Live data from Hacker News

Alternatives to Google Products

restoreprivacy.com

291–300 of 527 posts

Re: Alternatives to Google Products

#291

Earlier quoted context omitted.

He's telling you about the fact that there's conflict of interest between you and crapple and you tell him an anecdote where some scum of this earth stole money and open source software was involved. Does this really sound like a compelling argument?

Yes. There are bad and good actors on all sides. Just because something is closed source doesn’t make it bad. And just because something is open doesn’t automatically make it good.

Agreed. But what can we infer from this? Let's suppose "good" refers to "privacy respecting", with regard to users.

The primary difference is that closed source cannot feasibly be determined to be good. This is an inherent property of being closed -- we, as the users, have no proper access to investigate the actions performed by the program.

Open source software can, potentially, be classified as privacy respecting. As others have mentioned, this is not a trivial task. It requires significant contributions from the community to audit the code perpetually. We cannot exercise complacency here and presume someone else has already performed this action on our behalf.

(Tangent: Perhaps we need to develop a system to keep track of which sections of which open source projects have been audited, and by whom. A list of volunteer auditors for each source file on a GitLab repository, for example? With each audit being associated with a hash/commit for that file. In the current model, reading the code without finding any privacy concerns means no commit. Whether there is value in keeping track of this occurrence and leveraging it to conclude an increase in trustworthiness of the project is both a philosophical and practical question.)

So being open source does not magically make software more privacy respecting. But it does open the door, and invite us to investigate its claims and behavior; something that closed source does not. It's our responsibility to capitalize on that advantage.

Considering the current state of privacy violators and malicious actors in this industry, a "guilty until proven innocent" approach might be the most pragmatic. This is not a form of scaremongering; this skepticism applies to both closed and open source software equally, contributing to a solid foundation of good OpSec and assisting to shape the industry into more ethical business models.

Re: Alternatives to Google Products

#293

> All they do is repackage mass corporate surveillance into convenient, free, trendy applications that suck up all your data. Your private data helps Google dominate the online advertising market. Google has what I think are the most transparent and user friendly controls for visualizing what personal data is collected, and disabling it (most often per product, for ex. disable location history and YouTube viewing his…

1. Please ask BEFORE you collect.

2. You can't expect every user to know they are logged, or how it's affecting the user, or know how to disable/delete it, can you?

3. How can I verify that you did delete the data about me instead of just hiding from me for viewing it? Alphabet is not belong to public sector. So the simple answer is I can't. If you want me to trust you, don't use opt-out as default.

4. I'm sure you can tell the differences between those alternatives and Google products.

5. It's not that hard to respect some one's data. First, do not collect it! Second, if you have to collect it, tell the owner why! Third, delete it completely while requested.

6. Aggregated data collection and use without permissions adds potential risks to the society. (Cambridge Analytica)

Edit: And you guys are doing deep learning, that's gonna consume lot's of data. Duplex for example, you use anonymous phone call data to train it. The question is, where does that data even come from? I'd blacklist whoever collected the data, even it's collected anonymously.

Re: Alternatives to Google Products

#294

> All they do is repackage mass corporate surveillance into convenient, free, trendy applications that suck up all your data. Your private data helps Google dominate the online advertising market. Google has what I think are the most transparent and user friendly controls for visualizing what personal data is collected, and disabling it (most often per product, for ex. disable location history and YouTube viewing his…

I don't work at Google, I live in Europe and I agree with you. So far, we didn't heard of any breach in any Google product, and the history of the different products can effectively be turned off. I remember years ago, when I started to care about data collected about me, Google was one of the first company allowing you to download a part of your data. We can see the emphasize about security on the evolution of Android APIs too (encrypted enclaves, key storages, for example). Google also contributes to open AI and ML researches. My only consumer concern is about monopoly, not about data collected on me.

Re: Alternatives to Google Products

#296

Earlier quoted context omitted.

Apple makes its money from expensive hardware. And respecting your privacy and security helps selling it a lot . And they earned trust by being serious about it for a long time.

Apple actually had some of the worst security for a long time. They even lied about Mac OS being immune to viruses rather than market share so low hackers didn't care about it. They still made piles of money due to great product development and marketing. Their brand was the main, selling point for a long time. The iOS situation is quite a turn around for them on privacy/security. They still sell them on mainly image…

Pre OS X versions of Apple OS had even smaller market share and way more viruses than current versions with much bigger market share.

Re: Alternatives to Google Products

#297
post #293

> All they do is repackage mass corporate surveillance into convenient, free, trendy applications that suck up all your data. Your private data helps Google dominate the online advertising market. Google has what I think are the most transparent and user friendly controls for visualizing what personal data is collected, and disabling it (most often per product, for ex. disable location history and YouTube viewing his…

1. Please ask BEFORE you collect. 2. You can't expect every user to know they are logged, or how it's affecting the user, or know how to disable/delete it, can you? 3. How can I verify that you did delete the data about me instead of just hiding from me for viewing it? Alphabet is not belong to public sector. So the simple answer is I can't. If you want me to trust you, don't use opt-out as default. 4. I'm sure you c…

> 6. Aggregated data collection and use without permissions adds potential risks to the society. (Cambridge Analytica)

Everything adds "potential risks". When you talk about risk, you have to give estimates of both the frequency and the criticity, and then compare to the potential benefits. Only then you have all the pieces to take an informed decision, according to your preferences.

Re: Alternatives to Google Products

#298
post #230

Hi all, I'm an engineer working on Firefox Platform (Gecko). In the linked blog post, the author recommends Firefox (thanks!) and links to a "privacy recommendations" for it, which include items such as "resistFingerprinting" settings. I'd like to remind everyone that turning on this setting has far fetched consequences to how you experience the Web. Your dates, timezones, preferred languages will all be masked which…

Is there a moderate resistFingerprinting setting? I don't mind my date/tz/language being known. There are 150m+ people living in my timezone who use en-US. I don't want my fonts, plugins, user agent, or detailed HW/graphics features (e.g. canvas/WebGL hash) being known. Those can uniquely identify me according to https://panopticlick.eff.org .

That https://panopticlick.eff.org link was interesting, but I don't see what about my user agent string makes it so unique (1: 76540.09) ?

  Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.62 Safari/537.36
Looks fairly generic, I think I'm running a mainstream chrome browser on a mainstream OS.

Re: Alternatives to Google Products

#299

Earlier quoted context omitted.

I think the average worst thing that could happen is that you end up going to court against someone (since we are thinking about averages, I'm thinking divorce), they obtain your data, and use that to build a case against you. If you were cheating, for instance, your location info could be used to show all your meetings in quite some detail. And even if you weren't, you can always bend your stats a little bit to make…

So how would this happen? Google gives them my data? I'm sorry but I don't get it. Google can't do that. Even if they work at Google they can't get it. I just represented myself in a week long custody trial (I won primary custody, and yes I went up against an attorney), and there were lots of risks involved, but this sort of thing seems to be about the smallest one I could imagine. I'd like to hear if this has actual…

> Google can't do that. Even if they work at Google they can't get it.

I'm not sure I understand this point, so let me make my point clearer. It's clear that Google(TM) can access your data. You probably mean "most google employees can't", which I agree with. But someone can access your data for sure, and in fact you can access your data: if you are a European citizen, you can request all of your data right now, thanks to the GDPR and Google has to comply. There are also other general tools to access the data[1].

So I'm not saying "a Google employee will go behind your back". I'm saying that either "Google(TM) could be compelled by a court order to give your data if laws change", or "someone could use your unlocked PC, click on 'Download my data', and give it to the other part" (again, more likely if the other part is tech savvy and planning on divorcing you).

> I'd like to hear if this has actually happened to anyone anywhere.

Someone getting in trouble because someone took their private information? It happens quite often in the Legal Advice subreddit. Here's one example[2]:

> "My wife uploaded screenshots from my Ashley Madison account, hotel receipts and non-nude but sexual photos of me online before she moved out and filed for divorce. Do I have any legal recourse under Delaware law? (...) They were not public. The photos were from my phone and were not anywhere online and the credit card was in my name only. She had no right to access either one (nor my Ashley Madison account)."

My specific case? No idea. But supposedly private information biting someone back is a regular event. Here's a page some lawyers in Orange County wrote on that [3] with some examples.

* Edit: rethinking my point, I think you meant "how is this a Google problem, rather than an infosec problem". To that, my point would be: the fact that the information exists forever in one central place.

[1] https://medium.com/productivity-in-the-cloud/6-links-that-wi...

[2] https://www.reddit.com/r/legaladvice/comments/5b895c/my_wife...

[3] http://orangecountydivorce.com/divorce-technology/

Re: Alternatives to Google Products

#300
I tried. However

- On Mailbox.org I receive spam. Lots of it. Why? Because they don’t look at message contents in their spam filter. Privacy, remember?

- On other search engines, I don’t find what I’m looking for. Not even remotely.

- Firefox Dev Tools suck. You have to test across all browsers anyway.

In the end, I will keep using G Suite. There is simply no equal alternative, with my own domains for mail and whatnot.

Post reply on HN