• 22 Posts
  • 457 Comments
Joined 7 months ago
cake
Cake day: February 17th, 2026

help-circle


  • In theory 23hr 59min 59sec of audio every day is not continuously recording.

    Practically speaking, it’ll be a lot of false positive detections of the wake word + following audio. Which phones and other voice devices also suffer from. Even if the wake word happens locally, it’s fragile! Other words sound like it, enoguh to trigger it. Then audio gets sent to the cloud. Often with no notice to the user b/c they figure the wake word was on purpose.


  • That’s an interesting idea.

    The wiki page says the pattern is repeated about 150 times on a standard page, so it is fault tolerant. In theory, a printer could also dynamically relocate them. To avoid regions of yellow. But if there was no dynamic reloc, then you could overwrite.

    Wikipedia thinks you are onto something!

    In 2018, scientists from TU Dresden developed and published a tool to extract and analyze the steganographic codes of a given color printer and subsequently to anonymize prints from that printer. The anonymization works by printing additional yellow dots on top of the printer’s tracking dots. The scientists made the software available to support whistleblowers in their efforts to publicize grievances.






  • Agree. Also weird b/c G has a special Google for Education scheme for schools. Which the school would be tied into, and accounts would be made through that. G makes promises like it won’t use the student’s data for other purposes, no profiling, no ads, etc.

    I still wouldn’t be happy with having to use G as a student. For lots of reasons, like normalizing it so students will keep using G after they graduate. Even so, I believe G does make a good faith effort to adhere to their promises about not using student data for other purposes. But prob only if done through the official channels to create the acct.








  • Blocking JS is a fingerprint

    IMO, that is true… but could potentially be misleading. It can still be better to block, even if blocking itself is a fingerprint. (edited here, fix bad wording)

    It only makes you worse off if the bits of identifying info with javascript exceed the bits obtained by the single option of disabling JS. And that depends on how many ppl do it. It’s the -log2 of the probability of that event. Let’s say that only 1 in 100,000 disables JS. (It’s gotta be more than that?) That is just under 17 bits of information from seeing that JS is disabled, b/c you’re only unique to one part in 100K. So if the number of bits obtainable with JS enabled exceed 17, then it’s a net win to disable JS!

    I don’t know what % of ppl disable JS. I feel it’s more than 1:100K. That’s only 1 person in a decent sized city. IDK what the right % is. But for any reasonable value I can imagine, it seems like a win. Far more bits of ID-ing info can be obtained through JS, than the -log2 of that %.

    Also, the more ppl disable JS, the fewer bits are obtained by seeing that JS is disabled, b/c the log2(%-who-disables-JS) gets smaller.


  • In theory a neighbours lg tv could broadcast their wifi credentials to your tv to connect to upload the data.

    but its technically doable.

    Agree that mesh networking is technically doable. Credentials, IDK about that, but mesh, yes.

    I thought I remembered a mfg who sold appliances that would try to mesh-network with others from the same mfg. Even if it was at another household or w/e.

    But I can’t seem to find the story now! IDK, maybe I’m fulla shit. Maybe I’m just jaded and my brain made it up. I’m trying to search but overloaded with pages about legit mesh networking.


  • Be aware that you will have no privacy on the school’s network. They usually block all known VPN endpoints, and require certs that will allow MiTM even for HTTPS connections. For lotsa reasons it’s best to cleanly separate personal activity, from school activity. Or work activity when you get a job.

    Since you mentioned “gaming distro”… what I do for private gaming is buy games from GOG. Every one I ever tried runs fine even with no network access. You can use sth like firejail to do this super easy. No need to set up a VM or w/e. Then you know it isn’t phoning home. B/c it can’t!

    Plus, all their games are DRM-free. Which is part of what makes them private. I’d rather my dollars support DRM-free stuff. Supply and demand. The more ppl buy DRM games, the more it teaches game vendors that we don’t care. There are other DRM-free stores too. Stay away from Steam. Go for GOG, Humble, and w/e else. Then you can have private gaming.


  • While I haven’t heard about any TVs that do this, seems like only a matter of time until Tvs that won’t function unless they can contact the mothership.

    It wouldn’t be hard to make it. Or w/e other consumer devices. Just gate all functionality behind the user “agreeing”. Most ppl will click OK on literally anything.

    By clicking agree, you accept that we or our 1829 partners can break into your house, steal your shit, shoot your puppy, plant rootkits in all your devices, piss in your pot of soup, and set the place on fire before we go. Millions of ppl -> Clicks OK.


  • Or maybe just a machine at the shipping carrier or post office that slaps a label on the package? Vendor still wouldn’t get access to the info, since label is applied after the carrier gets the package. Then the delivery person wouldn’t have to faff around with a code.

    Ofc, the carrier would have to be somehow prevented from selling the link from 17bkHdb74nKl to 123 Main Street. That may have to be solved legally, since they have a financial incentive to sell the link.

    Provided the problems could be ironed out, I like the 1 time code idea. I like it a lot. It cuts a lot of the commercial surveilence ecosystem off at the knees.


  • Phone call tapping needs a warrant.

    This is correct for the US, and I think quite a few others. Generally that req has been upheld in the US.

    It is also correct that there is little to no technical protection against intercepting the content. The only protection you have is legal.

    Hence why discussions become confusing. You get people insisting there is no protection. They are correct, in a way. Then you get people insisting there is. They are also correct, in a different way. Then, here’s an example of when the legal protection failed, therefore, the legal protection does not exist. Which is generally wrong.

    To add even more confusion, the NSA was collecting metadata about the phone calls of over 100M people! Per Snowen’s disclosures,

    Under the order, the numbers of both parties on a call, as well as the location data, unique identifiers, time of call, and duration of call were handed over to the FBI, which turned over the records to the NSA

    But that is not the same as collecting and processing the audio.

    It is important to be specific about the exact thing you are worried about. I live in the USA, and for USA-to-USA conversations over the traditional phone network, I generally do not worry about the audio being interepted without a warrant. Even though my only protection is legal. If I was going to have an extremely sensitive conversation, esp if I was afraid of disclosure of who I talked to, I would chose a different method to talk. But not b/c I think the risk is very high of my phone audio being surveiled. Just from an abundance of caution.