this post was submitted on 14 Sep 2024
491 points (97.5% liked)

Privacy

32424 readers
346 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Hi everyone! For... I guess over a year now? I've been observing and trying out lots of software recommended by the privacy community and internet as a whole. With that time, I've been able to slowly put together a list of all the software I personally believe to be the best for their own various reasons. I finally have enough to be able to share it with all of you!

I'm also looking for feedback. I haven't tried all the software on that list, and I'm sure there's software I've never heard of that needs added. I'm looking for your feedback on what you think should be added, removed, or changed. That includes the list itself, if you think there are any design improvements.

Do note: Any software marked with a ⭐️ I am not looking for feedback on. This is software that I firmly believe is the best of the best in its category, and likely will not be changed. However, if there is a major issue with the software that you can provide direct proof of, then there is a chance it will be changed in the next release. There are no grantees.

The sections marked with ℹ️ are lacking, and can use your help! Some software there may not be the best one, or may have many software or sections missing. I am absolutely looking for help and feedback here, and would love your help!

My goal with this project is to help people find the best software from many standpoints, and to prove that there really are good open source alternatives for almost anything! I hope this helps someone, and I look forward to your feedback!

Thank you all for reading and taking the time to look through my list!

Edit: This project has moved to GitLab!

top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 27 points 3 months ago (1 children)

Not to disparage your effort, but I looked into music and I only see:

Audio & Music

Audacity Audire Audile

Aaaand I'm out.

This is so lopsided it should be titled "A random collection of free software that has caught my eye"

[–] [email protected] 15 points 3 months ago* (last edited 3 months ago) (3 children)

I'm sorry you weren't satisfied with some of the software on my list. Audire and Audile are not options I preferred to add, but there are simply no better music recognition apps out there that I could find. I would love to know if you have any! As for Audacity, I'm not sure what concerns you have over that. If you have any constructive feedback, I'd love to hear it!

The project is still in its early stages, so not everything is perfect :)

[–] [email protected] 3 points 3 months ago

Tenacity is a telemetry-free fork of Audacity for a start

load more comments (2 replies)
[–] [email protected] 18 points 3 months ago (1 children)

Love that you have Joplin on the list! I started using that recently to handle all of my notes and it’s been great.

[–] [email protected] 3 points 3 months ago* (last edited 3 months ago) (2 children)

I'm still on Google Keep. Please, tell me why I should switch.

[–] [email protected] 22 points 3 months ago (1 children)

Your data has monetary value to google. Giving them access, without getting any money from them (or even knowing what ways it will be used) is not something you must do.

If the app provides enough value that is unique to it, then thats OK, but if a data-respecting alternative exists that costs nothing to download or use, and fits the same (or more) needs, then using it just makes sense.

If thats not you, then thats ok.

I also use keep, but thats because I haven't degoogled my phone yet, so they already have most if not all of that data. Once I am in a position to be able to root and remove google without risking bricking my device (currently unhoused, and just cannot risk it rn), then I plan on never touching the damn thing.

To each their own.

[–] [email protected] 2 points 3 months ago* (last edited 3 months ago) (1 children)

Your data has monetary value to google. Giving them access, without getting any money from them (or even knowing what ways it will be used) is not something you must do.

To be fair, while you may not be getting money in its direct form (cash, bank deposit, etc) from Google, they are providing you a service which costs them money for free. So they are providing something of monetary value.

Only the individual can determine if their data is worth that free (to the individual, not free to Google) service. I'm assuming that most people in a privacy community would be against that, though.

load more comments (1 replies)
[–] [email protected] 7 points 3 months ago
  • Joplin has a lot of customization
  • Can store your notes wherever you want (Dropbox, WebDAV, OneDrive, Nextcloud, Joplin’s own cloud service, etc)
  • Backups can optionally be encrypted (you set a password used to decrypt them and store that somewhere)
  • You can make multiple notebooks in the hierarchy structure you want
  • Open source
  • Markdown (if you’re into that)
  • Plugin support
  • Tags
[–] [email protected] 15 points 3 months ago (2 children)

How about not hosting this list in Microsoft's GitHub?

[–] [email protected] 17 points 3 months ago

Creating mirrors on other platforms such as GitLab and Codeberg is on my to-do list. Thank you!

[–] [email protected] 6 points 3 months ago* (last edited 3 months ago) (2 children)

lemmy hosts their source code on github and alot of floss sites uses github also i agree with you not to use github dont understand why people use github for markdown

load more comments (2 replies)
[–] [email protected] 15 points 3 months ago* (last edited 3 months ago) (2 children)

For instant messengers, I would also add Wire and Matrix/Element (Matrix is the protocol, Element is the messenger that uses the protocol).

https://wire.com/en

https://matrix.org/ - https://element.io/

Both good open source secure messengers. Matrix is made by a type of non-profit foundation made to guide the development of the core protocol, and Wire is a Swiss company staking their future on how secure their messenger is for Enterprise applications. They both have different philosophies on how their operations are ran, but they're both open source and secure.

They're not as privacy respecting as Briar or SimpleX, but they're also more aimed at organizations and groups that plan on self-hosting and potentially not federating with the rest of the network to help silo their organizational data. Wire obviously aims towards Enterprise customers, but Matrix does as well, despite a different approach. Matrix has had growth with both German and French governments for various secure communications systems within their government bodies based on the matrix protocol. So good messengers, just aimed at a different group of people as Briar/SimpleX.

So maybe they could have their own "Enterprise Chat" section? I dunno, just my thoughts.

[–] [email protected] 4 points 3 months ago (2 children)

Hi! Thanks for the feedback!

The "Video Conferencing Tools" section is my aim at enterprise applications. My goal there was to find an app that is available for Online, Windows, macOS, Linux, ChromeOS, Android, and iOS that supports group chats, video calls, and screen sharing. I was only able to find Infomaniak kMeet, which I'm not even sure fits the bill. If you have any suggestions that meet these requirements, I would be happy to add them!

In the meantime, feel free to make an issue on the repo suggesting these services!

[–] [email protected] 5 points 3 months ago* (last edited 3 months ago)

There is BigBlueButton. It's more focused in educational usecases (online classes and the like) but it works just fine for everything else. You need to host it yourself, but there are hosted instances out there. I for example use senfcall.

But I think we are talking about different things here. What Chanuk was talking about (I think) is a ms-teams or slack alternative, not a zoom or oracle WebEx alternative. Basically Discord but for business. Sidenote: there is a open source Discord clone called revolt

[–] [email protected] 3 points 3 months ago (3 children)

Element meets all of that criteria

load more comments (3 replies)
[–] [email protected] 3 points 3 months ago

Thank you. Was going to suggest matrix/elements. But you explained it better ;)
It has really improved the last years. Especially the e2e encryption key sharing, and verfication system vs what was before.

[–] [email protected] 12 points 3 months ago (1 children)

Thanks! I’ll give it a gander. I was off hiking today, and used some crappy app to track my progress. I know there’s an open source ware that can do it, without invading my privacy; it’s time to start using that ‘ware.

[–] [email protected] 11 points 3 months ago (3 children)

Trail Sense mentioned in my list has options for tracking hiking progress. Unfortunately, open source health apps are few and far between.

[–] [email protected] 2 points 3 months ago

Gnome Health and my GNU Health works well. Linux only though

load more comments (2 replies)
[–] [email protected] 6 points 3 months ago* (last edited 3 months ago)

man i wish there was a more powerful alternative to gimp hope gimp 3.0 solves it and currently am using the affinity photo 6 month free trial

[–] [email protected] 6 points 3 months ago

My latest favourite is missing: Note Taking Apps:

Joplin is good for organising text-based notes, so I'm not surprised to see that on your list. But xournal is a for mixed drawing / hand-writing / text, etc. So it's a different use-case to Joplin. (It would be perfect if Joplin supported xournal notes; so that you could write with xournal and then organise with Joplin. ... But that hasn't yet come to pass.)

[–] [email protected] 6 points 3 months ago* (last edited 3 months ago) (1 children)

No rsync? No pass? I’d definitely have the xmpp and matrix protocols on that list with a few clients listed for desktop and mobile.

[–] [email protected] 2 points 3 months ago (1 children)

Hi! If you have any suggestions for software, please provide links to them and I will be sure to check them out! Ideally, open an issue on the repo (this is the best way for it to be added). Thanks for the suggestions!

[–] [email protected] 7 points 3 months ago* (last edited 3 months ago)

pass - password manager https://www.passwordstore.org/

rsync - provides fast incremental file transfer https://rsync.samba.org/

xmpp - the universal messaging standard https://xmpp.org/

matrix - an open network for secure, decentralised communication https://matrix.org/

retroshare - private and secure commmunication and sharing platform. RetroShare provides filesharing, chat, messages, forums and channels. https://retroshare.cc/

[–] [email protected] 6 points 3 months ago (1 children)

Nice list. I chuckled at the fact that the bitcoin section does not recommend bitcoin :) We're also here on lemmy, if you ever need help or just want to say hi

load more comments (1 replies)
[–] [email protected] 4 points 3 months ago

Now plz do hardware

[–] [email protected] 4 points 3 months ago (1 children)

There's obviously a zillion open source games you could add, but I'm partial to pixel dungeon and its many variants

load more comments (1 replies)
[–] [email protected] 3 points 3 months ago (1 children)

Bookmarking this. How about a photo library category under photos and grafics

[–] [email protected] 2 points 3 months ago* (last edited 3 months ago)

Thanks for bookmarking! I will absolutely be adding a photo library, it was something that slipped under my radar. Thank you!

Edit: Added in version 5.2024.09.15.1

[–] [email protected] 3 points 3 months ago

On windows for a screenshot tool a good one is ShareX. and for a clipboard manager Ditto

[–] [email protected] 3 points 3 months ago (2 children)

Why KeePassXC over Bitwarden or VaultWarden?

[–] [email protected] 10 points 3 months ago (1 children)

I'm no expert, but I think KeePassXC doesn't need to sign in to a server somewhere.

[–] [email protected] 8 points 3 months ago (1 children)

You can also self-host bitwarden.

[–] [email protected] 10 points 3 months ago (1 children)

This still requires a server setup, focused entirely on passwords. Why do that?

Why not just use KeePass or KeePassXC, and use Syncthing for this and general files, or KeePassXC's keeshare sync to sync the files without any hosting, server, or other services.

Extremely simplified tldr: both of these are like a authenticated private bittorrent, where the "tracker" only helps you find yourself on another devices, no data is ever sent outside of your authenticaed devices, and all transmissions are encrypted as well.

[–] [email protected] 6 points 3 months ago* (last edited 3 months ago) (5 children)

Few reasons, with the most important being convenience. Syncthing is going to see just a binary blob as the password storage is encrypted. This means it is impossible for syncthing to do proper synchronization of items inside the vault. Generally this is not a problem, but it is if you happen to edit the vault on multiple devices and somehow syncthing didn't sync yet the changes (this is quite common for me on android, where syncthing would drain the battery quite quickly if it's always actively working). For bitwarden on the other hand the sync happens within the context of the application, so you can have easy n-way merge of changes because its change is part of a change set with time etc.

Besides that, the moment you use syncthing from a threat model point of view, you are essentially in the same situation: you have a server (in case of syncthing - servers) that sees your encrypted password data. That's exactly what bitwarden clients do, as the server only has access to encrypted data, the clients do the heavy lifting. If the bitwarden server is too much of a risk, then you should worry also of the (random, public, owned by anybody) servers for syncthing that see your traffic.

Keeshare from my understanding does use hosting, it uses cloud storage as a cloud backend for stateful data (Gdrive, Dropbox etc.), so it's not very different. The only difference would be if you use your private storage (say, Synology Drive), but then you could use the same device to run the bit/vaultwarden server, so that's the same once again.

The thing is, from a higher level point of view the security model can only be one of a handful of cases:

  • the password data only remains local
  • the password data is sync'd with device-to-device (e.g. ssh) connections
  • the password data is sync'd using an external connection that acts as a bridge or as a stateful storage, where all the clients connect to.

The more you go down in the list, the more you get convenience but you introduce a bit of risk. Tl;Dr keepass with keyshare/syncthing has the same risks (or more) than a Bitwarden setup with bitwarden server.

In addition to all the above, bitwarden UX is I would say more developed, it has a better browser plugin, nice additional tools and other convenience features that are nice bonuses. It also allows me to have all my family using a password manager (including my tech illiterate mom), without them having to figure out anything, with the ability to share items, perform emergency accesses etc.

Edit: I can't imagine this comment to be deemed off topic, so if someone downvoted simply to express disagreement, please feel free to correct or dispute what I wrote, as it would certainly make for an interesting conversation! Cheers

[–] [email protected] 5 points 3 months ago (1 children)

There's often the 'security vs. convenience' tradeoff, but for most people you have both sides with Bitwarden over KeePass.

Bitwarden is undoubtedly more convenient. If you can create an account, you can use it. I have a family account, and have both of my parents using it. The love it now, but given the friction to get them there in the first place, it would impossible to get them on KeePass. Especially because they wanted their passwords on all devices.

Regardless of using Vaultwarden or KeePass, you need to have quite a bit of expertise to self host. And you are trusting your own ability to secure your attack surface. I'm sure many if not most in this thread can, but it would take me quite a while to convince myself I have. I would much rather trust security professionals.

Somewhat, although, potentially related. Have you seen Bitwarden's git repos? It is immaculately organized.

Consistent, clear naming convention. There is literally one called 'self-host'. If you put that much effort into keeping your code that useable/available/auditable etc. Oh yea. I'm going to trust you to handle security for me

load more comments (1 replies)
load more comments (4 replies)
[–] [email protected] 3 points 3 months ago (3 children)

One of many reasons is the nonfree nature of Bitwarden. You have to pay for a premium account to use certain methods of 2FA, for example (last I checked).

load more comments (3 replies)
[–] [email protected] 2 points 3 months ago

Thanks for the list! Sharing this with lazy friends.

load more comments
view more: next ›