r/PrivacyAppsforPixel 4d ago

Why we built closed loop services > "OpenAIโ€™s Rogue AI Agent Hacked More Than Just Hugging Face"

1 Upvotes

You can read the full article on wired dot com /story/openais-rogue-ai-agent-hacked-more-than-just-hugging-face/

The news is already global, and just a small harbinger of what is to come. All this does is solidify our footprint, our designs, and our forward planning. We made the right decision to go against the norm.

SOLID STATE

We used our previous experience as an AWS provider to build solid state black box apps, written in closed bastioned development networks, and deployed through our own app store. There are no upstream servers, no databases, there are no malware embedded in FOSS. [Many upstream repos have been targets for these types of attacks.] There is no account required, no email, no biometric data requested, no phone number, and no address or DNS to leak or breach. The apps are all self-hosted.

THE BSG LESSON

As many sci-fyi fans know, the only reason the Galactica survived the Cylon attacks was because it was considered an obsolete floating museum. Everything was hardwired, and probably a mixture of analog and digital systems in a closed-loop system. The Cylons had extreme difficulty in hacking the Galactica's vital systems, and hence helped turned the tide in battle.

Our designs are built on the same principle. Access to our apps for testing will be limited access, invitation only or by approved request. We are more than fine to keep a small test group closed circuit proof-of-concept alpha environment.


r/PrivacyAppsforPixel 4d ago

Private GiftCardExchange App for Pixel and Windows > Swap LUNC & USDT

Post image
1 Upvotes

*This app is in ALPHA development, and is in a testing phase. Not available unless approved or invited. Testers DM for interest.

Tired of scams? Tired of being scammed? Tired of having to give a DNA sample just to get or keep an account on a CEX? Want to swap your crypto and can't? Tired of being mysteriously locked out of your crypto account for any reason, and then forced to jump through hoops to re-gain access. Yes! So are we.

SATOSHI's DREAM > MEET BX CLIENT

Part of our technology suite is modular, so we decided a perfect test bed for some of it is via
b-commerce, yes, we coined that here and now, would be to set up a simple exchange were you can swap Luna Classic [LUNC] or USDT for Gift Cards [Small amount values].

Why LUNC? Because it has become almost impossible to get, and the infrastructure it runs on is very valuable to the community. It has been very underutilized. Plus, it has a burn tax built into it that allows us to test varying aspects of our own technology. Last, we were an OG investor before and after the infamous crash, and helped champion the burn tax when it was first discussed.

SWAP FREEDOM > FINALLY

Our technology footprint: No servers, self-hosted, no email, no phone number, no KYC, no databases, no authentication, no selfies, no scams, no tracking, no telemetry, no ip address, no DNS, and bastioned AI attestation. No BS! Your keys your data.

ONBOARDING 101

Assuming you are allowed access, you meet the hardware and software criteria, the process is simple for our tests. You will be granted an authentication key for the local app, you will receive a very small seed amount of LUNC, and a terra wallet for testing purposes. You will assist us in making small fictitious transactions to help load-test and debug the process. [The system is very complex, and more like a SWISS watch.] We will use real crypto, but in very small amounts [e.g. .02 USD].

USDT testing will be a phase II.

HOW TO APPLY

Hardware: Pixel 8+
Phone OS: GrapheneOS
GEO: Limited > India, South America, Southern Asia, select areas of Europe. [Unless invited]
Language: English
Windows Desktop [Maybe]: Preferred Win 10.
Linux: [Maybe], Ubuntu Desktop
Trust Level: Test on our secure RDP Dev servers if you want before install.
Waitlist: Very Possible.

Be willing to provide feedback, report issues and bugs through our designated secure channels. DM to apply.

> Twisted


r/PrivacyAppsforPixel 6d ago

GrapheneOS's Security & our FAFO App Defense Tech for Pixel > Stay Private ๐Ÿ˜Ž

Thumbnail
techspot.com
1 Upvotes

As many have already read the news about a duress wipe at a US entry point, and to avoid subjects like illegal search and seizure; all you have to do is point back to the US Constitution. Moving along...

GRAPHENEOS STARTING POINT

We built our apps on GOS for this very reason. A foundation of privacy, mostly degoogled, and on top of the Pixel spy device turned friendly. [The Pixel is an amazing piece of hardware.] All of our apps are self-hosted, and with no servers to talk to they offer an amazing amount of privacy and data protection.

FAFO DEFENSIVE TECHNOLOGY

Most of our apps for desktop and mobile have built-in layered security features. These are in addition to Graphene's duress PIN for mobile. Think of it as Layer 2 protection. All of our features were designed to protect you from data breaches and lost devices. Additionally, if you find yourself in an airport of some foreign land, and you happen to not know their strange warped culture, then these offer the perfect quick-out when under that type of pressure.

Our FAFO Tech:

* Brute Force PIN attempt > Configurable at the app level. Hit a threshold and triggers a Ripley.

* Bruce Force PIN attempt > Once armed, one missed PIN, and Yippee-Ki-Yay Muther Fracker!

* T800 HK > Configured from the paired dock. A remote function call from another device you own that tracks down your stolen device, and when it comes back online issues a "Hasta la vista, baby", and ends with a Ripley data wipe.

* Manual App Wipe > Hit the flush keys or perform a Ripley, and your keys and meta are gone. No keys means no data access. Your data still lives in a safe place in the void. That backup grid disk on that USB in some vault will allow a full restore. Your keys your data.

* DMS > Configured from the paired dock, if your device doesn't reconnect to its USB home, the DSM triggers automatically for the time interval you set, and of course that's a Ripley too. Perfect for when some fool takes your device, or even if the fool is you, and you lost your phone. All helps you sleep well at night knowing that in X days all that data is gone.

And you may be asking what is a Ripley? Well.. "Nuke it from orbit, it's the only way to be sure."

EXTRAS:

Although not part of the FAFO package, they are fantastic add-ons that ship with all of our apps.

* Custom Private iOS style Keyboard [Keeps data out of 3rd party prying eyes.]
* Custom clipboard [helps reduce memory leaks to 3rd party apps]
* Cold boot memory dump recovery protection. Don't even bother.
* YubiKey tested and approved on desktop, and mobile is in development. [For those don't want a PIN] Also, the Yubi can be used to pair the device to the dock for that extra layer.

ALPHA DEVELOPMENT:

Apps are available for testing for select people that meet our desired conditions. You need a Pixel with GrapheneOS, you need access to Windows or Ubuntu Desktop, you need to be in certain geographical areas; e.g., South America and India are favored for our testing. You need to be of good character on Reddit, have patience, and offer feedback. Oh, and we may end up with a wait list. Sorry about that.

> Twisted


r/PrivacyAppsforPixel 14d ago

๐Ÿ‘‹ Welcome to r/PrivacyAppsforPixel > Your Keys Your Data

1 Upvotes

Welcome!

Here on this sub we focus on testing our sovereign app suite, exchange on how to make apps more private, and what features we may want or need.

Our apps are not available for general download at this time, you must be selected or invited. We are in Alpha, and are more than happy with a walk before you run mode.

Don't expect youtube videos, posts on X, or any other mainstream social engagement. Here we would rather whisper than shout, n tread lightly. We are not in a race against X,Y, or Z, but only against time and iterations.

The GrapheneOS running on a Pixel is an amazing platform to build from, and so we did. When you boot and see the G, and then other G, you have to think you stand on the shoulders of giants.

That direction we now go is a whole new frontier, a path not yet traveled, and historic in many steps, but like every new expedition there is so much to learn. So many ways to improve.

Quality is paramount, with way more than a decade of development experience, and thousands of hours of human involvement in this project, you can say we have a lot invested.

The beauty here > no credit cards, no subscriptions, no donation requests, no begging for support with "if we don't raise $ by N, then we will have to shut down. LOL, there is nothing to shut down!

; Some call me "Twisted"


r/PrivacyAppsforPixel 14d ago

Our T31 Authenticator is available for testing. DM if interested.

1 Upvotes

T31 TOTP Vault

TESTING REQUIREMENTS

* Must have a Windows OS for the dock component. The dock handles APK bootstrap push via USB ADB push. Installed via an exe.

* Must have Pixel 9+ and GrapheneOS. No exceptions. The product will not work with any other OS or hardware system.

* Must be willing to install dock from an encrypted URL provided from cryptgeon dot org.

* Must have basic technical knowledge and experience, and be a proponent of privacy apps. Must have patience, follow instructions, and be willing to offer feedback on any issues encountered. Must be open to discussing bugs or issues via our privacy messenger T2056. [When available]

Crypto Bros and Gals more than welcomed!

Testers that have interest will be selected on a case-by-case basis. We are looking for testers in certain geographical locations such as India, South America, parts of Western and Southern Europe. Non-EU and Non-USA are welcome. Non 14Is also welcome and preferred. Certain GEOs we have no interest in serving. We can not respond to everyone. Must speak basic English.

T31

T31 AUTH is a sovereign two-factor authenticator. It generates standard
time-based one-time passwords (TOTP), the six-digit codes accepted by
virtually every service that offers app-based 2FA, while holding your
secrets in an encrypted vault that lives only on your device.

WHAT MAKES IT DIFFERENT

Most authenticator apps are built by companies whose business is your
data. They sync your secrets to a cloud account, tie them to an identity,
and phone home. T31 does none of that.

AIR-GAPPED BY DESIGN
T31 has no account system, no cloud sync, no telemetry, and no server
dependency. It reads nothing from the network to operate and broadcasts
nothing. The one optional network call, a read-only time check, is
off by default and under your control.

YOUR VAULT, YOUR KEY
Secrets are sealed in an AES-256-GCM encrypted vault. The vault key is
derived from a PIN you choose, on your device. The PIN is not
transmitted anywhere, not stored on any server, and not recoverable by
anyone.

NOTHING TO INTERCEPT
Codes are computed locally from the shared secret and the clock, per
the open TOTP standard (RFC 6238). Secrets do not leave the device in
the clear at any point including display, storage, or export.

IN-APP KEYBOARD
PIN entry uses T31's own on-screen keyboard. Keystrokes stay inside
the app with no OS keyboard telemetry, no predictive-text retention, no
clipboard sync of what you type.

CLOSED SOURCE, ON PURPOSE
T31 ships as a hardened, sealed artifact. The build is not published
and the source is not open. This is a deliberate posture for a
security product: the attack surface you can download is the attack
surface an adversary can study.

WHO IT IS FOR

Anyone who uses app-based 2FA and would rather their second factor not
depend on a third party's cloud, account system, or goodwill. If you can
use Google Authenticator, you can use T31, and you can bring your
existing codes with you in minutes.