Signal without a phone number is finally
rolling out.
ClickFix cyber attacks are going viral and
a data broker lost their domain in a
lawsuit.
All this and more coming up on This
Week in Privacy, so stay tuned.
Welcome back to This Week in Privacy,
our weekly series where we discuss the
latest updates with what we're working on
in the Privacy Guides community and this
week's top stories in data privacy and
cybersecurity while answering viewer
questions.
I am Nate,
and with me this week is Jordan.
How are you doing, Jordan?
Doing great and looking forward to diving
into some very interesting stories with
you this week.
Yeah, for sure.
Let's go ahead and jump right into it.
I'm going to turn it over to you
for our big headline story about Signal.
And a reminder to the audience to feel
free to chime in with any questions,
like Norway here.
Hello, Norway.
Hey there.
All right, yeah,
let's jump straight into this first story
here.
Signal registration without a phone number
is now available in Android beta.
The ability to register for Signal without
a phone number is a long request feature.
While Signal hides phone numbers by
default and gives users control over who
can discover them by phone number,
registration itself has continued to
depend on a number capable of receiving an
SMS or verification call.
Signal login changes that by allowing
users to create an account without
providing a phone number.
So here's this article here from About
Signal.
They did a great job just summarizing
everything and including screenshots and
everything.
Basically,
you can see the registration without a
phone number is optional and it's not a
replacement of the current signup process.
And to kind of dive more into how
this works,
Signal requires users who choose to
register without a phone number to make a
one time payment.
The price at launch is two dollars ninety
nine USD or three point four nine euro.
And the euro price includes VAT as well.
Although this price may vary by region and
currency.
The payment itself uses zero knowledge
proofs.
which is the same as Signal's donation
system,
meaning there's no direct link between
your payment and your Signal account.
The payment is intended to introduce a
barrier by creating an account without a
phone number.
You need to prevent spam and abuse.
So a Signal developer on the community
forum said the price could be increased in
the future if Signal login accounts become
a source of spam.
And it's currently not yet possible to buy
a Signal login account on a device that
has no Play services.
And Signal says that they have plans to
add more payment methods,
but currently only offer Play Store in-app
purchases, which requires Play services.
Signal login currently only works for new
accounts,
and it's not possible to remove a phone
number from an existing account,
although this may become possible in the
future.
And when you purchase a Signal login
account,
you'll be given an account ID and a
recovery key.
This recovery key is also used for
on-device backups and Signal secure
backups,
even if you enable backups at a later
time.
Signal encourages you to save your account
ID and recovery key in a password manager
you trust.
Alternatively,
you can also save this login as a
PDF.
Without an account ID and recovery key,
you won't be able to recover your account
and there's no way to get your account
back if you lose either your account ID
or recovery key.
And yes,
currently Signal only supports TOTP-based
authentication.
Signal says passkey support including
hardware keys will be added soon.
The two-factor authentication setting is
currently only available for Signal login,
but Signal plans to add support for
accounts registered with a phone number in
the future.
Finally,
Signal Desktop currently has no standalone
registration process,
but Signal is working on making desktop
available as a primary standalone device.
All right.
So that's like kind of a massive info
dump.
I guess throwing it back over to Nate.
Is this good?
Why is this not?
Is this not good?
Like a lot of people probably have a
lot of thoughts on this.
What's your initial like thoughts on this?
Yeah,
so I think this is a win for
sure.
Signal has been criticized a lot over the
years for requiring a phone number.
I don't necessarily think it's a fair
criticism.
Like Signal,
they do hash the phone numbers,
so they can't turn over a list of
phone numbers.
But authorities can totally go to them and
be like, we have a phone number.
Can you confirm that this is a user?
And I think people really confuse privacy
and anonymity a lot.
Like Signal is not anonymous right now for
that reason.
And here in the US,
you can use like a voice over IP
number.
But I know in a lot of countries,
you have to hand over ID to get
a phone number.
So in a lot of countries...
that is a bit of an issue.
But I still think this is a good
thing because it's less data for them to
have and it's providing that opportunity
for them to not have anything.
What happens when the government comes up
and they says, hey,
do you have this phone number?
And they go, well,
we don't have that phone number,
but person might still have an account.
We don't really know.
So I think generally speaking,
any service that engineers themselves out
of the equation as much as possible and
tries to have as little data as possible,
I think is a really good thing.
But
Yeah, I think we're... Yeah,
I'd say it's a good thing for sure.
Yeah,
I think this is always going to be
one of these topics where I think people
are going to be kind of split on
this.
I think people that already don't trust
Signal are going to say,
this is Signal trying to get access to
your payment information or link it to
your Google account.
And it's like...
Well,
I don't think this is really the tool
for you if this is, like,
the concern that you have, right?
Because even if you were doing this
before, right, like,
the way that this is implemented,
you kind of have to trust that Signal
is doing it correctly.
We don't really need to, like...
like super trust them because you know
obviously the code is open source and
things like we can see that the phone
number is hashed when you sign up but
you still have to provide the phone number
itself right um the same thing goes for
this payment process right it's done
through google play but the account isn't
actually it's not linked back to your
actual account because it's um like it
said earlier this is like a zero knowledge
proof system so you know
you're able to prove that you made the
payment,
but it's not linked to the actual payment
itself.
So I think SQL has basically done every
possible thing that they can to make this
be
accessible and robust i think you know
this is one of these things where it's
in a beta process and i think people
should be like if we will talk about
this later but there were some comments on
the forum discussing this um earlier and
we'll get to those soon but if you
do have any other thoughts as well do
leave those on our forum at
discuss.privacyguides.net but the there
were people complaining about the option
for cryptocurrency but again signal has
said that there will be
more payment options available.
So I think you shouldn't put a pass
signal to implement the best and most
robust ways of, of doing this.
And I think it would not be a
stretch for them to implement a Monero
payment method.
Absolutely would not be a surprise if they
did that in the end.
So I think, you know,
this is already an early like beta, uh,
version of this feature.
So I think it's only going to get
better from here basically.
Yeah,
and that's definitely the criticism I've
seen a lot is the fact that there
is no private payment option.
But like you said,
this is still in beta.
I mean, it's literally in beta.
Like if you use the stable Android client,
it's not there.
It's not on iOS yet.
So they are going to work on that,
which I think is good.
I agree with you.
I think they did this in a really
solid way,
but I'm also glad to see that they're
going to continue to improve and go above
and beyond that.
I had a thought that got away from
me.
Um, let me,
let me ask you this and get your
opinion.
Uh, so do you,
do you think at this time we would
recommend that people like create new
signal accounts with,
without phone numbers?
Because it says that you can't at this
time,
you can't remove a phone number from an
account.
So you would have to create a new
one,
which I know I've seen at least one
person in our signal chat so far has
done in the supporter chat.
But, um,
do you think people should do that?
Or do you think it's kind of like
up to you or what are your thoughts?
Yeah.
I mean, I kind of think like,
I don't know if you're like me,
but I have like too many signal contacts.
That would be a nightmare personally.
I could never recreate my account,
unfortunately.
Oh my goodness.
Sorry.
I could never recreate my account because
I have so many,
I have so many contacts.
So I think it's one of those things
where it's like a threat modeling thing.
If you think you're at risk and you
don't mind re-adding all your contacts,
then sure.
But like,
having to do that whole process again.
I think Signal is probably going to add
the option to remove the phone number at
some point.
So I think it's probably better just to
wait until that comes around than
restarting your entire account.
And I think, yeah,
I feel like people are still going to
have issues with the way that this works,
even if they're like, you know,
even if Signal does this in the most
privacy respecting way,
people are always going to have issues
with how this is implemented.
And unless it's like, you know,
no payment required,
like the signup process is completely
anonymous and it's like, well,
that would kind of ruin the experience for
a lot of people on Signal and it
would put an undue amount of pressure on
Signal to basically just allow spam.
So I think this is like a decent
middle ground.
that they've taken,
and I think we'll see it be probably
the way that we recommend people to sign
up.
It depends on, like, you know,
how things go and if they offer more
private payment methods because I think,
you know,
if people are using Graphene OS currently,
you can't even do this.
So it will be interesting to see how
this goes.
But it's definitely a story we're going to
be keeping an eye on and keeping everyone
updated on.
Yeah,
the thing I was going to mention that
kind of got away from me is it
is a challenge for any service to balance
accessibility and spam.
I think there's nothing wrong with saying
I don't like Signal's approach to spam,
like requiring a phone number or requiring
a payment.
But I think it's valid to understand that
Signal would want to cut down on spam.
I got a family member using Matrix for
a short period of time,
and he stopped using it.
Because he got tired of all the spam.
And it's not just him,
like in his case,
although I've met a lot of people who
say that they get tons of signal spam,
or I think not so much these days,
ever since they did the username.
But he was in a lot of groups,
just totally innocent, normal groups,
where you know how it is,
trolls would come in and post gore and
see Sam and all kinds of stuff.
and after a while he's like i don't
want this like this is not what i
signed up for this is bad and stop
using matrix because so many matrix
servers have absolutely no obstacles to
sign up and people would do that so
if you don't put roadblocks in the way
it just makes it too easy for spammers
but at the same time like again i
accept the argument if you're like yeah
but this isn't the right roadblock so i
don't know it's it's it's a tough thing
to balance um
I will say the chat's already going off.
But yeah,
definitely let us know what you guys think
in the comment.
Are you excited for this,
like phone number free accounts?
What do you think they should focus on
next?
This is something I was wondering.
If you don't currently use Signal,
would this make you reconsider using it?
But before we move on,
we did have a few questions.
Let me start with a Pingu said that
a signal has chosen their own weird
currency with no exchange supports rather
than XMR.
So I highly doubt it will support XMR.
I mean, maybe like there is.
Yeah,
there is a famous video with Jonah and
Henry from Tech Lord a couple
years back where they were trying to
figure out how to use mobile coin and
neither of them could figure it out it's
actually kind of funny to watch but and
for the record that's the point is they
said that at the end they're like if
we couldn't figure this out then there's
ninety nine percent of people using this
are not going to be able to figure
this out so i think that's um uh
yeah hopefully this is kind of their
wake-up call to just get rid of that
mobile coin thing entirely because that
was weird from the start and i don't
think anybody was really crazy about it
Anon pointed out what I just said.
How do they ban accounts for spam?
There's still got to be some kind of
identifier.
I mean,
there's probably some kind of internal
identifier.
And then when they report,
like if somebody reports you,
then they can ban you.
I don't know.
That's kind of above my head really,
but definitely a good concern.
Couple other comments that are not related
to this from RoncLars on Twitch.
He said,
do you think in the future more and
more apps like Revolut will not be
supported on Graphene?
Or how do you think the future will
be for apps like this on such an
OS?
I'm not familiar with that specifically.
I'm going to say in my opinion,
it's probably going to be a cat and
mouse thing.
Um, you know,
they're going to crack down on like the
Google safety net attestation or whatever
the heck it's called.
And then, um, you know, in return graph,
you know,
figure out some kind of way around that,
like they're trying to do right now with
RCS,
but that would be my guess is it's
probably never going to be a hundred
percent successful stuff like that.
There, there will always be workarounds.
Do you have any thoughts on that one?
Um, not really.
I think, you know, this,
this does come down to like Google
controlling the platform, right?
Like they can kind of just like implement
these, like,
I think before it was safety net and
now it's like, um,
integrity check or whatever.
Um,
I've had apps that now just like won't
work at all,
but it's like not due to graphene OS,
it's due to Google.
So there's not much we can do when
it comes to this sort of stuff.
Um,
and we kind of just need to keep
pressuring, um,
Google and also the organizations that are
enabling the integrity check because I
think a lot of them like for instance
one that I know is the Australian
government has their own app and it won't
let you sign in if you're on Graphene
OS and it's like well
Like this is objectively more secure than
a standard Google Pixel.
So it doesn't really make any sense to
block it.
It makes sense, I think,
if you had an unlocked bootloader and you
were running like some ancient operating
system.
But if you're running like the latest
security patches and everything like that,
it doesn't really make much sense for them
to block access.
And, you know,
as long as you're using all the Android
security features,
it doesn't really make sense
much sense for them to block that.
We did also get another comment from
Ronclas as well,
and I can answer this because I agree,
actually.
I'm usually a free and open source kind
of guy,
but there is two software I think is
superior and I cannot live without,
Todoist and OnePassword.
Both are awesome features and great to
use.
I use both of them.
I actually don't know how I would be
able to organize everything at work
without Todoist.
The amount of tasks that I have to
do is just like...
obscene and I would always forget stuff
and Todoist just makes it easy to track
everything um I haven't really found an
app that does the same thing as well
as Todoist so I can actually agree on
that I mean I think you know you
have to be you have to be like
kind of uh
kind of pragmatic with stuff, right?
Like if it's objectively improving your
life and like helping you to stay
organized and it's not super sensitive
data, I think, you know,
you can definitely make exceptions, right?
So I think that's not the worst thing
ever.
I don't use it for anything sensitive,
obviously, just like work stuff,
which is usually already public.
It's like, oh,
this thing needs to get done that needs
to be published or something like that.
And it's like,
already public.
So I'm not really,
I don't have an issue with that.
OnePassword,
I just think it has the best UI.
It has the best features.
It has the best integrations.
It's just the better,
it's just has better like features.
It just works better.
There's other issues with it, obviously,
like the source availability.
And I know Nate also has issues with
their, well, I have issues with it too,
but they require an NDA to access their
security audits and stuff,
which I think is kind of a little
bit disgusting.
So, you know,
there's issues with one password and I
think, you know,
it's fine to acknowledge some of that,
but I do think some people will be
like, oh,
just use BitWater and just use like
ProtonPass.
But like, if you,
if you've ever used one password,
you just know that the features are
better.
It just works better.
Like it's just a better app.
I'm sorry.
Just try it out.
Seriously.
Like you'll, you'll probably agree.
Yeah.
If you don't mind not having some of
those features,
then I think you could probably use some
of the other ones that we recommend.
But personally, I am a fan of it.
It works kind of well.
But yeah, someone said it's three dollars.
This is too expensive.
Oh, you're talking about Signal.
Okay.
I mean,
one password is kind of expensive as well.
But yeah,
I guess I'll throw it back to you
on this one, Nate.
I don't know if you have anything to
add on it.
No,
you're meaner to one password than I am.
I was going to say the NDA thing
is uncool,
but disgusting is a good choice of words
too.
No, I agree.
My wife actually,
we're talking about possibly getting her
the Todoist premium because it comes with
like,
you can set deadlines and you can do
time blocking.
And those are all things she really wants.
And I think reminders too.
And
Um, it's fairly affordable.
I think she said it's like twenty bucks
for a year.
So we'll probably end up getting that.
But yeah, I'm with you.
Like it's it's very, um,
like the password manager thing is
actually a really good example.
I do use Bitwarden.
I'm very happy with it.
I don't have any plans to move.
But at the end of the day,
you have to use what's right for you.
Like if I traveled a lot more,
especially to a lot more like, um,
like more hostile countries,
I would probably consider one password
instead because of that travel mode thing,
which is a really cool feature.
So at the end of the day,
you have to use what works for you
and what fits your threat model.
And something that I point out to a
lot of people is like,
If something is too painful,
people just aren't going to use it.
And so there's a good argument to be
made that SimpleX, for example,
is an improvement over Signal in some
ways.
It's more decentralized.
It's more metadata resistant,
things like that.
But there's also a bit of a learning
curve,
and it's missing a lot of the quality
of life features that Signal has,
like GIFs and stuff like that.
And so if people are constantly missing
their notifications,
and I know it's one of those things
that to some people it's stupid.
It's like, well, who cares about the GIFs?
But for some people, that's a big thing.
That's a nice little thing that keeps them
using it and keeps them engaged.
And if people aren't going to use it
for whatever reason,
then what's even the point?
So at the end of the day,
as long as you're meeting your threat
model,
it's okay to use something that maybe
isn't perfect,
but it still covers you and fits your
needs.
So-
Um, on the topic of signal.
Yeah.
Uh, Pingu said here,
they need more peer to peer stuff, uh,
block listed or anonymous and shared
automatically.
Yeah.
That can be kind of cool.
Um,
kind of like how matrix has that community
one, but, uh, yeah.
And, um, our, our forum question actually,
I've been keeping an eye on it.
Our forum thread,
this is a dag overhaul said no phone
number, just Kate, uh,
your KYC credit card.
That's a criticism that pretty much
everybody's been saying, but again,
it's something they're,
they're hoping to address.
And, um, it's something that, uh,
should be fixed in the future.
I definitely understand if you're like,
well,
I'm not going to use it until they
fix that.
That's totally valid,
but that is a common criticism that people
are disappointed by.
And again,
they have pledged to do away with it
and allegedly should not be tied to your
account in a way that's traceable anyways,
but you know, it is what it is.
Um, Oh,
people were talking to hear about
productivity tools.
Let me see what we got here.
Cause I had that other window open.
Um,
Eddie sync.
Yeah.
Eddie sync is really popular for like
local land syncing.
Yeah.
Pinky says a lot of these productivity
tools, harder to share data.
Please recommend other tools.
I mean, yeah, definitely.
It's...
for media channel is so niche.
I mean,
a lot of people use to do stuff.
Like a lot of my wife has straight
up said that, and my wife has ADHD.
She has really severe ADHD.
I'm very open about this.
And so like, yes,
for the average person whose ADHD is not
as bad as her, like me, for example,
I think it's fair to say like, Oh,
well just try, you know, try Vicuna, try,
uh, you know, next cloud.
I use next cloud personally try these
other things, but it's also, um,
For somebody like her,
she kind of has to use whatever will
work in her situation.
But I will say, yes,
the first place to start would obviously
be, I'm sure on Privacy Guides,
we have a list of recommended productivity
tools.
The one that she's been waiting on, sorry,
I started saying that and then I trailed
off.
The one that she's been waiting on is
Google Calendar has a task thing that
integrates with the calendar.
So when you add a task and you
say, this needs to be done by Monday,
it shows up on your calendar as well.
And Nextcloud does that,
but it's not quite as clean.
It takes a little bit more work to
set up.
Proton Calendar does not have anything
like that right now.
And my wife has straight up said,
she's like,
that is the one thing keeping me on
Google Calendar,
is if Proton would add something like
that,
she would be all in on Proton Calendar
in a freaking heartbeat.
But I'm trying to see here.
I'm on our website.
I'm trying to see if we have
recommendations for note taking or
productivity tools here.
I don't know if you have anything to
add.
I mean,
I think you need to use tools that
work for you.
And if the tool that you recommend,
like Vicunia or like Edisync or something
like this exists,
but it doesn't really allow you to
actually track the tasks that you need
and, and stay on top of things.
And it's like, well,
what's really the point?
Um, I think what they said,
please recommend other tools because
organizing to do's for a media channel is
so niche.
It's just, well, kind of your opinion.
I mean, it is my opinion.
Like that's,
that's kind of the whole point is we're
like sharing our opinions and answering
questions.
So, I mean, if that's,
that's kind of why we're here.
So, um,
I'm really sure why you would have an
issue with that.
But, um, I think the,
The thing that I kind of want to
get back to is, you know,
like I think you need to, like,
prioritize your –
your like needs first like even if you
were to use like Todoist and you know
maybe you would put some sensitive
information in there possibly you could
you know like put stuff in there not
under exactly what it is like you know
if you have an appointment at let's say
like a psychologist and you don't want
Todoist to know that you could put a
code name for it or you could put
something like that instead so you can
still remember the task but not give as
much information to Todoist so
I don't know,
it's kind of not the greatest solution,
but you kind of just have to use
like, I don't know,
like you just kind of have to use
tools that work.
And every privacy tool is not going to
always have the same usability as the
other non-encrypted ones.
So it kind of sucks,
but it's just like the situation we're in.
I don't want to, uh,
I don't want to beat a dead horse
or get too defensive, but, uh,
odd bite here said I deal with my
ADHD by forgetting everything and having
everything fall apart.
Yeah.
Um, that's kind of part of it is,
you know, if, if for her,
if she doesn't find a way to manage
it, it just doesn't get done.
And then I have to do everything.
And I've literally had breakdowns over
that before not to air too much dirty
laundry.
So yeah, it's, it's kind of like,
we have to use what works for us,
but, um,
Anyways, yeah,
we don't actually have a task section on
the website,
which kind of goes back to one of
the complaints that I've made in the past
of like, there are so many, like,
you know, people will be like, oh,
here's my new messenger,
number five million,
six hundred seventy eight thousand three
hundred thirty three.
And it's like,
we don't have a good task manager.
We don't have a good to do list
alternative.
Like, why didn't you code that instead?
So, yes, any developers listening,
please stop making messengers and start
making to do apps,
which which we really don't.
Um, we really need, yeah.
Like Pingu said,
I also have really severe ADHD.
People should still have shit that's
private.
Yeah, I agree.
And we should have more options besides
Vicuna and that's it,
which I'm on their website now.
I'll take a look at it for sure.
I will definitely look at it.
Um, and some people pointed out, I met,
I mixed up Eddie sync with sync thing
for the record.
So I apologize.
Yeah, you're right.
Eddie sync is something else.
I think edisync is interesting because I
remember we used to recommend it at
Privacy Guides,
but I think they had some pretty
significant delays on updates for a while
and it seemed like nothing was really
changing.
Maybe that's not the case now.
Maybe it still works.
Maybe it's good.
It would be interesting to learn more
about it if they've picked up development
again because it was a very interesting
project back when I was looking into it.
Let's have a look.
It does look like it still hasn't really,
like I'm looking at the server repository
right now and it's been updated two years
ago.
So I don't know.
It's interesting.
It's an interesting project and I wish it
was still getting developed because like
you said,
it is kind of a really useful tool.
And this Vicuña one, like, again,
I'm sorry,
I'm not sitting here trying to poke holes,
but right on the front page,
it says the task manager you actually own.
Vicuña is an open source task management
with lists, Kanban, Gantt, and more.
It's like, dude,
I just want a simple to like,
or my wife, I should say,
just wants a simple to-do list.
She doesn't need Gantt charts.
She doesn't need a Kanban board.
She just needs a simple to-do list.
And this, this seems like it's overkill.
And that's kind of like,
that's the same issue with next cloud,
right?
It's like next cloud is great.
And I like next cloud and it works
for me.
But for some people, it's like,
I don't need all this stuff.
I just need somewhere to store my
contacts.
I just need somewhere to store my
calendar.
Like for the longest time,
that was kind of my issue with next
cloud is I'm like,
what if I just want a calendar?
And now I'm glad that there's like two
to calendar and proton calendar and all
these other options.
But for a while it was like, well,
you can use next cloud or you're just
kind of screwed.
Yeah.
And I think sometimes it's nice to have
something that's just a little bit,
a little bit more aimed at consumers,
I guess, but yeah,
like collaborate with peers.
I don't know if she needs that.
Yeah.
Yeah.
It's, it's, it's,
it's frustrating that we don't have
anything that's kind of simple.
I guess just to kind of remind people,
just remember we can keep leaving our
chats in the, in the, in the,
in the chat and also on the forum.
And we'll try and get to those at
some point.
But I think we should probably try and
move on to the next article here before
we get too caught up with questions.
I guess I'll throw it back to Nate
to do that.
For sure.
Absolutely.
So our next story here is about ClickFix,
which I will explain what that is for
anyone who doesn't know.
But this comes from Ars Technica,
and it says that ClickFix attacks
infecting PCs and Macs are going wild.
viral um so for anyone who hasn't heard
of it click fix is basically it's a
type of cyber attack where you go to
a website and this actually happened to me
the other day um over at the new
oil i posted a short video a short
vertical video and i post those to youtube
loops and tick tock and i went on
my computer to ticktock.com i typed that
in and it took me to a captcha
that
looked kind of convincing.
I was like, all right, whatever.
And I clicked it and I passed it.
And then it popped up with some kind
of like download this certificate.
And I'm just like,
I don't think this is legit.
So that's basically what a click fix is.
It's a fake captcha that looks,
usually in some of the screenshots,
let me see,
he doesn't have any screenshots here.
But in some of the screenshots I've seen,
it looks very much like a regular
Cloudflare captcha.
But then once it's done,
It says like, okay,
now hit control V and then type this
thing into your Windows toolbar.
And basically it's instructing you to open
up the terminal and paste a set of
commands that you didn't know you copied.
And it runs malware in the background.
So...
I'll,
I'll switch over to the article here.
Now it says more seasoned internet users
are quick to dismiss the attack and they
typically blame people who fall for the
scams and marvel at their gullibility and
lack of attention.
But the reality is that for more casual
users using computers in the internet has
become so difficult.
Think impossible to close interstitials
captures when with endless series of
pictures to analyze quick note there,
I'm sure as privacy people,
we've all seen the endless captures where
you just keep filling them out.
It just refreshes and brings you more.
Um, you know, uh,
Constantly changing interfaces that bury
the features they're looking for.
Users have grown desensitized to
instructions that seem ridiculous and
burdensome.
So click-fix attackers capitalize on this
fatigue.
The attacks typically begin with a simple
capture image,
often masquerading as one from Cloudflare.
After engaging,
the user sees a line of text,
often obscured in a way to mask any
malicious commands.
The user is then instructed to copy the
text and paste it into Windows Run,
PowerShell, or macOS Terminal,
and click Enter.
Again,
these instructions come from websites
people have used for years.
Again,
went straight to TikTok.com the other day.
I need to make sure my DNS is
encrypted because that should not have
happened.
But anyways,
the directions seem no more suspicious
than the other things they've been
required to do for decades.
So why would someone without a firm grasp
of computer security have any reason to
hesitate?
The article says here for the people
behind the attacks,
ClickFix makes their job easier.
Prior to ClickFix,
they would have needed to install the
malware and then use resource-intensive
infrastructure.
But now they can basically just get users
to do it for themselves.
So...
The article does note that on Mac,
the situation isn't much better.
Mac security firm Jamf and a researcher
have documented Mac OS variations of
ClickFix that can bypass the gatekeeper
protections.
And let's see, towards the bottom here,
it says, yeah,
so the upshot of all this is that
ClickFix is a highly effective and
efficient means of spreading all sorts of
malware.
It's not going away and victim blaming or
shaming only makes the problem worse.
So, yeah, that's fun.
I'm going to go ahead and bring Jordan
back here, and I'm going to ask you,
do you think there would be any defenses
against this aside from, I mean, again,
you know,
more experienced users like myself,
when that little download window popped
up, I'm like, hold on,
something's not right here.
But like the article pointed out,
for the average person who's used to
having to jump through five hundred hoops
that may not recognize it,
is there any sort of passive defenses that
they can add that might act as a
safety net?
Yeah, I mean, apart from, like you said,
just like being knowledgeable that this is
a thing,
there are some things you can do,
I guess.
I guess the most important thing that I
think blocks a lot of these attacks is
just using Adblock or a content filter,
such as like, you know, uBlock Origin,
or you can use like DNS-based ones.
I think, you know, that's going to block
most like malicious looking ads um online
as well and a lot of um these
dns blockers also have um protection
against malware and a lot of sites that
are hosting this this content are blocked
by those so that's one thing um the
article itself also mentions this um this
software on mac os called block block
which basically will monitor your
processes and
It will see if something is operating in
a way that looks suspicious and it will
stop it from running.
So there's that as an option too.
And I think, you know,
apart from all the usual things that we
recommend,
keeping your computer up to date,
keeping your antivirus up to date if you
use one,
But I think in our notes we do
have to recommend, like, if you are, like,
considering a third-party antivirus,
that could be a concern too.
But obviously there's privacy concerns
with that too.
I guess, like...
you know,
just being kind of conscious of this is
the most important part.
I guess I can throw it back to
you.
Like,
what's the best way to kind of get
people aware that this is a thing?
Because I feel like it's one of these
new things that we're seeing more in the
wild now.
And it seems like people are falling for
it quite a lot.
Yeah, I think I mean,
I think articles like this are really
useful.
I copy and pasted this in my family
group chat personally.
And I was like, hey, guys,
if you are asked to open the terminal
or paste anything or download anything,
you should be aware that that's malware.
The nice thing about these kind of
articles and if you find a good video,
you can share that with your friends and
family.
Like the nice thing is it opens that
door to talk about it, right?
Like you don't have to
There's something really powerful,
especially if you are like the IT guy
for your family.
There's something really powerful,
like a social proof almost when something
comes from someone else.
And then it's not just you being like,
hey, guys, watch out for this.
It's like, hey, here's an article.
And a lot of the time,
at least with my family,
when I post stuff like that in the
chat,
they just kind of thumbs up and move
on.
But sometimes there's follow-up questions
like,
oh –
Does this happen on every website?
Or who's doing this?
Or things like that.
So I don't know.
To me, it is very effective.
It's not as awkward as it seems to
just post it and just leave it there.
And if people have questions,
they can ask.
But yeah, articles like this.
Again, if you guys know any good videos,
Yeah,
I guess that's kind of my question for
the audience.
Have any of you guys encountered that?
Again,
I had that TikTok thing the other day.
Are there any defenses you think we
missed?
Yeah, there's uBlock Origin.
It's helpful stuff.
It's not necessarily foolproof.
on the topic of antivirus,
I just want to throw it out there
real quick.
It's antivirus has come a long way and
good antivirus is no longer just like back
in the old day,
it was basically just like a list of
signatures and it was very, um,
what sort of look for it was very
reactive, um,
These days,
a good antivirus is a lot more heuristic
and it's not so much looking for a
signature.
It's looking for behavior.
It's looking for things that are behaving
like malware and making certain calls or
accessing certain files and stuff.
So it can be effective if you get
a good one.
But yeah, like we said,
I like the way that Kerry Parker describes
it is he talks about how it's like
having a bodyguard if you're like a rich
or a famous person.
Like that bodyguard will come with you
everywhere and he's there to protect you.
But that means he has to come to
your drug dealer's house,
your mistress's house.
He has to know all your dirty little
secrets because he has to come with you
everywhere.
And antivirus is kind of the same thing
where it will protect you,
but it's got to look at every single
thing that happens.
So there's a privacy concern there.
And I think there was actually something
that happened with Avast several years ago
where it got compromised.
So yeah, just beware of that.
That does happen.
Yeah.
I do love that analogy.
Haven't heard it before,
but that is a great analogy.
Yeah, he's used it a few times.
It's a really good one.
So yeah, I mean,
if you're a really high threat model
person where you're like, no,
this is worth it and I'm not doing
anything super sensitive on my computer,
then it's worth it for some people,
but just keep that in mind.
So Anand here said,
not the piracy site being malicious.
I mean, sometimes, sometimes it's not.
In a lot of cases,
it's just a legitimate website that got
hijacked, so.
The threats are never ending.
I've definitely seen this in the wild a
couple of times.
I've seen websites being like,
to fix this error,
to verify your identity,
please enter this command in the terminal.
And it's like, yeah, that's new.
I've seen it a couple of times.
So it is a new thing that's going
around.
So definitely keep an eye out for that.
I guess so.
We've kind of talked about that for a
while.
We can probably jump into this forum
update here.
This is from our community forum,
discuss.privacyguides.net.
And it's about the UK confirming that it
will make Apple and Google scan everything
people look at on phones and block nudity
for users who don't verify their age.
And there is a petition saying,
for the UK Parliament and UK Government to
basically stop this.
So if you don't understand how this works
in the UK,
basically if enough signatures are
obtained by a petition for the UK
Parliament and UK Government,
it has to be considered by the government
and they have to respond to it.
If it gets a hundred thousand signatures,
it will be considered for debate.
If it gets ten thousand signatures,
the government will respond to it.
So I think this is kind of a
good way to do things.
If you are a UK citizen,
I would recommend checking this out.
You should be able to find this on
the petition.parliament.uk website,
but you can also find this on our
forum as well.
So if you want to sign this,
it's currently only had two thousand
signatures,
so it would be good to
get more signatures on this because,
you know,
I think this is one issue that a
lot of people are concerned about.
We're kind of just sharing this because we
want to signal boost it.
If you're a UK listener,
be sure to share this around to people
and try and get people engaged about it.
We've talked quite a bit about this,
but I guess I can throw it back
to Nate here.
Like why, just quickly,
why are we against this?
Yeah, it's... You know,
this poster said it really well here.
It's like, it's not...
A lot of this stuff is...
I think it's one of those...
Like the risks outweigh the rewards kind
of things.
I mean,
this requires the phone to be scanning
every single item that comes through.
And that could... You know, Apple...
abandoned this initiative several years
ago because, um,
because they couldn't find a way to do
it that they felt was safe from abuse.
And one of the common examples is like,
okay, sure.
Right now we're just using it to like
filter for like CSAM or violence.
What happens when it turns into like
identifying people at a protest and
reporting that back.
And it's, it's also,
it requires like the whole age
verification thing.
Like, okay,
I need to prove that I'm so I
can send and receive pictures.
It's, it's, I mean,
there's so many issues with this.
It's like taking away your control of the
device.
And it's also like, um,
especially for younger people,
like the technology doesn't always work
very well.
Like if you're eighteen, nineteen,
you might still look seventeen, sixteen.
And not that I'm encouraging anyone to
send nudes for the record,
but it's just this this scanning
technology is not always very accurate.
It gives the government a doorway to,
you know,
the slippery slope argument to start kind
of pushing the envelope a little bit.
And I mean,
that is not paranoia for the record,
this whole slippery slope argument,
because we see it over and over again
where like
they roll out this surveillance technology
and they're like, oh,
it's just for like terrorism and sea
salmon, really bad things.
And also for drugs and also for violent
criminals and also for this and also for
this and also for this.
And now I see flock cameras everywhere I
go in my city that are just catching
random people driving around in the day.
And it's like,
what violent crime are we stopping here?
None apparently,
because I do read the local news and
I swear there's murder in the news every
single day.
So we're not stopping any violent crime.
But yeah, it's just, it's,
It's the potential for so many things to
go wrong and that it's taking away a
lot of agency from people.
So I don't know.
Did I miss anything there?
I think those are a lot of the
issues we usually have with this stuff.
Yeah, no, no notes from me.
All true stuff.
I definitely share this around to anyone.
And even if you're not in the UK,
share it because like, you know,
the more the more things,
more eyes we get on this sort of
stuff, the better.
And it's only got two thousand signatures.
So come on,
let's get this to let's get this to
at least ten thousand.
Yeah, while you were talking,
I actually did remember.
I'm like, oh,
I do have a friend in the UK.
And I went ahead and sent that to
him.
So hopefully he can spread it around too.
Somebody on Twitter said, good evening.
So hello.
Hi.
Thank you for joining.
I guess we can dive into some site
updates here.
So Nate, what have we got this week?
Yeah,
so a little bit later in the show,
we're going to talk about how a data
broker lost their domain,
which is awesome.
But first,
we're going to give some quick updates
about what we've been working on this week
over at Privacy Guides.
And again,
remember to leave any questions,
comments in the chat.
We'll get to them in a moment.
But first up,
we have a new video out.
We have the ultimate instant messenger
tier list.
Our last tier list video generated a lot
of conversation,
which I think was pretty awesome.
And Jonah went ahead and released this
video.
I will say it's a dramatic improvement
from mine.
There were lessons learned from my video.
And yeah, I thought it was pretty good.
It was cool to hear his thoughts.
there's a,
I'll say it's a little bit of an
Easter egg.
I mean, it's pretty easy to spot.
I just don't want to spoil it for
anybody.
There's,
there's something in there that I think I
originally suggested it as a joke and he
went ahead and put it in there and
I thought it was pretty funny.
So that's a, that is out now,
as you can see on the,
for video watchers, it's on peer tube.
So you don't need YouTube to watch it.
Or if you prefer YouTube,
it is over there as well.
Um,
We have some more videos coming up soon.
I think Jordan is almost done with the
Apple versus FBI video and posted a teaser
in the supporter signal chat, by the way.
So, you know,
you get little perks like that sometimes.
It looks like it's coming along really
well.
I am almost done with a script explaining
the history of FISA and Section seven oh
two and kind of.
how we got here and what all that
is.
Cause we,
we talk about it all the time,
but we don't really explain like what it
is or how we got here,
like not really in depth.
So maybe it's me cause I'm a nerd,
but I like these history videos.
Like.
sorry to keep using the phrase,
but explaining how we got here.
Cause I feel like the more I learned
about history,
the more things make sense now.
Like I'm like, oh, that's why this is,
that's where that came from.
So yeah,
this has been really cool and actually
gave me a million other ideas along the
way for like, oh,
we should talk about COINTELPRO.
We should talk about Watergate.
We should talk about this.
So yeah,
probably a lot more history videos on the
way.
And we also have decided to do another
tier list in the near future about email
aliasing services.
And that should be,
really really fun.
Do you want to take the site updates
before we respond to some questions here
in a second?
Yeah, let's dive into some site updates.
So there's been some movement.
There was a release on the website,
which is twenty twenty six oh nine
seventeen,
which was released two days ago.
And there are quite a lot of new
changes.
But firstly, thank you to Chas Nelson,
nineteen ninety for their first
contribution.
Die down nine nine eight nine and M.D.,
Evold also made their first contribution
in this release.
So thank you to the people in our
community that helped with fixing up some
stuff.
Kind of just covering a couple of these.
There were some issues on the donation
page with Delete Me and Power Up Privacy.
So both of those were removed.
Simple Login got an update in its section
to reflect the proton integration status.
And there was also an addition,
an update to the Windows guide where we
now recommend you to re-disable Windows
Recall in GP Edit.
There were some dead links that Freya got
removed.
We updated our Archbase
anti-recommendations.
So we don't have anti-recommendations,
but there were some leftover ones which we
got removed.
So that was good.
We removed some staging link previews that
were incorrect.
So those were removed.
in the README and there was also the
RETO swap issue so that was something that
I was looking at basically someone from
our community messaged us and notified us
that a RETO swap had a cyber incident
where basically people lost like millions
of dollars of Monero because of an issue
in the Havana RETO protocol so for now
Haveno doesn't actually recommend any
provider.
So we're going to remove RitoSwap for now
and see how things go.
And hopefully once things get into a more
stable position,
we can recommend a Haveno Rito provider.
But right now we can't because things just
don't seem super, super stable.
super stable,
so we're leaving that for now.
There was some issues with the wording on
the Tor and Molvad browser page,
so that's just been clarified.
There was also a recommendation to disable
Brave wallets as well,
and
Daniel has also added a rumdl config.
A couple of extra things and there's also
a Radaris manual opt-out link which was
removed by Freya,
which we'll talk about a bit later in
the show.
That's all interesting stuff.
As usual,
privacyguides.org slash news has been
going great.
We've been releasing lots of new articles.
As you can see,
Nate just launched a data breach roundup
this week.
If you want to keep up to date
with data breaches,
You can definitely check that out.
Highly recommend subscribing to that every
week.
I like getting that in my email every
week.
So definitely check that out.
UK's rolling out pass keys for millions of
citizens.
Signal enables phone numberless
registration in beta.
X's encrypted messenger.
XChat disappears from the app store.
And cops search flock databases for
reasons such as LMAO and LOL.
and random keyboard mashing.
So, you know,
if you want to be up to date
on kind of some of the latest news,
then definitely check that out.
There was also another issue with Revolut
giving away customer passports and selfies
to fake government requests.
So, yeah.
If you want to keep up to date,
definitely check out privacyguides.org
slash news.
But again,
I just want to remind everybody,
this is all made possible by our
supporters.
And you can sign up for a membership
or donate at privacyguides.org.
Or you can even pick up some swag
at shop.com.
dot privacyguides.org.
Privacy Guides is a non-profit which
researches and shares privacy related
information and facilitates a community on
our forum and matrix where people can ask
questions and get advice about staying
private online and preserving their
digital rights.
So now let's dive into this next story
about Meta's copyright system being abused
to suppress protests.
But remember to leave comments in the chat
and we'll get to them in between stories.
All right, Nate.
Actually, real quick on that note,
I think we will address a couple of
the questions that came in during the site
updates.
Hanu over on x slash Twitter asked,
what do you think about Session Messenger?
I've been using it for a few months.
That is one of the messengers that we
mentioned in the Messenger tier list
video.
It's not officially one of our
recommendations because it is missing a
few features like perfect forward secrecy,
for example.
um i know they're working to add that
back but i don't believe they're finished
adding that back uh when they do we
could take a look at it see if
it meets the criteria but um i will
admit me personally i have a bit of
a soft spot for session i i know
the guys for session um i've had good
experiences using it personally but i know
a lot of people have not a lot
of people have said that it's um a
little bit unreliable sometimes but um
I mean,
I would put it in the category of
like,
it's definitely better than just using SMS
and plain text, but, uh,
we do believe that there are better
options out there,
like signal or simple X, for example.
So depending on why you're using session,
like if you like that decentralization
model,
simple X might be something worth looking
into.
Um, and then, uh, a non asked here,
uh,
if we have any updates about the verified
apps thing,
I swear Jonah was talking about it with
somebody recently.
Um,
I looked through all the chats and I
couldn't find it.
So I think maybe I'm thinking of the
staff meeting this week, but, um, he's,
he's definitely still working on that.
I remember it did come up recently,
so it's still a topic of conversation,
but I,
I couldn't tell you what the latest is.
So like you said, that's,
that's his thing.
He's spearheading.
So I don't really know.
ask about it too much,
but it's still on his radar for sure.
I think it's,
there has definitely been updates.
I will just say that it hasn't been
no updates in months, just to clarify,
like Jonah has made some changes to the
app submission process and everything.
So there has been updates.
You'll probably hear something bigger in
the next month or so.
I think he's still working some stuff out.
So definitely kind of stay tuned with
that.
It's definitely a project that we want to
continue supporting.
Cool.
Thanks for adding that,
because I'm not paying attention to it at
all,
so I didn't know that there have been
updates.
But yeah,
let's go ahead and talk about one of
my favorite companies.
That's sarcasm, by the way.
Meta.
So Meta's copyright system is being
weaponized against Albanian protesters,
and
I guess to some extent,
I can't hate meta as much as I
usually do here.
But we'll talk about that at the end.
I'm actually going to read off my show
notes because there's Wired does really
good articles, but they also get really,
really in depth.
And there's like a lot here.
So I'm just going to read the parts
that I picked out.
so for those who don't know in albania
right now there is a series of protests
they're calling it the flamingo revolution
interestingly enough and it is sparked by
the development of a luxury resort that is
linked to ivanka trump and jared kushner
and they have been uh these protests have
been taking place daily in the albanian
capital for over three months demanding
changes in the law that allows development
on protected land as well as the
resignation of the country's prime
minister and uh
Meta is now having a series of accounts
that belong to protesters who are being
suspended as a result of multiple
copyright complaints.
And...
It's definitely one of those things where
like when you look at it,
there's no way that something is – I
mean actually you don't even need to like
– okay.
Let me back up.
So some of these accounts, for example,
will get multiple copyright claims at like
one in the morning all at the same
time.
So that's a little bit suspicious.
A lot of the people who have had
these accounts like suspended –
They say that they're getting copyright
claims for – they're posting videos of the
protests, right?
Like, hey, I'm out here.
This is what's happening.
And they're like,
what do you mean that's a copyright?
Like, I took this video.
I was there.
This is my video from my phone.
So that's what's going on here.
Now, the interesting thing,
in at least one case,
the complaint was traced back to someone
who claimed that they had been paid to
make the complaint.
The person actually – let me see if
I can find it here because I didn't
write this whole part down.
But basically the person managed to
somehow get a hold of the email address
of the person who –
uh,
submitted the copyright complaint and kind
of emailed him like, Hey, what's,
what's going on here?
Like, is this a mistake or something?
And the guy was like, Oh,
it's right here.
Um,
he texted me and said that he'd been
paid eighteen hundred dollars to report
these accounts and he would withdraw his
complaints if you pay me instead.
So these are people who are literally just
and I don't know anything about these
people.
Maybe they're in a really tough spot.
Eighteen hundred dollars is a lot of money
to turn down, y'all.
I'm saying that, too.
Like that's that's to report an account.
That's good money.
So I'm not judging these people too much.
I don't know what their situation is,
but they're also clearly like they're not
idealistically motivated.
Like, yeah,
you pay me two thousand and I'll take
the complaint back.
So.
That is worth noting.
But yeah,
the article says that collectively the
targeted accounts have reached millions of
people,
meaning that when they are restricted or
removed, millions can lose access to news,
political information,
protest documentation, and civic voices.
A Meta spokesperson told Wired that the
accounts were removed in error and had
been restored but did not comment on the
investigation.
The source of the attacks remains unclear.
Several have accused the Albanian
government of orchestrating attacks.
And the European Commission has confirmed
that an investigation is ongoing and
highlighted the role of the Digital
Services Act in enabling users to
challenge unjustified content moderation
decisions.
So, yeah, that's what's going on there.
I think that the reason this story really
captivated me and I wanted to talk about
it is because this illustrates that it can
be a little bit dangerous to rely on
these centralized big tech platforms.
We do appreciate all of our Twitter
viewers, but Twitter, for example,
Instagram,
these are platforms where
there's one person at the top and they
decide that you're out for any reason,
whether it's fair or not, and you're out.
And that can definitely be an issue.
So, Jordan,
what would you say that ideally in a
perfect world, you self-host it, right?
Like if you have your own self-hosted
cloud storage, for example,
or video platform,
Nobody can take that down,
or at least it's extremely hard because
they have to go directly to like the
hosting providers and the infrastructure.
And that's way harder to do than meta.
So what would you say are some of
the tools that we would recommend for
something like political organizing or
something in a situation like this?
I think like, obviously we need to,
I think when it comes to like political
organizing,
you still need to reach the most amount
of people, right?
So I don't think we would advocate for,
you know,
don't use any of these platforms because
obviously you do need to use those
platforms to reach where all the people
are.
So still keep using these platforms,
but I think offering alternatives to those
platforms that people can access the
information as well without it being
controlled by like a big tech company is
also really important.
I think, you know,
having your organizing happening on a
Facebook messenger group is probably not a
good idea.
Please stop doing that.
I don't know why everyone seems to think
that's a good idea.
Please stop using Facebook events and
getting everyone to RSVP because that's a
really bad idea.
It's got a list of everyone going.
That's just a bad idea.
I'm sorry to stop doing that.
But you know,
if you're using it to post, like,
like Nate said, this,
this article is about people posting like
stuff that happened at this specific
like, you know, protest, then I think,
you know, if you're posting that publicly,
that kind of makes sense.
It's a good use of that social media
platform.
But I think, you know,
if you've got groups that need people to
message in, I would suggest, you know,
maybe try a Signal group instead.
You don't need to put everything on
Facebook Messenger.
You don't need to make everything
inaccessible to people that don't have
those accounts.
I think Signal is a decent middle ground
for people.
It's easy to sign up for.
It's not hard to use.
It's a good option for that.
NextCloud and CribPad, you know,
for organizing like documents and stuff,
I think that's a fair alternative to
Google Docs.
I think if we can avoid using Google
Docs, that would be great.
I think too many places are also using
that as well.
But I would just urge people to just...
be a little bit more aware of you
know if you're organizing something make
sure that everyone can access it um
because too many times i've seen people
organizing protests or any sort of
movement like this and they would limit
everything to instagram and facebook and i
think it's it's a big loss for people
if they don't they're not going to be
able to find that information without
having an account and being locked into
all these platforms so we need to try
and avoid that um
But I guess, yeah,
do you have any thoughts on how people
can kind of organize and get information
at scale while staying kind of, you know,
resistant to censorship and stuff?
Or are you kind of on the same
page?
Yeah, no, it's...
Yeah, it's like you said,
it's it's it's tricky because and for the
record, I just want to point out here,
we're we're kind of taking a very high
level view of like mass protesting.
I know that if you're like deeply
politically involved,
that's a very advanced threat model that
kind of deserves a one on one discussion
and not really like a.
talking to the masses platform like this,
but yeah, it's,
it's really about what are you going to,
or what are you trying to accomplish?
Cause I think, um,
like you mentioned like the Facebook
events and, uh,
I'm thinking of like EFF Austin,
for example, where I sit on the board.
Um,
we use meetup.com to broadcast our events,
but it's public.
And we even tell people like people get
mad at us sometimes like, well,
I don't want to use meetup.
Then don't like, you don't have to,
in our case, I know not everybody,
some groups are like,
please RSVP.
So we know how many people to plan
for.
We specifically tell people, it's like,
you don't have to RSVP.
Like you can totally go there and just
look at the page without logging in and
then just be like, all right, cool.
It's here at seven PM on Tuesday.
See you there.
Like that's totally fine.
And so I think it's like considering that
kind of stuff.
Like you pointed out,
like if you're going to make a Facebook
event,
if you're one of the organizers and you're
like,
I'm going to make this Facebook event to
let people know and like do it in
a way where people don't have to RSVP.
And if you're one of the viewers,
please don't RSVP.
But yeah, I mean,
like when it comes to internal, you know,
communication and stuff, Michael Lee,
I actually went and found it here.
I'm going to share this tab real quick.
Michael Lee has a tutorial on his website
about using signal groups for activism.
And he talks about how you can like
vet people,
how you can manage public groups,
how to make announcement only groups that
are kind of like telegram channels where
like other people can't post.
And, you know, keep in mind anytime,
anytime someone, something is public,
like, again,
he has advice on how to vet people,
but there's always a possibility there
might be someone there that,
Thank you.
might've snuck in somehow.
So, you know, there's threat modeling,
there's all that kind of stuff to keep
in mind.
But yeah, I mean,
there's like different tools for different
jobs.
Because like you were saying,
there's certain things where it's like,
oh,
I'm documenting this like violence that
was happening at this protest.
That needs to go, for better or worse,
that needs to go on the public platforms
like Instagram, you know, YouTube,
stuff like that,
because that's where people are and that's
where you're trying to get the word out.
But I think this is also where it's
useful to have, you know,
maybe like a ProtonDrive link
that people can publicly share.
So if it gets taken down on YouTube,
people can still like share the link
around or whatever.
So that would be my argument is, yeah,
just try to think in that case,
in terms of resilience,
try to make it something where,
and especially again,
if you're like one of the organizers of
some kind of movement,
like do people know where to go if
your Facebook account gets banned,
if your Instagram account gets banned,
if it's just like, oh,
they banned me and I lost all three
thousand people I was talking to.
I mean, I'm not trying to victim blame,
but that's kind of a failure to plan
ahead on your end.
And obviously you're never going to get
anybody, right?
Like maybe only two thousand people follow
you to this other platform.
But at least people know like, OK,
if this page goes down, go to YouTube,
go to Tumblr.
I don't know.
Go to Mastodon, whatever.
Like just having that resilience in mind,
I think, because, yeah,
it is it is a shame if people
are not breaking any laws here and are
just being silenced.
That's extremely not cool.
So, yeah.
Yeah.
I think also don't underestimate your
ability to advocate for these platforms at
these like organizations.
You know, if you just say to them,
if you,
if you just get involved with these groups
and you bring these things to them,
I guarantee you,
like I've done this multiple times and
they were fine with opening a signal
group.
They were fine with having a master on
page that they posted to as well.
Like there's,
there's many things that you can do.
a lot of people will be just unaware
of these issues.
And if you bring it to their attention
in a way that is respectful and
understanding,
then I think you can really make a
difference with this sort of stuff.
And the more people that are not using
Facebook meetups, the better.
If you can try and explain that to
people.
Some people,
I guess it depends on the organisation,
but I think a lot of times people
will understand.
Yeah.
It's definitely worth getting involved.
For sure.
Yeah, I mean,
if you guys have any other ideas in
the comments,
something we missed about ways you can
organize or, again,
get information out at scale,
then definitely let us know.
But in the meantime,
I think we'll turn things over to Jordan
and check in on another forum update here.
Yeah, so busy week on the forum.
We've had quite a lot of nice threads
going on this week.
Nate's kind of been busy adding these into
the show notes this week.
A lot of good discussions this week.
Great, great discussions, yeah.
This one here is someone posted at the
start of this week in the general
category,
what messenger do you use for people who
won't use privacy-preserving apps like
Signal or SimpleX?
So I think the easy answer to this
is...
if you live in the US or if
you live in,
I would say like some countries,
you can't really generalize,
but if you live in a country where
everyone has iPhones,
I would say iMessage,
which kind of sucks because then you kind
of have to have an iPhone.
But that is kind of like the default
in a lot of places,
especially in the US.
I know most,
I think it's like everyone under twenty
five is basically all on just iPhones.
So
I've experienced this.
I don't see many young people using
Androids.
So, you know, that's an issue.
I think, you know,
if you can put up with using an
iPhone, that's like, eh.
It's not the greatest option.
I think we're getting to a point now,
though,
where RCS is interoperable between
platforms and RCS encryption.
So that would be probably the least worse
option because, you know,
at least then you don't have to have
an iPhone,
which Oddbyte in the chat seems to be
very passionate about.
I'm happily not using Crapple.
I mean, yeah.
So, you know, not every young person is...
is using Apple,
but I think it is just a,
it is a statistical reality.
Unfortunately,
it's just what young people are using.
So we need to need to be aware
of that.
I think that's kind of my initial
thoughts, you know, RCS,
iMessage use these sort of middle ground
options.
I would say try and avoid the other
platforms if you can,
because they're probably not great from a
privacy perspective.
What do you think, Nate?
No, actually, I totally agree.
I remember back when I used to work
with Henry at Surveillance Report is he
mentioned that too,
that a lot of the time if people
don't use Signal and they're not willing
to get Signal because that's his primary
messenger, he's an Apple user.
And so,
or at least he was at the time.
I don't know if he's changed his mind
since then.
But he was like, yeah, at that point,
I'll just add them on iMessage.
Because like you said,
here in America especially,
iPhones are super common.
I do see some Samsungs.
I am actually seeing a lot more Pixels
lately, which makes me happy.
But definitely by far,
I think in the US,
the market share for Apple is something
like seventy five percent or something
crazy like that.
So at that point, like you said,
statistically speaking,
the people you're talking to probably have
an iPhone.
And I mean, like
I'm with Oddbite.
As an Android user,
I'm not going to carry around an Apple
just to iMessage people.
But with something like Google Messages,
yeah, it's a privacy nightmare.
I've specifically pointed out with Google
Messages specifically,
they have been accused in the past of
hashing your messages and comparing hashes
so they know who you're talking to and
they're recording all that metadata.
um but especially now with like graphene
rolling out their rcs messenger um the
point is it's giving you more of that
option where it's like okay my choices are
either sms which basically should be a
postcard it's so easy to crack it has
basically no encryption at all
Or I can at least get some content
protection.
Like with SMS, you're getting everything,
right?
Like you're getting the metadata,
you're getting the content.
With RCS,
at least you're only getting the metadata.
It's still not great,
but it is a definite improvement.
And it's like, I don't know.
I've never really understood...
Okay,
I'm going to get on a soapbox for
a second here.
I've never understood the people who are
like, oh, something isn't perfect,
so don't use it.
And I'm talking about where there is no
better option.
So, okay,
if you run into somebody who's like,
I absolutely refuse to put another app on
my phone.
I'm not using WhatsApp.
I'm not using Signal.
I'm not using SimpleX.
I'm not using Session.
No, you can text me.
You have the choice between RCS and SMS.
Why would you pick RCS or SMS?
It's like if somebody tells you like,
you know, you have two doors.
If you open one door,
you're definitely going to get punched in
the face.
But if you open the other door,
there's a fifty fifty chance you might get
punched in the face.
Who's going to open the door where they
know for sure they're going to get punched
in the face?
I've never understood this logic,
but I see this logic a lot.
Um, so yeah, I mean, it's,
it's definitely not ideal and it is really
unfortunate,
but somebody in here did kind of point
out that like,
sometimes you just have to use what people
use, like, um, you know,
for better or worse, like, yeah,
maybe you can talk them into like, oh,
it turns out they use WhatsApp,
which again, a lot of metadata concerns.
But if you both have WhatsApp for whatever
reason, like to me,
that's still better than SMS.
So
But you kind of have to,
if they're not willing to download an app
at that point,
you just kind of have to work with
them and be like,
what do you have that's at least not
SMS?
And so, yeah,
Oddbite very much disagrees with me.
He says SMS is more open.
RCS is a pain in the ass.
Like, yeah, I mean, it's an open standard,
but again, it offers no protection.
I don't see what the,
who cares that it's an open standard.
I don't see what the protection is there,
to be honest, so.
I do.
You're kind of on fire with the analogies
today.
Not going to lie.
I've used that one before.
That one's me.
I'm not going to lie.
That one was me.
And I've used it before.
Okay.
Yeah, no, I like that.
I like that.
I like that analogy.
I think this is the other thing is
that we should probably talk a little bit
more because, you know,
there is the entire other part of the
world called Europe and whatever.
And like, you know,
they use all sorts of different things.
WhatsApp is kind of a thing there.
It's the main thing.
So I would say, you know,
people are much more on WhatsApp there.
So I'd say, you know, if you,
if you are in
in a country where there's one of these
messengers that's like the one that
everyone uses,
which I know there's certain countries
where it's like Viber or it's WhatsApp or
it's in Australia,
it's unfortunately it's Facebook
Messenger.
You kind of just have to suck it
up sometimes.
I think...
If you can limit, you know,
the permissions that you're giving these
apps and stuff, that's definitely a help.
I think WhatsApp is not the worst.
You could do worse.
So, you know, I would say, yeah,
I think what Nate is saying is correct,
though.
I think we should try and
We should try and prioritize tools that
actually give protection.
Obviously, you know,
the level of protection is kind of gonna
be dubious with some of these,
but I think anything that has any sort
of encryption is going to be better.
Um, I will say odd bite.
I am not using Facebook messenger.
I have not caved to it yet.
Um, when I was in university, it was,
I was using it, but not anymore.
Um, it's really bad,
but everyone uses Facebook here.
Um, if you're, if you're,
if you're a uni student, if you like,
uh, that age, then you'll,
you'll know what I mean.
Um,
Here it's just very ubiquitous.
So anyway, it kind of sucks.
It just depends on the country that you
live in and what people use.
But I would say, you know,
move more towards things that offer
protection.
Like just because something is open is not
really a good excuse to use it.
I don't think if your messages,
just remember like your SMS messages could
be stored and saved forever.
Those messages that you sent.
Or like,
I know Nate's talked about this a couple
of times, but there's been like,
you know,
hackers inside the United States telecom
system,
like getting people's data and storing
those texts and all sorts of stuff like
that.
So that's just such a huge concern that
I think, you know,
any app that offers any sort of end-to-end
encryption is going to be better than
that.
So,
but you can kind of prioritize certain
aspects, um,
try and reduce the data that's being
collected and stuff.
But kind of a sucky situation.
But hopefully that kind of discussion
helps some people in this thread.
Was there anything you saw in this thread
that we should touch on before we move
on with things?
I was going to say real quick, yeah,
T-Mobile has had like a billion data
breaches,
some of which have included text message
content.
And T-Mobile is one of the biggest
providers here in the US.
So yeah,
even without that whole backdoor thing
I've referenced a few times.
The only thing I'll add is I saw
a surprising number of people in this
forum thread talking about Telegram.
And I'm going to write a blog post
about it soon over at The New Oil,
but I just want people to know I
don't think you should trust Telegram for
anything.
They've been lying to users for years.
We talked about this a little bit in
our encrypted messaging video here at
Privacy Guides, but...
You can also go check that thread because
I posted an old story from Surveillance
Report where we found out that Telegram
was lying to users for years.
So yeah, I said not even joking,
I would literally rather not have a phone
than use Telegram.
So yeah, when you're like,
you could do worse than WhatsApp, yeah,
you could do Telegram.
And then, yeah,
I think that's kind of about it.
Terracotta said that I might be talking
about perfectionism.
It's more of a community thing.
I'm going to show one of my own
things here.
This is personal opinion stuff,
but over at the new oil,
ghost.thenewoil.org,
one of the pin posts I have is
called the Harm Reduction Model of
Privacy.
And that's what it is,
is I'm talking about people that are like,
oh, well, if I can't use, you know,
Arch Linux, like,
but they'll say to other people,
that's the thing is they'll be like, oh,
well, if you can't use Arch Linux,
there's no point in even changing the
settings on Windows.
And it's like,
or there's no point in using Mac.
And it's like, why?
And that's kind of where I came up
with that analogy of like getting punched
in the face.
It's like, you know, because they're like,
oh, well, you know,
what if changing the settings don't do
anything?
Yeah.
Then you're right back where you started.
What if they do something like,
what do you have to lose by changing
the settings and trying to make it suck
less?
And like, yeah, if,
if you can switch to something that is
considerably more privacy respecting,
of course you should,
I'm not saying you should stay where
you're at, but you know,
sometimes you're like,
you mentioned you were in university and
you had to like,
use facebook messenger with other people
i've i've also met people who are like
i'm in college right now and everyone uses
whatsapp but the minute i graduate i am
deleting that you know so it's yeah it's
um it's a very unhealthy mindset i think
but i could rant about that forever so
i think we'll uh we'll just go ahead
and move on to our next story here
about um tick tock and google and also
linkedin but
Yeah, so this comes from the markup.
Let me throw this up on screen here.
And this says how TikTok and Google ended
up with information about doctor's
appointments around the world.
Yeah, friendly reminder before I jump in.
Definitely, if you have any questions,
comments,
go ahead and leave them in the chat.
We'll get to them in between stories about
anything we're talking about or anything
else.
So for anybody who's been following The
Markup for a while,
this is actually kind of a continuation of
a series they've been doing.
They call it Pixel Hunt.
There are...
A lot of you probably know this.
There are analytics tools out there like
Google Analytics.
The Metapixel is a really famous one.
For some reason,
Snapchat and TikTok have their own
analytics tools.
And when you embed these on a website,
which for the record, I don't...
It's probably me,
but I don't understand why there are
people out there embedding multiple
analytics tools on a website.
But when you embed these on a website,
it gives you insight about people who
visit.
What operating system are they using?
What's their screen size?
And like...
Ostensibly that stuff can be useful to the
web developer to help them make sure,
you know,
if eighty percent of their visitors are
coming from an iPhone or just a mobile
phone in general,
then they know that that's what they need
to focus on is making sure the mobile
experience is ideal.
So the problem is a lot of these
analytics tools are embedded on medical
websites.
And a lot of them are collecting way
more information than they should.
The article says,
including specialties and names of
doctors,
and it is being sent to social media
companies like TikTok, Google,
and LinkedIn.
So again,
this has been covered quite extensively
here in America, but...
This article is showing that this is a
global issue because this article focuses
specifically on South America.
So, for example,
they teamed up with Agência Pública,
which I probably screwed up that
pronunciation.
Apologies to everyone in Brazil.
But that's an investigative journalism
nonprofit in Brazil.
They reviewed a website called – what was
it called?
Doctoralia, which is similar to Zocdoc,
if anyone has ever used that, I haven't,
but they say it lets people look for
healthcare easily and search for a variety
of providers in the area and book
appointments.
And as part of the series on web
tracking,
we looked at the network traffic between
Doctoralia domains in multiple countries
and popular social media sites.
According to traffic logs,
embedded online trackers followed visitors
in Brazil, Colombia, Mexico,
and other countries from nearly the second
they started to search for care and then
sent that data to tech industry for
advertising purposes.
So for example,
if a visitor search for a gynecologist
based in Sao Paulo,
then the website sends searches for
provider specialties and other information
to Google through its marketing platform.
If the visitor continued through to book
the appointment name and other information
on the doctor,
as well as the date and time of
the appointment was also sent to the
company.
And, uh,
They basically just talked about how they
tracked this down in Brazil, Colombia,
Cartagena – again,
probably mispronounced that.
I'm sorry.
Bogota.
I know I pronounced that very, very wrong.
So yeah,
it's – and the interesting thing they
pointed out here is that this is kind
of a –
What did they say?
Some of these countries like Brazil,
for example,
do actually have privacy laws.
They're not quite as good as GDPR,
which I know some people have complaints
with GDPR too.
But it's not like America where it's like,
well, just do whatever.
And if anybody complains,
it sucks to suck.
But even in those countries,
they did – there was somebody who said
that –
Man, where was the quote?
There was a quote about basically,
at very least,
governments should be looking into this
because this probably runs afoul of civil
privacy laws.
And of course, the companies were like,
no, we follow laws.
We care very much about laws.
And my favorite thing is the tech
companies always blame the users.
So Google...
Google and Facebook, for example,
they are notorious for being like, no, no,
no,
we don't allow for sensitive medical
information.
We don't allow for like political
information.
This is all like very sensitive
information and we don't want them to send
it to us.
Then why is it configured into your tool?
And that's always what they do is they
say like, well,
it's on the sysadmin installing this tool
on the website.
They didn't configure it right.
They're supposed to configure it so it
doesn't send us that information.
We don't want that information.
Then why did you build the capability into
the freaking tool in the first place?
Yeah,
big tech companies being big tech
companies.
Yeah, I'm skimming the notes here.
They said similar data was shared across
other countries with other tech giants.
Dr.
Aurelia said it would conduct a detailed
review of its practices,
but says that it does not monetize patient
data because I guess that's better that
they're spying on you as long as they're
not selling it.
I mean, I guess it could be worse,
but still.
Oh, here's a quote.
The tracking on Dr.
Ali has started before any personal
information such as email address or names
were entered,
but trackers are often tied to unique user
IDs.
Social media companies say that they can
tie users' social media profiles to
browsing behavior through such
identifiers,
and it says the tracking happened across
providers and borders in Latin America.
So, yeah, again,
the big takeaway there is that this is
actually –
this is a global issue.
This is not just something that's been
happening in America.
I'm really glad the markup is, is, uh,
shining a light on that.
Again,
some of these countries do actually have
decent privacy laws in some areas, but,
um, Jordan,
I'll toss it over to you to this
one.
What's in your opinion,
do you think there's any defenses the
average person could take, um,
while trying to protect their privacy in,
in these kinds of areas?
Yeah,
this is kind of like one of these
situations where like, uh,
These a lot of times when we hear
about this sort of stories,
these stories where it's like, you know,
they're linking things to like in this
case,
it was unique IDs or if they're like
anonymizing things to like make it so it's
not actually linked back to someone.
You know,
a lot of times this isn't as robust
as we think.
Yeah.
I think obviously we can always recommend
using like privacy browsers,
using uBlock origin,
blocking these sort of scripts from
running entirely is kind of like a good
way of doing it.
But again,
ideally this shouldn't actually be a
concern.
Um, this should be like illegal.
Um,
this shouldn't be like something that
companies can even think of doing or,
you know,
I think a lot of times if it's,
uh,
The way that it works here,
I don't know how it works in Brazil
or in the US,
but having these sort of trackers on
websites that are related to health
information is amazing.
illegal um so like it doesn't really
happen you can check when when you're
going through like the signup process you
can use ublock origin you can check to
see which connections are being made you
can see the amount of things that are
being blocked you can see the things that
are loading it's kind of a pain in
the ass you shouldn't have to do that
but it's just kind of the reality in
some countries where like you know it's
kind of the wild west like they're not
really um
There's not really legislation that
prevents this.
I think privacy laws can only go so
far sometimes because negligent businesses
can do this sort of thing all the
time.
I think we've seen this.
It feels like this has been going on
for years.
Websites that were medical information,
people were submitting their information
and it had a Facebook tracking pixel and
it was collecting everything.
this is like an ongoing issue that we've
been seeing for quite a while.
So I think kind of the,
the thing here is like, like I said,
you know,
you can see the connections that it's
making, but is there,
is there ways for people to find medical
providers that aren't doing this?
Is there, you know,
resources for that or is this sort of
just one of these things you kind of
have to do your own research on?
Yeah, I, I'm not sure.
Um,
I'm a veteran,
so I've always gone through the VA,
so I don't really have – I mean
I could go through private healthcare,
but why would I do that?
It's crazy expensive here in the US.
So I personally don't have a lot of
firsthand experience with this,
but I know that, for example, my wife,
when we have insurance,
she can go to the insurance provider's
website and look up who's in network and
who's covered insurance.
I mean, I'm kind of,
kind of struggling to think of other ways
you would look for it.
Cause I mean,
the only other alternative is to go to
like a search engine, right.
And just be like, you know,
OBGYNs in my area, my zip code.
It's, and I mean, you know, I guess,
yeah,
at that point you could use like a
privacy respecting search engine, but, um,
it feels like one of those things where
like, yeah,
there's not a lot of great options here.
I feel like the best you can do
is, you know, private browsers,
brave Firefox with you block origin.
And I mean, there's always like a, I'm,
I'm a really big fan of like having
dedicated like,
like a dedicated voice over IP number
that's just for or even maybe even a
dedicated SIM number just for like your
bank and your doctor and like all those
really important accounts and maybe even a
dedicated email or email alias saying if
you pay for like simple login and you
can have like ten billion different emails
and I give literally everybody a unique
email address.
So
But yeah, even then it's like,
that won't protect you from like a lot
of these trackers.
And that's the thing is like, I know,
um, I don't think this article said it,
but in the past, excuse me,
some of the other articles we've covered
to the markup on this, this subject,
they were sending like information that
you would type in the box.
So like you'd go and you'd like schedule
an appointment with your doctor and maybe
it might ask, like,
can you give us a brief explanation of
what, what your issue you're having is?
And you, you know, you type in like,
um, yeah, you know, I've been like, um,
Like waking up in the middle of the
night,
coughing really bad at two in the morning
for the past three days.
And, you know,
if you type that in or something even
worse,
I'm purposely trying to keep it tame
because YouTube and public streaming.
But, you know,
if like I always tell people, I'm like,
do not lie to your doctor because they
need to help you.
And.
The best well-meaning doctor cannot help
you if you go in and you're like,
I have an issue,
but it's really embarrassing.
So I'm going to lie and say it's
something else.
Like that doesn't help anyone.
So you have to be open with your
doctor.
And it sucks that a lot of the
time they're pulling this data.
Some cases, like I said,
even that like sensitive and actually
since the last time I talked about this,
now we have LLMs and there's people
recording their conversations and feeding
it into there.
So yeah,
medical is turning into a privacy
nightmare,
but-
Unfortunately,
I feel like it's going back to the
idea of harm reduction.
There's only so much you can do,
I feel like.
Because you still got to get medical care,
right?
I don't know.
I don't know that there's a good solution.
Yeah,
it seems like everything in that field is
kind of going in the wrong direction,
unfortunately.
But I think you can try and decline
these things when it happens.
I think there's a lot of pressure.
I can't lie.
I've been to the doctor a couple of
times and, you know, they said,
do you want to use this tool?
And it felt like I was being pressured.
It felt like I was if I said
no, they would say, oh, don't worry,
it's all private.
It doesn't get saved or anything.
And then I felt like I was being
pressured.
And I ended up saying yes.
And it's like,
this is kind of problematic when we start
like normalizing this stuff and,
and forcing people to do that.
I think that's another issue with,
you know, people will say,
just go in person,
just don't tell them anything.
Don't sign up through like a web portal,
just go to the place and book an
appointment through that.
And like,
don't give them information through the
web portal and avoid all that.
But you know,
there's all these other aspects that are
also kind of problematic to, um,
that can happen in person now,
unfortunately.
So, well, and even when you go in,
sorry, I don't mean to cut you off,
but even when you go in person,
like a lot of the time, um,
you know,
my wife and I have gone to the
ER a couple of times and every time
we go, they text her, you know,
we check in and then they text her
the paperwork to like fill out.
It's not even physical paperwork anymore.
And I mean,
I'm sure I could go up and probably
ask like, Hey,
can I get a physical copy of this?
But it's also, there's like a,
there's like a, um,
almost like a power imbalance there,
right?
Like,
if you go to the ER at three
in the morning, like,
do you really want to be that guy
that's like, no, give me the paperwork.
Like, I want to read through everything.
I want to cross out that they... No,
somebody's in pain.
Just get me in a freaking bed.
It's like, that's not really...
It's such a, like...
you're not really in a position to be
making demands like that.
And I mean, like,
I know like legally they have to treat
you and you know, doctors and nurses,
they're good people.
They're going to treat you,
but it's still like, it just, to me,
it feels like I hate to keep using
the same word,
but it's just a power imbalance.
Like something's wrong there.
It's not the time to be worrying about
that.
And it's unfortunate.
So yeah.
Yeah.
I don't know.
Yeah.
Do you have anything to add there?
No,
I guess we can jump into this next
forum update, another forum update.
So this one is from our forum,
discuss.privacyguides.net,
and it's about how to preserve anonymity
under camera surveillance.
So, you know,
this is kind of a discussion of how
to be kind of more anonymous in public.
I think there's some interesting thoughts
that people are sharing here.
I think
There's definitely some interesting
products that exist that kind of have sort
of shielding protection against
surveillance cameras and stuff like that.
And I think some people here brought up
some
interesting points, I would say, um,
you know, wearing all black,
wear a ski mask or a hood and
a medical mask.
Um,
I don't think this would attract much
attention, to be honest.
I think a ski mask would,
I don't think, you know,
wearing a medical mask,
I think that's pretty normalized at this
point after, after COVID-Nineteen.
I think you can get away with that.
I do that.
No one really cares.
Um, I think, you know,
there's certain things you can do.
I think
I don't think people will really worry
about if you're wearing some like
surveillance camera blocking gear,
I don't think you'll have any issues.
I think people are mostly just minding
their own business.
And if you look kind of just,
you know, Oh,
just a person wearing all black,
you know what I mean?
It's not that weird.
I don't think, um,
but I guess it really depends where you
live and what people think.
Um, because yeah,
I think you can definitely,
you can definitely draw attention if you
if no one dresses like that where you
live, then maybe.
But I think there's always interesting,
some interesting comments here.
Was there anything you were thinking there
or?
No, I think kind of like you said,
like, yeah,
there's certain things that like,
you know,
a COVID mask doesn't really stand out.
And I think I really want to get
the the reflecticles glasses next time I
buy glasses.
He sells out really fast.
That's the problem.
And it's like right now I don't need
new glasses and I don't want to drop
that kind of money.
But, you know,
is it like by the time I'm ready
for glasses,
is he going to be sold out?
So, yeah.
Somebody said an umbrella may work,
but not during regular days.
I don't know, man.
It gets really hot in Texas.
An umbrella really helps keep the sun off
you.
But it's, yeah, I think,
I guess I have two thoughts here.
One is, how does it say?
There's a saying that you spend a lot
of time wondering what people think about
you, and the truth is they don't.
And like, yeah, you know,
like you might look weird walking down the
street and like your anti-surveillance
shirt or whatever.
But nine out of ten people,
they're going to like, yeah,
they'll look at you and be like, well,
that's a weird shirt.
And then they'll just move on with their
day.
Like I'm trying to think if there's
anybody I've ever seen just walking down
the street that stuck with me.
And the only answer I'm coming up with
is I saw Santa riding a horse in
July one time and I'm not making that
up.
Um,
and that's the only thing I can think
of that was so weird that all these
years later, I'm just like,
that was strange.
Um, so yeah, I mean, generally speaking,
if you're wearing your big aviator
sunglasses, if you're wearing your,
your mask,
as long as you're not causing trouble,
I don't think people are really going to
care too much.
Um, maybe don't do that in the bank,
but generally speaking.
And the, the other thing is, you know,
a lot of people are talking about in
this thread,
they're talking about things like gate
recognition or like thermal recognition.
I don't know how common some of that
stuff is.
And it kind of goes back to not
to keep harping on it,
but it kind of goes back to what
I was saying earlier about like harm
reduction is like, like, yeah,
it's cool to be aware that this technology
exists and to know that it's there,
but there comes a point where it's like,
what are you going to do about it?
You know, are you going to be,
I think it was Julian Assange who famously
like put a rock in his shoe so
that when he walked to the embassy,
his gate was thrown off and they wouldn't
recognize him.
Like, are you going to do that everywhere?
And you're just going to like screw up
your feet just in the off chance that
the camera on the street has gate
recognition.
Like you kind of have to balance it
a little bit and not let the,
the fear and the paranoia get too far
away from you.
So yeah, I don't know.
I mean, it's,
it's an interesting discussion and I think
it's a great thought experiment to think
about for sure, especially as, um,
We've raised the point on this show a
few times that, you know, like, okay,
yeah, we can,
you can switch to Linux and you can
switch to graphene and you can like evade
all the age gating stuff.
And, but like,
what are you going to do about the
flock camera that's right outside your
neighborhood?
So unfortunately surveillance is moving
into the real world.
And I think it's really important that we
think about it a little bit more and
at least ask ourselves these questions.
So somebody said,
if you live in the South,
you can order a large sombrero.
So, you know, whatever works for you.
Um, but yeah, that's,
that's all I got on that one.
Um, if you, I don't know, let,
let us know what you guys think in
the comments.
What,
what methods can you guys think of that
again, are not like inconvenient,
like you're going to mess up your feet,
but also possibly helpful.
So, and, uh, on that,
I think we'll move into the next story
unless you have anything to add.
Alrighty,
then let's talk about some good news.
Let's talk about a data broker who got
their domain taken away.
so this comes from brian krebs who is
an amazing investigative reporter uh
definitely recommend following his stuff
he posts these really good uh detailed
articles and uh so there's if you're
familiar with the space you probably heard
this name at least in passing there's a
data broker called radaris radaris.com and
uh you know it's one of those things
where they collect all your information
and then people look you up and it
says oh this person
lives here and, you know,
works here and is related to these people
and has this phone number and this email
and blah, blah, blah, blah, blah.
What made Radar special is they are one
of the ones that has a reputation for
ignoring requests to take down
information.
And like many of these data broker sites,
they own tons of other sites.
We'll get into that in a minute.
So this article kind of goes through the
history of this
So there's a company called Atlas data
privacy,
which I think they actually make kind of
like a, have I been pwned type service?
Um, if I remember correctly,
I feel like I've heard of them.
I'm not necessarily vouching for it.
I'm just saying,
I think I've heard of them.
And, uh,
There's a law in New Jersey that allows
law enforcement officials,
government personnel, judges,
and their family to have their information
completely removed from data broker and
people search sites and provides fines of
one thousand dollars per violation against
companies that ignore removal requests.
But only them.
Nobody else gets to take their stuff down.
Only them.
Kind of pisses me off.
But
sued Radaris claiming that they were
violating this law.
Um, and apparently they've, uh,
it says further down,
they've sued like dozens of companies.
So I think this is just kind of
like,
I don't think it's about Radaris
specifically.
I think these guys are actually trying to
get these companies to go away and this
is how they're doing it.
It's like, Hey, this has a law.
Um,
So there's kind of this back and forth.
Apparently Krebs published an article
quite some time ago.
When was this one?
In twenty twenty four.
He published an article about the
co-founders of Radaris.
They are Russian born brothers living in
Massachusetts who, quote,
operate a dizzying array of people search
companies,
as well as a number of Russian language
dating services and affiliate programs.
Their attorneys threatened to sue Krebs if
he didn't redact the story and issue an
apology.
And instead he doubled down and was like,
here's all my receipts.
And eventually the lawyers did admit that
like, yeah, they made up a CEO pseudonym.
It's them, blah, blah, blah, whatever.
And then he kind of goes over there.
This is a,
their lawyers kind of just did a lot
of,
just a lot of crap to like try
and wear people out.
So like you would take them to court
and then they would move all the companies
under another shell company,
all the websites,
they'd move all the sites under another
shell company and be like, well,
you're suing the wrong guy.
This isn't even the right company.
So you'd have to start all over with
this other company.
And, uh, you know,
they'd wait until the last minute to show
up to court and just like all these
legal shenanigans.
And, uh, it finally get,
got to a point where, um, uh,
I think this was a different unrelated
lawsuit.
There was a lawsuit in twenty seventeen
that they lost because Radar is they lost
because they never contested the claim in
court.
And when they told the judge that they
couldn't collect the seven point five
million dollar default judgment,
the court ordered the domain registry to
transfer Radar's dot com to the
plaintiffs.
The lawyer appealed the verdict,
arguing that the lawsuit hadn't named the
actual owners, blah, blah, blah.
Again, more Shell Corporation garbage.
And in that twenty seventeen case,
apparently the plaintiffs just never
refiled because, again,
they just all this legal shenanigans.
They were like, dude,
we don't have time for this, whatever.
But apparently Atlas,
if I'm reading the story correctly.
Atlas was able to kind of take advantage
of that.
And when they filed their lawsuit,
they made sure to spread the net wide
and managed to get these guys and then
went back to that twenty seventeen ruling.
And they were like, OK, well,
they're never going to pay us.
We want the domain name.
And it went through.
And the lawyer saying that there's a new
lawyer now, a Mr. Victor Worms.
I just want to point that out.
That is a.
That is a sad name for a lawyer.
But he says there's some other lawyer now,
and we're going to appeal this decision
and blah, blah, blah.
But Radaris.com now redirects to a website
or a page that says that the domain
no longer exists.
And what is it?
It has a copy of the link to
the ruling and whatnot.
So yeah, Radaris.
Atlas told Krebs on Security that it
obtained more than ten thousand emails and
documents in the course of litigation.
They listed off a ton of other shell
corporations that have these ridiculous,
generic sounding names.
Bit Seller, Expert Limited, Digital Orbit,
Core Solutions, Lucky Solutions,
Growth Data Advisors, blah, blah, blah,
blah, blah.
They said that Radaris.com earned
approximately forty two thousand a month.
While Veripages.com earned around forty
five thousand a month.
And that one also included People Looker,
People Smart, Number Guru and Bumper,
which is a car history site.
This circles back to a previous older
story.
The Radaris family of websites earned as
much as twenty five thousand dollars each
month from their partnership with OneRep.
which was a company that Mozilla used to
work with for a data scrubbing tool that
had to drop them because Krebs found out
about this thing.
And there's like this shady relationship
there.
Still took Mozilla a year to stop working
with them, but eventually they did.
All told,
they transferred fourteen domains from the
Radar's family of companies over to Atlas.
And he goes on to talk about apparently
this Daniel's Law is actually kind of...
In debate,
the data broker lobby industry is trying
to challenge this law's unconstitutional.
Fourteen other states have passed similar
laws modeled after that one.
However,
one of them in West Virginia was found
unconstitutional in twenty twenty five.
So, yeah.
Yeah,
I guess that's more about data privacy
laws and stuff like that,
but it's interesting stuff.
It's an interesting read,
and it's also just nice to see one
of these data brokers lose for once.
So yeah, I mean,
I don't know if Jordan has any additional
thoughts here, but...
I guess while there are still,
as far as actionable takeaways,
we'll end on this one because there's not
too much to discuss on this story,
but how can users opt out?
Because this isn't the only data broker
website by a long shot.
Do we have any advice on how users
can get out of these still existing ones
and stay out?
Yeah, I mean,
we can kind of point towards a lot
of the tools that we recommend.
We recommend data removal services such as
easy opt-outs.
And there's also manual removal if you're
a masochist and you like doing that.
I'm sure you can do that.
There's the access to the big ass data
broker opt-out list.
I think they call it the bad bull
for short.
Yes, the bad bull indeed.
So yeah, you can check that out.
We've also got a list of our own
on our website too.
You can check that.
But generally we kind of recommend a
layered approach.
Use these easy opt-outs tools and then
kind of do the rest of the clean
up yourself.
So you can try and do that to
get your information removed.
But again,
this is like one of these systemic issues
where
It shouldn't be allowed,
but it is somehow.
There's definitely countries where this is
illegal,
but unfortunately the US is kind of
think in a very interesting spot it
definitely there's like you know I know
there's reasons why this sort of
information is public but it does kind of
have um privacy implications and
especially when we move into like the
digital world I think a lot of this
kind of made sense when we were like
you know you would have to make like
a full like request um at like a
government agency to find this information
but now it's just like
two seconds away just googling someone's
name and you can find out basically
everything about someone it's a little bit
it's a little bit much um so yeah
I don't really have too much to add
because I'm not from the US and we
don't really have this issue there in
Australia so I can't really add much but
um I think this is definitely an
interesting story too um it was
interesting hearing about the whole
history there
Yeah,
I think the Krebs article kind of talked
about that.
It's like, yeah,
the public records laws made a lot more
sense a hundred years ago when you had
to physically go down to a courtroom or
courthouse and ask somebody, like,
give me this person's record.
But now you can like,
you don't even have to put pants on.
You can just Google somebody's name.
And a lot of these records have become
digitized too,
like not to put all the blame on
the data broker people,
but it's the same thing now.
Like the city or the county puts all
those records online too.
Yeah.
i haven't checked but i'm willing to bet
i could find me and my wife's marriage
license online if i'd look for it so
yeah it's uh it's very unfortunate but no
yeah i've um i've been using easy opt-outs
for years i'm very happy with them uh
full disclosure they were a uh a sponsor
of surveillance report back when i was on
surveillance report but
Um,
they don't pay privacy guides any money.
They don't pay me any money.
I pay them.
Uh, I used to do manual removal,
but like you said, it's like, look,
if you have the time and you really
want to do it that way, it's definitely,
um, the most efficient way to,
or not the most efficient.
It's the most effective way to make sure
you've got everything to handle it all
yourself.
But it,
it used to take me like two days
to go through it.
So it's.
It's a lot of work.
I kind of like to do the whole
like I'll let easy opt outs get all
the low hanging fruit and then I'll go
through and look for anything they might
have missed like some niche stuff.
So yeah.
Yeah, I think it's also, you know,
I think you could previously you could
make the argument that it was like, oh,
it's like, you know,
one hundred and twenty dollars a year or
something.
No,
easy opt outs is like twenty dollars a
year or something ridiculously cheap.
So you don't really have an excuse.
It's cheap.
It's like a couple of bucks a month.
So it's an easy process to get that
stuff removed.
And yeah.
Obviously,
you're never going to get everything,
but significantly reducing that sort of
stuff is definitely a step in the right
direction.
And it's going to help if someone just
looks up your name,
they won't immediately know where you live
or other creepy stuff.
So definitely keep that in mind.
But I guess we've kind of gotten to
the end of our topics today.
We can kind of dive into some Q&A
topics now.
Was there any that you were seeing in
the chat or in the forum thread that
we should cover?
I have not.
I've been keeping an eye on the forum
thread.
I've been keeping an eye on the supporter
signal chat.
I've been keeping an eye on the chat
over here.
Just some people popping in on Twitter and
YouTube saying hi.
One person did say do more tier list
videos.
Love them, but it's three a.m.
and I got to sleep.
So yeah,
those do seem to be doing really well.
People do like those and we're planning to
do more for sure.
Yeah,
we're kind of learning from everyone.
Like if there's stuff that people enjoy
watching, we're going to keep making it.
So if that's what everyone wants to watch,
then that's what we're going to make to
bring people,
as many people as we can into privacy
and understanding how to protect
themselves.
So yeah, it's going to be interesting.
The latest one seems to be doing well
too.
So yeah,
definitely seems like people really are
enjoying those.
I think we should team up with MrBeast
and make a video where all the tech
CEOs have to fight a cage match.
Yes, I agree.
You're talking about things people want to
see.
That's what I want to see.
Sorry, I'm a terrible person.
But yeah, no,
I think that's kind of it.
I'll do one more check here.
But been a very quiet week from everybody.
But we do appreciate people who have been
talking.
definitely a lot of discussion at the
start of the show, but yeah,
we do find, you know,
as the show goes on,
it's almost two hours in,
so we can understand,
but everyone's kind of doesn't have time
to,
to jump in the entire two hour podcast.
So it makes sense,
but thanks so much to everyone who was
leaving comments and stuff.
I guess I can start rolling into the
outro here.
Yeah.
So all the updates from this week in
privacy.
will be shared on the blog every week.
So sign up for the newsletter or subscribe
with your favorite RSS reader if you want
to stay tuned.
We also offer a podcast available on all
podcast platforms and RSS,
which now includes video on supportive
platforms.
And this video will also be synced to
PeerTube.
Privacy Guides is an impartial non-profit
organization that is focused on building a
strong privacy advocacy community and
delivering the best digital privacy and
consumer technology rights advice on the
internet.
If you want to support our mission,
then you can make a donation on our
website at privacyguides.org slash donate.
You can also make a donation on any
page on the website by clicking the red
heart icon located in the top right corner
of the page.
You can contribute using standard fiat
currency via debit or credit card,
or you can opt to donate anonymously using
Monero or with your favorite
cryptocurrency.
Becoming a paid member unlocks exclusive
perks like early access to video content,
exclusive video content,
and priority during the This Week in
Privacy livestream Q&A.
You'll also get a cool badge on your
profile in the privacy guides forum and
the warm,
fuzzy feeling of supporting independent
media.
Thanks so much for watching and we will
see you next week.