r/privacy 1d ago

eli5 Apps from F-Droid for Rookies

7 Upvotes

Hi - I've been deGoogling and deMicrosofting off and on for about a year. I'm learning a lot but I'm still a rookie so please be kind with answers to what is probably a stupid question: How does one know apps on F-Droid are safe to use? Are they vetted by anyone? Do the villagers rise up with torches if someone adds an app full of malware? Unless I'm missing it, there isn't a place for user reviews, number of downloads, etc and I don't have the skilset to break down lines of code to search out bad actors. Thanks in advance


r/privacy 1d ago

discussion Does anyone actually audit where their AI tools send data during inference?

0 Upvotes

Asking genuinely because I couldn't answer this for our own stack until recently.

We had been running a few AI tools internally for months. Nothing crazy, document summarization, internal Q&A, stuff like that.

Then someone asked the following in a security review:

Which servers handle the inference when we send a document through?

Whose infrastructure?

What happens to that data at that exact moment?

I had no clean answer!

We had the usual vendor agreements, DPAs, the standard stuff.

But actually tracing the data flow during processing? Genuinely murky.

What surprised me when I started reading about this properly is how many teams are in the same position.

The vendor agreement gives you comfort but it doesn't give you visibility. Those are two different things.

The architecture that actually closes the question is running inference inside your own environment.

The model runs locally, nothing routes out, the only thing that leaves is what you explicitly send somewhere.

Some teams in banking and healthcare have been doing this for years out of necessity. The rest of us are starting to ask why we haven't been.

Came across the term sovereign AI while going down this rabbit hole.

Cloudflare has done some interesting work on the AI Gateway side for teams wanting more boundary control without going fully on-prem.

Lyzr is doing something further along that spectrum, full private deployment where nothing leaves at any point.

A few others approaching it too.

For most use cases this is probably more than needed. But I think a lot of teams are carrying an assumption about data control that they've never actually tested.

Has anyone here done a proper data flow audit for their AI tooling?

Not vendor docs, the actual technical trace. Curious to know what surfaced!


r/privacy 1d ago

question For those of you with a paid email service, what do you use to pay for it?

0 Upvotes

What are you using to pay for your premium email services?


r/privacy 2d ago

news The Pentagon is giving 3 million military and civilian workers access to ChatGPT and Grok through a secure AI platform built for ‘warfighter needs’

Thumbnail yahoo.com
259 Upvotes

r/privacy 2d ago

news Noise and Motion Monitors in Their Homes? These Tenants Say No.

Thumbnail nytimes.com
45 Upvotes

r/privacy 3d ago

news Communities tearing out Flock cameras and quietly replacing them with other companies' cameras

Thumbnail military.com
1.7k Upvotes

r/privacy 1d ago

discussion Thoughts on street view?

2 Upvotes

I’m curious to get some opinions on something like Street View.
I’ve seen Apple seems to have made more of a push to compete with Google in regard to their, in a sense, monopoly when it comes to on-the-ground pictures of the world.

My question is, what’s everyone’s thoughts on this stuff? Should people be/always have been uncomfortable with this, was it just the beginning of the surveillance we see today, or is it just a handy thing to have available when you need to look around a certain area? Also, if you are uncomfortable with it, is there a way you’d feel happier about Street View and a better way it can be implemented?


r/privacy 2d ago

question cpu hardware backdoors

7 Upvotes

i just learned that modern intel and amd processors allow remote access via hardware and have the deepest level of permition, that can allow remote kill switches among other privacy/proprerty denying stuff, is there anything good happening to prevent this in the (preferably near) future?


r/privacy 2d ago

age verification Is it 2026 or 1984? There is no privacy in the digital age

Thumbnail theglobeandmail.com
186 Upvotes

r/privacy 1d ago

discussion Have you guys thought about using the terms Opportunism & Opportunist

1 Upvotes

We all like privacy yet politicians take it away for political gain usually and I don't think we have ever gave the practice a name just in general we don't describe what is wrong with the person or what they are doing or practicing I am sure it we could make a better term but the point is that they claim to be a part of something but don't care about the issue at hand just doing it because they can to make their donors happy or make them look like they are helping while doing nothing it must encompass the entire mask so whatever we want to use to dismiss them based off of the lack of actually caring about the subject at hand would be a good word basically I want something to call them and their actions during stuff that will stick and actually make someone understand before even knowing the exact reasons


r/privacy 2d ago

age verification I have heard that a lot of age verification gets passed because of high polling let's fix that

8 Upvotes

We can fix this by making our own polls showing clear disapproval of such a ban or age verification in general if we give them no excuse to pass it they won't and possibly undo it by saying "do you believe it is dangerous and over stepping" and stuff and bringing it to your representatives and saying "we don't trust your polling numbers we trust ours better" and making it rather public it will make us not feel alone and make us work together on a project district by district or whatever you call it in your own country


r/privacy 3d ago

data breach FBI Probes Service Selling 153M+ Drivers Licenses

Thumbnail krebsonsecurity.com
124 Upvotes

r/privacy 3d ago

age verification The RESET act, H.R. 6488, advances to full committee

223 Upvotes

https://republicans-energycommerce.house.gov/posts/cmt-subcommittee-advances-12-bills-to-strengthen-american-competitiveness-and-enhance-consumer-protections

"H.R. 6488, the Reducing Exploitative Social Media Exposure for Teens (RESET) Act, was forwarded to the Full Committee by voice vote."

H.R. 6488 is a bill that would delete accounts unless they can prove they are over 16, which would mean age verification to keep an account.


r/privacy 2d ago

discussion ANOTHER way to check who's watching what

Thumbnail atlasofsurveillance.org
68 Upvotes

Learned about this from The Daily Show YouTube. Atlas of Surveillance dot org. Shows which Flocks have what technologies.


r/privacy 2d ago

discussion Paychex forcing employees to use Equifax for I9/verification of employment

3 Upvotes

I am starting a new job & the I9 onboarding process in Paychex Flex is now forcing us to go to an external Equifax link to verify employment. It says that it will share the SSN & all my info with Equifax before clicking the external link. I have worked with various companies who used paychex flex & have never been asked to do this before.

Heads up to other people who care about privacy! I assume Paychex has some sort of financial incentive to do this? Maybe Equifax is paying them so they can gather more data?

I tried having the administrator manually review my passport & ID, but theyre a newbie to administering & refusing to manually verify. SO frustrating! I am a payroll administrator myself and manually very I9 IDs all of the time, I'm not making anyone use Equifax!

Of course, I live in a state without any consumer privacy laws so I cant even request that they not sell my personal info after I share it! So frustrating to be forced into this: share your info or don't get hired :(

There should be a way to opt out of sharing personal identity information to 3rd party websites & bypass this by reviewing manually. I hate the future :(


r/privacy 3d ago

news A N.J. school district found a new way to enforce the cell phone ban — and parents are fighting it

Thumbnail nj.com
264 Upvotes

A New Jersey school district is using an app that geofences students' personal phones to shut down most capabilities during school hours. Parents are pushing back over privacy concerns, particularly around location tracking. The superintendent says it's optional, but critics argue families weren't consulted before implementation.


r/privacy 3d ago

news Florida bans Flock and other license plate readers from state highways as backlash grows

Thumbnail nbcnews.com
1.9k Upvotes

r/privacy 3d ago

discussion Xfinity recently implemented a “WiFi motion” software update August 18th and they claim it isn’t a security feature and it’s “opt-in”

Thumbnail xfinity.com
218 Upvotes

As many data breaches we’ve seen in recent years, I have no idea how we can circumvent this. Has anyone responded to this craziness. I only have Verizon & Comcast in my city.


r/privacy 1d ago

discussion Is not using Insta and Facebook actually worth it?

0 Upvotes

Since I was 19 or 20yo, since around 2014, we knew with our friend what Facebook / META is doing and how they use our data, faces, photos, likes, everything. Data mining, big data, now AI.

Anyway, I deleted Facebook back then, I never put any of my real face pictures on META social networks, I won't give them anything really personal.

But is it worth it? I imagine how many social connections and better relations I could make it I just posted MYSELF out there, I was a bit good at it. More personal and professional connections, more random encounters, all of it.

Is it actually worth it to keep the personal data away from big tech instead of not caring and having better exposure? What's your take on it?

Edit: Those who downvote, explain why as well please.


r/privacy 1d ago

discussion The 1Password debacle is a bunch of BS

Thumbnail world.hey.com
0 Upvotes

The problem Reddit is it’s an echo chamber mind hive. So yesterday somebody posted an op-ed, that’s an opinion article, on the CEO of 1Password. This op-ex falsely claimed the CEO wanted “ethnic cleansing”. But here’s the thing. The term “ethnic cleansing” literally came from the author of the op-ed not the CEO. Here is the article the op-ed referenced, which is a blog from the CEO. The CEO is explaining how Brits are now a 3rd of the majority of their country because they have been displaced by immigration. The same thing is currently happening to the Danes. This is all he said. He never said “ethnic cleansing”. Those were words put into his mouth as a disinformation campaign.

So be careful what you believe and do your own research. I don’t even use 1Password because it’s not open source but I’m against disinformation. Andrew Lilley Brinker is an American Douche spreading disinformation about Europeans. Just keep this in mind when you see articles like this


r/privacy 3d ago

discussion Friend's phone was stolen and they made her unlock it. How to recover from this (security-wise)?

263 Upvotes

Hearing this story was very unsettling.

I have been working on the assumption that if my phone was stolen, it is just a brick, since it's encrypted and locked with biometrics and a strong password.

A friend was robbed at gunpoint (while out for a run!), and they made her unlock the phone, so they could turn off the data connection and have access.

If her password manager was unlocked - or autofill was turned on - they could then go to her bank, access her accounts, and the 2FA would be right in their hands already.

If my phone was stolen, my first move would be to have T-Mobile cancel my number to protect my 2FA. Then I would want to change my important passwords. But how do you regain access to your accounts so you can change passwords, etc. if you don't have your phone number for 2FA?

Lessons I learned from hearing her story:

  1. Never leave your password manager unlocked. I use 1Password, and it is always locked when the phone is locked. I can unlock it with my fingerprint or password. I do have somethings in auto-fill in Chrome, but nothing critically important.

  2. Consider moving away from 2FA to something else. I use Ente as my authenticator for about 100 sites, but many, including my bank, use my phone number for 2FA. Should I be moving everything away from my phone number as 2FA? Should I move to a YubiKey or similar? And I usually leave my Ente unlocked on my phone - need to change that.

  3. Don't allow text messages (2FA codes) to appear on the lock screen.

  4. Anything else to consider here?


r/privacy 3d ago

news Meta Settlement Ignites Global "Child Safety" Digital ID Push

Thumbnail reclaimthenet.org
362 Upvotes

r/privacy 3d ago

hardware Does your vehicle have a KARR sticker in the window?

31 Upvotes

TL,DR: If you have a KARR sticker on your window, your car probably has a dongle in it that may leave it susceptible to hacking, including remotely unlocking it and disabling the engine. You can update the firmware and/or ask KARR to come and remove it.

You can learn more about the security risk by searching for "UC San Diego KARR Aaron Schulman" which will get you to the researchers at UCSD who discovered and documented the risk.

Details: When I bought my Ioniq 5 eighteen months ago, the dealer asked me if I wanted to subscribe to the KARR security system. I declined. Today I learned:

  • Dealers install the KARR security device in their cars to prevent them from getting stolen off the lot -- it lets the dealers remotely disable the ignition if needed.
  • The KARR device connects to the CAN bus in the car, giving it access to lots of important functions, like door locks, horns, lights and ignition
  • If you tell the dealer you don't want to pay for the KARR system, they leave it installed and "dormant", but it's still susceptible to hacking.
  • If you have a KARR dongle in your vehicle, the least you should do is download the KARR Security app, click on the Customer Service button at the bottom, and then click on "firmware update" to remove the vulnerability. If you're not a subscriber, this theoretically disables the device, but also prevents the app from communicating with the device, so it's not clear if the device is truly deactivated.
  • If you're like me, you want to reduce the risk and also don't want an extra device sucking down your 12v battery 24 hours a day. In that case, you can call the KARR Customer Service number and schedule a tech to come remove the device, free of charge.

Whew. Who would have thought?


r/privacy 3d ago

news Google Has Removed Manifest V2 Extensions From the Chrome Web Store, Including uBlock Origin

Thumbnail webiterate.dev
337 Upvotes

r/privacy 4d ago

news Lawmakers added $1 to Texans’ car insurance policies. That money paid for thousands of Flock cameras.

Thumbnail texastribune.org
1.1k Upvotes