mirror of
https://github.com/privacyguides/privacyguides.org.git
synced 2026-10-01 19:12:43 +00:00
Compare commits
7
Commits
2026.09.17
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c3e1984cbd | ||
|
|
f7316b605e | ||
|
|
dbc140bd50 | ||
|
|
9262e3401b | ||
|
|
aca2cf49fe | ||
|
|
d077e5b66b | ||
|
|
b1441f5960 |
@@ -45,7 +45,7 @@ A famous example is the AOL search log release. AOL had been logging its users s
|
||||
|
||||
#### Strava Heatmap Incident
|
||||
|
||||
In 2018, the fitness app Strava announced a major update to its heatmap, showing the the workout patterns of users of fitness trackers like Fitbit.
|
||||
In 2018, the fitness app Strava announced a major update to its heatmap, showing the workout patterns of users of fitness trackers like Fitbit.
|
||||
|
||||
Analyst [Nathan Ruser](https://x.com/Nrg8000/status/957318498102865920) indicated that these patterns can reveal military bases and troop movement patterns. This is obviously a huge op-sec problem and can endanger the lives of troops.
|
||||
|
||||
|
||||
@@ -10,7 +10,7 @@ tags:
|
||||
- Email
|
||||
license: BY-SA
|
||||
schema_type: BackgroundNewsArticle
|
||||
description: Email is ubiquitous. If you want to function in modern society, you pretty much have to have an email address. But is it really a good idea to still be relying on the same decades old techology? What can we do about replacing it?
|
||||
description: Email is ubiquitous. If you want to function in modern society, you pretty much have to have an email address. But is it really a good idea to still be relying on the same decades old technology? What can we do about replacing it?
|
||||
preview:
|
||||
cover: blog/assets/images/email-security/cover.png
|
||||
---
|
||||
|
||||
@@ -266,7 +266,7 @@ Confirm your choice by clicking on "Save changes" on the upper-right.
|
||||

|
||||
|
||||
<div class="admonition tip" markdown>
|
||||
<p class="admonition-title">Hide posted media (slighly)</p>
|
||||
<p class="admonition-title">Hide posted media (slightly)</p>
|
||||
|
||||
Additionally, you might want to check the "Always mark media as sensitive" option from the same section. This will label the media as "Sensitive content", and require others to click on it to view the image. This will **not stop anyone from clicking to view it**, including people without a Mastodon account from your account's public page, but it might *slightly* reduce the visibility for certain media.
|
||||
|
||||
|
||||
@@ -59,7 +59,7 @@ There are different levels to this. It could mean sharing a first name but not a
|
||||
|
||||
Using a pseudonym and a profile picture that isn't a self-portrait can help significantly to reduce digital footprints and improve online safety. It can also help to detach different accounts from each other, for example by using a certain name for a work account and a pseudonym for a personal alt account.
|
||||
|
||||
Remember that that this will not make you anonymous online, however. It will only help hide or separate your legal identity from your public-facing profile.
|
||||
Remember that this will not make you anonymous online, however. It will only help hide or separate your legal identity from your public-facing profile.
|
||||
|
||||
If you want to use more serious pseudonymity online, you will also need to consider using different email addresses to sign up, different phone numbers if required, different photos of course, but also different IP addresses, and so on and so forth.
|
||||
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
---
|
||||
title: Consider Everyone's Unique Situation
|
||||
description: To give actionable privacy advices, it's essential to consider everyone's situation. Learn more on how you can evaluate each person's unique threat model.
|
||||
description: To give actionable privacy advice, it's essential to consider everyone's situation. Learn more on how you can evaluate each person's unique threat model.
|
||||
icon: fontawesome/solid/users-between-lines
|
||||
cover: activism/banner-toolbox-tip-everyone.webp
|
||||
---
|
||||
|
||||
@@ -126,7 +126,7 @@ In this example we will record what happens when we make a DoH request:
|
||||
|
||||
We can see the [connection establishment](https://en.wikipedia.org/wiki/Transmission_Control_Protocol#Connection_establishment) and [TLS handshake](https://cloudflare.com/learning/ssl/what-happens-in-a-tls-handshake) that occurs with any encrypted connection. When looking at the "application data" packets that follow, none of them contain the domain we requested or the IP address returned.
|
||||
|
||||
## Why **shouldn't** I use encrypted DNS?
|
||||
## Encrypted DNS Limitations
|
||||
|
||||
In locations where there is internet filtering (or censorship), visiting forbidden resources may have its own consequences which you should consider in your [threat model](../basics/threat-modeling.md). We do **not** suggest the use of encrypted DNS for this purpose. Use [Tor](../advanced/tor-overview.md) or a [VPN](../vpn.md) instead. If you're using a VPN, you should use your VPN's DNS servers. When using a VPN, you are already trusting them with all your network activity.
|
||||
|
||||
|
||||
@@ -92,7 +92,11 @@ It is critical to understand the difference between bypassing censorship and eva
|
||||
|
||||
### Tor Browser is not the most *secure* browser
|
||||
|
||||
Anonymity can often be at odds with security. Tor achieves anonymity by ensuring every user appears identical, creating a digital monoculture where the same vulnerabilities exist across all installations. In cybersecurity, monocultures are generally considered a risk. Security through diversity provides natural segmentation by limiting the impact of an exploit to a smaller segment of users. While such diversity is structurally desirable for security, it inherently compromises user anonymity by making individuals trackable.
|
||||
Anonymity can often be at odds with security. Tor achieves anonymity by ensuring more users appear [similar](https://support.torproject.org/tor-browser/features/fingerprinting-protections/#:~:text=Tor%20Browser%20is,individual%20users%20effectively.):
|
||||
|
||||
>Tor Browser is specifically engineered to minimize the uniqueness of each user's fingerprint across various metrics. While it is practically impossible to make all Tor Browser users identical, the goal is to reduce the number of distinguishable "buckets" for each metric. This approach makes it harder to track individual users effectively.
|
||||
|
||||
While this is effective at preserving anonymity, it also creates a digital monoculture where the same vulnerabilities exist across many installations. In cybersecurity, monocultures are generally considered a risk. Security through diversity provides natural segmentation by limiting the impact of an exploit to a smaller segment of users. While such diversity is structurally desirable for security, it inherently compromises user anonymity by making individuals trackable.
|
||||
|
||||
Additionally, Tor Browser is based on Firefox's Extended Support Release builds, which only receives patches for vulnerabilities considered *Critical* and *High* (not *Medium* and *Low*). This means that attackers could (for example):
|
||||
|
||||
|
||||
@@ -121,6 +121,6 @@ The [F-Droid](https://f-droid.org/en/packages) and [IzzyOnDroid](https://apt.izz
|
||||
<div class="admonition note" markdown>
|
||||
<p class="admonition-title">F-Droid Basic</p>
|
||||
|
||||
In some rare cases, the developer of an app will only distribute it through F-Droid ([Gadgetbridge](../health-and-wellness.md#gadgetbridge) is one example of this). If you really need an app like that, we recommend using the newer [F-Droid Basic](https://f-droid.org/en/packages/org.fdroid.basic) client instead of the original F-Droid app to obtain it. F-Droid Basic supports automatic background updates without privileged extension or root, and has a reduced feature set (limiting attack surface).
|
||||
In some rare cases, an app may only be available through F-Droid. If you really need an app like that, we recommend using the newer [F-Droid Basic](https://f-droid.org/en/packages/org.fdroid.basic) client instead of the original F-Droid app to obtain it, as it has a reduced feature set (limiting attack surface).
|
||||
|
||||
</div>
|
||||
|
||||
@@ -5,11 +5,19 @@ icon: material/tag-remove
|
||||
description: Use these tools to remove metadata like GPS location and other identifying information from photos and files you share.
|
||||
cover: data-redaction.webp
|
||||
---
|
||||
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
- [:material-account-search: Public Exposure](basics/common-threats.md#limiting-public-information){ .pg-green }
|
||||
|
||||
When sharing files, be sure to remove associated metadata. Image files commonly include [Exif](https://en.wikipedia.org/wiki/Exif) data. Photos sometimes even include GPS coordinates in the file metadata.
|
||||
When sharing files, be sure to remove associated metadata. Most common file types (including documents, images, and videos) include metadata. Image files, for example, commonly include Exif data. Photos sometimes even include GPS coordinates in the file metadata.
|
||||
|
||||
Windows has a built-in metadata remover, but unfortunately it cannot remove many types of data such as:
|
||||
|
||||
- Documents: Comments, author names, tracked changes, hidden worksheets, slide notes, custom XML, and document revision histories.
|
||||
- Images: Camera serial numbers, XMP/IPTC data, C2PA metadata, and image thumbnails (which can dangerously expose original details from cropped or erased areas).
|
||||
- Audio & Video: XMP metadata, C2PA metadata, and certain ID3v2 tag fields.
|
||||
- Embedded Files: Hidden metadata nested inside images that are embedded within documents.
|
||||
|
||||
<div class="admonition warning" markdown>
|
||||
<p class="admonition-title">Warning</p>
|
||||
|
||||
+2
-3
@@ -92,7 +92,7 @@ Proton Mail has internal crash reports that are **not** shared with third partie
|
||||
|
||||
From your inbox, select :gear: → **All Settings** → **Account** → **Security and privacy** → **Privacy and data collection**.
|
||||
|
||||
- [ ] Disable **Collect usage dignostics**
|
||||
- [ ] Disable **Collect usage diagnostics**
|
||||
- [ ] Disable **Send crash reports**
|
||||
|
||||
=== "Mobile"
|
||||
@@ -100,7 +100,7 @@ Proton Mail has internal crash reports that are **not** shared with third partie
|
||||
From your inbox, select :material-menu: → :gear: **Settings** → select your username.
|
||||
|
||||
- [ ] Disable **Send crash reports**
|
||||
- [ ] Disable **Collect usage dignostics**
|
||||
- [ ] Disable **Collect usage diagnostics**
|
||||
|
||||
#### :material-check:{ .pg-green } Custom Domains and Aliases
|
||||
|
||||
@@ -277,7 +277,6 @@ We regard these features as important in order to provide a safe and optimal ser
|
||||
|
||||
- Must encrypt email account data at rest with asymmetric encryption, where only the user has the private keys needed to decrypt it.
|
||||
- Must be capable of exporting emails as [Mbox](https://en.wikipedia.org/wiki/Mbox) or individual .EML with [RFC5322](https://datatracker.ietf.org/doc/rfc5322) standard.
|
||||
- Allow users to use their own [domain name](https://en.wikipedia.org/wiki/Domain_name). Custom domain names are important to users because it allows them to maintain their agency from the service, should it turn bad or be acquired by another company which doesn't prioritize privacy.
|
||||
- Must operate on owned infrastructure, i.e. not built upon third-party email service providers.
|
||||
|
||||
**Best Case:**
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
meta_title: "Privacy-Respecting Health and Wellness apps for Android and iOS - Privacy Guides"
|
||||
title: "Health and Wellness"
|
||||
icon: material/heart-pulse
|
||||
description: These applications are what we currently recommend for all health- and fitness-related activites on your phone.
|
||||
description: These applications are what we currently recommend for all health- and fitness-related activities on your phone.
|
||||
cover: health.webp
|
||||
---
|
||||
<small>Protects against the following threat(s):</small>
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Linux Overview
|
||||
icon: simple/linux
|
||||
description: Linux is an open-source, privacy-focused desktop operating system alternative, but not all distribitions are created equal.
|
||||
description: Linux is an open-source, privacy-focused desktop operating system alternative, but not all distributions are created equal.
|
||||
---
|
||||
**Linux** is an open-source, privacy-focused desktop operating system alternative. In the face of pervasive telemetry and other privacy-encroaching technologies in mainstream operating systems, desktop Linux has remained the clear choice for people looking for total control over their computers from the ground up.
|
||||
|
||||
|
||||
@@ -73,7 +73,7 @@ If you use Android and your threat model requires protecting against [:material-
|
||||
|
||||
{ align=right }
|
||||
|
||||
**Molly** is an alternative Signal client for Android which allows you to encrypt the local database with a passphrase at rest, to have unused RAM data securely shredded, to route your connection via Tor, and [more](https://blog.privacyguides.org/2022/07/07/signal-configuration-and-hardening#privacy-and-security-features). It also has usability improvements including scheduled backups, automatic locking, and the ability to use your Android phone as a linked device instead of the primary device for a Signal account.
|
||||
**Molly** is an alternative Signal client for Android which allows you to encrypt the local database with a passphrase at rest, to have unused RAM data securely shredded, to route your connection via Tor, and [more](https://www.privacyguides.org/articles/2022/07/07/signal-configuration-and-hardening#privacy-and-security-features). It also has usability improvements including scheduled backups, automatic locking, and the ability to use your Android phone as a linked device instead of the primary device for a Signal account.
|
||||
|
||||
[:octicons-home-16: Homepage](https://molly.im){ .md-button .md-button--primary }
|
||||
[:octicons-eye-16:](https://signal.org/legal/#privacy-policy){ .card-link title="Privacy Policy" }
|
||||
@@ -92,13 +92,9 @@ If you use Android and your threat model requires protecting against [:material-
|
||||
|
||||
</div>
|
||||
|
||||
Molly is updated every two weeks to include the latest features and bug fixes from Signal. The exception is security issues, which are patched as soon as possible. That said, you should be aware that there might be a slight delay compared to upstream, which may affect actions such as [migrating from Signal to Molly](https://github.com/mollyim/mollyim-android/wiki/Migrating-From-Signal#migrating-from-signal).
|
||||
|
||||
Note that you are trusting multiple parties by using Molly, as you now need to trust the Signal team *and* the Molly team to deliver safe and timely updates.
|
||||
|
||||
**Molly-FOSS** is a version of Molly which removes proprietary code like the Google services used by both Signal and Molly at the expense of some features (like battery-saving push notifications via Google Play Services). You can set up push notifications without Google Play Services in either version of Molly with [UnifiedPush](https://unifiedpush.org). Using this notification delivery method requires access to a [MollySocket](https://github.com/mollyim/mollysocket) server, but you can choose a public MollySocket instance for this.[^3]
|
||||
|
||||
Both versions of Molly provide the same security improvements and support [reproducible builds](https://github.com/mollyim/mollyim-android/tree/main/reproducible-builds), meaning it's possible to confirm that the compiled APKs match the source code.
|
||||
Molly provides support for [reproducible builds](https://github.com/mollyim/mollyim-android/tree/main/reproducible-builds), meaning it's possible to confirm that the compiled APKs match the source code.
|
||||
|
||||
## SimpleX Chat
|
||||
|
||||
|
||||
@@ -179,7 +179,7 @@ As an end user on a public homeserver, you can consider unchecking the **Enable
|
||||
|
||||
- [ ] (Optional) Uncheck **Record the client name, version, and url to recognize sessions for easily in session manager**
|
||||
|
||||
Unchecking this option may make it more diffcult to discern your active sessions if you logged in to your Matrix account on multiple devices.
|
||||
Unchecking this option may make it more difficult to discern your active sessions if you logged in to your Matrix account on multiple devices.
|
||||
|
||||
#### Encryption
|
||||
|
||||
|
||||
+1
-1
@@ -76,7 +76,7 @@ We also think it's better for the security of the VPN provider's private keys if
|
||||
|
||||
#### :material-check:{ .pg-green } Independently Audited
|
||||
|
||||
Independent security researcher Ruben Santamarta conducted audits for Proton VPN's [browser extensions](https://drive.proton.me/urls/RWDD2SHT98#v7ZrwNcafkG8) and [apps](https://drive.proton.me/urls/RVW8TXG484#uTXX5Fc9GADo) in September 2024 and January 2025, respectively. Proton VPN's infrastrcture has undergone [annual audits](https://protonvpn.com/blog/no-logs-audit) by Securitum since 2022.
|
||||
Independent security researcher Ruben Santamarta conducted audits for Proton VPN's [browser extensions](https://drive.proton.me/urls/RWDD2SHT98#v7ZrwNcafkG8) and [apps](https://drive.proton.me/urls/RVW8TXG484#uTXX5Fc9GADo) in September 2024 and January 2025, respectively. Proton VPN's infrastructure has undergone [annual audits](https://protonvpn.com/blog/no-logs-audit) by Securitum since 2022.
|
||||
|
||||
Previously, Proton VPN underwent an independent audit by SEC Consult in January 2020. SEC Consult found some medium and low risk vulnerabilities in Proton VPN's Windows, Android, and iOS applications, all of which were "properly fixed" by Proton VPN before the reports were published. None of the issues identified would have provided an attacker remote access to your device or traffic. You can view individual reports for each platform in their dedicated [blog post](https://web.archive.org/web/20250307041036/https://protonvpn.com/blog/open-source) on the audit.
|
||||
|
||||
|
||||
@@ -5,6 +5,7 @@
|
||||
*[attack surface]: The total number of possible entry points for unauthorized access to a system
|
||||
*[AVB]: Android Verified Boot
|
||||
*[cgroups]: Control Groups
|
||||
*[C2PA]: Coalition for Content Provenance and Authenticity
|
||||
*[CLI]: Command Line Interface
|
||||
*[CSV]: Comma-Separated Values
|
||||
*[CVE]: Common Vulnerabilities and Exposures
|
||||
@@ -48,6 +49,7 @@
|
||||
*[IPv6]: Internet Protocol version 6
|
||||
*[ISP]: Internet Service Provider
|
||||
*[ISPs]: Internet Service Providers
|
||||
*[IPTC]: International Press Telecommunications Council
|
||||
*[JNI]: Java Native Interface
|
||||
*[KYC]: Know Your Customer
|
||||
*[LLaVA]: Large Language and Vision Assistant (multimodal AI model)
|
||||
@@ -107,6 +109,7 @@
|
||||
*[VLAN]: Virtual Local Area Network
|
||||
*[VoIP]: Voice over IP (Internet Protocol)
|
||||
*[W3C]: World Wide Web Consortium
|
||||
*[XMP]: Extensible Metadata Platform
|
||||
*[XMPP]: Extensible Messaging and Presence Protocol
|
||||
*[PWA]: Progressive Web App
|
||||
*[PWAs]: Progressive Web Apps
|
||||
|
||||
Reference in New Issue
Block a user