Why is privacy so selective, even within the privacy community?

I’ve been thinking about this for a while and wanted to get everyone's perspective. Why does privacy advocacy feel so selective, even among people, creators, and projects that supposedly care about digital rights?

I’m not talking about beginners who simply don't know how tracking works. I’m talking about knowledgeable folks, privacy advocates, and even privacy-focused organizations who constantly compromise and stick to Big Tech or less private solutions:

  • Privacy creators hosting their main discussion hubs on Discord, WhatsApp, or Telegram instead of Matrix, Signal, Threema, or SimpleX.
  • Major privacy-focused companies using X or YouTube as their primary outreach channels, while treating open protocols like Mastodon or Nostr as an afterthought.
  • Hesitation around truly private, decentralized alternatives in favor of whatever is commercially convenient.
  • Reliance on centralized ecosystems and app stores instead of actively promoting and maintaining open alternatives.

It often feels like many people just switch to a privacy browser, create an encrypted email account, and call it a day. (Nothing against these tools, they’re great, but you get what I mean.)

When even prominent privacy figures and companies won't actively dogfood privacy-first alternatives, it creates a feedback loop: 'If the privacy experts aren't bothering with decentralized protocols and are using X, why should I?' As a result, genuinely great privacy-first solutions get left behind and struggle to survive simply due to convenience and network effects.

Is pure convenience and network effect really the only bottleneck, or is there something deeper going on with how we balance threat models and practicality? I don't know if I'm too OG, but what do you think would actually push the community to bridge this gap?

reddit.com
u/EriksonThorsen — 1 day ago
▲ 13 r/signal

Any chance of a Signal Web App in the near future?

Back in 2017, the Signal Chrome/web app was discontinued when the standalone desktop app launched, and it was officially deprecated.

Now, almost 10 years later, is there any possibility we might see a web client return in the near future?

I know it was phased out originally due to browser security concerns and sandbox limitations, but web tech and security standards have evolved a lot since then. Other secure messengers like Threema have managed to build functional web clients using modern workarounds and session models.

Signal is incredible, but not having a browser version can be frustrating, especially on work computers and managed machines where installing custom desktop software isn't permitted.

Curious to hear thoughts from the community or if anyone has heard of any updates/discussions around this!

reddit.com
u/EriksonThorsen — 1 day ago

Are we far off from getting a dedicated Beehiiv mobile app?

I know the Beehiiv ecosystem is getting massive and complex with everything being built, but is there any word or timeline on an official mobile app for creators?

I don't even expect a full post editor on mobile (drafting and designing newsletters on a phone sounds like a nightmare anyway). But having a proper mobile companion app to:

  • Check the main dashboard and real-time subscriber metrics
  • View website, podcast, and community analytics
  • Check and reply to DMs / community messages
  • Get push notifications for new free/paid subs, milestone alerts, etc.

Logging into the mobile browser version just feels clunky when all you want to do on the go is check stats, respond to messages, or see alerts.

Has the team mentioned anything on the roadmap about a native app anytime soon?

reddit.com
u/EriksonThorsen — 3 days ago

How much safer is cold storage really, once you factor in the person using it?

Been chewing on this for two weeks and I want to hear where people actually land because I keep flip flopping.

Quick recap in case you missed either one. Coldcard: a build error in firmware from March 2021 meant some devices generated seeds using a software PRNG instead of the chip's hardware RNG. Effective entropy dropped to around 40 bits on older models, which is brute forceable offline. Nobody got phished. Nobody's device was stolen. Nobody typed their words into a fake site. Something like 1,800 BTC gone from 5,000+ addresses, and updating the firmware doesn't fix a seed that was already generated weak.

Then Trezor's fulfilment partner got breached. About 13,700 customers, and for most of them it was full name, email, phone number and home address. Credit where it's due, Trezor's own systems were never touched, and no keys were exposed, and their 90-day retention policy is the only reason it wasn't every buyer in company history. But think about what that list is. It's confirmed hardware wallet owners with the address the box was delivered to. Phishing by email, phone, and physical mail. Someone sends a letter on branded paper about an urgent recall or a mandatory firmware update, and I'd bet a decent number of people follow the instructions. Reports are already saying the data is being used to ask people for their 24 words.

Ok, so here's the thing I want to argue about, and I want to say upfront I don't think there's a correct answer. I'm not saying cold wallets are unsafe. I'm not saying hot wallets are safe. I own hardware wallets, and I'm not getting rid of them.

Conceptually, cold is obviously better. That's not in question. What I'm less sure about is how much of that advantage survives contact with a normal human being.

Take bad products out of it. There's garbage on both sides, and there are wallets that used to be good and aren't anymore. Assume the person picked well either way.

Good hot wallet, the chain is short. Most don't ask for any personal info. You install the app, generate the wallet, and after that, it's two questions. Is the seed handled properly, and is the phone clean. That's basically the whole thing.

Good cold wallet, the logic after generation is identical. Seed safe, wallet safe. But now look at everything that has to go right before you even hold the device. Did you buy from the real site or a clone. A lot of manufacturers don't ship everywhere so now you're trusting a reseller, or a third-party seller on Amazon because that's your only option. Was the package tampered with. And to buy it you hand over name, email, phone, home address and payment method, and that data then gets handed to fulfilment and courier companies you never picked and can't audit. That's the exact link that failed at Trezor.

That's a lot of companies holding a file that proves you own crypto. Half this space cares about privacy above almost everything else, and buying a hardware wallet is one of the least private purchases you can make. Once it leaks, it's also something a tax authority can cross-reference, which is a very different conversation for anyone whose declarations don't line up.

And then there's the part nobody wants to bring up. Loads of people buy a hardware wallet, generate the seed offline exactly like the manual says, and then save the 12 or 24 words into their password manager. Bitwarden, Proton Pass, a local KeePass file, whatever. They think it's fine because it's encrypted. What they actually did was turn a cold seed into a hot seed, and the device is now a paperweight with a screen.

I'm not laughing at anyone for that. Errors are the price of being your own bank. We have a long, very public list of people at the top of this industry who lost absurd amounts to small operational mistakes, so it's clearly not a beginner thing. It's a human thing. If you haven't made your mistake yet, give it time.

Which gets me to the part I actually believe. People point at funds and custodians running cold storage as proof that cold is the answer. Sure, but those operations know how to handle a seed, they don't go connecting their savings wallet to random contracts, they keep firmware current, and there are people whose entire job is that. Retail buyer has none of that. So when the standard advice is "buy a hardware wallet, or you're doing it wrong," two things happen that, I think, are worse than the alternative.

One, someone with a small stack gets intimidated by the whole ritual, decides self custody is above their level, and leaves the coins on an exchange. Which we all agree is the worst option available.

Two, someone spends 250 bucks on a device to protect 50 bucks of crypto because they were made to feel irresponsible for not buying the "safe" option.

So my position, and tell me where it's wrong: a hardware wallet is a tool that quietly assumes a level of knowledge and paranoia that most of this market doesn't have yet. For people who don't have it, a good hot wallet with a couple of boring habits, like a cheap dedicated phone that does nothing else, might be the better real-world outcome than a hardware wallet used badly.

Anyway. If you're advising a friend with a few hundred dollars and no technical background, what do you actually tell them and why? And does the purchase and shipping surface bother anyone else, or do you think anonymous delivery and paying in crypto solves it? Also, curious whether the Coldcard bug changed how anyone thinks about "it's open source" as a security argument. Most of the people can't read that code, and even the people who can have no way of knowing how many other qualified eyes actually looked. Open-source means auditable, not audited. Or do you file this one as a fluke and move on?

Not looking for a winner, I just think this sub gives better answers than "not your keys, buy a hardware wallet, done." Sorry for the wall of text.

reddit.com
u/EriksonThorsen — 6 days ago

How much safer is cold storage really, once you factor in the person using it?

Been chewing on this for two weeks and I want to hear where people actually land because I keep flip flopping.

Quick recap in case you missed either one. Coldcard: a build error in firmware from March 2021 meant some devices generated seeds using a software PRNG instead of the chip's hardware RNG. Effective entropy dropped to around 40 bits on older models, which is brute forceable offline. Nobody got phished. Nobody's device was stolen. Nobody typed their words into a fake site. Something like 1,800 BTC gone from 5,000+ addresses, and updating the firmware doesn't fix a seed that was already generated weak.

Then Trezor's fulfilment partner got breached. About 13,700 customers, and for most of them it was full name, email, phone number and home address. Credit where it's due, Trezor's own systems were never touched, and no keys were exposed, and their 90-day retention policy is the only reason it wasn't every buyer in company history. But think about what that list is. It's confirmed hardware wallet owners with the address the box was delivered to. Phishing by email, phone, and physical mail. Someone sends a letter on branded paper about an urgent recall or a mandatory firmware update, and I'd bet a decent number of people follow the instructions. Reports are already saying the data is being used to ask people for their 24 words.

Ok, so here's the thing I want to argue about, and I want to say upfront I don't think there's a correct answer. I'm not saying cold wallets are unsafe. I'm not saying hot wallets are safe. I own hardware wallets, and I'm not getting rid of them.

Conceptually, cold is obviously better. That's not in question. What I'm less sure about is how much of that advantage survives contact with a normal human being.

Take bad products out of it. There's garbage on both sides, and there are wallets that used to be good and aren't anymore. Assume the person picked well either way.

Good hot wallet, the chain is short. Most don't ask for any personal info. You install the app, generate the wallet, and after that, it's two questions. Is the seed handled properly, and is the phone clean. That's basically the whole thing.

Good cold wallet, the logic after generation is identical. Seed safe, wallet safe. But now look at everything that has to go right before you even hold the device. Did you buy from the real site or a clone. A lot of manufacturers don't ship everywhere so now you're trusting a reseller, or a third-party seller on Amazon because that's your only option. Was the package tampered with. And to buy it you hand over name, email, phone, home address and payment method, and that data then gets handed to fulfilment and courier companies you never picked and can't audit. That's the exact link that failed at Trezor.

That's a lot of companies holding a file that proves you own crypto. Half this space cares about privacy above almost everything else, and buying a hardware wallet is one of the least private purchases you can make. Once it leaks, it's also something a tax authority can cross-reference, which is a very different conversation for anyone whose declarations don't line up.

And then there's the part nobody wants to bring up. Loads of people buy a hardware wallet, generate the seed offline exactly like the manual says, and then save the 12 or 24 words into their password manager. Bitwarden, Proton Pass, a local KeePass file, whatever. They think it's fine because it's encrypted. What they actually did was turn a cold seed into a hot seed, and the device is now a paperweight with a screen.

I'm not laughing at anyone for that. Errors are the price of being your own bank. We have a long, very public list of people at the top of this industry who lost absurd amounts to small operational mistakes, so it's clearly not a beginner thing. It's a human thing. If you haven't made your mistake yet, give it time.

Which gets me to the part I actually believe. People point at funds and custodians running cold storage as proof that cold is the answer. Sure, but those operations know how to handle a seed, they don't go connecting their savings wallet to random contracts, they keep firmware current, and there are people whose entire job is that. Retail buyer has none of that. So when the standard advice is "buy a hardware wallet, or you're doing it wrong," two things happen that, I think, are worse than the alternative.

One, someone with a small stack gets intimidated by the whole ritual, decides self custody is above their level, and leaves the coins on an exchange. Which we all agree is the worst option available.

Two, someone spends 250 bucks on a device to protect 50 bucks of crypto because they were made to feel irresponsible for not buying the "safe" option.

So my position, and tell me where it's wrong: a hardware wallet is a tool that quietly assumes a level of knowledge and paranoia that most of this market doesn't have yet. For people who don't have it, a good hot wallet with a couple of boring habits, like a cheap dedicated phone that does nothing else, might be the better real-world outcome than a hardware wallet used badly.

Anyway. If you're advising a friend with a few hundred dollars and no technical background, what do you actually tell them and why? And does the purchase and shipping surface bother anyone else, or do you think anonymous delivery and paying in crypto solves it? Also, curious whether the Coldcard bug changed how anyone thinks about "it's open source" as a security argument. Most of the people can't read that code, and even the people who can have no way of knowing how many other qualified eyes actually looked. Open-source means auditable, not audited. Or do you file this one as a fluke and move on?

Not looking for a winner, I just think this sub gives better answers than "not your keys, buy a hardware wallet, done." Sorry for the wall of text.

reddit.com
u/EriksonThorsen — 6 days ago
▲ 6 r/Setapp

Would love to see Letterbox (or a similar newsletter reader) on Setapp!

I've been a Setapp user for a few years now and love how it covers so many productivity and utility bases. One app I've been using a lot lately is Letterbox for managing and reading newsletters, keeping them out of my main email inbox.

I know Setapp already has some great email clients, but having a dedicated newsletter reader/aggregator like Letterbox included in the bundle would be an awesome addition to streamline daily reading routines.

Curious if anyone else would find something like this useful, or if you're using another app to keep newsletters organized alongside Setapp?

u/EriksonThorsen — 7 days ago
▲ 4 r/Tangem

Question about backup cards when using a seed phrase

I’m trying to understand how the backup card setup works with Tangem.

The Tangem kits come with 2 or 3 cards, which makes perfect sense for a seedless wallet. Since access to the wallet is tied exclusively to the Tangem cards, having additional cards as backups is obviously important.

However, Tangem also supports wallets created with a seed phrase. From what I understand, even when using a seed phrase, you still have to set up additional backup cards during the initial setup.

Is that correct, or am I misunderstanding something?

My confusion is that, with a seed phrase wallet, the seed phrase itself is the backup of the wallet. If I have the seed phrase securely stored, I should theoretically be able to recover the wallet without needing another Tangem card.

So in that case, what is the purpose of having 2 or 3 Tangem cards? Is there an additional security or recovery benefit that I'm missing?

I'm genuinely trying to understand the logic here, especially the difference between the backup model for seedless wallets and seed phrase wallets. If someone from Tangem or an experienced user could clarify, I'd appreciate it.

reddit.com
u/EriksonThorsen — 8 days ago
▲ 43 r/Bitcoin

Traveling internationally with a hardware wallet: what's been your experience with customs/immigration?

Hey everyone, curious to hear people's real-world experiences with this.

When traveling internationally, most countries require you to declare if you're carrying over $10k in cash or monetary instruments. Crypto creates a weird gray area for border control.

Technically, carrying a hardware wallet isn't carrying money across the border. The funds reside on the blockchain, not on the device. It's fundamentally no different than carrying a phone with a banking app or a bank token device.

That said, border control and immigration agents usually stick strictly to their playbook, and many might not understand or care about how the blockchain works if they inspect your bags.

For those who travel often with hardware wallets:

  1. Have you ever been asked about your wallet by border agents?
  2. How do you handle declarations or questions if custom officials bring it up?
  3. What seems to be the broadly accepted or safest approach when crossing borders?

Would love to hear how you guys approach this in practice!

reddit.com
u/EriksonThorsen — 9 days ago
▲ 95 r/Bitcoin

I've never trusted device-generated entropy. Here's my full offline dice + BIP39 workflow, step by step

I'm not trying to make this an "I told you so" post, but I'll admit that's roughly how I felt reading the Coinkite advisory last week.

Quick recap for anyone who missed it. A firmware integration mistake from March 2021 caused Coldcard seed generation to fall back to MicroPython's software PRNG instead of using the chip's hardware RNG. The build check tested whether a macro existed, not whether it was enabled, and since the value was zero it silently passed. Nothing crashed. No warnings. Seeds kept coming out looking like completely normal 12 and 24 word phrases and nobody noticed for four years. Coinkite's own estimate is around 40 bits of effective entropy on Mk2 and Mk3, and around 72 bits on Mk4, Mk5 and Q, against the 128 bits that should have been there.

On July 30 someone drained 1,196 addresses in 41 minutes. Later on-chain analysis has the total north of 1,300 BTC.

I've never trusted device-generated entropy. Not because I'm smart, but for a genuinely dumb reason: I can't audit it. You cannot crack open a hardware wallet and confirm that the number came out of a real TRNG and not out of a timer register. You just trust it. And trust is the exact thing we spend all day telling each other not to do. Don't trust, verify, except at the single most important moment in the whole stack, which is the birth of the key, where basically everyone just trusts.

I've said this for years and always sounded like a crank. This week made me realize how few of us actually do it, so here's my process. It's much simpler than people expect.

The reasoning

No computer is truly random. It simulates randomness. A die bouncing across a table involves physics nobody can model or predict. That's actual randomness, not an imitation of it. When you roll it yourself and type the result, you stop outsourcing the most critical part of your security to firmware you've never read.

The tool

I use Ian Coleman's BIP39 tool. It's free, the code has been open on GitHub for years, plenty of people have gone through it, and most importantly there's a standalone single-file build that runs fully offline. You download one HTML file and that's it. No server, no network calls, nothing.

Link: https://github.com/iancoleman/bip39/releases

Type that address into the address bar. Do not Google it. I'm serious about this one. I've seen sponsored ads for clones of this tool, and the clone had hardcoded entropy. You generate a seed, everything looks right, you deposit, and the coins are gone. Searching and clicking the first result is a great way to hand your wallet to someone for free.

On the releases page on GitHub, under the latest version (0.5.6), expand assets and download bip39-standalone.html. That single file is all you need.

Going offline

Pick your paranoia level:

  • Basic: unplug the machine from the internet. Cable out, Wi-Fi off at the hardware switch if you have one. Only then open the file.
  • Better: use a second device. An old laptop you don't use for anything else, no network.
  • The annoying level (mine): an amnesic system like Tails booted from a USB stick. It writes nothing to disk and forgets everything on shutdown.

If you're going to skip all of that and open the file on your daily driver with forty tabs open, do yourself a favor and stop here.

Generating the entropy

With the machine offline, open bip39-standalone.html in your browser. It loads exactly like the online version, just without any internet.

  1. Tick "show entropy details". A new panel opens with an entropy field and a bunch of technical readouts underneath.
  2. Under "valid entropy values include", pick the Dice [1-6] option. It shows an example like 62535634 so you can see the expected format.
  3. Grab your die and start rolling. Type each result into the entropy field. No spaces, no commas, all run together.

It ends up looking like this:

6245612344552631245563124563123456311243563212345641... 

As you type, watch the panel below. It updates "Event Count" (how many rolls you've entered) and "Total Bits" (how much entropy you've actually accumulated) in real time. That counter is what you follow, not my guess.

My reference numbers:

  • 12 words: you need at least 128 bits. In this tool that works out to roughly 80 rolls.
  • 24 words: at least 256 bits. Somewhere around 155 to 160 rolls.

Yes, it's tedious. I put on a podcast and get through it in about 15 minutes. Given what it's protecting, 15 minutes is cheap. And if you overshoot, fine. Extra entropy doesn't hurt anything.

A quick tip on the die: ensure you actually roll it so it bounces. A light, two-inch drop with a warped novelty die creates bias, so rolling more frequently helps to counteract that.

If you're more advanced, the tool also accepts coin flips and playing cards as entropy sources. Same idea. I'm using dice here because it's the easiest for most people to get right.

Getting the seed

Done rolling? Scroll down. Your phrase is already sitting in the BIP39 Mnemonic field. That's it. Just confirm Mnemonic Length is set to whichever you wanted, 12 or 24.

Write the words down on paper, in order, by hand. Don't photograph it. Don't type it into your phone. Don't email it to yourself, don't put it in Notes, don't put it in Google Keep. Paper, pen, in order, then check it word by word twice, paying attention to the ones that look similar.

After that, restore the seed into whatever wallet you trust, hot or cold, and use it normally. If you want to stay fully offline, Electrum or anything else that takes a BIP39 import works fine.

When you're finished, close the browser and delete the file. On Tails, just shut down.

Stuff I do and strongly recommend

  • Test before you trust it. Restore the seed in your wallet, confirm the addresses match what the tool showed, send a small amount, try spending it. Only then move real money.
  • Do not use the example dice string I pasted above. Obvious, but someone will. That's an illustration.
  • Consider a BIP39 passphrase. It's another layer, and in this exact incident a strong passphrase also kept people out of the blast radius.
  • Never type an existing seed into this tool while online. The tool is offline by design, but people aren't.

Being honest about the downsides

This isn't a foolproof solution, and I'm not going to pretend it is.

The weak point is that the seed passes through a general purpose computer. Browsers cache, systems swap, there's always some surface. A hardware wallet that takes dice input directly on the device (Coldcard itself does this, which is the irony here) has the advantage that the seed never touches a PC at all. If you have that option, and you trust the device to do the mixing, that's an equally valid path and arguably a better one.

There are other approaches too: hand-picking words from the wordlist, computing the checksum manually, coins, cards. Each one trades off differently between security, complexity, and how likely you are to screw it up. Honestly, the biggest risk across every manual method is the user making a mistake and bricking their own money.

And the obvious point: this isn't Bitcoin only. It applies to anything using BIP39, so most of the rest of the space too.

This is the method I use, trust, and recommend to friends and family. It isn't the only correct one. Do your own research, understand what you're doing before you do it, and above all, store those words properly. Generating the most perfectly random seed in the universe means nothing if the paper ends up in a kitchen drawer or in your camera roll. No generation method survives bad storage.

If you use a different method, drop it in the comments. I'm actually curious how many people here generate entropy by hand versus how many just hit generate and hope.

u/EriksonThorsen — 16 days ago

Do you actually trust that "temporary chats" aren't used for training? Let's talk about it

I've been thinking about this a lot lately and wanted to get people's opinions here.

So basically, every major AI company now offers some form of "temporary" chat mode. OpenAI has Temporary Chat, Google Gemini has Temporary Chats, Anthropic has Incognito Chats. They all say the same thing: these chats won't be saved to your history and won't be used to train their models. Sounds great in theory, right?

But here's the thing that bugs me. If you actually read the fine print, "temporary" doesn't really mean temporary. OpenAI is pretty upfront about it actually. Their own FAQ says that Temporary Chats are deleted from their systems after 30 days, and during that window they may be reviewed to monitor for abuse. So it's only ephemeral from our perspective as users. The data still sits on their servers for a month. Google does something similar but keeps it for 72 hours instead. Anthropic's Incognito chats aren't used for training, but deleted conversations may still hang around in backups for 30 days before permanent deletion.

And honestly? I have a hard time believing that companies spending hundreds of millions (or billions) on training the next generation of models are just throwing away all that conversational data. Like, that's some of the most valuable, naturally occurring training data you could ask for. People typing real questions, real follow-ups, real corrections. You're telling me they're not at least skimming off some of that for RLHF or something similar? There was even a thread on r/OpenAI a while back where people noticed OpenAI was doing A/B testing on Temporary Chats, which makes you wonder what exactly they're doing with that data if it's not supposed to be used for anything.

There's also the whole legal angle. OpenAI was under a court order for a while (related to the NYT lawsuit) to retain consumer ChatGPT and API data indefinitely. They said they fought it and eventually got out from under that order, but it shows that "we delete your data" can be overridden by legal demands at any point.

Now, where I do feel somewhat more confident is with API usage. OpenAI explicitly says API data is not used for training by default, and they back that up with enterprise privacy commitments. Anthropic says the same about their commercial products (Claude for Work, API, Claude Gov). The reason I buy this more is that these are B2B/Enterprise clients pushing massive volumes of sensitive company data through the API. If it came out that an AI provider was secretly training on API data, the enterprise contracts would evaporate overnight, and the lawsuits would be brutal. Plus, you're literally paying for tokens, so there's a cleaner commercial justification for not needing to squeeze training value out of it.

But even there, some people have pointed out that the terms of service only restrict using data for "AI training" specifically, which doesn't necessarily close the door on other uses like safety monitoring, abuse detection, or "product improvement" which can be pretty broadly defined.

So I'm curious what people here actually think:

Do you believe the claims that temporary chats are genuinely not used for training? Which companies do you trust more on this, and which ones don't you trust at all? Is the API a different story in your mind, or do you think it's the same situation, just wrapped in better marketing?

Genuinely interested in hearing different perspectives!

reddit.com
u/EriksonThorsen — 17 days ago

Is there any way to change the timezone in Rumble Studio?

Hey everyone, I've been messing around with Rumble Studio and I can't seem to find any setting to change the timezone. Everything seems to be stuck on one timezone, and it's throwing off my stream schedules and analytics.

I looked through all the settings I could find, but nothing jumps out at me. Am I just missing it somewhere, or is this not a thing that's available yet?

If anyone has figured this out or has a workaround, I'd really appreciate the help. Thanks in advance.

reddit.com
u/EriksonThorsen — 17 days ago

Love Nextcloud, but the theming is my one struggle. Has anyone found a setup that works?

I have been running Nextcloud for a while now and I really do love it. It does everything I need, and I would not go back to the big cloud providers at this point.

That said, I want to be honest about the one thing I keep bumping into: the theming. It is not the most polished part of the experience, and sometimes it actually gets in the way. Dark icons sitting on a dark background, text that basically disappears depending on which app I am in, that kind of thing. Nothing that breaks anything, but enough that I catch myself squinting or hovering around trying to find a button I know is there.

To be very clear, this is not a criticism of the project, and it is not me questioning the quality of what the team has built. Anyone who uses open-source software knows that the visual layer is often the part that does not get revisited as often, and for pretty obvious reasons. There is a limited amount of time and there are far more important things to fix first. I get it, and I am grateful for the work that goes into it.

So my actual question: has anyone here managed to adjust the theme, colors, contrast, whatever, and ended up with a layout you were genuinely happy with? I am curious what people are doing. Custom CSS? A specific theming app? Just tweaking the admin theming settings and living with it? Screenshots very welcome if you have something you like.

Would love to hear what has worked for you.

reddit.com
u/EriksonThorsen — 21 days ago
▲ 14 r/yubikey

Where do you keep your third backup key outside your home?

I feel like the ideal solution would be to rent a safe deposit box and keep it there, but honestly, that's getting harder and harder these days. A lot of banks stopped offering the service entirely, and the third-party companies that still do have waitlists that are literally years long. If you live in a smaller city, good luck finding one at all.

So my backup key has been in a few places over time. My gym's overnight locker. My under-desk pedestal at work. Even my car at one point. And honestly, I don't feel great about any of those. The gym locker isn't exactly Fort Knox, people come and go at work all the time, and a car is probably one of the worst places for something like that.

I'd really love to hear where you guys keep yours, especially outside your home. And not just YubiKeys either, I'm curious about how you handle crypto wallet seed phrases and similar stuff too. What's worked for you, what hasn't, any creative solutions you've come up with?

Appreciate any input!

reddit.com
u/EriksonThorsen — 21 days ago

Are parents in Ireland taught the Heimlich maneuver / infant choking first aid before leaving the maternity ward?

In some countries, parents are often encouraged to learn the Heimlich maneuver and infant back blows as part of basic first aid training, especially in prenatal classes. But I get the impression this isn't universal everywhere.

I'm interested to know whether in Ireland:

  • Are parents formally taught how to respond when a baby or child is choking?
  • Is it part of any mandatory class (e.g., prenatal, hospital, or school programs)?
  • Or is it something most people just pick up on their own (YouTube, etc.)?

Would love to hear how it works!

reddit.com
u/EriksonThorsen — 24 days ago

Any demo access for the new Community platform?

Hey, does anyone know if there's a demo or sandbox of the new Community feature on Beehiiv? Like both the frontend (what subscribers see) and the admin side?

I've been looking around and can't find anything. Checked the website, the support docs, the features page... nothing really shows the actual UI in action.

I'm trying to get a sense of how it works before committing to a plan. Anyone have info on this?

Appreciate any help 🙏

reddit.com
u/EriksonThorsen — 24 days ago

The EU is the world's most active tech regulator. So when is it going to do something about "buying" digital media that you never actually own?

Look, we all know the EU has been ahead of the curve on tech regulation. GDPR changed how the entire internet handles privacy. They forced USB-C on everyone (Apple included). The DMA cracked open iOS and forced Apple to allow alternative app stores. The AI Act, DSA, right to repair, repairability scores on phones, and the list goes on. When Brussels moves, the rest of the world usually follows.

So here's what I genuinely don't understand: why has nobody tackled the absolute scam that is "buying" digital media?

You buy a book on Kindle. You buy a game on Steam, PlayStation, Nintendo eShop. You click a button that says "Buy." You pay money. And what you actually get is a "license to use", a revocable permission that can be yanked away from you at any time, for any reason, with zero refund.

This isn't some theoretical what-if. It keeps happening:

Amazon literally remotely deleted copies of 1984 and Animal Farm from people's Kindles in 2009 over a licensing dispute. Yes, they deleted 1984. The irony was not lost on anyone. Bezos called it "stupid and thoughtless" but the precedent was set and nothing structurally changed.

Sony is deleting 551 purchased movies from PlayStation users' libraries in the UK and Europe on September 1, 2026 because their licensing deal with StudioCanal expired. These are movies people paid for. Gone. No refund. No way to download and keep them. Just a message saying "you will no longer be able to access your previously purchased content."

If Amazon has a contract dispute with a publisher, your books can vanish. If a game studio decides to shut down a server, you might not be able to download a game you paid for anymore. You paid for it. It's gone. Good luck getting your money back.

And don't tell me "just buy physical" because that's becoming a joke too:

GTA VI's "physical edition" is literally a box with a download code inside. No disc. Rockstar confirmed this. You buy a plastic case at retail, open it, and find a code. It's functionally identical to buying it digitally, you just got a fancy box for your troubles.

PlayStation announced they're ending all physical disc production for new games starting January 2028. Which strongly implies the next PlayStation won't even have a disc drive. They're not even pretending anymore.

Nintendo Switch 2 has a massive code-in-a-box problem. Multiple "physical" releases, including Bethesda's Oblivion, Skyrim, and Fallout, are just an empty case with a download code. No cartridge. Some of them don't even use the game-key card format, which at least lets you resell. You're buying a plastic shell.

So even when you try to do the "right thing" and buy physical, you often end up with a digital license in a fancy box. The illusion of ownership in a $70 plastic case.

And the brands I mentioned are just examples. This is an industry-wide pattern. It's everyone.

There's a slogan that's been going around in gaming communities and I think it captures the frustration perfectly: "If buying is not owning, piracy is not stealing."

Let me be crystal clear because I know how this sounds, I am NOT encouraging piracy. That slogan is a protest motto from gamers fighting against having access to games they paid for taken away. But there's a real point in there: when publishers kill servers and make it impossible to legally access a game you bought, or any game at all, piracy literally becomes the only way to play discontinued titles. The companies themselves created the conditions where piracy is the only preservation method left. That's not consumers being entitled, it's a policy failure.

So does anyone know if the EU has anything in the pipeline for this?

There's been some movement but it's been pretty disappointing. The Stop Killing Games campaign (started by YouTuber Ross Scott) managed to gather over 1.29 million verified signatures as a European Citizens' Initiative, the biggest gaming-related petition in EU history. But in June 2026 the Commission basically said "nah" and declined to propose any binding legislation. They offered a voluntary industry code of conduct instead, which... yeah, we all know how voluntary industry self-regulation goes.

The campaign has now pivoted to trying to get game preservation amendments added to the Digital Fairness Act, which is expected to be proposed in late 2026. They apparently have support from 40+ MEPs. But it's early and there's no guarantee it'll go anywhere.

There's also the EU Directive on Digital Content and Services (2019/770) which gives some consumer protections for digital goods, but it doesn't address the core issue: it doesn't stop companies from revoking access to stuff you paid for because of licensing disputes.

Honestly, the EU proved with GDPR that consumer rights regulation can reshape the global landscape. USB-C proved even Apple will comply. The DMA proved walled gardens can be forced open. Digital ownership feels like the obvious next fight.

What I'd want to see is pretty simple: if it's a license, call it a license. Don't put a "Buy" button when you mean "rent indefinitely until we decide otherwise." Make companies provide offline access or downloadable copies for stuff people paid for. Mandatory refunds when access gets revoked. And if a company is shutting down a service, require them to give users a way to keep what they bought: offline installers, community server tools, something.

I'm really hoping this gets on the EU's radar properly. If anyone here knows of other initiatives, or MEPs who've spoken about this, I'd love to hear about it. This feels like one of those things where if the EU moves first, the rest of the world will follow, just like every other time

reddit.com
u/EriksonThorsen — 29 days ago

Beehiiv's ad network is nice but not great for every niche. Anyone else wish we could add Google AdSense to our Beehiiv sites?

I really like Beehiiv's ad network. It's well built and it definitely has value. But let's be real, it's not for every single niche. Depending on your audience and topic, the fill rates can be low, the payouts might not be that great, and you're kind of stuck with no alternative.

So I'm wondering, am I the only one who'd love the option to add Google AdSense to a Beehiiv site? Is this something we can hope for in the future or is it a hard no from Beehiiv?

I feel like they should just go for it without worrying too much. Their own ad network is genuinely good, so it's not like AdSense would replace it for most people. But for creators in niches that don't get much love from the native network, having AdSense as an option would be a lifesaver. I don't think offering other ad networks would hurt them at all. If anything, it shows confidence in their own product and gives creators more flexibility.

Anyone else feel the same? Has Beehiiv ever said anything about this?

reddit.com
u/EriksonThorsen — 29 days ago
▲ 56 r/europrivacy+1 crossposts

The EU is the world's most active tech regulator. So when is it going to do something about "buying" digital media that you never actually own?

Look, we all know the EU has been ahead of the curve on tech regulation. GDPR changed how the entire internet handles privacy. They forced USB-C on everyone (Apple included). The DMA cracked open iOS and forced Apple to allow alternative app stores. The AI Act, DSA, right to repair, repairability scores on phones, and the list goes on. When Brussels moves, the rest of the world usually follows.

So here's what I genuinely don't understand: why has nobody tackled the absolute scam that is "buying" digital media?

You buy a book on Kindle. You buy a game on Steam, PlayStation, Nintendo eShop. You click a button that says "Buy." You pay money. And what you actually get is a "license to use", a revocable permission that can be yanked away from you at any time, for any reason, with zero refund.

This isn't some theoretical what-if. It keeps happening:

Amazon literally remotely deleted copies of 1984 and Animal Farm from people's Kindles in 2009 over a licensing dispute. Yes, they deleted 1984. The irony was not lost on anyone. Bezos called it "stupid and thoughtless" but the precedent was set and nothing structurally changed.

Sony is deleting 551 purchased movies from PlayStation users' libraries in the UK and Europe on September 1, 2026 because their licensing deal with StudioCanal expired. These are movies people paid for. Gone. No refund. No way to download and keep them. Just a message saying "you will no longer be able to access your previously purchased content."

If Amazon has a contract dispute with a publisher, your books can vanish. If a game studio decides to shut down a server, you might not be able to download a game you paid for anymore. You paid for it. It's gone. Good luck getting your money back.

And don't tell me "just buy physical" because that's becoming a joke too:

GTA VI's "physical edition" is literally a box with a download code inside. No disc. Rockstar confirmed this. You buy a plastic case at retail, open it, and find a code. It's functionally identical to buying it digitally, you just got a fancy box for your troubles.

PlayStation announced they're ending all physical disc production for new games starting January 2028. Which strongly implies the next PlayStation won't even have a disc drive. They're not even pretending anymore.

Nintendo Switch 2 has a massive code-in-a-box problem. Multiple "physical" releases, including Bethesda's Oblivion, Skyrim, and Fallout, are just an empty case with a download code. No cartridge. Some of them don't even use the game-key card format, which at least lets you resell. You're buying a plastic shell.

So even when you try to do the "right thing" and buy physical, you often end up with a digital license in a fancy box. The illusion of ownership in a $70 plastic case.

And the brands I mentioned are just examples. This is an industry-wide pattern. It's everyone.

There's a slogan that's been going around in gaming communities and I think it captures the frustration perfectly: "If buying is not owning, piracy is not stealing."

Let me be crystal clear because I know how this sounds, I am NOT encouraging piracy. That slogan is a protest motto from gamers fighting against having access to games they paid for taken away. But there's a real point in there: when publishers kill servers and make it impossible to legally access a game you bought, or any game at all, piracy literally becomes the only way to play discontinued titles. The companies themselves created the conditions where piracy is the only preservation method left. That's not consumers being entitled, it's a policy failure.

So does anyone know if the EU has anything in the pipeline for this?

There's been some movement but it's been pretty disappointing. The Stop Killing Games campaign (started by YouTuber Ross Scott) managed to gather over 1.29 million verified signatures as a European Citizens' Initiative, the biggest gaming-related petition in EU history. But in June 2026 the Commission basically said "nah" and declined to propose any binding legislation. They offered a voluntary industry code of conduct instead, which... yeah, we all know how voluntary industry self-regulation goes.

The campaign has now pivoted to trying to get game preservation amendments added to the Digital Fairness Act, which is expected to be proposed in late 2026. They apparently have support from 40+ MEPs. But it's early and there's no guarantee it'll go anywhere.

There's also the EU Directive on Digital Content and Services (2019/770) which gives some consumer protections for digital goods, but it doesn't address the core issue: it doesn't stop companies from revoking access to stuff you paid for because of licensing disputes.

Honestly, the EU proved with GDPR that consumer rights regulation can reshape the global landscape. USB-C proved even Apple will comply. The DMA proved walled gardens can be forced open. Digital ownership feels like the obvious next fight.

What I'd want to see is pretty simple: if it's a license, call it a license. Don't put a "Buy" button when you mean "rent indefinitely until we decide otherwise." Make companies provide offline access or downloadable copies for stuff people paid for. Mandatory refunds when access gets revoked. And if a company is shutting down a service, require them to give users a way to keep what they bought: offline installers, community server tools, something.

I'm really hoping this gets on the EU's radar properly. If anyone here knows of other initiatives, or MEPs who've spoken about this, I'd love to hear about it. This feels like one of those things where if the EU moves first, the rest of the world will follow, just like every other time

reddit.com
u/EriksonThorsen — 29 days ago

Anyone using Google Titan Keys along with YubiKeys in their personal setup?

Hey folks,

Right now, my personal security setup is all YubiKeys, got a couple of the 5 Series ones that I use for everything, including TOTP through Yubico Authenticator. Works great, no complaints.

But here's the thing: a few years back I worked at a company that gave everyone Google Titan Keys, and I've still got a few of them sitting in a drawer at home. Specifically, I've got the USB-C nano ones, which are tiny and honestly super convenient for just leaving plugged in or having on a keychain without even noticing they're there.

So I've been thinking... why not put them to use? Feels like a waste to just let them gather dust. I'd mainly want them as backup/secondary keys on some accounts where I just need a phishing-resistant second factor or passkey support.

I know the obvious tradeoff: no Yubico Authenticator / TOTP on the Titan Keys. No OTP, no PIV, none of that stuff. From what I can tell, they basically do FIDO2/WebAuthn and U2F, which puts them roughly in the same category as the Security Key C NFC from Yubico? That's my understanding at least, correct me if I'm wrong.

Honestly, I don't know a ton about the Titan Keys beyond using them at my old job for basic 2FA. Never really dug into the details. So if anyone here has used both, I'd love to hear:

  • How are they day-to-day compared to YubiKeys? Any durability issues?
  • Have you hit any services that work with one but not the other?
  • I've seen the Titan Keys can store a lot more passkeys than the YubiKey 5, is that actually useful in practice or is it kind of a "nice on paper" thing?

My thinking is keep the YubiKeys as my main keys (for TOTP and everything else) and use the Titans as backups for pure FIDO2/passkey accounts. The nano form factor is really the main reason I'm even considering this, having something that small you can just forget about is genuinely nice.

Anyway, would appreciate any experiences or honest takes on whether this is a solid idea or overcomplicating things for no reason. Thanks!

reddit.com
u/EriksonThorsen — 29 days ago