• 17 Posts
  • 333 Comments
Joined 5 months ago
cake
Cake day: February 17th, 2026

help-circle
  • “there’s no expectation of privacy in public places”

    In the US, the judicial system is shifting about that. Slowly! But it is. There is a name for this legal theory which I forgot now. The idea is, once you string together enough individual data points, they enjoy 4A protection. Even if any one by itself wouldn’t rise to 4A level. That means while you don’t have an expectation of privacy, you DO have an expectation the gov won’t use all that data to surveil you without a warrant.

    Ofc, that only binds the government. It does NOT bind private co’s! Google. Meta. A million data brokers. Flock! So it only addresses part of the prob. Is it good? Yes! But we also need protection against private collectors. In meatspace, we cannot block Flocks and randos with smart glasses. Or the total data fusion that results.


  • being able to pay my gas bill

    Have you considered running two browsers? That’s what I do.

    I use one for things that have to know me anyway. Bills, utilities. Banking. W/e. It’s FF based. It’s locked down against analytics and trackers. But not to extreme levels. Required sites still work.

    The other, for looking up games on vintage board game sites. Movie/TV shows. News sites. Stuff that has no gd business knowing my ID. That browser is normally Tor. If a site blocks it, fine. It isn’t essential b/c all my bills and essentials use the other one.



  • and not break websites?

    That’s the hard part! IME the more private you try to make FF, the more sites will break. Well not just FF prob any browser, but I noticed it with FF when changing about:config stuff to ressist fingerprinters and improve other privacy. BTW, Edge works since Edge is Chromium with some MS shit slathered on.

    There’s a bunch you can tweak in about:config. Like blocking battery charge queries. turning off various telemetry from Moz. Resist fingerprinting. Cross site referrers. WebRTC. Disable Google Safebrowsing! More private search engine. But the more you change, the more sites will break. In the end, FF with all privacy tweaks, is essentially equal to Librewolf. So if you have probs with LW, prob same with FF.

    I have complained to a local utility co that their site breaks in FF. Called them up. They basically told me they get so few FF users they don’t care and they told me to install Chrome. Everyone is on one of 2 phone browers, or a few on desktop Chrome.

    Which is the prob with losing too much market share. It’s a downward spiral of irrelevancy. But we need ppl using non-Chrome browsers, or G will fuck the web even more than it already is.

    There is a whole ass other topic about Identity Resolution on the web and how more and more sites will block you if the identity resolver they use can’t peg your meatspace ID.


  • OP has a righteous rant.

    It’s why we must never give up control of Linux to BigTech. It’s OSS, yah… But there are lotsa ways they can weasel. Ex, see Google’s h/w attestation. Or co’s trying to monopolize the ecosystem. Or legal attacks. Or subtle ways to wrestle control, that most ppl won’t recognize until its too late.

    There are LOTS of important contributions to Linux by big tech co’s. That’s fine and good. We need that! But that’s as far as we can let it go. Contributions, good. Taking control, bad.

    Linux is a tempting target, since it isn’t yet vassalized. Vigilance is critical.


  • after which you can run OOBE\BYPASSNRO to reboot into a mode that allows you to skip ms account setup.

    “But the plans were on display…”

    “On display? I eventually had to go down to the cellar to find them.”

    “That’s the display department.”

    “With a flashlight.”

    “Ah, well, the lights had probably gone.”

    “So had the stairs.”

    “But look, you found the notice, didn’t you?”

    “Yes,” said Arthur, “yes I did. It was on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.”




  • I don’t have those chops either. Also NAL. The wiki page says Tampering charges require there to be an ongoing investigation, which wasn’t the case here, so I’m thinking it wouldn’t apply. But! I wonder about spoliation. Spoliation before a case is brought, while not illegal per se, can result in negative inference,

    spoliation inference is a negative evidentiary inference that a trier of fact can draw from a party’s destruction of evidence that is relevant to an ongoing or reasonably foreseeable civil or criminal proceeding

    Negative inference, to my NAL understanding, means the tampered evidence may be taken in the worst light for the defense. Here, it’s all resting on flimsy and politically motivated pretext with no evidence. Still.

    Needs an immigration lawyer to give an answer to this, but I’m thinking it may be legally safer to have strong encryption and refuse to unlock, rather than to wipe. Not unlocking isn’t tampering, so no spoliation, but wiping might be. Well, safest of all is to use a burner. But next best, strong encryption + don’t unlock. CBP can confescate the device, but they cannot compel you to produce a pw or unlock code.




  • Some agencies insist suspects do not have access to those rights if certain conditions apply, such as being within one hundred miles of a US border (such as a coast),

    It seems kinda nuanced tho. From various sources, the rules look like this. Ofc sometimes the rules may not be followed, that’s a separate issue. This is just the rules CBP has,

    1. CBP agents can, with no cause, perform a “basic search”. That means looking through photos, text messages, call logs, and emails. But not using tools or forensic methods.

    2. CBP CANNOT compel you to unlock the device for them or produce a pw. They CAN confescate the device if you don’t, tho.

    3. CBP agents CANNOT perform a forensic search without reasonable suspicion and a signoff from a supervisor. A forensic search is one that uses external tools, not just the agent eyeballing your photos and messages after you unlock it for them.

    4. CBP agents CAN perform a forsensic search with reasonable suspicion, and a supervisor signoff.

    5. CBP CANNOT access cloud data from your device. Only data on the device is in bounds.

    6. CBP MUST follow a special protocol if the owner asserts certain privileges, such as attorney client priviledge, or protected medical data.

    This leaves travelers in a position where they CAN assert their 4A rights when it comes to data on the device. But it comes at a price. It may lead to the confescation of the device. That is coersive ofc, and many ppl won’t want to. So in practice, many ppl will cooperate and unlock the dev for the agent. But if you really want to push back, you can, and they have to let you into the country still if you are a citizen.


  • pay cash

    Ooo! I didn’t know Proton accepted cash payments. But you are right. They do.

    My proton is tied to me, b/c I didn’t really care and it wasn’t important to my threat model. But it’s good to know they offer this. I was paying for Mullvad with cash. Since the whole thing has happened with Mullvad, maybe I’ll open a cash paid Proton just for the VPN option.

    I really wish Proton offered Wireguard tho. It’s so much nicer than OpenVPN.





  • Yah, lots of interesting things here. I agree, seems like it’s long past the point where this needs to get sorted out.

    I think in legal cases with a warrant and so on, the police make a forensic image of the device, and will not just try to unlock it like happend here. They entered the code here without a safe image, b/c there was no court case, no warrant, just the border search.

    Here’s what the EFF has to say about border searches. They agree with us, it’s past time to get a solid legal framework. They talk about the 4A border search exception a little.

    Mostly I’ve heard that they can take your device, but they can’t stop a US citizen from entering the country, and they can’t compel a pw from you. However, for most ppl, that’s already a LOT of duress, b/c losing a phone with your whole life on it, is a huge blow.


  • Tunick’s federal public defenders,

    TBH I hope he can get more than public defenders. They work hard but they are often over worked and under resourced. Plus not being specialists in this. Maybe the EFF will offer specialist help. EFF is already aware of his case. Hence why anyone who is able to, should donate to the EFF. So they can employ high powered lawyers.

    Additionally, the agents produced no warrant and did not read Tunick his rights.

    NAL, but I think the gov can’t have it both ways. IF they did not produce a warrant or Mirandize him, THEN they cannot come at him for wiping his own phone. The gov might have a case if they had a warrant and he knowingly wiped it. But that’s not what allegedly happened here. No warrant = still 100% his device to do what he wants.

    Aside from his case, courts in the US are all over the place, on whether you can be compelled to unlock a device if there IS a warrant. More often than not, they have ruled you CAN’T be compelled to produce a passcode from your memory. But in some cases, they have ruled the opposite. It’s super chaotic, and prob needs a SCOTUS ruling.


  • Proton vpn is pretty good, except on Linux where the client is horrendous. The Killswitch is very unreliable there. When it fails, it sends your machine right back to the internet instead of blocking the connection completely like it’s supposed to.

    I have a paid proton email level, which gives me (I think?) one active VPN tunnel to use.

    I tried it out and it works fine with the standard openvpn client on linux. I always set up my own killswitch, which is easy with ufw. You block all traffic except allow the VPN interface and IP. Bulletproof.

    But what I really want is wireguard! I didn’t know I wanted it, til I tried it. It’s a lot nicer IMO than openvpn.