Live data from Hacker News

Prism Break

prism-break.org

21–30 of 205 posts

Re: Prism Break

#21
Its kinda nice of a list thanks :) I'd add here.com as proprietary maps. Its actually pretty good. yes its proprietary - but even having proprietary alternatives is good.

oh also gallery3 should probably be in there.

Re: Prism Break

#22
post #14

Earlier quoted context omitted.

> None of the proprietary browsers will track you. Can you elaborate a bit on this, how do you know they won't? My default assumption is that anything I can't see the source code of and compile myself is compromised.

Sociologically: there is a surprisingly large contingent of people who believe that if a company makes a claim, it's the God's honest Truth. The OP may not necessarily fall into this camp. Technically: if the browsers were somehow phoning home, even if the data were highly fuzzed, I'm sure there would be guys like tpatcek who would manage to detail, if not the content of the tracking, at least the amount of data sent…

Indeed. To quote myself in another reply:

> Although proprietary software may be easier for a government to compel to be modified to add tracking, it still runs the risk of being noticed in most reasonable cases, and there is in fact no evidence that any Western government is doing any such thing. It does increase the chance that you are being tracked due to incompetence, but I don't think this is particularly likely for such well-known software.

Re: Prism Break

#23
post #14

Earlier quoted context omitted.

> None of the proprietary browsers will track you. Can you elaborate a bit on this, how do you know they won't? My default assumption is that anything I can't see the source code of and compile myself is compromised.

Sociologically: there is a surprisingly large contingent of people who believe that if a company makes a claim, it's the God's honest Truth. The OP may not necessarily fall into this camp. Technically: if the browsers were somehow phoning home, even if the data were highly fuzzed, I'm sure there would be guys like tpatcek who would manage to detail, if not the content of the tracking, at least the amount of data sent…

It is possible to send data along with other data so that it's reaaally hard to find. Also, they don't need to send data all the time, but rather activate this mode on request, say when a person using this browser is a suspect for some reason and govt needs to track his every move on the internet. This would make detecting of such a functionality virtually impossible, because it'd be turned off most of the time for most people.

Re: Prism Break

#24
post #19
post #16

Earlier quoted context omitted.

> Several of these suggestions seem somewhat disingenuous - e.g. many of them to be about free software more than actual concerns about tracking [..] None of the proprietary browsers will track you. No, these issues are very much related. It is the very nature of proprietary software that you cannot inspect and modify it, so you cannot know if it will track you or not, and cannot fix things if you are. (Inspecting ou…

Although proprietary software may be easier for a government to compel to be modified to add tracking, it still runs the risk of being noticed in most reasonable cases, and there is in fact no evidence that any Western government is doing any such thing. It does increase the chance that you are being tracked due to incompetence, but I don't think this is particularly likely for such well-known software. True, there i…

You seem to be assuming that tracking only happens either through incompetence or government mandate? Companies also track users to make money. Just today there was the news that twitter is starting to track its users, for example (at least it is opt-out).

Re: Prism Break

#25
post #16
post #8

Several of these suggestions seem somewhat disingenuous - e.g. many of them to be about free software more than actual concerns about tracking, as reflected in the labels "Proprietary" and "Free alternatives". In particular: - None of the proprietary browsers will track you - well, beyond what's specified in the privacy policy. Two of the alternatives are Tor applications, but the other two are Firefox (which provide…

> Several of these suggestions seem somewhat disingenuous - e.g. many of them to be about free software more than actual concerns about tracking [..] None of the proprietary browsers will track you. No, these issues are very much related. It is the very nature of proprietary software that you cannot inspect and modify it, so you cannot know if it will track you or not, and cannot fix things if you are. (Inspecting ou…

Chrome's sync service also features client side encryption. [1]

[1] https://support.google.com/chrome/answer/1181035?hl=en

Re: Prism Break

#26
post #23

Earlier quoted context omitted.

Sociologically: there is a surprisingly large contingent of people who believe that if a company makes a claim, it's the God's honest Truth. The OP may not necessarily fall into this camp. Technically: if the browsers were somehow phoning home, even if the data were highly fuzzed, I'm sure there would be guys like tpatcek who would manage to detail, if not the content of the tracking, at least the amount of data sent…

It is possible to send data along with other data so that it's reaaally hard to find. Also, they don't need to send data all the time, but rather activate this mode on request, say when a person using this browser is a suspect for some reason and govt needs to track his every move on the internet. This would make detecting of such a functionality virtually impossible, because it'd be turned off most of the time for m…

It is possible. However, considering that it would only take one person being exceptionally curious with IDA, one employee to blow the whistle (the source is still "open" to a fairly large number of people, and a backdoor is far harder to hide than passive collection of existing data), or one slipup to cause a massive amount of PR damage, and this has never occurred, nor does the Snowden leak suggest this is happening, I personally consider this claim extremely improbable. YMMV.

Re: Prism Break

#27
Although it relies on Mega and Chrome, neither of which is recommended in the article, http://www.nimbusvid.com streams encrypted videos from your private cloud storage in your browser.

No other service does this and it allows you to have the convenience of the cloud and video streaming while maintaining the privacy that you would get by viewing videos on your local computer.

As far as I know it is one of the few examples of a (client-side) web app based on encrypted cloud storage. (I would like to know other examples, I don't know any).

(I am the author)

Re: Prism Break

#28
post #11

Surprised Arch Linux [1] isn't listed. It's probably one of the most secure distros by limiting the installed packages to a bare minimum. Combine that with App Armour (or SELinux designed by the NSA) with a firewall and basic network monitoring to protect against rootkits. Plus always-on VPN, dm-crypted harddrive, noscript etc. NSA also released SEAndroid [2] which hardens Android significantly. It's included preinst…

I'm more surprised that Mint is being suggested at all in this. Considering how ridiculous this list is in the first place, the 'curator' should have noted that Mint, by default, installs search engines that are partnered with Mint[1].

Even more surprising is that BSD just got a cursory mention. You may as well switch to OpenBSD if you're going to switch to a majority of these alternatives.

[1] http://www.linuxmint.com/searchengines.php

Re: Prism Break

#29
post #20

If you're going to continue using Google Mail, it's a dumb idea to deliberately switch away from Chrome. The connection between Gmail and Chrome is among the more carefully guarded TLS connections on the Internet.

How does Google create one of the most carefully guarded TLS connections? Should other sites model their implementation?

Re: Prism Break

#30
post #24
post #19

Earlier quoted context omitted.

Although proprietary software may be easier for a government to compel to be modified to add tracking, it still runs the risk of being noticed in most reasonable cases, and there is in fact no evidence that any Western government is doing any such thing. It does increase the chance that you are being tracked due to incompetence, but I don't think this is particularly likely for such well-known software. True, there i…

You seem to be assuming that tracking only happens either through incompetence or government mandate? Companies also track users to make money . Just today there was the news that twitter is starting to track its users, for example (at least it is opt-out).

Tracking in client-side software that occurs to make money is typically described in privacy policies, and a browser adding additional tracking would likely cause an uproar. While Firefox may provide a better default regarding sync, there is a difference between saying "stop using Chrome" and "enable client-side encryption".
Post reply on HN