The problem with lists like this is they really are just a "here's 100 open source products", without any criteria or individual evaluation. It is often just parrots repeating what other parrots say. Something which is clearly alpha-state isn't usable to regular users shouldn't have a "recommendation". Then you get sub optimal recommendations, listing some projects which are unmaintained etc. With the cleanup at http…
Privacy-Respecting Software
21–30 of 53 posts
Re: Privacy-Respecting Software
#22Re: Privacy-Respecting Software
#23The problem with lists like this is they really are just a "here's 100 open source products", without any criteria or individual evaluation. It is often just parrots repeating what other parrots say. Something which is clearly alpha-state isn't usable to regular users shouldn't have a "recommendation". Then you get sub optimal recommendations, listing some projects which are unmaintained etc. With the cleanup at http…
OpenPGP is a message standard that specifically covers the offline, end to end encryption case. So the contention that it bad at other cases isn't very interesting.
Forward secrecy can be implemented in the OpenPGP case in way compatible with regular usage, but no one bothers. Offline encryption can be made arbitrarily secure so that it is always better to spend the time and effort on preventing the compromise in the first place. Besides, no one wants to have to immediately delete all their emails after having read them. Forward secrecy is simply not relevant for offline applications.
Re: Privacy-Respecting Software
#24The problem with lists like this is they really are just a "here's 100 open source products", without any criteria or individual evaluation. It is often just parrots repeating what other parrots say. Something which is clearly alpha-state isn't usable to regular users shouldn't have a "recommendation". Then you get sub optimal recommendations, listing some projects which are unmaintained etc. With the cleanup at http…
It feels as if their project was ill-defined and grew too quickly, and they're not really sure exactly what it's supposed to be yet.
Re: Privacy-Respecting Software
#25Re: Privacy-Respecting Software
#26Earlier quoted context omitted.
According to the PR[1] it is because it doesn't use end-to-end encryption. [1]: https://github.com/privacyguides/privacyguides.org/pull/192
Hmm, I guess that matters if you are using public servers. If you are running your own server, then it is a non-issue. I still think self hosted mumble is a great solution to the problem. Looking through the privacyguides recommendations[0], I don't see a good alternative. [0] https://www.privacyguides.org/real-time-communication/
Re: Privacy-Respecting Software
#27I went through a mad phase where I had loads of extensions installed in my main browser. Then all these stories came out about addon authors getting contacted by shady actors who wanted to buy the addon so they could add malicious code that siphons off personal data. Now I just have uBlock Origin and that's it! I trust it NOT to be taken over by bad actors.
Addons also have exploitable bugs in them, and also having multiple 'privacy addons' can mean some overlap in functionality where the tracking protection is redundant since it's covered by another addon. Like who really needs Privacy Badger, DuckDuckGo privacy essentials, and then uBlock running all together?
And with browsers shipping with fingerprinting mitigation, and having the option to surf strictly HTTPS sites, some addons are becoming redundant, like HTTPS Everywhere & 'useragent spoofing' addons which can actually make you stand out (privacy.resistFingerprinting:true in Firefox FTW). The trick is to blend in with a useragent, not stand out.
Re: Privacy-Respecting Software
#28The problem with lists like this is they really are just a "here's 100 open source products", without any criteria or individual evaluation. It is often just parrots repeating what other parrots say. Something which is clearly alpha-state isn't usable to regular users shouldn't have a "recommendation". Then you get sub optimal recommendations, listing some projects which are unmaintained etc. With the cleanup at http…
I've followes the specs a little and it seems to be implemented in a cautious manner. But haven't seen it being mentioned anywhere on privacy focussing lists, and I haven't heard of any audit of their codebase/protocol specs.
Do you know by chance anyone currently auditing and/or describing threat models etc for it?
Re: Privacy-Respecting Software
#29The problem with lists like this is they really are just a "here's 100 open source products", without any criteria or individual evaluation. It is often just parrots repeating what other parrots say. Something which is clearly alpha-state isn't usable to regular users shouldn't have a "recommendation". Then you get sub optimal recommendations, listing some projects which are unmaintained etc. With the cleanup at http…
"The problem" with lists like these is that they proliferate without reason. This fragmentation means that it's basically impossible for anybody who needs one to know which ones are good or up to date. It also guarantees that most of them will be unmaintained at any given time. Somebody should make a list of lists. Or a list of lists of lists... > - Off-The-Record: Doesn't cover group chats or other side channels, su…
There is Matrix. The issue is that people don't know what actions are E2EE and what is not.
> That's not what it's for, and email is not "real time communication". I have an archive of email going back 30 years. Forward secrecy is not always a win.
It was listed under the "encrypted messaging" section.
> That's an awfully strong statement to make without a threat model...
It's not, its that browsers have evolved to the point where a lot of those extensions are unessary and actually are counter to privacy, modifying your fingerprint to be unique.
> ... but you list "social networks", which are intrinsically "not private" in their very purpose, just like video sharing...
As it happens we're removing those sections for this very reason https://github.com/privacyguides/privacyguides.org/discussio...
Re: Privacy-Respecting Software
#30The problem with lists like this is they really are just a "here's 100 open source products", without any criteria or individual evaluation. It is often just parrots repeating what other parrots say. Something which is clearly alpha-state isn't usable to regular users shouldn't have a "recommendation". Then you get sub optimal recommendations, listing some projects which are unmaintained etc. With the cleanup at http…
There's nothing inherently wrong with a having lists like that to serve as a starting point to see what exists for your own research, the bigger issue is that it claims to be curated when it's more like a wiki. It feels as if their project was ill-defined and grew too quickly, and they're not really sure exactly what it's supposed to be yet.
Problem is they also serve to repeat bad/out of date practices.
I always feel people who put together these lists are in a competition to list as many products and cover as many areas as possible, without evaluation.