IE like Crypto AG:

In 2020, it was revealed that the Swiss company, Crypto AG, which provided secure communications services to ~120 governments throughout the 20th century, was secretly ran by the CIA and West German Intelligence. The CIA and later NSA were able to read encrypted communications for many countries such as Saudi Arabia, Iran, Italy, Indonesia, Iraq, Libya, Jordan and South Korea.

  • HiddenLayer555@lemmy.ml
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 months ago

    All of the “delete my information from data brokers” services IMO, especially the ones that advertise on YouTube. Always smelled fishy to me.

    Either that or they’re just more data brokers trying to get exclusivity.

    • GaumBeist@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      3 months ago

      Reject Convenience did a pretty thorough rundown on what they’re doing: https://www.youtube.com/watch?v=iX3JT6q3AxA

      It’s been a minute since I watched, but my key takeaways were that they just reach out to one type of broker which barely scratches the surface of the Data Economy iceberg, and since there’s no legal precedent outside of California and the EU, it’s purely up to the brokers to decide whether or not they want to comply.

      So I think it’s probably more likely they really are just private companies preying on people’s anxieties about privacy and relative ignorance about the topic, rather than some kind of governmental conspiracy

  • hexagonwin@lemmy.today
    link
    fedilink
    arrow-up
    8
    ·
    3 months ago

    i don’t think anyone here considers it a private service at all, but i’m almost certain cloudflare is a honeypot

      • hexagonwin@lemmy.today
        link
        fedilink
        arrow-up
        4
        ·
        3 months ago

        the biggest part is they’re doing way too much of the internet while being quite opaque. and their service is “too generous”, with free tiers, no ads. and the whole MITMing every traffic and serving from CDN architecture seems ideal for a honeypot to me.

        even if cloudflare themselves don’t intend to be one, i’m pretty sure some three letter agency has backdoors to their systems.

  • GaumBeist@lemmy.ml
    link
    fedilink
    arrow-up
    6
    ·
    3 months ago

    Proxies and VPNs seem like the most obvious targets. They mostly prey on people who don’t understand the technical workings thereof (had my mom ask if she needed to get a VPN bc firefox opened on ad for theirs, claiming it enhanced privacy), and serve little benefit to people who are doing the kind of illegal activities that make governments take notice. They serve as a single point of compromise for anyone, and they work worldwide so that all your traffic can be monitored even when you’re on a different ISP/in a different country. It’s like the perfect MITM, and people are even willing to pay to have themselves monitored.

    The truth is that at best they benefit people who only don’t want their network-provider watching, but don’t care who else may be. It’s the perfect setup for a 3-letter agency to just sit and monitor everything anyone does, waiting for someone who’s just a little too careless to access illegal content thinking they’re anonymous.

    • AlteredEgo@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      3 months ago

      They are perfect for torrenting though. The kind of activity 3 letter agencies don’t want their spying to be disturbed for.

      • GaumBeist@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        3 months ago

        they benefit people who only don’t want their network-provider watching, but don’t care who else may be.

        • AlteredEgo@lemmy.ml
          link
          fedilink
          arrow-up
          5
          ·
          3 months ago

          Just FYI: It’s not the network provide we have to worry about in my country. That is specific to the USA I believe.

          Here they have “headhunters” that make a contract with a rights holder, torrent a file, write down the IP of someone who uploads a video to them, then legally request the name to the IP and send an invoice for about $2000. No three warnings or anything. And they are very good at sending legal officials to impound any of your valuable stuff in case you don’t pay.

          Even other “illegal” activity like calling Israel an apartheid regime or supporting palestine or insulting your head of state might get you flagged by a three letter agency, but they won’t use official legal channels. There is a protection of the herd with VPN.

  • zebidiah@lemmy.ca
    link
    fedilink
    arrow-up
    5
    ·
    3 months ago

    Not a privacy app, but you should definitely not think anything said on discord is private in any sense whatsoever

  • pineapple@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    3 months ago

    Signal and Tor have both received huge amounts of US government funding, very suspicious.

  • Korkki@lemmy.ml
    link
    fedilink
    arrow-up
    4
    ·
    3 months ago

    Signal I think. I don’t mean that the end2end algorithm or messaging itself are itself unsafe, the algo has been shown to be secure. This is what people usually rebuke this with, with the reminder of Signal’s OSS nature.

    The issue the servers and the social networking data that can be harvested. The server code only partially exists in public and we just have to trust that that is actually what is running on whatever AWS server without tampering and self hosting is nearly impossible in practice if technically possible and nobody does it. The social network data (who talks to who) is more valuable than the actual messages logs, which give a massive, but mainly useless datasets. Until LLMs, like 10-15 years ago they were basically impossible to parse for any useful info without using large quantities of eye pairs. Basically if you are an organizer, criminal, government, part of a hunted opposition, you will leak the whole core group structure of your org with attached phone numbers. Whoever with that data can then target their devices and persons with other means. Plus it’s literally built on top of CIA money. I think signal is totally safe and adequate for friends and family type of use, but not much else, but then all in all so is whatsapp, mostly since signal and Whattsapp share the same end to end algorithm.

    • Dessalines@lemmy.mlOP
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      3 months ago

      Signal is def one, otherwise US government orgs like RFA and OTF wouldn’t be defending and pushing for it so hard in western privacy spaces, nor fund it.

    • SteleTrovilo@beehaw.org
      link
      fedilink
      arrow-up
      0
      arrow-down
      1
      ·
      3 months ago

      It’s funny how every poster who criticizes Signal inevitably makes a technical error. In your case, the claim that “Basically if you are an organizer, criminal, government, part of a hunted opposition, you will leak the whole core group structure of your org with attached phone numbers” entirely lacks basis. The Signal client - the OSS part we can and do control - does not divulge phone numbers.

      You have this theory that Signal’s servers are storing communication records. (While there is no evidence to support this, it’s valuable to consider what they could do.) So the data that would be captured here is a network of hashed phone numbers and literally undecryptable messages. It’s impossible for the adversary to determine any phone numbers they don’t already know this way.

      And since you can make a Signal account with a burner phone and create a “username”, even a known phone number becomes useless against targets who don’t want to be identified.

      • pineapple@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 months ago

        The US government could easily force google to put a compromised binary of signal on the google play store.

      • techpeakedin1991@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        3 months ago

        The phone numbers being hashed doesn’t matter because of how small the input space is. A standard phone number is a country code plus 9 digits. If we assume that anybody looking at this information already knows what country the people they’re targeting is from, that means there is 1000 000 000 possible phone numbers to check for any hash. Even if the hash is extremely slow, and takes 1 second to compute on a strong CPU, that still only takes 1000 000 000 / (60 * 60 * 24) = 11574 days, or 31 years to compute on a single core. For any large organization (like, say, any government or any large tech company), getting 1000 cores to run the hashes in parallel would be quite simple, reducing the time it takes to have a complete hash list down to 11 days to get a complete database of all possible hashes. Hashing phone numbers is literally just a mild inconvenience.

        Edit: Actually looking it up phone number formats vary quite a lot by country, but the point still stands.

      • 0_o7@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        3 months ago

        Signal doesn’t run in a vacuum. It’s main distribution platforms are app stores from Google and Apple. And most people are going to use stock smartphones from these two companies to sign up to Signal. But with them being under the same US jurisdiction, matching the two identities isn’t that far-fetched.

        The parent companies of both OS platforms are well known to funnel data and notifications to the US government. It too had no evidence to support it, until they admitted it. There’s a setting for it now, but the person you’re talking to might not be doing the same, so it’s still out for profiling.

        Other thing, they vehemently oppose F-Droid because “f-droid security flaws” bs, even though they can literally host their own repo for it without anyone else building their app. They would control every aspect of supply chain, but they didn’t.

        Besides that, they make it very inconvenient to get it from elsewhere, even though they did the bare minimum to provide a standalone installer, after an outcry. And with those stripped down installers, you have to deal with inconsistent notifications, because no apple/google. And they never ever gave unified push a look. I wonder why? Are they a small indie company with just a couple of devs?

        Signal protocol may be “secure”, but it’s only a part of a bigger picture.

        It’s forced reliance on phone numbers, privacy averted platforms and unwillingness to work with opensource platforms and standards that lets it become decentralized and out of the hands of authoritarian government, leaves a lot to be desired.

        Facebook’s whatsapp also uses the signal protocol, but would you call it private or secure after all that zuck has shown to do? Signal creator literally helped them implement it too. I wouldn’t touch a Facebook product with a 10 feet pole.

        And now he’s helping them again encrypt Meta AI, whatever that means. Why is he working with one of the worst offenders of privacy?

        If that doesn’t tell you these things are concerning, you do you.

        https://lemmy.ml/post/48427945

      • Dessalines@lemmy.mlOP
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        3 months ago

        All speculation. You gave them your phone number (which also means your real identity), so you should assume they have it. And because its a US-based company, it must adhere to US laws including key disclosure laws, which make it illegal for any signal employee to tell you that any US government agency has asked for this information.

        https://en.wikipedia.org/wiki/National_security_letter

        So the data that would be captured here is a network of hashed phone numbers and literally undecryptable messages

        With this data you can build social networking graphs: who is talking to who, and when.

        Also this is all the more suspect when you consider that US military / government agencies like OTF fund signal, and constantly try to push signal in privacy spaces.

        • pineapple@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 months ago

          which make it illegal for any signal employee to tell you that any US government agency has asked for this information.

          That’s funny so this list of government data requests is just meaningless.

          • Dessalines@lemmy.mlOP
            link
            fedilink
            arrow-up
            2
            ·
            3 months ago

            Yep it does. The Obama admin issued ~60 NSLs every single day, and I’m sure the number hasn’t decreased since then.

        • Moovau@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          3 months ago

          They could pull a Lavabit if presented with gag order, but of course, no way to know for sure how they would react.

  • RobotToaster@mander.xyz
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    3 months ago

    Bitcoin.

    Hell, monero is the only crypto I think isn’t a honeypot, since so many exchanges refuse to list it. That could just be how the government wants us to think though 🤔

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      4
      ·
      3 months ago

      It’s not even that Bitcoin is a honeypot, it’s that it isn’t actually private at all, and through good ol detective work a wallet can be connected to a person, as well as their inflows and outflows and what wallets they’re sending or receiving money from.

      • mrmacduggan@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        yeah, the whole point of Bitcoin is literally everyone sees your transaction on there. not very cryptic if you ask me

  • edel@lemmy.ml
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    edit-2
    3 months ago

    Of course, nobody is going to have evidence here, if there was any the cover would be lifted. But one can guess chances here:

    Proton: “Unlikely”… but there is a but. They never cater for the ultimate privacy and they make typical blunders of a company wanted to growth really fast. Now, that they want to be a behemoth in Privacy makes it more vulnerable to requests from law enforcement. Also, law enforcement and intelligence agencies have it easier to penetrate within Proton massive headcount growth.

    Tuta: “Very Unlikely”. The people behind started very young and had a sustainable growth. The people are very visible (unlike Crypto AG) so least likely to be working for an “agency”.

    Mullvad: “Very Unlikely”. I think their story is similar to Tuta (haven´t followed it that much though).

    GrapheneOS: “Very Unlikely”. But in the last year I have raised some minor concerns, but I haven change my rating yet…

    /e/: “Very Unlikely”. I know the dude behind for 2 decades, he wouldn´t. However, /e/ never claimed full privacy and from the beginning says he would comply 100% with “lawful” requests, but it is not a honeypot, not that would make much difference to an intelligence agency if they wanted it.

    Signal: “Potentially”… yes, yes… audited, solid privacy code… but still does not make sense to me many aspects; financially solvent from day one, the extreme unquestioned massive and vast support from launching till today… if i have to bet in all of these providers, this platform would have been my take as potential compromised one. I still use it to communicate with family since I trust better than WhatsApp, but I would not use it for critical journalistic info.

    • beutlin@feddit.org
      link
      fedilink
      arrow-up
      1
      ·
      3 months ago

      Oh what are your minor concerns with GrapheneOS? I heard the head behind it is a little weird and paranoid, but honestly i think you kinda need to be for a project like that.

    • AlteredEgo@lemmy.ml
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      3 months ago

      Signal requires to use phone number, which in many countries is legally required to be tied to your personal identity. Like the SMS provider must have a copy of your id card. You’re basically naked to the CIA when using Signal. Even if not like in the US they presumably mass collect SIM and location correlations for ID. For the life of me I do not understand how anyone can promote that shit.

      So the “honeypot” of Signal is that the mainstream promotes it as IF it was a privacy focused app when it’s very glaringly obviously is not. So the effect is that it prevents market space and attention for other apps actually focused on privacy without requiring ID to sign up. It’s a bit like introducing sterile insects to prevent the spread of unwanted pests (= actually secure communication).

  • IratePirate@feddit.org
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    3 months ago

    Maybe not a honeypot, but definitely too large for my taste by now: Proton. With Mail, VPN, password manager, file storage, AI and whatnot, it’s one ginormous basket to put all of your eggs into, hoping it’ll hold.

    • birdwing@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      3 months ago

      Not to mention Graphite and Pegasus, Israeli spyware.

      When parliaments have to inquire their own spy services, it’s a sign that these spy services must be disbanded, as they are becoming a deep state of their own, intimidating and harassing politicians. After all, if you can’t trust your own politicians, whom can you? And that’s problematic.

      Disbanding those services and prohibiting any secret services from ever forming, would also regain a great deal of trust of society in each other. And that trust in turn, can foster society to advance for mankind.

  • SusanoStyle@lemmy.ml
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 months ago

    Unpopular takes incoming.

    Signal.

    Way too many red flags.

    • Why ask for mandatory phone numbers? You could at least make it opt in.
    • Why we can’t inspect the latest server code?
    • Why not make it easy for people to run their own servers?

    Do you truly believe that a company that wants to preserve your privacy would take this direction?

    And i don’t care how secure the protocol is, how well the code is audited. They can still map your social graph.

    Anyways, because of my threat model, i still use Signal. But if i were an activist i wouldnt touch it.

    More unpopular takes:

    Tor and Mullvad probably compromised too. If a service gets too mainstream, I dont believe for a second that they would let it run without care. They would take it down, or control it.

    Now, these services are still usefull. For example mt threat model is to deny my shit to the big tech. So they are useful if you want to escape data collection for adversiment purposes.

    I don’t think they would burn the reputation of these services for low hanging fruit like selling data for ads.

    • edel@lemmy.ml
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 months ago

      Signal, I agree… it has flags for me in so many ways.

      Tor. Unlikely though. For sure many nodes are controlled and now they are using massive power to unlock the traffic, but was not set up as a honeypot per se, it is now, probably, technologically quite compromised though.

      Mullvad. Funny, your suspicions probably got enhanced when Mullvad makes a browser based on Tor’s. But I still not highly suspect of Mullvad. Quite steady organic growth, profitable, no much pronouncements or catering to certain “targeted” groups… No mayor red flags for me.