Despite trying my best to persuade my friends that we should all stop giving away our information to big tech companies, I’ve mostly failed to get them to take meaningful steps to protect their privacy. I believe that when I have IRL conversations with them, these conversations being recorded by various apps on their phones that are always listening.
Although I don’t want to stop being their friend, I’m interested in developing IRL friendships with people who are already privacy conscious. For IRL friendships, I need to find people who live near my area. The problem is that most privacy conscious people justifiably don’t want to reveal even the general area where they live online. For example, I can’t tell if there are any other PG members who live near me.
Does anyone have any suggestions on how I might meet other privacy conscious people in my area? I tried Mastadon, but the only local server had only about 75 members, maybe 4 of whom were active, and covered a geographical area that’s bigger than many countries.
The idealized terminology you are looking for is called a cryptoparty, but those are not common, so other adjacent movements are LUGs and DWeb nodes:
If you want to bring the party to the people instead, here is a step-by-step guide from the Tor Project:
I have a strong security background, so I can intermingle in various cybersecurity communities such as OWASP and my local DEF CON chapter, but still remain distant due to my own discipline and practices. Privacy is not a subject I promote to others due to different threat models, use cases, and/or workflows, even on Internet forums. I usually bridge the two concepts by referring to topics such as database dumps/leaks, data exfiltration, misappropriated third-party trust surfaces, and other industry regulatory compliance concerns.
This might indicate that your behavior is off-putting to normies. It’s one thing to get someone to switch to Signal or even start acknowledging privacy problems. People don’t want to leave their comfort zone. If you’re starting or including in conversations stuff like this it could make people very defensive.
Obviously I’m extrapolating and I could be totally wrong and I don’t mean any offense.
It’s just highly unlikely that this is happening or compromising your privacy on iPhones or Android even with any voice assistant.
Friendship is a strong word. Connection sounds a bit more realistic to me. If you’re a specialist in a certain field then a local professional community is an obvious choice. There is a high chance of finding a couple folks who you can relate with.
Personally, I’m really intrigued by the so-called Vtubers scene and their professional community growth over time. A lot of them take privacy seriously - practical utilization of voice changers, llm’s, thorough IRL meeting organization etc. So basic opsec knowledge is definitely there with some notable cases of advanced practices application. A perfect example of finding them gems in unexpected places.
Other than that, you can attend any of your home country based events (defcons, seccons, hackathons, Tor community events, Linux devcons, you name it).
If you’re not trying to influence anyone but share your experience then you’ll easily get yourself a connection or two.
VTubers are still performers at the end of the day, as they provide financial payout information to Twitch or YouTube, so they are still highly susceptible to database leaks.
I’m turning my existing friends into privacy minded ones with Jedi mind tricks . I managed to get three people around me to start using password managers, switch to better browsers, use DNS filtering, and use Proton mail. So far im calling it a victory.
Reading the first post it appears OP is looking for IRL friendships and not just professional/community connections.
Privacy/security/crypto events are good for making professional/community connections, and those may lead to some friendships, but making/maintaining good IRL friendships in a surveillance world while maintaining privacy is a big challenge considering the friction surveillance and countermeasures add.
As someone who sees everyone around me carrying phones but doesn’t carry one myself, I have wondered how likely/realistic this threat is. I assume it has become impossible to have confidential discussions unless one takes “extreme” measures like demand every party to either leave behind or hand over their phones. Hanging around journalists, human rights defenders, activists etc (surveillance tech targets) would elevate the likelihood, and anyone can covertly open a voice recorder app, but I’m unsure how often things get recorded in practice.
Consider non directly privacy related groups. FOSS software groups tend to lean privacy preserving. Unsure the size of your city or town, but check online or even bulletin boards for said groups.
Thank you everyone for your replies. This gives me some good options.
A few people have questioned whether this statement that I made is accurate. I can’t prove it, which is why I said “I believe”. I’ve seen a lot of circumstantial evidence though. There have been many times where my friends and I were talking about a particular topic and then someone pulls out their phone and sees an ad for that same topic. It could be coincidence, but it seems to happen a lot.
My main argument here is “why wouldn’t they?”. Big tech companies profit by collecting as much data as they can. Most people leave their apps open in the background. Why wouldn’t big tech have their apps record audio whenever they could? What’s the downside?
If we could trust that our cameras and microphones were only recording when we asked an app to do so, why would we need camera covers? Why would we need to disable the camera or microphone on our GOS phones?
Yeah, when talking with others, I don’t generally bring up that their privacy choices affect me too. It’s more like I point out that FB is addictive and bad for privacy, and I can convince them of that but they still use the platform.
I have convinced a few friends to get on Signal just to talk to me, but that’s as far as it goes. They won’t take steps to secure their own privacy, even if I can get them to agree with me in principle.
Permissions are effective and there’s no evidence of iPhones listening on you. The burden of proof is on the person making the claim. Your claims are ridiculous and would require extraordinary proof.
Noticing similar ads is not casual evidence at all.
There’s no reason a company would take these measures to spy on privacy concious users when the vast majority of uses can be spied on through regular means.
There’s no way in hell the benefits of more data of this kind of spying would outweigh the controversy and congressional investigations that would affect a company engaging in this practice.
Even assistants like Alexa, Google, and siri are proven to not send data of what you say when they aren’t activated.
Just because something is closed source doesn’t mean it can’t be analyzed by security researchers. In fact, source code might be used less than the actual binaries because the researchers want to observe what the app does instead of what the source code says it does.
I completely agree that I don’t have causal evidence, which is why I only say “I believe”. I can’t prove it. I only have circumstantial evidence.
I wasn’t aware of that, and it makes me feel better. Can you please provide sources?
Has this been done? For which apps? I’m particularly interested in WhatsApp & FB messenger here. If so, can you please send me some links to read about this? Seriously, this would ease my mind and I’d like to be more educated here.
There’s definitely significant concerns, but all have to do with the trigger words. I couldn’t find anything indicating that they send recordings of your home when not activated. They could definitely activate accidentally as a lot of coverage mentions.
You could observe network traffic when the device isn’t activated to see that it’s clearly not sending home data.
This controversy is based on flawed wake words, not always listening sending data.
If you can find evidence that they do record everything all the time and send it back I’d enjoy reading as well.
You shouldn’t believe something based on flawed reasoning. “The earth is flat because I’ve never seen evidence that it’s not.” When presented with evidence that it’s not, “that evidence is fake”. The only way to prove something is true is through rigorous scientific testing.
This comment is made of misunderstandings and flawed logic. In the future please don’t come with flawed logic that takes forever to explain why it’s wrong.
You should look into defense in depth.
You should read the GrapheneOS website because you are misrepresenting their OS and it’s features.
You are presenting a false dichotomy. Absolute OS trust, or none at all. There’s a middle ground. Mostly trust the OS, but understand it can fail or be exploited.
You are saying that trustworthy software can’t fail. You baked the conclusion into the premise.
Those were when you were talking to the assistant after the wake word. I never said there weren’t huge privacy concerns, I said that they aren’t always recording and sending. They’re only recording and sending when activated.
All three lawsuits are plaintiffs arguing that no wake words were used:
I assume you would be more willing to read the actual class action lawsuits, so here they are:
The Google class action lawsuit is recent and does not appear to have a respective PDF file, so you can get payment instead, although no explicit amount has been disclosed.
I agree that should be fined more, but class action lawsuits never give large amounts per person, it’s about disincentivizing the company from repeating bad behaviour. Of course they’re gonna need more fines than this one to be significant, but using the $20 figure is disingenuous. Apple doesn’t choose how much to compensate people, it’s as little as they can because it’s a lawsuit.
That’s the best I’ve seen, but none of these even allege constant listening, it’s just “bits” and these companies have improved their wake word detection.
There’s a big difference between occasional accidental activation and constant spy monitoring recording. That’s the original claim I was addressing.
On Macs, there’s an OS level indicator for when the microphone is recording, so you’d know when siri is activated. I’m not sure about Alexa, but i assume it also indicates when it’s been activated, regardless of if the wake was intentional.
Right, the difference I contributed is that these accidental activations were more than occasional for the defendants, enough to expend multiple years to achieve meager settlements. It is not constant spy monitoring, but neither is it the device functioning exactly as the vendors claim it to be. Long-term, these vendors understand that these lawsuits are cheap enough to write off, and even if people constantly litigated as a full-time job against them, consumer behaviour is not meaningfully changing anytime soon to make any technical difference.
I imagine these reasons. Practically, constantly streaming/recording audio and video would generate massive amounts of data to be stored on people’s devices or streamed to companies’ servers, thus costing storage space and people’s mobile data. Tactically, this kind of malicious activity would be easily detectable and people will either uninstall offending apps or sue the companies responsible. So I don’t think it happens constantly or indiscriminately.
Spyware (criminal or surveillance capitalist) could do this selectively or tactically, either by trigger words, by target or by some other selection method.
I see the biggest threat to someone of being recorded may come from the people in proximity to them, by them deliberately recording (smart glasses for instance) or installing an app that does a lot of listening/recording.
There are other threats to consider too, for instance, surveillance cameras should be assumed to be constantly recording audio and video.
Defense in depth.
Showing people around you that your device’s camera is physically incapable of recording.
Smartphone permissions may be effective when people use them properly, but most normies don’t.
The exact cause of ads being served based on topics discussed in @useduser’s case is unknown to them, and they were unsure that there even was a causation between their conversation and the ads. I don’t think they meant to make claims to be tried but meant to explain their beliefs/suspicions of what happened and ask some questions.
Talking generally about burden of proof, it depends on the purpose. When making a claim against someone, the burden lies with the claimant to prove wrongdoing. When deciding about one’s own life about something or someone, a person has no burden of proof. I would hope they make good decisions based on the best information available to them.