OK so not exactly what OP asked, but if you might like a 2D minecraft-like, check out Terraria. Fun, and plays fine with no network access. So zero potential for data collection. Has native linux version.
Thinking more about your (and TU Dresden's) idea, circumvention would be a nice ability to have as standard functionality in linux printer drivers.
I wonder if inkjets do this too. I have only heard it in the context of color lasers, and that's all the wikipedia page says. But IDK why they wouldn't also add it to inkjets.
In theory 23hr 59min 59sec of audio every day is not continuously recording.
Practically speaking, it'll be a lot of false positive detections of the wake word + following audio. Which phones and other voice devices also suffer from. Even if the wake word happens locally, it's fragile! Other words sound like it, enoguh to trigger it. Then audio gets sent to the cloud. Often with no notice to the user b/c they figure the wake word was on purpose.
The wiki page says the pattern is repeated about 150 times on a standard page, so it is fault tolerant. In theory, a printer could also dynamically relocate them. To avoid regions of yellow. But if there was no dynamic reloc, then you could overwrite.
Wikipedia thinks you are onto something!
In 2018, scientists from TU Dresden developed and published a tool to extract and analyze the steganographic codes of a given color printer and subsequently to anonymize prints from that printer. The anonymization works by printing additional yellow dots on top of the printer's tracking dots. The scientists made the software available to support whistleblowers in their efforts to publicize grievances.
Apple seems really focused on preventing the audio from making it off the device.
Which fine, I believe they'll make that very difficult. Apple has engineering chops.
But it's not the fucking point. I ALSO don't want every watchhole around me making transcriptions of anything I say within earshot of whoever wears one. Which will be way less noticeable than even smart glasses. Say goodbye to having an unrecorded conv in most public places.
IDK... I'm not defending the bad shit Apple does. But they pushed back against both US and UK govs who were trying to backdoor their shit.
In the UK case, they pulled the entire feature rather than backdoor it for the Home Office. With warning for users, so ppl are not expecting to have encryption, w/o knowing it is backdoored.
In the US case, the US gov tried to compel Apple to create special versions of IOS with encr backdoors. The gov later found a 3rd party who was able to unlock the iPhone, and withdrew the demand. But a judge ruled that Apple could not be compelled to build a special backdoor version.
I don't like Apple. I don't use 'em. They have privacy probs for sure. But they also have pushed back lots of times vs gov attempts to force backdoors into iOS.
Paper ones that don't track everything you read. Old fashion paper. Browse your fav local bookstore. Or hit the library. Walk out with little stack of books. Read 'em over weeks or months. Lather. Rinse. Repeat.
Agree. Also weird b/c G has a special Google for Education scheme for schools. Which the school would be tied into, and accounts would be made through that. G makes promises like it won't use the student's data for other purposes, no profiling, no ads, etc.
I still wouldn't be happy with having to use G as a student. For lots of reasons, like normalizing it so students will keep using G after they graduate. Even so, I believe G does make a good faith effort to adhere to their promises about not using student data for other purposes. But prob only if done through the official channels to create the acct.
Ah, n/m, if I fully disable JS on the site, it loads without that interception! Anyone else ran into that, try disabling all JS. I had most disabled but was still running 1st party JS from the domain.
I've read a few other stories about it. But none of them gave a way to know if you were in the breach. Early on you could apparently do it through the group who did the breach. But 1st I wouldn't want to do that. And 2nd that has been taken offline anyway.
Is there a known, private way? And without giving private info to an untrustworthy party in the process?
so many third-parties involved with managing PHI, it’s impossible to secure it.
For sure! I got notified my PHI was breached. By a company I never even heard of! And certainly never directly used. I never even figured out the chain, from health services I used, to the breached co. Might have been multiple others between. Given how often these breaches happen, defacto we have no medical privacy.
And no doubt people are trying to grab live audio of doctors visits
Happens already, yah! New England Journal of Medicine has a paper about the privacy risks. Prob lots of other papers too, that's just what I had in my bookmark list.
These systems capture audio of clinical encounters and generate transcripts and structured clinical notes, yet vendor practices differ substantially in how long each data type is retained and whether it is used for AI training.
Offices are supposed to have signs, and/or the dr should tell the pt. But drs are human, right? They may forget! And sometimes, you may be there in your worst, vulnerable moments. When you are badly injured, or distressed.
It chantges the whole trust relationship between dr & pt.
IMO, that is true... but could potentially be misleading. It can still be better to block, even if blocking itself is a fingerprint. (edited here, fix bad wording)
It only makes you worse off if the bits of identifying info with javascript exceed the bits obtained by the single option of disabling JS. And that depends on how many ppl do it. It's the -log2 of the probability of that event. Let's say that only 1 in 100,000 disables JS. (It's gotta be more than that?) That is just under 17 bits of information from seeing that JS is disabled, b/c you're only unique to one part in 100K. So if the number of bits obtainable with JS enabled exceed 17, then it's a net win to disable JS!
I don't know what % of ppl disable JS. I feel it's more than 1:100K. That's only 1 person in a decent sized city. IDK what the right % is. But for any reasonable value I can imagine, it seems like a win. Far more bits of ID-ing info can be obtained through JS, than the -log2 of that %.
Also, the more ppl disable JS, the fewer bits are obtained by seeing that JS is disabled, b/c the log2(%-who-disables-JS) gets smaller.
In theory a neighbours lg tv could broadcast their wifi credentials to your tv to connect to upload the data.
but its technically doable.
Agree that mesh networking is technically doable. Credentials, IDK about that, but mesh, yes.
I thought I remembered a mfg who sold appliances that would try to mesh-network with others from the same mfg. Even if it was at another household or w/e.
But I can't seem to find the story now! IDK, maybe I'm fulla shit. Maybe I'm just jaded and my brain made it up. I'm trying to search but overloaded with pages about legit mesh networking.
Be aware that you will have no privacy on the school's network. They usually block all known VPN endpoints, and require certs that will allow MiTM even for HTTPS connections. For lotsa reasons it's best to cleanly separate personal activity, from school activity. Or work activity when you get a job.
Since you mentioned "gaming distro"... what I do for private gaming is buy games from GOG. Every one I ever tried runs fine even with no network access. You can use sth like firejail to do this super easy. No need to set up a VM or w/e. Then you know it isn't phoning home. B/c it can't!
Plus, all their games are DRM-free. Which is part of what makes them private. I'd rather my dollars support DRM-free stuff. Supply and demand. The more ppl buy DRM games, the more it teaches game vendors that we don't care. There are other DRM-free stores too. Stay away from Steam. Go for GOG, Humble, and w/e else. Then you can have private gaming.
OK so not exactly what OP asked, but if you might like a 2D minecraft-like, check out Terraria. Fun, and plays fine with no network access. So zero potential for data collection. Has native linux version.
Thinking more about your (and TU Dresden's) idea, circumvention would be a nice ability to have as standard functionality in linux printer drivers.
I wonder if inkjets do this too. I have only heard it in the context of color lasers, and that's all the wikipedia page says. But IDK why they wouldn't also add it to inkjets.
In theory 23hr 59min 59sec of audio every day is not continuously recording.
Practically speaking, it'll be a lot of false positive detections of the wake word + following audio. Which phones and other voice devices also suffer from. Even if the wake word happens locally, it's fragile! Other words sound like it, enoguh to trigger it. Then audio gets sent to the cloud. Often with no notice to the user b/c they figure the wake word was on purpose.
That's an interesting idea.
The wiki page says the pattern is repeated about 150 times on a standard page, so it is fault tolerant. In theory, a printer could also dynamically relocate them. To avoid regions of yellow. But if there was no dynamic reloc, then you could overwrite.
Wikipedia thinks you are onto something!
Apple seems really focused on preventing the audio from making it off the device.
Which fine, I believe they'll make that very difficult. Apple has engineering chops.
But it's not the fucking point. I ALSO don't want every watchhole around me making transcriptions of anything I say within earshot of whoever wears one. Which will be way less noticeable than even smart glasses. Say goodbye to having an unrecorded conv in most public places.
The whitewashing of the privacy probs with this is galling.
Just any parts of your day you spent near ppl wearing one of these.
Or any of the others that'll have a shittier implementation than Apple's.
IDK... I'm not defending the bad shit Apple does. But they pushed back against both US and UK govs who were trying to backdoor their shit.
In the UK case, they pulled the entire feature rather than backdoor it for the Home Office. With warning for users, so ppl are not expecting to have encryption, w/o knowing it is backdoored.
In the US case, the US gov tried to compel Apple to create special versions of IOS with encr backdoors. The gov later found a 3rd party who was able to unlock the iPhone, and withdrew the demand. But a judge ruled that Apple could not be compelled to build a special backdoor version.
I don't like Apple. I don't use 'em. They have privacy probs for sure. But they also have pushed back lots of times vs gov attempts to force backdoors into iOS.
Seconding that rec to disconnect wifi hw.
Some TVs have been found storing audio locally, then sending it if they ever get access to a network. Which can happen accidentally.
Tests also showed the sets can capture microphone audio with the screen off — they then upload data once reconnected to the internet.
LOT to be said for that.
Paper ones that don't track everything you read. Old fashion paper. Browse your fav local bookstore. Or hit the library. Walk out with little stack of books. Read 'em over weeks or months. Lather. Rinse. Repeat.
Agree. Also weird b/c G has a special Google for Education scheme for schools. Which the school would be tied into, and accounts would be made through that. G makes promises like it won't use the student's data for other purposes, no profiling, no ads, etc.
I still wouldn't be happy with having to use G as a student. For lots of reasons, like normalizing it so students will keep using G after they graduate. Even so, I believe G does make a good faith effort to adhere to their promises about not using student data for other purposes. But prob only if done through the official channels to create the acct.
Well, very many deaf people can talk just fine, and do, for the benefit of hearing ppl who may not know sign language.
I just hope this sort of post won't be happening with any frequency.
The audio warning chime would also not help ppl who are deaf.
I see what you did there.
I was unable to read the article b/c,
Ah, n/m, if I fully disable JS on the site, it loads without that interception! Anyone else ran into that, try disabling all JS. I had most disabled but was still running 1st party JS from the domain.
I've read a few other stories about it. But none of them gave a way to know if you were in the breach. Early on you could apparently do it through the group who did the breach. But 1st I wouldn't want to do that. And 2nd that has been taken offline anyway.
Is there a known, private way? And without giving private info to an untrustworthy party in the process?
For sure! I got notified my PHI was breached. By a company I never even heard of! And certainly never directly used. I never even figured out the chain, from health services I used, to the breached co. Might have been multiple others between. Given how often these breaches happen, defacto we have no medical privacy.
Happens already, yah! New England Journal of Medicine has a paper about the privacy risks. Prob lots of other papers too, that's just what I had in my bookmark list.
Offices are supposed to have signs, and/or the dr should tell the pt. But drs are human, right? They may forget! And sometimes, you may be there in your worst, vulnerable moments. When you are badly injured, or distressed.
It chantges the whole trust relationship between dr & pt.
Ugh, some video got embedded b/c I put the story link. It isn't playing for me (YT block) and I have no idea what that is.
Sorry! Trying to figure out if i can undo it sh.
Edit -> hopefully fixed.
IMO, that is true... but could potentially be misleading. It can still be better to block, even if blocking itself is a fingerprint. (edited here, fix bad wording)
It only makes you worse off if the bits of identifying info with javascript exceed the bits obtained by the single option of disabling JS. And that depends on how many ppl do it. It's the -log2 of the probability of that event. Let's say that only 1 in 100,000 disables JS. (It's gotta be more than that?) That is just under 17 bits of information from seeing that JS is disabled, b/c you're only unique to one part in 100K. So if the number of bits obtainable with JS enabled exceed 17, then it's a net win to disable JS!
I don't know what % of ppl disable JS. I feel it's more than 1:100K. That's only 1 person in a decent sized city. IDK what the right % is. But for any reasonable value I can imagine, it seems like a win. Far more bits of ID-ing info can be obtained through JS, than the -log2 of that %.
Also, the more ppl disable JS, the fewer bits are obtained by seeing that JS is disabled, b/c the log2(%-who-disables-JS) gets smaller.
Agree that mesh networking is technically doable. Credentials, IDK about that, but mesh, yes.
I thought I remembered a mfg who sold appliances that would try to mesh-network with others from the same mfg. Even if it was at another household or w/e.
But I can't seem to find the story now! IDK, maybe I'm fulla shit. Maybe I'm just jaded and my brain made it up. I'm trying to search but overloaded with pages about legit mesh networking.
Be aware that you will have no privacy on the school's network. They usually block all known VPN endpoints, and require certs that will allow MiTM even for HTTPS connections. For lotsa reasons it's best to cleanly separate personal activity, from school activity. Or work activity when you get a job.
Since you mentioned "gaming distro"... what I do for private gaming is buy games from GOG. Every one I ever tried runs fine even with no network access. You can use sth like firejail to do this super easy. No need to set up a VM or w/e. Then you know it isn't phoning home. B/c it can't!
Plus, all their games are DRM-free. Which is part of what makes them private. I'd rather my dollars support DRM-free stuff. Supply and demand. The more ppl buy DRM games, the more it teaches game vendors that we don't care. There are other DRM-free stores too. Stay away from Steam. Go for GOG, Humble, and w/e else. Then you can have private gaming.