Live data from Hacker News

How to Avoid Leaving Tracks Around the Internet

nytimes.com

61–70 of 108 posts

Re: How to Avoid Leaving Tracks Around the Internet

#61

> Nearby patrons, using their phones or laptops, can easily see everything you’re sending or receiving — email and website contents, for example — using free “sniffer” programs. Is the author assuming the absence of https encryption here, or is there some widely available exploit I don't know about?

mitm for weak https exists

All "antiviruses" use it

Re: How to Avoid Leaving Tracks Around the Internet

#62
post #51

Install uMatrix and block all 3rd party JavaScript. It breaks functionality in some sites that embed social networks' widgets, but other than that works like a charm. As a bonus sites load at least 30% faster.

Exactly my experience, going on 3 to 4 years now. Spend the time to learn uMatrix. It's an incredible investment into yourself and your web experience. I barely browse on mobile anymore since I don't have uMatrix, although Brave does allow blocking scripts and some stuff quite easily. Highly recommend Brave on mobile.

Re: How to Avoid Leaving Tracks Around the Internet

#63
post #11

-Use a private cloud, so that your data is in your control. We've actually developed a self-hosted private cloud solution as a substitute to Dropbox for exactly these reasons. Basically a private Dropbox at home (no complicated installation and no server needed) We're currently in beta, could interest a few in this thread! https://www.duple.io/en/ The point is to have a product that works just like a Dropbox, as simp…

Somehow I don't understand how you say Syncthing's disadvantage in comparison is that it's a P2P system[1], but at the same time your website says duple doesn't need a server. Maybe I've misunderstood, but this sounds just like Syncthing with an always-on client - except for the file versioning, that sounds like an interesting feature to me. [1] https://blog.duple.io/what-is-the-point-of-duple/

Agreed.

I've been using SyncThing for over 4 years and while it has a few rough edges (synced/shared/global file ignore would be great) still it's been fully reliable and a generally great user experience. So if you're trying to cater to existing SyncThing users don't mince words to make it appear that something which you claim is a negative with SyncThing doesn't exist in your product - which it clearly does.

SyncThing has a huge advantage: years of trust. They have been around since 2013 and continue to crank out features and builds consistently. Duple hasn't been around for one year at the time of this writing. Beyond that it's clear from the Duple site that it's main goal is to take my data and file replication hostage via licensing fees. I'm curious how or why I'd donate before I've even installed the Beta (based on your click flow to even reach the downloads page)? No thanks.

Also, let's clarify something Duple has wrong...

Duple states: "Syncthing is P2P, so you get the disadvantages along with it e.g. all your devices need to be turned on at the same time. If not, you get a desynchronisation between your devices and create conflict." - This is wrong. You do not need all your devices on at the same time with SyncThing. Yes, it is true that it's good to have a device with a consistent state, however it's not required. The second part of the statement is FUD. When conflicts happen it's generally around odd permissions or file updates with regard to versioning. This was more problematic in versions prior to 1.0. At this point in time I haven't run into this issue other than because of disparate problems caused by file permissions which SyncThing does a great job preserving.

Duple also states SyncThing has no IOS support and yet, itself, has neither IOS or Android. Or Windows... Or an open source repo of what I'm supposedly using.

In my mind Duple doesn't compete with SyncThing and, really, never will. But here's the thing... Don't pretend to compete where you don't. SyncThing users aren't looking for Duple. You'd do yourself a better service to take that verbiage out because all it did for me was give me the impression that Duple is lying about competitors that they simply didn't take the time to understand. That leaves a bad impression in my mind.

Re: How to Avoid Leaving Tracks Around the Internet

#64

> If you’re in that category, Ms. Winterton recommended Ghostery, a free plug-in for most web browsers that “blocks the trackers and lists them by category,” she wrote. I’m not sure I can recommend Ghostery, as their business model is a bit suspicious: https://en.wikipedia.org/wiki/Ghostery#Criticism > Using websites whose addresses begin with https are also safe; they, too, encrypt their data before it’s sent to you…

After Apple destroyed safari extensions and forced everyone to use declarative net requests, there are few options. I’m pretty sure Ghostery is now unable to perform the analytics or data collection from previous versions. KaBlock and others are worth trying. There are few options, so I’ve settled on Ghostery for safari on macOS

Re: How to Avoid Leaving Tracks Around the Internet

#65
post #55

> If you’re in that category, Ms. Winterton recommended Ghostery, a free plug-in for most web browsers that “blocks the trackers and lists them by category,” she wrote. I’m not sure I can recommend Ghostery, as their business model is a bit suspicious: https://en.wikipedia.org/wiki/Ghostery#Criticism > Using websites whose addresses begin with https are also safe; they, too, encrypt their data before it’s sent to you…

Anyone can got your phone number from fb, which fb "use" for 2fa You should stop printing nonsense

Me, personally?

Re: How to Avoid Leaving Tracks Around the Internet

#66

Is this the level of technical competency needed to work at the New York Times? How much do they pay?

Well, they just made their director of infosec redundant, so it seems the answer is yes.

https://twitter.com/runasand/status/1186775481615605760?s=20

Re: How to Avoid Leaving Tracks Around the Internet

#68
The omission of "Disable third party cookies" is fairly shocking. From my understanding, it might be the single most effective thing you can reduce tracking. Whenever I get the chance, I recommend the following pieces of Internet hygiene to anyone and everyone I can:

* Disable 3rd party cookies

* uBlock Origin

* Privacy Badger

* HTTPS Everywhere

These things are all dead simple and will significantly reduce your trackability. Of course they are far from comprehensive or perfect, but it's the Internet equivalent of washing your hands after you go to the bathroom.

Re: How to Avoid Leaving Tracks Around the Internet

#69
post #33
post #9

Earlier quoted context omitted.

Oh companies have become smarter about it! Even the scammers I suspect! Many won’t accept + in the email address and I think now it’s well known enough that most scammers will run a regex to detect and remove the + sign. Useful workaround is to have unique aliases on a domain name you control. Can’t get around that with a minute of work!

fastmail supports a variation of this: if my email is me@mydomain.com, then I can use service+me@mydomain.com, or better service@me.mydomain.com (or anything@me.mydomain.com). It seems like it'd be a little less obvious to scammers.

Yes, it’s a great feature! They also have many non-fastmail.com domains available on the basic plan.

Re: How to Avoid Leaving Tracks Around the Internet

#70

The omission of "Disable third party cookies" is fairly shocking. From my understanding, it might be the single most effective thing you can reduce tracking. Whenever I get the chance, I recommend the following pieces of Internet hygiene to anyone and everyone I can: * Disable 3rd party cookies * uBlock Origin * Privacy Badger * HTTPS Everywhere These things are all dead simple and will significantly reduce your trac…

Won’t disabling third-party cookies render certain payment gateways unusable? While such advice may be very welcome among savvy computer users who know when they should temporarily turn third-party cookies back on, the NYT is unlikely to give advice that will break online shopping for large numbers of people.
Post reply on HN