1
112
submitted 1 year ago by jonah@lemmy.one to c/privacyguides@lemmy.one

TL;DR: Reddit is making their tracker-filled mobile app the only way to access Reddit on mobile devices, they are falsely accusing third-party developers of blackmail, and they are on a path to severely lower the quality of content posted on Reddit and increase the amount of spam you see. To stand against these changes, alongside numerous large subreddits, Privacy Guides is not currently available on Reddit. Join us on Lemmy at [!privacyguides@lemmy.one](/c/privacyguides@lemmy.one) :)


As we discussed and announced a week ago on Reddit, the Privacy Guides subreddit is being made private from June 12 to June 14th to call attention to Reddit's most recent anti-consumer behavior.

What is Reddit doing?

A few weeks ago, Reddit unveiled plans to change the pricing for their API from $0 to $12,000 for 50 million requests. For third-party clients like Apollo on iOS or Sync on Android, this suddenly put the cost to create such an app in the realm of $20,000,000 per year, a figure clearly unsustainable for third-party Reddit client developers. For comparison, Imgur—a website with a similar userbase and size to Reddit—charges developers approximately $166 for every 50 million requests. This change in Reddit's pricing to far beyond any reasonable market value was driven solely to eliminate third-party clients from the market, in order to force Reddit users to use the official app instead, a plan which was successful given that most major third-party Reddit clients have now announced they are shutting down by the end of this month.

Reddit's API changes also affect a number of bots which are critical for moderation. Reddit cutting off access to clients and bots which moderators require to effectively care for their communities will only result in Reddit being overtaken by spam and low-quality content.

Why does Privacy Guides care?

The internet is supposed to be an open standard, and information on the internet cannot be funneled solely through proprietary first-party clients. The difficulty I had in merely archiving the r/PrivacyGuides announcement post on the New Reddit design (note everything missing here on internet archive) clearly demonstrates the danger of locking information into closed ecosystems like Reddit, where merely accessing this information is subject to their whims.

Open APIs and third-party clients are paramount to enabling privacy-friendly access to otherwise proprietary silos on the web. Through the use of those APIs and clients, it was possible to interact with Reddit in an entirely user-controlled, privacy-friendly way. Reddit's restrictions take that choice away, making their official app virtually the only portal to the information on their platform available to mobile users.

While Reddit is certainly within their rights to make these changes, Reddit users are certainly within their rights to reject these changes and choose an alternative.

We—obviously—think that the r/PrivacyGuides community is hugely beneficial to the internet at large, and a lot of great discussions take place informing people about privacy and protecting their data online. All of this taking place on Reddit was a necessary price to pay in order to reach a ton of new people and get them interested in private, open-source technologies, but if Reddit is going to abuse that power and try to control those people into using privacy-invasive clients, the cost of that might outweigh any benefit to us remaining on the platform.

Reddit's Current Response (Unmitigated Disaster)

In the past week, Reddit has largely made two real announcements about this change:

Firstly, they announced that they would keep the API free to certain clients which provide accessibility features. It should go without saying that this is just another way of Reddit saying: Because we are unwilling to make our website and apps accessibility-friendly ourselves, we will very generously let third-party developers do it for us for free.

Their second response has been to falsely accuse a prominent developer of blackmail, and then double down on their false accusations when confronted with irrefutable proof of their behavior. Threatening and accusing people in private messages, and then acting like the victim when those people publish those messages to refute your claims is incredibly toxic and inappropriate behavior from anybody working on any project, much less the CEO of Reddit.com.

In my view, this childish behavior from Reddit moves this situation far past the typical money-grabbing moves you should expect from Big Tech corporations and into legitimate concerns about integrity and stability at Reddit. If their leadership is going to devolve into Twitter-esque, dictatorship-fueled decision making, the entire platform can no longer be trusted as a source of knowledge at all.

What happens on June 15th?

I don't know what Reddit's response to this widespread protest will be. In any event, the Subreddit will re-open, but if Reddit's response is to do nothing, then r/PrivacyGuides will re-open in restricted, mod-only posting mode. Then we will have a community discussion about our next steps.

Reddit choosing to do nothing is—in my opinion—an untenable solution. While we will re-open r/PrivacyGuides in order to allow people to access the vast community knowledge that is already there (while you still can), it is entirely possible that the subreddit will remain restricted indefinitely. It is hard to imagine a reason why we should encourage our incredibly helpful and generous community to continue to provide valuable content to Reddit for free, only for Reddit to go down this privacy-invasive, ad-first path.

What's Next?

In any case, I would strongly encourage you to stop using Reddit going forward. The fiascos at Twitter and now Reddit clearly demonstrate that centralized big tech companies can no longer be trusted with being the gatekeepers to user-generated information (as if they ever could, hah!).

I think that smaller, federated communities like Lemmy/Kbin/Mastodon are the future of knowledge-sharing on the internet, and the new Privacy Guides community on the fediverse can be joined from any ActivityPub enabled instance, such as:

All of these are links to the same community, just pick whichever site you already have an account on.

Privacy Guides additionally hosts a Discourse forum at discuss.privacyguides.net where we have discussions about and analyze various privacy tools.

2
175
submitted 19 hours ago by neme@lemm.ee to c/privacyguides@lemmy.one
3
89

After all, the privacy of our mind may be the only privacy we have left.

4
178
5
147

The EU Council has now passed a 4th term without passing its controversial message-scanning proposal. The just-concluded Belgian Presidency failed to broker a deal that would push forward this regulation, which has now been debated in the EU for more than two years.

For all those who have reached out to sign the “Don’t Scan Me” petition, thank you—your voice is being heard. News reports indicate the sponsors of this flawed proposal withdrew it because they couldn’t get a majority of member states to support it.

Now, it’s time to stop attempting to compromise encryption in the name of public safety. EFF has opposed this legislation from the start. Today, we’ve published a statement, along with EU civil society groups, explaining why this flawed proposal should be withdrawn.

The scanning proposal would create “detection orders” that allow for messages, files, and photos from hundreds of millions of users around the world to be compared to government databases of child abuse images. At some points during the debate, EU officials even suggested using AI to scan text conversations and predict who would engage in child abuse. That’s one of the reasons why some opponents have labeled the proposal “chat control.”

There’s scant public support for government file-scanning systems that break encryption. Nor is there support in EU law. People who need secure communications the most—lawyers, journalists, human rights workers, political dissidents, and oppressed minorities—will be the most affected by such invasive systems. Another group harmed would be those whom the EU’s proposal claims to be helping—abused and at-risk children, who need to securely communicate with trusted adults in order to seek help.

The right to have a private conversation, online or offline, is a bedrock human rights principle. When surveillance is used as an investigation technique, it must be targeted and coupled with strong judicial oversight. In the coming EU council presidency, which will be led by Hungary, leaders should drop this flawed message-scanning proposal and focus on law enforcement strategies that respect peoples’ privacy and security.

Further reading:

6
83
7
213

We’ve said it before: online age verification is incompatible with privacy. Companies responsible for storing or processing sensitive documents like drivers’ licenses are likely to encounter data breaches, potentially exposing not only personal data like users’ government-issued ID, but also information about the sites that they visit.

This threat is not hypothetical. This morning, 404 Media reported that a major identity verification company, AU10TIX, left login credentials exposed online for more than a year, allowing access to this very sensitive user data.

A researcher gained access to the company’s logging platform, “which in turn contained links to data related to specific people who had uploaded their identity documents,” including “the person’s name, date of birth, nationality, identification number, and the type of document uploaded such as a drivers’ license,” as well as images of those identity documents. Platforms reportedly using AU10TIX for identity verification include TikTok and X, formerly Twitter.

Lawmakers pushing forward with dangerous age verifications laws should stop and consider this report. Proposals like the federal Kids Online Safety Act and California’s Assembly Bill 3080 are moving further toward passage, with lawmakers in the House scheduled to vote in a key committee on KOSA this week, and California's Senate Judiciary committee set to discuss AB 3080 next week. Several other laws requiring age verification for accessing “adult” content and social media content have already passed in states across the country. EFF and others are challenging some of these laws in court.

In the final analysis, age verification systems are surveillance systems. Mandating them forces websites to require visitors to submit information such as government-issued identification to companies like AU10TIX. Hacks and data breaches of this sensitive information are not a hypothetical concern; it is simply a matter of when the data will be exposed, as this breach shows.

Data breaches can lead to any number of dangers for users: phishing, blackmail, or identity theft, in addition to the loss of anonymity and privacy. Requiring users to upload government documents—some of the most sensitive user data—will hurt all users.

According to the news report, so far the exposure of user data in the AU10TIX case did not lead to exposure beyond what the researcher showed was possible. If age verification requirements are passed into law, users will likely find themselves forced to share their private information across networks of third-party companies if they want to continue accessing and sharing online content. Within a year, it wouldn’t be strange to have uploaded your ID to a half-dozen different platforms.

No matter how vigilant you are, you cannot control what other companies do with your data. If age verification requirements become law, you’ll have to be lucky every time you are forced to share your private information. Hackers will just have to be lucky once.

8
141
9
22

cross-posted from: https://discuss.tchncs.de/post/18038249

Are thwre guides, tutorials or similar on how to use Steam more privately?

I'm at a point where I'd like to play certain games, but I dislike that they're exclusively available on consoles and Steam for Desktop. Steam's Privacy Policy and Terms of Service raise concerns about my personal security and privacy. I'm looking for advice on how to improve my privacy while using Steam.

Thank you in advance!

(I will use Steam on Linux)

10
118
11
93
12
15
13
15

If you want to join the group, please send me a PM with the reason you want to and your favourite animal.

14
294
15
87
submitted 2 weeks ago* (last edited 2 weeks ago) by DreitonLullaby@lemmy.ml to c/privacyguides@lemmy.one

Does anyone know about the legality of removing the built-in sim cards from your car, specifically in Australia?

I don't intend on using any car smart-features when I get one. For context, I've never owned a car. When I do get one though, I intend to remove the sim card to prevent the car's location from being constantly tracked. All I care about in terms a cars functionality is a radio, a CD drive (Yes, I use CD's), and Bluetooth audio, so I don't think removing the sim card should affect this much, if at all. Any knowledge and advice would be appreciated, thankyou!

Update: What I was referring to is an eSim, which appears not to be in the form of a physical card. Even so, if possible, I would like to disable the functionality of this eSim assuming the car I purchase has one in-built. From my research, I cannot find anything that explicitly forbids disabling or removing Sims.

16
194
17
27
submitted 3 weeks ago* (last edited 3 weeks ago) by chemicalwonka@discuss.tchncs.de to c/privacyguides@lemmy.one

Hi guys!

Today I use Mullvad VPN on my Pixel 8 but unfortunately Mullvad team didn't enable multihop feature to use on Android app.

Use WireGuard official app and importing wireguard key file is a good approach to have multihop feature enable on Android?

18
135

iOS apps that build their own social networks on the back of users’ address books may soon become a thing of the past. In iOS 18, Apple is cracking down on the social apps that ask users’ permission to access their contacts — something social apps often do to connect users with their friends or make suggestions for who to follow. Now, Apple is adding a new two-step permissions pop-up screen that will first ask users to allow or deny access to their contacts, as before, and then, if the user allows access, will allow them to choose which contacts they want to share, if not all.

For those interested in security and privacy, the addition is welcome. As security firm Mysk wrote on X, the change would be “sad news for data harvesting apps…” Others pointed out that this would hopefully prevent apps that ask repeatedly for address book access even after they had been denied. Now users could grant them access but limit which contacts they could actually ingest.

19
99
20
30
submitted 3 weeks ago by land@lemmy.ml to c/privacyguides@lemmy.one
21
26

Hello let's say you are absolutely forced to join zoom in the future, is there any way at all to have any security, such as an alternate client that can connect? I expect the answer is no besides only connecting in a browser with add ons or in a sandbox etc etc and nothing truly groundbreaking.

22
25
23
24
submitted 4 weeks ago* (last edited 4 weeks ago) by hellfire103@lemmy.ca to c/privacyguides@lemmy.one

cross-posted from: https://lemmy.ca/post/22775470

I'm looking to buy a router for home use, on which I plan to install OpenWRT. After some research, I have come across the TP-LINK Archer AX23, which checks all of the boxes I have:

  • [x] Comparatively low price

  • [x] Supports WPA3

  • [x] Supported by OpenWRT

  • [x] Has at least three LAN ports

However, before I and my dad go and buy one, it has to pass the final test: the forums.

Has anyone used this router before? What was your experience? Can I do better, or have I found the best router ever made? Please share your thoughts.

24
46
submitted 4 weeks ago by otter@lemmy.ca to c/privacyguides@lemmy.one

I'm asking for Android specifically, but I'm curious what else is out there.

For example, some apps work without internet but may use it if it's available. I might want to block that without having to turn off wifi, force stopping it, and wiping the cache/data.

Similarly, maybe I only want to use the app over a VPN and want to prevent accidentally opening it without first turning the VPN on.

25
98

I have thought about this on and off for quite a few years now, and I was just wondering what people here have done while maintaining account / device security.

I hope people don't mind this rather morbid conversation, but how have people here planned for what will happen with their accounts, computers, self hosted things etc. in the event of their deaths? I am particularly interested in what people have planned for if they are the person in their household who is self hosting things for the household. I'm not in a living situation that allows me to self host much but it is one of the questions I've had for myself when I decide to move in with my significant other and self host more things. I don't think they could manage much of the self hosted stuff and I also don't think they can remember all of the credentials for accounts etc., is the best way of going about it sharing a keepass database or bitwarden account with them?

In regards to my accounts, I am not expecting most of my accounts to transfer, if anything I'd much rather them be deleted (and I have enabled this feature where possible). There are a few however, that I wouldn't mind leaving to someone after my passing. Is there a privacy and security preserving way of setting this up?

I guess I have just been struggling with how to do this, ideally I would want a way for accounts to transfer to someone listed in my will, but I don't think it's a good idea to give ~2-3 people a copy of my keepass databse while I am still living.

I am looking forward to hearing what people's thoughts are on this matter, and I apologize again for such a morbid topic.

view more: next ›

Privacy Guides

16113 readers
351 users here now

In the digital age, protecting your personal information might seem like an impossible task. We’re here to help.

This is a community for sharing news about privacy, posting information about cool privacy tools and services, and getting advice about your privacy journey.


You can subscribe to this community from any Kbin or Lemmy instance:

Learn more...


Check out our website at privacyguides.org before asking your questions here. We've tried answering the common questions and recommendations there!

Want to get involved? The website is open-source on GitHub, and your help would be appreciated!


This community is the "official" Privacy Guides community on Lemmy, which can be verified here. Other "Privacy Guides" communities on other Lemmy servers are not moderated by this team or associated with the website.


Moderation Rules:

  1. We prefer posting about open-source software whenever possible.
  2. This is not the place for self-promotion if you are not listed on privacyguides.org. If you want to be listed, make a suggestion on our forum first.
  3. No soliciting engagement: Don't ask for upvotes, follows, etc.
  4. Surveys, Fundraising, and Petitions must be pre-approved by the mod team.
  5. Be civil, no violence, hate speech. Assume people here are posting in good faith.
  6. Don't repost topics which have already been covered here.
  7. News posts must be related to privacy and security, and your post title must match the article headline exactly. Do not editorialize titles, you can post your opinions in the post body or a comment.
  8. Memes/images/video posts that could be summarized as text explanations should not be posted. Infographics and conference talks from reputable sources are acceptable.
  9. No help vampires: This is not a tech support subreddit, don't abuse our community's willingness to help. Questions related to privacy, security or privacy/security related software and their configurations are acceptable.
  10. No misinformation: Extraordinary claims must be matched with evidence.
  11. Do not post about VPNs or cryptocurrencies which are not listed on privacyguides.org. See Rule 2 for info on adding new recommendations to the website.
  12. General guides or software lists are not permitted. Original sources and research about specific topics are allowed as long as they are high quality and factual. We are not providing a platform for poorly-vetted, out-of-date or conflicting recommendations.

Additional Resources:

founded 1 year ago
MODERATORS