• einlander@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 month ago

    Don’t forget with the Recall feature, you may be on Linux and are using a secure communication application, but if who you are talking to is on windows your conversation can be scraped.

    • Hellfire103@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 month ago

      Same thing with email. It’s all well and good if you’re using ProtonMail or Tuta or Posteo, but you’re still cooked if the other side is using Gmail.

      Old problems, new modi operandi.

    • jonne@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      It’s not like companies that use Linux don’t get breached either. Your personal data is in thousands of databases that have varying levels of security. Personal choices don’t affect any of that, regulations like GDPR are what’s needed.

      • Rivalarrival@lemmy.today
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        1 month ago

        GDPR has much the same problem: it can only actually be enforced against entities with a presence in Europe. When Europeans do international business, the GDPR only protects them if that foreign site has a business presence within Europe. When they have no bank accounts or business assets inside the EU, they are not subject to the GDPR.

        Even though the GDPR covers your side, it doesn’t always cover the other side.

        • jonne@infosec.pub
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          1 month ago

          That’s why I said “regulations like the GDPR”. The US and other blocs need similar regulations. Especially the US is important, as they’ve shown that they’re willing to stretch the size of their jurisdiction to sometimes absurd lengths.

          That’s usually a bad thing, but in this case that might be good.

          • Rivalarrival@lemmy.today
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            1 month ago

            I think you missed my point…

            I am not subject to the GDPR. I don’t have to abide by it. Even if my country adopted a GDPR-like regulation, that regulation would only apply to my privacy. Not yours.

            Microsoft has proven themselves overtly hostile to privacy. Yours, mine, and everyone’s. The available options are:

            1. Attempt to regulate them into behaving like decent human beings.

            2. Avoid their business.

            When my therapist is using a system that is overtly hostile to their privacy and mine, the solution is not to ask the government to chastise their attacker. The solution is to eliminate their reliance on their attacker, and get them in a system the attacker doesn’t control.

            I’m not saying we should avoid GDPR-like regulation altogether. I’m saying that at the OS level, Linux is intrinsically compliant with the intent of such regulation but may not comply with the letter, if the letter requires some sort of affirmative confirmation or certification of compliance that would be complicated for the developer to implement.

            Microsoft will be able to be technically compliant with the law, but will definitely subvert it’s intent and purpose however it can.

            Regulation will likely have chilling effects on the better option, while promoting the worse.

  • AgentGrimstone@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    30 days ago

    I’m still pissed the email I had managed to keep junk free for years was leaked because my insurance company had a breach.

  • Limonene@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 month ago

    But does your medical clinic do?

    No, they don’t, and it pisses me off. Every time I see it, I think, Well, there goes my medical privacy.

    But where else can I go? There’s only one health company in town, and they bought all the doctor’s offices.

    Who can I complain to? The doctors and nurses are visibly frustrated with Windows every time I see them use it. If they can’t change it, how could I?

    • groet@feddit.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      They might not know there are alternatives. So they likely do not ccomplain to their IT person.

      Dont be a “jUsT uSe LiNuX” guy, but when you see them frustrated maybe say “hey I see you are frustrated as well and I as a patient are concerned about my medical data privacy. You know there are better and safer alternatives, maybe you could ask your IT if it would be possible to switch to Linux?”

      Realistically, they can’t switch because the software to use some $€1m medical device only runs on windows.

      • ewigkaiwelo@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        I’ve had the se thought as expressed in the last paragraph the other day and isn’t the anwser in compatibility layer? Like can’t they install and run windows medical software using WINE?

        • lightnsfw@reddthat.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          Having worked in healthcare IT. Adding more complexity will only make things harder for them. A lot of healthcare staff can barely operate the Windows PCs and applications they’re used to. Change anything and they act like the sky is falling.

        • skulblaka@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          That opens up a legal liability for the people creating the compatibility layer. You’ve gone from two points of failure (the doctor and the machine) to three.

          For sure it can be done but most people / companies won’t want to take on that liability.

    • CarbonatedPastaSauce@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      That ship has sailed anyway. I’ve had no less than 5 breach notifications show up in the mail from things related to my health care in the last 2 years, and it’s not like I’m constantly at the doctor. The whole system is a disaster.

  • drathvedro@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    30 days ago

    But does your medical clinic do? Does your therapist do? Does your family member…

    Surprisingly, yes. Though they’re not happy with it, for various reasons. But it was refreshing to rant to my therapist about snap, apt and systemd and have them truly understand me.

  • spujb@lemmy.cafe
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    i use linux and don’t have family or friends or get any kind of medical care ☺️ checkmate

      • spujb@lemmy.cafe
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        The failures of the United States healthcare system are compatible with the Unix philosophy due to its emphasis on doing one thing poorly and leaving the rest for the user to figure out. Like Unix tools, each component—insurance, billing, and treatment—functions independently, refusing to communicate effectively while relying on the user to “pipe” themselves between endless calls, paperwork, and escalating bills. Debugging your health, much like debugging code, requires advanced knowledge, infinite patience, and a willingness to accept that nothing will ever be fully resolved.

  • savx@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    privacy is scary stuff if you think. it’s like, i care so i dont share my phone number with facebook, but someone out there may have my number/address/name on their contact list and chances are big that they have no problem sharing with zuck. so i’ll still end up on zuck’s database.

  • Phoenixz@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    No, you need to demand that government organizations use Linux or other open source systems as well, there is no other way.

    You can require Microsoft to comply with rules, it won’t. It doesn’t care, it wants money, and more money, and that is it. It’s been like that since it’s inception. The same goes for all other tech companies

    You know what brand doesn’t careuch about money and will respect your privacy?

    Open source software. Linux. Firefox (eh, mostly) with plugins, mariadb, etc…

    • ByteOnBikes@slrpnk.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      I once took a government contract for rebuilding a critical piece of software to provide civic services to the under-employed.

      I finished it in about a month. Was paid. And I was on a retainer for three years to provide updates.

      It actually took FOUR years before it was launched live to the general public.

      Best of luck convincing the underpaid govt IT to move OSes.