#privacy

anonymiss@despora.de

Why is #Mozilla collecting our #search data?

source: https://blog.mozilla.org/en/products/firefox/firefox-search-update/

Sensitive topics, like searching for particular health care services, are categorized only under broad terms like health or society. Your search activities are handled with the same level of confidentiality as all other data regardless of any local laws surrounding certain health services.

Hello Mozilla, I use Firefox because my privacy is important to me. The best security is still achieved if you don't collect the data. That is why I will use a fork that does not collect search data. It would be nice if Mozilla took user privacy more seriously.

#privacy #news #browser #web #internet #firefox #security #cybersecurity #surveillance #statistics #bigdata #bigbrother

prplcdclnw@diasp.eu

TunnelVision: Decloaking Routing-Based VPNs

CVE-2024-3661

If you want to be safe, don't get DHCP service from anything but your own router. Don't connect to public WiFi anywhere. If you need to use a local network you don't control, connect your router to it and connect your device to your router so you get DHCP service from your router, not someone else's. It's also important that only your devices be allowed to connect to your router.

https://github.com/leviathansecurity/TunnelVision

TunnelVision is a local network VPN leaking technique that allows an attacker to read, drop, and sometimes modify VPN traffic from a targets (sic) on the local network. This technique does not activate kill-switches and does not have a full fix for every major operating system. We are using the built-in and widely supported feature DHCP option 121 to do this.\
\
Option 121 supports installing multiple routes with CIDR ranges. By installing multiple /1 routes an attacker can leak all traffic of a targeted user, or an attacker might choose to leak only certain IP addresses for stealth reasons. We're calling this effect decloaking.\
\
TunnelVision has been theoretically exploitable since 2002, but has gone publicly unnoticed as far as we can tell. For this reason, we are publishing broadly to make the privacy and security industry aware of this capability. In addition, the mitigation we've observed from VPN providers renders a VPN pointless in public settings and challenges VPN providers' assurances that a VPN is able to secure a user's traffic on untrusted networks.\
\
A fix is available on Linux when configuring the VPN users host to utilize network namespaces. However, we did not encounter its use outside of our own research. The best documentation we've found about that fix is available from WireGuard's team. It remains unclear, at the time of publishing, whether this fix or a similar fix is also possible on other operating systems such as Windows and MacOS due to neither appearing to have support for network namespaces.

#security #safety #privacy #surveillance #spying #vpn #vpns #virtual-private-network #virtual-private-networks #tunnelvision

danie10@squeet.me

4 Tools to Share Large Files Over the Internet Securely

Tux penguin in foreground with a representation of a file manager icon behind it.
These are privacy respecting tools to consider. But what signifies as a big file? Any file that you cannot seem to send through an encrypted messaging app like Signal or Telegram’s secret chat. Ideally, it should be anything more than 1 GB.

Internxt is probably the most convenient being online, whilst an option like OninionShare is fully peer-to-peer but then does require the app to be installed at both ends (but is available for all generally used platforms).

See itsfoss.com/share-large-files-…
#Blog, #filesharing, #opensource, #privacy, #technology

psych@diasp.org

Hm... On "euthanizing G-Mail" (&/or Google et al)

Opinion | Happy 20th Anniversary, Gmail. I’m Sorry I’m Leaving You. (Ezra Klein)

When Google unveiled Gmail 20 years ago, everyone wanted in — but you needed an invite, our Opinion columnist Ezra Klein writes. He remembers the thrill of finding one: “I felt lucky. I felt chosen.”

"There is no end of theories for why the internet feels so crummy these days. The New Yorker blames the shift to algorithmic feeds. Wired blames a cycle in which companies cease serving their users and begin monetizing them. The M.I.T. Technology Review blames ad-based business models. The Verge blames search engines. I agree with all these arguments. But here’s another: Our digital lives have become one shame closet after another."

#GMail #Google #privacy #algorithms #DataScraping #monetizing #GoogleIs#vil #technology

berternste2@diasp.nl

EU-Raad onder vuur wegens controversiële en privacyschendende anti-kinderpornowet

De Volkskrant

Dat kinderen beschermd moeten worden op het internet, staat buiten kijf voor de EU. Desondanks stuit een wetsvoorstel van de Raad van de Europese Unie op felle kritiek, omdat hiermee surveillance-software geïnstalleerd kan worden op de telefoons van alle Europeanen.

(Tekst loopt door onder de foto.)

Foto van antikinderporno-poster
Een overheidscampagne om aandacht te vragen voor de (online) verspreiding van kinderporno. Beeld Harold Versteeg/ ANP.

In 2023 stuurden de wetenschappers al een open brief met kritiek over het voorstel naar de Raad, maar deze heeft hun waarschuwingen over surveillance en privacyschendingen op grote schaal niet ter harte genomen, schrijven meer dan 250 ondertekenaars donderdag in een tweede brief. Nog altijd wil de Raad AI-toepassingen installeren op de telefoons van Europeanen om te detecteren of iemand bijvoorbeeld op WhatsApp ongepast contact legt met minderjarigen of schadelijk materiaal deelt.

Deze technologie, client-side scanning geheten, doet een inbreuk op de privacy en kan onschuldige EU-burgers onterecht bestempelen als crimineel, vinden wetenschappers, het Meldpunt Kinderporno en de Tweede Kamer. Daar is het Europees Parlement het mee eens, waarna het een tegenvoorstel opstelde, dat gericht is op het voorkomen in plaats van het detecteren van kindermisbruik. (...)

Hele artikel

> Zie ook: Yesilgöz, koningin van de onderbuik Citaat:
“Het belangrijkste bezwaar van een hele reeks is echter dat er geen enkele garantie is dat client-side scanning alleen gebruikt zal worden voor de detectie van kinderporno. Niet voor niets nam de Tweede Kamer een motie aan die het kabinet opriep om tegen alle client-side scanning voorstellen van de Europese Commissie te stemmen. Maar Yesilgöz, koningin van de onderbuik, vertrouwt meer op haar gevoel dan op de experts, en legde de motie naast zich neer.”

Tags: #nederlands #nederland #kinderporno #client_side_scanning #censuur #privacy #kinderporno #europese_commissie #eu #europese_unie #vvd #tweede_kamer #massasurveillance

caos@anonsys.net

📲 "Datensparsames Android mit der Android Debug Bridge" & "Google-Apps und weitere Bloatware loswerden mit dem 'Universal Android Debloater Next Generation'"

Für diejenigen, die Android-Geräte betreiben, bei denen sie kein Custom ROM installieren können (oder wollen), hier zwei gnulinux.ch-Artikel, in denen es darum geht, wie auch ein Stock-Android ohne Root weitgehend datensparsam betrieben werden kann und wie Google-Apps und weitere Bloatware entfernt werden können:

Im ersten Teil der Artikelreihe "Datensparsames Android mit der Android Debug Bridge" beschreibt Matthias "den Versuch, unter Android durch Umbau mittels der Android Debug Bridge (ADB), ohne Root soweit wie möglich an das Datenschutzniveau besserer Android Custom ROMs heranzukommen. Es ist der erste Teil einer voraussichtlich dreiteiligen Serie. Im ersten Teil wird der Ansatz für ein aktuelles Samsung Android (Stock-ROM) mit Android 14 demonstriert." und zeigt "wie mit Hilfe der Android Debug Bridge (ADB) und weniger Apps zur Geräteadministration auch ein vorinstalliertes Stock-ROM mehr oder weniger datenschutzfreundlich umgebaut werden kann".

Google-Dienste sind in Shelter eingefrostet

Ergänzend dazu habe ich im Artikel "Google-Apps und weitere Bloatware loswerden mit dem Universal Android Debloater Next Generation" noch eins der Tools vorgestellt, mit dessen Hilfe Funktionen der "Android Debug Bridge" über ein grafisches Frontend genutzt werden. So können auf relativ einfachem Weg auf vergoogelten Androids Google-Apps und weitere Bloatware wie Hersteller- und Werbeapps entfernt werden.

Oberfläche des Universal Android Debloaters

#Android #Google #Datenschutz #Privacy #Samsung #ADB #Bloatware #UniversalAndroidDebloater #FDroid #CustomROM #RethinkDNS #Shelter

@Datenschutz - Privacy - Digitale Selbstverteidigung

faab64@diasp.org

This is cool update from "The Signal" app.

I didn't like sharing my telefon nummer with people, but now I can share faab.64 so people can contact me without giving them my phone number.

#SignalApp #Privacy

berternste2@diasp.nl

The US isn’t just reauthorizing its surveillance laws – it’s vastly expanding them

The Guardian

A little-known amendment to the reauthorized version of Fisa would enlarge the government’s surveillance powers to a drastic, draconian degree.

(Text continues underneath the photo.)

Photo of Capitol

The US House of Representatives agreed to reauthorize a controversial spying law known as Section 702 of the Foreign Intelligence Surveillance Act last Friday without any meaningful reforms, dashing hopes that Congress might finally put a stop to intelligence agencies’ warrantless surveillance of Americans’ emails, text messages and phone calls.

The vote not only reauthorized the act, though; it also vastly expanded the surveillance law enforcement can conduct. In a move that Senator Ron Wyden condemned as “terrifying”, the House also doubled down on a surveillance authority that has been used against American protesters, journalists and political donors in a chilling assault on free speech. (...)

Complete article

Tags: #surveillance #mass_surveillance #nsa #fisa #government_surveillance #spying_law #Foreign_Intelligence_Surveillance_Act #privacy #human_rights