I think some of them might be improvements, but moving from one commercial online service to another commercial online service isn't a big improvement. The best way to protect your privacy is to not spray your private information at commercial providers who can turn evil at any time.
I do agree with you, but I see this list as a first step for those who want to improve [but are not sure where to begin]. It provides easy alternatives to common uses. While some are commercial to commercial, they're spyware to nonspyware, which is a great Step 1.
It is amazing just how many applications, software, and services we need to just do stuff. Getting rid of Google is always a step in the right direction.
I would suggest not advertising what you run on your devices, but if someone does, take a moment before replying because it is possible you're being baited into an debate with a stranger on Lemmy, or they might have never heard a bad thing about the software they use.
Mullvad has been in the news recently, Proton's CEO has certain political views, mentioning Signal is a good way to start a debate, and e/OS is frequently late with security updates. But, all way better than just using the Google suite.
What I'd like to see is a site like the one used to make this graphic, but with some sort of threat model questionnaire to help people get started.
This is the best rebuttal. I might change my opinion a little bit on this. But as a service that still passes data through someones centralized network, there is no real guarantee for full privacy. But it does look to be ran by a rockstar with a descent view on privacy first. So I will yield to signal.
The problem with proton is that centralized service. Proton has given up user data before and ideally if your trusting a platform for privacy reasons then you dont want them to have a mechanism for handing over your data. So proton is still a platform that needs work before it can be what it promises to be. That said it is probably still better than using non privacy centric services like gmail and so on.
Yeah, I trust Whittaker's conviction on this because she's been tested multiple times by the governments of multiple countries at this point. When pushed, her response is "OK, we just won't support your country, bye"... and then the government ends up using Signal internally anyway. She is more than just talk, and so far she's been unwilling to sell out or compromise Signal for anyone. At the moment, there's no other secure communication project that I know of that is similarly effective, well audited by third parties, and has trustworthy leadership.
Proton is more complicated. There are more tradeoffs and compromises, but it is also more complex and offers more functionality than just a messaging platform. I recommend this video by Reject Convenience: https://www.youtube.com/watch?v=xFKSKjyBVDU He used Proton services for awhile and has made some different choices since, so he has some useful criticism from experience (not knee-jerk reactionary stuff).
At some point you have to make decisions about what your risk tolerance is, how much manual effort you can reasonably put in to sustain your tools, and how much money you're willing to spend on it. Proton is the right choice for many people not because it's a perfect company, but because providing equivalent functionality for yourself is a full-time job.
In order to provide a globally accessible, reliable, and high-performance communications service for the many millions of people around the world who depend on Signal, it’s necessary for Signal’s servers to be globally distributed. Having a geographically distributed network of servers is particularly important for end-to-end encrypted voice and video calls, because latency can result in audio delays or degraded video connections that quickly make the app unusable for real-time communication.
Because everything in Signal is end-to-end encrypted, we can rent server infrastructure from a variety of providers like Amazon AWS, Google Compute Engine, Microsoft Azure, and others while ensuring that your messages and calls remain private and secure. We can’t access them, and neither can the companies that provide any of the infrastructure we rent. As a small nonprofit organization, we cannot afford to purchase all of the physical computers that are necessary to support everyone who relies on Signal while also placing them in independent data centers around the world. Only a select few of the very largest companies globally are still capable of doing this, which is a hallmark of a troublingly concentrated industry.
Signal's servers are distributed globally, but yes rented primarily from American companies. I think they would diversify this if they could, but there aren't really other options with global presence. The only other host providers with comparable scale are Chinese ( like Tencent), but Signal is banned in China as of 2021 ( https://www.vice.com/en/article/signal-blocked-in-china/ ) because the PRC does not allow its citizens to have privacy from government surveillance at all.
There is no evidence that having Signal infrastructure hosted on US company servers provides any capacity for the US government to bypass Signal's encryption.
There is no evidence that having Signal infrastructure hosted on US company servers provides any capacity for the US government to bypass Signal's encryption.
I didn’t say that. A foreign government being able to disable your communication whenever they want to is already a threat to national security
16 Comments
johnefrancis@lemmy.ca · 14 pts · 2d
I think some of them might be improvements, but moving from one commercial online service to another commercial online service isn't a big improvement. The best way to protect your privacy is to not spray your private information at commercial providers who can turn evil at any time.
valar@lemmy.ca · 10 pts · 2d
IMO moving from Google to anything else is an improvement. Ideally sure you'd end up on non-commercial everything... But perfect is the enemy of good
01189998819991197253@infosec.pub · 1 pts · 2d
I do agree with you, but I see this list as a first step for those who want to improve [but are not sure where to begin]. It provides easy alternatives to common uses. While some are commercial to commercial, they're spyware to nonspyware, which is a great Step 1.
pasdechance@jlai.lu · 5 pts · 2d
It is amazing just how many applications, software, and services we need to just do stuff. Getting rid of Google is always a step in the right direction.
I would suggest not advertising what you run on your devices, but if someone does, take a moment before replying because it is possible you're being baited into an debate with a stranger on Lemmy, or they might have never heard a bad thing about the software they use.
Mullvad has been in the news recently, Proton's CEO has certain political views, mentioning Signal is a good way to start a debate, and e/OS is frequently late with security updates. But, all way better than just using the Google suite.
What I'd like to see is a site like the one used to make this graphic, but with some sort of threat model questionnaire to help people get started.
01189998819991197253@infosec.pub · 3 pts · 2d
I think you meant
Noteand notNoneloremipsum@feddit.online · 2 pts · 1d
here's what mine looks like

Wiz@midwest.social · 1 pts · 1d
OK, Helium. That's a new one for me!
Nightrider@lemmy.ca · -6 pts · 2d
Signal and any of the proton products dont belong in this list.
NaibofTabr@infosec.pub · 9 pts · 2d
Hard disagree on Signal: https://www.youtube.com/watch?v=qYVeyhxLF7s
Nightrider@lemmy.ca · 4 pts · 2d
This is the best rebuttal. I might change my opinion a little bit on this. But as a service that still passes data through someones centralized network, there is no real guarantee for full privacy. But it does look to be ran by a rockstar with a descent view on privacy first. So I will yield to signal.
The problem with proton is that centralized service. Proton has given up user data before and ideally if your trusting a platform for privacy reasons then you dont want them to have a mechanism for handing over your data. So proton is still a platform that needs work before it can be what it promises to be. That said it is probably still better than using non privacy centric services like gmail and so on.
NaibofTabr@infosec.pub · 3 pts · 1d
Yeah, I trust Whittaker's conviction on this because she's been tested multiple times by the governments of multiple countries at this point. When pushed, her response is "OK, we just won't support your country, bye"... and then the government ends up using Signal internally anyway. She is more than just talk, and so far she's been unwilling to sell out or compromise Signal for anyone. At the moment, there's no other secure communication project that I know of that is similarly effective, well audited by third parties, and has trustworthy leadership.
Proton is more complicated. There are more tradeoffs and compromises, but it is also more complex and offers more functionality than just a messaging platform. I recommend this video by Reject Convenience: https://www.youtube.com/watch?v=xFKSKjyBVDU He used Proton services for awhile and has made some different choices since, so he has some useful criticism from experience (not knee-jerk reactionary stuff).
At some point you have to make decisions about what your risk tolerance is, how much manual effort you can reasonably put in to sustain your tools, and how much money you're willing to spend on it. Proton is the right choice for many people not because it's a perfect company, but because providing equivalent functionality for yourself is a full-time job.
amzd@lemmy.world · 2 pts · 1d
Which is terrible for national security because everything is hosted on centralized American servers
NaibofTabr@infosec.pub · 1 pts · 18h
https://signal.org/blog/signal-is-expensive/
Signal's servers are distributed globally, but yes rented primarily from American companies. I think they would diversify this if they could, but there aren't really other options with global presence. The only other host providers with comparable scale are Chinese ( like Tencent), but Signal is banned in China as of 2021 ( https://www.vice.com/en/article/signal-blocked-in-china/ ) because the PRC does not allow its citizens to have privacy from government surveillance at all.
There is no evidence that having Signal infrastructure hosted on US company servers provides any capacity for the US government to bypass Signal's encryption.
amzd@lemmy.world · 2 pts · 14h
I didn’t say that. A foreign government being able to disable your communication whenever they want to is already a threat to national security
amzd@lemmy.world · 1 pts · 1d
Yeah Signal requires a phone number which is PII so the app does not belong in a “privacy” pack
staircase@programming.dev · 1 pts · 2d
Disagree re Proton