DOGE for privacy. @Brave | priv/acc 🚀 views ≠ employer's.

Earth
anon’s guide to actually supporting privacy: > donate to tools you use instead of just complaining they need money > contribute code if you can, documentation if you can’t > use private money (cryptocurrency, cash) > tell normies about alternatives without being insufferable about it > work for companies that aren’t surveillance machines > push for legal protections because tech alone won’t save us privacy isn’t a product you buy, it’s an economy you build
19
39
280
65,357
Hey @shl, I am a self-proclaimed DOGE for privacy. I like helping the American people protect their data and stay safer online. I looked at the IRS app's public privacy disclosures. Here's what I found. On Google Play, the developer-provided label lists crash logs, app interactions, and device or other IDs as data the app may collect and may share with other companies or organizations. For device or other IDs, it lists Analytics as the purpose. The App Store label says usage and diagnostic data may be collected for analytics but are not linked to your identity. It separately lists a user ID linked to identity for app functionality. Both listings link to the general IRS privacy policy. It covers IRS.gov and its online applications, but does NOT explain the mobile app's analytics practices. The IRS's public PIA index links “The IRS app” to an IRS2Go assessment approved in June 2020. That document predates this release and does NOT discuss analytics. With the app now offering tax records, notices, and bank account updates, could the IRS prominently link the current mobile app privacy notice and applicable assessments from its app page and store listings? It would help to know which providers receive which data, which identifiers are used and whether they can be linked to taxpayer accounts, how long the data is kept, and what users can turn off. It would also help to confirm that tax identifiers, bank details, document contents, and authentication tokens are excluded from analytics and crash reports. These are requests for clarity and verification. I only reviewed public pages and their expanded disclosures. The screenshots highlight the relevant disclosures.
Introducing the official IRS app!
2
5
16
1,224
3 copies of your data can still be vulnerable to the same disaster. That's what stood out to me about the AWS data loss in Bahrain and the UAE. AWS said it couldn't restore access to data hosted exclusively in its Bahrain region or in an affected UAE availability zone. 3-2-1 backup rule is a good place to start: 3 copies, on 3 different types of media, with 1 copy offsite. For me, the real question is what could take out every copy at once. Multiple availability zones give you protection within a cloud region. Surviving the loss of that region requires a recovery plan that reaches beyond it. Even then, the location matters. If you need your data to stay in the US, you have more room to work with. AWS has 4 commercial US regions: N. Virginia, Ohio, N. California, and Oregon. Keeping data in the country doesn't force you into one region. Pair an eastern region with a western one. Ohio and Oregon, for example, are far apart and on different major power grids, which lowers the odds of one regional disaster hitting both. For data you can't afford to lose, I would also keep a recoverable copy outside AWS, still in the US. A different provider's US storage or an encrypted offline copy you control adds protection against a problem affecting your provider. Make sure you can access that copy and its encryption keys independently.
1
2
15
809
Before buying a new router, check whether yours still receives security updates. If it does and the WiFi works well throughout your home, I would keep it. If you need a replacement, here are two options, depending on how much setup you are prepared to do. 1. For the simpler setup: GL.iNet Flint 2 (GL-MT6000). This would be my pick between the two for a beginner. It has Wi-Fi 6 and can be set up locally through a browser without creating a cloud account. Start with GL.iNet’s supplied firmware. Set a strong administrator password, leave cloud remote management disabled unless you specifically need it, and install stable updates through System -> Upgrade. Leave preview releases disabled. You are relying on GL.iNet for that firmware and its updates. It is based on OpenWrt, but it is not the same firmware maintained and released by the OpenWrt project. 2. For someone willing to learn network configuration: OpenWrt One. It comes with OpenWrt, an opensource OS for routers [already installed]. I would choose it for someone who specifically wants that software and is prepared for more hands-on setup. It has one 2.5GbE WAN port for the internet connection and one 1GbE LAN port for wired devices. To connect multiple wired devices, add a network switch to the budget. For most people, I would prioritize a router they can configure and keep updated over one that becomes a networking project just to get online.
10
13
87
3,810
GL.iNet Flint 2, including local setup, cloud settings and firmware updates: docs.gl-inet.com/router/en/4… OpenWrt One, including hardware specifications and documentation: openwrt.org/toh/openwrt/one
1
9
430
I dictated a made-up sentence in Bionic 1.1.5, stopped normally, and cleared the composer without pressing Send. After quitting and reopening, the sentence was still in a separate local JSON transcript file. This is local retention of unsent dictation. @lmstudio, is retaining unsent dictation intended, and where can users control or clear this history?
Introducing local realtime voice transcription. Speak freely to your agents, without sending your voice data to the cloud. Available for Mac, Windows - and now also Linux!
3
1
17
1,297
An Indiana police officer searched Flock records covering 82,413 license-plate cameras. The reason entered in the audit log: “idk.” @EFF uncovered the May 7, 2025 search through public-records requests. Other searches listed reasons including “LOL,” “LMAO” and “WEIRD KID.” These cameras can record where your car was even when you are not suspected of a crime. Those audit entries give the public almost no explanation for why officers accessed that location data. Flock has since added a required dropdown for offense categories, which it says makes audits more consistent. Someone still needs to check whether the stated reason matches the actual purpose of the search. If your city uses Flock, who independently audits the searches, and can residents see the findings?
6
10
39
2,913
Researchers got two already-compromised computers to communicate through heat, without a network connection between them. One computer varied its heat output. The other detected those changes using built-in temperature sensors. In the 2015 BitWhisper experiment: - The machines were up to 40 cm apart. - Transfer rates were 1–8 bits per hour. - Both computers were already compromised. @polynoamial cites this academic example when discussing AI agents that are supposed to be isolated and independent. Coordination can require very few bits, so even a slow channel could matter. He calls air-gapping an extremely strong safeguard. His argument is that absolute guarantees about isolation are difficult, which is why safety protocols need independent layers of defense. One lesson from the @huggingface incident was that too much trust had been placed in sandbox isolation, with too few independent safeguards. What could those defenses look like? For physical communication channels, researchers discuss physical separation, zoning and activity detection. Their effectiveness depends on the channel and the environment being protected. Related research: “AI Control” paper tests monitoring, auditing and trusted-model editing against deliberate backdoor insertion in a limited coding setting. The broader argument is that safeguards can buy time while the alignment problem still needs solving. The question I would like to understand better: if isolation fails, which other safeguards still hold, and how have they been tested against agents trying to defeat them?
3
3
12
885
Sources and further reading: BitWhisper (2015), the thermal communication experiment: arxiv.org/abs/1503.07919 Mordechai Guri on physical-channel countermeasures, slide 61: i.blackhat.com/us-18/Thu-Aug… AI Control: Improving Safety Despite Intentional Subversion. Related research on evaluating safeguards against deliberate misbehavior: arxiv.org/abs/2312.06942 Full Noam Brown / Dwarkesh conversation: dwarkesh.com/p/noam-brown
2
147
Agreed @BorisMPower. AI conversations deserve strong legal protection. OpenAI can build privacy into its products by design. Start with the defaults users live with right now. 1. Training is enabled by default on personal Free, Plus and Pro workspaces. Paying for Plus or Pro does not automatically exclude conversations from training. 2. The opt-out has a feedback exception. OpenAI's documentation says that even after opting out, submitting thumbs-up or thumbs-down feedback can make the entire associated conversation eligible for training. 3. For eligible Free and Go users receiving ads - turning off ad personalization still allows the current conversation to inform ad selection. Using conversation content to pick an ad is still a choice OpenAI makes. I prefer privacy by design over privacy by policy.
AI conversations should be considered privileged, the same way lawyer or doctor communications are.
2
3
12
830
Muse's "secure VM" does NOT mean Meta cannot access your data. Training on your conversations is also enabled by default. According to Meta’s own security write-up: - Meta retains the ability to access VM data when necessary to support, secure or operate the service. Access by Meta personnel is restricted through "operational" policies. - Conversations, tool calls and subagent handoffs are used for model training after removing key personally identifiable information. Meta calls this training arrangement "a good default."
we took security extremely seriously in building muse. the thing that took the longest before we felt comfortable releasing was security and safety, because we knew the only way people would use it is if they trusted it. read more: security.muse.ai
2
6
24
1,683
I do NOT consider stock Firefox privacy-respecting by default. I reviewed Mozilla’s privacy notice and technical documentation. These are the details users should know. - Search suggestions are enabled by default in normal browsing. They send your search text to your selected search provider as you type, before you submit it. Where Google is the default, those requests go to Google. - Firefox also collects telemetry by default. Mozilla documents client and profile-group identifiers in some telemetry pings, explicitly designed to correlate reports. Those identifiers allow telemetry reports to be linked to a browser profile. That alone does not establish that browsing history is being uploaded, but it does make linkability a concrete privacy concern. - Turning off the main technical and interaction data setting does NOT disable the separate daily usage ping. That ping has its own opt-out. Mozilla says it excludes browsing history. Users should not have to discover this distinction after believing they have disabled usage reporting. - There is also a difference between Firefox’s default tracking protection and its stricter configuration. In Standard mode, “tracking content” blocking applies only to Private Windows. Extending that protection to ordinary windows requires Strict or Custom mode. Firefox has meaningful protections, including Total Cookie Protection enabled by default. Those deserve credit. My criticism is specific: search text leaves the browser while you type, some telemetry supports correlation across reports, usage reporting has separate controls, and broader tracking-content blocking requires a settings change. These defaults fall short of what I expect from a browser marketed as private by default. Sources from Mozilla in the reply.
6
15
103
5,871
Sources from Mozilla: 1. Default search engine: firefox.com/en-US/more/faq/ 2. Privacy notice, including search suggestions and separate usage reporting: mozilla.org/en-US/privacy/fi… 3. Telemetry collection by default: support.mozilla.org/en-US/to… 4. Telemetry identifiers and their correlation purposes: firefox-source-docs.mozilla.… 5. Daily usage ping and its separate opt-out: support.mozilla.org/en-US/kb… 6. Standard versus Strict tracking protection: support.mozilla.org/en-US/kb…
1
14
724
DeGoogle 101: practical replacements for the Google ecosystem Gmail → @ProtonMail Google Photos → @enteio Photos Google Search → @brave Search Chrome → @brave Google Messages → @signalapp Google Keep → @notesnook, @StandardNotes Google Drive → @ProtonDrive, @enteio Locker Google Password Manager → @Bitwarden, @Proton_Pass Google Authenticator → @enteio Auth Google Calendar → @ProtonPrivacy Calendar Google Contacts → @ProtonPrivacy Contacts Play Store → @accrescentapp + Obtainium Google Gemini → @brave Leo, @ProtonPrivacy Lumo Google Maps → @osmandapp + @OrganicMapsApp Google Translate → @brave Translate Google Meet → @brave Talk, @ProtonPrivacy Meet Google Pay → @Zcash Android → @GrapheneOS Google Workspace → @LibreOffice, @fileverse, @cryptpad
40
215
1,130
32,394
I built Site Behavior Lab to turn a website visit into evidence you can inspect. v0.6 update brings: - Clearer reports that link findings to evidence - Better comparisons, site history, search and exports - Clearer coverage limits and uncertainty - Faster CI and deployments, with verification intact It’s open source and runs real browser scans on Cloudflare. Hosting it reliably is the part I can’t afford to keep funding on my own. @Cloudflare @github, are there OSS credits, sponsorship programs or teams you’d point me to? I’d also appreciate advice from other maintainers on grants or potential sponsors. I’m open to investment if there’s a fit. If you know someone who supports opensource privacy tools, an introduction or a share would help.
2
7
15
1,153
The useful test for Pirate Face is whether a model remains downloadable when Hugging Face stops serving it. Its FAQ says the torrents include Hugging Face as a download source. They can work with zero peers while Hugging Face still hosts the files. A successful download alone doesn’t tell us whether an independent swarm can serve the model. I like the preservation idea. Keeping useful open models available after their original host removes them would be a worthwhile use of BitTorrent. According to the FAQ, you can download and seed without an account. Posting a claim reserves a name and earns points. @ThePirateFace, how many models can currently be downloaded entirely from independent peers, with the Hugging Face source unavailable?
Can someone please explain wtf @thepirateface is and why so many people are tweeting about registering their handle on it. 🤨
1
3
17
1,332
Take app, browser, and OS updates more seriously than ever. The economics of exploitation are changing fast. Brave desktop build 1.94.121 includes the Chromium fix for CVE-2026-85046 [a V8 vulnerability for which Google confirms an exploit exists in the wild]. Now connect that with OpenAI’s latest results. GPT-6 Astra scored 100% on ExploitBench. This benchmark gives an AI agent a known V8 vulnerability, source code, debugging tools and the patch (but no reference PoC). It measures progress toward arbitrary code execution. V8 is the engine involved in the browser bug above. My takeaway: as exploit development gets easier, delaying security updates becomes harder to justify. A published patch gives defenders a fix. It can also give attackers clues about how to exploit devices that haven’t updated. If Brave says “Relaunch to update,” do it now.
⚠️ Today's browser update (v1.94.121) contains a fix for a Chromium vulnerability found to be exploited in the wild. You may have received the automatic Brave update already. If not, you can manually update by visiting 'About Brave' from the browser's ☰ menu. The Android update is waiting on Google Play Store review and should be out shortly.
5
20
137
9,383
What does it actually take to self-host frontier open-weight models like GLM-5.3 / Kimi K3 at a usable speed? AI sovereignty is starting to make a lot of sense to me. I want a private setup where my prompts, files and long-term context stay on hardware I control, and I can switch models without moving my working memory between AI companies.
2
4
35
6,980
Follow the money. Domestic mass surveillance isn’t dynamism. It’s un-American.
Flock eliminates crime. Decline is a choice. @flocksafety
2
11
49
2,952