techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

5.3K
active users

#tinyprivacytip

0 posts0 participants0 posts today

Tiny Privacy Tip About Faraday Bags 🚫📶

If you are about to trust a Faraday bag/pouch/box/sleeve to block a device's signals:

TEST. IT. FIRST!

Be especially skeptical about anything using zippers, too thin material, or with any kind of holes through the material. Good ones usually use folds, not zippers.

There is a lot of snake oil online for Faraday anything. Be skeptical.

TEST. IT. FIRST.

Tiny Privacy Tip To Fight For Privacy Rights ✊🔒:

Cumulative effect is important to
fight for better privacy rights for all.

Each time you oppose, each time you
opt-out of a privacy-invasive feature or process, you are making a statement that data privacy matters.

The more people opt-out and oppose,
the stronger the message sent to officials and corporations.

Whenever it is possible for you, please opt-out. It will not only help yourself, but it will also help all of us 🔒💚

Tiny Mastodon AND Privacy Tips :mastodon: 🔒:

Depending on your situation,
you might want to increase your privacy and security levels on Mastodon.

Here are a few easy things
you can do for this. Pick and choose what works best for you (instructions are from a browser's web interface):

Enable 2FA ✌️

Why? Reduces account takeover

How? Go to Preferences > Account > Two-factor Auth. Pick a method here and make sure to carefully note and safely store your "Backup recovery codes."

Activate Auto-Delete :nes_fire:

Why? Reduces unwanted parties collecting your data overtime

How? Go to Preferences > Automated post deletion. Select "Age threshold" and "Exceptions" based on your preferences.

Default to Private 🚪

Why? If you post on more sensitive/personal topics, you might want to limit visibility to your followers only. Know that your posts will not be "boostable," however. You can change this per post as well.

How? Go to Preferences > Preferences > Other. In "Posting Defaults" you can adjust the "Posting privacy" to "Followers-only".

Approve Followers ✅

Why? If you want to limit who can see your Followers-only posts, you might want to restrict who can follow you.

How? Go to Preferences > Public profile > Privacy and reach. In "Reach", uncheck "Automatically accept new followers". You will have to approve each new follower manually.

Block Corporate Media ⛔

Why? If you post about sensitive topics, you might want to reduce visibility from larger corporate media such as Meta's Threads, who might use your information in different ways.

How? Follow these instructions: mastodon.moule.world/@MOULE/11

Cautiously Use Direct Messages 🤐

Why? Direct Messages (Specific People messages), are not end-to-end encrypted on Mastodon. This means your instance's administrator(s) could technically read your messages, now or later on.

How? For any sensitive discussion, you should transfer to a trustworthy end-to-end encrypted (E2EE) application. For example, share your Signal's username, Matrix's handle, or throwaway E2EE email address in DM to continue the conversation there.

Verify External Accesses 👀

Why? Verify the apps that have access to your Mastodon account are the ones that you want. In case of doubt, ask your instance's administrator.

How? Go to Preferences > Account > Authorized apps. Make sure every app there is something that you use or that your Mastodon instance's administrator uses.

Stay safe my friends! 🔒💚

Screenshot showing Mastodon's CSV import menu with "blocked_domains.csv" uploaded as a domain blocking list with "merge" selected.
MOULE WORLD MastodonMOULE (Snow Way out Dec 6th!) (@MOULE@moule.world)Attached: 1 image Here's how to #FediBlock threads.net on #Mastodon 4.1.0 and above (I'm unsure about how to do this on other #Fediverse #servers, sorry: FOR USERS: 1. Create a txt document 2. Type "threads.net" (without quote marks) 3. Save as "blocked_domains.csv" 4. On Mastodon, go to Preferences > Import and Export > Import. 5. For input type select "Domain blocking list". 6. Upload blocked_domains.csv. 7. Click "Merge" so threads.net is added to your block list. Do NOT click "Overwrite"! 8. Click "Upload"!

Tiny Privacy Tip for Organizations 🔘🔒:

1. If you are not absolutely required to be able to contact people by phone, do not make a phone number field mandatory in your forms ☎️🚫

2. If you are not absolutely required to be able to mail/ship something, or visit someone in-person, do not make a home address field mandatory in your forms 📪🚫

3. Do not make mandatory (or even request) any data in a form that you do not *absolutely require* to fulfill the purpose of this form 🚫

4. If you use a third-party vendor for your forms, make sure to remove any piece of data you do not actually absolutely need to collect. If you can't, select a different vendor that will allow you to 🔒👍

Yes, this mandatory by law.

Tiny Privacy Tip for Events 📸🔒:

If you value privacy, remember to also value the privacy of others.

Be mindful of the photos you post online that might include none-consenting people.

Everyone has a different threat model and, unless you ask first, you cannot know if these persons could even be endangered by having their faces showing unwillingly online (and showing where they are).

👉 Be mindful.
👉 Stay respectful.
👉 Blur faces where you can.
👉 Ask for consent before posting.

Privacy rights is team work! 💚🙌✨

Important Privacy Tip for Organizations 🔒👩‍⚖️:

Never dismiss the privacy concerns
of a data subject by claiming it does not matter because they are the only one caring about that.

1. It might be true for now, but more people might care tomorrow, next month, next year :haikupeople:

2. Even if only one person cares, it matters ethically 💚

3. It only takes one person who cares to start a damaging lawsuit or to place a privacy complain triggering a full investigation from a data protection authority 📄💼

👉 One person who cares matters.

👉 Take all privacy concerns with the respect that it deserves. Not doing so could be devastating to your organization in the future. It is much easier for you to care now.

Tiny Privacy Tip 👁️🔒✨:

Biometric data is one of the
most sensitive type of data you have.

Why?

You cannot change biometric data like you can change a password.

If your password gets leaked,
you can change it easily 🔑🔑🔑🔑

If your email gets leaked,
it's a pain but you can change it ✉️✉️✉️

If your phone number gets leaked,
it's an even bigger pain but you still can change it 📞📞

But when your fingerprints, facial print, voice print, keystroke pattern get leaked?

It's game over ☠️
You cannot change any of these.
Ever.

You should be extremely careful about where you are sharing your biometric data and how it is protected.

For all biometrics,
preventive protection is vital.

Tiny Privacy Tip for Everyone 🔒✨:

We often talk about what we can do to protect our own privacy, but we don't talk enough about what we should be doing to protect other people's privacy.

If privacy is important to you, then you *must* also value the privacy of others.

This is a great cultural shift we all need to work on, collectively.

Data privacy isn't only about using the right software and implementing legislation, it is also about people and cultures.

Always think about what you can do to improve the privacy of others around you.

This is how we build a better world 💚

Tiny Privacy Hope 🔒💚

Some cultural trends seem so embedded in our societies, it feels impossible to change them sometimes.

Some think it's impossible to reverse the surveillance capitalism we live in now. But this is only a perspective we have while being in it.

40 years ago, it seemed impossible in some countries to imagine a restaurant without a smoking section. And now, in these same countries, it has completely disappeared. At some point, collective choices were made to change this, and it worked.

We absolutely can do the same for privacy and to stop surveillance capitalism. The way it is now isn't intrinsic to our societies.

Never give up on making the world better.

It takes patience yes, but it is only when we give up that it truly becomes impossible to change.

Tiny Privacy Tip for Others' Data 🧑‍🤝‍🧑🔒

If you post screenshots of other people's posts:

Please keep in mind that if you are posting a screenshot of someone’s post without their explicit consent, you are effectively removing their ability and right to delete their data later on or to auto-delete it.

Please refrain from doing so if you respect the poster and use a link to the post instead. Remember, caring about privacy also means caring about other's people data.

Privacy is team work! ✊💚

Gentle Privacy and Security Reminder
for Organizations 🔒🗑:

One of the easiest way for your organization to not have data stolen in a data breach, is simply to not have this data.

One of the easiest way to save your organization future headaches and costs is to simply delete thoroughly the data you do not need anymore as soon as you do not need it anymore.

Whenever possible, it's even better to not collect it at all in the first place.

You might need to retain some data of course, but when an incident occurs, you will greatly reduce the harm, damage, and cost if you keep only the minimum data required.

You cannot be held accountable for the data you simply do not have.

Keep this in mind! ✔️✨

A Word on Data Anonymization 🔥🔒:

Data anonymization is the
process of removing any identifiable information to insure a piece of data cannot be linked to an individual anymore.

Anyone using this technique must be extremely careful about it.

Only removing the obvious identifiers such as name and email might not be enough. When applying anonymization techniques, it is vital to consider the data in context.

Here are a couple of examples
to illustrate my point 🧵👇:

1/4 #DataAnonymization #Privacy #TinyPrivacyTip

Tiny Privacy Tip for Application Developers 🔒✨

Every piece of data you
collect on others with your application becomes a liability to you.

You are responsible for
safeguarding and keeping track of every single piece of personal data you collect.

This is a heavy responsibility.

Especially if you collect and store a lot of data.

A much easier approach is to collect only what is absolutely necessary and delete it thoroughly as soon as it is not necessary to keep it anymore. You will save yourself so many headaches adopting this practice right from the start in your software development.

Remember: You can't be liable for the data you simply never had.
This is the easiest path for you,
and the safest path for your users.

Important Reminder for Signal Users :signal:🔒:

If you activate the new Username feature, you might want to go to:

Settings > Privacy > Phone Number and make sure to select "Nobody" in "Who Can See My Number".

You can also select "Nobody" in "Who Can Find Me By Number" if you prefer that people who get your phone number not know if you are on Signal or not.

This is valid for both Mobile and Desktop.

For Data Privacy Day today 🔒✨

I would like to share with you
this article I wrote last year to guide privacy beginners and more advanced alike towards improving privacy online using easy, accessible, and slowly incremental steps.

I tried to build it so
it would be encouraging and easy to follow in a casual way. In incremental order or not.

No prior knowledge required! 📚
I hope you find it helpful :awesome:

controlaltdelete.technology/ar

controlaltdelete.technologyEasy Practical Privacy Tips for EveryoneA simple blog about privacy, security, open source, software engineering, and tech in general.