Earlier quoted context omitted.
HTTPS still reveals the domain you're requesting, last I checked.
The eSNI/ECH extensions fix that.
I don't know where things stand with other browsers.
611–619 of 619 posts
Earlier quoted context omitted.
So if I tell a friend a secret, and they plaster it on my wallpaper, and then I have a different friend over for dinner, my different friend is the one violating my privacy?
In that case no-one has violated your privacy - your wallpaper is private, so friend A didn't, and you invited friend B over, so they definitely didn't. I would entertain the idea that friend A is being a bit of a douchebag by painting stuff all over your house without you asking them to, but if you subscribe to that thought process you'd already be running an ad-blocker and this scenario wouldn't ever occur in the f…
Earlier quoted context omitted.
You can't be compelled to incriminate yourself, but your server provider can very much be compelled to give access to the server. And once the server is physically compromised the battle is lost, anyway, but in that case probably with a larger papertrail leading to you. One expensive but possible option would be to build a server yourself with sufficient traps to shut off when it's tapered with. Then set it up with f…
> .. and put it in a shared rack What would be the benefit of being in a shared rack? Wouldn't the service provider still know which physical system is yours if you only rented a 1/2/3U space? (Or is there an advantage at a network layer?)
Going for a rack has the advantage that you own the hardware and can install the anti-tamper measures so that the server can't be turned against you. Anonymity wise, renting a server makes things a lot easier.
Earlier quoted context omitted.
> The act of analyzing my data is what is the violation. So to be 100% clear on this: if you tell someone information, and they think about that information, that's a violation of your privacy? I've definitely always assumed that the right to think about information is intrinsically coupled with the right to know about that information. I wouldn't give someone data that I didn't want them to think about. > for possib…
>So to be 100% clear on this: if you tell someone information, and they think about that information, that's a violation of your privacy? If your phone began analyzing your local photos for child porn, you'd probably be upset, no? >This is a completely reasonable concern to hold, but surely "they could possibly do something bad later" applies to every email provider in existence. True, but google is CURRENTLY abusing…
Yep. "local" here is the key word, though. If a service I uploaded photos to began doing that, I would not be upset. And indeed, just about every image-hosting website in existence already does this, because they're legally required to.
Gmail is markedly not a local service.
> True, but google is CURRENTLY abusing it by selling ads to me based on it.
This makes it seem like your concern is with the advertisement funding model, not with privacy.
Earlier quoted context omitted.
That's fine in my "paying ProtonMail customer" view. Use VPN + Tor if you don't want your IP address be known. I use ProtonMail to reduce my exposure to Google tracking/possibility of business execution leaks they might use in their favor and keep alternatives alive.
So does any non-Google email provider meet your criteria then?
Earlier quoted context omitted.
Don’t those binaries come with signatures you can verify? People in the community would notice if building from source produced different signatures than the binaries provided directly by torproject
In practice the USG would not distribute malevolent binaries everywhere, but could target them to particular IP- and time-ranges. Downloading Tor from a particular IP in Iran? We'll add a little something extra... Or maybe you're a US citizen with a set of known IPs on a "watchlist".
Earlier quoted context omitted.
Were _you_ mislead by this? Did you really expect a Switzerland-based company not to comply with law of the land? There is a difference between "available to police, not retroactively, and only with a valid warrant" and "available to any government agency constantly and in bulk, as well as to data-collecting commercial entities, Russian and Chinese hackers, and their dogs". Don't you agree?
Wouldn't they have to comply with a secret data collecting order? We are trusting they wouldn't comply or no one would make that request?
This is the benefit if being located in Switzerland, where banking is one of the main pillars of the economy and which historically has been much more supportive of personal privacy than most other countries.
They eventually caved under US pressure on some things, so it's not such a "haven" as it used to be, but I believe it is still the country that respects individuals' rights the most.
Not perfect by any means, just better than most others.
Earlier quoted context omitted.
You think nobody can tap phone records, when you called someone outside India? Oppressive government?
ah yes. unless they are actively listening in am i not safe enough as compared to DPI censorship and network analyzers mandated by the said oppressive government?