<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Privacy on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/privacy/</link>
    <description>Recent content in Privacy on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sun, 02 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/privacy/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Permanent geolocation: how your phone tracks you even when you think you have stopped it</title>
      <link>https://arpokrat.com/blog/how-your-phone-tracks-your-location/</link>
      <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/how-your-phone-tracks-your-location/</guid>
      <description>&lt;p&gt;In 2024, two researchers at the University of Maryland repeatedly queried Apple&amp;rsquo;s Wi-Fi positioning service, with no special privilege and no specialised hardware, and in a single year reconstructed the precise location of more than two billion Wi-Fi access points worldwide. Their paper, &lt;a href=&#34;https://www.cs.umd.edu/~dml/papers/wifi-surveillance-sp24.pdf&#34;&gt;Surveilling the Masses with Wi-Fi-Based Positioning Systems&lt;/a&gt;
, shows what that map makes possible: tracking equipment moving in and out of Ukraine, observing population displacement after the Maui wildfires, following an individual through their home internet router.&lt;/p&gt;
&lt;p&gt;None of those devices had GPS switched on. The position came from somewhere else.&lt;/p&gt;
&lt;p&gt;This is the most widespread blind spot in mobile privacy: the belief that there is a location switch, and that once it is off, the phone stops knowing where it is. That belief is wrong on seven separate levels.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Location is not a feature your phone turns on. It is a property of what your phone is.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;gps-the-least-troubling-vector-of-all&#34;&gt;GPS, the least troubling vector of all&lt;/h2&gt;
&lt;p&gt;The one mechanism everybody can name is also the one that should worry you least.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;GNSS&lt;/strong&gt;, the umbrella term covering American GPS, Galileo, GLONASS and BeiDou, works by listening. Satellites continuously broadcast timestamped signals, the receiver picks up several of them and computes its position from the differences in propagation time. Typical accuracy in the open: three to five metres, often several tens of metres in a city, where building façades reflect the signals.&lt;/p&gt;
&lt;p&gt;The decisive point is that this calculation is &lt;strong&gt;passive&lt;/strong&gt;. The phone transmits nothing towards the satellites, and no satellite operator knows you exist. If GNSS were the only thing in play, turning off GPS would be enough.&lt;/p&gt;
&lt;p&gt;There is a caveat, however. To speed up the first fix, phones use &lt;strong&gt;A-GPS&lt;/strong&gt;: they download satellite ephemeris data from a server, over the &lt;a href=&#34;https://en.wikipedia.org/wiki/Assisted_GNSS&#34;&gt;SUPL&lt;/a&gt;
 protocol. To receive the right data, the phone sends that server the identifier of the network cell it is attached to. Pure GNSS does not betray you, but the accelerator bolted onto it does.&lt;/p&gt;
&lt;h2 id=&#34;the-mobile-network-what-the-operator-knows-by-design&#34;&gt;The mobile network: what the operator knows by design&lt;/h2&gt;
&lt;p&gt;For a call to reach you, the network has to know roughly where you are. This is not an option you can enable, it is the precondition for the service existing at all. Your phone announces itself continuously to the nearest tower, and that registration leaves a record on the operator&amp;rsquo;s side. No installed app, no permission granted: an active SIM card is enough.&lt;/p&gt;
&lt;p&gt;Accuracy depends on the method:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cell ID alone&lt;/strong&gt;: from 200 metres in a dense urban area to more than 30 kilometres in the countryside, where a single tower covers a very wide radius.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhanced Cell ID&lt;/strong&gt;, which adds the antenna sector (most sites are split into three 120-degree sectors) and signal strength: from 100 metres to a few kilometres.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Timing advance&lt;/strong&gt;, which measures the round-trip delay between phone and tower: on the order of 550 metres on GSM, around 78 metres on LTE.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Multilateration&lt;/strong&gt; across three or more towers: 50 to 300 metres in urban LTE.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;5G&lt;/strong&gt; changes the scale for two cumulative reasons. Density first: 5G cells cover much shorter radii, so simple attachment is already fine-grained information. Standardisation second: since Release 16, 3GPP has built in native positioning signals. Commercial targets aim for under 3 metres indoors and under 10 metres outdoors for 80% of devices, and &lt;a href=&#34;https://arxiv.org/pdf/2401.17594&#34;&gt;Release 18&lt;/a&gt;
 goes down to centimetre level for certain industrial use cases.&lt;/p&gt;
&lt;p&gt;The infrastructure that connects you therefore becomes a positioning system of a quality comparable to GPS, without you having enabled anything. That data is retained under national rules and made available to authorities through procedures that vary widely. It is the same underlying debate as the one covered in our piece on &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;the jurisdiction applicable to hosted data&lt;/a&gt;
: technical protection and legal protection do not overlap.&lt;/p&gt;
&lt;h2 id=&#34;wi-fi-a-map-of-the-world-made-of-hardware-addresses&#34;&gt;Wi-Fi: a map of the world made of hardware addresses&lt;/h2&gt;
&lt;p&gt;Every Wi-Fi access point continuously broadcasts a unique hardware identifier, the &lt;strong&gt;BSSID&lt;/strong&gt;. These identifiers are fixed and geographically stable: a home router stays in the same place for years.&lt;/p&gt;
&lt;p&gt;Apple, Google and a handful of specialised players maintain databases mapping each BSSID to coordinates, built by their own users&amp;rsquo; phones, which report the list of visible access points together with a GNSS fix. The operation is then reversed: a phone that can see four known access points no longer needs a single satellite. In a dense urban area, accuracy routinely reaches a few tens of metres, and drops below that indoors.&lt;/p&gt;
&lt;p&gt;Two properties make this mechanism hard to neutralise. First, the phone &lt;strong&gt;scans even when Wi-Fi appears to be off&lt;/strong&gt;: since Android 4.3, the system keeps a periodic scan running to improve location accuracy, independently of the quick-settings toggle. This behaviour depends on a separate setting, buried in the location services, that almost no user has ever opened.&lt;/p&gt;
&lt;p&gt;Second, the database can be queried from outside. That is the flaw Rye and Levin exploited: the positioning interfaces return not only the requested location but also that of nearby access points, which makes it possible to harvest the map without ever going near the places involved.&lt;/p&gt;
&lt;h2 id=&#34;bluetooth-and-ble-located-by-other-peoples-phones&#34;&gt;Bluetooth and BLE: located by other people&amp;rsquo;s phones&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Bluetooth Low Energy&lt;/strong&gt; adds a proximity layer, with a range of a few metres to a few tens of metres, making it far more fine-grained than the mobile network. Two uses coexist. &lt;strong&gt;Commercial beacons&lt;/strong&gt;, deployed in shops, airports and shopping centres, broadcast an identifier that apps on the phone recognise, revealing which aisle you stopped in front of and for how long. And &lt;strong&gt;crowd-sourced location networks&lt;/strong&gt;, of which Apple&amp;rsquo;s Find My is the model, since copied by Google and Samsung.&lt;/p&gt;
&lt;p&gt;This second mechanism inverts an implicit assumption. The reference analysis, &lt;a href=&#34;https://petsymposium.org/popets/2021/popets-2021-0045.php&#34;&gt;Who Can Find My Devices?&lt;/a&gt;
, published in the PETS 2021 proceedings by researchers at the Technical University of Darmstadt, reverse-engineered Apple&amp;rsquo;s protocol. An offline device emits a BLE signal, any nearby Apple device picks it up, attaches its own position and sends it encrypted to Apple&amp;rsquo;s servers, without the knowledge of either its owner or the owner of the device being located.&lt;/p&gt;
&lt;p&gt;The consequence is structural: a device with no SIM card, no Wi-Fi and no network connection of any kind remains locatable, as long as a stranger walks past with a phone in their pocket. Your isolation no longer depends on your settings, but on those of passers-by.&lt;/p&gt;
&lt;h2 id=&#34;inertial-sensors-locating-you-without-location-permission&#34;&gt;Inertial sensors: locating you without location permission&lt;/h2&gt;
&lt;p&gt;A phone contains an accelerometer, a gyroscope, a magnetometer and often a barometer. These sensors fall under a permission category separate from location: an app can read them without ever having asked where you are.&lt;/p&gt;
&lt;p&gt;Researchers at Princeton demonstrated this with &lt;a href=&#34;https://arxiv.org/pdf/1802.01468&#34;&gt;PinMe&lt;/a&gt;
. Their app starts from the IP address and time zone for a coarse position, then reads the sensors: the accelerometer gives the acceleration and braking profile, the gyroscope the sequence of turns, the magnetometer the heading, the barometer the changes in altitude. A neural network identifies the mode of transport, walking, car, train or plane, and the route is matched against public mapping, elevation and weather data. The result: a trajectory of accuracy comparable to GPS, with no location permission. The method has limits, which the authors document, since it fails in areas without roads and degrades on uniform grid layouts, where many routes produce the same signature. It remains the demonstration that a denied permission is not a closed door.&lt;/p&gt;
&lt;p&gt;The barometer additionally supplies the dimension GNSS handles poorly, the vertical one. US requirements for emergency calls mandate floor-level accuracy of plus or minus 3 metres for 80% of indoor calls. Knowing which floor someone is on is a different kind of knowledge from knowing which city block they are in.&lt;/p&gt;
&lt;h2 id=&#34;the-data-market-the-most-mundane-vector&#34;&gt;The data market: the most mundane vector&lt;/h2&gt;
&lt;p&gt;The mechanisms above describe how a position is computed. What remains is where it goes, and that is where most of the everyday risk lies.&lt;/p&gt;
&lt;p&gt;Thousands of apps integrate &lt;strong&gt;advertising SDKs&lt;/strong&gt;, third-party software components a developer adds to monetise their work or measure their audience. These components inherit the host app&amp;rsquo;s permissions: a weather app that legitimately needs your location passes it to companies whose names you have never read. To this are added &lt;strong&gt;advertising bid streams&lt;/strong&gt;, where your approximate position is broadcast to dozens of potential buyers every time a banner is displayed, including to those who buy nothing and simply listen.&lt;/p&gt;
&lt;p&gt;This raw material feeds an industry. The Electronic Frontier Foundation documented the case of &lt;a href=&#34;https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police&#34;&gt;Fog Data Science&lt;/a&gt;
, which claimed billions of data points on more than 250 million devices, sold to local US police forces. Brian Krebs described &lt;a href=&#34;https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/&#34;&gt;Locate X&lt;/a&gt;
, a product that lets you draw a polygon on a map and view the history of devices that entered and left that area.&lt;/p&gt;
&lt;p&gt;This vector requires no technical feat, only that somebody is willing to pay. The price is modest.&lt;/p&gt;
&lt;h2 id=&#34;imsi-catchers-active-location&#34;&gt;IMSI catchers: active location&lt;/h2&gt;
&lt;p&gt;The mechanisms described so far exploit normal operation. There is also active location, carried out by a third party intervening on the network.&lt;/p&gt;
&lt;p&gt;An &lt;strong&gt;IMSI catcher&lt;/strong&gt;, or cell-site simulator, is a piece of equipment that impersonates a legitimate tower. Phones within range attach to it, revealing their subscriber identifier and their presence within a limited perimeter.&lt;/p&gt;
&lt;p&gt;5G was supposed to close that door by replacing the permanent cleartext identifier with an encrypted one, the SUCI. The closure is partial. The work presented under the title &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt;
 documents linkage attacks that make it possible to re-correlate sessions despite the encryption. More importantly, the protection collapses entirely if the attacker forces the device to fall back to an earlier generation, 2G in particular, whose authentication is one-way. A 5G phone remains vulnerable to an attack designed for a 1990s network, because it still agrees to go down there.&lt;/p&gt;
&lt;h2 id=&#34;countermeasures-and-how-effective-they-really-are&#34;&gt;Countermeasures, and how effective they really are&lt;/h2&gt;
&lt;p&gt;Every measure below does something. None of them does everything, and the gap between what they do and what people credit them with is what produces bad decisions.&lt;/p&gt;
&lt;h3 id=&#34;airplane-mode&#34;&gt;Airplane mode&lt;/h3&gt;
&lt;p&gt;Airplane mode cuts transmission from the cellular modem, Wi-Fi and Bluetooth. That is real, and it is the best result available for such little effort.&lt;/p&gt;
&lt;p&gt;What it does not do: it does not stop the inertial sensors, it does not delete already cached positions, which will be sent on reconnection, and on most devices it allows Wi-Fi or Bluetooth to be switched back on separately without leaving the mode. Finally, it is a software state, not a power cut: its reliability depends on the integrity of the system enforcing it.&lt;/p&gt;
&lt;p&gt;An underrated detail: detaching from and re-attaching to the network are themselves timestamped events on the operator&amp;rsquo;s side. A phone that vanishes at 9 pm in one cell and reappears at 11 pm in another has produced information, not silence.&lt;/p&gt;
&lt;h3 id=&#34;mac-address-randomisation&#34;&gt;MAC address randomisation&lt;/h3&gt;
&lt;p&gt;Mobile systems today emit random MAC addresses when scanning, to prevent tracking from one place to another. The intent is good, the result incomplete. The reference work, including &lt;a href=&#34;https://papers.mathyvanhoef.com/asiaccs2016.pdf&#34;&gt;Why MAC Address Randomization is not Enough&lt;/a&gt;
, shows that the content of discovery frames is often enough to re-identify the device: the number of information elements, their values and their order form a fingerprint. Add to that sequence numbers, which are incremental and therefore chainable, and the timing signature specific to each model. Some studies report successfully tracking half of all devices for at least twenty minutes.&lt;/p&gt;
&lt;p&gt;Finally, a conceptual limit: randomisation only applies to the discovery phase. As soon as you connect to a network, the address used is stable for that network, by design, so that the connection works. The café you go to every morning recognises you.&lt;/p&gt;
&lt;h3 id=&#34;actually-turning-off-scanning&#34;&gt;Actually turning off scanning&lt;/h3&gt;
&lt;p&gt;This is the most cost-effective and most overlooked setting. On Android, Wi-Fi scanning and Bluetooth scanning are two separate options, located in the location services, independent of the quick-settings toggles. As long as they are active, turning Wi-Fi off from the panel is not enough: the scanning continues.&lt;/p&gt;
&lt;p&gt;Disabling them removes an entire layer of collection, at no cost other than a slightly slower first position fix. For most readers, this is the best ratio between effort spent and result obtained.&lt;/p&gt;
&lt;h3 id=&#34;app-permissions&#34;&gt;App permissions&lt;/h3&gt;
&lt;p&gt;Revoking location permission from apps that manifestly do not need it remains useful, and recent systems offer three gradations: one-off authorisation, authorisation limited to active use, and &lt;strong&gt;approximate location&lt;/strong&gt;, which only transmits an area on the order of a kilometre.&lt;/p&gt;
&lt;p&gt;This does not, however, protect against SDKs hosted inside an app that has a legitimate reason to access your location, nor against inertial sensors, nor against the network layers, which go through no permission at all.&lt;/p&gt;
&lt;h3 id=&#34;what-a-vpn-does-not-protect&#34;&gt;What a VPN does not protect&lt;/h3&gt;
&lt;p&gt;A point worth clarifying, because the opposite belief is very widespread: &lt;strong&gt;a VPN does not hide your location&lt;/strong&gt;. It hides your public IP address, so it falsifies IP-based geolocation, which is in any case the crudest mechanism on this list.&lt;/p&gt;
&lt;p&gt;A VPN touches neither the GNSS receiver, nor Wi-Fi scanning, nor Bluetooth, nor the sensors. It changes nothing about what your operator knows, since the encrypted tunnel travels through its towers and cellular attachment remains visible to it. It does not stop an app holding location permission from transmitting exact coordinates inside the tunnel. A VPN protects the content and destination of your communications on an untrusted network, and that is already a lot. Location is not within its scope.&lt;/p&gt;
&lt;h3 id=&#34;physical-limits&#34;&gt;Physical limits&lt;/h3&gt;
&lt;p&gt;A Faraday pouch works in the literal sense: it blocks transmission and reception. So does removing the battery, where that is still possible. A dedicated device, or simply leaving your phone elsewhere, remains the most robust measure.&lt;/p&gt;
&lt;p&gt;These solutions share a flaw that has to be faced head-on: they produce an anomaly. A phone that goes quiet for two hours every Tuesday evening is saying something. Against an adversary who analyses patterns rather than instantaneous positions, absence is data.&lt;/p&gt;
&lt;h3 id=&#34;three-adversaries-three-strategies&#34;&gt;Three adversaries, three strategies&lt;/h3&gt;
&lt;p&gt;This is the most important distinction in this article, and the one you read least often.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against an advertiser or a data broker&lt;/strong&gt;, the fight is winnable. Permission discipline, disabling scanning, a system without proprietary location services, resetting the advertising identifier: together these sharply reduce the volume collected. This adversary is after cheap volume, not your particular case.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against your operator&lt;/strong&gt;, no configuration is enough. Cellular location is the precondition for the service. The only real variables are legal, what the law permits to be retained and disclosed, and material: which device, which SIM card, in whose name, switched on where.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against a targeted state adversary&lt;/strong&gt;, the reasoning changes again, since it combines legal access to operator data, active location via cell-site simulator, requisitions to platforms and, where applicable, compromise of the device itself. Software countermeasures reduce the surface, but the realistic goal is not disappearance: it is knowing precisely what remains exposed.&lt;/p&gt;
&lt;h2 id=&#34;the-arpokratos-approach&#34;&gt;The ArpokratOS approach&lt;/h2&gt;
&lt;p&gt;&lt;a href=&#34;https://arpokrat.com/os/&#34;&gt;ArpokratOS&lt;/a&gt;
 answers this landscape with a choice that follows from the distinction above: what needs to be neutralised is neutralised at system level, not in a menu.&lt;/p&gt;
&lt;p&gt;On &lt;strong&gt;GNSS&lt;/strong&gt;, the hardware driver is removed. The device behaves as if the chip did not exist, both for applications and for the system itself. The difference from a settings toggle is not cosmetic. A toggle is a policy: it is enforced by a layer that can be bypassed by a sufficiently privileged component, re-enabled by an update, or ignored by a compromised system. Removing the code path removes the question, since there is no longer anything to enable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Bluetooth&lt;/strong&gt; is handled at the Core level, on the same logic. Bluetooth switched off in the settings in practice leaves the software stack alive on many devices, to feed proximity services and crowd-sourced location networks. Absent at system level, it cannot talk to a shop beacon, take part in a Find My-style network, or serve as a zero-interaction attack surface.&lt;/p&gt;
&lt;p&gt;It has to be said plainly what this does not do. &lt;strong&gt;ArpokratOS does not make a phone undetectable.&lt;/strong&gt; As long as a SIM card is active, the operator knows the cell you are attached to, and no operating system changes that, not even with all traffic routed over Tor. Routing protects the content and the destination, not the radio geometry. Anyone promising invisibility is selling a story.&lt;/p&gt;
&lt;p&gt;What such an architecture provides is more modest: the removal of the application and proximity layers, through which the vast majority of real-world collection passes, and an explicit threat model for what remains. It is the same reasoning applied to choosing a desktop system, detailed in our &lt;a href=&#34;https://arpokrat.com/blog/os-comparison-security-privacy-windows-macos-linux-qubes/&#34;&gt;operating system comparison&lt;/a&gt;
: the useful question is not whether a tool protects, but what it protects against and at what price.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;This article does not provide a method for disappearing. That method does not exist, and texts claiming otherwise mostly produce false confidence, which is more dangerous than no protection at all because it makes people take risks.&lt;/p&gt;
&lt;p&gt;The aim was to replace a binary question, am I locatable or not, with a useful one: by whom, with what accuracy, at what cost to them, and does it matter to me. The answer differs for a journalist protecting a source, an executive travelling in a sensitive jurisdiction, a lawyer whose appointments reveal a strategy, or a private individual annoyed that an advertiser knows their habits.&lt;/p&gt;
&lt;p&gt;What deserves attention, in fact, is not the performance of each of these mechanisms taken in isolation, but the fact that they overlap. A position accurate to fifty metres is not very interesting. A position accurate to fifty metres, every fifteen minutes, for two years, draws a home, a workplace, a religion, a health condition, an affair, a source. Location data is the metadata that makes all the others legible, and that is why it is worth so much.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Erik Rye, Dave Levin, &lt;a href=&#34;https://www.cs.umd.edu/~dml/papers/wifi-surveillance-sp24.pdf&#34;&gt;Surveilling the Masses with Wi-Fi-Based Positioning Systems&lt;/a&gt;
, IEEE Symposium on Security and Privacy, 2024&lt;/li&gt;
&lt;li&gt;Alexander Heinrich et al., &lt;a href=&#34;https://petsymposium.org/popets/2021/popets-2021-0045.php&#34;&gt;Who Can Find My Devices? Security and Privacy of Apple&amp;rsquo;s Crowd-Sourced Bluetooth Location Tracking System&lt;/a&gt;
, PoPETs, 2021&lt;/li&gt;
&lt;li&gt;Arsalan Mosenia et al., &lt;a href=&#34;https://arxiv.org/pdf/1802.01468&#34;&gt;PinMe: Tracking a Smartphone User around the World&lt;/a&gt;
, IEEE Transactions on Multi-Scale Computing Systems&lt;/li&gt;
&lt;li&gt;Mathy Vanhoef et al., &lt;a href=&#34;https://papers.mathyvanhoef.com/asiaccs2016.pdf&#34;&gt;Why MAC Address Randomization is not Enough: An Analysis of Wi-Fi Network Discovery Mechanisms&lt;/a&gt;
, AsiaCCS, 2016&lt;/li&gt;
&lt;li&gt;Merlin Chlosta et al., &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt;
, ACM WiSec, 2021&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://arxiv.org/pdf/2401.17594&#34;&gt;5G NR Positioning Enhancements in 3GPP Release-18&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police&#34;&gt;Inside Fog Data Science, the Secretive Company Selling Mass Surveillance to Local Police&lt;/a&gt;
, 2022&lt;/li&gt;
&lt;li&gt;Krebs on Security, &lt;a href=&#34;https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/&#34;&gt;The Global Surveillance Free-for-All in Mobile Ad Data&lt;/a&gt;
, 2024&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://ssd.eff.org/module/mobile-phones-location-tracking&#34;&gt;Mobile Phones: Location Tracking&lt;/a&gt;
, Surveillance Self-Defense&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>Which operating system for your security and privacy? Windows, macOS, Linux, Tails, Whonix and Qubes OS compared</title>
      <link>https://arpokrat.com/blog/os-comparison-security-privacy-windows-macos-linux-qubes/</link>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/os-comparison-security-privacy-windows-macos-linux-qubes/</guid>
      <description>&lt;p&gt;Choosing an operating system is not merely a matter of interface preference or software compatibility. It is also — and increasingly so — a security and privacy decision. Each OS collects data differently, exposes different attack surfaces, and offers a highly variable level of control to the user. This comparison analyzes the main systems on the market exclusively through this lens, from the most widely used to the most specialized.&lt;/p&gt;
&lt;h2 id=&#34;the-central-criterion-who-controls-your-system&#34;&gt;The central criterion: who controls your system?&lt;/h2&gt;
&lt;p&gt;Before diving into the details of each OS, one structuring principle: the security of an operating system fundamentally depends on who holds the code and what architectural decisions were made at design time. A proprietary closed-source OS (Windows, macOS) delegates that trust to its publisher. An open-source OS delegates that trust to the community auditing the code. An OS designed for compartmentalized security (Qubes OS) starts from the assumption that no component of the system should be entirely trusted.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;windows-11&#34;&gt;Windows 11&lt;/h2&gt;
&lt;h3 id=&#34;data-collection-and-telemetry&#34;&gt;Data collection and telemetry&lt;/h3&gt;
&lt;p&gt;Windows 11 is the most widely used desktop OS in the world, and also one of those that collects the most data by default. Microsoft divides its telemetry into two official categories:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Required data&lt;/strong&gt; (cannot be disabled on Home and Pro editions): hardware configuration, device identifiers, error and stability reports, update and driver data. This data is transmitted to Microsoft regardless of user preferences.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Optional data&lt;/strong&gt;: usage behavior, application interactions, personalization data. Can be disabled in settings, but is automatically re-enabled during certain major updates.&lt;/p&gt;
&lt;p&gt;Windows 11 24H2 introduced several new collection layers tied to AI:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Windows Recall&lt;/strong&gt;: takes a screenshot every five seconds to create a searchable timeline of everything you have done on your machine. Can be disabled, but is enabled by default and linked to access rights that can be extended by other applications&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Copilot&lt;/strong&gt;: every query is transmitted to Microsoft servers, including screenshots, selected text, and the context of open applications&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Defender Cloud Protection&lt;/strong&gt;: sends hashes of suspicious files and behavioral data to the Microsoft cloud for analysis&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The conclusion documented by numerous independent technical sources is unequivocal: it is impossible to fully disable Windows 11 telemetry on Home and Pro editions. The only way to achieve this is to use an Enterprise or Education edition, apply specific group policies, or resort to third-party tools such as O&amp;amp;O ShutUp10++ or WPD, with the stability risks that may entail.&lt;/p&gt;
&lt;h3 id=&#34;attack-surface-and-security&#34;&gt;Attack surface and security&lt;/h3&gt;
&lt;p&gt;Windows 11 is the target of the vast majority of malware, ransomware, and exploits available worldwide, proportional to its market share. Microsoft has introduced significant security mechanisms (mandatory TPM 2.0, Secure Boot, VBS, Credential Guard), but these operate within a monolithic model: a compromise of the kernel or a privileged system service affects the entire environment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security/privacy verdict:&lt;/strong&gt; the most exposed system in this comparison, telemetry that cannot be fully disabled, trust model entirely delegated to Microsoft and US jurisdiction.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;macos&#34;&gt;macOS&lt;/h2&gt;
&lt;h3 id=&#34;data-collection-and-telemetry-1&#34;&gt;Data collection and telemetry&lt;/h3&gt;
&lt;p&gt;Apple has built part of its marketing image on privacy. The technical reality is more nuanced.&lt;/p&gt;
&lt;p&gt;macOS collects significantly less data than Windows by default, but collection remains real and partially non-disableable:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Gatekeeper and OCSP verification&lt;/strong&gt;: every time an application is opened, macOS performs an online check with Apple servers to confirm the application has not been revoked. This request transmits information about the opened application and the device&amp;rsquo;s IP address. No native setting allows disabling these checks without breaking the security chain&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;macOS Analytics&lt;/strong&gt;: collects data on system usage, disableable in System Preferences &amp;gt; Privacy &amp;gt; Analytics&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apple application telemetry&lt;/strong&gt;: Maps, Siri, App Store, and other built-in Apple applications each maintain their own collection with rotating identifiers, independently of the system analytics setting&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For users who want to go further, security experts recommend using an application firewall (Little Snitch or LuLu, which is open source and free) to monitor and block outgoing connections on a per-application basis.&lt;/p&gt;
&lt;h3 id=&#34;attack-surface-and-security-1&#34;&gt;Attack surface and security&lt;/h3&gt;
&lt;p&gt;macOS benefits from several robust security mechanisms: System Integrity Protection (SIP), which protects system files as read-only; Kernel Integrity Protection at the hardware level on Apple Silicon chips; sandboxing of App Store applications; and the Secure Enclave on recent machines. The relationship with an Apple ID is the primary vector for personal data collection.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security/privacy verdict:&lt;/strong&gt; better than Windows on default telemetry, but still subject to non-disableable OCSP checks, US jurisdiction, and Apple&amp;rsquo;s closed model. Difficult to audit independently.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;linux-general-purpose-distributions&#34;&gt;Linux (general-purpose distributions)&lt;/h2&gt;
&lt;p&gt;Linux is not a single operating system but a kernel upon which very different distributions are built. From a security and privacy standpoint, they share a common foundation but diverge on several points.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ubuntu&lt;/strong&gt; is the most popular distribution for beginners. It sparked controversy in 2012 by sending local search queries to Amazon servers — behavior that has since been removed. Ubuntu maintains its own usage data collection (whoopsie, ubuntu-report), which is disableable, and tightly integrates Snap repositories controlled by Canonical Ltd.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Debian&lt;/strong&gt; is the base upon which Ubuntu is built, without the layers added by Canonical. Governed by a non-profit community project with a strict commitment to free software, it collects no telemetry by default. Its conservative update policy is generally preferable in terms of attack surface.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fedora&lt;/strong&gt;, sponsored by Red Hat (an IBM subsidiary), is technically modern with a fast update cycle. No telemetry by default, but the relationship with Red Hat/IBM introduces a corporate dependency worth noting.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Linux Mint&lt;/strong&gt;, derived from Ubuntu, is designed for users coming from Windows. It has removed the most controversial Ubuntu components (Snap is absent by default) and introduces no telemetry of its own.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Arch Linux&lt;/strong&gt; targets advanced users with a minimalist philosophy: the user installs only what they need. No telemetry, rolling release updates, and total freedom of customization.&lt;/p&gt;
&lt;h3 id=&#34;what-linux-fundamentally-offers&#34;&gt;What Linux fundamentally offers&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Open and auditable source code&lt;/strong&gt;: any security researcher can inspect the kernel and main component code&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No imposed telemetry&lt;/strong&gt;: no major distribution forces non-disableable data collection&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Stricter permissions model&lt;/strong&gt; by default: use of a root account separate from daily actions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduced attack surface&lt;/strong&gt;: Linux is less targeted by mass malware&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Security/privacy verdict:&lt;/strong&gt; clearly superior to Windows and macOS on data collection. No general-purpose distribution protects against a compromised application spreading across the entire system.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;tails-os&#34;&gt;Tails OS&lt;/h2&gt;
&lt;h3 id=&#34;philosophy-amnesia-as-protection&#34;&gt;Philosophy: amnesia as protection&lt;/h3&gt;
&lt;p&gt;Tails, an acronym for &lt;em&gt;The Amnesic Incognito Live System&lt;/em&gt;, is a Debian-based operating system that merged with the Tor Project in 2024. Its philosophy is radically different from all other OSes: rather than attempting to secure a persistent environment, it eliminates all persistence by default. &lt;strong&gt;Tails exists only for the duration of a session.&lt;/strong&gt;&lt;/p&gt;
&lt;h3 id=&#34;technical-architecture&#34;&gt;Technical architecture&lt;/h3&gt;
&lt;p&gt;Tails runs entirely from a USB drive (8 GB minimum) and operates entirely in RAM. When you shut it down, no trace remains on the host machine: no temporary files, no history, no credentials, no forensic artifacts on the PC&amp;rsquo;s hard drive. It does not matter if that PC is compromised at the software level: Tails never writes to its disk.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tor by default and without exception&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;All network traffic in Tails is systematically routed through the Tor network. If an application attempts to establish a direct connection bypassing Tor, Tails blocks it. It is not possible to use Tails to browse without Tor, even by mistake.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Encrypted persistent storage (optional)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;By default, Tails forgets everything on each shutdown. For users who need to retain certain data between sessions, Tails offers a &lt;strong&gt;Persistent Storage&lt;/strong&gt;: an encrypted volume (LUKS) created on the USB drive itself, protected by a passphrase. The user chooses precisely what is stored there: certain files, application configurations, PGP keys, etc. This persistent storage does not change the amnesic nature of Tails with respect to the host machine — it only affects what is retained on the USB drive between sessions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pre-installed tools&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Tails comes with a set of pre-configured tools: Tor Browser, an encrypted email client, a file encryption tool (Kleopatra/GnuPG), secure messaging clients, and LibreOffice for office tasks. No additional software needs to be installed for common high-security use.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2026 technical note:&lt;/strong&gt; Tails 7.7 added a notification for outdated Secure Boot certificates, as Microsoft&amp;rsquo;s 2011 keys are beginning to expire in June 2026. Users whose UEFI firmware has not been updated may no longer be able to boot Tails on certain machines.&lt;/p&gt;
&lt;h3 id=&#34;what-tails-protects-against-and-what-it-does-not&#34;&gt;What Tails protects against and what it does not&lt;/h3&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Threat&lt;/th&gt;
					&lt;th&gt;Tails Protection&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;Forensic analysis of the host disk after seizure&lt;/td&gt;
					&lt;td&gt;Total: the host disk is never touched&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Network surveillance (IP, sites visited)&lt;/td&gt;
					&lt;td&gt;Strong via Tor, but depends on Tor&amp;rsquo;s robustness&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Persistent malware on the host machine&lt;/td&gt;
					&lt;td&gt;Bypassed: Tails does not use the installed system&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;BIOS/UEFI malware (compromised firmware)&lt;/td&gt;
					&lt;td&gt;None: Tails cannot protect against the firmware of the machine being used&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Human error (logging into a personal account)&lt;/td&gt;
					&lt;td&gt;None: if you log into Gmail under Tails, you de-anonymize the session&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Compromise of software during the session&lt;/td&gt;
					&lt;td&gt;Limited to the current session, destroyed on shutdown&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&#34;honest-limitations&#34;&gt;Honest limitations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Tails is not suitable for everyday use: the lack of persistence means reconfiguring the environment on every boot&lt;/li&gt;
&lt;li&gt;A BIOS or firmware-level malware (such as a UEFI-level implant) can potentially compromise a Tails session, because Tails does not control the firmware layer of the machine it runs on&lt;/li&gt;
&lt;li&gt;Logging into a personal account (email, social network) cancels the anonymity of the session, regardless of Tor&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;who-is-it-for&#34;&gt;Who is it for?&lt;/h3&gt;
&lt;p&gt;Journalists working with sources via SecureDrop, activists under surveillance in repressive regimes, and anyone needing a one-off high-sensitivity session on hardware they do not control. Used by Glenn Greenwald and Laura Poitras to process the Snowden documents, recommended by the EFF, the Freedom of the Press Foundation, and the Tor Project.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; a first-choice tool for one-off high-sensitivity sessions. Not a primary everyday OS.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;whonix&#34;&gt;Whonix&lt;/h2&gt;
&lt;h3 id=&#34;philosophy-structural-anonymity-through-network-isolation&#34;&gt;Philosophy: structural anonymity through network isolation&lt;/h3&gt;
&lt;p&gt;Whonix addresses a different question than Tails: rather than erasing all traces after the session, it ensures that malware running in the work environment &lt;strong&gt;structurally cannot know the user&amp;rsquo;s real IP address&lt;/strong&gt;, even if it has root privileges on the work virtual machine.&lt;/p&gt;
&lt;p&gt;Whonix is based on Debian (via KickSecure, a hardened version of Debian developed by the same team) and runs inside a Type 2 hypervisor (VirtualBox, KVM) on any host OS, or natively in Qubes OS as a Type 1.&lt;/p&gt;
&lt;h3 id=&#34;the-two-vm-architecture&#34;&gt;The two-VM architecture&lt;/h3&gt;
&lt;p&gt;The central principle of Whonix is a &lt;strong&gt;strict separation between the network layer and the application layer&lt;/strong&gt;, implemented via two distinct virtual machines:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Whonix-Gateway&lt;/strong&gt; is the first VM. It runs the Tor daemon and serves exclusively as a network gateway. It is the only VM with Internet access. It contains no user applications. Its sole role is to intercept all incoming and outgoing network traffic and force it through Tor.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Whonix-Workstation&lt;/strong&gt; is the second VM. It is the working environment: browser, messaging, file processing, development. It is connected to the Internet only through the internal virtual network pointing to the Whonix-Gateway. It has no direct Internet access, no ability to connect in a way that would bypass the Gateway.&lt;/p&gt;
&lt;p&gt;Here is what happens when a network request is made from the Workstation:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The application issues a network request&lt;/li&gt;
&lt;li&gt;The Workstation sends it via its internal network interface to the Gateway&lt;/li&gt;
&lt;li&gt;The Gateway intercepts the request and reroutes it through Tor (three successive relays)&lt;/li&gt;
&lt;li&gt;The response returns by the same path in reverse&lt;/li&gt;
&lt;li&gt;The Workstation receives the response without ever having knowledge of the real exit IP address&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;The fundamental guarantee&lt;/strong&gt;: even if malware compromises the Workstation with root privileges, it cannot know the user&amp;rsquo;s real IP address, because the Workstation itself never has access to it. The Workstation only sees the internal IP address of the Gateway.&lt;/p&gt;
&lt;h3 id=&#34;additional-security-mechanisms&#34;&gt;Additional security mechanisms&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Stream isolation&lt;/strong&gt;: Whonix uses separate Tor circuits for different applications (the browser does not use the same circuit as the email client, etc.), which prevents traffic correlation between different activities.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Boot clock randomization&lt;/strong&gt;: the Workstation&amp;rsquo;s system clock is slightly and randomly offset on each boot to prevent timing attacks based on the exact system time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;sdwdate&lt;/strong&gt;: Whonix uses its own time synchronization daemon (sdwdate) that retrieves the time via Tor from onion servers, instead of classic NTP which could leak the IP address.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;AppArmor&lt;/strong&gt;: AppArmor profiles harden the sandboxing of critical applications such as Tor Browser at the system level.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disposable VMs&lt;/strong&gt;: Whonix supports disposable Workstations (&lt;em&gt;Whonix-Workstation DispVM&lt;/em&gt; in Qubes-Whonix) for one-off tasks without persistence, similar to the Tails approach but within an otherwise persistent environment.&lt;/p&gt;
&lt;h3 id=&#34;the-three-deployment-modes&#34;&gt;The three deployment modes&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Whonix on VirtualBox or KVM (Type 2)&lt;/strong&gt;: the most accessible mode. Both VMs run on an existing host OS (Windows, Linux, macOS). Convenient, but introduces an additional trust layer in the host OS: if the host is compromised, Whonix&amp;rsquo;s protection can be bypassed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Qubes-Whonix (Type 1, recommended)&lt;/strong&gt;: Whonix is natively integrated into Qubes OS as templates. The Gateway becomes a ProxyVM (sys-whonix) and the Workstation an AppQube (anon-whonix). This is the most robust configuration because the isolation relies on the bare-metal Xen hypervisor rather than a Type 2 hypervisor running on a potentially vulnerable host OS. This is the configuration recommended by both projects.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Physical isolation (advanced mode)&lt;/strong&gt;: the Gateway and the Workstation run on two separate physical machines connected by an Ethernet cable. The Workstation has no network card except the one connected to the Gateway. This mode drastically reduces the trust base but requires two dedicated machines.&lt;/p&gt;
&lt;h3 id=&#34;what-whonix-protects-against-and-what-it-does-not&#34;&gt;What Whonix protects against and what it does not&lt;/h3&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Threat&lt;/th&gt;
					&lt;th&gt;Whonix Protection&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;IP address leak from the Workstation&lt;/td&gt;
					&lt;td&gt;Structurally impossible by architecture&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;DNS leaks&lt;/td&gt;
					&lt;td&gt;Impossible: all DNS goes through Tor via the Gateway&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Root malware on the Workstation seeking the real IP&lt;/td&gt;
					&lt;td&gt;None: it will not find it&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Compromise of the Gateway itself&lt;/td&gt;
					&lt;td&gt;Partial: if the Gateway is compromised, the IP can leak&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Host OS compromise (in Type 2 mode)&lt;/td&gt;
					&lt;td&gt;None: a compromised host can observe both VMs&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;De-anonymization through user behavior&lt;/td&gt;
					&lt;td&gt;None: Whonix does not protect against human error&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Forensic analysis of the disk after seizure&lt;/td&gt;
					&lt;td&gt;Partial: Whonix is persistent by default, except for disposable VMs&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&#34;honest-limitations-1&#34;&gt;Honest limitations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Whonix does not erase disk traces: it is persistent by default (unlike Tails). If your machine is seized and host disk encryption is absent or weak, VM data can be recovered&lt;/li&gt;
&lt;li&gt;In Type 2 mode (VirtualBox/KVM on a host OS), Whonix&amp;rsquo;s security is limited by the security of the host OS. A compromised host can potentially observe traffic between the two VMs&lt;/li&gt;
&lt;li&gt;Performance is impacted by double virtualization and routing through Tor: connections are slow, and large downloads are difficult on a daily basis&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;who-is-it-for-1&#34;&gt;Who is it for?&lt;/h3&gt;
&lt;p&gt;Anyone needing a persistent working environment with structural network anonymity: development of sensitive software, extended pseudonymous research, management of multiple distinct digital identities, onion servers. The Qubes-Whonix combination is considered by many security experts to be the most robust anonymous working environment currently available for everyday use.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; the reference OS for structural network anonymity in a persistent environment. Complementary to Tails (which handles one-off sessions), not a competitor.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;qubes-os&#34;&gt;Qubes OS&lt;/h2&gt;
&lt;h3 id=&#34;philosophy-security-through-compartmentalization&#34;&gt;Philosophy: security through compartmentalization&lt;/h3&gt;
&lt;p&gt;Qubes OS represents a fundamentally different approach from all the preceding systems. Whereas other OSes attempt to prevent compromises, Qubes starts from a radically different postulate: &lt;strong&gt;the compromise of certain components is inevitable. The objective is to ensure it cannot spread.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Created in 2012 by security researcher Joanna Rutkowska, Qubes OS is publicly recommended by Edward Snowden, among other security professionals.&lt;/p&gt;
&lt;h3 id=&#34;technical-architecture-1&#34;&gt;Technical architecture&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;The Xen hypervisor as the base layer&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Qubes is not a Linux distribution in the classical sense. It uses the &lt;strong&gt;Xen hypervisor&lt;/strong&gt;, bare-metal virtualization software that runs directly on the hardware without an intermediate host OS, to create lightweight virtual machines called &lt;strong&gt;qubes&lt;/strong&gt;. Isolation between qubes is enforced at the hardware level via &lt;strong&gt;Intel VT-x/VT-d&lt;/strong&gt; and &lt;strong&gt;AMD-Vi (IOMMU)&lt;/strong&gt; technologies, which prevent VMs from accessing the memory or devices of other VMs without explicit permission.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;dom0: the maximum-trust domain&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;At the top of the hierarchy sits &lt;strong&gt;dom0&lt;/strong&gt;, a privileged domain from which the desktop manager is run. dom0 manages the display of all windows from other qubes. For security reasons, dom0 has &lt;strong&gt;no network connection&lt;/strong&gt; and runs no user applications. It serves only to orchestrate display and domain management.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Qubes: airtight compartments&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The user defines as many qubes as needed, each corresponding to a trust context:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A &lt;strong&gt;&amp;ldquo;work&amp;rdquo;&lt;/strong&gt; qube for professional applications&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;&amp;ldquo;personal&amp;rdquo;&lt;/strong&gt; qube for emails and social networks&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;&amp;ldquo;banking&amp;rdquo;&lt;/strong&gt; qube dedicated solely to financial transactions&lt;/li&gt;
&lt;li&gt;An &lt;strong&gt;&amp;ldquo;untrusted&amp;rdquo;&lt;/strong&gt; qube for opening suspicious attachments&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Disposable qubes&lt;/strong&gt; that disappear entirely on closure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Each qube has its own network stack, its own memory space, and its own processes. Malware that compromises the &amp;ldquo;untrusted&amp;rdquo; qube is confined to that qube. It cannot access files in the &amp;ldquo;work&amp;rdquo; qube, nor traverse to other domains.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Visual color coding&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Each window displays a colored border corresponding to the trust level of its qube: red for untrusted domains, green for high-security isolated domains, yellow for semi-trusted domains. This simple visual system allows users to know at all times in which context each action is taking place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Templates and centralized management&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Qubes do not contain their own full OS installation: they share &lt;strong&gt;templates&lt;/strong&gt; (Fedora, Debian, and Whonix by default). Security updates are applied to the template, and all qubes based on that template benefit from them automatically.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PCI passthrough and hardware isolation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Whereas classic OSes run hardware drivers in the same space as user applications, Qubes assigns each physical device (network card, USB controller) to a dedicated qube via PCI passthrough. A compromised network driver cannot access data from other qubes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Whonix integration&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Qubes natively integrates Whonix as templates, allowing the traffic of any qube to be routed through Tor transparently. This is the Qubes-Whonix configuration described in the previous section.&lt;/p&gt;
&lt;h3 id=&#34;what-qubes-actually-protects-against&#34;&gt;What Qubes actually protects against&lt;/h3&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Attack scenario&lt;/th&gt;
					&lt;th&gt;Classic OS&lt;/th&gt;
					&lt;th&gt;Qubes OS&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;Malware in a PDF attachment&lt;/td&gt;
					&lt;td&gt;Potential access to the entire system&lt;/td&gt;
					&lt;td&gt;Confined to the &amp;ldquo;untrusted&amp;rdquo; qube, destroyed on closure&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Web browser exploit&lt;/td&gt;
					&lt;td&gt;Access to user profile, files&lt;/td&gt;
					&lt;td&gt;Confined to the browser qube&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Network driver compromise&lt;/td&gt;
					&lt;td&gt;Access to system memory&lt;/td&gt;
					&lt;td&gt;Confined to the network qube via PCI passthrough&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Stolen PGP key&lt;/td&gt;
					&lt;td&gt;Yes, if the signing software is compromised&lt;/td&gt;
					&lt;td&gt;No, if the key is in a dedicated qube with no network&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Leakage between applications&lt;/td&gt;
					&lt;td&gt;Possible via IPC, shared memory&lt;/td&gt;
					&lt;td&gt;Impossible between distinct qubes&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&#34;honest-limitations-2&#34;&gt;Honest limitations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Qubes does not protect against a dom0 compromise&lt;/strong&gt;: if the Xen hypervisor itself is compromised, isolation can be broken (bulletin QSB-115 dated June 9, 2026, regarding vulnerability XSA-491)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No isolation within a single qube&lt;/strong&gt;: two applications in the same qube are not isolated from each other&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Significant hardware requirements&lt;/strong&gt;: processor supporting VT-x/VT-d, minimum 16 GB RAM (32 GB recommended), 32 GB storage. Apple Silicon machines are not supported&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Real learning curve&lt;/strong&gt;: copy-pasting between qubes requires a conscious action, and installing software goes through templates&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;who-is-it-for-2&#34;&gt;Who is it for?&lt;/h3&gt;
&lt;p&gt;Qubes OS is designed for profiles whose threat model includes serious adversaries: journalists working with sensitive sources, lawyers managing confidential files, security researchers, professionals handling industrial or diplomatic secrets.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; the reference standard for personal workstation security against capable adversaries. The Qubes + Whonix combination is considered the most robust environment currently available.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;how-these-systems-combine&#34;&gt;How these systems combine&lt;/h2&gt;
&lt;p&gt;It is important to understand that these OSes are not exclusively alternatives to one another: they address different needs and are often combined.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Qubes + Whonix&lt;/strong&gt;: the most robust combination for high-security everyday use. Qubes handles compartmentalization, Whonix handles network anonymity within certain qubes&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Qubes + Tails&lt;/strong&gt;: some advanced users use Qubes as their primary OS and boot Tails from a dedicated qube for particularly sensitive one-off sessions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Linux + Whonix in VMs&lt;/strong&gt;: an accessible entry point into structural network anonymity without the full complexity of Qubes&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id=&#34;summary-table&#34;&gt;Summary table&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Criterion&lt;/th&gt;
					&lt;th&gt;Windows 11&lt;/th&gt;
					&lt;th&gt;macOS&lt;/th&gt;
					&lt;th&gt;Linux (Debian)&lt;/th&gt;
					&lt;th&gt;Tails&lt;/th&gt;
					&lt;th&gt;Whonix&lt;/th&gt;
					&lt;th&gt;Qubes OS&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;Default telemetry&lt;/td&gt;
					&lt;td&gt;Significant, cannot be fully disabled&lt;/td&gt;
					&lt;td&gt;Moderate, partially non-disableable&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Auditable source code&lt;/td&gt;
					&lt;td&gt;No&lt;/td&gt;
					&lt;td&gt;No&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Data persistence&lt;/td&gt;
					&lt;td&gt;Permanent&lt;/td&gt;
					&lt;td&gt;Permanent&lt;/td&gt;
					&lt;td&gt;Permanent&lt;/td&gt;
					&lt;td&gt;None by default&lt;/td&gt;
					&lt;td&gt;Permanent (VMs)&lt;/td&gt;
					&lt;td&gt;Permanent per qube&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Network anonymity&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;Strong (Tor enforced)&lt;/td&gt;
					&lt;td&gt;Structural (Tor enforced)&lt;/td&gt;
					&lt;td&gt;Via Whonix integration&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Isolation between applications&lt;/td&gt;
					&lt;td&gt;Weak&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Weak&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Strong (hypervisor)&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Resistance to compromise&lt;/td&gt;
					&lt;td&gt;Weak&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;High (amnesic)&lt;/td&gt;
					&lt;td&gt;High (network isolation)&lt;/td&gt;
					&lt;td&gt;High (compartmentalization)&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Ease of use&lt;/td&gt;
					&lt;td&gt;High&lt;/td&gt;
					&lt;td&gt;High&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Low to moderate&lt;/td&gt;
					&lt;td&gt;Low&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Required hardware&lt;/td&gt;
					&lt;td&gt;Standard&lt;/td&gt;
					&lt;td&gt;Mac only&lt;/td&gt;
					&lt;td&gt;Standard&lt;/td&gt;
					&lt;td&gt;Standard + USB&lt;/td&gt;
					&lt;td&gt;Standard + RAM&lt;/td&gt;
					&lt;td&gt;x86-64 with VT-d, 16+ GB RAM&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Suitable profile&lt;/td&gt;
					&lt;td&gt;General use&lt;/td&gt;
					&lt;td&gt;General use&lt;/td&gt;
					&lt;td&gt;Intermediate profile&lt;/td&gt;
					&lt;td&gt;One-off sensitive sessions&lt;/td&gt;
					&lt;td&gt;Persistent network anonymity&lt;/td&gt;
					&lt;td&gt;High-security daily use&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;p&gt;Choosing an OS based on security is not a binary decision. It is an alignment between a real threat model and acceptable trade-offs in terms of compatibility and ease of use. For the vast majority of users, a well-configured Linux distribution already offers a level of protection radically superior to Windows 11 or macOS. For high-sensitivity profiles, &lt;a href=&#34;https://tails.boum.org&#34;&gt;Tails&lt;/a&gt;
, &lt;a href=&#34;https://www.whonix.org&#34;&gt;Whonix&lt;/a&gt;
, and &lt;a href=&#34;https://www.qubes-os.org&#34;&gt;Qubes OS&lt;/a&gt;
 represent three complementary approaches, each optimized for a distinct threat model.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>Arpokrat Swap: exchange your cryptocurrencies without leaving a trace</title>
      <link>https://arpokrat.com/blog/arpokrat-swap-privacy-crypto-exchange/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/arpokrat-swap-privacy-crypto-exchange/</guid>
      <description>&lt;p&gt;We believe that the act of exchanging value should not leave a trace. Today, we make that belief a reality with the launch of &lt;a href=&#34;https://arpokrat.com/swap&#34;&gt;Arpokrat Swap&lt;/a&gt;
: a cryptocurrency exchange platform designed from the ground up for absolute privacy.&lt;/p&gt;
&lt;h2 id=&#34;an-infrastructure-that-doesnt-know-you&#34;&gt;An infrastructure that doesn&amp;rsquo;t know you&lt;/h2&gt;
&lt;p&gt;The vast majority of exchange platforms, even those that claim to be &amp;ldquo;private&amp;rdquo;, collect data by default: IP address, session cookies, browser fingerprinting, transaction logs. These metadata, often underestimated, build an exploitable behavioral profile — by third parties, by regulators, or by malicious actors in the event of a data breach.&lt;/p&gt;
&lt;p&gt;Arpokrat Swap is built on the opposite principle: &lt;strong&gt;we cannot identify you because we do not try to.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;No cookies&lt;/strong&gt; — no session, tracking, or analytics cookies&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No IP logs&lt;/strong&gt; — your network address is neither recorded nor transmitted&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No sign-up&lt;/strong&gt; — no account, no email address, no KYC&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No fingerprinting&lt;/strong&gt; — no third-party JavaScript, no data collection scripts&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;accessible-via-tor&#34;&gt;Accessible via Tor&lt;/h2&gt;
&lt;p&gt;For users who want an additional layer of protection at the network level, Arpokrat Swap is fully available via our .onion address:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;arpokrat4asurnhw7v3s6rinjqgcwo2fx54fq7zlacawc2xuq7wppsad.onion
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Accessible from the Tor browser or via Orbot, this interface is functionally identical to the clearnet version — no compromise on features, no degradation of experience.&lt;/p&gt;
&lt;h2 id=&#34;privacy-cryptocurrencies-first&#34;&gt;Privacy cryptocurrencies first&lt;/h2&gt;
&lt;p&gt;Arpokrat Swap supports over 350 digital assets across all major blockchains. We pay particular attention to privacy-enhanced cryptocurrencies, which form the core of our philosophy:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Monero (XMR)&lt;/strong&gt; — opaque transactions by default, the gold standard for on-chain privacy&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Zcash (ZEC)&lt;/strong&gt; — shielded payments via the zk-SNARKs protocol&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Bitcoin (BTC)&lt;/strong&gt; — on mainnet and Lightning networks&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ethereum (ETH)&lt;/strong&gt; — as well as all ERC-20 tokens&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Litecoin (LTC)&lt;/strong&gt;, &lt;strong&gt;Dogecoin (DOGE)&lt;/strong&gt;, &lt;strong&gt;Cardano (ADA)&lt;/strong&gt;, &lt;strong&gt;Solana (SOL)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Avalanche (AVAX)&lt;/strong&gt;, &lt;strong&gt;Polkadot (DOT)&lt;/strong&gt;, &lt;strong&gt;Chainlink (LINK)&lt;/strong&gt;, &lt;strong&gt;Uniswap (UNI)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tether (USDT)&lt;/strong&gt; and &lt;strong&gt;USD Coin (USDC)&lt;/strong&gt; on Ethereum, Tron, BSC and Polygon&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;XRP&lt;/strong&gt;, &lt;strong&gt;Stellar (XLM)&lt;/strong&gt;, &lt;strong&gt;Cosmos (ATOM)&lt;/strong&gt;, &lt;strong&gt;Algorand (ALGO)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Toncoin (TON)&lt;/strong&gt;, &lt;strong&gt;Near (NEAR)&lt;/strong&gt;, &lt;strong&gt;Aptos (APT)&lt;/strong&gt;, &lt;strong&gt;Sui (SUI)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Shiba Inu (SHIB)&lt;/strong&gt;, &lt;strong&gt;Pepe (PEPE)&lt;/strong&gt; and the main memecoin tokens&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Dai (DAI)&lt;/strong&gt;, &lt;strong&gt;FRAX&lt;/strong&gt; and decentralized stablecoins&lt;/li&gt;
&lt;li&gt;And hundreds of other tokens and cross-chain pairs&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;OPSEC tip:&lt;/strong&gt; For swaps involving traceable assets, we recommend using Monero as an intermediary — for example BTC → XMR → ETH rather than a direct BTC → ETH swap. This breaks the on-chain link between the two addresses.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;xstocks-tokenized-stocks-tradeable-without-a-broker&#34;&gt;xStocks: tokenized stocks, tradeable without a broker&lt;/h2&gt;
&lt;p&gt;Arpokrat Swap also integrates &lt;strong&gt;xStocks&lt;/strong&gt; — tokenized US stocks and ETFs, backed 1:1 by the underlying asset held by a regulated custodian. Each token represents exactly one share of the corresponding company, with immediate on-chain settlement and 24/7 availability, with no market hours.&lt;/p&gt;
&lt;p&gt;Available xStocks include:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Technology&lt;/strong&gt;
&lt;code&gt;AAPLx&lt;/code&gt; Apple · &lt;code&gt;MSFTx&lt;/code&gt; Microsoft · &lt;code&gt;NVDAx&lt;/code&gt; NVIDIA · &lt;code&gt;GOOGLx&lt;/code&gt; Alphabet · &lt;code&gt;METAx&lt;/code&gt; Meta · &lt;code&gt;AMZNx&lt;/code&gt; Amazon · &lt;code&gt;TSLAx&lt;/code&gt; Tesla · &lt;code&gt;AMDx&lt;/code&gt; AMD · &lt;code&gt;ADBEx&lt;/code&gt; Adobe · &lt;code&gt;ACNx&lt;/code&gt; Accenture · &lt;code&gt;APPx&lt;/code&gt; Applovin · &lt;code&gt;AMATx&lt;/code&gt; Applied Materials · &lt;code&gt;APLDx&lt;/code&gt; Applied Digital&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Finance &amp;amp; Crypto-adjacent&lt;/strong&gt;
&lt;code&gt;COINx&lt;/code&gt; Coinbase · &lt;code&gt;HOODx&lt;/code&gt; Robinhood · &lt;code&gt;MSTRx&lt;/code&gt; MicroStrategy · &lt;code&gt;CRCLx&lt;/code&gt; Circle · &lt;code&gt;AMBRx&lt;/code&gt; Amber&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Healthcare &amp;amp; Pharma&lt;/strong&gt;
&lt;code&gt;MRKx&lt;/code&gt; Merck · &lt;code&gt;AZNx&lt;/code&gt; AstraZeneca · &lt;code&gt;ABTx&lt;/code&gt; Abbott · &lt;code&gt;ABBVx&lt;/code&gt; AbbVie&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Consumer &amp;amp; Miscellaneous&lt;/strong&gt;
&lt;code&gt;MCDx&lt;/code&gt; McDonald&amp;rsquo;s · &lt;code&gt;NFLXx&lt;/code&gt; Netflix · &lt;code&gt;GMEx&lt;/code&gt; GameStop&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;ETFs &amp;amp; Indices&lt;/strong&gt;
&lt;code&gt;SPYx&lt;/code&gt; S&amp;amp;P 500 · &lt;code&gt;QQQx&lt;/code&gt; Nasdaq-100 · &lt;code&gt;GLDx&lt;/code&gt; Gold · &lt;code&gt;PALLx&lt;/code&gt; Palladium · &lt;code&gt;PPLTx&lt;/code&gt; Platinum&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And many more&lt;/strong&gt; — the full list exceeds 131 assets (100 stocks, 27 ETFs and 4 specialized assets), available directly on the platform.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;xStocks do not confer voting rights or direct dividends. Dividends are automatically reinvested into the token balance. Geographic restrictions apply — not available to residents of the United States, Canada, the United Kingdom, and Australia.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&#34;a-route-aggregator-not-a-single-provider&#34;&gt;A route aggregator, not a single provider&lt;/h2&gt;
&lt;p&gt;Arpokrat Swap is not an exchange platform in its own right: it is an &lt;strong&gt;aggregator&lt;/strong&gt;. When you initiate a swap, we simultaneously query multiple partner providers and present you with the best available options based on two transparent criteria:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. The lowest fees&lt;/strong&gt;
The displayed rate already includes all fees — network fees and the provider&amp;rsquo;s commission. You pay nothing extra for using our aggregator: our commission is taken directly from the provider&amp;rsquo;s fee, with no impact on your rate.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. The provider&amp;rsquo;s KYC rating&lt;/strong&gt;
Each route is associated with a privacy rating that we establish by reading the terms and conditions and privacy policies of each partner, by directly questioning them about their practices, and by taking their track record into account:&lt;/p&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Rating&lt;/th&gt;
					&lt;th&gt;Meaning&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;✅ &lt;strong&gt;A&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;Never requests identity verification&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;🟡 &lt;strong&gt;B&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;Very rarely requests KYC, refunds upon refusal&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;🟠 &lt;strong&gt;C&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;Rarely requests KYC, refund within a few days&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;🔴 &lt;strong&gt;D&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;May request KYC and potentially freeze funds&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;We recommend prioritizing routes rated &lt;strong&gt;A&lt;/strong&gt; or &lt;strong&gt;B&lt;/strong&gt;, particularly for large volumes or swaps involving privacy-enhanced cryptocurrencies.&lt;/p&gt;
&lt;h2 id=&#34;why-this-makes-a-difference&#34;&gt;Why this makes a difference&lt;/h2&gt;
&lt;p&gt;Most aggregators redirect you to the most favorable rate without informing you of the privacy risks associated with the underlying provider. An exchange may display an excellent rate while enforcing an aggressive KYC policy that will block your transaction after the fact and hold your funds.&lt;/p&gt;
&lt;p&gt;Arpokrat Swap is the only platform where &lt;strong&gt;cost and KYC risk are presented together&lt;/strong&gt;, allowing you to make an informed choice rather than a blind trade-off.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;a href=&#34;https://arpokrat.com/swap&#34;&gt;Access Arpokrat Swap →&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Arpokrat Swap is a non-custodial service. We never have access to your funds at any point. Swaps are executed directly between your wallet and the selected partner provider.&lt;/em&gt;&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The Shouting Silence: What is a Warrant Canary and Why Its Disappearance Should Worry You</title>
      <link>https://arpokrat.com/blog/canary-warrant-explained/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/canary-warrant-explained/</guid>
      <description>&lt;p&gt;Deep in the coal mines of the 19th century, miners carried caged canaries with them. These small birds, extremely sensitive to toxic gases like carbon monoxide, succumbed long before the miners perceived the danger. They served as a silent, but highly effective early warning system.&lt;/p&gt;
&lt;p&gt;In our modern digital world, this bird has come back to life in the form of the &lt;strong&gt;&amp;ldquo;Warrant Canary&amp;rdquo;&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id=&#34;what-is-a-warrant-canary&#34;&gt;What is a Warrant Canary?&lt;/h2&gt;
&lt;p&gt;It is a public statement, published and updated regularly by a service provider (messaging app, VPN, host), stating that, up to that exact date, it has not received any secret legal request forcing it to compromise its users&amp;rsquo; data — such as an American &lt;em&gt;National Security Letter (NSL)&lt;/em&gt; or an order issued by a FISA court.&lt;/p&gt;
&lt;p&gt;The subtlety — and the gravity — of the canary lies in what happens when it disappears.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;If a service that displayed the statement &lt;em&gt;&amp;ldquo;We have received no secret orders&amp;rdquo;&lt;/em&gt; every month suddenly stops updating it, the informed user deduces the obvious: &lt;strong&gt;the canary is dead&lt;/strong&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The company has been targeted by a surveillance measure accompanied by a &lt;strong&gt;gag order&lt;/strong&gt;, legally forbidding it from revealing the existence of this request. Unable to say that they have been compromised, they simply stop saying that they haven&amp;rsquo;t been.&lt;/p&gt;
&lt;h2 id=&#34;the-era-of-invisible-surveillance-and-bypassing-silence&#34;&gt;The Era of Invisible Surveillance and Bypassing Silence&lt;/h2&gt;
&lt;p&gt;At a time when extraterritorial legislations like the &lt;strong&gt;CLOUD Act&lt;/strong&gt; and &lt;strong&gt;FISA&lt;/strong&gt; (Foreign Intelligence Surveillance Act) allow the U.S. government to access data hosted by companies without ever informing the targets, the Warrant Canary constitutes one of the few mechanisms to bypass this forced silence.&lt;/p&gt;
&lt;p&gt;With the CLOUD Act, the geographical barrier no longer exists: if data is under the &amp;ldquo;control&amp;rdquo; of an American company, the United States government claims the right to access it, even if these servers are physically located in Europe. The canary then becomes the last warning signal before a user&amp;rsquo;s digital sovereignty is silently sacrificed.&lt;/p&gt;
&lt;p&gt;This is why major actors in the &lt;em&gt;Privacy&lt;/em&gt; sphere have adopted this tool as a standard of transparency:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://proton.me/legal/transparency&#34;&gt;Proton&lt;/a&gt;
&lt;/strong&gt;: The Swiss messaging and email service publishes a transparency report including a strict Warrant Canary.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://riseup.net/en/canary&#34;&gt;Riseup&lt;/a&gt;
&lt;/strong&gt;: The secure communication collective for activists maintains one of the most famous and monitored canaries on the web.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://arpokrat.com/canary&#34;&gt;Arpokrat&lt;/a&gt;
&lt;/strong&gt;: Our own ecosystem maintains a public Warrant Canary, cryptographically updated, to guarantee absolute transparency to our community.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;legal-analysis-the-right-not-to-lie&#34;&gt;Legal Analysis: The Right Not to Lie&lt;/h2&gt;
&lt;p&gt;The very existence of the Warrant Canary rests on one of the most fascinating pillars of constitutional law: the doctrine of &lt;em&gt;compelled speech&lt;/em&gt; and its collision with judicial secrecy.&lt;/p&gt;
&lt;p&gt;The legal basis rests on a simple principle: &lt;strong&gt;if the State has the power to impose silence on you (via a gag order), it does not have the constitutional power to force you to lie.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Under the First Amendment of the United States Constitution (and analogous principles in Europe), the government cannot force a company to produce a factually false statement. Thus, when a company removes its canary, it does not violate the silence order — since it does not explicitly announce having received a warrant. It simply exercises its fundamental right to stop making a statement that is no longer true.&lt;/p&gt;
&lt;h3 id=&#34;the-conflict-with-european-law&#34;&gt;The Conflict with European Law&lt;/h3&gt;
&lt;p&gt;The relevance of the canary is today reinforced by &lt;strong&gt;Article 32 of the Data Act (EU Regulation 2023/2854)&lt;/strong&gt;. This provision requires providers to implement technical and legal measures to prevent data access by authorities of third countries when this contradicts European law. The death of a canary immediately signals this conflict of laws: the provider is likely being forced to bypass European guarantees to satisfy a foreign mandate.&lt;/p&gt;
&lt;h2 id=&#34;the-arpokrat-approach-sovereignty-by-design&#34;&gt;The Arpokrat Approach: Sovereignty by Design&lt;/h2&gt;
&lt;p&gt;In the &lt;strong&gt;Arpokrat&lt;/strong&gt; ecosystem, operating under the jurisdiction of the Swiss FADP (Federal Act on Data Protection - RS 235.1), the canary takes on an even more powerful dimension. It is part of a holistic approach to digital sovereignty: &lt;em&gt;Zero-Knowledge&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;The architecture is designed in such a way that the company creates a &lt;strong&gt;technical and mathematical impossibility&lt;/strong&gt; to obey a mandate. The State or an intelligence agency can issue all the orders it wants, the answer will remain the same: there are no private keys, no identities (Zero-ID), and no centralized metadata to hand over.&lt;/p&gt;
&lt;p&gt;In this context, the canary is no longer just a warning of compromise; it is the continuous public proof that the infrastructure has remained technically inviolable and faithful to its principles.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Ultimately, the Warrant Canary is the piece of &lt;strong&gt;legal agility&lt;/strong&gt; that complements the cryptographic agility necessary to face the horizon of modern threats (such as post-quantum computing). In an infrastructure where data is sovereign by design, the canary is not just a simple bird in a mine: it is the silent guardian of your digital fortress.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>Utiq: The new telecom &#39;Super-Cookie&#39; threatening your privacy</title>
      <link>https://arpokrat.com/blog/utiq-supercookie-telecom-privacy/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/utiq-supercookie-telecom-privacy/</guid>
      <description>&lt;p&gt;The scheduled end of third-party cookies on web browsers has triggered a true arms race in the targeted advertising industry. While Google is trying to impose its own standards (like the Privacy Sandbox), another unexpected player has decided to grab a piece of the pie: &lt;strong&gt;your Internet Service Provider (ISP)&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Thus was born &lt;strong&gt;Utiq&lt;/strong&gt; (formerly known as project &lt;em&gt;TrustPid&lt;/em&gt;), a joint venture founded by European telecommunications giants. Sold to the general public as a &amp;ldquo;transparent and respectful&amp;rdquo; solution, Utiq is actually what cybersecurity experts fear most: a &amp;ldquo;supercookie&amp;rdquo; operating at the network level.&lt;/p&gt;
&lt;h2 id=&#34;what-is-utiq-and-how-does-it-work&#34;&gt;What is Utiq and how does it work?&lt;/h2&gt;
&lt;p&gt;Traditionally, advertising tracking (cookies) is managed by your web browser (&lt;a href=&#34;https://www.google.com/chrome/&#34;&gt;Chrome&lt;/a&gt;
, &lt;a href=&#34;https://www.mozilla.org/firefox/&#34;&gt;Firefox&lt;/a&gt;
, &lt;a href=&#34;https://www.apple.com/safari/&#34;&gt;Safari&lt;/a&gt;
). You could block it using extensions (like &lt;a href=&#34;https://ublockorigin.com/&#34;&gt;uBlock Origin&lt;/a&gt;
) or a privacy-oriented browser (like &lt;a href=&#34;https://brave.com/&#34;&gt;Brave&lt;/a&gt;
).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Utiq shifts the problem one step back: to the level of your network connection.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Here is how the trap springs:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Network interception:&lt;/strong&gt; When you browse the internet via your mobile connection (4G/5G) or your fiber box, Utiq uses your IP address and your telecom subscription data to identify you.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Consent (the false choice):&lt;/strong&gt; Upon arriving at a partner site, a pop-up window asks you to accept Utiq. Due to the fatigue associated with cookie banners (&lt;em&gt;Consent Fatigue&lt;/em&gt;), millions of users click &amp;ldquo;Accept&amp;rdquo; without reading.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The &amp;ldquo;Network Signal&amp;rdquo;:&lt;/strong&gt; Once consent is given, Utiq directly contacts your telecom operator. The latter generates a unique, pseudonymized identification token (the network signal) which it transmits to advertisers.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You are now trackable from site to site, not by a file stored on your computer, but by &lt;strong&gt;the very infrastructure that provides you with the internet&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id=&#34;why-utiq-is-a-privacy-nightmare-opsec&#34;&gt;Why Utiq is a privacy nightmare (OPSEC)&lt;/h2&gt;
&lt;p&gt;The initiative raises serious problems for digital sovereignty and the confidentiality of your data:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tracking at the source:&lt;/strong&gt; Unlike classic cookies, you cannot simply &amp;ldquo;clear your history&amp;rdquo; or &amp;ldquo;empty your cache&amp;rdquo; to get rid of Utiq. The identification token is generated by your ISP.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The centralization of profiles:&lt;/strong&gt; Telecom operators already know your name, physical address, banking details, and location in real-time. By linking your web browsing history via Utiq to this, they create behavioral profiling of daunting precision.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The flaw of pseudonymization:&lt;/strong&gt; Utiq defends itself by not sharing your name in plain text, claiming to use &amp;ldquo;encrypted&amp;rdquo; tokens. However, in the cybersecurity world, it is proven that pseudonymization is reversible. Cross-referencing these tokens with other databases allows individuals to be easily re-identified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;which-operators-use-utiq&#34;&gt;Which operators use Utiq?&lt;/h2&gt;
&lt;p&gt;Utiq was founded by an alliance of the four largest European operators. If you are a customer of one of them (or one of their low-cost subsidiaries), your connection is potentially already &amp;ldquo;compatible&amp;rdquo; with this tracking.&lt;/p&gt;
&lt;p&gt;Here are the founders and links to their respective privacy policies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.orange.fr/portail/politique-de-confidentialite&#34;&gt;Orange&lt;/a&gt;
&lt;/strong&gt; (France, Spain, Poland, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.vodafone.com/privacy-center&#34;&gt;Vodafone&lt;/a&gt;
&lt;/strong&gt; (Germany, Spain, UK, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.telefonica.com/en/privacy-policy/&#34;&gt;Telefónica / O2 / Movistar&lt;/a&gt;
&lt;/strong&gt; (Spain, Germany, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.telekom.com/en/company/data-privacy-and-security&#34;&gt;Deutsche Telekom&lt;/a&gt;
&lt;/strong&gt; (Germany, Central Europe)&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The OPSEC tip:&lt;/strong&gt; Although Utiq offers a centralized consent management portal (&lt;a href=&#34;https://consenthub.utiq.com/&#34;&gt;consenthub.utiq.com&lt;/a&gt;
) to revoke access, the best defense remains technological.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;the-zero-trust-approach-to-counter-utiq&#34;&gt;The Zero-Trust approach to counter Utiq&lt;/h2&gt;
&lt;p&gt;The philosophy of digital sovereignty, driven by ecosystems like &lt;strong&gt;Arpokrat&lt;/strong&gt;, relies on a simple principle: never trust the network infrastructure.&lt;/p&gt;
&lt;p&gt;To technically neutralize systems like Utiq, the solution is to hide your traffic from your own internet service provider:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Using a sovereign VPN:&lt;/strong&gt; By encrypting your traffic as soon as it leaves your device, your ISP only sees an unreadable stream of data directed towards a VPN server. It can no longer inject or read Utiq tokens.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Tor network (&lt;a href=&#34;https://orbot.app/&#34;&gt;Orbot&lt;/a&gt;
):&lt;/strong&gt; Onion routing prevents any end-to-end identification.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;DNS Encryption (DoH/DoT):&lt;/strong&gt; Prevents your operator from knowing which websites you request to visit.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In summary, Utiq is proof that internet service providers are no longer content with being mere &amp;ldquo;pipes&amp;rdquo;; they want to become data brokers. More than ever, encrypting your traffic is no longer a security option, but an absolute necessity to preserve your digital silence.&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>