Hi y’all. As time progresses, and AI becomes more and more integrated into the mainstream closed-source OSes like Windows, macOS, iOS, iPadOS, and Android, I feel like it’s going to be increasingly important to teach people how to harden these OSes to reduce harm. We already know that the integrated AI can be a threat to many of the E2EE products we recommend on this site (the Signal president gives interviews about it, and it’s been discussed on this forum). Do any of y’all have favorite trusted resources for hardening guides that ideally involve hardening against AI features and are updated regularly? I wonder if this is a list we could keep compiled on the wiki, or if anyone would want to collaborate to make these guides if good ones don’t already exist?
Im not sure if any resources exist in the specific context of AI but generally not much will change in terms of approach
Windows Pro or higher to disable any AI Slop via policies and whatever your debloat process is
Apple Configurator/iMazing Profile Editor for MacOS and Supervise iOS devices
Android using ADB you’ll have parse through which packages are AI related
and then using hosts file, firewalls, DNS filtering to block any AI related domains from contacting the internet
I’ve observed a relevant ideological split on this issue amongst the PG community:
- Meet the people where they are, provide the tools/resources to optimize privacy as best as possible on every setup, acknowledge that some optimized setups will still have lingering privacy issues, as not every setup can be made to be truly private
- Provide guidance on attaining real privacy. Detail how weaker setups still make the user vulnerable. Setups that still expose the user to serious privacy issues are theater & should be avoided
For better or for worse, the prevailing school of thought seems to be the latter. I can’t cite any ‘Mainstream OS Privacy Guides’ that have broad community backing, but I can cite the recommended OS guidance for desktop & mobile
This is a great comment. I am definitely in the latter camp. However, I work on some projects with many people who couldn’t care less about their personal privacy. I advocate pretty much always for people to stop using closed-source OSes, but even in this forum there are still many people, even in the leadership team, who are fine with Apple products for example. There are discussions about info sec. in the projects I’m a part of, and there is about zero chance of these people switching to Linux or GrapheneOS. So then my thought goes to education that can potentially reduce harm in the overall project.
Why reduce harm when you can exercise your political agency to prevent it in the first place? I can understand the necessity of harm reduction for established technology like browsers, but AI as we know it today in the commercial space is still a relatively new product. Treat the issue at its roots while it’s still fresh and growing before it becomes too unmanageable. That is, if you believe you have political agency… And if you don’t believe so, shouldn’t your actual goal be to attain that political agency back?
If you believe that you have political agency, but do not exercise it, you are refusing to do good. If you don’t believe that you have political agency, and also do nothing about it, you are also refusing to do good.
I think this is becoming more important now, especially for normal users who will never switch to Linux or other privacy-focused systems.
Many people use Windows, Android or iPhone because of work, school or convenience. For them, a practical harm reduction guide would be more useful than a guide that only recommends changing the whole OS.
Things like disabling unnecessary AI features, reviewing app permissions, limiting cloud sync, using a password manager, enabling device encryption and choosing privacy-friendly apps could already make a big difference.
I would definitely like to see a community-maintained list that gets updated regularly because AI-related features are changing very fast.
We cannot control others. I exercise my agency and completely avoid all privacy invasive tech. I am talking about others. We do not and cannot exist in a vacuum within our highly-connected societies. Are you going to never message anyone who has an iPhone again? Never email anyone who’s gonna read that email on Windows? No. I’m asking about information on reducing harm, not your anonymous opinion about whether that’s the right approach. Your message is off topic, please leave the thread open for people who want to contribute.
Are you saying that this is what im saying? Im not saying that u should do these things. I am also responding to the very beginning of ur post, so I dont think its off topic.
I agree with you when you say “I feel like it’s going to be increasingly important to teach people how to harden these OSes to reduce harm”, which is why i said this
But my point is that “As time progresses, and AI becomes more and more integrated into the mainstream” is wrong. U are suggesting some causal connection between the progressing of time and the integration of AI. I am telling you, maybe not you specifically but to everyone who holds that view, that there is no causal connection. The actual causal connection Im stating is between political power and AI’s integration. It is not the case that as time progresses, AI becomes more mainstream. What is actually the case is that as corporations exercise their political power, AI becomes more mainstream. To combat this, attack the root of the cause by exercising one’s own political agency. That is what I am saying. It’s true that I didnt answer ur question as to what good harm reduction guides there are, but my reply is still on topic because I am responding to an underlying belief you have.
I apologize if reading it wasted ur time. I wrote that in hopes that I could inspire people to be politically agentic/active, and to change people’s minds on the defeatist idea that AI (and its privacy invasiveness) is somehow inevitable. We both presumably agree that privacy is a right. Fighting for that right is inherently political.
Maybe I shouldnt have moralized it so much, since that tends to anger people. I apologize for that too.