8 ms·
I have something to hide
- geekamongus 11y agoNeat site. I like the presentation of talking points. My question, though, is how does this differ from other similar sites such as privacytools.io? How do I reconcile the privacy tools listed there with the ones listed here? Most of them are different. Ultimately, whose recommendations should I trust?
- at-fates-hands 11y agoFor me, I only saw a few things I wasn't aware of. The site itself seems to be more general knowledge about how to keep your info from being scooped up. Just using some of the tools will thwart most 3rd parties and a significant chunk of government techniques to spy on you. I would trust their recommendations since you see the same applications popping up repeatedly like Tails, Tor, Linux, Diaspora, etc. These are are well known tools in the hacking community and have been used and tested for years.
- pierreozoux 11y agoThanks! And thanks for privacytools.io, I wasn't aware of! We want to spread the word that people should protect themself. Once we manage to convince, people are like "Ok, but what now?" You'll probably answer: "Well, you have to quit facebook, start using linux and have your server at home". And the person will be overwhlmed and just say "it's too complicated." We try to offer a gamified way: "Here is the first step, and it will take you 5mins of your time!" Then people feel they are on the way to get better at protecting their privacy. And if you feel we don't recommend the right one, please get in touch, we'd love to collaborate to make it better!
- juanito 11y agoI really appreciate the resources provided. But I'm not a fan of the website suggesting that I want/need privacy because I have something to hide.
- 01Michael10 11y agoWell, we all have something to hide.
- mhurron 11y agoExactly. The phrase 'something to hide' has become synonymous with 'something illegal' or 'you're doing something wrong', when in reality everyone has things they simply wish to keep private.
- JoeAltmaier 11y ago'I have something to keep private' isn't as punchy. Also it doesn't go far enough. 'My entire life is private' is closer. Of course my public interactions aren't AS private; but still largely private (its nobody's business what laundry detergent I buy at the public supermarket).
- mhurron 11y agoI wasn't talking about the title of the article, but in general. Those in support of these surveillance programs have worked hard to conflate 'something to hide' with 'something illegal' so that most people will go along with them as they have 'nothing illegal to hide.'
- JoeAltmaier 11y agoAgreed. Its the doublespeak used by those trying to make ubiquitous surveillance commonplace.
- egwynn 11y agoThird parties are happy to extract value from data you share. Even if you’re not doing anything wrong, controlling that information has an impact. The way I see it, saying “I have something to hide” is, WLOG, the same as saying “I want to control what gets shared with whom.” EDIT: If the site author is reading this, tip #6 misspells ‘diaspora’ as ‘dispoara’.
- skimmas 11y agoI've been lurking around watching this project grow but never actually went to a meeting. So I'm kind of a spy. :P Nice work. Congratulations.
- pierreozoux 11y agoThanks :)
- userisuser 11y agoI commend you for compiling all of the resources. I would like to point out that your choice of Ubuntu linux is deficient. If one was concerned about privacy the choices that come to mind are tails/whonix. Debian and OpenBSD both respect privacy
- egwynn 11y agoI agree. But he does recommend tails in the TL;DR at the top.
- pierreozoux 11y agoWe try to target broad audience, and indeed ubuntu is easier to use than Debian for a windows user. There is the TL;DR on top. The idea here is if you need privacy right now, use Tails. And then for yor day to day life, here are the steps.
- danieldk 11y agoBut Ubuntu sends all queries typed in Unity to Amazon by default. Canonical says that the queries are anonimized, but no one can check what data is actually leaked. Otherwise thanks for the great site!
- Koahku 11y agoI think that adding a few other user-friendly distributions such as Fedora or Mint in the "Install Linux" step might be a good idea. Also, I haven't really followed the developments on this story but Ubuntu did effectively spy on you at some point by sending your searches to Amazon, considering this it is a pretty bad choice to recommend it in my opinion.
- Dirlewanger 11y agoHas uBlock reached "just werks" status (not referring to ease of installation)? It was still really unwieldy in terms of what it blocked/didn't block last time I tried it out when there was a thread on it. First time I'm hearing about Disconnect. Is it really all it's hacked up to be? On first glance to me, they have a pretty package but I feel like in practice they are just as furtive as Ghostery is with the promise of blocking all the bad shit. Nice site too btw. Great presentation for those looking to make a change with their habits.
- noir_lord 11y agoHas for me, it all just works.
- pierreozoux 11y agoI'm using both daily, and I'm really happy!
- aesthetics1 11y agouBlock is constantly blocking things that I actually would like to see. Wasn't able to download msu packages from Microsoft's website without turning it off as recently as last week. It seems to hog less resources than AdBlock/etc, but I still find it breaking a lot of things. Maybe I need to tweak the settings, but with that in mind, I don't consider it to be "just working!"
- dkns 11y ago"A website that wants you to understand that you're being tracked everywhere on the internet" Oh great! piwik script in source code Oh great! That really helps to drive the message.
- pierreozoux 11y agoI was lazy to right a script to parse my server logs! But common, we are not using GoogleAnalytics :)
- chinathrow 11y agoIf you preach against tracking, the first rule is: do not track. do not store logs at all.
- jackreichert 11y agoThere is a huge difference between anonymous visitor statistics to measure various metrics of performance, and tracking unique digital footprints.
- qbrass 11y agoUnless you're trying to demonstrate why. It doesn't seem to be the case here, but you could probably get the point across better if you simply showed people how much information you could gather about them.
- bostik 11y agoNot to mention the website wanted to drop a cookie too. I block cookies by default, and only allow manually selected sites to set them. Even then, the default for allowed is only until end of browser session. So unless the cookie was something like "irony=true", it should not have been there. (I didn't bother to look what value it tried to set.)
- pierreozoux 11y agoIPs are annon, and I respect DoNotTrack from browsers. I think it is quiete fair!
- TeMPOraL 11y agoYou are being watched. The government has a secret system: a machine that spies on you every hour of every day.
- lorenzhs 11y agoThis week's episode was pretty cool from the viewpoint of someone who works on communication efficient distributed computing. The story (for lack of a better non-totally-spoiling word) seems to be ahead of the research community there ;)
- rizumu 11y agoA primary goal here appears to be one of convincing people to use open and secure tools, but if you are already convinced of that, a far more comprehensive list is PRISM-break https://prism-break.org https://prism-break.org
- pierreozoux 11y agoYes this is true, there is also: https://www.privacytools.io/ https://www.privacytools.io/
- rayalez 11y agoWebsite is broken on my mobile browser. http://imgur.com/dILU51x http://imgur.com/dILU51x
- pierreozoux 11y agoyes, there is an issue open here: https://github.com/LisbonInternetFreedom/ihavesomethingtohi.de/issues/18 https://github.com/LisbonInternetFreedom/ihavesomethingtohi....
- rpcope1 11y agoSpeaking of which, did anyone else notice that the Initializr default favicon is still present? The owner might be wise to find his own (and to make it look less Initializr-y). :)
- pierreozoux 11y agoThanks, it is being addressed here: https://github.com/LisbonInternetFreedom/ihavesomethingtohi.de/issues/30 https://github.com/LisbonInternetFreedom/ihavesomethingtohi....
- mrek0 11y agostupid guide, does recommend TOR for everyone without further information.
- thejrk 11y agoI'm curious why the desktop OS matters and why they suggest using linux to thwart NSA surveillance.
- pierreozoux 11y agoFree software is the way to go :) If your software is not free, you have no guarantee of what's happening there.
- RodgerTheGreat 11y agoIf you don't actually audit the hundreds of thousands or millions of lines of code comprising an open source application stack you don't have a guarantee of what's happening either. Bugs like Heartbleed demonstrate that massive vulnerabilities can be introduced and persist in well-regarded open-source codebases for long periods of time without detection in spite of theoretical "millions of eyes". Heartbleed was, to the best of our understanding, the result of an honest mistake. What's to say that any significant OSS codebase with thousands of committers doesn't have a substantial number of subtle and less-than-honest "mistakes" of a similar character?
- pierreozoux 11y agoThis is true, but for proprietary software it is way worse...
- RodgerTheGreat 11y agoIn proprietary software it's different. Proprietary software is less vulnerable to infusions of backdoors from untrusted sources and side channels. Proprietary software can only be audited by the developers themselves, and it will depend on the kinds of resources the developers can bring to bear directly. Companies that can afford it can dedicate large teams to reviewing and testing their codebases. That open source code can be audited by third parties is only relevant if it actually happens, and otherwise you have only a false sense of security.
- J_Darnley 11y agoWow, it largely (maybe completely) works without javascript. A rare thing these days for pages which look like that.
- rgbrgb 11y ago"Would you allow a stranger to enter your home, and look around?" Yeah, that's how you make friends. Certainly not into government spying but this is a ridiculous comparison. Reminds me of those piracy ads that try to convince you not to download music by saying "you wouldn't download a car". It's like pretty different and of course I'd love to download a car. I'm down for the cause but I don't think talking to people like they're idiots is a good way to rally support.
- pierreozoux 11y agoWould you give me your email and password?
- rgbrgb 11y agoNo.
- ZoFreX 11y agoNot really relevant but those anti-piracy ads say "You wouldn't steal a car", not download.
- jedmeyers 11y agoThen they also say something about the policeman's helmet, as far as I remember.
- yellowapple 11y agoIn addition to doing something to that helmet, if I recall correctly.
- GigabyteCoin 11y ago>Yeah, that's how you make friends. Certainly not into government spying but this is a ridiculous comparison. I disagree. The wording might not be perfect, but the comparison is sound imho. Potential friends aren't typically total strangers. You are usually at least considered aquaintances at first. And potential friends don't typically go "looking around" your home on the first visit, either. They're usually quite respectful of your privacy from what I have gathered over the years. They don't just get up and search for a bathroom, they'll ask you where it is.
- signaler 11y agoCould be relevant: http://blog.higg.so/2015/04/29/do-ad-blockers-and-anti-tracking-plugins-only-partially-solve-privacy-on-the-web/ http://blog.higg.so/2015/04/29/do-ad-blockers-and-anti-track... I wrote this in response to all the silver bullets being offered as a solution to fingerprinting. It turns out, it's a hard problem and not a quick fix. A small excerpt: "The EFF have released a tool called Panopticlick that creates a lossy hash of your browser. The idea behind the tool is to issue each user with a very unique browser footprint that is used to definitely verify you are the person visiting a page. I stress the importance of definitely because the tool can zoom right in to an individual at the personal level, or a small sample size of users. (More on sample sizes later). Especially concerning about fingerprinting is how accurate it can be. If a useragent is changed, something else will give an identity away like the fonts installed on a machine, the pixel depth of a screen, or the time you visit a page. Flash and JavaScript are typically disabled by users now because they can prove too invasive"
- maxerickson 11y agoThe phrasing of Flash and JavaScript are typically disabled by users now because they can prove too invasive is awkward. I guess you must mean that is the typical motivation of people that choose to block, the problem I see is that it can be read to mean that typical users block flash/js (of course they don't).
- deleted 11y ago[deleted]
- signaler 11y agoIt's a tricky one this, because on one hand it sounds like a blanket statement: that all users of a web browser disable...and on the other hand it could be entire opposite - that some users block. I don't have the numbers, so there is wiggle room for awkwardness. Please read the entire article and don't snipe out isolated sentences please.
- maxerickson 11y ago
- inverba 11y agoThe website is designed in a very jarring way. The transitions should be much more obvious.
- feld 11y agoThe "tor" column has the difficulty rating at "2h". Someone mistook it for a time measurement, which is what the previous column is for.
- pierreozoux 11y agoI think you mean the point #6, but now it's corrected, thanks!
- evv 11y ago> Have your server at home. Why? People would need to break into your house to get your data. Really?? Don't tell people things that are patently untrue. Your home server can be hacked remotely. And if you don't fully trust the hardware and software in your server then it is probably already compromised. Physically keeping your server in your house, by itself, does nothing to increase your cyber-security. Its like trying not to get sick by avoiding handshakes, but welcoming coughs and sneezes in your face.
- poiuytre 11y agoI like the concept of different steps!