Privacy is dying (for real this time)
![]()
10 years ago
If I were to tell you the only way to install an app on your own Android device that you developed would be to send Google your state-issued ID, you wouldn’t believe me.
If I were to tell you Linux distros would have to check the age of their users, you wouldn’t have even understood what I had just said.
If I were to tell you Samsung would remove the ability for official firmware to be flashed on their mobile devices, you would have laughed and called it nonsense.
If I were to tell you mass private message scanning would be incentivized or even forced by governments without prior suspicion, you would’ve probably said we lived in a democracy, where this could never legally happen for various reasons (unless you were from a country like China).
Unfortunately, this will soon happen, and it has already begun!
The state of (digital) privacy and freedom as of April 2026
Age verification
Several countries are pushing for online regulation of content deemed inappropriate for children, which may sound good, but the way it’s being implemented comes at the price of mass surveillance and free speech, while other less invasive methods already exist.
The EU is pushing for but also somewhat fighting against Chat Control, while other countries and states already have similar laws in place (e.g. the Online Safety Act in Australia and the UK).
The proposed solutions start with age verification systems, which require scanning your face or your state-issued ID, or both. This is a major security risk; you don’t want to give away your ID or passport to some random website or company. And if you’re OK with that, then you should also be OK with your ID being exposed in a data breach and giving up control.
Some people also find it scary to have a government ID tied directly to your online presence, not to mention that such solutions absolutely obliterate the right to anonymity. There are already better zero-knowledge solutions to age verification, which do not require scanning your ID for each website or app.
California passed a verification law that tries to enforce age verification at the OS level, which takes effect on January 1st 2027. Yikes! Not to mention that other states are following suit with much stricter requirements. These laws would require your OS constantly transmitting your age to all your apps.
As if systemd didn’t already suck enough, a guy named Dylan M. Taylor has pushed a PR paving the way to future endorsement and compliance with the Californian age verification law, which the creator of systemd merged. Dylan has hit many other big open source projects such as Arch Linux and Ubuntu. Yes, it’s literally a field in a file at this point in time that anyone for some time will be able to lie about, but that doesn’t mean the idea won’t be built upon in the future, and this is exactly what others in the open source community fear. On the flip side, open source is open source, and you can still remove or add whatever you like to it, the problem is that the majority of people will still use what’s available, hence the backlash. Let’s just hope the law won’t actually be enforced anytime soon.
Someone on Reddit traced back $2 billion in lobbying efforts and various PACs to pass verification laws, which are beneficial to big tech companies (most notoriously Meta).
Mobile freedom
Looking at the mobile market, it seems that we are speedily heading towards a future, where the software, operating system, or firmware on your mobile device cannot be controlled or installed by you but by whoever else is in control (be it the vendor and/or the government). And this is already true for most phones today. It started with Huawei, it just might end with the Google Pixel, which has one of the easiest bootloaders to unlock.
I’ve already seen stories of people on XDA, who say their bank requires them to have their app installed in order to log in (even from the desktop). This is and was the case with Revolut from the beginning, which cannot be installed on some custom Android ROMs because of Play Integrity and other shenanigans.
About 2–3 months ago I installed a crDroid GSI on a new Samsung tablet using some niche (and smart) methods that aren’t widely popular, but in order to do that I still had to unlock the bootloader (OEM unlock toggle in settings). 2 months ago I wanted to put on a new GSI and do a clean install, so I flashed the latest firmware and to my surprise the OEM toggle wasn’t anywhere to be found. It turns out Samsung had silently removed the option to unlock the bootloader in One UI 8.0, and so I had just locked myself out, bootloader locked, forever. You can’t downgrade because you would blow a physical fuse, which would hard brick the device (thanks Samsung! I just don’t get what this protects the user from!).
What’s more, Samsung has doubled down and has started removing the option to flash official firmware for Samsung devices. In the best case scenario, you will still have to go through hoops to re-enable it. Imagine a Samsung update corrupts your phone’s system, and you can’t flash the official firmware on it… And yes, doing a factory reset is sometimes not enough, or you might not even be able to boot into recovery mode to do it. This is really concerning seeing that the mobile vendor market share of Samsung in the USA is about 20%.
Perhaps the worst news of all is Google killing alternate open source stores such as F-droid by requiring developers give up their government IDs in order to install those APKs locally, even if they don’t want to have their app on the Play store.
Desktop freedom
PCs are known for their repairability and modularity, but this doesn’t apply to the software being run on them. The worst things I’ve heard about privacy on the desktop always end up being something to do with Windows. When Windows 10 came around they were collecting more information than ever before. It was surprising and terrifying to learn that Microsoft had so much data about my device, and how hard it was to disable all the telemetry.
A point can be made here that the collection of data is justifiable, if it is used only to improve the product as it’s true that it makes developer’s lives easier. But the amount of data Microsoft gathered in the days of Windows 10 was anything but justifiable. The claim that data is anonymously collected doesn’t hold, when so much data, even if it isn’t tied to your name or online account, can be used to track you. Tech companies don’t need your name to profit off of you, they just need to build up a profile on you; this is called fingerprinting.
Here’s an interesting study I came across, when looking deeper into the issues with anonymous datasets: The risk of re-identification remains high even in country-scale location datasets.
With Windows 11 Microsoft kicked it up a notch by requiring you have a TPM chip in order to upgrade. This is to say Microsoft wants you to throw away your otherwise totally OK computer and buy a new one making it possibly the worst case of incentivized e-waste. The TPM chip is used to track you and your computer using an identifier of the TPM chip you cannot ever change. To top it all off, Microsoft is actively trying to disable local account support. What this means is that you cannot own a computer with Windows on it without it being directly tied to you.
Rob Braxman, known as the Internet Privacy Guy, has highlighted a lot of privacy issues with Windows, the latest video I came across was about how the previously mentioned identification using TPM can be used for age verification as well.
This is sadly not the primary reason users are switching to other OSes, most are switching just because Windows 11 is becoming more and more unusable.
Web tracking
The web is a disaster, when it comes to privacy and usability. I cannot realistically believe anyone saying they know what data is being collected by a website, it’s not just the cookies, it’s not just the IP address. Your browser is the kindest salesman ever to exist, it’ll give you anything you ask it for, no questions asked and batteries included.
Techniques used to fingerprint you range from the system time zone to the characteristics of your typing speed. For an incomplete but awfully long list of the things website can use to track you, try taking the test at Cover Your Tracks.
Your browser’s fingerprint is then used to profile you, sell your data, and show you ads. It can be used to discriminate against you, or track you down in real life to silence you, if you hold certain opinions against certain entities in certain places. The right to anonymity is becoming an illusion with the amount of tracking that’s taking place on the web. And Tor isn’t immune, it’s weaker than you might think, but that’s a topic for another post.
At this point I’m looking upon what I’ve just written and wonder if I’m not one of those conspiracy guys, but after all, these are things I know and have experience with. Scary times to live in, I guess.
Solutions
When it comes to solutions. Well, I haven’t finished writing this blog post, so you’ll have to ask your search engine (which might also contribute to a breach of privacy, try for example SearXNG as an alternative)