home.social

#privacybydesign — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #privacybydesign, aggregated by home.social.

  1. Offline First ist mehr als nur ein Komfort-Feature für schlechte Internetverbindungen.

    Wer Daten zuerst lokal verarbeitet und nur bei Bedarf synchronisiert, reduziert unnötige Datenflüsse, Metadaten und Cloud-Abhängigkeiten – ein spannender Ansatz für Privacy by Design.

    In diesem Artikel geht es darum, warum Offline-First-Architektur ein unterschätztes Datenschutzprinzip ist.

    pyngu.com/magazin/privacy/offl

    #Privacy #OfflineFirst #Datenschutz #PrivacyByDesign
    #pyngumagazin #pyngurocks

  2. 🚌 Der Vorschlag, Cookie-Banner über den #DigitalOmnibus abzuschaffen, soll gestrichen werden.

    Reminder: Die Cookie-Banner sind keine Erfindung des Datenschutzes, sondern der Tracking-Industrie.

    #Datenschutz bietet längst bessere Lösungen: #DoNotTrack, #PrivacyByDefault und #PrivacyByDesign.

    Weitere Infos von @noybeu: noyb.eu/de/eu-member-states-an

    🥠 Wir freuen uns darüber nur aus einem einzigen Grund: Endlich können wir die Fotos unserer Glückskekse posten. 🙃

    Fotos: Photothek Liesa Johannssen

  3. 🎆 Happy New Year 2026! 🎆

    Here’s to a fresh start, new opportunities, and another year of protecting what matters most: your data.

    Before the year officially begins: our #WinterSale ends tonight ❄️ Read more about it on our blog!

    cryptomator.org/blog/2025/12/0

    Wishing you a secure, successful, and joyful year ahead! 🚀🔒

    #HappyNewYear #NewYear2026 #LastChance #WinterSale #PrivacyByDesign

  4. Think of online anonymity as being one person in a vast crowd. Every piece of personal information you reveal reduces the size of that crowd, the group of people you could plausibly be. For example, revealing your gender cuts the number of potential identities roughly in half.

    One way to regain some anonymity is through deliberate disinformation. Suppose you share \(n\) independent yes/no facts about yourself, but intentionally flip \(k\) of them (without the attacker knowing which). In that case, you increase the number of identities consistent with your answers by a factor of \(C(n,k)\).

    #OnlinePrivacy #DigitalAnonymity #InformationSecurity #CyberAwareness #PrivacyMatters #DigitalFootprint #DataProtection #InformationTheory #Anonymity #PrivacyEngineering #DataAnonymization #Disinformation #Combinatorics #SecurityResearch #ThinkBeforeYouShare #OnlineIdentity #PrivacyByDesign #DigitalEthics #ProtectYourData #InternetSafety #Privacy #CyberSecurity #Infosec #DataPrivacy #OnlineSafety #SecurityMindset

  5. @Jörgi It does work Fediverse-wide, i.e. as a Hubzilla user, I can send posts and other content specifically to those in a certain privacy group (= Mastodon list on coke and 'roids from before there was even Mastodon), regardless of where they are. They could be on Hubzilla, on Friendica, on Mastodon, on Misskey, on Pixelfed, doesn't matter.

    But there is one limitation.

    Most Fediverse server software out there will understand anything coming from Hubzilla with limited permissions as a one-on-one DM. This means that in a thread with limited permissions, e.g. Mastodon users will only be able to discuss with the thread starter, but not with the others who were granted permission to receive the start post.

    If I have a privacy group with Alice and Bob in it, and both are on Mastodon, and I send a post to only this privacy group, Alice and Bob will both receive the post as a DM. They will only be able to have a conversation with me. Alice won't know that Bob got the post, Bob won't know that Alice got the post, and Alice and Bob will not be able to converse with each other within this conversation thread.

    It's only Hubzilla and its still existing descendants, (streams) and Forte, that fully understand this special permission setting because they have a permission system that's very similar to Hubzilla's whereas Mastodon & Co. don't have any permission system to begin with.

    So if Alice is on Hubzilla, and Bob is on (streams), and one of them replies to me, the other one can and will see that reply and will be able to interact with that reply. Like, Alice can reply to me, Bob can reply to Alice, and absolutely nobody else in the Fediverse will see my post or Alice's reply or Bob's reply.

    By the way: (streams) and Forte literally have "privacy by default". While privacy groups are an optional, off-by-default feature on Hubzilla, access lists (practically the same) are part of the core on (streams) and Forte. And all your posts go to an access list named "Friends" by default unless you go and configure your channel to post in public by default. Conveniently, all your new connections are automatically added to the "Friends" access list by default.

    Is it part of the protocol? That's where it should be defined

    For the longest time, namely until last August, it wasn't available on ActivityPub-based software at all. For Hubzilla itself is not based on ActivityPub.

    It was first implemented in an early "pre-cursor" version of Hubzilla from 2012 that was built on a protocol specifically designed by Hubzilla's creator for a) privacy by design and, especially, b) resilience against server shutdown. That was five years before ActivityPub was first shown and six years before it became a standard. The protocol was (originally) named Zot, and Hubzilla is still based on Zot6 with ActivityPub being supported via an optional add-on that's on by default for servers, but off by default for new channels. (By the way, Hubzilla was the first software to ever implement ActivityPub.)

    There's also (streams) from October, 2021, a fork of a fork of three forks of a fork (of a fork?) of Hubzilla by Hubzilla's own creator which is based on what's actually a newer version of Zot, but which has advanced so much that it's incompatible with Hubzilla's Zot6, so it's named Nomad now. (streams) has Nomad as its base protocol, it also supports Zot6, and it optionally supports ActivityPub, only that ActivityPub is built into the core now and always on by default.

    ActivityPub-based software with this permission system did not exist until August, 2024 when the self-same creator forked the streams repository into something new named Forte, ripped out any and all support for protocols that aren't ActivityPub and ported all of (streams)' features to ActivityPub.

    #Long #LongPost #CWLong #CWLongPost #FediMeta #FediverseMeta #CWFediMeta #CWFediverseMeta #Fediverse #Hubzilla #Streams #(streams) #Forte #Permission #Permissions #PrivacyGroups #AccessLists #Privacy #PrivacyByDesign #PrivacyByDefault
  6. Something I miss in the #Pixelfed & #Mastodon software: the possibility to have lists (like the circles in Google+) and show some content really only for some close friends.
    I don't wanna show everything to all and have more privacy. So I still need to send everything via Signal and co.
    i have no idea if #misskey写真部 , #lemmy or any other #fediverse software has that feature.
    #featurerequest #privacy #circles #privacybydesign #privacybydefault

  7. „Datenschutz kann eine regulatorische Hürde sein, aber er ist auch eine Chance, nachhaltige digitale Geschäftsmodelle zu etablieren. Lesen Sie mehr in unserem neuesten Blogbeitrag, der in Zusammenarbeit mit der Universität Innsbruck verfasst wurde:“ 👉 threema.ch/de/work/blog/posts/

    „Datensparsamkeit für die nachhaltige Digitalisierung von Hochschulen – Gastbeitrag von Matthias C. Kettemann, Leiter des Instituts für Theorie und Zukunft des Rechts an der Universität Innsbruck [@uniinnsbruck], in Zusammenarbeit mit Peter Szabó, Legal Counsel und Datenschutzberater bei Threema, und Danilo Bargen [@dbrgn], CTO bei Threema“

    Von: @threemaapp 👉 mastodon.social/@threemaapp/11

    #Threema #ThreemaWork #Threemaapp #3maRTDeutsch #Datensparsamkeit #Datenschutz #PrivacyByDesign #DSGVO #Datenminimierung #Hochschulen #Digitalisierung #PrivacyByDefault #Messenger #Datensicherheit #InformationelleSelbstbestimmung #Grundrechte #Datensouveränität #Recht

  8. "Am 8.5.2024 haben wir ohne Kartennummer hinterlegte Vorteilscards aus den Konten entfernt."

    Jetzt ist die Angabe der Kartennummer verpflichtend, wenn man auf der Website ein Ticket kaufen will. So geht #PrivacyByDesign - not!

    #OEBB #BahnBubble #Datenschutz #Datensparsamkeit #PrivacyByDefault

  9. @mozilla A privacy preserving online presence should be enabled by default by the browser and shouldn't need users to install extensions that increases their attack surface and makes them more fingerprintable and unique.
    #privacy #firefox #mozilla #librewolf #mullvadbrowser #waterfox #midori #tor #brave #bravebrowser #vanadium #brave #privacybydefault #privacybydesign

  10. @hensys Ich finde, mehr Fediverse-Instanzen und andere Websites sollten dem Vorbild von digitalcourage.social und nuudel.de folgen und auf das Speichern von IP-Adressen ganz verzichten. Für @digitalcourage und die Nutzenden dieser Dienste hatte dieser Verzicht bisher keine Nachteile.

    Schon anno 2000 haben die #BigBrotherAwards #Apache dazu aufgefordert, das voreingestellte #Logging entsprechend zu ändern. Passiert ist nichts, obwohl die #DSGVO inzwischen #privacyByDesign und #privacyByDefault vorschreibt. #nginx macht es auch nicht besser.
    bigbrotherawards.de/2000/sonde

    #ipadresse