freedomPusher

joined 4 years ago
MODERATOR OF
 

The problem:

Most #fedi authors post links with no idea if the hosting server discriminates against people, or who. The consequence is that the fedi is muddied with references to exclusive venues that do not treat people equally, which wastes the time of readers who are impacted by discrimination. A variety of walled gardens pollute our threadiverse experience. So how can we remedy this?

Proposed fix:

Suppose we create a community and designate it as a testing area which welcomes bots. So e.g. I post something in the test community, and a bot that is paywall-aware replies yes or no whether the link is paywall-free. A bot that is Cloudflare-aware does the same. A regional bot, such as a bot in Poland can check that Polish IP addresses can reach the URL and make noise if the website blocks Poland. Etc. It need not be just bots.. someone in some oppressed region might manually attempt to visit links and report access problems. We would certainly like a bot in a GDPR region to test whether access is refused on the basis of a data controller’s unwillingness to respect GDPR rules. The OONI project could have a bot that reports anything interesting in their database.

There could also be anti-enshitification bots, which point out things like cookie walls.

There are bots that find better links to replace Cloudflare links. Those bots could help direct authors to better URLs to share.

There could be a TL-DR bot that replies with a summary or even the full text, so an author can decide before posting in the target community whether to omit a shitty link and just post the content.


(update) It’s worth noting that for Mastodon there an ad hoc tool. If you follow @[email protected], that bot will follow you back and analyze every URL you share for whether it is Cloudflared. If yes, it will DM you with alternative URLs.

Note that the mitigator bot is quite loose it its judgement. If the host is not Cloudflared but another host on the same domain is Cloudflared, it is treated as a positive because it’s assumed that when you visit the host it will link to other hosts on the same domain.

[–] [email protected] 1 points 10 months ago

eclic.ro is an exclusive Cloudflare site just like change.org is. Exclusivity is obviously quite lousy for democracy. Better alternatives are here:

https://codeberg.org/swiso/website/issues/140

[–] [email protected] 2 points 10 months ago* (last edited 10 months ago)

privacytools.io always was shit show even before the infighting. They put their own endorsement site on Cloudflare. Despite a collossal pile of dirt emerging on #Signal:

https://github.com/privacytools/privacytools.io/issues/779

PTIO continued endorsing Signal non-stop, refusing to disclose the issues. That was also before the breakup. Dirt was routinely exposed on PTIO endorsements and it never changed their endorsement nor did they reveal the findings on their website.

Now both factions are hypocrits just as they were when they were united. The original PTIO site is back to being Cloudflared (nothing like tossing people coming to you for privacy advice into the walled garden of one of the most harmful privacy offenders), and Privacy Guides has setup on a CF’d Lemmy node. The hypocrisy has no end with these people.

[–] [email protected] 2 points 10 months ago (1 children)

Interesting, but that does not help because Mint jails all their docs in Cloudflare.

[–] [email protected] 2 points 10 months ago* (last edited 10 months ago) (2 children)

Also worth noting that #Ubuntu and #Mint both moved substantial amounts of documentation into Cloudflare (the antithisis of the values swiso claims to support). I have been moving people off those platforms.

BTW, prism-break is a disasterous project too. You know they don’t have a clue when they moved their repo from Github.com to Gitlab.com, an access-restricted Cloudflare site. There are tens if not hundreds of decent forges to choose from and PRISM Break moved from the 2nd worst to the one that most defeats the purpose of their constitution.

It might be useful to find dirt on various tech at prism-break, but none of these sites can be trusted for endorsements.

The prism-break website is timing out for me right now. I would not be surprised if they were dropping Tor packets since they have a history of hypocrisy.

[–] [email protected] 1 points 10 months ago

If you look in their bug tracker, it actually reveals that they ignore dirt that has been dug up on their suggestions.

[–] [email protected] 1 points 10 months ago* (last edited 10 months ago) (1 children)

As others have mentioned there is little in the way of justification for these suggestions, and while I happen to agree with plenty of them, I’d personally like to see more reasoning, if not to appease people that already have opinions then to help newer users understand their options.

Indeed. In fact it’s actually worse than you describe. Swiso witholds negative information. They don’t want to inform people. They want to steer people. For example, swiso’s endorsements for donation platforms have some quite serious problems:

https://codeberg.org/swiso/website/issues/141

swiso is also aware of the serious issues with Qwant and the serious issues with DuckDuckGo. Not only failing to remove them but also failing to inform. Qwant and DDG are both Microsoft syndicates!

(if anyone is interested, one of the most privacy-respecting search services is Ombrelo¹, which is largely unknown to the world because PTIO, swiso, and prism-break don’t do the job they claim to do)

And swiso is aware because that’s their bug tracker.

/cc @[email protected]

¹ https://ombrelo.im5wixghmfmt7gf7wb4xrgdm6byx2gj26zn47da6nwo7xvybgxnqryid.onion/

[–] [email protected] 1 points 10 months ago* (last edited 10 months ago)

There are a few good alternatives and swiso has been aware of them for ~4+ years:

https://codeberg.org/swiso/website/issues/140

 

cross-posted from: https://sopuli.xyz/post/13489053

In the onion v2 days we had underwood2hj3pwd.onion. There were half a dozen other onion email providers but Underwood was the only one that did not have a clearnet email alias (IIRC). That was a useful feature because you could distribute an onion address to a MS Outlook or Gmail user and they could not use it to share their correspondence to you with Google or MS in the loop. They had just two options: step off the ad surveillance platform or not contact you at all. That option died with Underwood.

The other onion email services all have a clearnet translation. So if (for example) I give a gmail user this address:

foo@yllvy3mhtamstbqzm4wucfwab57ap6zraxqvkjn2iobmrtxdsnb37dqd.onion

and they are motivated to reach me, they can figure out that the corresponding clearnet alias is foo(/at/)onionmail.info and then they can use that address to send me a msg that is then shared with their surveillance advertiser. And worse, that’s less effort for them than obtaining an onion email account.

So what I do now is give an XMPP account. Since Google has abandoned jabber and MS never partook, XMPP avoids Google and MS. But XMPP is not a drop-in replacement for email. OMEMO is glitchy/buggy with pitfalls.

I would like to offer an email option. Ideally, an onion email service would offer a clearnet alias that cannot be determined from the onion address, which implies a different userid string.

 

The linked¹ #gemini article is the political platform of the French green party in Belguim w.r.t. digital rights. It was translated from French.

I’m overall impressed enough to vote for them. But I do have some concerns:

“At the Belgian level, we propose to establish a legal guarantee of 5 years for new electronic devices.”

Yikes, waaay too short. Needs to be at least 10 years. But it helps that they advocate FOSS:

“Generalize the ability to use free software on all devices to decrease software obsolescence.”

Though this statement is far too vague. If a maker of hardware with proprietary non-free software only gives 5 years of support, there needs to be a legal obligation that they port FOSS to the device at the end of the warranty. This is missing in the green party’s plan.

A lot of other things are missing in their plan, but generally their principles are sensible.

¹ (edit) actually it cannot be linked using the URL field due to a #LemmyBug. But at least it was linkable in the msg body.

 

Belgian elections are today. Mailbox flyers for political candidates often show profiles in exclusive walled gardens (Facebook, TikTok, LinkedIn, Twitter, Instagram). And they often have email addresses at hotmail, gmail, or outlook. They are betting on #digitalExclusion. I am cancelling all of them regardless of party.

nuancesAll policians likely have a Facebook acct. That’s a sad state of affairs, but merely having an account does not get them cancelled. A cancellable offense is public displays that flaunt their digital exclusion. It’s despicable when their flyer pushes people into US walled gardens with no way to reach them in the free world.

I am also cancelling five whole parties for undermining democracy via digital exclusion by using Cloudflare for the party’s own website. Digital rights are important in 2024, particularly for democracy, as we are increasingly being disempowered by power abuses through forced use of oppressive technology. Direct Tor blocking? Also cancelled.

I am also cancelling all extreme right parties on general principle. And even slightly right if “immigratie stoppen” is something they are misfocused on.

Who’s left? I think I’ll be voting none of the above on a lot of positions because they don’t clear my basic bare minimum bar of digital decency.

(edit) maybe ecolo has a chanceNo one represents me, apart possibibly from Ecolo. But superficially, it seems contradictory that a “green” party proposes making energy cheaper for a broader demographic of people. That obviously removes pressure to conserve energy.
(update) ecolo looks like a winner

[–] [email protected] 2 points 10 months ago

That confirms it then: it’s a client feature. I also have a dbzer0 acct as you do, but I only see the total, which apparently can be attributed to the stock web client.

[–] [email protected] 1 points 10 months ago (3 children)

The only relevant user setting I have is “show scores”. False shows no scores at all for comments and threads. True shows up votes and down votes on comments, but not threads. So if lemm.ee shows you up and down votes on threads and you are using the web client, then that must be a server-side option or mod. It could be a client capability but I’ve not found a worthy 3rd party client for Lemmy yet (for the desktop).

[–] [email protected] 1 points 10 months ago (1 children)

[email protected] is a better place for this info.

 

cross-posted from: https://sopuli.xyz/post/13155149

other people’s iPhones more intrusive than other people’s droids


According to the linked research, all iPhones are spying on everyone within Wi-Fi range. If your phone of any kind is squawking wi-fi, all in-range iPhones are grabbing various bits of data like your MAC address and the SSIDs your phone normally looks for (e.g. your home SSID) and reports that back to Apple along with time and location data. The same study could not say the same for Google. So other people’s iPhones are more of a privacy intrusion to you than other people’s droids.

your own iPhone is less intrusive than your own droid when navigating


However, another study shows an inversion between Apple and Google when it comes to what you own and use for navigation. If you use an iPhone for navigation, the iPhone will only send one or two BSSIDs near you to Apple’s server, and the server then floods you with detailed information about other possible BSSIDs around you and their position, so your own device computes your precise location, not Apple’s servers.

Whereas if you navigate using Google’s location services, your device feeds everything to Google and Google’s server does all the work, computes your precise location, and tells you. This is of course more intrusive because Google learns your precise location and time, and (IMO) is likely interested in whatever shop you might be in.

These two studies actually seem superficially contradictory. But there is a difference between ratting out other portable devices and reporting stationary devices.

free-world proponents might be able to exploit Apple for better nav


In any case, the take-away for people living in the free world: forget about using Google Location Services to improve your navigation if you do not want to feed Google your precise location. OTOH, there seems to at least be a theoretical possibility for people not pawned by tech giants to use Apple’s API to get better-than-GPS navigation. Though I suspect it would mean many people would have to share someone’s sacrificial Apple account or get burner accounts.

I’m always on the look out for ways to improve my shitty navigation on a deGoogled phone that’s limited to a slow energy hungry GPS receiver -- without feeding the baddies.

 

Nano Garden was a node for the Nano cryptocurrency. There is was a “cashless society” community which is now a ghost community:

https://sopuli.xyz/c/[email protected]

I would normally say refugees should move to [email protected], but it looks like there aren’t many refugees. It always was relatively dead. Which is a shame. There needs to be more people talking about the consequences of #forcedBanking.

 

cross-posted from: https://sopuli.xyz/post/13133455

It used to be that you could insert a coin into a washing machine and it would simply work. Now some Danish and German apartment owners have decided it’s a good idea to remove the cash payment option. So you have to visit a website and top-up your laundry account before using the laundry room.

Is this wise?

Points of failure with traditional coin-fed systems:

  1. your coin gets stuck
  2. you don’t have the right denomination of coins

Points of failure with this KYC cashless gung-ho digital transformation system:

  1. your internet service goes down
  2. the internet service of the laundry room goes down
  3. the website is incompatible with your browser
  4. the website forces 3rd party JavaScript that’s either broken or you don’t trust it
  5. you cannot (or will not) solve CAPTCHA
  6. the website rejects your IP address because it is a shared IP
  7. the payment processor rejects your IP address because it is a shared IP
  8. the bank rejects your IP address because it is a shared IP
  9. the payment processor is Paypal and you do not want to share sensitive financial data with 600 corporations
  10. the accepted payment forms do not match your payment cards
  11. the accepted payment form matches, but your card is still rejected anyway for one of many undisclosed reasons:
    • your card is on the same network but foreign cards are refused
    • the payment processor does not like your IP address
    • the copy of your ID doc on file with the bank expired, and the bank’s way of telling you is to freeze your card
    • it’s one of these new online-only bank cards with no CVV code printed on the card so to get your CVV code you must install their app from Google’s Playstore (this expands into 20+ more points of failure)
  12. your bank account is literally below the top-up minimum because you only have cash and your cashless bank does not accept cash deposits; so you cannot do laundry until you get a paycheck or arrange for an electronic transfer from a foreign bank at the cost of an extortionate exchange rate
  13. you cannot open a bank account because Danish banks refuse to serve people who do not yet have their CPR number (a process that takes at least 1 month).
  14. you are unbanked because of one of 24 reasons that Bruce Schneier does not know about
  15. the internet works when you start the wash load, but fails sometime during the program so you cannot use the dryers; in which case you suddenly have to run out and buy hanging mechanisms as your wet clothes sit.

In my case, I was hit with point of failure number 11. Payment processors never tell you why your payment is refused. They either give a uselessly vague error, or the web UI just refuses to move forward with no error, or the error is an intentional lie. Because e.g. if your payment is refused you are presumed to be a criminal unworthy of being informed.

Danish apartment management’s response to complaints: We are not obligated to serve you. Read the terms of your lease. There is a coin-operated laundromat 1km away.

Question: are we all being forced into this shitty cashless situation in order to ease the hunt for criminals?

 

cross-posted from: https://sopuli.xyz/post/13133455

It used to be that you could insert a coin into a washing machine and it would simply work. Now some Danish and German apartment owners have decided it’s a good idea to remove the cash payment option. So you have to visit a website and top-up your laundry account before using the laundry room.

Is this wise?

Points of failure with traditional coin-fed systems:

  1. your coin gets stuck
  2. you don’t have the right denomination of coins

Points of failure with this KYC cashless gung-ho digital transformation system:

  1. your internet service goes down
  2. the internet service of the laundry room goes down
  3. the website is incompatible with your browser
  4. the website forces 3rd party JavaScript that’s either broken or you don’t trust it
  5. you cannot (or will not) solve CAPTCHA
  6. the website rejects your IP address because it is a shared IP
  7. the payment processor rejects your IP address because it is a shared IP
  8. the bank rejects your IP address because it is a shared IP
  9. the payment processor is Paypal and you do not want to share sensitive financial data with 600 corporations
  10. the accepted payment forms do not match your payment cards
  11. the accepted payment form matches, but your card is still rejected anyway for one of many undisclosed reasons:
    • your card is on the same network but foreign cards are refused
    • the payment processor does not like your IP address
    • the copy of your ID doc on file with the bank expired, and the bank’s way of telling you is to freeze your card
    • it’s one of these new online-only bank cards with no CVV code printed on the card so to get your CVV code you must install their app from Google’s Playstore (this expands into 20+ more points of failure)
  12. your bank account is literally below the top-up minimum because you only have cash and your cashless bank does not accept cash deposits; so you cannot do laundry until you get a paycheck or arrange for an electronic transfer from a foreign bank at the cost of an extortionate exchange rate
  13. you cannot open a bank account because Danish banks refuse to serve people who do not yet have their CPR number (a process that takes at least 1 month).
  14. you are unbanked because of one of 24 reasons that Bruce Schneier does not know about
  15. the internet works when you start the wash load, but fails sometime during the program so you cannot use the dryers; in which case you suddenly have to run out and buy hanging mechanisms as your wet clothes sit.

In my case, I was hit with point of failure number 11. Payment processors never tell you why your payment is refused. They either give a uselessly vague error, or the web UI just refuses to move forward with no error, or the error is an intentional lie. Because e.g. if your payment is refused you are presumed to be a criminal unworthy of being informed.

Danish apartment management’s response to complaints: We are not obligated to serve you. Read the terms of your lease. There is a coin-operated laundromat 1km away.

Question: are we all being forced into this shitty cashless situation in order to ease the hunt for criminals?

 

It used to be that you could insert a coin into a washing machine and it would simply work. Now some Danish and German apartment owners have decided it’s a good idea to remove the cash payment option. So you have to visit a website and top-up your laundry account before using the laundry room.

Is this wise?

Points of failure with traditional coin-fed systems:

  1. your coin gets stuck
  2. you don’t have the right denomination of coins

Points of failure with this KYC cashless gung-ho digital transformation system:

  1. your internet service goes down
  2. the internet service of the laundry room goes down
  3. the website is incompatible with your browser
  4. the website forces 3rd party JavaScript that’s either broken or you don’t trust it
  5. you cannot (or will not) solve CAPTCHA
  6. the website rejects your IP address because it is a shared IP
  7. the payment processor rejects your IP address because it is a shared IP
  8. the bank rejects your IP address because it is a shared IP
  9. the payment processor is Paypal and you do not want to share sensitive financial data with 600 corporations
  10. the accepted payment forms do not match your payment cards
  11. the accepted payment form matches, but your card is still rejected anyway for one of many undisclosed reasons:
    • your card is on the same network but foreign cards are refused
    • the payment processor does not like your IP address
    • the copy of your ID doc on file with the bank expired, and the bank’s way of telling you is to freeze your card
    • it’s one of these new online-only bank cards with no CVV code printed on the card so to get your CVV code you must install their app from Google’s Playstore (this expands into 20+ more points of failure)
  12. your bank account is literally below the top-up minimum because you only have cash and your cashless bank does not accept cash deposits; so you cannot do laundry until you get a paycheck or arrange for an electronic transfer from a foreign bank at the cost of an extortionate exchange rate
  13. you cannot open a bank account because Danish banks refuse to serve people who do not yet have their CPR number (a process that takes at least 1 month).
  14. you are unbanked because of one of 24 reasons that Bruce Schneier does not know about
  15. the internet works when you start the wash load, but fails sometime during the program so you cannot use the dryers; in which case you suddenly have to run out and buy hanging mechanisms as your wet clothes sit.
  16. (edit) the app of your bank and/or the laundry service demands a newer phone OS than you have, and your phone maker quit offering updates.

In my case, I was hit with point of failure number 11. Payment processors never tell you why your payment is refused. They either give a uselessly vague error, or the web UI just refuses to move forward with no error, or the error is an intentional lie. Because e.g. if your payment is refused you are presumed to be a criminal unworthy of being informed.

Danish apartment management’s response to complaints: We are not obligated to serve you. Read the terms of your lease. There is a coin-operated laundromat 1km away.

Question: are we all being forced into this shitty cashless situation in order to ease the hunt for criminals?

 

I’ve noticed that if you try to contact corp or gov offices the old fashioned way, they simply ignore you. They want to force you to use email or solve a CAPTCHA. The fix I have in mind is a tweak on this idea:

https://sopuli.xyz/post/12919557

but the first contact you make with an office need not even be GDPR¹ related. If you contact a gov or corp for any purpose and they ignore it, your next request can and should include an access request for records on how they handled your initial correspondence.

¹ GDPR isn’t the only game in town. Brazil and California supposedly have some privacy law similar to the GDPR which I assume includes a right of access. Hence why they were also mentioned in the title.

#fuckEmail

 

It was a Lemmy service that centered on law. Now it gives a 404.

The threadiverse is starving for small decentralized nodes with a theme focus. There are far too many general purpose nodes. It’s a shame the law node is gone. There is nothing to replace it.

1
submitted 11 months ago* (last edited 11 months ago) by [email protected] to c/[email protected]
 

I just had to send a msg to a gov office.

Email has been generally broken¹ the past couple decades. I prefer fax. It’s more reliable and I choose what I want to disclose to the recipient. Even in cases where part of the fax transmission routes over email, it’s still more reliable than pure email because those fax→email gateways are managed by recipients to ensure all-or-nothing (all faxes are delivered or none of them). Fax is immune to shenanigans like “mail server X accepts mail from Y but not Z”.

When I tried to send the fax, the fax machine did not answer. So I voice called the office. They said “we unplugged our fax machine”. WTF! So I said please plug it back in because I’m trying to send a fax. So a bit later I tried again and it worked.

Folks, we are losing fax because most of the population does not grasp the privacy compromise with email, and the compromise of netneutrality and reliability. If I am the only person in the world who keeps fax in use, fax will die fast because it’s easy to marginalise 1 person.

Footnote 1: Email is shit--Even if the gov office mail server were to accept my msg, I face the problem of not wanting an email reply and not trusting them not to abuse whatever address I reveal to them. I don’t want to be forced to put Google and Microsoft in the loop on my conversations, to go through their hoops, solve their dkim CAPTCHA, and ultimately I don’t want to be forced to feed profitable data to those surveillance advertisers who have partnered with the oil industry. Google and SpamHaus broke email and the population accepted it. So email can fuck right off.

[–] [email protected] 1 points 11 months ago (1 children)

Mobile apps for this sort of thing is quite alien to me -- out of sight and out of mind because I cannot imagine using a small screen and tiny keyboard for forums when I am all day sitting at a PC with proper keyboard. Although speech to text probably makes small device input a little more tolerable.

The small nodes are not dead, so I wonder if the activity and accounts on the disproportionately small nodes can be attributed largely to mobile app users.

view more: next ›