The Privacy Iceberg

This is original content. AI was not used anywhere except for the bottom right image, simply because I could not find one similar enough to what I needed. This took around 6 hours to make.

Transcription (for the visually impaired)

(I tried my best)

The background is an iceberg with 6 levels, denoting 6 different levels of privacy.

The tip of the iceberg is titled “The Brainwashed” with a quote beside it that says “I have nothing to hide”. The logos depicted in this section are:

The surface section of the iceberg is titled “As seen on TV” with a quote beside it that says “This video is sponsored by…”. The logos depicted in this section are:

An underwater section of the iceberg is titled “The Beginner” with a quote beside it that says “I don’t like hackers and spying”. The logos depicted in this section are:

A lower section of the iceberg is titled “The Privacy Enthusiast” with a quote beside it that says “I have nothing I want to show”. The logos depicted in this section are:

An even lower section of the iceberg is titled “The Privacy Activist” with a quote beside it that says “Privacy is a human right”. The logos depicted in this section are:

The lowest portion of the iceberg is titled “The Ghost”. There is a quote beside it that has been intentionally redacted. The images depicted in this section are:

  • A cancel sign over a mobile phone, symbolizing “no electronics”
  • An illustration of a log cabin, symbolizing “living in a log cabin in the woods”
  • A picture of gold bars, symbolizing “paying only in gold”
  • A picture of a death certificate, symbolizing “faking your own death”
  • An AI generated picture of a person wearing a black hoodie, a baseball cap, a face mask, and reflective sunglasses, symbolizing “hiding ones identity in public”

End of transcription.

  • recklessengagement@lemmy.world
    link
    fedilink
    arrow-up
    167
    arrow-down
    1
    ·
    1 year ago

    I think this is the first time I’ve seen an iceberg meme with sources and explanations for each item. Fantastic. Your work is appreciated.

  • nossaquesapao@lemmy.eco.br
    link
    fedilink
    arrow-up
    127
    ·
    1 year ago

    Funny how you need more and more technical knowledge to go deeper into privacy, until the last level, which is basically giving up on technology itself.

    • The 8232 Project@lemmy.mlOP
      link
      fedilink
      arrow-up
      51
      arrow-down
      1
      ·
      1 year ago

      “As seen on TV” does not imply privacy, it just implies a large advertising budget. These are software that market themselves as private (and are sometimes better than nothing at all) but may still be just as bad as software on the tip of the iceberg.

    • zarkanian@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      1 year ago

      A man holds a laptop computer as cyber code is projected on him in this illustration picture taken on May 13, 2017.

      Did AI write this?

  • mmhmm@lemmy.ml
    link
    fedilink
    arrow-up
    64
    arrow-down
    1
    ·
    1 year ago

    I was at the bike shop a few weeks back and a ghost walked in. He came in wearing a medical mask covered by a bandana, sunglasses, cap. They wore gloves, long sleaved pants and shirt.

    First question from staff, ‘this a robbery?’

    Ghost, ‘no, I just need 27 2.5 tubes, miss.’

    They get the tubes, he agrees. Staff asks if he has an account. Ghost says, “nope, why would I need one?” Staff says they do it for records, insurance claim assist, and discounts. Ghost goes with a John Doe, pays cash and peaces the fuck out.

    Total King, but dude was given up a lot. Half of us were drinking beers enjoying a warm evening in spring. I hope he has had some good rides.

    I can say with confidence thay he was a white male. In his 50s. About 5’10". 140 lbs-ish. If anyone wants to get any tips, good luck!

  • 𝕨𝕒𝕤𝕒𝕓𝕚@feddit.org
    link
    fedilink
    arrow-up
    36
    ·
    1 year ago

    I have no clue why telegram is often mentioned when it comes to “privacy focused messaging”. They don’t even have e2e encrypted group chats. Only 1:1 chats may be encrypted as an opt-in. Even WhatsApp is more secure than that, since they use signals encryption.

    Also the “we don’t give out even a byte of data to anyone” statements made by telegram have been thoroughly debunked as lies. When telegrams bottom line is in danger, they have and will give out your data.

    • Bazoogle@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      1 year ago

      Yea, telegram being advertised as a privacy messenger is a joke. If people want to have group chats like in discord and don’t care about privacy, whatever. But to try and flaunt how privacy focused you are while using your own home-brewed encryption is a joke. Not to mention the fact you have to turn it on for every chat you want end to end encrypted.

      The whole thing about not giving out data is really only accomplished by spreading user data across several countries. So you would have to get a search warrant from every country to get the data, relying on some countries not wanting to cooperate with other countries. That is not real security. Real security would be encrypting it so you literally couldn’t give them the data, even if they had a search warrant. Ya know, like signal.

      • SirPea@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Even Threema is more secure than Telegram, this iceberg is messed up and missing a lot of things and some inconsistencies. You could say it’s not free but so isn’t mullvad and it’s in the iceberg.

    • ReversalHatchery@beehaw.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      1 year ago

      well that section has a few not so effective services, like authy, and imo brave and adblock, to depict what people believe at that point. and telegram probably gets to be there because it’s not the usual big tech companies, and it seems fine, even if unencrypted.

      Only 1:1 chats may be encrypted as an opt-in.

      and only on the phone app

      • The 8232 Project@lemmy.mlOP
        link
        fedilink
        arrow-up
        9
        arrow-down
        1
        ·
        1 year ago

        well that section has a few not so effective services, like authy, and imo brave and adblock, to depict what people believe at that point.

        Yes, this is the exact reason Telegram was put there. I even see Telegram recommended alongside Signal, despite the privacy risks.

    • Undertaker@feddit.org
      link
      fedilink
      arrow-up
      4
      ·
      1 year ago

      WhatsApp claim to use this. They do not show their code nor did they do any kind of audit. Therefore we have to assume that there is no encryption.

      • ReversalHatchery@beehaw.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        or that some part of the encryption, like key handling is flawed. also, considering they have an RCE vulnerability every year, I wouldn’t be surprised if the encryption keys could just be stolen remotely.

        we also don’t know if facebook has implemented some kind of analytics for message content, sent files and media.

    • JiminaMann@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      Just curious, does telegram keep a log of our msgs? Im guessing right now, mitm attacks doesn’t work since tls exists, but telegram can still read the msg cuz it’s not e2e?

  • neuroneiro@lemmy.world
    link
    fedilink
    arrow-up
    34
    arrow-down
    2
    ·
    1 year ago

    Was going to say links or it never happened but you provided them! And categorized by level! Excelsior!

    Thanks also to the comments giving more information.

    So grateful for this platform. For the most part.

      • wolfinthewoods@lemmy.ml
        link
        fedilink
        English
        arrow-up
        6
        ·
        1 year ago

        So what’s the deal with i2p? I heard it was a more secure alternative to vpns, I downloaded it but I haven’t been motivated to figure out how to set it up on Linux.

            • swelter_spark@reddthat.com
              link
              fedilink
              English
              arrow-up
              3
              ·
              1 year ago

              In some ways I2p is more secure, but it has its own pros and cons. It’s primarily used with services & sites within its own network, similar to onion sites, and used that way it’s said to be faster than Tor. It can be used for torrenting with a client that supports it, like qBittorrent or BiglyBT, without harming the network. There are outproxies you can use if you want to anonymize access to normal websites, but there’s only a few of them, and it’s slow. You can have it and Tor running at the same time without them interfering with each other, though.

              • wolfinthewoods@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                ·
                1 year ago

                So, it sounds like you’d be better off just running Tor or a vpn unless you have a specific use-case for i2p. I looked briefly at the install instructions, but it seemed to be like it would be a hassle to initially setup on my linux build.

                • swelter_spark@reddthat.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  1 year ago

                  I think that would be fair to say. I mostly run it to contribute to the network, so that other people can communicate or share files more privately. (On OpenSuSE, it can be installed from the repo and just run with no special configuration.)

            • sploodged@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              3
              ·
              1 year ago

              as a darknet it’s more secure than tor, but less people use it so less anonymous. the benefits are really for using in-network services there, not so much for accessing the clearnet, though you’ll find clearnet things bridged to i2p

                • sploodged@lemmy.dbzer0.com
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  1 year ago

                  to remain secure from outside observers is the main goal, the i2p network is much more secure than tor or a vpn, though it does a good job protecting you from others on the network too.

  • jagged_circle@feddit.nl
    link
    fedilink
    English
    arrow-up
    31
    arrow-down
    2
    ·
    edit-2
    1 year ago

    I give workshops on privacy. I always tell them that if they get nothing else out of my presentation, its that they should use a password manager.

    Honestly I think keepass should be beginner. That comes first before everything else.

    Also I think Tor Browser should come before VPNs. Its free and easier to use than VPNs (for when you want to google something secret and don’t want to be tracked. Most beginners are selective like that)

    • Bazoogle@lemmy.world
      link
      fedilink
      arrow-up
      8
      arrow-down
      1
      ·
      1 year ago

      Why keepass and not Bitwarden? Wouldn’t bitwarden be more user friendly for trying to ease people into secure technologies?

      • jagged_circle@feddit.nl
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        1 year ago

        Bitwarden had some security issues historically. I generally recommend using software for password managers that isn’t internet connected.

        My keepass trainings involve generating a veracrypt encrypted USB drive (for windows and Mac users) for storing a backups of their keepass file. I also recommend they upload it to whatever cloud storage they use (google drive or iCloud usually)

        • Bazoogle@lemmy.world
          link
          fedilink
          arrow-up
          5
          ·
          1 year ago

          Bitwarden had some security issues historically.

          What security issues? If you mean potential security vulnerabilities researcher found that they’ve patched, I don’t understand how that would be different from Keepass and their previous security vulnerabilities. Bitwarden has never had a security issues historically that I know of. Lastpass, on the other hand…

          I generally recommend using software for password managers that isn’t internet connected.

          I also recommend they upload it to whatever cloud storage they use

          I also really don’t get these two. They seem to contradict each other.

          I usually recommend bitwarden, where they can use the browser extension and mobile phone app. It gives them autofill features on all their sites. Getting someone to change their passwords and use a password manager is already difficult enough. Giving them the most convenient option is going to make it more like they stick with it.

  • LeTak@lemm.ee
    link
    fedilink
    arrow-up
    28
    ·
    1 year ago

    Tried the Privacy Activist and Enthusiast section. Was not really fun and you loose connection to most of your friends and family. Now I have a balanced setup with something out of each layer. Perfect balanced, as things should be

  • ISOmorph@feddit.org
    link
    fedilink
    arrow-up
    22
    ·
    1 year ago

    Can you explain why you would think Steam is so bad? I would argue they’re pretty fair, especially with the option to buy steam cards for cash to not disclose your personal data. Does the client do some unsavory shit?

    • lazynooblet@lazysoci.al
      link
      fedilink
      English
      arrow-up
      21
      arrow-down
      1
      ·
      1 year ago

      Seeing steam at the top makes me question the list. Likely a hate of DRM rather than privacy

      • lb_o@lemmy.world
        link
        fedilink
        arrow-up
        32
        ·
        1 year ago

        Yeap, and Brave in the middle. They only pretend they are for privacy, but they are the very opposite.

        • dogs0n@sh.itjust.works
          link
          fedilink
          arrow-up
          18
          ·
          1 year ago

          Yeah i hate when I see people using Brave, because they have been brainwashed.

          Does anyone remember when they were injecting their own referral links into links for online stores (99% certain they did this pls prove wrong if you know better)? This alone leaves them with 0 trust in my books.

          • const_void@lemmy.ml
            link
            fedilink
            arrow-up
            11
            ·
            1 year ago

            Brave is and always has been gross. Never understood how they’ve been so successful at tricking people into installing it.

            • SirPea@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              3
              ·
              edit-2
              1 year ago

              OP replied in another comment its because “firefox is not secure” https://lemmy.dbzer0.com/post/43710170/18564861 :

              […] Chromium-based browsers aren’t all bad, such as Vanadium or Trivalent, so people sometimes feel more comfortable sticking with what seems familiar (coming from Chrome).

              In another reply parents to this one:

              LibreWolf is far from secure, as it is based on Firefox and so comes with the same security issues. If you meant to say privacy and not security, the reason nobody makes high threat model browsers for Windows is because Windows itself is not private and it would be a losing battle.

              So OP is saying it’s not private nor safe? I get what some people are saying of Firefox constantly changing Terms of Services but that’d be in regard to privacy not security and OP tries to argue not being safe which his iceberg also implies in terms of privacy not being good too. Yeah, LibreFox’s ToS isn’t the same as Firefox’s ToS and his counterarguments to Firefox and Firefox-based on replies is Chrome-based browsers exclusive to niche OSes (also OP don’t even try arguing Brave on comments so probably just trying to rage-bait with every opportunity). I’d love OP to argue using the examples he used in the iceberg. So many discourse incosistencies along with the iceberg. Also OP FYI while privacy does not mean secure, lack of privacy could mean security risks in some cases.

        • MajesticElevator@lemmy.zipBanned
          link
          fedilink
          arrow-up
          2
          arrow-down
          3
          ·
          1 year ago

          They’re not the very opposite. They have done wrong things, just like Mozilla. Doesn’t make them Google though.

            • MajesticElevator@lemmy.zipBanned
              link
              fedilink
              arrow-up
              1
              arrow-down
              1
              ·
              1 year ago

              That’s not what I wrote

              Also, please stop with the Mozilla praise

              You seem unaware of the bullshit they do. They’re not clean at all.

        • shneancy@lemmy.world
          link
          fedilink
          arrow-up
          0
          arrow-down
          3
          ·
          1 year ago

          and then Tor so high up, unless you’re hell bent on leaving 0 traces that thing is a pain to use, can’t have it maximalised, pages load sometimes minutes at a time, no addons, just suffering. nobody sane uses that thing for more than the occasional trip to whatever deep web market is not yet exit scamming

      • Nalivai@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        Their bottom line is gold, this should tell you everything you need to know about the creator of the meme.

        • antbricks@lemmy.today
          link
          fedilink
          arrow-up
          0
          ·
          1 year ago

          it also has a log cabin… and Log Cabin is a maple syrup brand… and maple syrup is from maple trees… and maple leaves are on Canadian flags… so… a snowman?

      • shneancy@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        1 year ago

        i don’t think valve does much with the data even internally. if they did at least the game recommending queue would be slightly accurate. instead i have to manually blacklist tags for it to stop showing me things i’m just deeply uninterested in. like yes Mr. Valve my steam library of RPGs, puzzle games, and open world sandboxes clearly profiles me as someone who’d be interested in the newest Fifa game every year, sure buddy

    • 9bananas@feddit.org
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      1 year ago

      afaik the client does collect a bunch if data, most (all, i think? but not a 100% on that) of which is opt-in.

      they do need stuff like IPs for internet related features.

      telemetry wise there’s the steam hardware survey, which is opt-in, and it asks every single time it attempts to collect your systems hardware and OS information. this could technically be identifying information, but since it’s opt-in it’s not a privacy violation and it’s entirely optional. (plus it’s super useful for all involved: users, devs, and steam. it’s kind of a win-win and straight up necessary info for devs to know which hardware they should optimize for)

      they might be putting it at the top because steam has native support for DRM?

      but that’s also weird, because DRM isn’t a privacy violation. it’s a shitty practice, barely does anything, barely works, and keeps breaking or hobbling otherwise perfectly good games, all of which is shitty, but it’s little to do with privacy. and the dev has to specifically opt-in and integrate it as a feature…unless they’re thinking of 3rd party DRM that can be waaay more intrusive, like Vanguard… THAT’S a privacy and security nightmare just waiting to blow up in people’s faces.

      otherwise…i haven’t really heard anything bad about steam privacy wise?

      doesn’t mean that there’s nothing to be concerned about, but i feel like there’d been some news about it if there was…

    • lb_o@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      1 year ago

      Agree. Steam doesn’t even save your birthday, and asks for it every time

    • chingadera@lemmy.world
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      1 year ago

      No. And also chrome is somehow at the bottom of this list, I don’t care if it’s chromium or vanadium, it’s still chrome.