Whenever some app or service claims to respect your #privacy, check for two things:
1. Is it open-source on both client and server (if applicable) ?
2. Is the service itself decentralized in some way (federated, allows self-hosting etc.) ?
Now evaluate everything you use - iPhones, WhatsApp, Telegram, Signal, Gmail etc. using this checklist.
Try to find and use software/services which satisfy both of the above conditions.
Wrt. to websites, you can also see (with extensions such as Privacy Badger or uMatrix) how much 3rd party JS and cookies the website uses. Those that use a lot clearly don't care about your privacy.
@njoseph I hear you
@njoseph is there any app or software which meets these two conditions? Is it possible to find an app or software for every need (email, browser, music player, etc.) which works well enough (can be compared to leading apps/softs) and is still being updated?
If a protocol is open-source, chances are an open-source implementation is out there.
PGP (OpenKeychain, gpg, etc. no reason yet to self-host a keyserver)
IMAP (K9-mail for client, dovecot for server)
SMTP (Exim for server, there are others)
XMPP (think whatsapp):
Client: Conversations (free on F-droid)
STOCK ANDROID: AOSP
I'd love to see more!
I'm sporting a Nexus 5X running LineageOS without Google Apps. I know a Samsung phone would do the same things, but it would be less flash-friendly (I presume from my experience with S3mini, YMMV). It was more expensive, but I knew it's repairable and that the target demographic are DEVS, so long-term support.
If you can, try to look up a teardown video of a device you want to buy. How difficult is it? How much glue is there? Does something break every time you open (glass back)?
Check the availability of spare parts for your phone. Even batteries, if a phone has a "non-removable battery", can be replaced with 20 minutes of time and a youtube video. You'll do future you a favour.
@barszczyk There isn't very much software that meets both of those criteria. Lots of software fits one, for example:
- Gmail is federated but not open source
- Signal is open source but not federated
As for software that meets both a few examples would be:
However, all of the above do lack certain features compared to their proprietary counterparts.
I call that "end-to-end free".
@njoseph Unfortunately #OprnSource misses the point as it doesn't care to educate people on the same issues as #FreeSoftware does. Besides, the Open Source Definition, kept by Open Source Initiative, doesn't address #DigitalHandcuffs such as #DRM or the more elaborated forms such as those in many phones that deny the user the freedoms 0 and 1 (to adapt and reuse that in the same unit).
@njoseph This is why I'm a weirdo who hosts his own Matrix server, although the only people I ever end up talking to via Riot.im are via the IRC bridge, or that one paranoid East German I know ;)
@njoseph would elementary OS satisfy this list? It's completely open source, infra included, and AppCenter could be self hosted. But that is so far outside the realm of user wants that I don't think it's ever been attempted.
@cassidyjames All free software usually ticks both the boxes, but beware of apps that only open-source the client and not the server (e.g. Telegram).
There are cases where the advertised "open-source" product you just downloaded cannot actually be created from its source since it has a lot of proprietary components added on top of the open core. e.g. Microsoft VS Code.
I use a #4opens checklist http://hamishcampbell.com/index.php/projects/4opens/ as a step away tool.
@njoseph afaik Telegram's client server is open-sourced. It also has two chats to offer: secret chat (e2e) and the regular chat where your messages are encrypted, but they're stored on Telegram's servers for a lot of benefits: so users can access their saved files/messages on their cloud storage offered by Telegram.
Actually, Durov has written why Telegram is not e2e by default:
Regarding about the second condition, Telegram isn't decentralized (yet).
1. Telegram server is not open-source yet.
2. Telegram is centralized and doesn't federate.
I don't buy their arguments against e2e encryption either.
#Matrix has e2e encryption but stores all messages on the server, allowing easy backups. You just have to keep your keys safe.
#Telegram's whole privacy model is, "there's one individual called Pavel Durov who will not sell your data and will be able to resist all coercion from governments to hand over the encryption keys"
This is a general instance supporting toots in English and తెలుగు.
Hero image credit: Sean O'Brien (CC BY-NC-SA 3.0)