• 9 Posts
  • 58 Comments
Joined 5 years ago
cake
Cake day: February 20th, 2021

help-circle
  • I prefer browser(web)-based banking apps which work well on a phone UI without the info-access creep.

    UBank (NAB subsidary) and Wise (not a bank) both support passkeys for login in the browser. Most other banks here seem to have regressed from hardware tokens to SMS codes or proprietary apps for their MFA.

    Passkeys are only as secure as your passkeys – I use Bitwarden with master password re-prompt checked for bank credentials, but I should probably switch to a hardware based passkey (at least for unlocking Bitwarden itself).

    The phone apps are sometimes required to do some things (like managing passkeys for UBank, verifying ID in Wise). They work on LineageOS without the google stuff, but might be worth installing only temporarily in a separate profile or phone.

    Retail payments – just use a physical card if you’re not using cash.




  • rcbrk@lemmy.mltoPrivacy@lemmy.mlPhone Purgatory
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    Yeah, it’d be a live monitoring footprint limited to, say, wherever you have/bring a personal device plus maybe wherever there’s a wifi network it knows. But you’d be able to see where the tag was when it last pinged you, so you could return to that location to search for it and get a more accurate location fix.

    The only case my example doesn’t cover is if a third party moves the tag away from your typical footprint and networks.


  • rcbrk@lemmy.mltoPrivacy@lemmy.mlPhone Purgatory
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    1 month ago

    I don’t want an even higher level spyware device.

    but I use […] AirTags regularly

    Hmm…

    Alfred is disappointed.

    wide shot of alfred looking at the bank of hijacked mobile phone echolocation surveillance monitors

    It might be time to move on from the mass-surveillance-on-every-single-device style of object location tracking.
    Are there localising/tracking bluetooth tags available which only connect to your network/devices?














  • Huh, first I’ve seen that writeup. First in-depth well-reasoned set of criticisms I’ve read on the XMPP+OMEMO setup, which is my goto and usual recommendation (and what I still find most power-efficient on a degoogled phone, most usable and reliable despite its stagnation).

    Gives a good overview of the accumulated technical debt/chaos beneath the surface. Really hope that conversations and omemo can sort out their mess, or that other clients like kaidan can rise up and push omemo forward, because xmpp itself has been a solid foundation.







  • Whittaker’s phrasing is ambiguous. Could be read as expressing one of a number of things:

    • The paper/article is misleading and distracting from meaningful threats to privacy.
    • That the original tweet is using misleading accusations to distract us from the article’s revelations of meaningful threats to privacy.
    • That Appelbaum’s authorship of the research is an unwanted negative association which undermines the attention deserved by the threats documented in the paper which are misleadingly justified as necessary by eg. governments.

    It’s difficult to know without a better understanding of Whittaker’s position on the various matters at hand, so I don’t know.


  • rcbrk@lemmy.mltoPrivacy@lemmy.ml*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    3
    ·
    9 months ago

    What ideally I’d like is some sort of good encrypted email […], which can achieve decent Android integration. Proton apps are pretty useless to that effect […]

    Don’t need provider-specific apps if their services use standard protocols:

    • IMAP: Fair Email or K-9 Mail(/Thunderbird)
    • CalDAV: DAVx⁵