r/PrivacyTechTalk

▲ 18 r/PrivacyTechTalk+1 crossposts

For prior iPhone users who now use Graphene OS, how is it?

I currently have an iPhone 13 and I’m looking to upgrade soon, but with all the ai and security news as of late, I’m moving away from Apple and Google and I self host. I’m thinking of getting a Google Pixel to run Graphene OS, but I’ve never had a non-iPhone before.

For those who were previous iPhone users and now run Graphene OS on an Android phone, how was the transition? What do you wish you knew before transitioning?

reddit.com
u/penguinpeep808 — 4 days ago

What privacy do I have in this situation? Work managed chrome profile?

I logged into chrome on my personal device (no installed work software) with my work managed chrome profile.

This was done on my personal device (in incognito mode) that has only ever been connected to my home network. I also used my own personal VPN during the session.

How likely is it that my work or the IT team knows/has been notified or have records of my history/activity? How much detail can they see?

PLEASE do not give me advice on how I could have avoided this. I'm aware incognito mode is not secure/private. I have done so much research on this but everyone else's questions were when they used work owned devices and/or were on their work WiFi (both of which I was not).

reddit.com
u/Ok_Cupcake_4208 — 3 days ago

How can I improve my cybersecurity and avoid all the ai bullshit?

Recently I've really been thinking about all the data that I'm allowing just about any app to have, and I want to stop that. I've started by deleting certain social media apps and I've been slowly but surely getting rid of my social media addiction. What I'm wondering is, how can I make my phone even more secure and private and not just delete apps? I've heard about using a PDA device or installing grapheneos but I don't know how to do that. Any tips for a starter like me?

reddit.com
u/andreiswatching — 5 days ago

Best privacy build for Macbook and Iphone?

so i have been trying to make my devices as secure and private as possible, but im not really sure if im doing everything i can possible do, for My laptop (mac) i turned on filevault, i also havent signed into an apple account nor have planned to even use one at all. with my iphone device, i had to create an apple account to download some software i needed, but i have lockdown mode and advancded data proctection on. for email providers, i use tuta and its been working fine for me. for VPN i use mullvad. I also have heard of "alphanumeric passwords" if anyone knows what that stuff truly means i would really apreciate it, im open to any reccomendations or anything like that so i can make my set up better than it is currently is if possible.

reddit.com
u/Equivalent-Cod4096 — 5 days ago

what's the first privacy setting you change on a new phone?

What’s one privacy setting you immediately change on every new phone?

I’ve been getting more interested in digital privacy lately and realised I probably accept way too many default settings without thinking about them 😭

What’s the first thing you always turn off/change?

Location tracking? App permissions? Ad tracking? Something else?

reddit.com
u/cloakedPacket — 7 days ago
▲ 9 r/PrivacyTechTalk+4 crossposts

[App]🛡️ Do you really know what the apps on your phone are doing? Meet Privacy Inspector!

Many apps we use daily request access to your camera, microphone, or location—and often bundle background analytics and tracking SDKs. But how many of us know exactly what is happening behind the scenes?

Privacy Inspector is an Android app designed to give you complete visibility and control over your device privacy and security—100% locally on your smartphone, with zero data ever sent to external servers.

🚀 Key Highlights & Benefits

  • 📊 Clear Privacy Score (0–100): Instantly evaluate the safety of installed apps based on requested high-privilege permissions, background behavior, and bundled trackers.
  • 🕵️ Ad & Analytics Tracker Detection: Reveal embedded tracking SDKs, telemetry frameworks, and ad networks hidden inside your apps.
  • 🔄 Privacy Changes Timeline: Get notified when an update or a newly installed app silently introduces new sensitive permissions.
  • 🧱 On-Device Firewall & DNS Filter (PRO): Block tracking domains in real time using a zero-cloud local VPN service—no traffic is ever routed through external servers.
  • 🧹 Unused App Cleaner: Easily identify and clean up apps you haven't opened in months that still hold background permissions.

🔒 Zero-Cloud Privacy Guarantee

Privacy Inspector operates strictly on-device. No user account is required, no analytics are collected, and no personal data ever leaves your phone.

📲 Try it today!

Take back control of your Android privacy. Download Privacy Inspector on the Google Play Store and scan your device in seconds!

Privacy #Android #CyberSecurity #MobileSecurity #PrivacyInspector #TechTools

u/djfabrix — 8 days ago
▲ 4 r/PrivacyTechTalk+3 crossposts

7 months, barely any users, so i made my privacy-first clipboard manager's source code public

built a privacy focused yet productive clipboard manager few months back. zero-knowledge encryption, so even i can't see what people copy/paste. genuinely proud of it, thought it solved a real problem.

7 months later, less than 25 users on the chrome store. closed source the whole time.

took me a while to admit the actual issue. you can't ask people to trust a security tool from some random solo dev they've never heard of, with code they can't even look at. "trust me" isn't really a pitch when the whole product is about not having to trust anyone.

so, last week i made the extension's source code public. not open source technically, it's under Polyform Noncommercial 1.0.0, so nobody can fork it and resell it as their own, but anyone can read the code, verify the encryption does what it says, build it themselves if they want.

no idea if this fixes anything tbh. but felt like the honest move after building something people had no real reason to trust yet.

repo's here if anyone wants to poke around: https://github.com/encryptedclipboard/chrome-extension

not trying to sell anything, just wanted to put this out there since this sub gets the "built a thing, nobody came" feeling better than most places.

u/nhrtrix — 8 days ago

is there really a best online privacy protection option for non-tech users?

i’m trying to figure out what actually makes sense for people who aren’t very technical.

you can get a vpn, anti-phishing protection, malware protection, identity monitoring, and a bunch of other tools separately, but that also means more apps, settings, accounts, and stuff to keep track of.

for someone who just wants decent privacy and security without constantly managing everything, does bundling these protections actually make sense?

is there really a best online privacy protection option for non-tech users, or are separate tools still the better way to go?

reddit.com
u/AleskerovaAflin_70 — 10 days ago

a PGP based messaging platform!

Hello World! I've been working on creating an encrypted messaging platform for the past year now and i would love to know your thoughts or opinions on it!

we have currently launched for Open-Beta testing!
the website is https://simplepgp.org/

It's entirely based around Simplifying the usage of PGP encryption for the average user as well as allowing for WebRTC calls, building communities and even hosting your own communities off of your own hardware / VPS using our Work-In-Progress FOSS 'Nodes' allowing for full customization and automation for uses like moderation, scripting and even building marketplaces / shops! Think of nodes as new-age Internet Relay Chats with a little bit better default encryption!

We also have emoticons that you can collect and trade with your friends which you can also use in chats, these animated icons are artist commissioned and they each have their own real-world value based on the reception of the community. :)

What's next for us?

  • Android App Version (Still a little bit iffy on developing for Apple at the moment due to current privacy concerns)
  • Constant development towards the Nodes FOSS clients (Should be able to release a working build by the end of August)
  • Performance, stability, and security improvements

Feel free to check it out, give me any advice or recommendations for further features / updates!
Simple, Free, Welcome to SimplePGP!

u/SimplePGP — 12 days ago
▲ 15 r/PrivacyTechTalk+4 crossposts

Simple Chrome extension for offline mode + backup to Telegram chats

Built a little tool that keeps your own local copy of your Telegram chats, so nothing ever really disappears. Channels can go down, messages can get deleted (even by the other person), and you'll still have everything saved on your side. Early and open source; curious what people think.

github.com
u/LordKittyPanther — 10 days ago

Tryme187

I'm just saying privacy policies.I understand you know, internet security and wanting to keep your business personal.However, I also understand it's probably not gonna happen.Because people are nosy, and they're crooked, and I really don't give a darn, what you find out about me or what i've done?An if it's true, then post it.If it's not true and it's made up, then you're the phony you know, you're the phony, not me. Cause i'm telling you, you're gonna find unfavorable things about me and again.If they're true, then it is what it is.An if it's not, and it's again made up through AI or some generated, you know, app, the new reason how the creator you're just a poser. Cause, I will say this about myself.I am authentic.

L

reddit.com
u/Texas_Primary187inf — 10 days ago

Has your phone ever made you feel like it was listening?

So recently I was talking to a friend about a pretty specific makeup product (Renee Nude Lake H20 Hydrating Glossy Liquid Lipstick) and I hadn’t searched for it or even typed the name anywhere.

A little while later, I started seeing ads for that exact product everywhere. Instagram, YouTube and even on random sites. I know there are plenty of explanations for this: maybe people around me were searching for the same thing or the algorithms were being ridiculously good at predicting what I wanted.

But when the timing is that specific, it still feels creepy. I just wanna know has this happened to you too? And if it has, do you wonder whether your phone was listening?

reddit.com
u/Straight-Site-8030 — 10 days ago
▲ 26 r/PrivacyTechTalk+3 crossposts

E2encrypt: Firefox extension for client side encryption with any transport

I made this alone (with my friend Claude) and am the only person who worked on it, treat it with the skepticism that it deserves:

What it is: a Firefox extension that encrypts in the extension and decrypts messages in place, on whatever transport you're already using. Discord, Gmail, a forum, Reddit. It has no idea what site it's on and doesn't need to — the ciphertext is just text, so you paste it wherever you'd paste anything.

No account, no server, no network requests of any kind from the extension.

You and the other person exchange public keys directly, once.

Why I built it: the EU's Chat Control regulation would require messaging platforms to scan private messages before they're encrypted — on your own device, whether or not you're suspected of anything. You can't have both client-side scanning and end-to-end encryption; if a message can be inspected before it's sent, it was never private. This is a small working example of the other model: there's no server to mandate scanning at and no hook in the client for one.

How it works, briefly:

  • Your identity is two keypairs (X25519 for key agreement, Ed25519 for signing), generated locally and never transmitted.
  • You and a contact swap public keys over any channel — DM, email, read aloud over the phone. Doesn't need to be secret.
  • Each message gets a fresh random key. The message is encrypted once with it; a copy of that key is sealed separately for each intended reader.
  • There's no "to:" field. The sealed copies are anonymous blobs — your client finds yours by trying. An observer can't tell who the recipients are or how many are real.
  • Every message is signed, so a group member can't forge one from someone else.

What it does NOT protect you from — please read this part:

  • No forward secrecy. One shared key per contact, derived once, never rotated. Anyone who extracts your private key can read every message you have ever exchanged with that contact, including ones captured years ago.
  • Your keys are protected only by your OS. They're non-extractable (extension code can't export them), but they sit unencrypted in a local SQLite file. Anything running as your user account can read them. There is no passphrase on the stored identity.
  • Decrypted text is rendered into the page. A hostile or compromised site can read it while it's on screen.
  • Metadata is fully visible. The platform still sees who you talk to, when, how often, and roughly how much.
  • Nobody has audited this. It uses WebCrypto primitives rather than hand-rolled crypto, which rules out a whole class of mistakes, but that is not the same as being reviewed.

If you need protection from a determined, well-resourced adversary, use Signal. This is for putting a floor under the conversations that currently have none, on platforms you don't control.

Links:

Source-available under PolyForm Noncommercial (not OSI open source — the license restricts commercial use, so I won't call it open source).

Feedback: I am looking for feedback on 2 things:

  1. The core idea, client side encryption agnostic about transport; how would you use it?
  2. The user experience, I am a technical person and user experience and privacy does not alwayes go hand-in hand. What could I do to improve the user experience?

Looking forward to hear from you!

u/DalekSall — 14 days ago

Most encrypted messaging app

Most encrypted messaging apps hand you a passphrase and call it secure. Share the passphrase, share the risk. One compromised device and the whole conversation is exposed.

I'm building VektorGrid, a cross-platform messaging app for Android and iOS, and the core decision I made early was to move away from shared passphrases entirely.

Instead, VektorGrid uses ECDH (Elliptic Curve Diffie-Hellman) key agreement. Every user gets a public/private key pair. When two people message each other, a shared secret is derived from their keys - without either party ever transmitting that secret. The encryption key never travels. It's computed independently on each device.

Each message stores an encrypted payload and an IV (initialization vector). No plaintext. No central key store.

The app also has full social infrastructure - profiles, posts, stories, group chats, follows - because I think privacy and community shouldn't be a tradeoff. That's the gap I'm trying to close.

Still pre-launch. Building in public and trying to get this in front of people who actually care about how their messages are secured, not just whether there's a lock icon on the app.

Curious: what's the one thing that would make you actually switch your primary messaging app to something new?

reddit.com
u/No-General-7317 — 13 days ago
▲ 1 r/PrivacyTechTalk+2 crossposts

Anyone else seeing more Windows digital signage setups lately?

Lately I’ve been noticing more companies using Windows digital signage for dashboards, announcements, meeting room displays, and internal communication screens.

At first it looks simple, just connect a screen and display content. But once there are multiple screens across different locations, managing everything consistently seems like a bigger task than expected.

Things like remote updates, kiosk mode, content scheduling, and keeping systems stable probably become really important at scale.

u/Unique_Inevitable_27 — 13 days ago