows of any.
| drunner wrote:
| Is anyone familiar with what privacy badger does over uBlock
| origin? Unless my information is out of date, the more extensions
| you have installed the more unique your fingerprint is?
| ghostwords wrote:
| Privacy Badger dev here.
|
| I think the biggest concern is to only install extensions from
| developers and organizations you trust.
|
| As for your browser fingerprint, on the one hand, the more
| custom your browser setup, the more you stand out. On the other
| hand, Privacy Badger exists to reduce pervasive, non-consensual
| tracking. We especially aim to block pervasive fingerprinters,
| along with other obnoxious types of trackers.
|
| More about Privacy Badger below, adapted from
| https://privacybadger.org/#Is-Privacy-Badger-compatible-with...
|
| While there is a lot of overlap between the various manually-
| edited advertising/tracker lists and Privacy Badger, unlike
| list-based tools, Privacy Badger automatically learns to block
| trackers based on their behavior. This means that Privacy
| Badger may learn to block trackers your list-based tool doesn't
| know about.
|
| Besides automatic learning, Privacy Badger comes with other
| advantages like cookie blocking, click-to-activate placeholders
| for potentially useful tracker widgets (video players, comments
| widgets, etc.), and outgoing link click tracking removal on
| Facebook and Google (recently updated, see
| https://www.eff.org/badger-link-tracking-protection-update).
|
| Privacy Badger is also a political tool. Privacy Badger sends
| the Global Privacy Control signal to opt you out of data
| sharing and selling, and the Do Not Track signal to tell
| companies not to track you. If trackers ignore your wishes,
| Privacy Badger will learn to block them. By using Privacy
| Badger, you support the Electronic Frontier Foundation and help
| fight for a better Web for everybody.
| blfr wrote:
| The big one is
|
| > Use fake profiles / identities.
|
| All the journos, mods, and celebs lobbying against, complaining
| about, and trying to eradicate anonymity/pseudonymity online are
| acting against your interests. I would even like to see more
| social norms against "namefagging."
|
| Real names are for the most banal online activities (mostly
| buying stuff), for everything else there are aliases with varying
| levels of technical obscurity (alternative/temp email - VPN -
| Tor). Give them nothing, pay Mullvad the EUR5 privacy tax.
| BelleOfTheBall wrote:
| I clicked this expecting some deep-dive ramble about moving all
| communications to Matrix, but this is actually a very concise and
| accessible guide. Now, I will admit I'm biased since I already
| follow all of these steps, but it seems really simple to me. In
| fact, the addition of the "Expected effort" bits makes me wonder
| if I could convince some friends to follow suit and at least
| switch to Firefox and DDG. OSM has proven a hard sell so far,
| sadly.
| nicholasjarnold wrote:
| Regarding usage of OpenStreetMap over Google Maps - assuming
| we're talking mobile usage - you might give OSMAnd[0] a try.
| I've been using it exclusively on a Pixel loaded with
| GrapheneOS for a few months now. I would never consider going
| back to GMaps and I don't feel that I've lost anything either.
|
| [0] - https://osmand.net/
| thenameipicked wrote:
| I have not had Google Maps on my phone for a couple of years
| now, but I still think that GMaps is superior. Locations are
| more maintained, address geocoding is near perfect, it has
| plentiful useful reviews, and live traffic updates.
|
| As far as location maintenance, this is obviously correlated
| with usage, and so I hope this will improve over time.
|
| I see very little progress on the other three.
| fmajid wrote:
| Use multiple browsers. Set your primary browser to block cookies
| not explicitly allowlisted.
|
| I use Vivaldi configured thus for general browsing, have Firefox
| for those annoying JavaScript-backed sites that fail miserably if
| cookies are blocked, with a one-click button to nuke all cookies
| just after reading the article, and Safari for e-commerce sites
| where I need autocompletion of shipping address and other
| stickiness.
| wolverine876 wrote:
| Your ISP will have a running log of every website you visit, and
| every website will have your personal identity (if they want it).
| Fake identies aren't especially useful if the other side can see
| your IP address.
|
| Those are just a couple of examples. The OP is a list of
| arbitrarily selected and often not particularly valuable advice
| that leaves many holes. What do people see in it that they voted
| it to the front page?
| agentdrtran wrote:
| I like the general recommendations here but think it really
| undersells how hard it is to switch in many cases - the time
| recommendation are comically short. Yes, going to a new site
| instead of a Google site might only take a minute of your time to
| sign up but moving all your data over and learning a new,
| sometimes inferior tool can take weeks.
| Joel_Mckay wrote:
| The harsh reality is privacy became a commodity, and due to
| overabundance it is relatively cheap. Even apparent competitors
| sell each other marketing data in this ecosystem.
|
| If you want to participate in the modern economy, than you need
| to assume there is never any isolation. Even creeps with phones
| will show up taking photos on private property, as some app paid
| them $5 to risk their lives trespassing.
|
| Mozilla Firefox collects beacon telemetry with a UUID by default
| (as does most browsers). While there is a lot of community
| goodwill around the popular browser, most are not technically
| advanced enough to mitigate the dozens of defaults that do not
| respect user privacy.
|
| Additionally, most modern OS are just a crude sales funnel for
| OEM products and services. Technically, tying and racketeering
| with a computer is still illegal, but cultural norms have shifted
| expectations on corporate conduct.
|
| This is the modern web, and arguably it was a mistake =)
| JohnFen wrote:
| > This is the modern web, and arguably it was a mistake
|
| Agreed. Although I say it differently: the web is dead. It has
| been thoroughly transformed into a hostile place optimized for
| commerce and surveillance. As such, it is no longer really
| capable of doing the things that used to make it great.
| nonrandomstring wrote:
| Sir Tim Berners-Lee said the Web 'failed instead of served
| humanity'. He claimed to be "devastated" by abuses of the
| web.
|
| I find this profoundly tragic. But also affirming that a
| respected source of wisdom aligns with my own "truth". So,
| maybe it's not too hyperbolic to say the "Web is dead" if it
| is dead to it's own creator.
|
| Some of whatever it was lives on, in ideas and values of a
| minority. We cannot wind it back, or rebuild it on the sewer
| it now is. For the rest, who know no better, it is a
| horrible, horrible place.
|
| What we might usefully teach children are the many other ways
| to use computers and the internet, as local oracles, as peer
| to peer technologies, through networks on other protocols.
| troyvit wrote:
| > The harsh reality is privacy became a commodity,
|
| Yep. Almost every CMP and privacy statement accidentally
| confirms that:
|
| "We value your privacy!"
|
| Yeah you value my privacy. You want to own it.
| jareklupinski wrote:
| real "to serve man" vibes
| m463 wrote:
| :)
|
| https://en.wikipedia.org/wiki/To_Serve_Man
| ds wrote:
| Not mentioned:
|
| Removing your information from all social media / messengers :
| https://redact.dev (disclaimer, im on the team)
|
| Removing your information from all databrokers
| https://easyoptouts.com / incogni / deleteme / optery
| autoexec wrote:
| Probably because it doesn't work. You can remove specific
| information from specific websites, but most of that has been
| scraped and copied already. You can request that companies
| delete information you have already handed over to them, but
| you have no power to compel them to delete all the information
| that they learned about you by analysis of that data.
|
| If your phone gives Google a list of your GPS coordinates over
| the last 30 days that's your data and you can request that
| Google delete it. They don't care, because they've already used
| that to learn where you live, how often you go to bars, where
| you work, how often you go to the gym, and who you've been
| sleeping with. That's _their_ data, not yours.
|
| Data brokers don't care about deleting your data. Their data
| about your data is what they get paid for.
| danwee wrote:
| > Removing your information from all databrokers
| https://easyoptouts.com / incogni / deleteme / optery
|
| How ironic. In order to remove my data from the internet, I
| first need to give my data to that random website.
| pc86 wrote:
| I mean in a world where data collection is pretty explicitly
| opt-out it makes sense. They do need to know what data to
| remove, right?
| shortcake27 wrote:
| Where is the world collectively on outlawing data brokers? If
| your business model revolves around selling people's data
| without their consent, you're a nuisance. Literally nobody
| would explicitly agree to have their data sold and used to
| bother them. We have plenty of laws against nuisance, because
| nuisance doesn't benefit society. Why is it taking so long to
| ban this business model?
| fmajid wrote:
| If you are a Californian, starting 2026 you will have a one-
| stop shop to opt out of all data brokers:
|
| https://www.theregister.com/2023/09/18/california_passes_bil.
| ..
| Slow_Hand wrote:
| I'm thrilled. This cannot come soon enough.
| JohnMakin wrote:
| > Literally nobody would explicitly agree to have their data
| sold and used to bother them.
|
| I don't think this is the case. fairly recently I've seen the
| old "if you dont want to be tracked by facebook, then dont
| use it!!!" take on here from people who are supposed to know
| better.
|
| Maybe not explicit, but if you told them I guarantee most
| people do not care at all, or people would be _far_ more
| upset than they currently are.
| Terretta wrote:
| And "But I _like_ ads that know what I want. Why would you
| want to see ads for things you _don 't_ want?" is hard to
| argue with until you realize there's no particular reason
| you have to see ads.
|
| The '90s web was fine without ads, in its "pamphleteering"
| days when people spent an amount of money proportionate to
| how badly they wanted to say something, and that was it.
|
| https://en.wikipedia.org/wiki/Pamphleteer
| jpsouth wrote:
| Does redact come with account deletion as well?
| gt2 wrote:
| Has anyone experienced a drop in recruiter spam when removing
| your information from databrokers with those services? I have
| daily unsolicited recruiter emails in the last few years, and
| I'm not on linkedIn since 2018-ish, so I have no idea where
| they are getting my info from.
| opteryology wrote:
| Absolutely agree with the importance of removing information
| from data brokers (aka People Search Sites), since they are be
| a goldmine for bad actors.
|
| Actually, Optery is a YC 2022 company and there are some good
| discussions on Optery and its competitors here on HN, ex:
| https://news.ycombinator.com/item?id=30605010
|
| For those evaluating data removal services, a solid first step
| is to sign up for each company's free scan and compare the
| results.
|
| Full disclosure: I am on the Optery team
| rodolphoarruda wrote:
| > "Delete cookies and site data when Firefox is closed".
|
| I have adopted this for almost a year now. Once I learned that it
| is possible to bypass Windows login, I thought that if the agent
| could get access to my browser with all cookies in, he could
| easily impersonate me in every possible corner of my digital
| life. So, no thanks. I live in a place where you can get your
| laptop stolen at any moment. So in my case, the perpetrator won't
| get much further as he won't have my password manager's master
| password. Local files are all inside a VeraCrypt volume so he
| won't have any luck finding them in readable form.
|
| This is the bare minimum of my threat model.
| therealmarv wrote:
| And loose everything you gained in this article by using a
| standard smartphone and some very common apps.
| vpaulus wrote:
| I am really looking forward when this becomes a base topic in the
| elementary schools (including tips how to use mobile apps). Right
| now it's self-evident that children learn using Chrome and Google
| rodolphoarruda wrote:
| I have worked in that front 5 years ago. Schoolsec, that was
| our name. Our target niche was elementary schools in southeast
| Brazil. It didn't work. Most of the schools we spoke to didn't
| even understand what we were talking about, so they couldn't
| assess the risk and, finally, realize the value of our work.
|
| Of course, as years pass, the need for more "digital self-
| defense" increases at all levels. Maybe one day we'll hear of
| someone who had pulled it off by presenting a great value prop
| for this kind of service.
___________________________________________________________________
(page generated 2023-09-19 23:01 UTC)