Yes im aware that my search engine choice is not the best option.
What is obsidian and signal note to self?
Rn I just add me wife to new chats and keep my notes there. Im sre she loves it.
I dont follow, how does it relate to signal as in the picture?
Apologies, my eyes are old
https://support.signal.org/hc/en-us/articles/360043272451-Note-to-Self
It’s to replace Google Keep as a note taker.
Dude is just Sendung a signal message to hinself
Perhaps this one:
Proton Mail -> Tuta Mail
Why? I would be careful with Proton Mail b/c it presumably advocates the Swiss surveillance and security law, which allows to keep information for a longer period of time.
Proton Pass could be replaced by a synchronised KeePassXC/DX database.
I understand your point for Independent Password Managers. For some people this is not a solution. I would always recommend a password managers that fits your needs and know-how. My parents could not use keepass with sync without breaking or loosing shit. But protonpass, or Bitwarden or strongbox could be a viable option. In some rare cases I would even recommend Apple Passwort App. Better than nothing.
If you can figure out Linux, you can definitely use KeepassXC…
I use KeepassXC and it’s database syncs great with Syncthing.
What I don’t like about KP is it’s ui. Too many pages. Everything should be one one page like KeepassDX. I wouldn’t recommend for noobs.
You got great choices, actually. I’d only recommend to be as little dependent on multiple fronts on one company. So I’d change a few of Proton to something else.
Depending on how private communications must be, Threema might be better than Signal.
Arch Linux
You can break anything quite easily on arch if you don’t know what you’re doing, including security.
Lol very true, Ive been using Mint for maybe 7 years now, Ive tried Arch 3 times or more, broke evey single time ive used it. And that’s with me not doing anything out of the ordinary. (No hate to Arch btw, I just can’t figure it out)
There is exactly zero privacy upside to be gained by moving from Mint to Debian, Fedora, OpenSUSE or Arch.
Qubes and Tails may give you an edge, but add quite dramatic convenience costs. Unless you have a very specific threat model, this is overkill.
Last time I tried qwant they don’t serve Taiwan, which is one of the points I VPN to that I cycle
I haven’t tried many other countries.
So just a head’s up to anybody reading.
Why is Threema better than Signal?
See here - secure messaging apps
another thing is that the Trumpist US regime allegedly got access to Signal through Israeli spyware (Paragon), or is trying to do so. (The Guardian)
The Swiss military also has publicly shifted away from Signal, as they deemed it unsafe for communications.Signal’s still subject to the CLOUD Act, while Threema is not. (Bleeping Computer).
The signal one suggests it’s a phone OS hack that can open apps so could probably do threema too.
The article you shared suggested it’s likely the result of lobbying by the company so they use a company inside the country.
See here why the link you shared isn’t a good source:
https://soatok.blog/2025/07/07/checklists-are-the-thief-of-joy/
And learn more about Threema vs. Signal:
https://soatok.blog/2021/11/05/threema-three-strikes-youre-out/
Ecosia has a terrible privacy policy, I analysed it in the past. They are likely in violation of the GDPR, I’m currently considering to file a complaint, they’re still a lot better than Google though, but DDG is privacy-wise superior.
SecureBlue also looks decent and brings some of the security hardening used in GrapheneOS
Adding my personal notes on search engines here for anyone’s interest. I personally use Qwant on Desktop and DuckDuckGo on mobile. I like Qwant because they are at least working on their own index and are EU-based. On the other hand, DuckDuckGo is faster and has a more comprehensive privacy policy. I’m really trying to use Mojeek on mobile but the search results are much worse than DuckDuckGo and Qwant in my repeated experience.
Qwant DuckDuckGo Mojeek xPrivo Kagi IP collection Yes No No No temporary Hosting FRA USA UK EU USA Index ~40% own index + ~60% Bing 100% Bing Own Own Own Direct monthly cost 0 0 0 4-7€ 5€ Passing data to third parties Search data and IP go to Microsoft separately No No No No Quality (subjective) +++ +++ + ++ ? AI summary / chat unclear optional no optional ? Speed + ++ +++ ++ ? Network effect is the biggest problem for messaging services, and so I would still push for Signal over the alternatives that are technically better. This guide seems like it is focussed on users who are new to the space
I agree with the Linux recommendation, but I’d offer CachyOS over pure Arch for newcomers. The limine bootloader gives a lot of peace of mind, since you can tell the user “if you get a bad update, reboot and pick an older option on the first screen”.
No VPN -> Mullvad VPN
Bro what? Using a VPN depends highly on your use case. This is way to general. I would remove that.
That really just depends on how privacy-respecting your ISP is compared to the vpn
I use proton for a lot of stuff. The calendar is useless IMO since their custom bridge doesn’t support linking anything else in. Same with contacts. For those two I use a self-hosted radicalev3 container, works like a charm.
Does someone have suggestions for what proton provides with its passmail? I think their implementation and usage experience with this entire reverse-email feature is pretty great and I dont want to give this anonymity up, selectively being able to send from those passmails is also a great feature that works really well in the rare case of getting something I need to reply to.
Wdym passmail? If you mean their subscription services, you can go look what they offer.
Proton’s decent as far how it works, but their CEO has some issues and an environmental activist using their services, had been arrested, though that activist afaik didn’t use a VPN.
Personally I’d recommend Tuta or Mailbox.
Other options would be CounterMail (🇸🇪) and Mailfence (🇧🇪). There’s other services, but those don’t have E2EE.
For passwords, you can use the same KeepassXC database on multiple devices. It’s encrypted, and you can have the passphrase file locally on multiple devices, and the cloud provider cannot access it even by brute forcing. The database itself would not be reliant on the cloud service, you can easily switch between any provider (I currently use dropbox)
Don’t know Ente, but the GrapheneOS gallery works fine for basics, and pop Immich on Mint for the rest of google photos functionality. I’ll suggest Bazzite for the distro, especially if they game or are likely to break things.
Ente is more than alright, I wouldn’t recommend self-hosted solutions to people who do not have the admin experience required, losing something as valueable as photos or videos can be very damaging.
After my wife complained again about not being able to delete photos in PhotoPrism, I finally bit þe bullet and migrated to Immich.
So. Much. Better.
Even if you wave off þe features PhotoPrism has locked behind a paywall which Immich provides for free, þe ecosystem is just better. Þe Immich mobike apps (on mobile Linux and on Android) are better; you don’t need a fussy 3rd-party sync tool*; Immich supports multi-user so you don’t have to run a server for each user; and Immich CLI tooling options (immich-go) are great.
I have an allergy to running node software anywhere, but it’s worþ it for Immich. It’s þat much better.
(*) DGMW, PhotoBackup is great, but having to set it up for each user on boþ server and mobile is tedious, and þe whole Rube Goldberg system is harder to keep track of - especially for non-techies who just want þe damned thing to work
Would CoMaps be a better recommendation than OSMand?
For those who are familiar with Ente, how are their apps? I use something different for 2FA and photos, but I need recommendations for people who don’t want to deal with selfhosting and backing up Aegis
Ente is pretty nice, Their UI’s are clean and not bloated much. I don’t use their online services though.
Edit: I use Osm since ive been using it for years now, all map’s are pretty much forks, either from Osm or something that uses Open Street Map (from my understanding)
OSMAnd is not OSM. OSMAnd and CoMaps are on equal ground as far as using OSM.
IMO OSMAnd has more features which is great if you want them, but I prefer CoMaps for having what I need while feeling simpler. Can’t really go wrong here, they’re both great.
I switched from Google Authenticator to Ente Auth recently and am very, very happy. It works great.
I haven’t tried their other apps yet, though. I intend to take a look at their images app.
People will agree and disagree on individual choices, as we can see by the other comments, but I think that is an excellent start.
A message for others, improving your privacy can be a gradual process, you don’t need change everything at once, since that would be overwhelming. Start with one or two, and if that works for you, move on to other items.
I’d add criteria, e.g.
- GDPR compliant
- no link with advertising companies
- free software or open source
- self-hostable
- security audit
etc and overall have a reasonable default option but not hide that there are alternative. We want everybody to move away but if everybody moves to Proton as a suite and they enshitify then we are (nearly) back to square one. So I think showing that good alternatives exist is great. Helping people who already use an alternative others, maybe even better one for THEIR criteria also exist, is even better.
I’d also add a Github (or better CodeBerg or self-hosted Gitea) link at the bottom to https://github.com/ente-io/privacypack with the license (MIT) visible.
As for GDPR, California has something similar, so that also might be good. California still falls under the federal CLOUD Act and their like, though.
If advertising companies (or really, stuff with an incentive to hunger for data) are a concern, I would not recommend the search engine Startpage. Other than that, its policies are afaik fairly decent.
For software, I think it being OSS or at least fully audited by an independent, transparent security auditor, is crucial. You want to avoid shell companies and such whose ultimate ownership is unclear. Or CEOs with questionable histories.
Self-hostability is a good one, though not everyone has the expertise required.
Not everyone car for the same things nor has the same abilities indeed, that’s why I’m thinking of optional filters. I also want to clarify the process is important to keep in mind, namely if somebody just started to move away from BigTech or surveillance capitalism or whatever is problematic for them, it’s not the same as somebody else who dedicated their live to that a decade ago. So IMHO the hope is that people can add more and more filters whenever they feel comfortable they have the available resources to do so. It’s a journey for each of us, on different paths at difference paces.
As others have pointed out, having so many Proton apps might be an issue. However, that line of thought only works if you’re really concerned about having a single point of failure. Most people value convenience much more than that.
The way I see it, this setup is somewhat noob-friendly, but relying heavily on Proton makes it a lot more convenient for many people. Using a greater variety of providers would make sense, but you can’t expect everyone to be ready for a hassle like that. People seem to expect you to be a hard-core privacy warrior who is willing to make significant sacrifices for philosophical reasons.
Most people aren’t like that. Just switching to DDG is hard enough for them, but at least it’s a step in the right direction.
If you take only 1/10th of this diagram, you get the simplified newbie version. Take all of it, and it’s for a person who is clearly interested in security and privacy. Modify a few things here and there, and you get a version for a serious security enthusiast. Different versions for different audiences.
Using Proton Mail, Calendar and Docs is a lot, lot better than using the Google suite. We shouldnt put people off changing, as you said the convenience is important and often forgotton as the major reason people stick with Google.
Just use tutamail - better track record and hosted in Germany
What track record? They are both the same.
Proton is just more user-friendly.
tuta hasnt sponsored a single far right influencer to my knowledge
That would have been my recommendation as well. It also diversifies the setup a bit.
However, I can also appreciate Proton as a convenient gateway drug that leads people away from Google.
Contacts > the stock apps on GOS without network access.
Keep > Notesnook.
Maps - > CoMaps Photos - > Immich (if you can self host) Passwords - > Bitwarden (May change in the future)
I agree with others on trying to not have one service for everything, which proton is trying to become. An alternative to Proton Mail and Calendar would be Tuta, though I haven’t used them.
Bitwarden (May change in the future)
The Bitwarden desktop client was on an EOL Electron version that doesn’t get security updates and marked as insecure in Nixpkgs and it took them 3 weeks to resolve it (finally got fixed an hour ago) and it’s still not fixed in any released version. It seems strange to me for a security-sensitive program to have problems like this.
mailbox also.
always check the profit motive. Often if it’s free, unsupported by donation/subscription nor sponsors with that system, and if it costs quite some money to uphold, then your data is the product.
I’m always pretty wary of when a company or its parent goes public, be it by IPO or trading - then ownership is no longer in people’s hands but in profit’s hands.
I prefer Comaps over OSMand.
OSMAnd has a lot more features that I personally use
different purpose in my opinion
How so? Isn’t it a fork after a dispute about direction?
Comaps is not a fork of OSMAnd… OSMAnd is a high powered offline maps and trip planning toolkit with many layer options, custom layers, multiple map views, and a range of plugins.
Comaps is… Well an offline compatible Google mapsish clone. It doesnt have anywhere near the capability of OSMAnd. Its more “general user” focused.
You’re thinking of Organic Maps












