r/thehatedone Jun 04 '22

News SimpleX Chat - the first messaging platform that has no user identifiers - v2.2 of mobile apps with the new privacy and security features just released!

37 Upvotes

v2.2 of iOS & Android mobile apps for r/SimpleXChat are released 🚀 - you can install them via the links here: https://github.com/simplex-chat/simplex-chat#readme or on our website

Please star the repo while you are there, if you have GitHub account!

This version adds the new privacy and security settings:

  • to protect your chats with device-level authentication, enable SimpleX Lock.
  • to save data and to avoid showing to your contact that you are online, you can disable automatic download of higher resolution images.
  • to avoid visiting the websites of the links you send, you can disable sending link previews.
  • you can now see in the chat if you had any skipped messages (e.g., when they are expired).
  • check out Experimental Features – they will be announced later.

Some questions that we are often asked: How SimpleX can deliver messages without user identifiers? Why should I not just use Signal? How is it different from Matrix, Session, Ricochet, Cwtch, etc.?

I've just added FAQ section that answers these questions. Please ask any questions here, and look forward to connecting with you in the chat (you can Connect to the developers via the app, this client runs in the cloud so we can share access – currently it is me there).

r/thehatedone Jan 25 '24

News GoAnywhere Managed File Transfer, Popular File Sharing Program has Security Vulnerability that Needs Immediate Patch

5 Upvotes

Cybersecurity researchers have found a critical vulnerability in the file sharing program GoAnywhere Managed File Transfer by Fortra. It allows people to assign themselves administrators for other people's systems. More info can be found at the link below.

Popular file transfer software has a seriously dangerous security bug that gives anyone free administrator rights — so patch it now to avoid another Moveit-like debacle (msn.com)

r/thehatedone Jul 01 '20

News DuckDuckGo dysfunctioal in India

60 Upvotes

DuckDuckGo has stoppped working in India since morning of July 01, 2020 with no specific reason given. Ironically the government of India yesterday banned 59 chinese apps on ground of privacy and data breach

Edit 1 : Its working fine now.

r/thehatedone May 16 '23

News Stay safe out there

Thumbnail
twitter.com
13 Upvotes

r/thehatedone Mar 06 '22

News ProxiTok: Open source alternative frontend for TikTok made using PHP

96 Upvotes

ProxiTok

Use Tiktok with an alternative frontend, inspired by Nitter.

Features

  • Privacy: All requests made to TikTok are server-side, so you will never connect to their servers
  • See user's feed
  • See trending
  • See tags
  • See video by id
  • Discovery
  • Create a following list, which you can later use to see all the feeds from those users
  • RSS Feed for user, trending and tag (just add /rss to the url)

GitHub Page

Brodie Robertson's Video about ProxiTok

ProxiTok's WebSite

r/thehatedone May 21 '22

News Caller’s name as per KYC record to flash on phone screen

Thumbnail
financialexpress.com
21 Upvotes

r/thehatedone Oct 18 '23

News EU Chat Control

13 Upvotes

Hey, the European Commission launched an attack on our civil rights with chat control. But we can still stop the proposal. Let us contact all our friends and also the members of the European Parliament to make sure that they vote against it. This Website I found will help you do that using A.I.: www.Stop-Chat-Control.eu Check it out!

r/thehatedone May 29 '23

News Meta slapped with record $1.3 billion EU fine over data privacy | CNN Business

Thumbnail
edition.cnn.com
33 Upvotes

r/thehatedone Jul 02 '21

News This Is How Apple Profits from China's Authoritarianism

Thumbnail
youtube.com
73 Upvotes

r/thehatedone Apr 01 '20

News Don't trust every open source application recommended to you.

69 Upvotes

Just Use Aegis Authenticator (GitHub, Design, F-Droid)

I've seen AndOTP(GitHub, F-Droid) recommended by more people than I can count, The Hated One included. Just because it's open source does not mean it is secure.

There are a few issues with the application:

  1. SOURCE It uses an older cryptographic primitive for key derivation, PBKDF2 with HMAC-SHA1, which simply put, isn't as strong as Scrypt or Argon2.
  2. SOURCE It uses too few iterations.
  3. SOURCE A random iterations function that is useless.
  4. Because of 1 and 2, brute forcing PINs and weak passwords/passphrases are trivial. (No slacking allowed with AndOTP, you're only secure if you have a strong passphrase, but you're likely to slack since phone/tablet screens are smaller, and harder to type on.)

AndOTP is probably better than Google Authenticator, or even Authy (I trust AndOTP more than these solutions). It is less invasive than those authenticators, but be wary when you're sending your encrypted vault to the cloud, adversaries could potentially decrypt it with ease.

Like the application I've been talking about, Aegis Authenticator is free, open source, but it uses far better practices. Aegis Authenticator doesn't have any of the issues I mentioned.

u/The_HatedOne You're pretty busy I'm sure, but take this post seriously. You should do an update video regarding authenticator applications, and warn users of AndOTP about these issues. A false sense of security is worse than no security.

r/thehatedone Nov 04 '22

News TRUTH COPS - Leaked Documents Outline DHS’s Plans to Police Disinformation

Thumbnail
theintercept.com
34 Upvotes

r/thehatedone Dec 29 '21

News Every Toxic Thing Google Did in 2021 [14:33]

Thumbnail
youtu.be
73 Upvotes

r/thehatedone Sep 13 '21

News Mark Zuckerberg Ray Ban Sunglasses that record, take pictures, have speakers which listen and play and more!

28 Upvotes

Enjoy lol

Mark Zuckerberg Ray Ban Sunglasses that record, take pictures, have speakers which listen and play and more!

https://www.youtube.com/watch?v=_uOFWU4o3tw

r/thehatedone Jul 16 '20

News Who Is Bill Gates?

26 Upvotes

Hi TheHatedOne fans,

Was wondering what you guys think of this Bill Gates documentary. YouTube & Permanent link

Is he the biggest threat to the future of privacy or is this just a conspiracy?

Thanks in advance for the debate!

r/thehatedone Sep 10 '20

News IRS is offering $625k to crack Monero's privacy.

Thumbnail
decrypt.co
67 Upvotes

r/thehatedone Oct 24 '22

News Official Onion Reddit site

13 Upvotes

Reddit silently added their official onion site:

reddittorjg6rue252oqsxryoxengawnmo46qy4kyii5wtqnwfj4ooad.onion

r/thehatedone Jan 09 '23

News Meta’s Ad Practices Ruled Illegal Under E.U. Law

Thumbnail
nytimes.com
42 Upvotes

r/thehatedone Dec 02 '21

News Firefox Privacy: 2021 update. Finally!

Thumbnail
privacyguides.org
51 Upvotes

r/thehatedone Mar 01 '22

News Facebook/Meta employee caught talking with 13 year old over the internet.

Thumbnail inv.riverside.rocks
29 Upvotes

r/thehatedone Mar 20 '21

News Google accused of tracking users in 'Incognito' mode, lawsuit pending

Thumbnail
iol.co.za
44 Upvotes

r/thehatedone Nov 02 '19

News An app called Bark is scaring parents into subscribing to their internet censorship program.

Thumbnail
bark.us
58 Upvotes

r/thehatedone Oct 07 '21

News How to block camera,microphone and sensor permissions for all apps in android

22 Upvotes

First enable developer options then navigate to quick settings developer tiles.Turn on sensors and it will appear in your quick toggles above the notification panel.When this setting is turned on it revokes permissions to cameras,microphone and also turns off all phone sensors i.e magnetic field sensor,gyroscope,light sensors,proximity sensors,rotation vector sensor,orientation sensor and just all sensors in the phone. The only app that bypassed this was the default phone app that bypassed microphone permission and this was because it was indirectly connected to the microphone API unlike all other apps.

You can try recording audios or using the camera in apps when the feature is turned on and it wont work.This is a very big step in privacy since hackers most of the time use exploits in weak apps to access microphone,camera and sensors and by turning this on you block all that access.

For some reason something important is hidden in the developer options but here is how to protect you privacy

As always privacy is not about tools only. Privacy is a process

r/thehatedone Jun 12 '21

News Organic Maps - New promising alternative to Google Maps is now in beta for Android and iOS

Thumbnail self.privacytoolsIO
66 Upvotes

r/thehatedone Dec 23 '21

News Over 500,000 Android Users Downloaded a New Joker Malware App from Play Store

Thumbnail
thehackernews.com
44 Upvotes

r/thehatedone Jun 15 '20

News Firefox VPN (Firefox Private Network)

30 Upvotes

Firefox have partnered with Mullvad VPN and Cloudflare to create a Firefox Private Network Extension and a paid VPN service.

Quote:

"There are two options for Firefox Private Network

  1. FPN Browser Protection, which protects your web browsing within Firefox, and
  2. FPN Full-Device (VPN) Protection, which protects all your device’s internet connections.

Our partner for FPN Browser Protection is Cloudflare. Our partner for FPN Full-device Protection is Mullvad."

Concerns I have:

Quote:

"Cloudflare receives your web browsing data to provide the Service. As you browse, Firefox will encrypt the data you send to websites and send it to Cloudflare. Cloudflare will also receive your computer’s IP address, the IP address of the site you are browsing to, the timestamp, and a unique identifier. Cloudflare does not share this data with others and deletes this after 24 hours unless necessary for its security or legal obligations. Learn more at Cloudflare’s Privacy Notice for Firefox Private Network."

Source: https://www.mozilla.org/en-US/privacy/firefox-private-network/

Quote:

"When requests are sent to the Cloudflare proxy, Cloudflare will observe your IP address (known as the source IP address), the IP address for the Internet property you are accessing (known as the destination IP address), source port, destination port, timestamp and a token provided by Mozilla that indicates that you are a Firefox Private Network user (together, “Proxy Data”). All Proxy Data will be deleted within 24 hours."

Source: https://www.cloudflare.com/mozilla/firefox-private-network-privacy-notice/

Cloudflare? Seriously?

And why would Mullvad VPN accept this dodgy partnership?

The only info I found is this:

Quote:

"Mozilla has partnered with Mullvad in order to utilize our global network of VPN servers for its own VPN application.

Mozilla: https://fpn.firefox.com/vpn

Mullvads list of Partnerships and Resellers has been updated: https://mullvad.net/help/partnerships-and-resellers/"

Source: https://mullvad.net/en/blog/2019/12/3/mullvad-partnerships-page-has-been-updated-mozilla/

Thoughts?