6 ms·
The problem with lists like this is they really are just a "here's 100 open source products", without any criteria or individual evaluation. It is often just pa
by dngray 4y ago
The problem with lists like this is they really are just a "here's 100 open source products", without any criteria or individual evaluation. It is often just parrots repeating what other parrots say.
Something which is clearly alpha-state isn't usable to regular users shouldn't have a "recommendation". Then you get sub optimal recommendations, listing some projects which are unmaintained etc.
With the cleanup at https://privacyguides.org https://privacyguides.org, (since we split from PTIO) we've removed a lot of things, and gone down the part of actually providing guidance rather than "use this software to make you magically more private".
I think it's important to think privately, modify behavior rather than rely on technology to do it all for you.
Looking at this particular list there are some bad choices:
- LessPass: We explicitly removed deterministic password managers https://github.com/privacyguides/privacyguides.org/pull/323 https://github.com/privacyguides/privacyguides.org/pull/323, https://tonyarcieri.com/4-fatal-flaws-in-deterministic-password-managers https://tonyarcieri.com/4-fatal-flaws-in-deterministic-passw...
- AndOTP: Uses PBKDF2 and a heap of rounds that is unbelievably slow when you have a number of OTPs. Aegis uses Argon, which doesn't have this problem, and we think it's code is developed by someone who is security conscientious.
- Qwant: https://github.com/privacyguides/privacyguides.org/pull/342#issue-1057922379 https://github.com/privacyguides/privacyguides.org/pull/342#..., we removed due to "due to bad privacy policies data is collected and shared with third parties"
- Silence: Unmaintained, uses SS7 network, should never be recommended.
- Off-The-Record: Doesn't cover group chats or other side channels, such as status updates, VOIP. In general XMPP isn't particularly "privacy friendly" https://web.archive.org/web/20211215132539/https://infosec-handbook.eu/articles/xmpp-aitm/ https://web.archive.org/web/20211215132539/https://infosec-h...
- PGP: NO. It has no forward secrecy, it's a terrible way to encrypt real time communication.
- Matrix + Riot client: Seriously, it's been "Element" for ages now, makes me think the author really isn't up to date with current events.
- Ricochet: Unmaintained, (2016) domain dead, Only supported .onion HSv2
- Tox + qTox: Developed wrong. They developed the software then decided to write the spec afterwards. There's also https://github.com/TokTok/c-toxcore/issues/426 https://github.com/TokTok/c-toxcore/issues/426
- Mailfence: Last email I sent to them they don't use any kind of disk encryption
- CriptText, these things really don't help, they are walled, in that everyone has to be on a centralized service to get the benefit. E2EE that comes with web-apps can often be dangerous as it can change, have vulnerabilities introduced after an audit etc.
- TorBirdy: Unmaintained
- Mumble: Not really private
- Linphone: Not really private
- Rocket Chat: Experimental E2EE
- Browser Extensions: NO JUST NO. https://blog.privacyguides.org/2021/12/01/firefox-privacy-2021-update/ https://blog.privacyguides.org/2021/12/01/firefox-privacy-20...
https://github.com/arkenfox/user.js/wiki/4.1-Extensions https://github.com/arkenfox/user.js/wiki/4.1-Extensions
- Video Platforms: These are not private
- RSS Clients: There are better options
- Mobile Operating Systems: Options without Verified Boot. NO. https://source.android.com/security/verifiedboot https://source.android.com/security/verifiedboot
- Linux recommendations: Those are also awful and don't have any threat model in mind.
I'm going to stop now, it's basically every bad thing that was ever on PTIO, that we removed. Basically there are terrible recommendations with a few good ones sprinkled in.
This list is *not* maintained!
- deif 4y agoWhy don't you submit a PR with a more up to date list? Or fork it? Lists don't get solved magically and a single person cannot keep up with all projects although your Privacy Guide seems to do a good job.
- dngray 4y agoIf I submitted PRs re-writing every privacy list/gist on Github. yeah you know where I'm going with that I'm sure. Privacy Guides, is a community project, we accept community contributions, which are then verified before being merged with the main repository. We are now looking at translation of our content https://github.com/privacyguides/privacyguides.org/discussions/30 https://github.com/privacyguides/privacyguides.org/discussio... which is exciting because we feel there really many resources in languages other than English.
- doix 4y ago> - Mumble: Not really private Could you elaborate? My friends and I self-host mumble. I never really thought about it, but I kind of just assumed that this is as private as it gets. I didn't read through the mumble source code, but I just assumed it wouldn't be sending data anywhere else. Edit: Their privacy page describes what data is sent where/when and it reads very privacy friendly to me: https://www.mumble.info/privacy/ https://www.mumble.info/privacy/
- _Algernon_ 4y agoAccording to the PR[1] it is because it doesn't use end-to-end encryption. [1]: https://github.com/privacyguides/privacyguides.org/pull/192 https://github.com/privacyguides/privacyguides.org/pull/192
- doix 4y agoHmm, I guess that matters if you are using public servers. If you are running your own server, then it is a non-issue. I still think self hosted mumble is a great solution to the problem. Looking through the privacyguides recommendations[0], I don't see a good alternative. [0] https://www.privacyguides.org/real-time-communication/ https://www.privacyguides.org/real-time-communication/