Are there any services which you believe are honeypots?

  • sunzu2@thebrainbin.org
    link
    fedilink
    arrow-up
    10
    ·
    15 hours ago

    ISP don’t even pretend not to sell your shit anymore…

    that’s really the only real benefit to using VPN, deny that parasite profit while shifting trust to another corpo. at least VPNs pretend to not sell your data. i mean some do it anyway

      • sunzu2@thebrainbin.org
        link
        fedilink
        arrow-up
        4
        ·
        11 hours ago

        I am talking about ISP selling tour traffic for marketing data.

        You are talking about state actor hunting you down.

        Different threat model.

        You sign hiding from NSA within US or other westoid regimes.

        They have legal right to do whatever they want. An individual has no chance

    • filister@lemmy.world
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      8 hours ago

      If you use your own DNS and also DNS over HTTPS I think they won’t be able to sell that data anyway.

  • stupid_asshole69 [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    9
    ·
    17 hours ago

    You may not like this: fediverse. Yes the site you’re on right now.

    Completely public forum scrapeable by api that exposes non-scrapeable, private information to the administrators of federated servers of which there are thousands.

    Even if you reject the idea that one of the thousands of “single user” servers is actually just quietly recording everything as a matter of mission, do you reject the idea that one of them hasnt been compromised? That an admin on one of the bigger ones hasn’t?

    Treat this site and any others that aren’t completely behind auth as social media.

  • cerebralhawks@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    2
    ·
    23 hours ago

    Anything by Meta (Facebook, Instagram, WhatsApp). Facebook literally got people killed by volunteering their location data to a tyrannical government in a third world country. Don’t think they won’t do that to Americans.

    Android (the mobile OS) kind of is. The only reason Google bought the hobby project to put Linux on smartphones was because they could collect more data with it than they could with Gmail. You can get a Pixel device and install GrapheneOS on it, but not even 1% of Android users are turning off telemetry (which only anonymises it), let alone installing custom firmware that doesn’t have it. I’m not saying iOS isn’t — because it’s not open source, we don’t know — but I am saying Android definitely is. And I don’t just mean Pixels — to use the Android brand, Google requires certain things of OEMs like Samsung, from having Gmail and/or Chrome on the main home screen, to having Google Play Services, which does the data collecting, installed. (I’m pretty sure the Play Store actually requires it. Forks that don’t use the Android branding, like Amazon’s Fire OS, don’t have this restriction, but Amazon probably has plenty of other crap in theirs.)

    Now, I never said Android was a honeypot, and it may not be. But Google was just sued for antitrust, and they made a deal to keep Chrome and Android under their banner. We don’t know what the terms of that deal are. I would consider both of them to be compromised by bad actors (potentially they always were since Google was selling the data). Don’t think so much about who you call (though that can be valuable) but like, your Maps data, anything you put in Health (like if you’re female, like if you miss two or more periods but not eight or nine and then start back up again, I’m sure the GOP would love to know that — for the dense fellas, it could mean she got pregnant and then terminated it, or the pregnancy failed somehow). Tim Cook’s advice of “get your mom an iPhone” doesn’t sound so far fetched now. Your sister, too. Heck, specifically regarding Health, Samsung put out an update last year, maybe the year before — that is, before the current administration — saying if you keep using Health, they can sell your information to whoever they want. Either agree and keep using it, or disagree and they delete your data. At this point, no stock Android phone can be trusted to keep your information private. It’s different if you use GrapheneOS, but that requires buying a Pixel, putting money in Google’s pocket. The Pixel 10 is what, about as powerful as an iPhone 11? A 12 maybe? And it costs the same as an iPhone 16. You decide. Personally I don’t think it looks like a very good deal.

    • Autonomous User@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      20 hours ago

      We know WhatsApp and others fail to include a libre software license text file. We do not control them. They are not honeypots. They are scams!

  • comrade_twisty@feddit.org
    link
    fedilink
    arrow-up
    57
    ·
    1 day ago

    There was speculation that the NSA is deeply involved in Cloudflare, which wouldn’t be a surprise at all.

    In fact all US services are probably infiltrated one way or another.

    • Scrollone@feddit.it
      link
      fedilink
      arrow-up
      6
      ·
      23 hours ago

      Yeah exactly. How can Cloudflare stay in business with such a huge free service? That’s why.

            • irmadlad@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              edit-2
              16 hours ago

              Encrypt your DNS. Use only DNSEC servers. TLS 1.3, Secure SNI. Use a VPN with double hop proxy.

              The issue is not all servers support TLS 1.3 and Secure SNI, so you are at the mercy of that particular server. Truth be known, there is probably zero ways to be totally secure, private, and anonymous, but that shouldn’t deter you from locking down what you can. However, if your threat model is hiding from a government, then unplugging is probably your best bet.

              People I talk to about security, anonymity, and privacy always ask me ‘Are you hiding from the government?’ which is rather hilarious to me. I send them tax forms every year. I vote once every four years and in local elections. We are in touch. If I were a person of interest, they’d come visit. However, there is absolutely no requirement to over share…with anyone.

              https://www.cloudflare.com/ssl/encrypted-sni

    • Autonomous User@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      2
      ·
      20 hours ago

      Anom failed to include a libre software license text file. We never controlled it. That’s not a honeypot. It’s a scam.