FreeVPN.One, a verified Chrome extension with over 100k installs on the Chrome Web Store, is taking screenshots of sites users visit.

  • NuXCOM_90Percent@lemmy.zip
    link
    fedilink
    English
    arrow-up
    15
    ·
    18 hours ago

    And this is why I am so obnoxious any time someone says “I found this plugin to block fandom wikis” or “I have this plugin to fix youtube embeds”.

    Code is only as safe as the people you trust to review it. And no, being open source doesn’t matter in that regard. Yes, it theoretically increases the number of eyes on but how many of those eyes who ACTUALLY look at the code are doing it with every release AND understand how to spot a vulnerability or a… whatever this is.

    Same with VPNs. NEVER trust a VPN. And sure as fuck never use a free one for anything remotely sensitive. Understand what your risk of exposure is and that, at the best of times, you are trusting a company to be telling the truth that they aren’t keeping a log of every single thing you nutted to.

    And before someone says “That is why I do everything over tor!”: Maybe also understand the concept of digital fingerprints and WHY it is that Google is able to know someone is pregnant even before they are late.

    Understand the risks and consequences of every action you take and act accordingly. And understand that there really is no one size fits all solution.

    • FreedomAdvocate
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      2
      ·
      9 hours ago

      NEVER trust a VPN.

      The only exception to this is IMO ones that have been proven in court to keep NO logs, like they claim. The only one I know of that has been tested is PrivateInternetAccess, which is why they’re the only VPN I’ve used for like 10 years.

      • NuXCOM_90Percent@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        9 hours ago

        You mean the court case from almost ten years ago?

        Yeah, that sounds safe. I mean, Google is still all about Do No Evil, right?

    • u/lukmly013 💾 (lemmy.sdf.org)@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      15 hours ago

      And sure as fuck never use a free one for anything remotely sensitive.

      I think ProtonVPN might might be an exception here. They’re pretty trustworthy as far as I know, and have some free servers.

      But my go-to is Mullvad, mainly for the flat pricing. I hate how most only have good prices if you buy a full year or so.