r/xprivo

Privacy, easy repairability, and software support until 2033: Europe's new deGoogled, eco-friendly phone with an open-source operating system. Fairphone 6+ with e/OS.
▲ 329 r/xprivo+1 crossposts

Privacy, easy repairability, and software support until 2033: Europe's new deGoogled, eco-friendly phone with an open-source operating system. Fairphone 6+ with e/OS.

The majority of smartphones have a lifespan of just a few years and rely heavily on Google's Android ecosystem, which compromises users' privacy.
It's getting time for a switch. The Fairphone 6+ (from the Dutch electronics manufacturer Fairphone) is designed to be opened so that you can take it apart and replace components with newer ones whenever you want, allowing you to keep it for as long as you like. Twelve components, including the battery, cameras, USB-C port and display, can be replaced with just a screwdriver. The phone also comes with a five-year warranty and will receive software updates until 2033.
In partnership with French developer Murena, the Gen 6+ runs /e/OS: a fully open-source, 'de-Googled' version of Android. It's built so that switching away from Google doesn't require you to become a power user. Murena's advanced privacy toggles and backup system are already integrated.

In terms of hardware, it has a Snapdragon 7s Gen 4 chip, 12 GB of RAM and a 120 Hz OLED display. And, as of this week, this combination of longevity and privacy is available outside of Europe for the first time, as Fairphone has launched the Gen 6+ directly in the US too!
Do you think it's a good, competitive phone in terms of privacy and durability, considering it's currently priced at around 699€ for a European phone manufacturer?

Source and more info: https://www.fairphone.com/de/the-fairphone-gen-6-plus-e-operating-system

▲ 70 r/xprivo

Think a VPN and Incognito mode protect you? Websites can still identify you really fast. Your GPU is snitching on you. Fingerprinting on the web:

You just cleared your cookies, opened a private window, and connected to a VPN. You think the previously visited website does not know you anymore and that you're anonymous. You aren't.
Without using your IP address or dropping a single cookie, websites can identify your device with high accuracy through browser fingerprinting.

What is Fingerprinting?
Every time you load a webpage, your browser hands over dozens of tiny technical details to render the site properly:
-Your screen resolution and color depth
-Installed system fonts and audio hardware
-Your exact graphics card model, driver version, and WebGL/WebGPU rendering quirks
Combined, this creates a mathematical "serial number" unique to your machine. Trackers use it to follow you across the web, even when you switch networks.

Brave recently shipped updated protections against invasive WebGL and WebGPU tracking by combining randomized noise ("farbling") with a single, uniform GPU profile across all its users. It’s good for everyday Chromium users that stops hardware tracking without breaking 3D maps or web games.

But Which Browser Is Actually the Best When It Comes To Stopping Fingerprinting? (I picked 4, so feel free to add yours in the comments)

1.** **Tor Browser & Mullvad Browser
Strategy: Strict Uniformity ("Hide in the crowd"
Instead of randomizing data, they force every single user to look 100% mathematically identical. They enforce strict letterboxing (gray borders that lock window sizes to fixed dimensions) and strip all hardware identifiers.
Pair Mullvad Browser with a trustworthy VPN (like Mullvad VPN itself) since, unlike Tor, it doesn't route traffic through the onion network by default.

  1. Brave
    Strategy**:** Hybrid Randomization ("Moving Target")
    Generates plausible randomized noise across APIs on each session and masks GPU strings. You still stand out as a "unique" user on any single visit, but trackers cannot link your visits across different sites. It gives high-end protection without breaking the modern web.

  2. LibreWolf
    Strategy: Loose Uniformity
    LibreWolf uses Firefox’s robust resistFingerprinting engine, but it disables letterboxing by default to give you normal, full-screen browsing. The problem? Your unique screen resolution and window dimensions are exposed, making your fingerprint mathematically unique. Tip for LibreWolf users: You can actually fix the "leaky default". You just have to open your librewolf.overrides.cfg file and change privacy.resistFingerprinting.letterboxing to true. This gives you Mullvad-level uniformity, but you will face a gray border around websites.

u/officialexaking — 4 days ago
▲ 148 r/xprivo

Good news: France's top court blocks ban on social media for children under 15, ruling it infringes on freedom of expression. The ID-card-or-selfie age verification law that would eventually affect every social media user is dead (for now)

The plan was that, starting in September 2026, anyone creating a new social media account would have to verify their age using an ID card or facial scan. That's only two weeks away! BUT:

France's top court struck down the under-15 social media ban on Friday (yesterday), the same law that would have required every user, not just minors, to prove their age through ID cards, FranceConnect, or facial recognition starting September 1.
The court ruled the measure unconstitutional on two separate grounds: it disproportionately infringed on freedom of expression and communication, and it failed to provide adequate legal safeguards to protect the right to privacy.

The ban would have applied indiscriminately to essentially any platform allowing users to connect and communicate, sweeping in far more than just Instagram or TikTok, and covering minors of any age or maturity level without distinction so also adults. The court also flagged that the law never specified the actual conditions under which every user, including adults, would have to prove their age, leaving the verification requirement itself constitutionally unmoored. On top of that, parents had no ability to lift the restriction for their own children even when they judged access to be appropriate, which the court treated as further evidence the law was disproportionate to its stated goal.

The effect of this: nothing changes this September for teenagers already on these platforms.

But be careful: President Macron has already directed the government to draft a new version addressing the court's concerns before his term ends, so this isn't necessarily the final word, just the collapse of the first version that made headlines as a "European first" back in July.

Maybe it will be pushed through like the Chat Control in July. To be continued...

u/officialexaking — 6 days ago
▲ 1.3k r/xprivo+2 crossposts

uBlock Origin is no longer supporting Facebook ad-blocking, and Edge is incompatible with uBlock Origin entirely. Here are three great browser alternatives and a privacy-focused one from Europe

Two separate pieces of news for ad-blocking just landed in the same week, and together they say a lot about where browser control is heading.

First, the developer of uBlock Origin announced that the team is no longer going to chase Facebook's constant filter-evasion tricks, describing Facebook as a "disgusting anti-user site". Facebook has repeatedly changed how it identifies and serves ads in order to defeat open-source blockers, monitoring projects like uBlock Origin and adjusting its code to bypass their filters. After years of this cat-and-mouse game, the small uBlock team decided that it was no longer worth the constant maintenance just for one platform.

Secondly, and more importantly: Microsoft Edge has started to disable Manifest V2 extensions by default in the Canary, Dev and Beta channels this month. The full rollout to consumers will be completed by the end of 2026, with enterprise devices following in early 2027. uBlock Origin has been installed over 13 million times on Edge, but there is no Manifest V3 version because MV3 removes the Web Request API that the full version depends on to work effectively. Chrome killed Manifest V2 entirely in mid-2025 and will have removed the last MV2 extensions from its store by 31 August this year. Edge held out for longer, but is now following the same route.

If you use uBlock Origin's full filtering power on Edge (or any other Chromium-based browser), the best option is to switch to a different browser, since all Chromium-based browsers are heading towards the same restriction eventually.

Firefox remains the safest option since Mozilla is committed to providing full Manifest V2 support, regardless of Chrome and Edge's actions. It also runs on Gecko, one of the few major rendering engines that is not controlled by Google. 

If you want a more modern interface alongside the same privacy protections, Zen Browser is a good European option: it's free and open source, and is built directly on Firefox's Gecko engine rather than Chromium. It also adds features like Workspaces and Split View without compromising the underlying privacy protections. 

Another Firefox-based alternative worth considering is Waterfox: it's open-source with no telemetry by default, and includes Oblivious DNS support to make it harder for your ISP to track which sites you visit.

All three keep uBlock Origin working exactly as it always has.

u/Delirium222 — 9 days ago
▲ 136 r/xprivo

The RAM shortage is already making PCs pricier. Now Microsoft adds a 10% Windows licensing hike on top of it. It's finally time to switch to better alternatives. Choose yours:

Microsoft is raising the price it charges PC manufacturers for Windows 11 OEM licenses. The hike took effect in July 2026 and lands between 7 and 10 percent. 

This only affects manufacturers building new PCs with Windows 11 preinstalled, not people who already own a Windows 11 machine or anyone buying a standalone retail license, which stays unchanged for Home and Pro. But manufacturers rarely absorb costs like this. Some portion of that increase typically gets passed straight through to retail prices, arriving at the worst possible moment, right as an ongoing RAM shortage is already pushing PC prices up.

This is a good moment to remember that none of this applies if you're not buying into the Windows ecosystem at all. Linux distributions carry no licensing fee, and several strong European-made options exist. So instead of using Windows save costs and increase data sovereignty:

Linux: Doesn't need any introduction I think. it's the OG.

openSUSE (Germany): backed by SUSE, mature, stable, and widely used in enterprise environments, with the Leap and Tumbleweed branches covering both stability-focused and rolling-release use cases

Linux Mint: It is the most beginner-friendly distribution for anyone coming straight from Windows, with a familiar desktop layout and minimal learning curve

Zorin OS: built specifically to feel like Windows or macOS out of the box, making it one of the smoothest transitions for former Windows users who don't want to relearn their workflow

u/Euhuntix — 8 days ago
▲ 54 r/xprivo

"If it was opt-in, nobody would opt in.". That's Twitch's own justification for training Amazon's AI on your streams by default.

"If it was opt-in, nobody would opt in". That's the actual reasoning Twitch gave for why AI training is on by default rather than something users have to actively choose. Here's what that default actually hands over, and how to shut it off.

Amazon can currently pull your streams, VODs, clips, stream chats, and any images or text on your channel unless you opt out. Per Twitch's own FAQ, this data may be used to train "a model developed by Amazon whose purpose is to generate or synthesize text, audio, images, or video", meaning your face, your voice, and your community's chat logs are all in scope by default.

To turn it off: go to your profile picture, then Settings, then Security and Privacy, scroll down, and toggle off "Training for Generative AI".

Two catches that you should be are of even after you opt out. First, it only protects your own channel, if you're chatting in someone else's stream, their setting controls whether your messages get used, not yours. Second, it only applies going forward. Nobody at Twitch can tell you what's already been collected and used to train models before you ever found the toggle.

u/Euhuntix — 7 days ago
▲ 313 r/xprivo+1 crossposts

Proton VPN which is built on trust got caught running secret price tests on users, then denied it. Their own code revealed the opposite.

Proton VPN was caught running price sensitivity tests on its own users and then provided a cheap and inaccurate excuse when asked about it. Users on Proton's subreddit (which has since been deleted by the moderators) noticed that they were quoted different prices for the same VPN Plus plan in the same country at the same time. Refreshing the page showed a price of $2.77 per month with 72% off, while opening a new incognito window showed a price of $3.23 per month with 68% off, despite nothing about the visitor having changed. I have conducted the test myself and can confirm this (and you can too, while it is still active). Proton's General Manager responded by saying that there was no adaptive pricing and that a recent sale simply hadn't "universally refreshed".

Windscribe then pulled the actual page source. Each visitor was assigned to a variant and the test was labelled in plain text inside an HTML meta tag. One session returned content "A" and the other returned content "B", with each pointing to a separate pricing URL. One of these was explicitly flagged as "test-300726-b". A screen recording showed the price changing in real time in clean incognito sessions. Expired sales don't do that. Neither do cached pages.

It is good to be precise about the terminology, because Proton was too. Adaptive pricing uses personal data to set a price tailored to an individual. Price sensitivity testing involves quoting different people different prices for the same product in order to establish the point at which sales begin to drop off. The GM denied the latter. Nobody had accused Proton of doing this.

Most major companies run A/B price tests, so it's a completely ordinary practice. However, Proton's entire business is built on trust, transparency and privacy, not just as a feature but as a promise. If you refer to your own labelled test code as a "glitch", it suggests that you are not transparent. For a brand built on trust and transparency, it is the most difficult thing to apologise for.

You can also read the original post from Windscribe here with their PoC: https://xcancel.com/Windscribe/status/2085859988090581461

u/Big-Lime4368 — 12 days ago
▲ 51 r/xprivo

SMS 2FA is a single point of failure for every account you own. One stolen number unlocks all your attached accounts at once. A former Apple security director got SIM-swapped despite knowing every trick. Here's why SMS 2FA makes it so easy and two better secure, open-source options.

If you're using SMS for two-factor authentication, one compromised phone number can expose every single account tied to it, at once. That's the story that just played out with Phillip Shoemaker*, the former Director of Apple's App Store, who understood exactly how SIM-swap attacks work and still lost access to his bank, crypto exchanges, email, and Apple ID within one afternoon on vacation. So this is how it happened: A stranger walked into a carrier store, claimed to be him, and walked out with his phone number on a new SIM. No hacking, no password cracking was involved, just a convincing story at a counter.

In the EU, this is harder, but not impossible. Most European countries require ID verification to activate or transfer a SIM, which raises the bar compared to the US, where Princeton researchers found carriers handed over numbers in 39 of 50 test attempts. But remote and video-based ID verification, now common in Germany and France for convenience, opens its own attack surface: deepfakes, manipulated video feeds, or stolen ID documents can potentially bypass automated checks. And in-person social engineering still works anywhere a human is the final decision-maker at a counter.

The vast majority of people don't talk about this, but here's the thing: even app-based 2FA has a hidden dependency problem. When you scan a 2FA QR code, it contains a secret seed that generates your one-time codes. Since 2023, Google Authenticator has backed up these secrets to your Google account. Researchers found that, at the time, backup traffic wasn't end-to-end encrypted, meaning Google's servers could technically access your raw 2FA secrets. If your Google account were to be breached, you could lose not only your email but also every 2FA seed you've ever scanned. Microsoft Authenticator has offered cloud backup for longer and claims to use AES-256 encryption for keys in transit. However, it also sends personally identifiable data back to Microsoft in some cases before you have even accepted the terms. Since these codes contain metadata about which service they belong to, this data could be used for profiling. In either case, your 'independent' second factor becomes recoverable through the same account that was supposed to protect you from it**.**

The fix is to break that dependency entirely. Here are my two favourite secure options: Aegis Authenticator is open source and is developed in the Netherlands. It is deliberately local-only: your vault never leaves your device unless you manually export it. There is no cloud, no company and no metadata trail. It's available on F-Droid, so you're not pulling it from Google Play either. If you're not using an Android device(not yet switched to GrapheneOS?) or you want to sync without handing your secrets to a tech giant, Ente Auth incorporates backup and cross-device sync from the outset. It also encrypts everything end-to-end before it touches Ente's servers, meaning that Ente itself cannot read your codes, even during sync. The crypto implementation is public, so you can verify the claim yourself too if you want to.

*(https://www.linkedin.com/pulse/i-director-apples-app-store-still-got-sim-swapped-phillip-shoemaker-ewk4c)

u/Euhuntix — 11 days ago