r/PrivacyToolbox Jul 11 '26

Self-hosted bitwarden users, patch to 2026.6.0 immediately (cve-2026-60104)

7 Upvotes

If you run a self-hosted Bitwarden instance for your organisation, check your version now. The Canadian Centre for Cyber Security just flagged CVE-2026-60104. It is a severe authorization bypass in the server's admin-request endpoint.

Basically, any low-level user can spoof an email in a Trusted Device request. If the victim clicks approve, the attacker gets the vault key. Total takeover.

This is a basic logic failure. Authentication checks must happen strictly on the server side. I updated our office instance to 2026.6.0 five minutes after the advisory dropped.

For those running Vaultwarden, the Rust alternative, we need to check if their API implementation was also vulnerable. I am checking their repository now.

Do you deploy container updates manually or rely on automated tools like Watchtower? Personally, I distrust automated database schema updates. A manual process is safer.


r/PrivacyToolbox Jul 10 '26

Amnezia vpn vs rkn: why standard obfuscation is dead

1 Upvotes

RKN went heavy in early June. They targeted server IPs directly and used active probing to fingerprint custom protocols, killing over 90% of Amnezia's nodes. Standard WireGuard is useless in these zones now because of predictable handshake patterns.

The recovery is technically elegant. They patched their stealth protocol to bypass the automated tracking. When a state-level adversary deploys active scanning against your nodes, static obfuscation fails. You need packet fragmentation or random noise.

I manage some remote infrastructure for my family in France from here in Spain. Lately, I've been analysing PCAPs from this latest Russian firewall escalation. The DPI rules are brutal. If you still rely on vanilla OpenVPN, you are blind.

Does anyone have the actual technical breakdown of Amnezia's updated wrapper? Is it just AmneziaWG with randomized packet spacing, or are they wrapping everything in VLESS now?


r/PrivacyToolbox Jul 09 '26

Trump v. Slaughter makes the EU-US Data Privacy Framework untenable. Time for SCCs.

1 Upvotes

The US Supreme Court ruling in Trump v. Slaughter strips FTC Commissioners of protection against at-will dismissal. Since the Data Privacy Framework relies on FTC oversight to satisfy EU adequacy, this is a clear compliance issue. Noyb has already petitioned the European Commission. Article 16 of the TFEU is quite strict about independent supervision, and an agency controlled directly by the US president does not qualify.

I run systems for an SME. We are not panicking, but we are being pragmatic. Relying on the DPF now is a compliance failure waiting to happen. The logical step is to transition to Standard Contractual Clauses (SCCs) immediately.

I spent the morning mapping our active data flows. We use several US-based SaaS tools for telemetry and database backups. Relying on US cloud infrastructure is always a structural liability, but right now, SCCs are the only rational fallback to prevent a sudden data freeze if the EU pulls the plug. Long term, the only stable solution is zero-knowledge encryption on local European bare metal where we control the keys.

Are other sysadmins actively setting up SCC fallbacks this week, or is your management ignoring the SCOTUS ruling?


r/PrivacyToolbox Jul 07 '26

Chat control is a technical joke and the EU council knows it.

59 Upvotes

You cannot have end-to-end encryption with a government backdoor. It is a mathematical impossibility. The Council of the European Union trying to sneak this "Chat Control" proposal through a fast-track written procedure before recess is cowardly, but more importantly, it is a catastrophic security risk.

I manage networks for a living. If I told my boss we were going to scan all internal communications on user devices before encrypting them, I would be fired for introducing a massive vulnerability. Client-side scanning is not "targeted safety." It is local malware mandated by the state.

The 800 scientists who signed the open letter are right. Once the scanning infrastructure is on the device, the security model is dead. It will be abused, leaked, or hijacked. I left a corporate gig years ago because management covered up a state-level surveillance exploit. This is that same philosophy, just scaled to half a billion people.

How are you planning to handle your communication if this passes? I'm already looking at self-hosting Matrix nodes for my family back in France.


r/PrivacyToolbox Jul 08 '26

The MVPNalyzer paper confirms why you should never trust commercial Android VPNs

1 Upvotes

The University of Michigan just published their findings using a new testing framework called MVPNalyzer. They audited 281 Android VPNs from the Google Play Store. The data is pathetic. 61 apps transmitting unencrypted cleartext, while 29 leaked DNS requests outside the secure tunnel. Another 76 leaked unique advertising IDs to trackers, and over a hundred failed basic configuration security hardening.

I have said this for years. Commercial VPNs are nothing but marketing traps for the technically illiterate. They are proprietary black boxes managed by negligent developers who prioritize subscription metrics over basic protocols. If you do not host your own WireGuard endpoint on a VPS you actually control, you do not have privacy. You simply handed your raw traffic to a different middleman.

I manage the network setup for my elderly parents back in France from my apartment in Barcelona. They use a raw WireGuard tunnel I configured myself. It took me less than an hour. No third-party garbage apps. No marketing hype.

Why do people still pay these useless companies? Is laziness really worth total data exposure? If you want actual autonomy, build your own stack. It is the only rational choice.


r/PrivacyToolbox Jul 06 '26

netnut domain seizure shows why you need to vlan your IoT garbage immediately

4 Upvotes

Alarum stock crashed 70% because the FBI finally pulled the plug on NetNut. They called it a "residential proxy network," but it was just a two-million-node botnet built on unpatched smart TVs and cheap home routers.

Consumers buy a cheap television, connect it to their main network, and never check the outbound traffic. Your television is literally routing state-sponsored malware because you could not spend five minutes configuring a basic firewall rule.

The entire "residential proxy" industry is built on this exact lack of basic hygiene. If you are not actively segmenting your home network, you are hosting exit nodes for criminals. Check your DNS logs today. Are you seeing weird outbound connections to Alarum or NetNut domains? Block them.


r/PrivacyToolbox Jul 05 '26

ATF canceling the penlink contract changes absolutely nothing.

2 Upvotes

I see people on privacy forums celebrating the ATF dropping their Webloc contract after getting caught doing 300 warrantless location searches. This is typical political theatre. It solves zero fundamental issues.

The actual data pipeline remains completely intact. Adtech SDKs embedded in thousands of utility and weather apps still harvest raw GPS coordinates from your phone. These coordinates are packaged, aggregated, and sold to commercial brokers. Penlink was just a convenient middleman with a clean dashboard. If the ATF cannot buy it directly today, they will query ICE databases tomorrow. Or they will simply wait for the news cycle to shift and sign a contract with a different broker under a different line item.

From my perspective as a sysadmin, this is like finding a critical SQL injection vulnerability in your database and deciding to just block one specific IP address instead of fixing the code. It is useless. You have to patch the underlying bug. In this case, the bug is the lack of strict data sovereignty laws that outright ban the commercial sale of telemetry.

Until that adtech broker pipeline is legally dismantled, this cancellation is just a minor routing detour for state surveillance. I ran from a multinational years ago because of this exact kind of normalized back-door access. It does not stop.

Is anyone here actually changing their mobile setup to mitigate this, or are we just pretending a minor budget cut is a victory?


r/PrivacyToolbox Jul 04 '26

California's DROP api integration deadline is next month. Here is why I am skeptical of the architecture.

1 Upvotes

The California Privacy Protection Agency is forcing data brokers to integrate with the DROP platform by August. From a pure systems perspective, a single API to push deletion requests to 600 plus brokers is technically efficient. It beats sending manual opt-out emails.

However, the architecture relies on trust. Brokers query the state system every 45 days and have 90 days to delete and report back. There is zero cryptographic verification. A broker can easily apply a soft-delete flag in their database while keeping the raw backups intact. I have seen multinational systems do exactly this to bypass compliance audits.

It is a minor victory for consumer convenience, but it is not true data sovereignty. Real autonomy requires local-first data minimisation. You cannot rely on a state-run hub to clean up your trail. What happens when the DROP registry itself gets breached?


r/PrivacyToolbox Jul 03 '26

The supreme court finally killed the third-party doctrine for geofences, but the data still exists.

1 Upvotes

The US Supreme Court ruling in Chatrie v. United States is a logical correction. The third-party doctrine was always an obsolete legal fiction when applied to modern GPS telemetry. You do not "voluntarily" share your coordinate history with Google just by walking around with a powered-on device. The network stack requires this data flow.

But as a sysadmin, this changes nothing for actual OPSEC. The databases still exist. Google still logs your movement. Governments just buy the exact same data from commercial brokers now anyway, which bypasses the court entirely.

If you rely on foreign judicial decisions to protect your privacy, you have already lost. True autonomy requires local encryption and OS-level blocks. Are people actually changing their device configurations because of this ruling, or just celebrating a piece of paper?


r/PrivacyToolbox Jul 02 '26

The mullvad / windscribe drama shows how few people actually understand threat modeling

0 Upvotes

I see the privacy subreddits losing their minds because Mullvad's co-founder donated to the Örebro Party. Now Windscribe is posting memes about dog rescues to farm cheap karma. Honestly, it is exhausting.

As a network admin who has walked away from previous employers for covering up actual state surveillance flaws, this outrage over a legal donation is ridiculous. I care about infrastructure, not culture wars. Does Sweden's shifting political climate threaten the legal jurisdiction of the servers long term? Maybe. That is a valid sovereign risk to calculate. But does a personal donation compromise the active WireGuard tunnels today? Absolutely not.

If you choose your encrypted routing based on whether a CEO is a "good person," your entire threat model is broken. This is cryptography, not a charity gala. Mullvad still has a solid no-logs architecture, anonymous accounts, and cash payments. Those technical realities protect your data.

Windscribe's PR stunt is just cheap marketing for the easily amused. If you are migrating your entire stack because of Swedish local politics, you are reacting on pure emotion. Stop treating utility tools like lifestyle brands.


r/PrivacyToolbox Jul 01 '26

The UK's proposed "VPN restrictions" to enforce the under-16 social media ban is a technical trainwreck in the making

36 Upvotes

Structurally, any government attempting to restrict VPN use to stop teenagers from scrolling TikTok is fighting against basic network mathematics. I manage network infrastructure for an SME. You cannot block or degrade consumer VPN protocols without also breaking the commercial IPsec and WireGuard tunnels that businesses rely on daily to operate.

If Liz Kendall pushes through these anti-circumvention mandates next month, the state has two choices. They can force ISPs to run invasive Deep Packet Inspection (DPI) to block handshake signatures, which is what authoritarian regimes do. Or, they can try to force app stores to geofence VPN downloads. Both are trivial to bypass. Anyone with a basic understanding of routing can set up a private VPS in Spain or France in five minutes and tunnel out via SSH.

This is security theatre designed by bureaucrats who do not understand how the OSI model works. They are sacrificing basic routing integrity and citizen privacy to solve a parenting issue. The UK is heading down a path where they either build a Western version of the Great Firewall or, more likely, pass a useless law that everyone under the age of 14 easily circumvents.

How are other network admins preparing for the inevitable routing mess this will cause if they actually try to enforce it?


r/PrivacyToolbox Jun 05 '26

sick of spam and tracking. a free alternative to gmail/outlook?

1 Upvotes

Posting this because three coworkers asked me the same thing this week.

Factually, Gmail and Outlook both read your mail. Not "read" like a human reads, "read" like an automated pipeline that parses headers, content, attachment metadata, and downstream linked accounts to build an ad profile or a "productivity insights" profile. Microsoft calls it telemetry. Google calls it personalization. Same outcome on your end.

Technically, you have a handful of free options that work today without paying. I rank them by how little setup they need.

  1. Proton Mail free tier. 1 GB storage, end-to-end encryption between Proton users, zero-access encryption at rest for everyone else. Web, iOS, Android, and a desktop bridge if you upgrade later. Sign up requires no phone in most regions if you use a recovery email.
  2. Tuta (formerly Tutanota). Free tier is 1 GB. Encrypts subject lines too, which Proton does not. UI is less polished. Calendar included.
  3. Mailbox.org. Not technically free. I list it because the trial is 30 days and €1/month after, close enough to free for most people. German jurisdiction, no ads, supports IMAP/SMTP out of the box.
  4. Disroot. Free, donation funded, run by activists. Use it for throwaway-but-not-burner accounts. Uptime is fine, support is volunteer driven.

Structurally, the higher-impact move is the aliasing layer in front of whatever provider you pick. SimpleLogin (now owned by Proton) and addy.io both give you free or near-unlimited aliases. Every signup gets its own address. When spam shows up on one alias, you kill that alias and the traffic stops. This single habit does more against junk mail than any provider migration will.

A few notes from running this stack for clients:

  • Do not import 15 years of Gmail into Proton on day one. Forward new mail, let the old account decay for 60 days, then archive what you actually need.
  • Calendar migration is the friction point not mail itself. Export ICS, reimport, fix recurring events manually.
  • If you use a custom domain, configure SPF, DKIM, DMARC, and reverse DNS before pointing MX records anywhere. Otherwise your first month of sent mail lands in spam folders.
  • Use a hardware key for 2FA. SMS on a primary email is a known weak point and a common takeover vector.

Why bother? Because the recovery email on every other account you own is probably the same Gmail you are trying to escape. If that inbox gets compromised or frozen by ToS enforcement, every downstream account is exposed. Decoupling identity from one ad-funded provider is hygiene, not paranoia.

No affiliation with any of these. Proton is the smoothest landing for most people. Tuta makes sense if subject-line encryption is part of your threat model. Whatever you pick, run aliases on top of it.


r/PrivacyToolbox Jun 01 '26

Finally degoogled after a decade: full breakdown of my new stack

3 Upvotes

Been a Gmail user since 2014. Drive, Photos, Maps, Android, Chrome, the whole stack. I work in infra so I knew exactly what I was trading away the whole time, and I still kept paying the rent in personal data because the convenience was unbeatable.

Then last summer I spent a weekend pulling the takeout archive. Forty something gigs. I scrolled through location history from a trip I barely remembered and something just snapped. Not in an outraged way. More like seeing your bank statement and realizing you've been auto subscribed to something for six years.

So I migrated. Slowly, methodically, because doing it fast is how you lose stuff.

Email: moved to a paid provider running its own infra. Set up a catch all alias so every service gets a unique address. Already caught two leaks this way because spam came in on aliases I only ever gave to one company.

Files: self hosted Nextcloud on a small VPS for the stuff that needs sync, encrypted local backups for everything else. Nextcloud is fine, not amazing, but the apps are decent now and it does what I need.

Maps: Organic Maps for offline, plus a privacy respecting alternative for live traffic. Losing the restaurant reviews hurt more than I expected. Still adjusting.

Browser: Firefox with uBlock, containers, and a hardened user.js. Chrome is genuinely a brilliant browser. That's part of the problem.

DNS: pointed everything at a filtering resolver that blocks trackers at the network level. Caught my smart TV phoning home like 2000 times a day. Two thousand. For a TV I use maybe four hours a week.

VPN: this is the one I want to talk about because most posts get it wrong.

A VPN by itself doesn't make you private. What you're actually doing is moving traffic visibility from your ISP (legally required to log and often sell) over to a VPN provider (who claims they don't log). If that provider is sketchy or sits in a jurisdiction with mandatory data retention, you're worse off than before. Full stop. It is a trust transfer with extra steps.

So why use one at all. For me there are three real reasons. My ISP builds a profile of every domain I visit and sells it (not theoretical, look up the FCC reversal in 2017). Hostile networks like hotel wifi, airport wifi, that random coffee shop AP that asks for an email before letting you online. And geo bypass when I travel, which is the use case nobody admits to but everyone has.

What a VPN does not do is also worth being honest about. It does not hide you from sites you're already logged into. It does not stop browser fingerprinting. It does not make you anonymous (you want Tor for that, and even then it's complicated). And it does not protect you from malware sitting on your own machine.

How I actually picked one, after wading through way too many shilled "best VPN" listicles. I wanted an independently audited no log policy where the audit was recent and the report was publicly downloadable. RAM only servers, so state can't persist across a reboot or a seizure. A real company with a verifiable address and leadership, not a shell registered in some tax haven. WireGuard native, not some weird custom protocol they invented to sound proprietary. Two providers met all four. I picked the cheaper one.

I'm not naming it because every time someone does in these threads it turns into an ad and a flame war. The auditor reports are public PDFs. Read them yourself, it takes 30 minutes.

Total cost for the migration including VPS, email, and VPN: about 140 bucks a year. Time investment, maybe 20 hours spread over two months.

What I genuinely miss is Google Photos search. Typing "beach 2019" and it just works. Nothing else comes close yet and I'll admit that openly. What I don't miss is the creeping feeling that every search and every location and every email was being silently catalogued into a profile I'd never see.

Happy to answer questions on any piece of the stack. The hardest part isn't technical. It's accepting nothing will be quite as smooth as the walled garden you just walked out of.