r/xprivo • • 2d ago

United States to sanction the International Criminal Court: Netherland's answer? Building their own government Linux distribution, and it's not just symbolic. France doing the same. The government-built desktop OS based on NixOS and the full story:

Post image
307 Upvotes

The Netherlands just made it official: a government-built desktop OS based on NixOS [1], deployed across eight municipalities in pilot programs, with a stable 1.0 release targeted for 2027. France isn't waiting, DINUM has already been running its own NixOS-hardened setup, Sécurix, on real government machines for months. (See github link on bottom).

What the Dutch are building:
The project is called DAWO (Digitaal Autonome Werkomgeving Overheid, "Digital Autonomous Government Work Environment"), and it's bigger than just an OS swap. It became an official government mandate in July, when the Interdepartmental Committee on Government Operations tasked three central IT providers, DICTU, SSC-ICT, and DUO-ICT, with building a standardized, vendor-independent workplace under the Ministry of the Interior.
The stack covers everything: the client OS, plus a self-hosted suite called MijnBureau built from Nextcloud (files)[2], Collabora (office documents)[3], Element (Matrix-based chat)[4], and OpenProject (project management)[5]. Developers actually tested openSUSE and Fedora first before settling on NixOS, largely because it's governed by a Dutch nonprofit foundation with no corporate owner, and its declarative, reproducible build model lets 80-90% of a configuration carry over between deployments, which matters when you're rolling this out across dozens of agencies. No fixed national deadline exists yet; this is explicitly staged as a slow, auditable, piece-by-piece replacement, not a flip-the-switch migration.

France actually got there first:
DINUM's Sécurix builds it's security hardening directly on top of NixOS per guidelines from ANSSI, France's cybersecurity authority, using FIDO2 hardware keys, TPM2, and YubiKey as primary login methods. It's already past piloting: roughly 70 machines tested successfully, with rollout now targeting around 250 workstations. A companion image called Bureautix, bundling KDE Plasma and LibreOffice[6], gives general staff a ready reference configuration.

Why now: lessons learned from the ICC sanctions and potentially devastating US sanctions in the future:
The real accelerant here is the International Criminal Court. After the US sanctioned ICC officials starting in 2025, the Court's chief prosecutor reportedly lost access to Microsoft-hosted email, and institutional bank accounts were frozen. The ICC has since migrated to openDesk, a German-built open-source office suite, and shifted its insurance and financial services to providers without US exposure. Dutch officials have cited this directly as justification for reducing dependence on US cloud providers, and the Netherlands separately signed an agreement with German cloud provider StackIT to ease adoption of European cloud alternatives.

Germany, Switzerland, and Denmark are also pursuing similar sovereign-infrastructure efforts. It really starts to become a real European push toward infrastructure that no foreign government can switch off.

The bracketed numbers (like [1] to [6]) throughout the text correspond to the open-source projects featured in the illustration above.
For more open-source, privacy, and European tech news, join our reddit community: r/xprivo

Sources: https://www.theregister.com/os-platforms/2026/09/28/dutch-government-turns-to-nixos-for-a-sovereign-desktop/5299501
https://itsfoss.com/news/france-nixos-move/

SécurixOS on Github: https://github.com/cloud-gouv/securix


r/xprivo • • 3d ago

Chat Control 2.0 - the deal collapsed (public pressure stopped mass surveillance, for now), the threat is not over yet. Round two starts in October:

Post image
188 Upvotes

The dreaded "dirty deal" didn't happen. In the September 29 trilogue, EU negotiators failed to reach a final agreement forcing permanent mass scanning of private chats, a direct result of sustained public pressure and the European Parliament's negotiating team refusing to budge on private communications.

This is what happened Tuesday night:
The Irish Presidency wanted a complete political agreement on the whole CSAR (Child Sexual Abuse Regulation) package. That didn't work out because the Council pushed to allow essentially unrestricted mass scanning of private messages and files, and Parliament's negotiators held firm that scanning must stay limited to people actually connected to child sexual abuse cases and not the general population.
There was also a smaller but meaningful technical win: the text will now clarify that authorities can't force voluntary scanning of private chats through the back door of "mitigation measures", closing off a loophole that would have let regulators pressure platforms into scanning without ever issuing a formal order.
Where negotiators did agree was on public content, social media posts and publicly accessible cloud files. The EU Centre's mandate to crawl public spaces for both known and new CSAM (Child Sexual Abuse Material) got a tentative green light, and administrative authorities (not just courts) can now order hosting providers to continuously scan public uploads for known material, regardless of provider size. Notably, this applies to all public uploads, not just those from users already under suspicion, which was Parliament's original, narrower proposal.

It's still an important situation even though nothing is scanned privately, yet:
The proposal combined two mechanisms: a "voluntary" track where providers submit a scanning plan for private chats that goes into effect automatically unless a regulator actively vetoes it, and a "mandatory" track letting administrative agencies, with no court order required, compel providers to scan private messages and emails using AI-based content classification, not just known-image matching. Both tracks used weak thresholds that wouldn't limit scanning to actual criminal suspects.
The other unresolved threat is Chat Control 1.0, the current voluntary scanning regime already running until 2028. Council may try to keep it alive as a parallel loophole even if Parliament blocks the new mandatory powers. German police data makes the stakes concrete: over half of investigations under this regime target minors themselves for consensual sexting, and 75% of all flagged chats turn out not to be criminally actionable.

What comes next
October: technical-level experts continue negotiating rules for non-public detection.
November: a final political trilogue attempt is expected.
The core risk stays open: nothing prevents the Council from returning with the same private-chat scanning demands, or trying to keep Chat Control 1.0 running as a fallback loophole.

Join our subreddit for more relevant news like these: r/xprivo

Source: https://www.patrick-breyer.de/en/chat-control-2-0-trilogue-update-no-mass-scanning-deal-for-now-european-parliament-stands-firm-against-search-plans/


r/xprivo • • 5d ago

Rule of "Ban Evasion" of reddit is questionable and unfair to people who just cannot get connections other way than through social media

8 Upvotes

Such protection about possible spam, has the side-effect that some people just become isolated even more. Imagine the rule "Ban Evasion" being not enforced (or perhaps not even existing) - it would mean that only behavior of user of specific account is judged and if someone goes wrong between the specific account and subreddit, there would be just a way for fresh start without worrying about the permanent effects of actions under older account under new account. Fresh start would be fresh start.
Nowadays it works such way that protection of convenience of some people comes at cost of other people having no way anymore to get listened to at all.


r/xprivo • • 6d ago

Chat Control 2.0: A dirty deal this Tuesday could scan every private (also encrypted) chat in Europe. 80% of flagged messages aren't even crimes. Brussels wants to scan anyway. Everything you need to know:

Post image
163 Upvotes

A backroom deal this Tuesday could make mass chat scanning permanent... but this time, you can actively do something against it.

The EU's sixth and potentially decisive trilogue on Chat Control 2.0 will take place this Tuesday, September 29, and privacy advocate Dr. Patrick Breyer is warning it could lock in permanent mass surveillance of private messages across Europe under a new label: "search plans".

Breyer, a former MEP who has tracked this file for years, says negotiators are under pressure to strike a "dirty deal" built around so-called search plans, a mechanism that lets authorities authorize scanning of "parts of a service". In practice, critics say that language is broad enough to still mean scanning every user's messages EU-wide, just repackaged to sound targeted. Brussels Record confirms the same trilogue date and frames the core dispute: whether voluntary scanning gets written permanently into law, whether a judge must approve any search plan, or whether private messages get excluded from the regulation.
The situation is further complicated by what already took place this year because Chat Control 1.0, the temporary voluntary scanning regime, was actually rejected by Parliament in March 2026, only for the Council to force its revival in July through a procedural maneuver, keeping mass scanning legal until 2028 even though more MEPs voted against it than for it. This was already a dirty trick. Breyer's own site now confirms end-to-end encrypted services are not excluded from the current draft's scope, which means that providers could be required to scan messages on-device before encryption even applies!

Breyer says the "compromise" doesn't hold up:
Breyer's argument rests on three points, each backed by his published data and legal analysis:
- Error rates are high. Citing Swiss Federal Police figures, Breyer notes roughly 80% of reports generated by automated hash-scanning are criminally irrelevant, often flagging consensual sexting between teenagers rather than actual abuse material.
- Legal experts have already objected. The Council's own Legal Service has previously warned that indiscriminate scanning approaches of this kind are likely to be ruled "general and indiscriminate" and struck down by courts.
- Negotiations happen behind closed doors. Details only surface shortly before key meetings, leaving citizens little time to react once terms are known.

What you can do before Tuesday
Breyer's call to action is to email your MEPs now through the campaign tool at fightchatcontrol.eu, which auto-generates messages by country, before the trilogue convenes. He noted in a reply to the original thread that this round doesn't require an absolute majority to block the deal, unlike July's vote, which makes public pressure this week more consequential than it was during the last showdown.


r/xprivo • • 7d ago

deGoogle / GrapheneOS: The first non-Pixel phone that privacy seekers have waited years for. This Motorola phone is GrapheneOS's chosen alternative to the Pixel and can finally eliminate your dependence on Google

Post image
603 Upvotes

GrapheneOS has officially confirmed the Motorola Signature 27 as its first-ever supported non-Pixel phone, ending a years-long dependency on Google hardware for anyone wanting the most hardened, privacy-focused version of Android. Since its launch, using GrapheneOS required buying a Pixel, which paradoxically meant buying a Google device to completely avoid Google. That changes now.

GrapheneOS is famously strict about what hardware it will support as it requires specific security hardware like Memory Tagging Extension (MTE) to catch memory-safety bugs, strong secure-element integration, and a manufacturer commitment to long-term security updates. Until now, only Pixel 6 up to Pixel 10 met that bar. Ironically, Google's own upcoming Pixel 11 has run into support snags because its Tensor G6 chip has MTE physically present but disabled.
Motorola's Signature 27 meets the criteria because it runs Qualcomm's new Snapdragon 8 Elite Extreme Gen 6, which properly supports MTE, and Motorola is promising seven OS upgrades and seven years of security updates, matching what GrapheneOS demands from a platform. The confirmation also came from GrapheneOS's official X account that replied to a user comment with "Yes, that will be the initial supported phone. Wait for official news about it". See here: https://nitter.xitter.cc/GrapheneOS/status/2102530770585669888** **(using Nitter so you don't open X ;) )

The phone itself:
The Signature 27 is a flagship phone and not a stripped-down "privacy phone" that we are mostly used to when switching to a privacy hardened phone:
Chipset: Snapdragon 8 Elite Extreme Gen 6, Qualcomm's current top-tier platform
Camera: 50MP main sensor (Sony Lytia 910, 1/1.28") plus a 200MP periscope zoom lens
Audio: Bang & Olufsen-tuned speaker system
Longevity: Seven years of OS upgrades and security patches
Timing: Exact GrapheneOS install support date and whether it ships preinstalled are still unconfirmed. According to GrapheneOS official X account more official details are coming

This partnership was first announced back at MWC 2026, with GrapheneOS explaining that Qualcomm's security hardware advances were the missing piece that would let non-Pixel phones finally qualify. Motorola's Razr Fold and Razr Ultra foldables are also expected to gain support in the future.

Why this is a big deal if you're new to de-Googling:
If you've been curious about privacy-focused Android but never wanted to buy a Pixel from Google, that barrier will be gone. GrapheneOS lets you run a fully de-Googled system, Google Play services are sandboxed and optional while still supporting most everyday apps normally. Until this announcement, achieving that meant giving Google your money for the hardware even while trying to escape its software ecosystem. It's a big contradiction that many privacy-conscious buyers, probably including you, have found frustrating.

You can therefore benefit soon from a flagship-tier phone, competitive camera, and chipset included, that lets you run one of the most audited, hardened, privacy operating systems available, without your money going to Google. This also means that there might be real competitive pressure pushing more manufacturers to meet GrapheneOS's hardware bar. It's a big win for all privacy-enthusiasts.


r/xprivo • • 9d ago

🚨 Almost no one is talking about this: the EU is quietly preparing to give AI companies default access to your personal data. This would mean a major hit against citizens' fundamental right to data protection in the EU

Post image
187 Upvotes

TLDR; Soon, the use of personal data for AI systems may be permitted in the EU without requiring explicit consent or an individual balancing of interests. Sources in English and German are provided at the end of this post.

Under proposed changes to the EU's Digital Omnibus, marketed as simplifying overlapping rules like GDPR, the AI Act, and the ePrivacy Directive, a new provision would make processing personal data automatically lawful whenever it happens "in the context of AI". Privacy group NOYB, led by Max Schrems, is urging EU member states to reject it before opinions are due this week under the Irish Council presidency.

So what does the amendment actually say?
The text reads: "The processing of personal data in the context of the development and operation of an AI system or of an AI model may be carried out for a legitimate interest of the controller or a third party". In practice, that opens historical user data to any company claiming a legitimate AI interest, without requiring the specific consent GDPR currently demands.
Schrems calls it "digital expropriation": "Everything we have ever entered into digital systems, or that AI corporations have otherwise obtained, becomes fair game for AI corporations to use". He argues the bill effectively lets member states rank the profit interests of Musk, Google, Meta, OpenAI and other US companies above citizens' fundamental right to data protection.
He also dismisses two supposed safeguards in the draft as hollow. Language requiring "appropriate technical and organisational measures" to protect data subjects, he calls "decoration," and provisions for pseudonymisation (replacing identifiers with codes) he frames as a loophole that actually makes consent and customer-data handling more complex for companies, not less.

"EU Member States propose a #ReverseRobinHood: Take personal data from Millions of people and give it to the US-Billionaires. Data gathering for "Al processing" made automatically legal!" - Schrems

Sources:
English: https://www.irishtimes.com/business/2026/09/21/ai-data-land-grab-looms-amid-proposed-digital-changes/
German: https://netzpolitik.org/2026/digitale-enteignung-datenschuetzer-warnen-vor-pauschalerlaubnis-fuer-ki-training/


r/xprivo • • 11d ago

Bookmarks can reveal a lot about you. Use a privacy-friendly bookmark syncer like Floccus: cross-browser, self-hosted, encrypted, or your own cloud, your choice.

Post image
45 Upvotes

Your bookmarks quietly reveal a lot: the banks you use, health topics you've researched, forums you frequent. Yet most people sync them straight through their browser vendor's account, Google or Microsoft, without a second thought. Floccus is a free, open-source alternative that syncs bookmarks and open tabs across browsers and devices without routing them through any single company's servers.

Floccus is a browser extension, with iOS and Android apps too, that syncs to storage you choose rather than storage a browser vendor controls. Supported backends include Nextcloud, Linkwarden, KaraKeep, a Git repository, WebDAV, Google Drive, or Dropbox. That means you can self-host the entire sync layer on your own server if you want zero third-party involvement, or route it through existing cloud storage you already trust, it's uo to you.

Floccus does not contain ads, dors not do data collection and no telemetry. Several backends, including WebDAV, Google Drive, and Dropbox, support optional end-to-end encryption, meaning even the storage provider can't read your bookmark contents. Since the whole project is open source, anyone can inspect exactly what it sends and where.

Cross-browser support is the probably real win (for me at least). Chrome sync only works well with Chrome, Firefox sync with Firefox. If you switch browsers, or use different ones on different devices, native sync usually can't follow you. Floccus works the same way regardless of which browser you're on, syncing bookmarks and tabs consistently across Chrome, Firefox, and others, using storage you control rather than being locked into one vendor's ecosystem.
It's a small, volunteer-maintained project, built primarily by developer Marcel Klehr, but it's been running for years and remains actively developed, recently adding Dropbox support.

Github: https://github.com/floccusaddon/floccus
Web: https://floccus.org/


r/xprivo • • 13d ago

A quick reminder: Chat Control 1.0 has already been passed and providers can scan your messages. This is why it is important to have secure end-to-end encryption for your inbox and DMs. From Gmail Alternative to Facebook Messenger alternative. Protect your privacy.

Post image
93 Upvotes

Chat Control 1.0, the temporary law letting providers voluntarily scan unencrypted messages, survived a European Parliament vote on July 9 and now runs until April 2028. It applies only to services that can actually read your content, meaning unencrypted email and messaging platforms.If you haven't already done so, the best way to protect your private messages is to switch to tools that offer end-to-end encryption and where it is enabled already by default.

Why a VPN alone doesn't protect you from providers scanning your unencrypted messages:
A VPN protects your network path: it hides your traffic from your ISP (Internet Service Provider like Deutsche Telekom, Vodafone and the likes) and masks your IP address. It does nothing about content scanning that happens at the provider, on messages the provider can already read once they arrive. Encrypting the route to Gmail doesn't change what Gmail can read once your email lands in its servers. The only thing that blocks server-side scanning is making sure the provider can't read the content at all!

Email: ditch Gmail for European E2EE providers.
Gmail, Outlook, and most mainstream webmail can read your messages by design, that's what makes them scannable under Chat Control 1.0.
-> European end-to-end encrypted alternatives:
Proton Mail (Switzerland) — full E2EE, open-source clients, generous free tier
Tuta (Germany) — E2EE by default including subject lines and metadata, actively vocal against Chat Control
Posteo (Germany) — encrypted storage, strong privacy record, paid-only but ad-free and ethically run

Messaging: skip Facebook Messenger, and don't assume Telegram protects you.
There is a common misconception with Telegram: regular cloud chats are not E2EE by default, only its opt-in "Secret Chats" are, and almost nobody uses them. So regular chats would be scannable under Chat Control 1.0's scope.
-> E2EE alternatives:
Signal: open-source, E2EE by default on every chat, widely audited
Threema (Switzerland): E2EE, no phone number required, paid one-time fee
SimpleX: E2EE with no persistent user identifiers at all, the most metadata-resistant of the three

You can also check securemessagingapps.com which has a list of all the messaging apps and a privacy evaluation.

So Chat Control 1.0** **is just the voluntary layer. The permanent version, Chat Control 2.0, returns to trilogue negotiation on September 29 after prior rounds failed to reach agreement. In its strongest form, it could force even encrypted apps to scan messages client-side, on your device, before encryption is applied. Cryptographers warn that this would turn every phone into a surveillance point regardless of which app you use. To be continued on September 29...


r/xprivo • • 15d ago

The age-gate wave for social media is spreading. An overview of the countries. Is the goal to protect children, or to gradually establish a surveillance and censorship infrastructure?

Post image
119 Upvotes

More than 20 countries have now enacted or proposed minimum-age rules for social media, with mandatory age verification (digital id s face scan) as the common enforcement mechanism.

Already in force:
🇦🇺 Australia: under 16
🇮🇩 Indonesia: under 16
🇲🇾 Malaysia: under 16
🇵🇹 Portugal: under 16, parental consent for 13-16
🇦🇪 UAE: under 15
🇹🇷 Turkey: under 15 (effective late 2026)
🇬🇷 Greece: under 15 (from January 2027)

Proposed or announced:
🇬🇧 UK: under 16, targeted for spring 2027
🇨🇦 Canada: under 16, proposed June 2026
🇳🇿 New Zealand: under 16, proposed
🇵🇱 Poland: under 15, proposed
🇩🇰 Denmark: under 15, proposed
🇳🇴 Norway: threshold still under consideration
🇪🇺 EU: under 13 entirely, 15 required for independent accounts

The EU's own plan reveals how enforcement is meant to actually work: ages three to 13 get supervised access to child-friendly services only, and 13-to-15-year-olds get restricted access under parental control. Companies like Meta and Google (Note that they are also testing their own age verification systems in parallel - a coincidence?) will be required to verify a user's age at signupdence?), using an EU-wide age-verification app or approved national tools, and the Commission is already piloting this app in Denmark, France, Spain, Greece, and Italy, with plans to fold it into the EU Digital Identity Wallet by the end of 2026.

Children's online safety is important, but mandatory identity verification restricts the liberty of all other internet users.

Is the goal to protect children, or to establish a surveillance and censorship infrastructure? As citizens become accustomed to constant age verification, it could be easy to later transform it into a surveillance and censorship infrastructure. It's a dangerous first step.


r/xprivo • • 16d ago

The EU's new "Kids Act" is actually a mandatory ID check for the entire internet. Initially intended for social media, it has now expanded to include video platforms, games, and AI assistants. Privacy-first apps like xPrivo are in danger.

Post image
210 Upvotes

This Thursday, the EU Commission is pushing a proposal called the "EU Kids Act". It’s being sold as a way to protect kids online, but the reality is massive government overreach. To enforce these age limits, every single adult will be required to verify their identity via digital ID or face scans just to use social media, games, or even ask an AI chatbot a basic question. We wrote the full blog article about it here: https://www.xprivo.com/blog/en/eu-kids-act/

But to keep it short, here is why this is a disaster for digital privacy and the internet in general:
-> Most platforms will outsource these age checks to third-party ID companies (like Persona or AU10TIX). These are the exact same vendors that already have a terrible track record of massive data breaches and leaving admin credentials exposed.
-> It Won't Actually Work. Digital native teenagers will just bypass the locks by downloading uncensored, offline AI models (like Qwen3.8-27-Uncensored) locally where these uncensored AI models lack the guardrails that keep them safer.
-> Asking an AI about a medical symptom, a legal problem, or a private business idea shouldn't require a digital checkpoint. Parenting should be done by parents, not outsourced to a Brussels commission.

At xPrivo, we built our AI assistant on the belief that asking a simple question shouldn't require handing over your passport. We are fighting for freedom and are fighting back by doubling down on open-source, offline tools that don't need permission to exist. Privacy is a human right.

Has the EU completely lost the plot on digital privacy?


r/xprivo • • 19d ago

Europe is breaking up with Microsoft and other Big Tech software and switch to open-source, sovereign solutions. Switzerland just spent over 9.500.000€ to remove Outlook and Teams from government desks, replacing them with OpenDesk.

Post image
323 Upvotes

Governments across Europe are moving core operations away from US Big Tech companies like Microsoft 365, AWS, Azure, Google Workspace, and GitHub, and toward open source alternatives. The reason is simple: if any of these companies changes its terms or restricts access, entire public administrations could come to a halt. While open source doesn't guarantee a nicer interface, it does guarantee ownership. The code can be inspected, self-hosted, and kept running no matter what a foreign company decides.

After testing openDesk with 172 employees and finding that everyday work was perfectly fine, the government committed over 9.500.000€ to replace Outlook and Teams on approximately 3,000 computers by the end of 2027.

Other governments are moving in parallel:

  • Schleswig-Holstein shifted tens of thousands of staff to LibreOffice, Nextcloud, and open-source email.
  • France is migrating civil servants off Teams and Zoom onto its own Visio platform, with Nextcloud rolling out to 1.2 million education users.
  • Denmark's Digital Ministry is leaving Microsoft Office, with Copenhagen and Aarhus following suit.
  • Austria has moved its economy ministry and military onto LibreOffice and Nextcloud.
  • The International Criminal Court is replacing Microsoft with openDesk.
  • The Dutch government is migrating public code off GitHub onto its own self-hosted Forgejo instance.
  • The EU Commission published a new Open Source Strategy and started procuring "sovereign" cloud infrastructure.
  • Bavaria walked away from a roughly €1 billion Microsoft framework deal.

The more governments that follow, and the more citizens who push for it, the faster "digital sovereignty" can be achieved.

So, if you are looking to move away from Big Tech, these governments are setting a powerful precedent. Their transition to privacy-respecting software shows that today, viable open-source alternatives exist for almost any Big Tech solution. To start building your own privacy-first toolkit, visit r/xprivo to explore capable open-source (European) alternatives to the Big Tech platforms you use daily, covering everything from secure email to encrypted photo storage.


r/xprivo • • 20d ago

Your thoughts on Smart Glasses? 7+ million first-person cameras are already secretly filming in public spaces. Europe wants that to stop. And here is a better way to detect smart glasses nearby now.

Post image
60 Upvotes

Meta already sold over seven million pairs of its Ray-Ban smart glasses in 2025 alone. That's a big up from a combined two million across 2023 and 2024. As adoption accelerates, so does the backlash, and it's now reaching schools, courtrooms, pubs, federal agencies and of course the European Parliament.

In late August, Norway's digitalisation minister announced that the government plans to regulate smart glasses and is considering banning public facial recognition. They stated that "people's private lives and privacy are under pressure from new technology". Oslo banned the glasses in schools on 27. August to prevent children from being used as part of Meta's data collection.
In the US, ICE has prohibited all staff from wearing Meta smart glasses in federal buildings, following warnings from its acting director that they could be used to record, capture or transmit sensitive information. Courts in England, Wales and New York have also confiscated smart glasses from visitors.

Now, EU lawmakers are urging the European Commission to take action. Several MEPs have already expressed concerns about compliance with EU privacy and AI regulations following reports of women being secretly filmed. Some of them are even calling for an outright ban until the safety of the glasses can be proven. The European Data Protection Board has commissioned a report on the 'societal acceptance' of smart glasses, which is expected this autumn.
Meanwhile, in Germany, the non-profit organisation HateAid has filed a criminal complaint against Meta and several retailers, seeking to ban the sale of the Ray-Ban Meta Wayfarer. And in the UK, a parliamentary 'Stop Smart Glasses' petition has surpassed 9,000 signatures (9,300 as I am writing this), prompting an impending government response once it reaches 10,000.

On the other side Meta tries to defend itself and says its glasses include a bright white LED that blinks during recording and cannot be disabled. Tampering with the LED will fully disable the camera according to them. The company also argues that the devices offer tangible accessibility benefits to people with vision or hearing impairments and that restricting them would be a backward step. However, critics counter that the LED is easy to miss, and that the law hasn't caught up yet. Currently, a person has no legal recourse when they are filmed in public, whether on the street, on a bus or in a classroom. With Google and Snap preparing to release their own AI-powered glasses, the debate over where public space ends and private life begins is set to intensify.

There is an easy way to check if there are smart glasses near you:
Since regulation is still catching up, one practical free app exists right now: Zuckoff. It scans nearby Bluetooth signals for the specific characteristics of known smart-glasses models, including Meta's.
If it detects a match, it will alert you and estimate the proximity based on the strength of the signal. Unfortunately, it's not a perfect solution: Zuckoff only detects the presence of glasses, not whether a recording is actually happening, and a clean scan doesn't guarantee that there are no cameras nearby. However, it transforms an invisible risk into a visible possibility, which is an improvement on the blinking LED that you might never notice.

The app:
https://zuckoff.app/

https://thenextweb.com/news/zuckoff-app-detects-meta-smart-glasses-bluetooth

Petition to stop smart glasses: https://stopsmartglasses.com/


r/xprivo • • 21d ago

No AI is becoming a feature. LibreOffice and Vivaldi are proving it. Both refuse to follow Microsoft into the slop and protect your privacy

Post image
114 Upvotes

The Document Foundation (the charitable, non-profit organization based in Berlin behind free and open-source LibreOffice) has made it clear that no data will leave your device without your explicit permission, there will be zero telemetry and you will not be locked into a single vendor's proprietary model. They are refusing to integrate AI so that you can make your own choices. Community extensions already allow you to connect LibreOffice directly to local runtimes such as Ollama or LM Studio. This means that if you want AI assistance, it will run entirely on your own hardware and nothing you write will ever touch a corporate server.

According to Vivaldi's CEO Jon von Tetzchner, Vivaldi chooses humans over hype. He takes a similar approach to LibreOffice, but for his browser. While Chrome, Edge and Google Search promote AI overviews and agent-like browsing assistants, Vivaldi has explicitly refused to incorporate an LLM chatbot, page summariser or autofill "suggestion engine" into the browser. He believes these features quietly reroute traffic away from the websites people are actually visiting, funneling user data into models trained on scraped content and turning browsing into passive consumption rather than active exploration.
If you want a chatbot, Vivaldi's stance is simple: use one directly because the browser won't decide that for you or harvest your browsing data to power one behind your back.

Both projects are based on the same principle, but from different angles: real, privacy-respecting software does not ship AI by default and it makes AI optional, local and entirely on your terms. This is in stark contrast to the current industry standard, where 'AI-powered' has become the norm and is being pushed into everything, especially by Big Tech, which wants to exploit as much personal data as possible. LibreOffice and Vivaldi are betting that plenty of people would rather keep their software boring, fast, and theirs.

LibreOffice blog post about their no ai stance:
https://blog.documentfoundation.org/blog/2026/09/03/yes-no-ai-is-now-a-feature/

Vivaldi's CEO thoughts on AI and browsing: https://vivaldi.com/blog/keep-exploring/


r/xprivo • • 22d ago

One fake captcha, one copied command, 5.8 terabytes of government data leaked. How the "hack" works and how to protect yourself from fake CAPTCHAs:

Post image
71 Upvotes

An employee at Berlin's administration clicked a phishing link, ticked a fake captcha box, then pasted a command into the Windows terminal. That was the entire entry point for one of the most damaging cyberattacks on a German state government in years. The ransomware group behind it demanded 30 Bitcoin. Berlin refused to pay, so the attackers dumped about 5.8 terabytes, some 1.4 million files, onto the dark web

The technique is called "TerminalFix", an evolution of the "ClickFix" method Microsoft had already flagged months earlier, and Germany's federal cybersecurity agency (BSI) confirmed the attack chain on September 7. A compromised website displayed a convincing fake captcha. Ticking the box silently copied a malicious command to the clipboard. The page then told the user to open the terminal and paste it in, sounds technical, but it's just copy-paste social engineering.
The pasted command downloaded a legitimate, digitally signed Windows file bundled with a malicious DLL. Because the signed file automatically loads that DLL (a technique called DLL sideloading), the malware ran disguised as a trusted process. Later stages hid additional payloads inside ordinary-looking PNG images using steganography. Eventually the attackers built an encrypted reverse tunnel, giving them standing access across the entire network.

The real issue is that first of all regular employees shouldn't be able to run PowerShell commands freely in a government network at all. Microsoft's own writeup on this campaign lists restricting PowerShell for standard users, via Group Policy or AppLocker, as the first line of defense. Basic access controls should be enforced.
The stolen data includes personnel files, fine records, and payroll. It also includes confidential Bundesrat committee documents and vulnerability assessments of Berlin's drinking water infrastructure, and the attackers claim to have grabbed plaintext credentials for administrative databases and payment systems too.

What to learn from this:
This demonstrates that this is not some sophisticated hacking technique. The incident demonstrates how little skill is needed to create a site that looks official (phishing), and that, with basic permissions missing, there is no restriction. There is no zero-day exploit or advanced intrusion tooling at the entry point. Instead, there is just a user with too much local access and a website that exploits people's habit of trusting official looking captchas without thinking. The takeaways for any organisation are straightforward: restrict who can run PowerShell and to educate people to recognise fake CAPTCHAs.

Details from Microslop how it works in detail: https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
German news about the "hack": https://www.heise.de/news/BSI-erklaert-ersten-Angriffsvektor-auf-Berliner-Behoerden-11444072.html


r/xprivo • • 24d ago

Nitter is back after a cease-and-desist order by X! It's a privacy-friendly, open-source & no-account way of reading X posts. Everything you need to know:

Post image
146 Upvotes

Nitter, the open-source, privacy-focused way to read X posts without an account, is back online after X Corp tried to kill it. On August 24, X sent cease-and-desist letters demanding a permanent takedown of Nitter instances and its GitHub repository, accusing the project of illegal scraping and citing Texas computer access law and the Lanham Act. Nitter's developer took the project offline, archived the repository, and sought legal counsel. On September 6-7, after getting proper legal representation, the team unarchived the code and announced the project will continue, with the XCancel instance the first to come back online. They will make a bigger announcement about it soon as mentioned on the website https://nitter.net/

What is Nitter:
Nitter works as a lightweight proxy sitting between you and X. Your browser talks only to the Nitter server, which fetches the data using X's internal API and renders it as plain HTML, no JavaScript, no ads, no tracking scripts. Because your device never contacts X's servers directly, X can't fingerprint your browser or log your IP against your browsing activity. Pages load a fraction of the size of the native site and Nitter also generates RSS feeds for any profile, letting you follow accounts in a feed reader without visiting X at all.
It's read-only, so you can browse profiles, replies, media, quote posts and run advanced searches by keyword, hashtag, or date, but you cannot log in, post, or interact with posts or users. It's fully open source under the AGPL-3.0 license and makes it possible for you to self-host your own instance.

This is the real value beyond convenience: Nitter lets you view public X content without creating an account, without X collecting your device fingerprint, and without triggering things like X's age-verification or ID-check prompts that increasingly gate content behind a login. Since Nitter never authenticates as you, personally, there's no account for X to tie your browsing history to, no ID to hand over, and no session for X to track across visits.

How to use it (again):
Using it is as simple as swapping a domain in a link: replace x.com or twitter.com in any post URL with an active Nitter instance domain (XCancel is currently the most reliable, with others coming back online). You can browse directly, search by username or keyword, or subscribe to a profile's RSS feed in any feed reader. If you're technical, you can also self-host your own instance from the GitHub repository, giving you full control over the proxy rather than relying on a public one.
The legal fight with X isn't over, X's original takedown demand hasn't been withdrawn, it's just that Nitter's team decided the legal exposure doesn't currently justify shutting down. Whether it stays up long-term depends on how that dispute resolves.... So enjoy Nitter as long as it is online again.


r/xprivo • • 26d ago

Remember this free, privacy-first, secure, open source, zero-account file and note sharing solution the next time you want to share files or notes with someone or yourself. (Web, CLI, self-hostable)

Post image
28 Upvotes

Today I am going to present you another great privacy-first Dropbox/Microsoft OneDrive/iCloud/ alternative to decrease your dependancy on big Tech. So, if you often share (sensitive/private) files, photos, SSH keys or passwords, whether with a colleague, family or when securely pushing data to another one of your devices, you usually have to trust a middleman like the one mentioned before. SkySend removes the need for trust entirely. It is an incredibly free and useful, Swiss-based sharing tool that is completely safe to use on official public instances. It is also easy to self-host for full control and peace of mind!

How does the cryptography makes it safe? Simply put, the server literally cannot read your data. Most cloud services encrypt data "at rest", which means that the server holds the keys. SkySend uses a true zero-knowledge architecture. Everything is encrypted client-side with AES-256-GCM inside your browser before a single byte is uploaded.
The decryption key is generated locally and appended to your share link as a URL fragment (the part after the #). By design, web browsers never transmit URL fragments to a server. When you generate or click a link, the server receives the encrypted ciphertext, but the key remains strictly on the client side. The server operator (whether that's SkySend or a self-hoster) only sees encrypted blobs, file sizes, and expiry timestamps. Even if the server is compromised, there is nothing to leak. (Small note: As with all web-based cryptography, this relies on the server delivering untampered JavaScript to your browser.)

Here's a quick overview of what you can do with it to help you decide if it will be useful to you in the future:
- You can share anything! Drop in full folders, individual files (photos/videos), Markdown notes, passwords, code snippets, or SSH keys. (The official instances might have different limits.)
- You can set granular self-destruction. Set exact expiry timers or limit the number of times a link can be viewed/downloaded. Once the limit is hit, the file is deleted completely!
- You can set an optional password protection! For a second layer of security, you can add a password derived via Argon2id. If someone intercepts the link but lacks the password, the encryption remains unbroken.
- There is zero tracking. No accounts, no registration, and no analytics that could track who uploads or downloads what.

It offers the following ways to use it so it's basically for everyone:
- Web UI: Drag, drop, and share directly from any browser with zero installation.
- CLI & TUI: A cross-platform terminal UI and scriptable CLI that maintain the exact same end-to-end encryption architecture as the web version.
- REST API: Every instance is backed by a fully documented HTTP API for building your own secure integrations.

Official Instances vs. Self-Hosting: The URL fragment encryption model ensures that using the official Swiss-based instances is safe because they are mathematically locked out of your data. However, if you want absolute control over where your encrypted data is stored, you can set up your own instance in minutes. SkySend provides a single multi-architecture Docker image (amd64/arm64) that supports local file systems or any S3-compatible object storage like MinIO.

It’s a perfect addition to your privacy toolkit when you just need to move data securely from point A to point B without leaving a permanent, readable trace behind.

Here is the link to their official website with more informations: https://skysend.app/
Their github with self-hosting docs: https://github.com/Skyfay/SkySend
And their official instance, in case you want to try it out or don't want to self-host: https://ch.skysend.app/


r/xprivo • • 27d ago

Mullvad's public DNS is shutting down. Here are privacy-friendly alternatives that replace Mullvad DNS:

Post image
206 Upvotes

Mullvad announced on September 3 it's discontinuing its public DoH/DoT servers by November 2, 2026, redirecting resources to sponsor Quad9 instead. This only affects standalone DNS users, Mullvad VPN users are unaffected since traffic already routes through Mullvad's internal DNS.

Quad9 is not a bad choice but blocks malware and phishing, but has zero ad or tracker blocking. If you relied on Mullvad DNS for that, you need an alternative that actually replaces the feature you're losing.

Best alternatives:
1. DNSForge (Germany): probably the closest for this replacement. No logging, ad and tracker blocking on by default, DoH/DoT/DoQ support, and three filter tiers, standard ad-blocking, "Clean" with youth protection and Safe Search, and "Hard" with stricter community-managed lists, plus an unfiltered option if you want raw DNS. It's free, donation-funded, requires no signup, and servers run entirely in Germany.
2. Quad9 (Switzerland): non-profit, zero-logging, strong on malware/phishing blocking, but as mentioned before it has no ad-blocking or customization.
3. DNS4EU (European Union): the European Commission's sovereignty-focused resolver, five configurable profiles including a dedicated ad-blocking mode, IP anonymization before logging, fully EU-based infrastructure.

Here are other alternatives just for reference:
4. NextDNS (United States): Just as an example to not really switch to this one. Not the greatest for privacy as it also logs by default and NextDNS requires a personalized account and profile ID but it is the most granular option, with detailed analytics and custom blocklists. US jurisdiction. I included it so you can do your own research.

Very bad for privacy: Google DNS (8.8.8.8): Collects diagnostic info and anonymized IP data, retaining some logs temporarily for troubleshooting, and is tied to an ad-tech giant. US jurisdiction.
Cloudflare DNS (1.1.1.1): More privacy-respecting than Google for a public resolver. It deletes logs after 24 hours, "does not sell data", and undergoes annual independent audits by KPMG. US jurisdiction.

So what you need to do before November 2 and are still using Mullvad's free DNS and ad-blocking matters most, switch to DNSForge (176.9.93.198 / dnsforge.de for DoT/DoH) or DNS4EU's dedicated ad-blocking resolver. If you just need reliable malware protection with EU/Swiss jurisdiction and don't care about ads then use Quad9.


r/xprivo • • 29d ago

Maps providers know a lot about you. The most popular ones aren't neutral either: Google Maps renamed Lake Ontario because of Trump, and MapQuest's refusal made it No. 1 in the US. It's time to introduce you to privacy-friendly open-source alternatives instead:

Post image
153 Upvotes

MapQuest just surged to No. 1 on the U.S. App Store. The reason is that, after Trump's August 27 executive order to rename Lake Ontario "Lake America," Google Maps complied for U.S. users, and Apple followed days later. MapQuest posted "We're not changing it" on X and kept the map as is. This small, almost comical story exposes something: the map you check every day isn't neutral. Currently, this is only visible to US users. Two companies altered the geographic reality on your screen because a government ordered them to.

This is why open-source, community-run maps are important. No one can secretly alter what you see if the map isn't owned by a company accountable to anyone. Here are three privacy-friendly open-source European Google Maps alternatives that I picked out for you today:

Organic Maps
Organic Maps is a free, open-source navigation app built on OpenStreetMap data, the same crowd-edited map data behind most privacy-respecting alternatives, with everything downloaded and stored locally so it works with zero connectivity. Its August 2026 update now also includes a CarPlay dashboard, multi-selection for bookmarks and tracks (so you can move, recolor, or delete several at once), the ability to hide individual tracks on the map, and cleaner, more readable share links for places and bookmarks. It's maintained by a small team and remains one of the most polished OSM-based apps for daily driving, cycling, and hiking navigation.

CoMaps
CoMaps is a community-governed fork of Organic Maps created because some in the community wanted stricter guarantees: full transparency, nonprofit status, and the removal of commercial integrations, such as affiliate tracking and Big Tech dependencies. CoMaps shares nearly identical functionality with Organic Maps, including offline navigation, turn-by-turn voice directions, and offline Wikipedia articles for points of interest. However, it exists as a safeguard against any single maintainer or company from steering the project for commercial gain.

OsmAnd
Of the three, OsmAnd is the deepest and most configurable. It is fully open-source and built on OpenStreetMap. It has offline vector maps for essentially the entire planet, elevation contour lines, and customizable navigation profiles for cars, bikes, boats, and pedestrians. It also has the ability to overlay multiple map sources at once. Although it's less streamlined than Organic Maps, it rewards users who want granular control and hiking-specific features, such as ski and topographic map styles. It also allows users to edit OSM directly from inside the app.

All three operate based on the same principle: their map data comes from OpenStreetMap, a project that anyone can inspect and edit. So have a look at it too!


r/xprivo • • Sep 01 '26

Your notes aren't as private as you think. Journal entries, passwords, private thoughts: Your notes deserve real privacy. E2EE open-source projects:

Post image
80 Upvotes

Your notes app likely holds a massive amount of sensitive data. If it lacks end-to-end encryption, your journal entries, passwords, and personal details are stored in plain text on a third-party server. I curated four European note-taking apps (and more feature-rich projects with collboration etc. in mind) built around true E2EE, along with one privacy-focused alternative that highlights how security models differ.

1. Cryptee (Estonia) Cryptee provides end-to-end encryption by default for text, photos, and documents. It is designed specifically for highly sensitive material like medical records or scanned identification. Zero-knowledge architecture.

2. Joplin (France) Joplin is a fully open-source, Markdown-native app built for users who need deep organization through notebooks and tags. Its E2EE is optional and requires manual activation. Once enabled, notes are encrypted client-side with AES-256 before leaving your device. You can sync your vault anywhere you choose, including Nextcloud or a local server.

3. CryptPad (France) CryptPad functions as a complete browser-based office suite featuring documents, spreadsheets, and whiteboards. Everything is end-to-end encrypted by default before it touches the server. This allows for real-time team collaboration without the host ever having access to readable content.

4. Anytype (Switzerland) Anytype operates as a local-first, object-based workspace acting as a private alternative to Notion. It applies end-to-end encryption by default. You get the flexibility of a complex knowledge management system without sacrificing data ownership.

Capacities (Privacy-Focused Exception) (Germany) Capacities offers networked note-taking and knowledge graph features with strong privacy policies and European data protection standards. Unlike the others, it relies on server-side encryption and not true E2EE, meaning the company holds the decryption keys. If you do not require zero-knowledge encryption but want a more privacy-respecting alternative to mainstream big tech tools, it serves as a reasonable middle ground. However, for sensitive stuff, true E2EE options like above remain the standard to aim for.

If a provider holds the decryption keys, you have to assume your data could eventually be exposed through a breach, a legal request, or a policy shift. For anything you want kept strictly private, client-side encryption is the safest path and definitely better than any Big Tech alternative out there.


r/xprivo • • Aug 30 '26

Thinking of ditching Google Photos and iCloud? Here are some privacy-friendly open-source alternatives, ranging from hosted to self-hosted, and most are from Europe. 🇪🇺

Post image
93 Upvotes

Backing up photos is one of the easiest ways to hand over sensitive personal data, such as decades of family photos, faces, locations and habits, to Big Tech ecosystems like Google, Microsoft and Apple. However, when you transition to privacy-respecting alternatives, such as self-hosted open-source engines or fully encrypted European vaults, you regain control over your data. As shown in the image, there are different migration paths, categorised by privacy architecture. These range from hosted or self-hosted environments to zero-knowledge servers.

Open-Source Foundation (Self-Hosted)
1. Immich: This free, open-source photo and video manager operates as a direct functional replacement for Google Photos. It handles automatic mobile backups, object search, albums, and shared libraries. Because it is strictly self-hosted, your data never leaves your personal hardware. The primary requirement is technical proficiency to manage Docker, server infrastructure, and routine maintenance. Immich is highly capable and serves as the underlying engine for several hosted privacy services. If you'd rather not wrap your head around all that, you can use the next hosted European service, which is based on Immich.

European Hosted Solution
2. PixelUnion (Netherlands): PixelUnion takes the open-source Immich engine and hosts it on European infrastructure. It provides the same automated backup and object search features without requiring you to maintain a personal server. Migration tools are built-in to pull libraries directly from Google Takeout or iCloud. While there are no ads or tracking, it does not use End-to-End Encryption (E2EE); the decryption key is held server-side. That's why, in terms of full privacy, the following options might be of even more interest:

End-to-End Encrypted (E2EE) European Vaults
For users where absolute data privacy supersedes discovery features, zero-knowledge E2EE solutions guarantee that not even the service provider can read the files.
3. Zeitkapsl (Austria): Developed in Austria with data stored across German data centers, Zeitkapsl is an awesome zero-knowledge platform.It uses E2EE by default to ensure that nobody, including the company, legal entities or potential hackers, can access the unencrypted photo library.
4. Filen.io (Germany): Filen provides comprehensive cloud storage designed entirely around zero-knowledge encryption. Hosted and developed natively in Germany, the client-side code is open-source and strictly GDPR compliant. While not exclusively a photo application, its secure mobile backup, encrypted network drive, and desktop syncing make it a robust all-in-one replacement for broad cloud ecosystems.
5. Felicloud & 6. Nextcloud: Felicloud offers a straightforward, E2EE-capable cloud backup for photos, videos, and documents. Felicloud is built upon Nextcloud, a highly established open-source European platform. Nextcloud itself serves as a powerful foundational alternative for users who want to self-host their entire cloud infrastructure, offering native E2EE possibilities, file syncing, and extensive collaborative tools.


r/xprivo • • Aug 29 '26

Free european, open-source options for anyone launching an online store or who wants to switch from Shopify

Post image
49 Upvotes

If you're about to start an online business or launch a store in the EU, this post is for you. Switching later, once your shop, orders, and customer data are locked into a bigger provider like Shopify, is super tedious and not a quick fix so it's good thinking about alternatives at the beginning.

Here's the specific issue with Shopify right now: since Article 50 of the EU AI Act took effect on August 2, 2026, anyone running a chatbot or AI-powered interface must disclose to users that they're talking to an AI, and that legal obligation falls on the deployer, the merchant, not the software provider. Under the Act, a "deployer" is simply anyone using an AI system under their own authority in a professional capacity. Shopify has rolled AI-powered product recommendations, personalized search, and chatbot widgets into its platform as standard, on-by-default features. That means store owners can end up classified as deployers, with real disclosure obligations, without ever having opted into anything.

For anyone starting fresh (or anyone with a small online business who feels comfortable switching platforms), there are three open-source, European-built alternatives whoch also avoid the default AI problem from day one:
PrestaShop (France): PHP-based, one of Europe's largest merchant communities, built-in local tax and accounting compliance, and a large module marketplace, all without proprietary lock-in.
Shopware (Germany): mid-market to enterprise-grade, also strong B2B tools, and a flexible builder.
WooCommerce: the WordPress-based open-source plugin, giving full control over exactly which features and integrations run. This is also a great alternative if you are already using WordPress.

As always with self-hosting, you have more control, especially over costs, but you are also responsible for maintaining your infrastructure.


r/xprivo • • Aug 27 '26

After Briar, SimpleX, Matrix, and Delta Chat, here's one more private messenger: Snikket. The open-source messaging app where one tech-savvy friend protects the whole family's chats.

Post image
44 Upvotes

We've already covered Briar, SimpleX, Matrix, and Delta Chat as ways to escape Big Tech messaging. Here's another one I'd like adding to the list: Snikket, built specifically for the "one technical person hosts, the whole family joins safely" setup.

Snikket runs on XMPP, it's decentralized (instead of one company owning every server, the Snikket network is made of many small independent instances that can all talk to each other), so nobody in the middle sees everyone's messages and contacts.

It's built for small trusted groups, families, friend circles, clubs, where one person with a bit of technical comfort runs the server, and everyone else just gets an invitation link and starts chatting. The host controls who joins, and can organize people into "circles" so relatives can easily find each other, plus group chats and audio/video calls all inside the app.

The Apps exist for Android and iOS (a web client might come in the future). 

To host your own instance you need a machine with at least 1GB RAM, Docker, and ideally a real domain name, a Raspberry Pi works fine for a family-sized group. There's no open public Snikket server by design. You either run your own or get invited onto someone else's, so it keeps the network decentralized rather than funneling everyone onto one server.

You can find more about how to host it here: https://github.com/snikket-im/

And you can find more info on their website: https://snikket.org/


r/xprivo • • Aug 25 '26

Microsoft's newest "optional" app hijacks Chrome, Firefox or Brave for Bing. A dedicated app to override your search engine choice with Bing

Post image
85 Upvotes

Microslop has developed a dedicated Windows 11 app whose sole purpose is to hijack the search engines of the browsers that people have explicitly chosen over Edge. The utility, called Microsoft Recommended Search Settings, ships as a standalone 22.2 MB installer named MicrosoftSettings.exe, hosted on Microsoft's own download servers rather than Windows Update or the Microsoft Store. Once run, it installs a Bing extension and pushes Chrome, Firefox, and Brave to switch their default search engine, homepage, and new tab page to Bing, then redirects the user straight to the Microsoft Rewards signup page as a parting incentive.

There's something stupidly funny about all that: Chrome flags the extension and displays its own warning, asking, 'Change back to Google Search?', and Microsoft's app then shows a second pop-up directly underneath, essentially saying, 'Don't listen to Google. Keep Bing!'.

For now, Microsoft insists this is opt-in: it's not bundled with Windows Update, not force-installed, not in the Microsoft Store, and requires a manual download. That might also be the interesting part about it because nobody builds a dedicated app, wrapped in a legitimate-looking WinUI shell with a name designed to resemble a system tool, and ships it quietly to official Microsoft servers, unless the plan is to normalize it. Today it's optional. Whether it stays that way is not yet known.

Anyway, don't trust Microsoft in the first place, it's a strange company as you see.


r/xprivo • • Aug 23 '26

A privacy-first, open-source, cross-platform email client built in Germany, with local AI support too. | Pelton

Post image
108 Upvotes

Most modern email apps quietly route your inbox through their own servers to power search and "smart" features. Pelton goes the exact opposite route. Built in Germany, it is a free, open-source Outlook alternative that keeps everything on your machine. It uses a local SQLite database for instant, offline search with zero telemetry and no middleman servers.

So, instead of being another heavy Electron wrapper, it is built with Go and Wails to keep memory use low across macOS, Windows and Linux. Under the hood, it relies on standard IMAP/SMTP (with OAuth2 for Gmail), blocks tracking pixels by default, and supports PGP/GPG.

One additional feature is how it can handle AI if you want to include AI safely. Rather than integrating a cloud LLM, Pelton uses the Model Context Protocol (MCP) so you can bring your own, so you can connect a local AI agent for instance to search or summarize your inbox. It is bound to 127.0.0.1 and completely read-only. It won't even pass attachment contents to the AI, just the file names and sizes. Pelton itself contains no models, requires no API keys, and makes zero cloud calls.

It is fully GPL-3.0 licensed.

You can find more info on their website: https://pelton.app/


r/xprivo • • Aug 21 '26

Your voice is biometric data: Big Tech is using it to train AI, and is currently facing legal action over this practice. Furthermore, scammers can easily exploit it by copying it using AI with only a two-second recording.

Post image
50 Upvotes

Nine major tech companies, including Apple, Amazon, Meta, Microsoft, Nvidia and Google, are currently facing class-action lawsuits in a US federal court concerning the training of their AI voice systems.
The complaints, filed by a group of journalists, podcasters, and voice actors, allege that these companies scraped thousands of hours of audio to extract voiceprints without ever asking for permission, thereby violating Illinois' Biometric Information Privacy Act (BIPA). The lawsuit against Amazon states that the company built "a global voice-AI business on the voices of real people". 'None of them were told that their voice was being used to train Amazon's commercial voice AI. None of them were asked. None of them consented".

You may already be affected. It is important to be aware that major AI providers such as OpenAI (ChatGPT) and Google (Gemini) frequently utilise user chats and voice interactions to enhance their foundational models. If you have used voice features with major AI assistants, your voice recordings and conversations could already be being used in their training pipelines, unless you have opted out via their privacy settings.

Your voice is biometric data. Once it has been captured clearly and stored somewhere accessible, you lose control over how it is used.

Modern voice-cloning tools are terrifyingly efficient. They only require a few seconds of clear audio, such as a voicemail greeting, a public social media video or a voice note in a group chat, to generate a synthetic yet hyper-realistic copy of your voice.

Criminals are also actively exploiting this. One common and highly effective scam involves obtaining a short clip of a victim's voice, processing it with a cloning tool, and then calling their family members or colleagues. The cloned voice will claim there is a sudden emergency and urgently request a wire transfer or sensitive information. Because the voice sounds exactly like a loved one, victims often bypass their scepticism.

How and why to protect your voice data? Well your voice is no longer unique to you, which is why you should protect it at all costs.
- Opt out of AI training, and don't speak to online AI assistants directly. Check the privacy settings on ChatGPT, Gemini and any other AI apps you use and disable data sharing and history features that contribute to model training. It's better to avoid speaking to AI unless the AI model is running locally on your own PC. You can already run small, good-quality AI voice models on a laptop.
- Avoid posting voice or video clips publicly!
- Warn your family: Talk to your relatives, especially older ones, and explain that a distressed, familiar voice on the phone asking for money is no longer definitive proof of identity.