-
27 votes
-
I am very privacy-oriented, but my recent Pixel phone somehow obtained all my pictures from my Linux computer
So I am attempting to swap phones, but because I am trying to use a pixel 9 xl and it was not previously on my network, I have to wait 40 days to unlock it so I can install GrapheneOS. I saw on...
So I am attempting to swap phones, but because I am trying to use a pixel 9 xl and it was not previously on my network, I have to wait 40 days to unlock it so I can install GrapheneOS.
I saw on Monday that suddenly there were a lot of photos dated from last Sunday on the phone's default "Photo" app. I have been keeping things to a minimum: I haven't logged into anything Google, and I've only installed F-Droid apps. Also, I had some issues with my desktop and did a clean reinstall 2 weeks ago.But still disturbingly, my ENTIRE ~/Picture directory (and subdirectories) from my PC were loaded onto my phone.
Now, I'd like to clarify, I do have a few Google accounts, but I have them logged into my desktop with containers on Firefox (particularly, I use one for a current hobby type situation that I have to use, and the other is a 20+ account that I've moved away from, but I still want to monitor).
I want to find out why anything from my PC ended up on this somewhat secluded phone. I have not attached it via USB, and while I have been attempting to limit my connections, I do need to access some of my rl/PC stuff on the phone. But I haven't logged into a google account on it, yet, all my photos showed up on it. I have not plugged it into the computer since I tried putting GrapheneOS on it, which failed due to it not being unlocked (PLEASE CORRECT ME IF I'M WRONG HERE, BECAUSE I STILL HAVE TO WAIT 2 WEEKS!), yet all these pictures that I would have never expected ended up on this phone.
And I just was looking around my ~/ directory, and I saw a directory titled .nuget... I checked pacman (I'm on Arch, so that's my package manager), and it's not installed, but I deleted it because it had a lot of sketch files that ... okay, so I deleted the directory and honestly I don't have it anymore to state what exactly was in it. But I'm really tired and it triggered issues, and I looked and I see that nuget is not installed... so okay, I'm just gonna end this here because I do need to go to bed.
But, would anyone be able to provide any assistance/advice/suggestions on how the heck my phone magically obtained my Linux desktop Picture files?
23 votes -
User-friendly and privacy-friendly LLM experience?
I've been thinking perhaps I'll need to get one of the desktop LLM UI. I've been out of touch with the state of the art of end user LLM as I've been exclusively using it via API, but tech-y people...
I've been thinking perhaps I'll need to get one of the desktop LLM UI. I've been out of touch with the state of the art of end user LLM as I've been exclusively using it via API, but tech-y people (who are not developers) mostly talk about the end-user products that I lack the knowledge of.
Ethical problems aside, the problem with non-API usage is, even if you pay, I can't find one that have better privacy policy than API. And the problem with API version is that it is not as good as the completed apps unless you want to reinvent the wheel. The apps also may include ads in the future, while API technically cannot as it would affect some downstream usecases.
Provider Data Retention (API) Data Retention (Consumer) UI-only features ChatGPT Plus 30 days, no training Training opt-out, 30 days for temp. chat, unknown retention otherwise Voice, Canvas, Image generation in chat, screensharing, Mobile app Google AI Pro 0 72 hours if you disable history, or up to 3 years and trained upon otherwise Android assistant, Canvas, AI in Google Drive/Docs, RAG (NotebookLM), Podcast generation, Browser use (Mariner), Coding (Gemini CLI), Screensharing Gemini in Google Workspace See above 0-18 months, but no human review/training See above Claude Pro 30 days Up to 2 years (no training without opt-in) Coding, Artifact, Desktop app, RAG, MCP As a dual use technology, the table doesn't include the extra retention period if they detect an abuse. Additionally, if you click on thumbs up/down it may also be recorded for the provider's employee to review.
I don't think OpenWebUI, self hosted models, etc. would suffice if they are not built to the same quality as the first party products. I know I'm probably asking for something that doesn't exists here, but at least I hope it will bring to people's attention that even if you're paying for the product you might not get the same privacy protection as API users.
15 votes -
I think I’m done thinking about genAI for now
37 votes -
Let's Encrypt is ending support for expiration notification emails
34 votes -
Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel
18 votes -
Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform
50 votes -
Private DNS (DoT) on Embedded / IOT Android Devices - Help With Connection Errors
Good evening, everyone. I was wondering if any of my fellow Tilders had experience with using Android's Private DNS feature on unconventional android devices e.g. WearOS, Android TVs etc. It was...
Good evening, everyone. I was wondering if any of my fellow Tilders had experience with using Android's Private DNS feature on unconventional android devices e.g. WearOS, Android TVs etc.
It was quite easy to figure out exactly how to set up an alternative DNS server on these devices. By default, Google has hidden the private DNS setting on them, but it is still accessible from ADB. In both of my examples it is likely easiest to enable “Wireless Debugging”, pair the devices successfully, and then run the commands.
settings put global private_dns_specifier one.one.one.one(replace this with the pertinent server!!)
settings put global private_dns_mode hostnameThe issue I have been running into, however, is if there is seemingly any form of content filtering enabled on the DNS server of your choice, the WearOS device seems to think internet is unavailable when first connecting. If you open the Settings app and leave it open for long enough on the Wi-Fi page, it will switch from “Internet not available” to “Connected”. Contrary to this, if you open an app like Samsung Internet for, it does not take this time and just refuses to use any configured Wi-Fi network.
To go into my specific situation in a little more detail, I use NextDNS configured with Hagezi Multi PRO++ block list. I have no issues on my S24+ with regard to internet being deemed unavailable by the OS (sure the occasional public Wi-Fi network blocks DoT—I just use mobile data then). I have also yet to try it on my Smart TV, which is frankly the more important target device than my watch (I will get around to it in the new year once the holidays are over).
This is all a potentially very convoluted way to ask what people's experiences are with this, and if they have faced similar problems to me when using providers like NextDNS, AdGuard etc. that provide content filtering options on their encrypted DNS connections.
Merci beaucoup !
4 votes -
EFF's Red Flag Machine: Guess why GoGuardian flagged a site
22 votes -
What To Use Instead of PGP
18 votes