Glorified network janitor. Perpetual blueteam botherer. Friendly neighborhood cyberman. Constantly regressing toward the mean. Slowly regarding silent things.

  • 1 Post
  • 39 Comments
Joined 11 months ago
cake
Cake day: December 27th, 2023

help-circle











  • 0xtero@beehaw.orgtoPrivacy@lemmy.mlIs it impossible to be private online?
    link
    fedilink
    arrow-up
    4
    arrow-down
    2
    ·
    edit-2
    6 months ago

    Every time I talk about privacy online, the pessimists always come out. "It’s impossible to have any online privacy.

    My experience is actually completely opposite. While mainstream “normies” don’t seem to care, most of them are using readily available privacy tools in their communication daily. Things like WhatsApp, Signal and iMessage. Most websites these days are HTTPS enabled. Governments are so concerned about this loss of monitoring capability, they’re trying to craft laws which allow them to backdoor devices before encryption happens. And they’re meeting resistance, despite all the lobbying (see Chat Control2.0). We’ve never had as widely adopted privacy tools as we have today.

    Big tech and advertising are two problems that still create trouble. A lot of this stems from completely different, non-privacy related reasons (the lax US policies concerning anti-consumer and monopoly laws) but even here policies around the world are slowly catching up. GDPR gives Europeans quite a bit of control over our data and while this is still just one baby step - it’s much better than it used to be. There’s a lot of global inequality here though. Facebook/Meta is synonymous to Internet in the developing world, because they’ve used their monopoly money to exploit the situation. Digital imperialism is still strong.

    I’m not going to harp too much on SMTP privacy, Proton has a bunch of nice services. If that’s where your MX happens to point at is, then great, but we do also need to slowly move away from these old protocols that offer no privacy choice (yeah I know, SMTP is here to stay).

    What I’d like to see more, is talk about threat modeling in this space. Because that’s where it all starts and threat models are quite personal. There’s no “one size fits all” privacy, because our needs vary. Political dissident living in exile from hostile government has completely different needs for privacy compared to a person who doesn’t like YouTube ads. We should try to foster easily digestible discussion around personal threat modeling - right now we (the privacy crowd) come across as loonies since lot of the advice we give starts from the wrong end of the model.

    I don’t see digital privacy as a pessimistic space. But what do I know, I’m not a content creator.




  • I also don’t get much value out of the statement that “every” OS except Android is vulnerable. Do they really mean all other OSes, or just what would come to mind for most people, i.e. Windows, macOS, Linux, iOS? What about the various BSDs for example?

    It’s a DHCP manipulation attack, so every RFC 3442 compliant DHCP implementation implementing option 121 would be “vulnerable” (it’s not vulnerability though). Android apparently doesn’t implement it, so it’s technically impossible to pull off against Android device. There might be others, but I’d guess most serious server/desktop OS’es implement it.

    The title isn’t misleading at all, even though the “neutering their entire purpose” is a bit of a click-bait. This doesn’t affect ingress VPN at all.

    It’s an attack that uses DHCP features (according to RFC).

    It’s a clever way to uncloak egress VPN users, therefore it does have privacy impact since most of us use VPN for purposes of hiding out traffic from the local network and provider and there’s no “easy” fix since it’s just a clever use of existing RFC.




  • I’m a consultant so whenever I’m applying for a new gig I need to provide a consultant profile, which is very similar to resume.

    Over the years I’ve learned that most customers are not very interested in the “personal stuff” sections - they just want to know you have the skills required, so try to minimize the amount of personal data and concentrate on skills and past gigs (anonymizing customers/companies) etc.

    But - unfortunately you have to tell something about yourself and your ability to work together with others, there’s really no way around it. It’s also more and more customary that (for some reason) they want your photo. Stuff like education, certifications need to be there, but keep it very short. Think about “social media profile page”.

    Provide stuff like contact info, address, phone, date of birth (if required) and references separately - don’t put them into your resume. You can add something like “Personal information and references provided separately by request” in there, that way, even if the document is shared, all they get is something resembling a LinkedIn profile.

    You can also try to add “confidential” to the document header, but I’ve noticed it’s not respected very often.


  • Teaching kids good, healthy anticapitalist values is important. It’s also good to teach them some basic computing and privacy skills, because they’re not going to get that anywhere else. They’re going to be under lot of social peer pressure to have the latest phones and being connected on social media, consuming information from algorithms.They need to understand how to minimize the harm from Meta and the big tech.

    Same applies to the copyright industry and their practices (along with corps who are heavily anti-repair like Apple) - they need to understand the exploitation model of capitalism and lobbying - from there, let them make their own choices.