10 ms·
I Tried Hiding from Big Tech in a Pile of Privacy Gadgets
- oscilloscope 7y agoSince this was about devices and ad-blocking, I expected the Pi-hole to make an appearance. But alas, the author used Brave browser. https://github.com/pi-hole/pi-hole/blob/master/README.md https://github.com/pi-hole/pi-hole/blob/master/README.md
- colordrops 7y agoBrave works. Lots of propaganda on here against Brave for some reason. It's open source based on chromium with all the Google bits taken out, and it has built in ad blocking. So there's an opt-in crypto coin, so what.
- t-writescode 7y agoIf I could have one thing in Brave, aside from bug fixes, it’s this: rather than give me popup ads on my desktop, replace some of the static ads it blocks with Brave ones. They’re way less intrusive.
- johnpowell 7y agoThen I would have to look for a solution for the sites I run that completely block Brave. I don't care if people block ads. But I give a massive fuck if someone/thing swapped out my ads for theirs.
- colordrops 7y agoWait, what? I've never seen popup ads on my desktop from Brave. I'm on Mac and linux. Is this a Windows thing? Are you on Windows?
- daybreak 7y agoI frequently recommend Brave to non-technical people who would have problems installing browser extensions. Everything works out of the box without configuration.
- ac29 7y ago> Lots of propaganda on here against Brave for some reason. I think the same reason some people find Google's advertising-based business model problematic, they find Brave's advertising-based business model problematic.
- nesadi 7y agoI'd say these people are out of touch. If sites aren't funded by advertising, that means people need to pay to access. See all the efforts to workaround paywalls because nobody wants to pay every single site that they visit $5 a month, and plenty of people simply couldn't afford paying to access the internet in that way. That's enabled by advertising. But somehow nobody here wants to hear it. Advertising is incredibly important to enable open access to, well, the entire internet. We see with the Linux Journal how well subscription-only services work out - they live by the skin of their teeth for a while until they go under. But somehow we're better off because they didn't use advertising for funding? Now we don't have any LJ at all. I don't see how that's better. Not that I'm advocating for ads that track and profile you and everything that you do. We should be making an effort to create an infrastructure for ads where they can't track and profile us. That's what Brave is trying to do, and I don't understand why people are against it. Like, how do they expect sites to be financed?
- colordrops 7y agoWhat is braves advertising based business model? I've been using it since it came out and haven't seen a single brave ad.
- deleted 7y ago[deleted]
- fit2rule 7y ago> Lots of propaganda on here against Brave for some reason. Lots of people on HN make money with ad networks or are otherwise invested in the concept of harvesting user data. Same thing happens with GDPR.
- jammygit 7y agoAfter a brief skim of that README, I'm not 100% certain how Pi-hole works. Basically, it is a DNS server whose job is to lose requests to trackers, sort of like modifying the hosts file to fail to connect to facebook owned domains? And you use it by telling your router to use it as its DNS server, controlling it via a webpage it hosts on your private network?
- duncan-donuts 7y agoIt’s on a raspberry pi that is connected to your LAN. It is dns for the LAN and blocks any requests to hosts that are blacklisted
- frutiger 7y agoI presume it doesn’t need to be a Raspberry Pi, it could be any host in your LAN?
- thejosh 7y agoYes, it can run on any host in your lan.
- thaumasiotes 7y agoHow does this differ from the traditional hosts file that blocks requests to blacklisted hosts?
- WrtCdEvrydy 7y agoWorks for devices with hard to access hosts files (IoT garbage, smart TVs)
- brewdad 7y agoMy understanding is that it accomplishes the same thing but for every device on your network rather than having to manage host files on each device. It also works for those where editing the host file isn't possible.
- owenwil 7y agoNot only did he not mention PiHole (or the similar, but better, Adguard Home), he didn't seem to be aware that network adblocking is a thing—but who can blame him? It's not exactly trivial unless you're comfortable with a terminal. Is there any sort of commercialized solution for this? I'd love to see Adguard/Pihole devices available off the shelf; with a little marketing I think they could really appeal to a lot of people. (I looked around and the only 'built in' solution I could find for adblocking is in Eero WiFi's paid subscription, which blocks ads on their wifi router)
- ac29 7y agoAdguard can be used with any router: https://adguard.com/en/adguard-dns/overview.html#instruction https://adguard.com/en/adguard-dns/overview.html#instruction Its not built in per se, but its arguably less complicated than replacing a router (or worse, putting one router behind another, as would be required for the many people who's cable/fiber/etc modem is all in one with their router).
- close04 7y agoI think what GP means is that someone needs to set up the PiHole/Adguard software on their own hardware (like a RPi). After it's up and running it's pretty trivial to set it up in your router. Reading through Adguard's GitHub page I can't help not noticing some disingenuous feature comparison there. Like how PiHole doesn't support "Blocking phishing and malware domains" or "Parental control (blocking adult domains)". Although they both do it in the exact same way: blacklists [0]. Does it block YouTube ads? I'd like better reports and stats on PiHole, not just top sites, top clients, etc. Adguard seems to do better here from the screenshots. But I'll take it with a grain of salt. [0] https://imgur.com/Um7o4fU https://imgur.com/Um7o4fU
- ac29 7y agoYou don't need to setup adguard software or hardware at all to use it - you just change your existing router's DHCP setup to point to their DNS servers. Its pretty handy on Android (I think requires 9 or later), you can set dns.adguard.com as your "Private DNS" server and it will work system wide, with no Apps or VPNs to install, and on every network you connect to. I beleive it uses DNS over TLS as well.
- positive_future 7y agoWhile activities like this may result in the author being less visible to a particular algorithm, I imagine that the instant dropoff from most networks and instant arrival in new networks would be a very strong signal of who they are. The more bizarre tricks you try to stay hidden, the more identifiable you (probably) are.
- waterhouse 7y agoBut if you can get hundreds or thousands of people to use the same tricks as you, then you may be able to blend in with that group. It's like the scenarios that weren't explored in the https://xkcd.com/1105/ https://xkcd.com/1105/ strip: yeah, if it's just one guy with the 1lIl11l license plate, it might attract police attention, but if the guy collaborated with ten others who got similar license plates for similar-looking cars, then that could work to confuse and divert the police.
- deleted 7y ago[deleted]
- xvector 7y agoI really loved this article. The way it was written was just beautiful.
- mirimir 7y agoHuh? A "pile of privacy gadgets"? I do a pretty good job of hiding from everyone. And I don't use any "gadgets". Indeed, not using smartphones is a major boost to privacy. Otherwise, it's just multiple VMs, nested VPN chains, and Tor. All running on ~old i5 boxes that I bought used, for cash.
- speedplane 7y ago> I do a pretty good job of hiding from everyone. ... it's just multiple VMs, nested VPN chains, and Tor. This condescension is so common and petty. It's like a real-estate broker laughing at someone for overpaying for a property, or a lawyer laughing that someone missed a court deadline they didn't know about. Experts of complex systems generally know how to get what they want out of those systems. Finding ways for non-experts to do the same should not be sneered at.
- mirimir 7y agoInstalling VirtualBox and Whonix is pretty simple. And just one VPN in the host machine, just so your ISP and its friends don't see you using Tor. Arguably a lot simpler than TFA goes on about.
- LilBytes 7y agoIt's really, really not _that simple_. The majority wouldn't know what VirtualBox and Whonix is, and that's before we start discussing what the benefits of privacy even are. This is the disconnect we have with our peers who don't work in software/IT and why the right to privacy is being lost to jargon and technical expertise. Privacy now is only a right to those who know how to employ it.
- pferde 7y agoHasn't that always been the case throughout the history, though? Everyone always knew everything about everyone else in the village, or neighboring villages. Only the select few knew and cared enough to keep their affairs hidden. Except that now the technology has packed the entire world into a single "global village".
- Yizahi 7y agoIt is impossible to hide from big corporate. People tried (1). There is no was to block all tracking unless you go full luddite and unless every single person you know or simply met randomly does so too. Otherwise big corps would just create tracking profiles for you based on activity of others. Small recent example - remember that russian spying app FaceApp (iirk) which made aged pics out of your photos? Even if you avoided it there is rather high chance that your friends uploaded pictures of you instead. Or that phone caller ID app (which is a spyware inside too) - even if you never used it they still know your number probably because others filled it in for you. (1) https://gizmodo.com/c/goodbye-big-five https://gizmodo.com/c/goodbye-big-five
- mirimir 7y ago> Otherwise big corps would just create tracking profiles for you based on activity of others. Mirimir is totally trackable. And if you could (not likely) get data from Riseup and Keybase, you could find all his contacts. But even then, none of that is linked to me in meatspace. Nobody I know in meatspace knows about Mirimir. Hiding is not so hard if you just compartmentalize.
- pferde 7y agoSure, but that only works if you compartmentalize from the very beginning, which regular people never do.
- mirimir 7y agoNot at all. Only from the beginning of a particular persona. Mirimir is about eight years old.[0] But I had numerous personas before Mirimir. Some you could maybe track back to, if you worked at it, and knew where to look. But some are just too old, and unconnected. I was lots sloppier, when I started going dark, in the late 90s. I even talked about it in meatspace. But gradually, I compartmentalized more and more. Anyone can do that. Just gradually disappear as your meatspace identity. Or restrict it totally to career, and friends and family. Ideally, keeping those separate, so your friends don't hose your career. And then create and develop an ~anonymous persona.[1] Or a few of them, one for each ~defined set of interests. And just don't talk about it in meatspace. Or mix stuff among personas. 0) https://www.wilderssecurity.com/members/mirimir.121604/ https://www.wilderssecurity.com/members/mirimir.121604/ 1) https://www.ivpn.net/privacy-guides/online-privacy-through-opsec-and-compartmentalization-part-1 https://www.ivpn.net/privacy-guides/online-privacy-through-o...
- vanous 7y agoWhen using smart watches I have found Gadgetbridge [1] useful, to keep my smart band conveniently connected to a phone but not to send my data to Xiaomi. Gradully going fully F-droid [2] on my devices. [1] https://blog.freeyourgadget.org/ https://blog.freeyourgadget.org/ [2] https://f-droid.org/ https://f-droid.org/
- u35517 7y agoReCAPTCHA prevents me from accessing this site. Could someone please provide a summary?
- mxuribe 7y agoWhoa, i had never heard of Reflectacles[0]. Beyond apps, these are the kinds of physical gadgets that we need nowadays to help protect our privacy! Certainly, more growth in this area will evolve these products to be more...subdued and subtle. Nevertheless, I'm encouraged to see that this type of thing exists. Beyond rfid wallets, these glasses, and the clothing/jacket the author mentioned in the article, are there any other cool apparel-related gadgets out there, which a privacy-conscious person could look into (without spending the equivalent of a 3-letter agency budget)??? [0] = https://www.reflectacles.com https://www.reflectacles.com
- Circuits 7y agoI think I was freaked out for the first time just a few months ago. I realized they were keeping tabs on me but to what extent I wasn't sure. It wasn't until the videos my roommate watches on YouTube ended up on my suggested list that I realized the extent. YouTube is, in some way another, in cahoots with my ISP? Perhaps, they traced my IP and saw that it matched my roommates IP? I am not sure how but they did it somehow.
- swebs 7y agoFunny how they don't mention uMatrix. Or maybe the editor just removed that part seeing how this page loads 36 different scripts from 9 different domains and sets 16 cookies.
- inetknght 7y agoI wonder how well uMatrix stacks against Firefox's reader mode? You can prepend `about:reader?url=` to most URLs and they'll load fine, fast, and have very clean UI elements. It's a lot less of a hassle than using uMatrix.
- m463 7y agoreader mode loads everything. umatrix prevents loading of a lot of stuff. I have configured umatrix to only load first-party content (I can always add 3rd party content back in using the menu and save it). Also, umatrix can be used first, then you can use reader mode. Weirdly I notice reader sometimes bypasses some umatrix protections.
- inetknght 7y agoIf reader mode loads everything, does it also execute all of the javascript? That's ultimately what I want to avoid; I want effectively a static page with zero javascript.
- pixelbath 7y agoI found myself wondering, "but why?" more than once reading this. >I realized that Signal is located in Mountain View, Calif. So I downloaded Burner... So, Signal is compromised because it's physically near Google? Okay. >and went to Amazon.com A company you can't shop at without leaving a digital trail? Okay. >seeing the 7-Eleven location listed there along with almost everywhere else I’d been in the last seven years You didn't turn off location services before trying a Faraday bag? You're still using your Android smartphone? I guess I can give the author credit for looking around and trying, but most of the privacy benefits likely come from things like: using Signal (or similar end-to-end encryption), using privacy-focused email (or a private email server), not logging into social media, turning off location services, using a privacy-focused search engine like DuckDuckGo or StartPage, and blocking ads (and possibly JS if you're that bold). If it's still not enough for the non-technically-minded, then I'd suggest doing some more research into more advanced techniques like network adblocking, Tor, VPN, or virtual machines.
- 40four 7y agoMaybe you are taking the article to literally. I thought it was a great read & enjoyed the writing style. I took it to be very tounge in cheek. It was a good overview of a number of cool products I was unaware of, while also being very funny and entertaining. Pretty silly ending, he just went back to doing the same old stuff he used to do. Fun read!
- neilv 7y agoI've been working on this since the early Web sites (starting with publishing a popular blocker ruleset), and also ongoing exercises with all kinds of measures, including compartmentalizing with a dumbphone when all the smartphone options turned out to be travesties. One thing I've found is that it's already clearly impossible to do perfectly, and looks like it will be getting even more difficult and limited in what privacy one can have. (Obviously, were my own privacy the biggest concern, I wouldn't be talking online in places where creepy companies scrape. I mainly dabble in privacy exercises out of a vague sense of public-interest obligation as a techie.)
- methou 7y agoI'm tired of hiding from the big techs in a pile of privacy gadgets. How so? They fight back, with dark patterns. Ruleset works today may not work on the next; you can update the rules; they can make your update break things. I can see that on some major Chinese e-commerce sites, blocking tracking scripts may cause search function to stop working, or you cannot comment because the submit button failed to load. It's difficult to know, I use uMatrix, and often run into questions like what is this <cryptic.cloudfront.net> domain doing? Sometimes it's almost 'first-party'; sometimes it can be something else. Domain names are too broad because I don't see why a site owner can not add trackers under the domain, or some related domain names that were 'trusted'. There's an option to do this as those anti-virus software do, have a database of hashes of the scripts and css, and audit them. But you know rapid things are changing on the web, it is next to impossible to keep track of those. Eventually, we'll run out of passion and energy, just unplug it already.