Replying to Avatar Co ⚡or

9. OPERATING SYSTEMS

Unfortunately, many closed-source, proprietary operating systems jeopardize user privacy due to their permissioned nature, built-in Digital Rights Management (DRMs), and GPS tracking on mobile devices. Desktop and mobile OSs come with unique privacy concerns and need to be evaluated separately. Luckily, we have Linux based distros as an alternative to Windows & Mac, as well as custom ROM alternatives for Android systems using Google Pixel phones. It’s a tough ask to use less used Operating Systems for most people, but it’s good to know that there are solutions available for those who are opposed to snooping.

Stop Using: Windows, MacOS, Android, IOS.

Start Using:

Mobile:

🔻 Graphene is a hardened offers a secure and customizable experience by providing an open-source, forked version of Android. So you get the Android experience, without the interference and the bloatware. It provides our sandboxed Google Play compatibility layer:

🔻Calyx is another privacy-conscious option for Android-based devices, CalyxOS emphasizes user autonomy and privacy through its custom ROM, featuring enhanced security features and strict adherence to user privacy principles.

🔻DivestOS is a mobile OS focused on harm reduction for end-of-life devices. . It is a soft fork of LineageOS that aims to increase security and privacy.

Desktop:

🔻Tails is FOSS OS based on Debian, Tails provides a secure environment by using the Tor network for browsing the web anonymously. It can be run from a USB stick, leaving no trace on the computer when shut down.

🔻Qubes is a utilizes hardware virtualization to separate applications and data, ensuring that sensitive information remains isolated.

🔻Ubuntu / Fedora / Whonix distributions provide strong privacy features by default, such as built-in encryption, anonymous browsing capabilities, and a focus on open-source software.

As Smartphone privacy alternatives are limited to Google Pixel phones. It’s expected that most people will stick with Apple/Android. In which case, it’s advisable to use device-level encryption to secure your device at a hardware level. For example, Apple's iOS devices use FileVault encryption, while Android devices typically have AES-256 encryption. Samsung also allows full-device encryption using Knox, while Blackberry have a similar solution in SafeZone.

Dig Deeper:

https://privacytools.io/os

https://www-kuketz--blog-de.translate.goog/android-grapheneos-calyxos-und-co-unter-der-lupe-custom-roms-teil1/

https://privacyguides.org/en/mobile-phones/

https://eylenburg.github.io/android_comparison.htm

https://privsec.dev/posts/android/choosing-your-android-based-operating-system/

10. AI CHATBOTS

Large language models (LLMs) have been assisting us with all kinds of tasks from writing blogs, books and code to answering all sorts of questions we used to ask Google. But as the old saying goes, if something on the Internet is free, the real product is you (and your data). So the onus is placed on us as individuals to find AI solutions, where we are the users, not the product.

AI is fundamentally ‘a surveillance technology’

- meredith Whittaker

It's a given that people will be using Chatbots henceforth, so the challenge is to move away from the easy solution and find the privacy level that suits you.

When using chatbots, look for platforms that allow private prompt storage, E2EE support, and anonymous usage. This approach will help protect your conversations and maintain anonymity.

Stop Using: Open Ai, xAi/Grok, Shapchat, Claude, Gemini, Samsung Galaxi Ai, Google Gemini, Stable Diffusion,

Start Using: Venice.ai, HuggingChat, Start9, llama file

As far as I can tell, the most private and secure approach to running AI chatbots boils down to three options:

1⃣ Download privacy-respecting AI chatbots like Venice and Hugging Face and run them locally on a desktop or phone entirely OFFLINE. While an air-gapped environment is ideal for maximum security, it's not always necessary. Ensure the operating system is encrypted to protect local data files.

2⃣ Download llama file and run privacy-respecting AI chatbots through its platform. This approach offers E2EE for confidential conversations and data protection, ensuring no data collection or sharing occurs for advertising/analytics purposes. However, this option requires interaction with external servers.

3⃣ Run ChatGPT on a start9 server. Start9 enables decentralized storage and processing without airgapping while maintaining local privacy features. User data remains on the device or within a private network, reducing the risk of breaches and unauthorized access.

While both options provide E2EE, Start9's E2EE is limited to user interactions, whereas LLaMA File encompasses conversations with its AI models.

Comparing Options B and C, running ChatGPT on a Start9 offers more control over data processing since it happens locally on your device. If you prioritize local privacy without the need for air gapping, Start9 might be an ideal choice.

Dig Deeper:

https://hackaday.com/2023/07/30/self-hosted-chatbot-focuses-on-privacy/

https://kdnuggets.com/distribute-and-run-llms-with-llamafile-in-5-simple-steps

More info on the dangers: 1⃣https://arstechnica.com/gadgets/2024/05/microsofts-new-recall-feature-will-record-everything-you-do-on-your-pc/

2⃣https://arstechnica.com/gadgets/2024/06/report-new-apple-intelligence-ai-features-will-be-opt-in-by-default/

3⃣https://reddit.com/r/privacy/comments/1dfrojd/former_head_of_nsa_joins_openai_board/

Reply to this note

Please Login to reply.

Discussion

11. VPNs

VPNs are key component of the privacy and security toolkit by preventing others from monitoring your online behavior. They create an encrypted connection between your device and a remote server, helping you access blocked content and conduct research without revealing your location.

Good VPNs don't keep logs and do cost money; free ones often collect data for advertising. VPN limitations include not protecting against malware, password theft, or complete anonymity. Your provider, partners, used sites/services, and governments may still track your online activities.

Stop Using: Hide My Ass, Express VPN , Pure VPN, Opera Free VPN, VPNSecure, VPN Master, Windscribe, Hotspot Shield VPN

Start Using:

🔻 ProtonVPN is operated by the same team behind ProtonMail, this VPN offers AES-256 encryption, DNS leak protection, and a no-logs policy for strong security. Its range of security features make it an attractive choice for those seeking privacy.

🔻NordVPN is a popular VPN provider known for its user-friendly interface and privacy features. NordVPN uses the NordLynx protocol (based on WireGuard) for faster speeds while maintaining security, along with a strict no-logs policy.

🔻 Mullvad is a popular Swedish solution that uses secure WireGuard protocol and doesn't keep any logs. Payments can be made in cash or cryptocurrencies for added anonymity.

🔻 ivpnnet is a privacy-focused VPN that doesn't collect or store any personal data on sign-up, not even email addresses. Payments can be made via cash, monero, or bitcoin for added anonymity.

Dig Deeper: https://securityplanner.consumerreports.org/tool/virtual-private-network-vpn

https://restoreprivacy.com/vpn/warning-list/

https://x.com/josephmenn/status/1437885720169836544

12. VIDEO HOSTING

YouTube is famous for censoring and cancelling content creators, raising the alarm bells about online freedom of speech and the need for privacy-respecting, censorship-resistant alternatives.

Moving away from YouTube is difficult though, as it has the largest repository of video content in the world. That said, the onus is on us to support platforms which champion privacy and/or free speech so that honest content has an outlet.

Stop Using: YouTube, Vimeo, Dailymotion, Twitch

Start Using:

🔻 BitChute is a decentralized video-sharing offering a censorship-resistant environment for content creators and viewers, making it an ideal alternative to centralised platforms.

🔻 LBRY is an open-source, peer-to-peer content distribution network that allows users to upload and share videos while maintaining control over their content. This platform doesn't rely on a centralized authority, reducing the risk of censorship.

🔻 Peertube is a decentralized video-sharing platform built on WebTorrent technology. It's an open-source project prioritising privacy and free speech. PeerTube uses a peer-to-peer model to reduce server load and provide an ad-free experience without tracking user activities.

🔻 Rumble is perhaps most recognised as a censorship free YouTube alternative. On their website, they state “we may process only minimal user data, only as much as it is absolutely necessary to maintain the website. Information collected automatically is used only to identify potential cases of abuse and establish statistical information regarding website usage”. The question remains, how much data is collected, what constitutes abuse and for how long can they resist censorship? That said, it's still better than YouTube.

Dig Deeper:

https://vdocipher.com/blog/2021/02/top-12-online-video-platforms-like-youtube-2021/#:~:text=Few%20alternate%20video%20platforms%20similar,Alternative%2C%20Vimeo%20alternative%20and%20more

14. BUYING BITCOIN

There is no disputing that Bitcoin is the most secure P2P network ever built. The on-ramps and off-ramps cannot boast the same level of assuredness, as centralized exchanges are widely recognised as a point of weakness, censorship and privacy abuse.

In contrast, P2P networks like BitTorrent, LimeWire or The Pirate Bay could never be shut down because they provide no single point of failure. P2P Bitcoin exchanges embody the same spirit and technology that underpins the torrent sites, creating marketplaces that allow people to buy and sell Bitcoin.

Stop Using: Coinbase, Kraken, Binance, Bitstamp, Revolut, OKX, Paypal,

Start Using:

🔻 Bisq is FOSS, is fully decentralized bitcoin exchange that enables P2P trading without KYC/AML checks. A self-hosted interface provides direct, anonymous transactions. It offers different types of payments, including face-to-face and cash, making it an ideal KYC-free solution.

🔻 RoboSats is a peer-to-peer, non-custodial Bitcoin exchange ideal for onboarding new users as it’s easy and quick to use. It requires no KYC since it’s based on pseudonymous avatars that allow customers to trade Bitcoin over the Lightning Network using the TOR browser only.

🔻 Vexl is non-custodial P2P mobile app without KYC/AML requirements. It provides a simple, inclusive, secure and private way to buy and sell BTC as it was intended: peer-to-peer.

🔻 Noones enables anonymous peer-to-peer bitcoin trades through an encrypted messaging system and secure payment channels. This platform eliminates intermediaries, ensuring user privacy and freedom.

🔻 Hodl Hodl connects buyers and sellers of cryptocurrency for direct P2P trading without KYC/AML checks. Users remain anonymous while securely exchanging bitcoin within a decentralized marketplace.

🔻 Peach is a decentralized marketplace unites buyers and sellers through encrypted messaging channels, eliminating intermediaries and compliance demands. Anonymity is preserved.

🔻 LocalCoinSwap is a KYC-free, peer-to-peer, non-custodial exchange that uses escrow protection for users who can buy and sell bitcoin with several payment methods, including cash in-person, cash by mail and gift cards for better anonymity.

Dig Deeper:

https://bitcoinmagazine.com/guides/how-to-buy-bitcoin-anonymously

15. DNS SERVERS

A DNS server is like a phone book that helps your computer find the address of a website you are trying to visit. Unfortunately, free DNS providers and local ISPs have removed many of the phone book's pages and track every page you turn. To solve this, you just need to find a different DNS.

Stop Using: Google Public DNS, Comcast DNS, Verizon DNS, OpenDNS and the default DNS from Local ISPs.

Start Using:

🔻 NextDNS blocks security threats, ads, and trackers while providing easy setup guides for all systems. Enjoy a free plan with up to 300,000 queries/month or upgrade for premium features.

🔻 AdGuard DNS offers ad-blocking and tracker-blocking capabilities with support for encrypted protocols like DoT and DoH. The free plan is limited to five devices.

🔻 Quad9 provides an open DNS recursive service that prioritizes security and privacy, offering a free solution for all users.

🔻 Cloudflare high-performance DNS resolver supports encrypted protocols like DoT and DoH while maintaining fast speeds and reliability.

🔻 Pie-Hole DNS is a self-hosted solution ideal for experts using Raspberry Pi or Linux-based systems. It offers powerful ad-blocking capabilities with customizable settings.

🔻 dnscrypt-proxy provides a flexible, open-source DNS proxy supporting modern encrypted protocols like DoH, DNSCrypt V2, and Anonymized DNSCrypt.

🔻 Unbound is a validating, recursive, caching DNS resolver that supports DNS-over-TLS for enhanced privacy. It's designed to be fast, lean, and secure with regular audits.

🔻 Nebula offers a light-weight, customizable, and battery-efficient DNS changer for Android devices. Perfect for those looking for a simple yet effective solution.

🔻 DNSCloak is an iOS GUI wrapper that enables encrypted DNS on iPhones and iPads by utilizing dnscrypt-proxy. It provides a user-friendly interface for managing DNS settings.

Dig Deeper:

https://recordedfuture.com/threat-intelligence-101/cyber-threat-landscape/dns-servers

https://privacytools.io/encrypted-dns

https://dnswatch.com/dns-docs/

16. SEARCH ENGINES

"Search" is overwhelmingly dominated by a small number of companies, particularly Google (90%) and Microsoft. These companies are filtering, favouring, and blocking results. Sadly many of the private search engines rely on these companies as a data source, and as such their results are filtered by default. Search Engines also track everything we search, they literally know our thoughts better than we do.

The battle here is on two fronts (privacy & censorship).

Privacy-preserving and censorship-resistant search engines provide an alternative to the Google panopticon. So it's highly recommended to protect ourselves and support these companies.

Stop Using: Google Search, Bing, Yandex, Yahoo (Bing)

Start Using:

🔻 Brave Search is a private and secure search engine that respects user privacy. Built on Brave's blockchain-based platform, it aims to provide users with accurate and relevant results while keeping data collection and tracking at bay.

🔻 DuckDuckGo doesn't track or store user data. Its focus on user privacy has made it a go-to option for those an escape from excessive tracking. DuckDuckGo has no relationship with Google, nor do they source any of our search results from Google.

🔻 MetaGer is a German-developed search engine that prioritizes user privacy through encrypted connections and anonymized search results.

🔻 Startpage is a Netherlands-based search engine that anonymizes your searches by using proxies to retrieve results from Google without storing any personal information.

🔻 Searx_engine is a decentralized, privacy-preserving search engine that allows users to access multiple search engines simultaneously. Its focus on user privacy and transparency has made it a popular choice among privacy-conscious individuals.

🔻 Mojeek is a UK-based search engine that aims to provide accurate results while respecting user privacy. It uses its own index of websites and doesn't rely on third-party data sources.

🔻 Swisscows is a Swiss based search engine that prioritizes user privacy by not storing any personal information or tracking user data.

🔻 Qwant is a France-based search engine that doesn't store user data or logs. Its decentralized approach to search ensures a more private experience for users while providing accurate and relevant results.

Dig Deeper:

https://restoreprivacy.com/private-search-engine/

https://privacytools.io/private-search

Friends don’t let friends use google products.

13. MONEY / PAYMENTS

Let's talk about money and payments. The legacy financial system provides absolutely no privacy, nor is it an equitable system. The move towards CBDCs will make it even less private and less equitable. So it's of utmost importance that we find a money system that's fair and a discreet payments system.

Stop Using: Credit/Debit cards, Stablecoins (Tether), Shitcoins, Paypal, Revolut, Venmo, Stripe, and so on.

Obviously, we cannot just exit the fiat world... but we can begin to move away on our own terms, whilst the options remain available.

Start Using:

🔻 Let's start with Bitcoin, which is the fairest system of them all, but not private, as it's built upon a public blockchain. It cannot be censored and has no kyc/aml requirement, so you can use it without doxxing yourself. It's also perhaps the only shot that we have of breaking the back of the incumbent unfair system. Everyone should own some Bitcoin.

Privacy & payments on the Bitcoin network are available on a growing number of layer two solutions (notably: eCash, Ark Protocol, The Lightning Network)

Bitcoin Layer 2:

🔻 The Lightning Network is a second-layer protocol designed to enable off-chain Bitcoin transactions, which are later settled on the Bitcoin blockchain. Lightning payments are extremely fast and quite cheap and provides privacy benefits for those who run their own nodes. Nostr Zaps are powered by the lightning network.

🔻 Ark Protocol is a layer-two solution for making off-chain Bitcoin transactions. is a payments system where people can make Bitcoin transactions at very low cost and without requiring any setup. The Ark model very closely resembles the UTXO model, which is a key differentiator with the Lightning network.

🔻 eCash

- Cashu utilises Chaumian ecash, a form of digital cash created by legendary cryptographer Dr. David Chaum in 1982. Ecash was waiting for Bitcoin as a foundational layer, which it now has. Ecash uses a mint, and is a bearer asset that can be transferred peer-to-peer, much like bitcoin. However, a key difference between ecash and bitcoin is that bitcoin exists on a ledger, whereas ecash lives on its holder’s device. Cashu is also available on the nostr network.

- Fedi is is an open-source eCash protocol for managing Bitcoin within a community. It is a system that uses a group of trusted members, called a federation, to hold and manage bitcoin for users.

🔻 Cash is a payment technology that's inevitably going to fail. Why? Society will continue to become more digitised and global, leaving little room for cash to continue. That said, we should use it while we still can, as it has the best privacy preserving properties of all. It's strong on privacy, weak on savings.

There are privacy protecting crypto alternatives like Monero & ZCash, however they have weak stores of value properties, and thus difficult to champion.