Sooraj

13.8K posts

Sooraj banner
Sooraj

Sooraj

@iAnonymous3000

DOGE for privacy. @Brave | priv/acc 🚀 views ≠ employer's.

Earth Katılım Mayıs 2013
1.1K Takip Edilen15K Takipçiler
Sabitlenmiş Tweet
Sooraj
Sooraj@iAnonymous3000·
anon’s guide to actually supporting privacy: > donate to tools you use instead of just complaining they need money > contribute code if you can, documentation if you can’t > use private money (cryptocurrency, cash) > tell normies about alternatives without being insufferable about it > work for companies that aren’t surveillance machines > push for legal protections because tech alone won’t save us privacy isn’t a product you buy, it’s an economy you build
English
20
39
273
61.9K
Sooraj
Sooraj@iAnonymous3000·
I checked this with Site Behavior Lab. The scan supports the surveillance concern. In one visit to AlaskaAir(.)com: - 249 (out of 309) went off-site across 29 third-party domains - 9 known tracking companies saw the visit - 10 third-party cookies appeared [52 requests matched Brave Shields filter lists] - Data reached Google, Microsoft, Meta - An Adobe tracker was hidden behind an alaskaair(.)com subdomain using CNAME cloaking - AppDynamics registered 409 third-party input listeners and 997 interaction/session-recording listeners @AlaskaAir why is any of this necessary before someone even books a flight?
Jack Rhysider 🏴‍☠️@JackRhysider

This is what I mean when I tell you that companies don't take your privacy seriously. Alaska Air already has my government ID. They know my legal name, my birthdate, my face. I cannot board their plane without handing that over. But that's not enough. Just to view their website they require me to DEGRADE my privacy AND security so they can collect even more data about me. They won't let me even look at their website unless they collect my IP, geolocation, finger print my browser, and collect any information they can use to identify me even more. The data they want is precise enough that it makes me trackable across the whole internet long after I use their site. This is not for my privacy or security. When companies say they value your privacy, what they really mean is your privacy is valuable to them, like an inventory item. They harvest privacy, not protect it. AlaskaAir you need to do way better than this.

English
5
17
70
6.7K
Suzie Dawson
Suzie Dawson@Suzi3D·
Twitter is literally spyware. Understand what it is doing to you. Here is the evidence:
Suzie Dawson tweet mediaSuzie Dawson tweet media
English
150
829
5.6K
363.1K
Sooraj
Sooraj@iAnonymous3000·
Yes, absolutely. 💯 The cleanest approach would be a “Scan with Site Behavior Lab” button beside each PriEco result that opens Site Behavior Lab with the destination URL prefilled. [PriEco should only send the URL after the user explicitly clicks the button. No automatic scanning or background sharing of search results.] Happy to coordinate on the URL format and implementation. This is exactly the kind of integration Site Behavior Lab was built for.
English
0
0
3
431
Sooraj
Sooraj@iAnonymous3000·
It is FREEDOM vs. SURVEILLANCE. The evidence is public: - 152 requests sent off-site across 40 third-party domains - 10 tracking companies - 26 third-party cookies - 116 requests matched Brave Shields’ default filter lists - Data reached Google, Meta, TikTok, and others - Only 1 of 10 observed tracking companies was named in TPUSA’s privacy policy - Input-monitoring and browser-fingerprinting signals matched Still, a political organization claiming to defend American liberty should explain why its website exposes visitors to this much third-party surveillance. You cannot defend freedom while treating Americans as data points. Full evidence: scan.sitebehavior.org/reports/202607…
Jane@Mrsianonymous

Why is @TPUSA tracking AMERICANS more aggressively than Chinese companies like Shein, Temu, and AliExpress? What is going on? TPUSA claims to exist to “continue Charlie’s vision” and protect America’s future. Beyond the slogan being painfully cringe, its actual behavior tells a very different story from a privacy and security perspective. How can we have freedom without privacy? Explain to me how collecting Americans’ data and potentially handing it to third parties serves Charlie’s vision. How does treating American citizens like products protect America’s future? cc: @RealCandaceO Thank you @iAnonymous3000 for building Site Behavior Lab so that even a nontechnical person like myself can see what websites are actually doing behind the scenes.

English
7
13
61
2.8K
Sooraj
Sooraj@iAnonymous3000·
@HaskapNL The block is coming from iHerb’s Cloudflare bot protection [not because Site Behavior Lab intentionally refuses the domain]. The scanner uses an automated Chromium session and does not attempt to bypass captcha / anti-bot challenges.
English
1
0
2
81
IntegrityFirst
IntegrityFirst@HaskapNL·
@iAnonymous3000 I wanted to check the iHerb site, because I noticed that the app sends a whole lot of data, but your site refuses me because of the cloudfare check.
English
1
0
1
77
Sooraj
Sooraj@iAnonymous3000·
@alexandr_wang Meta is not a company I trust with my health data. So the benchmark score is almost irrelevant unless users can retain custody of that data. Will Muse Spark 1.1 be released as open weights under a license that permits local inference?
English
3
1
7
357
Sooraj
Sooraj@iAnonymous3000·
It should NOT be this hard to buy a privacy-respecting router. Seriously. A router forwards packets. That should be the whole relationship. Instead you get mandatory cloud accounts, phone apps for basic settings, telemetry, and "AI security" subscriptions. Amazon's eero will not even give you a local admin interface. Comcast runs AI analysis on the traffic of every device in your home and markets it as a feature. The router is the one computer that sits between everything you own and the internet. It sees every DNS lookup from every device. It sees which sites you connect to even when the traffic is encrypted. It knows when you leave, when you come home, when you sleep. That is a behavioral dossier of your entire household, and nobody audits it. Most people never log into their router at all. Now the part everyone tiptoes around: most routers sold in America are produced in China. TP-Link, the best-selling brand in the country, has been under federal investigation since 2024. Volt Typhoon built its US attack infrastructure out of aging home routers. Flax Typhoon ran a botnet of more than 200,000 hijacked routers and cameras through a Beijing company until the FBI took it down. Used routers are worse. ESET bought secondhand corporate routers and found over half still held the previous owner's full configuration: credentials, VPN keys, complete network details. For consumer gear, assume WiFi passwords, admin logins, and device history all ship with the box. Anything named Armor, HomeShield, AiProtection, or Advanced Security is a pipe to a third-party cloud. Netgear Armor is Bitdefender. ASUS AiProtection is Trend Micro. Enabling them means accepting someone else's data terms for your entire network. And the part almost nobody knows: your router's Wi-Fi hardware address sits in global location databases run by Apple and Google. Researchers mapped hundreds of millions of routers this way and tracked Starlink terminals in active war zones. You can opt out by appending _nomap to your network name. Almost nobody does, because almost nobody knows. Good intel on this is weirdly hard to come by.
English
53
119
849
52.9K
Sooraj
Sooraj@iAnonymous3000·
These glasses are made by Snap. The account doesn't say it, the launch video doesn't say it, and specs.com barely says it. You find out in the footer, where every legal link resolves to snap.com. I read all 4 privacy documents behind this pre-order. The Specs Supplemental Privacy Policy covers only the pre-order: name, address, payment, and a face scan for sizing. For everything the glasses will actually do, the policy defers to Snap's main privacy policy. The same one that governs Snapchat. That policy is written for an advertising business. Snap auto-tags your content to infer interests and target ads, and gives the example that a dog in your photo can lead to dog food ads. It defines AI "Inputs" as text, images, video, audio, and precise location. It says conversations with Snap's AI are used to improve its models. And on third-party integrations inside Lenses, the apps that run on these glasses, it states plainly: "We are not responsible for how those partners collect or use your information." Specs has no device privacy policy yet because the device hasn't shipped. The closest preview is the supplemental policy for Snap's current Spectacles. That one says Snap collects information about your physical surroundings: walls, windows, furniture, "whether or not you are in a vehicle." Voice commands become text transcripts, and the mic may pick up ambient sound around you. Device data is used to develop and improve Snap's machine learning models. Snap may also share your information with service providers, Lens developers among them. Then there's the flagship feature. Contextual answers and live translation run on OpenAI and Google models, which means what you see gets processed on third-party AI infrastructure. The product page says "We prioritize on-device processing." Prioritize is doing all the work in that sentence. The same page confirms third-party Lenses can request camera or microphone access while connected to the internet. A developer's app seeing through your camera and phoning home, gated by a permission prompt. Consider the incentives. Advertising made up roughly 87 percent of Snap's $5.9 billion in 2025 revenue. A camera at eye level, 6 microphones, location, and an AI that labels everything you look at is the most valuable ad targeting sensor package ever strapped to a human face. Consider the track record. Snap deceived users about disappearing messages and transmitted location and collected address books without notice or consent. And for everyone who never agreed to any of this, the people the wearer looks at all day, the protection is a small glowing light.
Sooraj tweet media
SPECS@specs

Introducing SPECS. Augmented reality glasses that make computing more human. Pre-order now.

English
5
7
56
6.3K
Sooraj
Sooraj@iAnonymous3000·
@lukemulks freedom fighter spotted 👀
Matt Van Swol@mattvanswol

🚨#BREAKING: Police in Houston TX are asking the public's help to identify the mystery person who cut down 2 Flock cameras on Independence Day. According to police, the mystery person chopped them down, spray-painted the lenses, and then put American flags in their place.

English
0
0
8
266
LukΞ Mulks 🦁⟁◎⟁
LukΞ Mulks 🦁⟁◎⟁@lukemulks·
Flock = diabolical. "Trust us bro, records of our 4th amendment violations are permanently stored." People should question their local governments that allowed for the installation of this garbage, demand it be removed and if not, replace the politicians with ones that understand Amendments 1 through 10. Because these cameras are all over the place. deflock.org Don't be gaslit by people with financial interests in eroding amendment protections in place to protect people from government overreach just like this.
Flock@Flock_Safety

@Mrgunsngear These cases don't reflect the life-saving work of first responders who use Flock. Rare, illegal use of Flock is stopped and prosecuted with the help of our permanent audit logs. Learn more: flocksafety.com/trust

English
1
3
10
577
Sooraj
Sooraj@iAnonymous3000·
You clicked "Reject all" on a cookie banner. Did it actually do anything? I tested it. On khanacademy, rejecting made no difference: 89 third-party requests either way, and Google still loaded. The report is public and reproducible. That test is one feature of something I built: Site Behavior Lab (sitebehavior.org), a free, opensource scanner that opens any public website in a controlled browser and records what it actually does, not what its privacy policy says it does. Every request, cookie, storage key, and tracker, with the exact scan conditions attached. Every report gets a shareable permalink and machine-readable JSON. Evidence (not a score). What makes it different from every other scanner I know of: - It runs @Brave's actual ad-block engine (the open-source adblock-rust crate with Brave's default filter lists) against a live visit, so you see both sides: what the site tried to load, and what a blocker would have stopped. usatoday tried 954 third-party requests. 936 would be blocked. - It types a synthetic value into forms (never submitting) and watches whether keystrokes leave to a third party, even base64, hex, or hash encoded, even buffered and flushed when you leave the page. - It resolves DNS CNAME chains to expose trackers disguised as first-party subdomains, the trick that URL-based scanners miss. - It decodes what Meta, TikTok, and X pixels actually report: which events fired, and whether hashed personal identifiers were attached (detected by parameter name only; the values are never read or stored). - It runs paired Accept-all vs Reject-all visits so you can see what your consent choice really changed. - It reads the site's own privacy policy and checks it against the observed evidence, quoting the exact sentence when a checkable claim contradicts what the scanner watched happen. No other free scanner shows what blocking changes, what rejecting consent changes, and whether the policy text matches measured behavior, all in one reproducible report. There are 230+ published reports across 100 real sites, with category medians (news sites: 56 tracker requests median per visit), a browsable directory, and a researcher CSV/JSON export.
Sooraj tweet media
English
11
57
233
10.3K
Sooraj
Sooraj@iAnonymous3000·
"Turn off location services" is the most repeated privacy advice on the internet. It is one switch in a system with a ton of leaks. GPS itself is receive only. The radio never transmits. Kill the switch and you lose navigation while your position keeps flowing anyway: ad identifiers, your IP address, WiFi mapping, account history, the cellular network itself. What a solid defense looks like: Audit location permissions. Almost nothing deserves Always access. Live navigation and an active rideshare trip qualify, little else does. Everything else gets while in use, coarse, or nothing. Websites ask too, so do the same in your browser. Navigate offline. @OrganicMapsApp or @osmandapp run on downloaded maps and plain GPS. Your travel history stays on the device with cloud backup and track sync off. One subtle leak remains: the first satellite lock on a stock phone fetches assistance data from vendor servers. GrapheneOS routes that through its own. [Staying on stock Android or iOS? Damage control: turn off Web & App Activity in your Google account and Timeline in Google Maps. Google moved Timeline on device after the central store became a geofence warrant magnet, but Web & App Activity still logs to their servers. On iPhone, clear Significant Locations and prune System Services. Treat every toggle as a request [not a guarantee]. Cut the ad pipeline. Delete your advertising ID on Android, deny every tracking prompt on iOS. SDKs inside ordinary apps harvest location and IP and sell it into the bidstream.] @GrapheneOS can revoke network access per app, which ends that conversation entirely. Your IP address places you at city level on its own, and far more precisely once brokers join it with those identifiers. Tor goes further, and on a phone that means Orbot, routing the whole device through Tor, or individual apps on Android. Slower, and exits get blocked, so it is the high threat mode rather than the daily driver. Neither touches GPS permissions, accounts you stay signed into, or tower records. Orbot is the free exception because it is Tor [not a VPN business]: volunteers run the relays and nobody monetizes your traffic. Google and Apple maintain databases mapping practically every router on earth to coordinates, so the networks around you place you to the building with GPS off. Randomize your MAC address at the strongest setting offered, iOS now has a Rotating mode. Disable WiFi and Bluetooth scanning, both sit under Location Services on Android. iOS exposes less, but check System Services under Networking & Wireless. Append _nomap to your SSID to pull your router from Google's database. Google's only. Stop volunteering it. Snap Map, Life360, Strava heatmaps, WhatsApp live location, Find My sharing. Each one is a standing beacon someone else reads. Cellular watches, trackers, and car infotainment write parallel trails. Strip metadata before posting photos. EXIF carries coordinates, timestamps, and device model. Microphones and motion sensors are documented location channels. Ultrasonic beacons earned FTC warning letters, and gyroscope route inference exists in the research. Niche next to adtech, but cheap to close: deny the mic by default, revoke sensors where your OS allows. GrapheneOS has a per app toggle, iOS only covers Motion & Fitness. Your phone is findable powered off. Recent iPhones keep beaconing into the Find My mesh after shutdown, and Pixel 8 class hardware does the same for Android's network. Both are opt out. Cellular is the hard floor. Your carrier logs tower connections around the clock. Disable 2G to cut exposure to downgrade attacks from fake base stations. Apple shipped Limit Precise Location, which degrades what the network sees to neighborhood level, but it needs Apple's own modem and in the US only Boost Mobile supports it. The real answer is still airplane mode with WiFi only and calls over @signalapp with always relay on, since peer to peer calls expose your IP to the other end. Few people live there. Every layer above still shrinks what anyone can buy about you. Reducing exposure works.
English
9
58
358
22.8K
Sooraj
Sooraj@iAnonymous3000·
America turns 250 today. Every other nation in history was built on blood, soil, or a crown. This one was built on an idea: that you are free, and your life belongs to you, not the state. I'm a security engineer, so I read the Constitution the way I read code. It is the greatest security architecture ever shipped. Power is distributed, so there is no single point of failure. The Bill of Rights is the access control list. The amendment process is the patch pipeline. The whole design assumes that people in power cannot be trusted, and that assumption is exactly why it still runs. Read the access control list closely: The First: speak, publish, assemble, worship, without asking anyone's permission. The Second: a free people are never defenseless. The Fourth: no one searches your home, your papers, or your effects without cause. This one is personal to the founding. The Revolution caught fire partly over general warrants, when the Crown claimed the right to rifle through any colonist's home looking for something to charge him with. Your "papers and effects" now live on servers. The principle hasn't changed. The Ninth: the quiet genius of the document. The rights not written down still belong to you. Privacy lives there. Now notice what these four have in common. None of them survive surveillance. Speech dies when every word is recorded, because watched people self-censor. Defense means nothing when the state already knows what you have and where. Security in your own home and effects is privacy by definition. And the Ninth exists precisely because the founders knew liberty is bigger than any list. There is no freedom without privacy. There never has been, anywhere, at any point in history. 250 years of uptime for an idea most of history called impossible. Not perfect. Never claimed to be. Fixable by design, and that is the feature every free nation since has copied. Happy 250th, America. Land of the free. Fight with every fiber of your being to keep it that way. 🇺🇸
English
13
27
146
44.5K
Sooraj
Sooraj@iAnonymous3000·
@followjason Woke up to the smell of liberty and freedom.
English
2
0
6
298
Sooraj
Sooraj@iAnonymous3000·
@AravSrinivas > run locally > hardware you own > personal robots > no way anyone is going to get comfortable streaming your home to a server privacy is winning. PS: @maticrobots does just that.
English
1
0
6
632
Aravind Srinivas
Aravind Srinivas@AravSrinivas·
The best application for models to run locally on hardware you own would be personal robots. There’s no way anyone is going to get comfortable streaming your home to a server. And when this happens, the local hardware will also become a token faucet for your digital tasks.
English
69
32
753
61.9K
Sooraj
Sooraj@iAnonymous3000·
A follow-up on Site Behavior Lab. The launch line was "what a website actually does, not just what its privacy policy says." So the scanner now reads the policy too. It finds the site's real privacy policy page and cross-checks its claims against the network behavior observed in the same visit, in the same report. Consent banners get a test now. The scanner runs 2 paired visits: 1 clicks accept all, 1 clicks reject all, on the site's actual banner (OneTrust, Cookiebot, Didomi, Usercentrics, TrustArc, and others). The report diffs what your choice actually changed, and names the tracking companies that still received requests after a real rejection. If the banner couldn't be clicked, the report says so. Another detail I forgot on the pixel side: events aren't just counted. The decoder unpacks advanced-matching payloads, so you can see when a Meta or TikTok pixel is carrying hashed identifiers (not just that it fired). A scan is a snapshot, so there's now a feed. Featured sites re-scan weekly, every site keeps a current and a previous report, and the directory shows what changed since the last scan: "Since Jun 25: +64 third-party, -71 tracker requests." With the honest caveat that two automated visits can differ for boring reasons like ad rotation and caching. For researchers: the whole corpus is downloadable at /corpus.json and /corpus.csv. One row per published report, with counts, consent mode, deltas, and links to the full report JSON. 230+ reports across 100+ sites so far, with the sampling caveats embedded in the file itself. Some rules that shaped all of this: - No bot evasion. If a site blocks the automated visit, the report says exactly that. Which is itself information. - Every claim carries its uncertainty. Failed consent clicks are disclosed, deltas carry variance notes, and the corpus states plainly that it's curated sites. - Plain language first, raw evidence always. There's a glossary now, and every technical term is defined where you first meet it. Same idea as before: the web should be inspectable. Now it's inspectable over time.
Sooraj tweet mediaSooraj tweet media
English
0
3
21
1.4K