Alternatives to Google Products
restoreprivacy.com
restoreprivacy.com
I'm an engineer working on Firefox Platform (Gecko). In the linked blog post, the author recommends Firefox (thanks!) and links to a "privacy recommendations" for it, which include items such as "resistFingerprinting" settings.
I'd like to remind everyone that turning on this setting has far fetched consequences to how you experience the Web. Your dates, timezones, preferred languages will all be masked which will result in weird experiences.
The option is behind a flag and without UI precisely because it is a pretty complex feature, that we didn't iron out yet, and which should be well understood before being used.
It concerns me to see it being references and recommended without any explanation whatsoever.
Of course I'm likely biased because I'm on the receiving end of bug reports from people who experience the Web in weird languages and with wrong timezones because they followed some tutorial that recommended it. :(
I don't want my fonts, plugins, user agent, or detailed HW/graphics features (e.g. canvas/WebGL hash) being known. Those can uniquely identify me according to https://panopticlick.eff.org.
So does your resolution. And that's hard to mask because JS usually needs to know it.
If you're not using the browser fullscreen, chances are that you're using a unique innerWidth+innerHeight.
As unsatisfying as it is, the current best solution seems to be not to care about privacy most of the time, and then take privacy seriously when you do. Whonix is excellent for this.
idk - it seems like that can't be enough?
No offense, but advice like this is useless. It reduces to, "someone I don't know thinks the average person with no special risk factors should think this way about their personal privacy based on who knows what priors."
Different people have different reactions to risk, have different actual exposures to risks, different competencies, and different tolerances for the hassles of opsec. And potential future risks of data slopping about are unknown.
There is no such thing as a "best solution" when talking about this.
What do you mean by this?
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.62 Safari/537.36
Looks fairly generic, I think I'm running a mainstream chrome browser on a mainstream OS.So the site should really only take into account your OS, maybe its major version, and browser version (which changes frequently so trackers can’t rely on that). Or at least not count any that are not used anymore.
I suspect it's partly because these plugins don't function fully in a private window?
I've yet to come across an extension that does something like this so I'm presuming it's not possible via extensions?
Are Mozilla working to make this more granular and let me whitelist individual features on a per site basis?
I'd far rather lose tracking than get the very minor benefit of a (slow loading) web font or en-GB over en-US. Especially if I can opt in the few I trust or need those features.
I remember reading an article about how Richard Stallman interacts with the internet a while back. I remember thinking that it seemed totally insane. But in light of the reality of 2018, I am coming around. The way I see it, I can keep tweaking privacy settings in a browser, or opting out of collection, or doing any number of other things to attempt to protect my privacy, _or_ I could just stop using services that do not respect my privacy in the first place. Perhaps certain aspects of modern life have taken too much, and they need to be abandoned until they are reformed?
One of these you mean?
The difficulty of course is right now it's nearly everyone at it. Too early to say if GDPR will make an appreciable difference, though it seems like it should. So that leaves few choices outside of gnu everything or layers of hacks and browser extensions. I have hope that many services will start being much more careful in what tracking and data they actually need after recent events.
I think this one is no longer working with the newest FF versions, but check back in on it every once in a while.
For Chrome: https://chrome.google.com/webstore/detail/random-user-agent/...
Not as configurable as I'd like, but it gets 25% of the job done.
Time to give the chrome one a look, thanks.
Apple can do it. There's no reason why Firefox can't. And if there is a reason, it should have been dealt with years ago.
--
¹ i just noticed that in Firefox 60, the setting is no longer as hidden as it used to be. Good!
That, and the user is likely used to having less-than-ideal browsing experiences if they run any adblockers. I do agree that the article should outline what the consequences would be for disabling browser fingerprinting; they simply have one sentence recommending it, and nothing else.
Unfortunately most websites don't understand this simple idea and show the cookie notice indiscriminately (or, perhaps, they just all use cookies for tracking in which case the notice should be there).
I’d be so keen for the solution to lie in the browser UX- in the same way as we currently request location information - rather than the current mish-mash of badly implemented, often disingenuous site overlays that have become the modern equivalent of the ‘enter site’ splash screen...
Because when ordinary users ask "what can I do to protect my privacy?" you have two possible answers:
a) "Nothing, you're not smart enough to do this, you're screwed"
b) "These things"
B has a high learning curve, but telling people about it scares them off. If you care about your friends privacy and want to get them past that learning curve, it's better to let them stumble into issues and be there to answer questions.
Or just donate if you can’t do any of those things.
For example, the "best" calendar alternative is Etar which looks to a Github repo. Really? At the very least you could mention Apple Calendar. Is Maps.Me (which uses AdSense) really better than Apple Maps? I'm not a fan of hooktube either - it just further cements YouTube's monopoly.
I think what what bothers me is that "privacy focused" tends to be conflated with FOSS. I'm really thankful for organizations like Mozilla and Signal that are trying to deliver privacy focused applications to real people. However I also think we should recognize Apple-like companies who are also privacy focused without necessarily being FOSS. I think that will help move more non-technical people out of central databases.
This is why, when it comes to privacy, Apple isn't worth consideration. All we have is their word, and that simply isn't enough.
I find this to be an extremely un-compelling position. A relatively small proportion of the general population has the skills to meaningfully look at the code, never mind the time. Moreover, even for someone who is capable, such an exercise quickly becomes non-trivial on an unfamiliar codebase for an app of any complexity.
In many cases there's also no guarantee that the code you're reading is the code that's running.
It's more damaging than that. The bundling of privacy and FOSS advocacy weakens the former. Few without deep technical knowledge is sympathetic to FOSS. The potential audience for a privacy pitch is broader. By bundling the two, however, the technical advocacy community limits the appeal of the former to those supporting the latter. This is an issue because the opponents of privacy rights are not similarly limited. Hence, we find ourselves reliant on Google, Apple, Facebook and Amazon being benevolent dictators, in their services and Washington.
Apple isn't worth consideration if you are willing to put in the effort, or delegate trust, to other systems. If you'd prefer to delegate trust to them, how is that effectively different that FOSS that you haven't examined?
The future looks good if we just continue to implement it the way it should be.
>This is why, when it comes to privacy, Apple isn't worth consideration. All we have is their word, and that simply isn't enough.
Quite a few of the things listed in the article are not open source (some of the map stuff, as an example). Last I checked (several years ago), we only have DuckDuckGo's word for it.
I think the idea is not that these are all trustworthy services, but that no single company has all the data on you.
In fact, the first systems that resisted strong pentesting by NSA were proprietary, shared- or closed-source systems. They shredded everything else. Two are below with another designed like that. The first, safe, kind-of-secure machine that I know of was Burroughs B5000 whose CPU did things like stop overflows, protect pointers, and check function arguments. It was immune to common, root causes of many failures or attacks. OS in a type-safe, high-level language (ALGOL variant). It was a proprietary system whose source was shared with customers. Linux systems still don't have as much code-level security in average case as that proprietary software from 1961. The virtualization solutions in FLOSS still aren't produced as securely as VAX VMM or the separation kernels that followed in 2000's with VMM's layered on top.
http://www.cse.psu.edu/~trj1/cse443-s12/docs/ch6.pdf
http://lukemuehlhauser.com/wp-content/uploads/Karger-et-al-A... (See Layering and Assurance sections especially. Compare to QA practices of favorite FLOSS VM.)
http://www.smecc.org/The%20Architecture%20%20of%20the%20Burr...
https://www.usenix.org/legacy/events/sec04/tech/wips/wips/04... (Nizza uses FLOSS components. This document is just great at describing the architecture they and the proprietary vendors were using with separation kernels. The proprietary offerings contained a lot of problems FLOSS didn't with their 4-12kloc kernels having less code to screw up. User-mode drivers can boost reliability a bit, too.)
You can also use all sorts of runtime tools to see what a binary is doing at runtime, so I imagine it would be pretty easy to see if an application is phoning home, and where home is located, although the data is probably encrypted.
In fact, it might actually be easier for an end user to audit a binary using such automated tools instead of looking at the source code itself. At least with the automated tools, the tools can flag suspicious constructs in the binary that may indicate that it's up to no good, and do so in a way that is more understandable to the end user.
Nowadays, very little of our data solely relies on our own devices, and most of the value of consumer software occurs when data is being transmitted between systems. When your data lives in the cloud, there is almost always a side-channel way to get at your private data that won't be visible in any Git repository: Just go look at it directly.
Meaning that, nowadays, if we're to live any sort of non-Luddite, Internet connected lifestyle, all we have to go on with anybody is their word. If I limited myself to services where inspecting the source code would give me what I need to know about how well my privacy will be protected, without trusting the word of any third parties, then I'd have to let go of email, telephone, and credit and debit cards (and banking in general). Plenty of other things, too, but I think those three paint the picture well enough.
[0]https://www.pcworld.com/article/184520/mozilla_endorses_bing...
DuckDuckGo uses Bing data and respects your privacy more, and probably the best choice for the privacy-conscious.
I doubt Mozilla would recommend Bing over Google again because it's more "pro-privacy."
I'm wondering if you could elaborate on what sorts of things you are trying to find and having trouble with. Perhaps HN could make a few suggestions for how to get more out of your Bing experience.
(The exceptions here are iMessage and phone backups which are E2E encrypted.)
This seems so deliberately wrong that I shouldn’t respond, but I will. Quick and easy synchronization of contacts, calendars, and photos are all features that I appreciate. What’s more, my fearful-of-technology brother tells me how useful they are to him. He mentioned photo sync as a benefit only a few days ago.
Side note: I don't think Apple will ever encrypt iCloud iPhone backups because that would make it difficult to use them (how would you restore an iPhone backup to a new device if your old one was incinerated? Your private key would be gone)
I would never trust Apple because they have consistently lied and cheated me - For instance, they throttled the speed on my iPhone, they hid the fact that my iPhone has more probability to bend and finally, as a cherry on top, they refused to honor warranty for a design flaw of theirs.
When they realized they fault, instead of making a free replacement, they charged me $30 for it.
Given all these experienced with Apple, to my eyes, Apple is no different than Google and I wouldn't trust any word of theirs as they've consistently been exposed time and again lying to consumers. So, I don't know where you got the idea of Apple being "entitled" to be in that list, but I'd say it's the right thing that they aren't.
>pro-privacy alternatives like Apple
I don't believe this. There is no evidence to support this as Apple runs on proprietary code. And you and I don't have access to the source code, so we have no idea what's going on on their servers. Ever wondered how Apple gets its data for its Apple maps? For all you know, they could be collecting your location information to build their database. Isn't that a privacy violation? I work in the Analytics industry, inside an iPhone, using Charles proxy, you'll be able to see random requests hit Apple's servers from time to time. For all you know, this could be info about you. You can't prove it nor disprove it.
I would never dare put all my trust into a single for-profit corporation whose sole goal is to maximize revenues and has been consistently exposed for unethical practices to its customers.
So, hope that answers why Apple isn't exactly a consideration.
[1] http://bgr.com/2017/12/28/iphone-battery-apple-apology-lette...
[2] https://www.theverge.com/circuitbreaker/2018/5/24/17389220/a...
[3] https://9to5mac.com/2018/06/07/class-action-lawsuit-apple-wa...
Consider this: for 90% of the population, that is also true of any FOSS solution. I'm tired of the "you don't have access to the source code" argument. I don't inspect the microcode that runs on my CPU - why should I trust Intel and not Apple? And for a greater portion of the population, that source code may as well be mud.
This article is about alternatives to Google on the basis of privacy. Isn't a company that doesn't base its core business model on mining your data an improvement for a vast majority of users?
Given that alternatives to Google products are largely services rather than software run locally on one's own machine, you're probably right about the partial orthogonality of FOSS here since it can be hard to verify that the remote server is in fact running the software it claims it is, and from a privacy-standpoint it may be somewhat irrelevant (I recall even the FSF said something of the sort).
I am fairly sure that no apple product is mentioned because replacing all the hardware one has just for more privacy is likely too extreme for many. Not to mention that one of the biggest things you can do for your privacy is ad-blocking / cookie cleaning, and apple does not make it easier at all.
Very true. But there is no problem with apple, in fact Safari is first browser that is clearing cookies - ITP(2). I use uBlock Origin on Safari and Private browsing - no cookies at all.
Also, they may work with the US government, even if they say otherwise, and people from both the US and other countries may not like that idea.
How can you trust a single point of failure to "do no evil"?
[0] https://machinelearning.apple.com/2017/12/06/learning-with-p...
Huh? Apple potentially has everything on the device, just as Microsoft does. Maybe they don't touch it, at least intentionally, out of respect (or just prudence). But if I recall correctly, they accidentally logged all Safari URLs for a while.
Which is true. They don't sell the data because they directly monetize it. Same with Google. Google didn't just start doing that one day, that's been their business model since they started doing ads. Apple's business model is selling users devices, which they would jeopardize if they tried to also sell their users' data.
The "Maps (F Droid)" alternative suggested before the Maps.me app is a fork of Maps.Me that doesn't include any tracker/ad. It works pretty well although I've had a few issues logging into my OSM account and it takes a little too long to navigate "up" from a place search. It also features a GPS track recording function that Maps.Me lacks (AFAIK). It's really great and deserves more contributions!
Has several useful functions like being able to pre-download specific countries or parts of specific countries.
Many mapping apps work offline but the way Maps.me lets you specifically pick & choose areas = more user friendly.
It uses Openstreetmaps which I've found to work amazingly well in areas where you wouldn't expect (it has off-road trails in remote areas of Vietnam for example)
via iTunes I can also import gpx tracks (or gpx converted to kml, I forget) for things like mountainbike routes, which works super well.
Google has what I think are the most transparent and user friendly controls for visualizing what personal data is collected, and disabling it (most often per product, for ex. disable location history and YouTube viewing history, but enable personalized ads).
- For most of the products mentioned in the blogpost (YouTube, Search, ...), people can just go to MyActivity [0] and delete any data they want to. They can also disable data collection here. [1]
- Emails received in Gmail are no longer used for advertisement in other Google products, only used for Gmail ads, and features like searching your emails, spam prevention, parsing orders/flights/etc. to display them in the app. Also note that emails received in GSuite ("enterprise Gmail") were never parsed for these purposes. [2]
[0] https://myactivity.google.com/
[1] https://myaccount.google.com/activitycontrols
[2] https://www.nytimes.com/2017/06/23/technology/gmail-ads.html
Important disclaimer: I work at Google [but only voicing my own opinions, as it goes], and only working there because I realize they are doing all they can to respect user privacy.
2. You can't expect every user to know they are logged, or how it's affecting the user, or know how to disable/delete it, can you?
3. How can I verify that you did delete the data about me instead of just hiding from me for viewing it? Alphabet is not belong to public sector. So the simple answer is I can't. If you want me to trust you, don't use opt-out as default.
4. I'm sure you can tell the differences between those alternatives and Google products.
5. It's not that hard to respect some one's data. First, do not collect it! Second, if you have to collect it, tell the owner why! Third, delete it completely while requested.
6. Aggregated data collection and use without permissions adds potential risks to the society. (Cambridge Analytica)
Edit: And you guys are doing deep learning, that's gonna consume lot's of data. Duplex for example, you use anonymous phone call data to train it. The question is, where does that data even come from? I'd blacklist whoever collected the data, even it's collected anonymously.
Everything adds "potential risks". When you talk about risk, you have to give estimates of both the frequency and the criticity, and then compare to the potential benefits. Only then you have all the pieces to take an informed decision, according to your preferences.
They can reduce the risks to a certain level if users were told how they are going to use the data and why before using it. Are they going to do that? No, because that increases the cost, which means less profit, which means shareholders won't agree.
So there comes law.
I don't think this stops Google from collecting your viewing history. If it did, Youtube recommendations wouldn't work at all, because they would know nothing about what I like or don't like. But I'm pretty sure recommendations work regardless of your settings -- meaning you're being tracked.
I happen to like the recommendations, so I don't mind this. But it's a hard problem.
Does that actually prevent the data from being stored on Google's servers? I'd like to believe that the data isn't being vacuumed up regardless of what the user says, so if you're willing to vouch for it then that would mean a lot.
You see, the point is that we, the users, helped to create a mammoth that has an enormous pile of sometimes very intimate data on almost anyone. This in itself is dangerous, regardless of what they do with this data - whether they share it with advertisers and other third parties, the government, NSA etc. or not. Also, the world changes fast. Owners change, governments change. Who is to blame when things end up badly? We are, because we got lured by free unlimited spam-free mailbox, free browser, cheap phone, free analytics, accurate search engine. We like these so much that we gave up critical thinking for a while. But the society as a whole is slowly waking up, hence articles like these (which is quite lacking on several points BTW.)
A breach would be a security issue, not a privacy issue.
A security issue is where a third party accesses your data stored at Google without Google's permission.
A privacy issue is where a third party accesses your data stored at Google with Google's permission but without your permission.
I guess it's a good reminder that i need to change services
Sometimes the ads it gives me are so relevant I actually click on them and I'm glad I did!
I just have a better experience where I'm constantly delighted by Google anticipating what I want because it knows so much about me.
I should be paranoid, I know, but I just like the convenience so much.
Things can get tricky if they pop up (thorough bad luck or as a consequence of their actions) on the radar of someone that wants to make their life miserable or if they bother someone with power.
Otherwise I assume you're well off financially by now, so getting screwed on insurance should be a non-issue. Discrimination is likewise a non-issue.
In general money helps and being a US citizen, straight, not muslim, healthy, male etc also helps.
E.g. thank to Gmail I rarely use an email application on my computer and use webmail. When I tried out Posteo it was extremely annoying that it logged me out every few minutes and I couldn't get my email. They said this couldn't be changed.
Google really did an excellent job of supply me with services which I want to use. Not just tools which are working well.
BTW, Google doesn't use all its services to sell or personalise ads. Which doesn't mean they don't use them to learn more about you which in turn is used to improve the services so that you them even more.
So as much as I wish I could restore my privacy by leaving Google, I think Google knows me too well that I won't for now.
From a search engine perspective I’ve switched to DuckDuckGo and I’m impressed with how good it has gotten.
With maps I’ve tried various solutions including mapquest, Microsoft, and Apple but nothing comes close to Google Maps.
I switched to DDG over a year ago and it works great for things that are simple lookups to Wikipedia, IMDB etc. When I have an arcane Windows bug, I end up using "G!". Also DDG isn't that great for latest News but the Image search is pretty good.
I set DDG as the default search on my non-techie wife's new PC earlier this year and she has not once complained about the search qualify.
If it's "costs money", we're not planning to change that! We (FastMail) are proudly a paid-only service.
I haven't encountered this with my personal email server nor heard of it from anyone else. I think this might just be an issue with Posteo.
It's easier if you don't try to move all at once. Spend some time looking at different email options and move that. Do calendar later. Get rid of Google Apps on your Android later still. Gradual change is much easier.
Lets me assume, that you're always logged in. Google thanks you for that, much easier to link this browser's history and searches to your account.
Is there actually some real, tangible harm that can come to me from using Google products? Not theoretical stuff, not stuff that is less likely than dying in a plane crash. Something that is actually likely to happen, that will affect me in measurable, negative ways?
I'm really trying to come up with something, and I'm really trying to care.
* actually I don't agree with that last one: ads are a product of Google, and various things like Gmail are products of Google. The latter is paid for with ad viewings rather than currency.
Really, there is no need to redefine "product" to include humans being advertised to and tracked. There was (and I guess is) a thing called "slavery," where humans were bought and sold....my voluntary use of Gmail is not comparable.
Whenever I discuss this topic people seem to almost take pride in giving their information to Google, Facebook and the thousands of other companies they have no clue about.
I think it's cognitive dissonance rearing its ugly head again: those people have tied their identity at some level with the use of the products and an attack on e.g. Google becomes an attack on them.
The concept of fairness also plays a role. Most people feel that Google should get something for providing their services and they also feel that it's ok if they are shown some ads. Fair deal. What they have no idea about is how much data is extracted from them, who it's shared with and for what purposes it's used. But we can be almost certain the answers to those questions is more and more data, more and more parties and more and more purposes, because data is forever.
And yes, real harm can come to you if you are promiscuous with your information. Additional information should be accessible through your favourite search engine. Hint: home invasion.
"So what? I don't have anything to hide."
"So what? They are a big company, surely they won't abuse my data."
"So what? How has Cambridge Analytica affected me?"
And for the ultimate capitulation: "So what? They already have so much data on everyone, you can't avoid it anyway."
Brave new world.
This is not only coming from folks with little understanding of tech, but also from "technologically literate" people who should know better. Sticking your head in the sand is just so damn convenient.
Even a comparatively widely reported privacy scandal like FB's can't seem to sway these folks... apparently because they feel like it hasn't affected them personally.
How do you deal with this kind of attitude?
Or are you talking about me posting stuff on Facebook? Because that's a very, very different thing.
* Propaganda: Because you understand what people need to hear, it’s a perfect tool to influence opinion. Of course, this doesn’t happen in your country (it never does). A recent popular example is the Cambridge Analytica scandal. Thankfully this evil cooperation does not exist any more (by changing its name).
* Reinforcement of monopolies: You need to hit a critical mass to use data effectively. Therefore, big players will have an advantage over competitors and can provide better products. Therefore big players …
* Reinforcement of dictatorships: If things turn bad they turn really bad. User data is gold in the hand of dictators. One reason is that is helps with propaganda, but it also helps to identify resistance. If for some reason your country ends up in a regime, it is going to be hard to get out of it.
* Self-censorship / freedom of speech: There is plenty of evidence, that we constrain ourselves because we know nothing online is anonymous. This also depends on which country you live in.
There must be a plethora of side effects I didn’t think of right now.
You have to decide how “theoretical” these issues are for you. Maybe it is more a thing of “believing” – such as vegetarianism (although we all know eating meat is bad for the environment).
I'd think they'd have an easier time breaking into my house and stealing my computer. By a factor of maybe a thousand.
If you live in the US this may not be a problem now, but you also have to think ahead: courts may not be allowed to obtain your information right now (although that's probably not true if you are in a murder trial), but they might in the future.
And even then, someone close to you could provide that information to the other part: a (soon to be ex) friend of yours downloads all your information* thanks to the new GDPR tools and provides them to the other part.
*: I think this evidence would be admissible in court, since it's not the police the one who obtained evidence with illegal means. But even if it were not directly admissible, parallel construction is also a thing.
I just represented myself in a week long custody trial (I won primary custody, and yes I went up against an attorney), and there were lots of risks involved, but this sort of thing seems to be about the smallest one I could imagine.
I'd like to hear if this has actually happened to anyone anywhere.
* No one can get access to Google's data * Those who can get access cannot harm you
In addition to trusting google not to be evil. What are your assumptions that lead you to that conclusion?
Or are you assuming that no matter who has access to your data, there is no one could ever do any harm to you with that data? (That's the 'I have nothing to hide' argument)
Maybe it's more about will than can if you're a bit more pragmatic? Anyone on the street can harm you, but not many will....
Meanwhile, why should I trust that that guy living on the sidewalk won't jump up and bash my head with a hammer? Or that the person driving the car in the opposite lane won't swerve into my lane and kill me? I just try to keep risks in perspective.
Not entirely relevant, yet considering the topic of the site it's a tad ironic, and a reminder of the prevalence of sites complicit in the tracking they advocate against.
The alternative is trying to monitise the userbase some other way, and we're not interested in that game. We have no advertising, no data sales, and no ethical conundrums or regrets about that choice!
Cheers.
I use Gandi.net as registrar for my domain name and they provide email hosting[1], CalDav and CardDav with it. They even have a web interface (using SoGo[2]).
So all my emails, contacts and calendars are properly managed[3] by a French company.
[1] https://www.gandi.net/en/domain/email
[2] https://sogo.nu/
Anyway, for privacy but also security it’s been amazing.
DKIM, DMARC, SPF, and S/MIME for mail. All attachments are executed in a special sandbox before moving to your inbox (delays mail a little bit). None of my personal data / content is scanned or looked at (I think?). Plenty of security rules, alerts, and audits I can set up. Also an actual support phone number I can call for help whenever.
Why can’t Google move to a paid model? It’s worked for both Oracle and Microsoft for the last 40 years.
I think it depends on how professional the personal URL is. If it is my_name@wazoo-how-is-it-going-lol.com, then I agree that it looks rather tacky. It it is first_name@last_name.com, then it looks more professional than a @gmail address.
How can you say "for privacy [...] it's been amazing" if you haven't even checked?
They do say "Google does not collect, scan, or use your data in G Suite services for advertising purposes" and "Google does not sell [your] data to third parties" which mostly covers it, though (although ideally they'd strengthen the wording in the first part to say they don't use your data for any purposes other than to provide it to you... but now I'm just being picky.)
https://gsuite.google.com/learn-more/security/security-white...
Free domains like gmail.com, hotmail.com, live.com, yahoo.com, etc emails are tacky, lazy, and unprofessional. A domain is less than $10/year. You don't even have to be technical to buy one and use it with G-Suite. There's no excuse to use a free email domain.
Yeah, they must have the enterprise edition - basic is $5 a month
2) We don't really know, Chrome is not open-source and it's hard to tell from network traffic, since nowadays pretty much every webpage loads something from a Google server in encrypted form anyways (and with those request, Google could send all kinds of data).
3) For Chromium (which's source code is basis for Google Chrome), this project tries to collect and fix all the privacy-infringing stuff: https://github.com/Eloston/ungoogled-chromium
4) There's many ways in which Chrome doesn't actively track you, but infringes on your privacy by just being terrible at protecting it from webpages' tracking. As in millions of lines of code, tens of thousands of design decisions, all made by the biggest tracking company on the planet. No journalist can report about all of these, but it'd be foolish to assume innocence until proven guilty.
I can recommend it however.
It's a self-hosted OS alternative to Google Analytics, much like Matomo (formerly Piwik) but less focused on developers and way more opinionated in terms of what data is visualized.
It's called Fathom Analytics[1]. Eventually we want to provide a paid hosted option much like what Ghost is offering to make sure we can keep on supporting it. For now, our development efforts are paid out of our own pockets.
It looks like fathom has just the stuff I want to see in a nice stripped down view
We'll be setting up a public roadmap over the next few weeks so your feedback while we built this would be very much appreciated!
This comment intersects with nemothekid's great comment below which highlights how there are some major player alternatives which, while they aren't OSS and may have some privacy considerations, probably are still worth mentioning as an alternative to Google.
1. Privacy against advertisers 2. Privacy against security agencies.
From my perspective, first issue, is more important than second one. I think Apple does pretty decent job regarding first issue. MS holds second position. Google/FB hold the worst position.
So even though Apple/MS are closed source, I think our privacy will improve considerably just by installing an ad-blocker and sticking to Apple/MS products.
Second issue is more involved and you'd probably need to give up on all sort of mobile devices. On desktop you have to move to Linux/BSDs. No online storage (or at least move to self hosted solution). No hosted email(Or maybe just protonmail, ...). Life becomes tougher, if you decide to improve privacy against security agencies.
People tend to treat privacy as a binary issue. (either no privacy or full privacy). However, as said, majority of people experience much higher privacy just by dumping Google/FB and using an ad-blocker.
If advertisers can't reach me then why should I be concerned what they collect about me?
I do not see any ads, I use gmail and gcal. Genuine question - I understand I'm still 'the product' as far as they're concerned but it's a broken loop if they don't get my eyeballs. Help me understand anything I'm missing.
I'm currently not motivated enough to move out of google products.
https://www.fastmail.com/ for email
https://vimeo.com/ for 4K HD video uploads
https://www.backblaze.com/ for backup
https://www.rackspace.com/cloud/files for sharing files and photos to people
https://www.shopify.com/ for processing payments for my company
https://www.linode.com/ for frontend hosting
https://www.heroku.com/ for app hosting
I don't use online services for calendars, project management, to-do lists, etc. so I can't help there.
First of all, I had to buy a 3rd party app that does CardDAV and CalDAV syncing, because unlike iOS, Android doesn't support it natively.
Secondly, IMAP doesn't come close to what I was used to with Gmail. And I'm not talking about the lack of good global search, I mean the general responsiveness when reading emails. No matter which client I use (I currently settled on Outlook), things seem to load for a long time, sometimes freeze, etc.
Thirdly, all the Google supplied apps technically have support for other providers, but the Google account is clearly a first class citizen. E.g. adding/removing a generic IMAP account simply makes it appear/disappear from the sidebar in the Gmail app. You can never truly hide the Google account. You CAN disable syncing, but it will remain in the app and you can easily re-enable it accidentally if you just tap it in the sidebar.
Anyone have similar experience? What do you recommend? Are there any commercial clients with a better user experience? Should I give up and move to iOS?
Android is made by Google and they now have an interest in not promoting open protocols. They are no longer the underdog, so it's in their best interest to push their proprietary protocols. It doesn't always work, the former Google Talk was great because it was light and compatible with XMPP, it all went to shit after Hangouts happened and I'm glad that Hangouts is almost dead.
Either way, you need to recognize that if Android doesn't work well with CardDAV / CalDAV, that's a problem that Google is creating.
> IMAP doesn't come close to what I was used to with Gmail. And I'm not talking about the lack of good global search, I mean the general responsiveness when reading emails. No matter which client I use.
If you're using Gmail, again, that's not fair because their IMAP implementation isn't that great. I haven't had any problems with iOS's Mail or with MailMate (https://freron.com/), in combination with FastMail.
Speaking of which, I use MailMate with my Gmail accounts too, because I love it and all third-party email apps work better with FastMail, because Gmail's IMAP is not standard; e.g. labels are IMAP folders instead of IMAP keywords, so you get duplicate emails and the client needs to do tricks to reconcile the two.
I also use Gmail accounts on iOS and Gmail doesn't do push email on iOS (FastMail does), but I don't mind it so much to be honest. I don't like being bombarded with notifications, so if email notifications from Gmail are a minute late, it doesn't matter.
And it should go without saying that if you want push notifications on Android's Gmail app, then you can't use IMAP. I don't know of any good solutions for Android, I was a user of K9 because it's open source and does push notifications for IMAP, but it's not great.
And now I'm an iOS user because it has better support for open protocols, even if I was a die hard Android fan. I might reconsider for my next phone, I might get back to Android, but when I do, I'll factor in the cost of using open protocols, because it's Android's fault for IMAP, CardDAV and CalDAV not working well.
It's like saying "for an alternative to NBC, try CBS". OK fine but Cheers airs on NBC, now what.
But as a producer, the others might be a good alternative - especially if you are not trying to monetize and/or rely on YouTube recommendation to get discovered. If you're posting family videos for aunt Mildred, and an instructional video linked to your blog post - then there are perfectly fine alternatives to YouTube - of which most people are completely unaware.
1. Replaced my Google G-Suite with Proton Mail and a self hosted Nextcloud The process was fairly easy: Just export all your mails and import them into Proton Mail. After that I've exported Google Drive data, contacts and calendar and imported everything into Nextcloud. This all took around two hours (including the Nextcloud setup).
The only "issue" was dealing with services where I use my G-Suite account as a login, but most of them allowed you to set a password so you can log in with email.
Nextcloud has amazing one click install apps that offer the same features that Google has (video calls, docs, notes etc.).
2. Removing Google from my Android phone For that I flashed LineageOS for microG. The great thing with this is, that you can install and use all apps you normally have but without having Google Services installed. As a PlayStore alternative you can use F-Droid and Yalp Store. Anyone who installed a custom ROM before will have it running in under an hour.
3. Securing my network with a PI-Hole and Proton VPN For devices like my phone, laptop and desktop I installed Proton VPN. As a browser for mobile and desktop I use Firefox with uBlock origin. For everything else (like "smart" devices etc.) I installed a Pi-Hole (basically Easy-List on network level) to remove ads and tracking scripts.
These were only the major steps that I've taken. So far I don't have any regrets about it and I haven't faced any limitations with the alternatives I use now.
If anyone has questions or ideas for further improvement, let me know.
Links: https://protonmail.com/ https://nextcloud.com/ https://lineage.microg.org/ https://protonvpn.com/
And Search suggestions in browser, when you type into address field.
https://www.theguardian.com/technology/2017/nov/22/google-tr...
So google play services is the necessary evil that I have to keep using even after switching to Lineage. I'm back to using them again, but PlayStore and PlayServices are the only two google apps that I have currently. I try getting most of my apps from FDroid -- my filter for "good" apps is mostly how active the repo is, not great but it works.
I've moved my mail over to Fastmail, and looking alternatives to Google Drive (Backblaze B2 is one that I'm thinking of). The problem with all of these non-google alternatives is although they're only slightly inconvenient for me, they're almost impossible for my family to use (B2 for example doesn't have an app).
Roboto is a typeface developed by Google...
It's hard to explain well, but roughly it lets lay people run cloud software on their own hardware (or in the cloud) with minimal fuss.
Yes I know they're mining data about me and are likely making money off that. But has that actually had a tangible negative effect on my life in any way at all? I'm not aware of anything bad, and their products are a boon to my life.
I've invested in a couple of other web sites to satisfy my requirements (like picmonkey) and have a DigitalOcean account for my VM needs, but that's it.
Not to mention the search works so well, I don't know how I'd replace it for finding things. I would take an eternity to go back and tag all of my photos.
Encrypted, open source, and cross platform :)
I've used alternatives (namely ProtonMail), but the experience is not as good as Gmail.
Today, only people who basically live inside terminal emulators have a fair chance of correctly configuring and running a server with mail/webdav/www/webindex/dns/git, and all of that with letsencrypt.
- On Mailbox.org I receive spam. Lots of it. Why? Because they don’t look at message contents in their spam filter. Privacy, remember?
- On other search engines, I don’t find what I’m looking for. Not even remotely.
- Firefox Dev Tools suck. You have to test across all browsers anyway.
In the end, I will keep using G Suite. There is simply no equal alternative, with my own domains for mail and whatnot.
A custom domain, commonly of the <firstnamelastname> format, also leaks personal information every time it’s used, whereas a consumer mail provider domain name doesn’t (as long as one chooses a somewhat random address).
[0] https://www.nytimes.com/2017/06/23/technology/gmail-ads.html
You can try it out at https://peertube.cpy.re
Former discussions on HN:
- About the crowdfunding: https://news.ycombinator.com/item?id=17153023
- About Peertube: https://news.ycombinator.com/item?id=16714453
Decentraleyes aids further by moving the CDNs into your own machine, killing even the little tracking enabled by those CDNs.
I would recommend The Transparent Society by David Brin to anyone interested in this matter: https://en.wikipedia.org/wiki/The_Transparent_Society
Not only is it unfair but when the rich are just getting richer them having privacy while no one else does just allows for so many more ways for the poor to get screwed.
Is there another good alternative for precise search? Thanks
Corporations can go back to their role of creating hardware. They have no business looking at our data.
Sometimes the devs have some awkward attitude towards not supporting the latest stable PHP version with their current version, but overall they do a decent job and every major release brings cool new features. With KDE the desktop integration is quite nice (don't know about other desktops).
... are any of them as usable as Google?
Or at least close. GMail's web interface is the only place where I have old email and i can actually find it by searching.
Any of these services offers both imap and a usable web interface?
EDIT: Seems you have to go through a "provider" https://nextcloud.com/providers/
I will investigate further.
EDIT2: OK, so you can can get a Nextcloud instance through one of these providers. Do you have a recommendation?
Consider making a small application to find the nearest cofee shop. OSM might have 10% of the POI coverage that Google has. And that 10% likely has some stale data.
Google built a bunch of ML systems that work by default for everyone. Personally, I just have a bunch of filters setup that do the same thing. Has taken minimal effort but some discipline to file incoming emails based on my own patterns.
Here is what I now do instead:
1. I archive all incoming email unless I still need to act on it. Ideally my inbox should always be empty.
2. I unsubscribe from all unwanted email like newsletters and most social network updates.
3. I learned gmail keyboard shortcuts to clear my inbox quickly.
4. I use filters for some mailing lists.
Since I started doing this I am much more on top of my emails. At least for me, most emails in those tabs was stuff I wasn't going to read anyway.
I only had trouble with Google's "intelligent" sorting; you're better off with a proper filter system, like sieve, and setting it up for yourself. Eg. I remember reservation confirmations going into "promotions".
1. Mailfence – Based in Belgium – 500 MB free; 20 GB Pro
2. Tutanota – Based in Germany – 1 GB free; 10 GB Pro
3. Mailbox.org – Based in Germany – 2 GB storage
4. Protonmail – Based in Switzerland – 500 MB free; 5 GB Pro
5. * * Runbox.com - Based in Norway * *
They forgot #5, runbox.com
If I were role-playing as some mighty and wealthy intelligence bureaucracy, I'd likely monitor anyone using such services as well as Tor, etc. No?
I do like protonmail btw and am concerned about privacy in general, esp for the maintenance of democracy. And I'm not at all against the intelligence bureaucracies, presuming that their true goals are... to protect and serve, and that they are law abiding and accountable.
Google DNS (8.8.8.8) -> Quad9 (9.9.9.9) or Cloudflare (1.1.1.1).
Google Domains -> Namecheap or Porkbun.
Google Hangouts -> Wire or Signal.
Google Groups -> Groups.io
Why would anyone take such efforts to avoid using Google products? That doesn't seem very rational...
Plenty wrong. It seems you're not new here so I'm amazed you asked that question. Have you been living under a rock in 2013?
Just to start, it creates a big power imbalance between consumer and corporations [1] and due to the tightly knit relationship between the Pentagon and Silicon Valley it's also a civil liberties problem [2]. It also screws with your ideology by turning your internet usage into an echo chamber.
And here's some books:
https://searchworks.stanford.edu/view/10384432
https://muse.jhu.edu/article/452645
https://www.democracynow.org/2013/4/5/digital_disconnect_rob...
https://www.goodreads.com/book/show/16006587-spying-on-democ...
[1] https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2309703