Privacy, easy repairability, and software support until 2033: Europe's new deGoogled, eco-friendly phone with an open-source operating system. Fairphone 6+ with e/OS.
▲ 329 r/xprivo+1 crossposts

Privacy, easy repairability, and software support until 2033: Europe's new deGoogled, eco-friendly phone with an open-source operating system. Fairphone 6+ with e/OS.

The majority of smartphones have a lifespan of just a few years and rely heavily on Google's Android ecosystem, which compromises users' privacy.
It's getting time for a switch. The Fairphone 6+ (from the Dutch electronics manufacturer Fairphone) is designed to be opened so that you can take it apart and replace components with newer ones whenever you want, allowing you to keep it for as long as you like. Twelve components, including the battery, cameras, USB-C port and display, can be replaced with just a screwdriver. The phone also comes with a five-year warranty and will receive software updates until 2033.
In partnership with French developer Murena, the Gen 6+ runs /e/OS: a fully open-source, 'de-Googled' version of Android. It's built so that switching away from Google doesn't require you to become a power user. Murena's advanced privacy toggles and backup system are already integrated.

In terms of hardware, it has a Snapdragon 7s Gen 4 chip, 12 GB of RAM and a 120 Hz OLED display. And, as of this week, this combination of longevity and privacy is available outside of Europe for the first time, as Fairphone has launched the Gen 6+ directly in the US too!
Do you think it's a good, competitive phone in terms of privacy and durability, considering it's currently priced at around 699€ for a European phone manufacturer?

Source and more info: https://www.fairphone.com/de/the-fairphone-gen-6-plus-e-operating-system

▲ 70 r/xprivo

Think a VPN and Incognito mode protect you? Websites can still identify you really fast. Your GPU is snitching on you. Fingerprinting on the web:

You just cleared your cookies, opened a private window, and connected to a VPN. You think the previously visited website does not know you anymore and that you're anonymous. You aren't.
Without using your IP address or dropping a single cookie, websites can identify your device with high accuracy through browser fingerprinting.

What is Fingerprinting?
Every time you load a webpage, your browser hands over dozens of tiny technical details to render the site properly:
-Your screen resolution and color depth
-Installed system fonts and audio hardware
-Your exact graphics card model, driver version, and WebGL/WebGPU rendering quirks
Combined, this creates a mathematical "serial number" unique to your machine. Trackers use it to follow you across the web, even when you switch networks.

Brave recently shipped updated protections against invasive WebGL and WebGPU tracking by combining randomized noise ("farbling") with a single, uniform GPU profile across all its users. It’s good for everyday Chromium users that stops hardware tracking without breaking 3D maps or web games.

But Which Browser Is Actually the Best When It Comes To Stopping Fingerprinting? (I picked 4, so feel free to add yours in the comments)

1.** **Tor Browser & Mullvad Browser
Strategy: Strict Uniformity ("Hide in the crowd"
Instead of randomizing data, they force every single user to look 100% mathematically identical. They enforce strict letterboxing (gray borders that lock window sizes to fixed dimensions) and strip all hardware identifiers.
Pair Mullvad Browser with a trustworthy VPN (like Mullvad VPN itself) since, unlike Tor, it doesn't route traffic through the onion network by default.

  1. Brave
    Strategy**:** Hybrid Randomization ("Moving Target")
    Generates plausible randomized noise across APIs on each session and masks GPU strings. You still stand out as a "unique" user on any single visit, but trackers cannot link your visits across different sites. It gives high-end protection without breaking the modern web.

  2. LibreWolf
    Strategy: Loose Uniformity
    LibreWolf uses Firefox’s robust resistFingerprinting engine, but it disables letterboxing by default to give you normal, full-screen browsing. The problem? Your unique screen resolution and window dimensions are exposed, making your fingerprint mathematically unique. Tip for LibreWolf users: You can actually fix the "leaky default". You just have to open your librewolf.overrides.cfg file and change privacy.resistFingerprinting.letterboxing to true. This gives you Mullvad-level uniformity, but you will face a gray border around websites.

u/officialexaking — 4 days ago
▲ 148 r/xprivo

Good news: France's top court blocks ban on social media for children under 15, ruling it infringes on freedom of expression. The ID-card-or-selfie age verification law that would eventually affect every social media user is dead (for now)

The plan was that, starting in September 2026, anyone creating a new social media account would have to verify their age using an ID card or facial scan. That's only two weeks away! BUT:

France's top court struck down the under-15 social media ban on Friday (yesterday), the same law that would have required every user, not just minors, to prove their age through ID cards, FranceConnect, or facial recognition starting September 1.
The court ruled the measure unconstitutional on two separate grounds: it disproportionately infringed on freedom of expression and communication, and it failed to provide adequate legal safeguards to protect the right to privacy.

The ban would have applied indiscriminately to essentially any platform allowing users to connect and communicate, sweeping in far more than just Instagram or TikTok, and covering minors of any age or maturity level without distinction so also adults. The court also flagged that the law never specified the actual conditions under which every user, including adults, would have to prove their age, leaving the verification requirement itself constitutionally unmoored. On top of that, parents had no ability to lift the restriction for their own children even when they judged access to be appropriate, which the court treated as further evidence the law was disproportionate to its stated goal.

The effect of this: nothing changes this September for teenagers already on these platforms.

But be careful: President Macron has already directed the government to draft a new version addressing the court's concerns before his term ends, so this isn't necessarily the final word, just the collapse of the first version that made headlines as a "European first" back in July.

Maybe it will be pushed through like the Chat Control in July. To be continued...

u/officialexaking — 6 days ago
▲ 313 r/ProtonPublic+1 crossposts

Proton VPN which is built on trust got caught running secret price tests on users, then denied it. Their own code revealed the opposite.

Proton VPN was caught running price sensitivity tests on its own users and then provided a cheap and inaccurate excuse when asked about it. Users on Proton's subreddit (which has since been deleted by the moderators) noticed that they were quoted different prices for the same VPN Plus plan in the same country at the same time. Refreshing the page showed a price of $2.77 per month with 72% off, while opening a new incognito window showed a price of $3.23 per month with 68% off, despite nothing about the visitor having changed. I have conducted the test myself and can confirm this (and you can too, while it is still active). Proton's General Manager responded by saying that there was no adaptive pricing and that a recent sale simply hadn't "universally refreshed".

Windscribe then pulled the actual page source. Each visitor was assigned to a variant and the test was labelled in plain text inside an HTML meta tag. One session returned content "A" and the other returned content "B", with each pointing to a separate pricing URL. One of these was explicitly flagged as "test-300726-b". A screen recording showed the price changing in real time in clean incognito sessions. Expired sales don't do that. Neither do cached pages.

It is good to be precise about the terminology, because Proton was too. Adaptive pricing uses personal data to set a price tailored to an individual. Price sensitivity testing involves quoting different people different prices for the same product in order to establish the point at which sales begin to drop off. The GM denied the latter. Nobody had accused Proton of doing this.

Most major companies run A/B price tests, so it's a completely ordinary practice. However, Proton's entire business is built on trust, transparency and privacy, not just as a feature but as a promise. If you refer to your own labelled test code as a "glitch", it suggests that you are not transparent. For a brand built on trust and transparency, it is the most difficult thing to apologise for.

You can also read the original post from Windscribe here with their PoC: https://xcancel.com/Windscribe/status/2085859988090581461

u/Big-Lime4368 — 13 days ago
▲ 412 r/xprivo

Revolut banned GrapheneOS and calls it a "security" decision. Revoluts own app runs on Android 9 with no patches since 2018. (+ Temporary workaround if you have problems using Revolut on your GrapheneOS)

GrapheneOS has publicly called out Revolut for banning its use, disputing the bank's stated reasoning entirely. Revolut claims the ban is for security purposes, but according to GrapheneOS's developers, the real driver is Google Play licensing enforcement, not any actual security gap.

There is a major contradiction: Revolut's own app has reportedly run on Android 9 with no security patches since 2018, while bundling multiple closed-source third-party libraries with known privacy, security, and compatibility issues, some of which supposedly exist to enhance security but actually introduce vulnerabilities instead. GrapheneOS argues it exceeds the security of every device Revolut currently permits, and that the bank has instructed customer support to make inaccurate claims about GrapheneOS's security and compatibility specifically to justify the ban.

GrapheneOS also points out that Revolut has had access to its hardware attestation documentation for years, a tool that could actually verify device integrity if security were the genuine concern, yet the bank has never used it. Instead, GrapheneOS says Revolut specifically detects and blocks it by checking for GrapheneOS's build values and by permitting an unlocked "orange" verified boot state while banning the more secure "yellow" locked state, the opposite of what an actual security-based policy would do. Notably, other banks have moved the other direction, explicitly permitting GrapheneOS alongside stock Android rather than excluding it.

For users still affected, GrapheneOS's team has offered a temporary workaround: log into a throwaway Google account so basic integrity checks pass, then install Revolut through the sandboxed Play Store so the installer check clears. They've stated a more permanent fix for the installer-check issue is coming, though the underlying policy conflict with Revolut remains unresolved.

u/officialexaking — 15 days ago
▲ 162 r/xprivo

Apple is fighting the UK government in court over a secret order demanding a backdoor into encrypted iCloud backups

Apple is taking the UK government to court over a secret order demanding access to encrypted iCloud backups for UK users. The original version of this order tried to reach further, seeking access to encrypted iCloud data for users worldwide, not just in Britain. That drew objections from Washington, and the UK withdrew it, only for the Home Office to issue a narrower version applying specifically to UK users. Apple filed its legal challenge against that revised order at the Investigatory Powers Tribunal last month.

Rather than build the backdoor the order demanded, Apple pulled Advanced Data Protection entirely from the UK back in February 2025. That feature is what end-to-end encrypts iCloud backups, photos, and notes, meaning Apple itself normally can't access the data even if compelled to. Without it, Apple retains the ability to unlock that data and can be required to hand it over upon a valid legal request.

That makes UK users currently the only Apple customers anywhere in the world who cannot turn Advanced Data Protection on. Their photos and backups sit on servers Apple itself can access, a security posture no other Apple customer base is subject to. Apple says, that building a backdoor for one government would inevitably weaken security for everyone, since there's no version of broken encryption that only the "right" people can exploit.

u/officialexaking — 17 days ago
▲ 174 r/xprivo+1 crossposts

According to figures from Germany's federal police (BKA), 52% of reports in the style of Chat Control in 2025 were legally irrelevant. Meanwhile, 113,000 private photos and chats were leaked. This is the reality of mass scanning people's private messages:

New data from Germany's federal police (BKA) shows just how unreliable automated scanning reports from US platforms have become, and it directly undercuts the justification behind Chat Control. In 2025, 52 percent of suspicious activity reports were legally irrelevant from the start, meaning more than half never should have been flagged at all. The consequence: 113,000 photos, videos, and chats were leaked without legal basis, a 14 percent increase and the highest number ever recorded.

So let's look at the numbers and who actually got targeted by the reports: In cases classified as "child p*rnography", 40 percent of investigations were directed at children themselves, aged 10 to 14, with US platform reports affecting over 8,000 children in Germany last year alone. The BKA explains this happens because children often photograph themselves or forward images without understanding the consequences. For content classified as involving minors more broadly, 53 percent of investigations targeted minors directly, criminalizing more than 12,000 teenagers, largely tied to sexting as part of normal adolescent exploration of sexual identity that increasingly happens online. Worth noting too: police also pursue purely fictional content, including hentai and AI-generated images, under the same classification.

Meanwhile, the actual clearance rate for distributing illegal content online already sits at an extremely high 87.1 percent, achieved without mass scanning. Case history shows that data retention schemes like this don't meaningfully improve that rate. What actually catches abusers and rescues children is undercover investigation within offender networks, not indiscriminate scanning of unencrypted US platforms that mostly ends up sweeping up teenagers and leaking their private images to reviewers who were never supposed to need to look at them in the first place.

The conclusion? Mass scanning doesn't protect children but criminalizes them at scale. Over half of all reports are false alarms, tens of thousands of private files get exposed unlawfully, and the system built to catch predators is instead built almost entirely around the children it claims to protect.

Source: Patrick Breyer (German MEP)

u/officialexaking — 19 days ago
▲ 36 r/xprivo

Today, Doctolib enrolled 50 million French patients in an AI research project by default. You have to opt out yourself. You can still do this, but the option is buried in the settings. Here's how:

Starting today, 1st of August 2026, Doctolib is including the health data of all 50 million French users, prescriptions, consultation notes, and entries in the app's "Santé" section, in a three-year AI research project run with Inria, Inserm, and Université Paris Cité. Users were notified by a single email sent 8th of July , giving most people barely three weeks to notice, read, and act before enrollment became automatic today.
The core problem is the opt-out model itself. Rather than asking users to actively agree, Doctolib enrolled everyone by default and left objection as the only escape hatch, a decision the Ligue des droits de l'homme publicly criticized it arguing it wrongly presumes every patient saw, read, and understood a single email about their medical data. You can still object at any point (see bwlow) while the research is ongoing, but once the project concludes, data already processed cannot be deleted retroactively.

Doctolib is using pseudonymized data, not even anonymized data. Pseudonymization still falls under GDPR protections and carries a residual risk of re-identification, unlike true anonymization, which removes that risk structurally. Doctolib's CEO has framed the project as serving the general interest, focused on earlier disease detection and better care pathways for chronic patients, with results to be published publicly, but the timeline and opt-out design are exactly what's drawing scrutiny regardless of the stated intent.

If you want to opt out, the exclusion form is available directly through Doctolib's privacy settings: https://www.doctolib.fr/privacy-settings?open=research\_exclusion\_form

Source: https://www.lefigaro.fr/societes/ordonnances-notes-de-consultation-doctolib-va-utiliser-les-donnees-de-50-millions-de-patients-francais-pour-un-projet-d-ia-20260721

u/officialexaking — 20 days ago
▲ 136 r/xprivo

Windows tracks you with an ID you never agreed to and can't turn off. A federal court filing just proved how far it reaches.

Windows is spying on you, by design. Microsoft assigns every Windows installation a Global Device Identifier, or GDID, a persistent, server-generated number stored in your registry that uniquely identifies that specific install. It's created the moment you set up Windows or sign into a Microsoft account, survives system updates, and stays consistent even after most changes to your machine.

A recently unsealed federal court filing showed exactly how far this reaches. The FBI tracked an alleged member of the Scattered Spider hacking group, tied to an $8 million crypto ransom demand, by pulling months of IP activity linked to his device's GDID across multiple countries, then cross-referencing it against his personal accounts. He was routing through VPNs and proxy servers the entire time. It didn't matter. The VPN hid his IP address at the network layer, but the operating system underneath was still reporting his device's identity back to Microsoft regardless.

VPNs don't help here, because GDID operates independently of your network traffic. Local accounts don't fix it either, since a GDID gets generated the moment Windows is installed, with or without a Microsoft account signed in. You can trim diagnostic data, turn off personalized recommendations, and disable activity history, and that will reduce what extra information rides alongside the identifier going forward, but none of it removes the ID itself or erases what Microsoft already has on file. Even reinstalling Windows just generates a new GDID, while everything logged against the old one stays on Microsoft's servers permanently

If you want an operating system that doesn't track you by design, you should finally switch to an open-source alternative like Linux which removes this entire tracking layer, because there is no equivalent hidden identifier baked into the system.

u/officialexaking — 22 days ago
▲ 486 r/xprivo

A GrapheneOS user wiped his phone at the border using a legal duress passcode - a privacy feature built to protect you under coercion. The DOJ is now prosecuting him for destroying evidence.

Federal prosecutors are charging Atlanta resident Samuel Tunick with destroying evidence after his phone wiped itself when he gave border agents a passcode, believed to be the first known US case of its kind. The phone was running GrapheneOS, a privacy-focused Android operating system that lets users configure a duress PIN, a code that looks like a normal unlock passcode but instead it will instantly and irreversibly wipe the device.

The incident happened in January 2025 at Atlanta's Hartsfield-Jackson airport, when Tunick was returning from the Dominican Republic. Agents demanded access to his phone, reportedly telling him they didn't need a warrant since he hadn't yet officially entered the US. When the code was entered, the screen went blank, flashed, and the phone restarted, agents seized the device anyway, then told him he was free to go.

Tunick has pleaded not guilty, and prosecutors are relying on a statute originally meant for physical evidence destruction. Legal experts say that this has never before been applied to a manufacturer-built security feature. His attorneys argue the seizure itself was unlawful and are seeking to have the evidence thrown out entirely. A ruling on that motion isn't expected until at least the end of October.

The case sits at an uncomfortable intersection: duress PINs exist specifically to protect people forced to unlock devices under coercion, which is arguably exactly the scenario a warrantless border search represents.

Full Source: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/

u/officialexaking — 25 days ago
▲ 58 r/xprivo

Facebook is following Google's lead at the exact same time. "Facebook Verified" wants a biometric face scan of you, dressed up as a free trust badge.

The process works by having you record a short video selfie, which Meta compares against your existing profile photos using facial recognition and liveness detection to confirm it's genuinely you and not a static image or deepfake. Once verified, the badge shows up across Marketplace, Dating, Groups, and your profile, with plans to expand it into News Feed posts later.

Meta previously deleted a large facial recognition database and paid out a $650 million settlement over biometric privacy violations tied to earlier face-scanning features. Facebook Verified effectively reintroduces that same technology, just repackaged as a free trust signal rather than a photo-tagging tool.

The pattern across both Google and Meta is the same: biometric collection presented as a convenience or safety feature, rolled out in phases, with the actual scope of future use left vague. As more platforms adopt face-based verification for logins, age checks, and "authenticity" badges, each one becomes another entity holding a copy of your face, and none of them have clearly defined where that data stops being used.

Source: https://about.fb.com/news/2026/07/introducing-facebook-verified/

u/officialexaking — 27 days ago
▲ 116 r/xprivo

Google wants your face, again. This time it's dressed up as a login convenience feature, with an opt-in to feed your biometrics into their AI. Don't be fooled by the selfie sign-in. It's time to degoogle

Google just launched selfie video sign-in, letting you log back into your account by recording a short video of your face performing guided head movements. It's being framed by Google as a helpful account recovery option, useful if you're locked out and don't have access to your usual phone or device. Don't let that framing distract from what's actually happening in the setup flow.

Because it's also important to read the fine print: Google's own support page confirms there's an optional toggle labeled 'Improve Google services', which lets Google use your selfie video and related data to develop and improve facial recognition, age estimation, and other verification methods based on your physical features or movement. Consented biometrics, feeding the models that check biometrics.

The exact wording: "When you submit a selfie video, you have the option to allow Google to use your video and related data to help ongoing efforts to develop and improve facial recognition, age estimation, and other verification methods that may use your physical features or movement." source: https://support.google.com/accounts/answer/16675622

What a coincidence of that timing. That has nothing to do with a login feature anymore but obviously a consented (or behind your back) biometric data collection feeding directly into the same age-verification and facial recognition systems now being mandated by governments worldwide, from Australia's social media ban to France's under-15 restrictions to the UK's age assurance rules.

Back in 2024, Google paid parents $50 per child through a subsidiary to collect facial video and eye/skin tone data specifically to train age-verification technology.

Google says the video is encrypted at rest, stored only with consent, and deletable at any time, and that it's used strictly for sign-in "unless you opt to share it for additional purposes".

Google hasn't clarified where the boundaries of "improve verification methods" actually end. As age-verification mandates keep expanding across more countries, the company building the biometric layer underneath all of them stands to benefit enormously from every face it collects along the way, regardless of how convenient the sign-in box makes it feel.

source: https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/?utm_source=tw&utm_medium=social&utm_campaign=og

u/officialexaking — 28 days ago
▲ 238 r/FOSSbertarian+2 crossposts

BREAKING: France just adopted the first social media ban for under-15s in Europe. Everyone in France will soon need to use Selfies, ID cards, or FranceConnect which will decide who gets to log in. (Or use a VPN. Easy as that)

France's Parliament has definitively adopted a law banning social media for anyone under 15, a measure without precedent in Europe, set to take effect at the start of the next school year. Creation of new accounts by under-15s becomes illegal starting September 1, 2026, while existing accounts belonging to minors under 15 must be closed by January 1, 2027, following a four-month grace period.

Because platforms need a way to verify age, not just for minors but functionally for everyone, users will need to confirm they meet the age requirement through one of three methods:
- Inserting a national identity card (NFC, most modern smartphones already support this)
- Logging in through FranceConnect, the French government's digital identity system
- Facial recognition via a selfie

The law does carve out notable exceptions in how it applies to specific platforms. YouTube video viewing itself stays accessible to minors, but the comment section does not. WhatsApp's core messaging function remains available, but its channels feature, which functions more like a social broadcast tool, does not.

Worth remembering: Australia was the first country to try this, banning social media for under-16s in December 2025. Within weeks, platforms reported blocking nearly 5 million accounts, yet Snapchat itself admitted the system has a 2-3 year margin of error and that teens were openly bragging online about bypassing the checks entirely. There's always a workaround, and no age-verification system so far has actually closed that gap.

For adults who simply don't want to hand over an ID card, FranceConnect login, or a facial scan just to open an app, a VPN is the straightforward way to avoid complying with this system altogether. Options like ProtonVPN, Mullvad, or NymVPN mask your location so the verification prompt tied to French IP addresses never triggers in the first place, no ID, no selfie, no FranceConnect required.

u/amogusdevilman — 27 days ago
▲ 42 r/xprivo

Email aliases are a great way to hide your identity online and to know exactly which company leaked/sold your email. If you use Apple's Hide My Email, this summer's domain change makes your aliases blockable! Why everyone should use email aliases + better open-source alternatives to switch to now:

If you use Apple's Hide My Email, there's a change coming this summer that quietly weakens it, and it's a good moment for everyone, not just iCloud users, to rethink how they protect their email. Apple confirmed it will unify the domains used by Sign in with Apple and iCloud+ Hide My Email under a single new domain, private.icloud.com, sometime later this summer, with no exact date announced yet. Currently, Hide My Email aliases blend in with regular icloud.com addresses, making them indistinguishable from normal iCloud mail and effectively impossible for websites to block selectively. Once the new aliases move to their own dedicated subdomain, any website or anti-abuse system can block every Hide My Email address in one move, without touching real iCloud users at all. Existing aliases you've already created will keep working exactly as before, only newly generated ones after the migration will carry the new, blockable domain

If you do not already use a email alias service and use the same real email address everywhere, there's no way to know which company leaked or sold your data when spam eventually arrives. Aliases solve that: a unique email address per signup means that if spam ever hits one specific alias, you instantly know which service is responsible, and you can delete just that one alias without touching anything else.

There's also a name-leak problem hiding inside most people's real inboxes. Addresses like max.mustermann123@email.com openly hand your real name to every company and every attacker who ever gets that address. That makes phishing dramatically more convincing, since an attacker can write "Max Mustermann, your account is about to expire due to inactivity, please log in to keep it active" using nothing more than the name baked into your own email address. A randomly generated alias contains no name and no pattern an attacker could exploit that way.

Given that Apple's own aliases are becoming easier to detect and block, two open-source-friendly alternatives stand out:
AliasVault: open-source, end-to-end encrypted, generates a random identity, alias email, and password together for every website, and can be self-hosted for full control over your data
Proton Mail: even the free plan includes Hide-my-email, letting you generate randomly created aliases directly from the app, each with no name or identifying pattern attached, and none of Apple's domain-blocking exposure

Yes, using email aliases requires an extra click at first, which can seem annoying. However, this quickly becomes second nature, and you'll wonder why you ever used your real email address everywhere.

u/officialexaking — 1 month ago
▲ 83 r/xprivo

YouTube might attach your name, handle and profile picture to any links you copy in the app and send to someone by default. The setting to turn it off is buried in the settings on purpose. Instagram & Tiktok might do the same. A really useful tool before sharing links is to use a link cleaner:

If you are using the YouTube app: By default, YouTube attaches your name, username and channel picture to every link you share, so anyone who receives the link can see who sent it, whether you intended that or not. As mentioned, this setting exists in the YouTube app, but it's an opt-out rather than an opt-in setting, and it's not easy to find as it's buried in settings that weren't designed to be easily accessible. Some users report having this setting, while others do not which means your profile might not be attached to the shared links yet.

To check whether YouTube has been secretly doxing you and to turn this feature off, go to Settings → Account → Sharing and disable "Attach account info to shared links", or alternatively check Settings → Privacy for "Channel visibility for shared links" and set that to disabled.

Both Instagram and TikTok might also attach identifying account information to shared links unless you find the toggle yourself. Again, this option is available to some users and not to others. Beyond the identity exposure, shared links from all three platforms also typically carry tracking parameters that let the platform and third parties follow engagement back to the specific link and, by extension, the person who shared it.

If you want to get rid of tracking parameters and identifying data before sharing any type of links, linkcleaner.app can do this for you right in your browser. It's open source, so the code is public, and it never sends your link to an external server for processing. This means the cleaning happens in your browser, so you don't have to worry about other parties getting access to what you're sharing.
So, whenever you want to share a link with someone, just open the link cleaner, drop your link into it, and then share your link.

u/officialexaking — 1 month ago
▲ 327 r/Buy_European+1 crossposts

"If you want a picture of the future, imagine a boot stamping on a human face, forever." Orwell wrote that in 1984. The EU just made it a policy proposal. Von der Leyen just confirmed it: every EU citizen will need a government ID app to access social media after the summer break.

Yesterday Ursula von der Leyen has 'confirmed' that every EU citizen will need to use an EU identity verification app before accessing or posting on social media, framed publicly as a child safety measure. Strip away the framing, though, and the mechanism is unavoidable: you cannot verify a minor's age without every adult verifying their identity too, since there's no way to selectively check ages without checking everyone.

Von der Leyen's own words undercut the pitch. She called the app "privacy preserving" yet also admitted it "won't be foolproof" a contradiction that answers itself: age verification without identity verification is not a technical option that exists. She framed this as "putting power back into the hands of parents," but the actual effect is the opposite, stripping authority from parents who already manage their kids' access through existing parental controls, and replacing that judgment with a single state-mandated checkpoint applied uniformly to everyone, including adults with no children at all.

The analogies used to sell this don't hold up either:
-> Car keys and driving licences: governments don't decide when a teen gets car keys, parents do, and licensed drivers aren't forced to re-authenticate every time they drive
-> Alcohol purchase age limits: nobody scans ID at the mall entrance because a few people might buy alcohol at a restaurant inside it
-> Seatbelts: a seatbelt protects someone while they stay in the car; this policy removes people from the car entirely rather than making the ride safer

This rollout simply follows the same sequence as Chat Control. First it was private messages, now it's public posting. In both cases, the public safety framing arrives first, and the infrastructure for identity-linked surveillance arrives attached to it. Von der Leyen has stated the EU's own age verification app is not foolproof, which raises the obvious next question: if voluntary verification fails, what fills the gap. Historically, gaps like that get closed with restrictions on the workaround itself, which in this case would mean VPN restrictions for anyone who's already verified their identity.

Orwell's warning in 1984 was that surveillance sold as protection eventually becomes indistinguishable from control. A mandatory ID checkpoint to read, share, or post anything online, layered on top of a law that already scans private messages, is not a hypothetical dystopia anymore. It's a policy proposal scheduled for after the summer break.

u/officialexaking — 1 month ago
▲ 60 r/FOSSbertarian+1 crossposts

Silent opt-in, no notification, no undo. Your face was public property on Instagram for a week. Meta's new AI tool is finally being walked back after letting strangers generate images using your photos.

Meta launched Muse Image about a week ago, an AI image generator built into Instagram. If your Instagram account was public, Meta had already opted your photos into this feature. Anyone could tag your profile in a prompt and generate AI images using your face, your likeness, and anyone else who appeared in your photos, including children who never consented to anything. You were not asked beforehand, and per Meta's own policy, you were not told afterward either.
Journalists testing the feature generated images of people they had never followed or interacted with, complete strangers, using nothing more than a public profile to pull from. See here: https://gizmodo.com/if-you-have-a-public-instagram-account-you-might-be-surprised-what-ai-users-can-now-do-with-your-face-2000782694
One reporter successfully generated images based on Mark Zuckerberg's own account and a real-world friend's Instagram without that person's knowledge. Meta's response when asked was that Muse Image has "built-in protections" against policy-violating content, which is the same reassurance every platform gives right before its safeguards fail publicly, as already happened with Grok on X during the AI-generated child image incidents a few months ago.

It's always the same nasty trick: data sharing defaulted to on, the opt-out buried several menus deep, and the public only learned about it through backlash afterwards, so the same way Google, X, and Meta itself have handled AI feature rollouts before this one.

Now, a week later, Meta is reversing the decision to allow AI generation using any public Instagram profile by default. Silent opt-in, public backlash, then reversal, is becoming the standard playbook for how these companies test the limits of what users will tolerate before scaling something back.

Remember that there are privacy-respecting alternatives for everything. There are also alternatives for Instagram like Pixelfed that take a fundamentally different approach: your data is never collected for AI training or generation to begin with, so there is no toggle to remember, no feature rollout to react to, and no silent default to get caught by. Services built on this principle, encrypted photo storage that never scans or trains on your images, messaging platforms that do not read your chats for any purpose, and social alternatives that do not treat your public content as free raw material, remove the risk structurally rather than asking you to manage it reactively every time a company decides to launch something new.

u/amogusdevilman — 1 month ago
▲ 307 r/Buy_European+1 crossposts

Telegram CEO Pavel Durov says Telegram won't scan your messages "no matter what banana-republic tricks the EU" tries. But Telegram isn't even end-to-end encrypted by default. Here are the most powerful, private full open source alternatives:

Telegram founder Pavel Durov has publicly rejected Chat Control, stating Telegram "won't scan your private messages, no matter what banana-republic tricks the EU" pulls. That stance might be worth applauding, but it only tells half the story of what Telegram actually protects.
Standard one-to-one chats and group chats on Telegram are not end-to-end encrypted by default. These are cloud chats, which means Telegram stores both your messages and the encryption keys on its own servers. Only Telegram's "Secret Chats" feature offers true end-to-end encryption, and that has to be manually enabled per conversation, it is not the default experience. So while Durov may refuse to hand over data under Chat Control pressure, the architecture means Telegram technically holds the keys to unlock your messages if compelled or compromised, a very different guarantee than apps where the company literally cannot read your content even if it wanted to.
We also recently published findings from a research paper that reveals a problem even deeper than message encryption. It affects every Telegram user, regardless of whether they use Secret Chats. (see post here: https://www.reddit.com/r/xprivo/s/zfVIWKVRPy)

If you want communication that resists surveillance by design rather than by promise, these alternatives close that gap:
- Session (Switzerland): fully open-source, hides metadata and IP address through onion routing, no phone number required
- Signal: end-to-end encrypted by default for all chats and calls, widely audited
- Matrix (Element): open-source, decentralized, end-to-end encrypted by default
- Briar: peer-to-peer messenger that works even without internet infrastructure, no central server to compromise
- Delta Chat: open-source, feels like Telegram or WhatsApp but runs entirely on email infrastructure, so there's no proprietary server to hand data over
- SimpleX Chat: no user identifiers at all, not even a phone number or username, minimal metadata by design
- Jami: peer-to-peer focused on encrypted audio, video, and text, no central servers involved

The common thread across all of these is that privacy isn't a policy promise from a founder, it's a structural property of how the app is built. That distinction is exactly what matters most heading into a regulatory environment where governments keep pressuring platforms to comply.

u/officialexaking — 1 month ago
▲ 993 r/Buy_European+2 crossposts

Today, Chat Control 1.0 passed. They put it on the agenda again, and again, and again, until they got the vote they wanted. This is not how democracy is supposed to work. Mass scanning of private chats with images & videos of 450 million EU citizens is now legal until 2028.

Despite being rejected twice before by the EU Parliament, Chat Control 1.0 has passed today, with 314 votes against it and 276 in favour (crazy!). Mass scanning of private chats is now legally permitted until 2028. The EU simply kept bringing it back through urgent procedure until the outcome finally matched what it wanted from the start, and that is not how democratic process is meant to function.

Here is what this actually means going forward:
- Every photo, message, and file you send through major platforms can now be scanned automatically by Big Tech
Mass surveillance of 450 million EU citizens is now permitted without individual warrants
- Every citizen is placed under general suspicion by default, rather than surveillance being targeted at actual suspects
- Standard messengers like WhatsApp, Facebook Messenger and email providers like Gmail and Outlook fall under this scanning obligation

If you want to keep your communications private going forward, here are the tools that were built specifically to resist this:
- Encrypted messengers: Threema, Matrix and Element.io, or Signal
- Encrypted email: Posteo or Tuta Mail, both of which refuse to support this kind of mass scanning
- Operating systems: Linux instead of Windows
- Mobile operating systems: GraphenOS or LineageOS instead of stock Android

... to be continued

u/SusejLegend — 1 month ago
▲ 630 r/Slovakia+2 crossposts

Chat Control just came back from the 'dead'. The urgent procedure passed today. Thursday's vote decides everything, and the rules were rigged so that not voting on Thursday counts as supporting mass surveillance:

The urgent procedure to revive Chat Control 1.0 passed today, clearing the way for the decisive vote this Thursday. This matters because of how the voting math is now stacked. In March, Parliament rejected extending this same mass scanning framework by 311 to 228, a clear democratic majority. Under the current procedural stage, however, blocking it again requires an absolute majority of Parliament's full membership, 361 out of 720 seats, not just a majority of those present and voting. Any MEP who does not show up or does not cast a vote is functionally counted as supporting the law, because their absence does not count toward the 361 needed to reject it. This vote is scheduled for Thursday, the final sitting day before summer recess, when attendance is historically at its lowest all year. That timing is not a coincidence.
If Chat Control 1.0 is reinstated Thursday, companies get the legal green light to resume scanning private messages, photos, and videos, including content in encrypted communications and email, before it is sent. This is the same voluntary scanning framework Parliament already rejected, being pushed back through a procedural route rather than real consensus.

⚠️ Breaking encryption for everyone and allowing mass scanning is not a child safety measure, it is a surveillance infrastructure that puts journalists, activists, abuse survivors, and ordinary citizens at greater risk, not less. ⚠️

You can check exactly how your MEP voted on the urgency procedure today at mepwatch.eu (https://mepwatch.eu/10/vote.html?v=195338 ), which tracks the vote in full detail. If your representative supported the urgency procedure, or if they were absent, now is the moment to contact them directly. fightchatcontrol.eu has direct contact tools for reaching MEPs before Thursday. Given that abstention functions as a yes vote under these specific procedural rules, getting your MEP to show up and actively vote no is the only way this stays blocked.

u/officialexaking — 1 month ago