We are looking back on an intense but successful 2023 & starting the new year full of motivation. 🚀 This important work for fundamental rights in the digital age is only possible with broad support from civil society, and for that we say: Thank you! https://epicenter.works/en/content/from-austria-to-the-un-an-intense-year-2023
Did you know Privacy Badger replaces embedded tweets, video/audio players, and comments sections with "click to activate" placeholders?
Although potentially useful, these "widgets" often track your browsing. The tracking happens regardless of whether you interact with the widget. If you see a widget, the widget sees you back.
Privacy Badger blocks the widgets to protect your privacy, and replaces them with placeholders to put you in control.
Learn more at https://www.eff.org/deeplinks/2024/01/privacy-badger-puts-you-control-widgets
Build your phone app on your phone https://f-droid.org/en/2024/01/11/twif.html
We invite you to our webinar on security audits tomorrow, Thursday January 11, at 13.00 CET.
Radically Open Security / @ros 's Melanie Rieback and Andrea Jegher will explain and demonstrate how security audits work.
ROS is the world’s first not-for-profit computer security consultancy company. As an NGI0 partner it offers security audits to all projects within the #NextGenerationInternet initiative.
The webinar is open to all and no need to register.
https://nlnet.nl/events/20240111/index.html
Hey! We've been thinking a lot about what's next for the postmarketOS project,
we have a lot of ideas, but we can't do it without your help. We've decided to
join OpenCollective, this makes it possible for us to be financially supported
by and beholden to you - our community.
If you like postmarketOS and want to help us continue on our quest of true
ownership, we would highly appreciate your donations!
More info here 👇
🎉 Best News Of The Year! 🎉
Google confirms they will disable uBlock Origin in Chrome in 2024: Finally everyone understands it's time to quit Google. 😎
Here are our favorite browser alternatives:
➡️ https://tuta.com/blog/best-private-browsers
Which one did you pick?
🦊 Firefox
🦆 DuckDuckGo
🕵️ Tor Browser
Mullvad
Pale Moon
Puffin
GNU IceCat
WaterFox
Brave
Hyphanet
Dropbox was caught enabling "Third-party AI" as an opt-out default to all user accounts.
Meanwhile users were deeply uninformed of the changes..
This is our new world: If your privacy matters, keep your data yours!
Our friends @arstechnica explore the debacle:
The jury in Epic v. Google has delivered its verdict — and it found that Google turned its Google Play app store and Google Play Billing service into an illegal monopoly.
https://www.theverge.com/23994174/epic-google-trial-jury-verdict-monopoly-google-play
Also need to address Apple’s monopoly too. https://www.gov.uk/cma-cases/investigation-into-apple-appstore
https://ec.europa.eu/commission/presscorner/detail/es/ip_20_1073
1.2+ million downloads and a rating of 4.2 – a good indicator for a safe app in Google's #PlayStore? One should think so – until one takes a look at its #permissions (46, including access to quite personal data) and the number of KNOWN #trackers #ExodusPrivacy reports (28!!).
Just wow. Had to add that one to my app lists, as a warning example.
https://android.izzysoft.de/applists/category/named/office_contacts_callerid
Who Cares Who Delivers Our Notifications? https://wrily.foad.me.uk/who-cares-who-delivers-our-notifications
In addition, we strongly advise developers to encrypt their push notifications, recommending #WebPush (following RFC 8291, forget about this draft abandoned 7 years ago!) or to adopt a sync-on-push strategy (which is what Signal does).
@Mer__edith Here is one thing Signal could be doing that it is not: the Signal fork @mollyim has already implemented #UnifiedPush support, Signal can help there, or even integrate that work https://github.com/mollyim/mollysocket
@Mer__edith @unifiedpush @fdroidorg and since you mentioned the world, there are 1.4 billion mobile phone users in China without Apple or Google push. There are half a billion #Huawei users around the world who do not have access to Apple or Google push. #AppGallery devices are sold around the world, including here in Austria. Signal's stance on push really only works in North America. 2/2
@Mer__edith I respect the work that Signal has done, and Signal has been a great leader in pushing e2ee over the past 15 years. Signal can also do better on push. It is not a binary choice, other options provide much improved privacy with smaller hit on battery usage. @unifiedpush does that and falls back to Google push for devices that don't have #UnifiedPush built-in. @fdroidorg is also helping to get it integrated into #CalyxOS #LineageOS etc https://f-droid.org/2022/12/18/unifiedpush.html
1/
Molly now officially supports #UnifiedPush with a separate app, available for download on GitHub and F-Droid through Molly's FOSS repository. Say goodbye to relying on Google for #Signal push notifications. Setting up your MollySocket server is all you need to start receiving notifications. 📡 Big thanks to @S1m for making this possible! ❤️ https://github.com/mollyim/mollysocket
Unidentified governments are surveilling smartphone users via their apps' push notifications, a U.S. senator warned : https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/
That's why it's important to offer your users alternatives.
We invite you to nominate a FOSS project for the Bluehats prize. There are four prizes of €10.000 each, to be spent freely.
Bluehats are civil servants who promote the use and development of Free Software in public administrations.
The French public administration has established the Bluehats prize for maintainers of critical Free Software. To be eligible the software must be in use by at least one agency of the French administration.
Seems google/apple's push notifications services are regularly queried by state authorities for obtaining user data -- see this german #netzpolitik article https://netzpolitik.org/2023/push-dienste-behoerden-fragen-apple-und-google-nach-nutzern-von-messenger-apps/ --
#deltachat only uses apple's push notifications on iOS for "heartbeat" services -- otherwise it's too hard to ensure the app can show messages for their user (and many users are asking for tighter integration). On Android and Desktop platforms no push notifications are used or needed, also no heartbeat ones.
"Unidentified governments are surveilling smartphone users via their apps' push notifications".
https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/
#Push services from #Google and #Apple are used in many messaging apps, letting those companies see a lot of about what the users are doing on their #mobile devices. It is clearly a rich source of #metadata with huge #privacy concerns.
People, apps and code you can trust