@SecurityPro@lemmy.ml avatar

SecurityPro

@SecurityPro@lemmy.ml

Security and privacy professional. Currently testing and evaluating Signal username staging application.

This profile is from a federated server and may be incomplete. View on remote instance

Encrypted services Apple, Proton and Wire helped Spanish police identify activist | TechCrunch ( techcrunch.com )

By the way, the earlier posted article https://restoreprivacy.com/protonmail-discloses-user-data-leading-to-arrest-in-spain had an update starting at the paragraph with title Update: Statement from Proton and additional commentary

SecurityPro ,
@SecurityPro@lemmy.ml avatar

"helped" is very misleading. Companies can't refuse to provide information they have when served a search warrant / court order. These companies DID NOT choose to provide the info on their own.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

As someone who has worked fraud and online investigations, and both written and served search warrants; it is not an option. A probable cause affidavit is presented to a judge and if the judge agrees there is sufficient probable cause, a search warrant is issued. This is an order by the judge and not optional. The judge can hold the company in contempt if they refuse to obey his/her order.

SecurityPro , (edited )
@SecurityPro@lemmy.ml avatar

Regarding: "On Android you can use [Stealth] . That's what I use for searches that pull up Reddit posts."

The stealth protocol does not have anything to do with accessing individual sites or services. The purpose of stealth is when trying to estata VPN connection to a provider that does not allow VPNs. For example, a public wifi that blocks VPN connections or some countries that require ISPs to block VPN connections.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Reach out to the job sites directly and report these as fraudulent. Ask them to remove the resume postings.

Also consider making accounts for her on these sites, may make it easier to prevent future posting and to remove any that do appear.

Then, since it sounds like you are her lawyer. Subpoena these sites for information on account, email address, IP address used for the fraudulent posts.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Agreed, grab AntennaPod from the f-droid store.

Looking for a privacy focused travel assistant on mobile

Heya, as the title suggests. I have tried the KDE Initary (on mobile), but the user experience didn't quite flop-my-mop. It is however the better one in terms of privacy as far as I have found. Are there any other ones that you folks know of and would recommend? Looking for an app that specifically can hold boarding passes....

SecurityPro ,
@SecurityPro@lemmy.ml avatar

I use Anytype (anytype.io) on my phone and desktop. I make a page for each trip and add screenshots of confirmations, maps, itinerary, etc.

Anytype is similar to Notion but is open source and encrypted locally.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Agreed, they are continually improving it

SecurityPro ,
@SecurityPro@lemmy.ml avatar

I've contacted Anytype about this and will post their response.

I run Graphene OS on my phone and have an always on VPN connection. Plus I use a different email address, username, and password for 99% of my accounts. So I don't worry about telemetry, analytics, or data marketing anymore.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

I looked at some of these on my own and found:

  • graylog provides data privacy and protection services for companies offering software as a service (SaaS). So this seems legit to me and needed for their core functionality. It is not a marketing or data analytics company.

  • amplitude appears to be a data analytics company and on the surface is not needed and Anytype should explain this.

  • sentry appears to be an application error tracking company and this seems a legit connection

  • api2 seems like a generic server name and likely needed for their core functionality, this seems legit to me

  • telemetry also seems like a generic server name; however, the purpose, based on its name does not seem to be needed. Anytype should explain this as well.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Anytype has responded and I had a couple other clarifying questions. Their first response:

"Hi! In our privacy policy we include Amplitude & Sentry & explain why we work with them: anytype.io/app_privacy.
Currently, you can opt-out by electing local-only or self-hosted network Mode"

Sentry is only used for bug tracking and I don't have any issue or privacy concerns with that.

I had already looked on their website for a privacy policy and the only one I could locate was a website only privacy policy. I learned later that the application privacy policy is buried as a link somewhere within the website privacy policy. This is not very easy to find.

I reviewed the application privacy policy and it conflicted with their answer stating that a user could opt out of information sharing with Amplitude by using "local only" or "self-hosted". So I pointed this out and posted this reply to them:

"Also, app privacy policy section for Amplitude states: Amplitude Analytics
Purpose: deliver behavioral and app usage data.
Opt-out possible: NO"

This is the response I received:

"Indeed this is outdated information, as it was written before self-hosting and local-only mode were properly configurable. Opt-out is now possible using these methods, and we will be updating the policy accordingly."

SecurityPro ,
@SecurityPro@lemmy.ml avatar

The bigger question I have is how are you going to view them? Did you build yourself and IMAX size screen?

SecurityPro ,
@SecurityPro@lemmy.ml avatar

I have a Jellyfin server running locally. All my TVs either have a Roku device connected or are a Roku embedded TV. I also run PiHole and all DNS queries in my local network go through it. That way all telemetry, "phoning home", and advertisments are blocked. All my TVs have the Jellyfin Roku app installed to stream my local content.

If you want access outside your local network. I setup Nginx Proxy Manager (NPM) locally and have my own domain pointing back to my NPM server to access my Jellyfin content and other self-hosted services that I run.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Well then your devices are still phoning home with telemetry that is still tied to your ISP assigned IP address (guest network doesn't provide any privacy).

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Can you provide a source for this information?

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Context (from the FAQ):

"We're not actually a domain name registration service, we're a customer to these. We sit in between the domain name registration service and you, acting as a privacy shield.

When you purchase a domain name through Njalla, we own it for you. However, the agreement between us grants you full usage rights to the domain. Whenever you want to, you can transfer the ownership to yourself or some other party."

How Do I Avoid Giving Home Address to Bank?

I've heard of things like iPostal and Traveling Mailbox. Do these services allow you to register with bank, DMV, IRS, Voting, etc? How do they work? Would a normal P.O box using its physical address from USPS work? I've tried researching it and haven't gotten clear answers....

SecurityPro ,
@SecurityPro@lemmy.ml avatar

What you are likely referring to is a "nomad" residence. There are some states that allow this, such as Florida. There is a process to getting this status and you would want to do that before opening a new account in that state.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

You are not defrauding anyone. Plus there is a legitimate process to go through to establish nomad residency. It creates a valid residential address.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

It didn't grant access to video. It just allowed public safety to say "Hey, everyone in this area, we had an incident and would like video if you have it and are willing to share it." The owner then had to manually share the video with the public safety agency in the app. The loss of this valuable tool actually harms public safety and make is more difficult and time consuming to solve crimes.

The Irish government wants to pass a law that could see you or your loved ones jailed for possession of memes, cartoons or any content that could be deemed "hateful".

The Bill includes no definition of hate and is wide open to abuse by bad actors. Defend free speech – say no to this legislation, and any legislation of is kind... Anywhere!...

SecurityPro OP ,
@SecurityPro@lemmy.ml avatar

Post it on social media.

SecurityPro OP ,
@SecurityPro@lemmy.ml avatar

Freedom of expression?

[https://extra.ie/2021/02/21/news/irish-news/gardai-tell-woman-to-take-down-social-media-post-after-she-identifies-herself-as-child-abuse-victim(url)
https://extra.ie/2021/02/21/news/irish-news/gardai-tell-woman-to-take-down-social-media-post-after-she-identifies-herself-as-child-abuse-victim

SecurityPro OP ,
@SecurityPro@lemmy.ml avatar

There is not freedom of expression if the police can demand that you take down or alter a social media post.

SecurityPro OP ,
@SecurityPro@lemmy.ml avatar

So an adult victim of a crime can't admit that they were the victim of a crime?

SecurityPro ,
@SecurityPro@lemmy.ml avatar

I had been running Nextcloud on an old laptop using Ubuntu, but that machine died. I have a Windows PC originally built for gaming that I am considering using for Nextcloud. Anyone have any experience with NC and Windows? Thought on the DB switch on Windows?

SecurityPro , (edited )
@SecurityPro@lemmy.ml avatar

I have docker on the machine now and thought I’d try that type of install first. Sorry, I’m not familiar with the abbreviation “wsl2”

Proton VPN on Linux looks very different from Windows. How do you select one of their P2P options for faster torrenting?

Pretty much what the title says. I noticed that ProtonVPN Linux has an EXTREMELY limited interface compared to their program on Windows. I also do not appear to have the option to bind qBittorrent to ProtonVPN the same way that I did with MullvadVPN. Has anybody experienced ProtonVPN on Linux and successfully used it for...

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Yes, but it still doesn’t have wireguard, only openVPN.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

I find that to be a frequent issue with Readarr.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Download and installed but it still insists on a phone number. I don’t see a way to bypass.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Have you looked at Starlink or T-Mobile 5g home internet?

SecurityPro ,
@SecurityPro@lemmy.ml avatar

This is fear mongering by EFF. These agencies all use the Vigilant LPR system. It allows other agencies that use the system to share data about vehicles linked to those with arrest warrants, stolen vehicles, as well as missing and abducted children. EFF has a political agenda.

SecurityPro ,
@SecurityPro@lemmy.ml avatar

What OS are you using with your RP4to host all that?

SecurityPro ,
@SecurityPro@lemmy.ml avatar

How do you set that environment variable for Steam?

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Is that within a Steam configuration file?

SecurityPro ,
@SecurityPro@lemmy.ml avatar

Great, thanks! I’ll give it a try

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • All magazines