Differences between revisions 14 and 16 (spanning 2 versions)
Revision 14 as of 2019-05-22 00:02:16
Size: 2723
Editor: PaulWise
Comment: ToC, detection tools
Revision 16 as of 2019-11-06 02:35:11
Size: 2853
Editor: PaulWise
Comment: add nsntrace detection tool
Deletions are marked like this. Additions are marked like this.
Line 29: Line 29:
 * [[https://github.com/jonasdn/nsntrace/|nsntrace]]
Line 30: Line 31:
= Bug reports = = Reports =
Line 33: Line 34:
 * [[https://debtags.debian.org/reports/facets/privacy|Debtags privacy facet]]

Privacy issues in Debian packages

Phone home

Phone elsewhere

  • systemd - Uses Google DNS resolvers as internal default, not explicitly documented: See "FallbackDNS" in systemd-resolved manpage

Data sharing

  • remmina - shares the clipboard with remote hosts over RDP by default
  • pidgin - shares typing notifications with remote peers by default

Data storage

  • web and other servers of various kinds default to logging information about requests over the network from external entities

Detection tools

Reports

Issue categories

  • logging & verbose logging

  • homephoning without user consent
    • cleartext
    • TLS
  • featurebug: when a bug is also a feature
  • privacy defaults
    • optin
    • optout
  • traceability
  • no deletion of config files when uninstalling a package