• 5 Posts
  • 122 Comments
Joined 1 year ago
cake
Cake day: April 26th, 2025

help-circle




  • not to shit on you specifically but I see this over and over, folks asking how to be “secure”. secure against what?

    if you’re into this, you need to set up a “threat model” i.e. what are your threat vectors and then you build your defenses against that model. a defense against blanket surveillance doesn’t handle targeted threats. a successful defense against your government doesn’t preclude other nation-state actors getting at you.

    like, if your threat vector is e.g. your SO “inspecting” your phone, you set up a passcode and you’re safe against that threat. but, if there’s a toddler going around smashing stuff, your defense isn’t valid. defense against that vector is placing your phone high up. but that defense isn’t effective against SO.

    I am sure any messenger recommended here can be successfully red-teamed, be it design flaws, operator error, the famous wrench comic, or whathaveyou. but that doesn’t mean it’s ineffective in your specific case.



  • don’t need any such “proof”. the whole industry has lost any and all benefit-of-doubt privileges, for ever. they don’t get an opportunity to gain a foothold in mi casa and possibly be in a position to do harm.

    I don’t get the idea that after all the shit they pulled someone’s like “well maybe this new thing’s nice”.

    those are immoral people with zero compunctions about doing anything that hurts you, your community, and humanity as a whole. we are in an adversarial position and you’d do well to remind yourself of that constantly.




  • glitching@lemmy.mltoPrivacy@lemmy.worldsignal w
    link
    fedilink
    English
    arrow-up
    28
    ·
    edit-2
    3 months ago

    The issue is them having any info to give out in the first place, it is a horrendous transgression for a shop that touts privacy as their thing.

    Signal demonstrated that you can decouple payment info from account info and thus they ain’t got nothing to produce, MLAT or not. The least Proton coulda done is mimic that tech.

    edit: are you shills illiterate, what’s your deal? signal also accepts payments, the kind normal people use, like CC and stuff. and they decoupled payment info from account info, so nobody can link John Smith, Fuckville, AL to account protonshill4lyfe@proton.yo



  • Imma be the problemXY guy - how often do you need to interact with your bank that you need to carry that attack vector always on your person? you managed to live without that thing for a huge percentage of your life, maybe try limiting your exposure. if that works out, your options for a degoogled life rise dramatically.

    get a used supported device that ain’t a pixel, if you haven’t already got one lying around and carry it in parallel - you still got all your shit on your main device and you have the luxury of offloading one by one use case onto the new device without downtime.

    maybe you’ll make do with just bare lineageOS. maybe you’ll need the intermediate step - lineageOS with microG which implements a subset of play services.

    hopefully, in the process you’ll throw out a buncha consumerism shit you don’t actually need. good luck.







  • I imagine they got courts and lawyers and motions and hearings and stuff over there, even if the fight is doomed you need to show your teeth once in a while. and what’s with the proton employee reviewing whether there were “explosives” and “guns” involved, naturally based on super-reliable evidence, what the fuck is that?!

    and alla that aside, why do they have payment and user info on file, for what fucking purpose? there’s either user privacy or there ain’t. and them folks are in the “ain’t” camp.


  • article in case you can’t read it: lemmy.ml/post/44086795 edit: better link in a reply.

    proton coulda put up a fight, a loud one, for optics sake if nothing else. rolling over on any (and by implication, all) request should be the last straw in their long line of snafus; by way of “death by a thousand cuts”, I would never entrust them with anything of importance.

    signal demonstrated that you could decouple payment info from user data and a shop that touts the privacy part of their offerings coulda at least mimic such a thing.

    edit 2: fuck any and all pay-with-crypto shills and the horse they rode in on.


  • I’m saying I’m not gonna use it as an email provider, as in pen a love letter to to sydney sweeney, reminding her of the shit she promised me in my most recent dream and she’s kinda tardy so what’s up with that and so on.

    I am gonna use it as a transactional email inbox, as in “you registered to yadda-yadda here’s shit you’re never gonna read”. and if in the process of using them it turns out they’re a buncha good folks, maybe I’ll elevate out reationship.

    the trackings and whatnot are a) blocked by a buncha filters, b) gone when I close the tab with their url, c) they don’t get my PII, and d) they don’t get to store anything on my hardware.

    way worse shit out there.