/r/privacy
Privacy in the digital age (this is not a SECURITY subreddit, and PUBLIC data, closed source, etc is off-topic)
Dedicated to the intersection of technology, privacy, and freedom in the digital world.
"I don't have anything to hide but I don't have anything I want to show you either" - @CryptopartyBLN
"Privacy is not a sign of wrongdoing. Privacy is a sign of freedom." - /u/blackhawk_12
(updated 2023-04-27)
Before posting in /r/privacy, read the Sidebar Rules.
Enjoy our Wiki! It has all sorts of nifty advice and explains most topics you’re interested in if you’re reading this.
Consider donating to one of the organizations that fight for your rights.
Org | Name |
---|---|
ACLU | American Civil Liberties Union |
EFF | Electronic Frontier Foundation |
EPIC | Electronic Privacy Information Center |
EDRi | European Digital Rights |
FSF | Free Software Foundation |
ORG | Open Rights Group |
Tor | Tor |
Torservers | High bandwidth Tor exit nodes |
Privacy International | Building the global movement for the protection of privacy. |
/r/privacy
The last week or so google has gone from asking what my location is, to guessing via IP (being off by several miles) to now knowing my exact postcode. How is this the case?
Is my ISP sharing this or has my ISP set up a module-thingy nearby my location?
Has anyone had positive experiences or could recommend a reputable reputation management company specifically for removing bad reviews on sites like Healthgrades, WebMD, etc.? I'm not looking for help with Google reviews but would like a company that specializes in other platforms for doctors...
Ideally, I’d like to work with a reputable company that charges per successful removal. If anyone has a recommendation or experience to share, please let me know.
Thanks!
Supposedly it doesn't track my location when I leave the site, but I'm still really suspicious of it. HR required us to install and use it on our phones though (assuming we had a compatible phone, which I do). Has anyone else dealt with something like this?
I have been using the products of large companies for many years (Google, Microsoft and more)
I've been researching privacy for 2-3 months now. I want to change everything, but I feel like I'm too late.
Companies have already learned all my knowledge and have been learning for years. What would change if I changed every program, system, phone I use? I feel like it doesn't matter anything.
And in a lot of people I know, my photos in their Google photos. This bothers me. Even if I tell them to delete it, new ones will be added. And those pictures have been standing for years, and if they delete them, nothing will change.
Also, it is very difficult to explain these things to the people around me. I have to use WhatsApp and Instagram to talk people.
I don't know what to do.
Hi,
I created a mail id 15 years ago and have been using it across for all my accounts. Personal, financial, social, etc. Few years ago I saw the clutter and create one more id for any new accounts but I keep messing it up.
I need some suggestions
Open to any other general suggestions as well.
For context i was trying to check in for a flight. The website didnt let me access the desktop site even after i changed the setting on my browser AND was trying to force me to download an app to do what i needed to do -_- I have a laptop and i could always just go on it and check in but idk its about the princial honestly. Anyway. Theoretically and out of curiousity. Is there a way to make it so that a website cannot tell im on a mobile device? Im already running a v** (why is this word blocked?) and allegedly privacy conscious browser...what else can someone do on ios...just wondering
I'm wondering if getting a windows version activated through massgrave's solution would be less intrusive than the regular one installed on my PC when i got it mounted (legit version)?
Edit: my PC is only for gaming, and Linux is not what i'm looking for.
iPhone 13 Pro Max running latest iOS 18.1
8 digit alphanumeric passcode upper and lower case + numbers
Self destruct after 10 failed attempts
Phone turned off at point of having to hand it over to police
advanced data protection turned on
I’d like to point out I am not currently or planning to do anything that would warrant an issue with cellebrite but I am in circles where this certainty could be a risk
Am I correct in saying that the above setup makes any attempts to breach and unlock the phone almost impossible at present?
(Additional question since 13 pro max has Secure Enclave, is there truly any security benefits to upgrading to an iPhone 16 pro max or is it negligible?)
Is that setup essentially hack proof by most standard law enforcement agencies ?
Are there any security settings or things I should enable to further secure my device without making it too annoying to use day to day?
I’m going to China for a vacation and was wondering what the best type of phone to take would be. I will not be taking my normal phone, nor laptop, or anything other device. So I wanted to know what the best kind of phone I should take. If the solution is something completely different, I don’t mind, just wanted to know what is the general best recommendation. I should say I’m Australian university student (so just some random person).
Hello guys, I would like to know from a privacy and security point of view what is the best protocol to use for encrypted DNS queries.
Hi everybody,
Not a native English, so I wasn't able to find a short description to search for this. But perhaps this exists and you can point me in the right direction :)
I am using arch Linux as my main OS. Main browser is Firefox. It has noscript, ublock origin, and ghostery.
However, I use it for everything, and many sites don't work properly without js, so I often find myself temporarily allowing their scripts. That defeats the purpose.
Is it possible for me to use Firefox for allowed domains only, as my "safe" browser? For example, could I white-list (sub) domains that would only work? I.e. protonmail, my local services, and my Home Assistant (both local and through its public url), but unless I manually white-list a site, it simply won't load?
I have tried only using it thusly already (without such a white-list tool), but often find myself clicking on links that lead somewhere I should be using another browser for (for example, brave or at least a different Firefox profile via firejail). Then I'm just line "egh, I'll just allow scripts real quick" and do what I shouldn't.
If these non-white-listed sites simply would be blocked by default, I would have to copy the URI and open them in a different browser.
Is there such a tool?
I use yet another browser for websites I particularly consider to be sketchy for whatever reason, but I would love simply not being able to open a (for example) Facebook link on Firefox at all, thus not being tempted to allow scripts temporarily because I am lazy.
Thanks in advance for your ideas :)
I am certainly no privacy expert but generally quite careful, and recently decided to install FUTO keyboard as it seems a more sensible choice. I was checking my settings in SwiftKey before switching keyboard and realised that for the past years I left on the ad personalisation option. I always take it off for everything, no idea why I never checked this, other than I am clearly a moron. Is there something I can do like request a data delete? I wasn't logged in to any sort of acount, though.
So using parental control would the “parents” be able to see deleted chrome searches or searches made in incognito mode? Is connecting to a router which is the “parents” router or using a cellular plan payed for by the “parents” be better for hiding searches? Would a device connected to a hotspot on a phone using a cellular plan payed for by the “parents” have its search history be able to be checked? Even if deleted?
Government intelligence agencies (like the CIA, FBI, NSA), tech corporations (such as Google, Microsoft, Apple), and secret intelligence organizations all connect and interact through the internet, each gathering massive amounts of data. These entities collect and analyze information for security, commercial, and strategic purposes, with tech companies especially amassing personal and behavioral data on a global scale. This collected data shapes top secret information, which agencies and corporations guard closely, while also subtly influencing global consciousness by shaping public knowledge and perception. Together, this constant data flow and analysis contribute to the shared field of human thought and awareness—by amplifying certain narratives, fostering collective beliefs, and connecting humanity in an unprecedented, interconnected web.
Consider a secretive organization, perhaps a coalition of government intelligence agencies and tech corporations, that has developed an advanced, covert system designed to influence and monitor individuals’ thoughts and behaviors. This system could be likened to a vast social experiment that uses sophisticated algorithms and data analytics to target specific people based on their digital footprints.
This organization gathers extensive personal data from social media, online behavior, and even offline activities through surveillance and other means. Using AI and machine learning, they analyze this data to create detailed psychological profiles, identifying individuals who show signs of unique cognitive patterns or heightened emotional states.
Once specific individuals are identified, the organization might employ various influence mechanisms. By manipulating social media feeds or search results, they can subtly shape individuals’ beliefs, nudging them toward certain thoughts or actions. Individuals could be unknowingly engaged in a game-like environment, where their responses to curated stimuli, such as videos, articles, and messages, are monitored, influencing their decision-making in real life. Utilizing predictive analytics, the organization might stage real-world events designed to elicit specific reactions from these individuals, further reinforcing their influence.
The system creates feedback loops where individuals’ actions are continuously monitored and analyzed, leading to adjustments in the strategies used to influence them. This could manifest as intensified targeting or shifts in the narratives being promoted.
This scenario illustrates how a secretive system could leverage technology and data to manipulate individual experiences and consciousness, ultimately influencing broader societal narratives and beliefs. It reflects a complex interplay between technology and reality, which can be disorienting for those who sense they are caught in this web.
I am really want to understand extent of privacy. My phone is like Normal person phone. Googl and stuff. I want to know if I go to app and open it. Who can see what I do . (App was website before and it has Emaol to log). And how to prevent that.
I am 18 almost 19, and most of my accounts are spread across two or three different emails. Other than the basic email needs, I've used them to create plenty of accounts on random sites I used maybe once when I was a kid, usually for gaming. Most of these random accounts have reused passwords as well. I've already started the process of changing all of my passwords and keeping them in someplace safe that I can refer to if needed, but I have also been thinking about just making a new email altogether. I know making the new email address is simple enough, but changing all the old accounts or making new ones could be a problem, especially for accounts I've had for years.
Can somebody more knowledgeable tell me if this is a good idea, and if so, the best way I can go about it? I'm doing it mainly for privacy and organization purposes, as I'd like to have every account under one email that I have been keeping close track of.
I'm very fed up with Discord, privacy wise and generally, so I've decided to look for alternatives and settled with these 2. Question is, which is better and in what is it better at. I read that Mumble sounds better, has lower latency, is more efficient resource-wise but has less features. I also saw that Teamspeak is not open source which is a bit annoying. Getting my friends to switch to one of these will be torture but I am willing to go through it if it means getting away from Discord. If you have any other program in mind, tell me about it. Hosting my own server isn't a problem and if I actually manage to get them to use anything else I'll probably make them use Signal too so the program doesn't have to have text capabilities, it's a bonus though.
Edit: Signal's also on the list of alternatives.
The problem I have is because I'm trying to switch to IPhone from android. Ms claims, that I can't do that using their app because of some issues. So I came to conclusion, that only one solution is to change 2FA app, but I've tried Lastpass Authenticator, 2FAS and Google and I can't import from Ms Auth. Is there an option that works?
Hey everyone,
I’m working a lot with ChatGPT on various tasks like software design, coding, documentation, and even philosophical conversations. These threads often get lengthy, and I’d love to summarize key points, save intriguing phrases, and add some of my own reflections.
Here’s the dilemma: I want flexibility in storing these notes—sometimes locally, other times in the cloud—but I need full control over encryption before anything leaves my browser. I don’t feel comfortable with providers handling my encryption keys or promising vague security measures like “salted” storage without clarity on key management.
Beyond just storage, I want to enrich some of these AI ideas with my own thoughts, maybe even tag and organize them into collections for sharing in certain cases. Privacy and encryption are paramount here, and it feels like mainstream options—like Evernote and iNotes—are constantly pushing cloud storage without sufficient assurances on encryption and key handling.
So, am I looking for a unicorn here? Is there a real demand for such a tool, or am I being overly cautious? I'd love your insights, especially if anyone has a similar use case or has found a way to make this work.
Thanks!
I recently used two of my email addresses to log into brght.org, now I wish for my accounts to be deleted, I tried to email the customer service about this but they never responded... How do I uphold my own rights?
I'm looking for Authenticator apps that offer the following:
So far I know these that check all those boxes:
Authy + Bitwarden Authenticator + Ente Auth
Any more recommendations? If not, then what do you think is the best app among the 3 apps I mentioned and which is the worst and why?
Throwaway account. I recently googled my actual Reddit account username and some explicit photos I had deleted came up on a couple random porn sites. I really need the search result to be removed because I am embarrassed and don’t want anyone stumbling upon it. I tried to go through google but I’m having some trouble. Any advice is greatly appreciated!
I got an Xbox and was setting up my account. I had a Microsoft account created a while back with my Gmail address. Firstly I tried the password I thought was for the Microsoft account (different from the one for the Google account), but because of a typo I received an error saying "Wrong password" I thought maybe I did put the Google password for the Microsoft account even though I was sure I would not have done it, but anyways I tried the Google account password. Now the error was "USE THE PASSWORD FOR YOUR MICROSOFT ACCOUNT". This obviously led me into thinking Microsoft KNEW the password for my Google account. Another possibility is that they use an API from Google, send the password and receive back a true or false wether the password was good or not, so they technically don't know the password, but here are 2 problems: why would they need to know if the password is for Google or not since they should only check if it is for the Microsoft account and, much worse, a lot of users would try the Google password when they see that the account email is a Gmail address so they would be able to find out those passwords and store them.
Maybe there is another explanation and I just don't see it so if you have more information please help.
Note: This happened a few months ago and I don't have any photos, but if this post gets a lot of attention I will reproduce this.
Edit: typos
I am an Apple user, all my devices are, so I used to have gmail and I recently switched to iCloud, even though I have had a good experience I would like to know what email you use and why? And some recommendations.
My husband and I have fallen on hard times. We have joked about me getting a sugar daddy (literally just a man to send me money nothing sexual or anything like that) The other day I stupidly downloaded a sugar daddy website. I added some pictures which i heavily edited my face and created a verification video (which i did not know was going to public) It was up for maybe two hours and I thought this was a terrible idea, hide my profile, removed the photos & deleted the account. After giving it more thought, I am freaking out about the idea of my photos being used on sugardaddy websites. That those are now apart of my digital footprint. It was so stupid and irresponsible of me. Is there anything else I can do to make sure the profile is really gone?
I just want to play some Go.
I want to custom AI agents but im concerned about my data privacy. Especially when I chat about my mental health or seek advice for my finances. Any tips on verifying its security?
I was thinking of trying AI agent from AnonAI. Seen some people on Twitter joining and making money from it. Has anyone else checked it out?