


I personally use Firefox still; and keep a fresh copy in a (Pixel only feature) Private Space (Basically an implementation of Android alternate user profile) as well. It works and accepts any privacy addons I throw at it.
Currently using:
- uBlock Origin
- Chameleon
- Privacy Badger1
- LocalCDN
- Decentraleyes1
- CanvasBlocker1
1 - May duplicate functions of other plug-ins; but provide additional protection layers and cover for the limitations of other addon(s)...
Being worried about addons adding to your fingerprint is something that I quite honestly find is not a significant issue usually...unless you're explicitly doing something truly spooky if found out...then you should use Tor Browser ONLY.

As someone who formerly modded on reddit for over a decade; I do know what trips the alerts typically. The steps I give are important to establish a fresh account with nothing an idle internet sleuth can link back to you; as well as preventing Mod(Bots) from detecting you. Reddit Automoderator has 'Admin eyes'...even if it lacks the permissions to act like one. It can, and will use algorithms on those eyes to assess your 'threat level'. Knowing the trajectory of reddit when I quit; it probably uses AI now. Before it was a dumb blackbox of algorithmic rules the Admins never really made fully clear about how it worked. This dumb blackbox made frequent mistakes.

I'd say you can try do it; but I caution you on doing so. It will be problematic
You cannot be completely undetected if using the reddit app. You must avoid using a mobile device; these are too easily trackable and the browsers on mobile devices lack sufficient privacy protections.
- First and foremost you'll have to setup to access reddit from a completely unique device. I recommend a virtual machine on a computer using a privacy respecting browser like Librewolf.
- Secondly, you'll need a good paid VPN...I recommend Mullvad. Do not create your account with this VPN! It will trip alarms.
- Third, you'll need a laptop with a similar private browser. do not use your main Windows user account. Create a new local account. This is to enforce that you do not access reddit for account creation using a "known" browser fingerprint.
- Fourth, you will need to travel. It must be somewhere out of town; and you should be using a public wifi network when creating the reddit account. Be aware of the ISP coverage in your area and travel far enough that you do not use the same ISP as your own. If you don't know their coverage area; look it up online. Travel to a place they don't offer service.
- Fifth, Once you have traveled, use the clean windows account you created to create the new reddit account. Do not name your account similar to your banned account, or subscribe to any subreddits that are outside of /r/popular.
- Farm some karma. Ideally 1k is enough. 100 will do in a pinch but you'll need to keep farming it; which is a dumb idea to do on a VPN.
- Verify a fresh email address. Use only tuta.com as your mail provider.
- Stay off the reddit account on your home PCs and network. Use reddit only in a public wifi setting on the laptop as described above. Do this for no less than 30 days while farming karma. No need to travel out of town; local public/private wifi will do. (Just not yours).
- Once the account has aged a month; you can log in with the VPN as mentioned above at home using the virtual machine at home. Continue using the VPN for the foreseeable future. Enjoy sticking it to Spez.

I would recommend resurrecting it.
Once you do so; Lock it down, make everything private that you can.
Secondly change all the privacy settings and opt out of any AI training.
Then slowly go back through your history and scrub out your posts; replacing them with gibberish and junk. Do not use AI text IMHO; use something like 'lorem ipsum' or some kind of 'Markov chain babbler'.
I would just suggest scrubbing back through your history slowly once a day; editing a few posts here or there. Look into what exactly the rate-limits might be; so that you can avoid triggering whatever automated suspensions that exist and edit one or two posts less than that a day.
Avoid using automation, as this too can be detected possibly...but do remember you can use other tools that run on your PC only to help streamline your editing.
In general, it's better if you can manually review and scrub over your old posts slowly. That way you can best decide how each posting and image will be scrambled. Maybe one post gets lorem ipsum in strategic places and the other gets 1000xTranslated into a barely plausible word salad.
Perhaps other times you feed the post into a markov babbler and let it babble on for a few minutes. Perhaps you leave a few otherwise innocuous posts alone so that the poison doesn't look so suspicious while you sanitize anything that you might consider sensitive.
Once a few months have passed and you've deleted all the sensitive information from the account that you can possibly edit or change; then you can proceed to deleting the account and waiting out that process.

- Get help. Your mental health and physical health must always come first.
- Privacy is not an all or nothing thing. Your mental health and physical health must always come first.
- Continue practicing good privacy habits at a rate, level and depth that fits your situation and needs. No need to constantly adhere to Snowden levels of privacy seeking and hiding under rocks. There never was a need for this unless you are in a situation like Snowden. Your mental health and physical health must always come first.
- It's totally fine to be as genuine or as pseudonymous as you feel as your needs and wants demand. However, Your mental and physical health must always come first.
- Relax. Current events have a way of making you paranoid but there truly is not usually a state level actor hovering over you waiting for your tiniest of mistakes. If you usually obey the law and do no significant harm to others, I doubt you have any significant worries. Your mental health and physical health must always come first though. Don't obsess over it if it makes you feel mentally unwell.

lol

It is likely they have the ability to sign the public key of your console with a "Suicide Key" which would signal your console to commit suicide by burning some internal e-fuse.
It is also equally likely this is an over-broad version of "Legal Rear Armor" that means nothing explicitly about what they can do. This is because modifying your system has long carried risk of bricking and their security systems to prevent modifications have only increased in strength.
It's likely the new security system in the Switch 2 is so naively hair-trigger sensitive that it absolutely will brick you or disable some functionality permanently if it thinks you even so much as modified a backup copy of a save file or encrypted binary stored on your SD card itself. It's very likely that any kind of attempt to write invalid foreign files onto an SD may result in issues. I'd expect Switch 2 systems to spontaneously self destruct if exposed to bad quality or fake SD cards with insufficient capacity; or an SD card that is failing if what I am guessing is true.
Is this confirmed? No; it's just idle wild speculation. But it is what I expect from Nintendo; given that their creatives have all been driven away from the executive positions of power and only money driven executives are left at the helm.
Given that the Switch has already been thoroughly cracked; it's likely now more than a want or need, Nintendo now has a mania or obsession with making their consoles un-exploitable. Likely, this is because they're too naive to avoid promising their consoles are 'unbreakable' to their third parties and publishers.
Unfortunately Nintendo is full of foolish pride and stubbornness. Tinkerers and video game preservers the world over will need to once again break the Switch 2 security to pieces to prove to Nintendo that this endeavor is futile.
In the meantime; don't tinker with a Switch or Switch 2 you can't afford to lose. Hell, don't even buy one if you're sensitive to it being un-tinkerable. Don't gift them to any children in your life either. Instead; gift them something more useful; like teaching them how to emulate one of the older Nintendo Systems and gift them a Library of ROMs so they don't have to torrent it themselves and 'give the family computer a virus' or 'cause a scary letter to be sent to their parents' with their inexperience. If you can't bear piracy; then go pick up one of the old legitimate retro systems. Buy it somewhere used and pick up whatever used games you can for them at any occasion.

There's something you need to know about the "anti-features" flags on F-Droid.
They're too "greedy" and widely defined. What you really need to do is examine the app and how the developer might use said "Anti-Feature". Not all internet access and telemetry is an anti-feature, and neither is reliance on a "third party service" where you can simply configure your app to use your own self-hosted server instance.
An app having no "Anti-Features" flag on F-Droid is absolutely not an informative indicator that it respects your privacy. Merely, it indicates common privacy foot-guns may not be present.
Frequently F-Droid also is far too opinionated in it's application of the anti-feature flags; giving developers no reason or chances to appeal or change the decisions. It does not matter if the anti-feature flag is mis-applied in any specific situation; nor does it matter if the developer shouldn't be getting an anti-feature label because they have everything open sourced and it's clear to see there is no anti-feature there.

False.
The ad attribution system was proposed but never implemented due to user outcry.
Some telemetry has been a part of Firefox for quite some time now; but it has always been privacy respecting and they self-host all of it. In general you can easily turn most, if not all of it off. The telemetry thing has been around since before they even started seriously fast-cadence releases. Some of my memories of this date back to the Firefox 34 days even. None of the telemetry collected is mandatory, and it can be shut off in preferences as well as through advanced config; which is what most forks do if they don't specifically rip the code out. You should read their source code sometime; it's quite interesting.
I will however agree that Brave is way more intrusive than any misstep made by Mozilla in developing Firefox.

No.
Brave is factually bad. It's a failed attempt at monetization of users seeking some form of privacy in browsing. From the entire crypto integration with BAT tokens to the weird VPN stuff and more; it's clear that the company who makes the browser is pivoting rapidly and iterating the software to make money from somewhere, somehow.
Brave does treat it's users like a product, and the company has made privacy-impacting decisions. They are very clearly a for-profit company with a well known CEO who operates on a for-profit basis only and never on a non-profit basis. You cannot say that Brave is operated on a non-profit basis. The entire concept of the Brave browser itself is to enable monetization methods that users and privacy advocates clearly want to see depreciated.
Mozilla on the other hand; has only recently begun to take some weird steps. Given that their exclusive contract with Google is likely to be dissolved in courts; they are simply stuck in a financially challenging situation. At no point has Mozilla or Firefox actually done anything actively hostile to privacy or users. While Mozilla does make mistakes; nothing notably wrong that they've done has actively been anything but a simple mistake. They have not yet crossed the threshold into malicious profit motive as of yet. Although many privacy enthusiasts are watching Mozilla very closely for any sign of them crossing that line right now.

Given the absurd number of sites that require a login for no discernible security reason at all whatsoever; I get it.
A "Common" password makes sense. This password should never be used to log into or protect anything secure however.
Similarly a "Common" password might be used to enable login more easily from certain devices; but ideally this "temporary" password should probably be something that is, yet again, different from the first "Common" password you use.
It boggles my mind that someone like this isn't at least using a specific passphrase for secure work accounts only.
While I can personally understand a need for some password reuse across multiple domains; at least there should be some separation of larger "superdomains" such as "work", "personal" and "throwaway" so that breaches don't have such a catastrophic impact.
A system of generating secure, unrelated but memorable phrases (for you) for those times you can't carry or use a password manager is frequently essential. That way you can recall the password on the fly when it is asked of you; all you need to do is think about the unrelated thing you attached that information to.

Good idea; bad execution.
If they think for a minute that Trump won't order his goons to arrest people doing this; they're being careless.
Instead of a bullhorn; a private message blast out to any interested parties would suffice; ideally via a secure Signal group chat or something similar. A phone tree being set into motion could work too; ringing phones; as could an SMS trigger an alert to all neighborhood residents.
All that said; it's good that they're basically warning folks of federal agents snooping around. There's no reason to let them get away with it casually during this Administration; if they want to illegally investigate immigrants, make it hard on them. Document everything.

This is mostly useless to me; I already enforce all tabs into unique containers to isolate browsing and website contexts from one another; while still allowing me to make exceptions to the rule and "unbreak" things if that's causing an issue, but still keeping things isolated from the rest of the browsing.
As for Tab Management; I use two windows and a plugin; Tab Stash Plus; which collapses tabs I stash into a bookmark.
Every so often when I reach a critical mass of tabs I personally go through them and play "Keep/Toss" with more odds on Toss. Only useful tabs get stashed and are then searchable from the plugin.
In general; since this feature now presents a possibility of an extremely UNWANTED AI integration I will be setting the config to off and leaving it off...using a relevant config policy tool or plugin to enforce this to off if needed. I hate AI features that I didn't ask for and this one definitely doesn't seem like it's going to be helpful nor compatible with my current workflow.

And this is why Fwyfwy refuse to move away from Windows 10. Fwy refuse to use any version of Windows that truly integrates their AI bullshit...and Fwy actively breaks and blocks installation of it too; during updates via NTFS security, policies and other tactics to otherwise deny or break their store app from installing anything automatically. If I need some shitty UWP packaged app; I will pull it down and manually install it myself using PowerShell kthx.
Fuck your AI shit Microsoft. If I want AI; I'll choose the models and run it locally on my own hardware and train it to my needs. If I need a screenshot; I have several app options to do so on command with a single keypress. I don't need my PC taking timelapse photos of what I'm doing.

Unfortunately this law is unconstitutional as ever. This is nothing more than a scare tactic; as it should not survive a true challenge in the SCOTUS. If it does survive such a challenge; burn them all, congress and all.
Permanently Deleted

I don't personally cut my usage of YouTube content at all; I just simply use necessary tools to prevent the apps and services from over-sharing too much data at a network level. DNS and IP level filtering is done typically to prevent well-known domains and telemetry targets from being utilized and any account preferences are set to minimize consent given. NewPipe and FreeTube are used interchangeably with yp-dlp if needed. No account is necessary...my viewing patterns aren't being recorded except in a generalized aggregate manner which enforces a reasonable amount of privacy.
I'm of the opinion that a completely de-googled device lacks critical features I use often; and restoring equal function is oftentimes made difficult. Unfortunately this also covers video content; there's no real viable FLOSS alternative with enough content. The creators typically do not have a motivation to use PeerTube or other viable FLOSS software that does exist currently and do not publish videos there; which introduces a heavy timelag; even if the creator or even someone else IS willing to export the YT content out to PT.

Network is standard double NAT grade B. [ISP <-> Router <-> Firewall <-> Client] with all necessary port forwards in place (TCP/UDP 1025-65535 to Firewall). Firewall is standard pfSense CE; and will forward invisibly and does automatically perform necessary UPnP and port forwarding as detected. STUN may be necessary but does function and establish the route(s) and the ports your application selected would ordinarily be invisibly NAT'ed quickly by the firewall as long as the packets are solicited.
ICE Candidates
udp <Public IPv4>:65359 srflx
udp <Public IPv6>:65363 srflx
udp [<Public IPv6 /64 issued by ISP>]:54597 srflx
udp [<Public IPv6 /64 issued by ISP>]:58798 srflx
Error: No active TCP candidates were found
To my knowledge your application does not appear to opinion or declare if it uses STUN. (Perhaps it should, there are valid reasons to offer STUN or not offer STUN). The application provides no meaningful errors so I can't tell what might need adjusted or allowed network-wise.

Obfuscated code is not "Source Available". You will need to provide the code without obfuscation; though I don't personally blame you if you're choosy about what reasons you will release the source for.

I'm of the opinion that you should probably provide Source Code on a "Source Available" basis to people who ask and have a need to see it to audit or self-compile. The lack of "Open-ness" in your code is disturbing.
I won't comment or judge on your decision to refuse to offer this software on a Libre basis. You absolutely have the right to monetize as necessary; especially if this code is speaking to a backend infrastructure that you maintain for it. Even if all you do is aim to break even and pay for those servers.
The experience is extremely unintuitive. I couldn't get your app to work at all on my privacy enforcing browser within the confines of my privacy enforcing LAN. (Yes; I do/did enable WebRTC and the other required technologies, however they're enabled in a privacy respecting manner.) Neither of my devices would show or remain connected once added. There were no popups or information given to me by the app to troubleshoot the issue; and I'm not going to crank open a Dev Console for something that I can't contribute to anyways. If your software is going to remain closed in source; "It should just work™".

No; it's not inarguable.
I do feel that some minor limitations around social media should exist; such as hours of the day you may not be allowed to read or post; but they should be simple age-gates created to privately verify a person's age via a simple SSO/OAuth style token. If you can't authenticate against some privacy respecting identity proving entity you probably aren't old enough and any account(s) you create would be limited.
Not all social media needs to be age-gated either; but social networks could be forced by law to avoid monetizing your account or habits at all if you don't willingly identify. (and by doing so; also CONSENT TO THIS MONETIZATION) In short; if you are not verified they're required to assume you are a child and handle your data as such...with utmost respect to your privacy.

Having issues with login
This post is currently a test and will be promptly deleted if it successfully posts without an unnecessary login prompt.

Moving right on...
Memes and comical images are now allowed; but please keep them tasteful, positive and nice. I will still moderate offensive images.

I have quit the /r/genderqeer team.
cross-posted from: https://lemmy.one/post/310151
Unfortunately and predictably /u/CedarWolf and I could not see eye to eye.
He is laser focused on protecting users. I do not see how this was possible on reddit if we lacked the normal 3rd Party Apps we've always used to manage the subreddit.
The subreddit has always been run through a massive set of YAML rules via the AutoModerator. Through these rules I was able to manage the entire subreddit. Alone.
Never did the other two mods really ever engage in any actions or even open dialogue. I had to open the dialogue about the community myself to get a response; and it was typical of your average reddit power moderator. He wanted to bend the knee to reddit. I refused.
Let me be perfectly clear. I accept responsibility for my actions.
However; I did not anticipate the complete lack of support from this top mod for the protest. Going forward I urge users to exercise their best judgement. The /r/genderqueer subr

Welcome to !genderqueer
How are all of you wonderful people doing these days? :3