Don't give your data to Google Search, use Brave Search
Don't give your data to Chrome, use Vivaldi
Don't give your data to Google Translate, use DeepL
Don't give your data to X, use Mastodon
Don't give your data to Windows, use Linux
Don't give your data to ChatGPT, use Lumo
Don't give your data to Google Maps, use Organic Maps
Don't give your data to Zoom, use Proton Meet
Don't give your data to Figma, use Penpot
Don't give your data to Discord, use TeamSpeak
Don't give your data to YouTube, use PeerTube
Don't give your data to Slack, use Element
Save this for later.
Proton VPN got caught running price sensitivity tests on its own users, then told everyone it was a stale sale.
Here's what happened. People on Proton's subreddit noticed they were being quoted different prices for the same plan. Refresh the pricing page and VPN Plus shows $2.77/mo at 72% off. Open a fresh incognito window and it's $3.23/mo at 68% off. Same plan, same country, same second. Nothing about the visitor changed.
Proton VPN's General Manager replied that there was no adaptive pricing, that a sale had recently ended, and that the intro prices hadn't "universally refreshed." He called the low numbers an error and suggested people grab them before they got fixed.
Then Windscribe pulled the page source. Every visitor is being sorted into a variant, and the test is labeled in plain text inside an HTML meta tag: ab-test:VpnHpAndPricingVpnPlusSensibility300726. One session returns content="A", the other returns content="B". Two separate pricing URLs, one normal and one flagged test-300726-b. A screen recording shows the price flipping between clean incognito sessions, $3.49 at 65% off, then $2.99 at 70% off.
Expired sales don't do that. Cached pages don't do that. Cloudflare has never once injected a named A/B test into anyone's markup.
Worth being precise about the wording, because Proton was. Adaptive pricing uses your personal data to set a number tailored to you. Price sensitivity testing quotes different people different prices for the identical product to find out how far you can push before sales drop off. The GM denied the first one. Nobody accused them of the first one.
A/B testing prices is ordinary commerce. Amazon does it, airlines do it in their sleep, and almost nobody would have cared. But Proton sells privacy, and privacy is a trust product. The experiment was never the scandal. The denial was.
Run the tests. Just don't call it a glitch when your own code is holding a sign with the test's name on it.
Receipts:
TRY LINUX FOR 30 DAYS
TRY LINUX FOR 30 DAYS
TRY LINUX FOR 30 DAYS
TRY LINUX FOR 30 DAYS
TRY LINUX FOR 30 DAYS
TRY LINUX FOR 30 DAYS
TRY LINUX FOR 30 DAYS
TRY LINUX FOR 30 DAYS
@SymbianSyMoh الموضوع في النهاية يعتمد على سيناريو المخاطر بتاع الشخص اللي قد يكون بيشتغل في المجال العام مثلا في بلد شديد القمع. ساعتها بس بنفهم الناس الvpn ده ايه واننا بنبدل ال isp ب مين وهكذا. ومخاطر وفوائد كل حاجة فيه. في الأخر المستخدم بيقيم وضعه المهم يفهم ان مفيش anonymity
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
Age verification is backdoor mass surveillance.
"ما عجز عدة فرق من المدققين في الأمن السيبراني عن كشفه خلال 5 سنوات، عثر عليه كلود في دقائق!"
لأ، مسمهاش كده، اسمها ناس ولاد وسخة عديمي المسؤولية والخبرة وال bug bounty program بتاعهم عبارة عن "مج" و "تي شيرت"، محدش هيضيع وقته فى إنه يدور عندهم على اي حاجه، بلس محدش خالص دقق الكود بتاعهم ولا عملوا pentest خالص بلس اكتر من متخصص شاور على مشاكل حوالين نفس موضوع التوليد اللعشوائي الغير امن بتاعهم من ٢٠٢١ و ٢٠٢٣ لحد من ٦ شهور حد اكتشف الثغرة تقري��ا ومبلغهمش بيها وكبر مخه وراح مباشرة يعملها CVE علشان يندد بالخطر بتاعها:
https://t.co/pZK09TFYp9
ف متبقاش "ما عجز عدة فرق من المدققين" لان مفيش فرق اصلا دققت 🤣
لحد ما حصلت الكارثة!
USA has ChatGPT
USA has Grok
USA has Claude
USA has Gemini
USA has Llama
USA has Copilot
China has DeepSeek
China has Qwen
China has Ernie
China has GLM
China has Kimi
China has MiniMax
Europe has?
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
Someone cloned Netflix.
Then cloned Spotify.
Then cloned Instagram.
Then cloned Airbnb.
Then cloned WhatsApp.
Then cloned TikTok.
Then cloned Amazon.
Then put the source code for all of them on GitHub. For free.
Not one app. Not ten. Over 100 open source clones of the biggest apps on Earth. With source code. With demos. With tech stacks listed.
It is called Clone-Wars. 34,555 stars on GitHub.
Built by an Indian-origin developer named Gourav Goyal. He started collecting open source clones of popular apps into one list in December 2020. In March 2021, it went from 0 to 4,000+ stars in 7 days. It was on GitHub Trending for 5 days straight. Someone posted it to Hacker News and it hit #1 on the front page.
Here is what is inside.
Netflix clones. React, TMDB API, full streaming UI.
Spotify clones. Music player, playlists, search, albums.
Instagram clones. Feed, stories, likes, comments, DMs.
WhatsApp clones. Real-time messaging, read receipts, group chats.
Airbnb clones. Search, booking, maps, payments.
Amazon clones. Products, cart, checkout, Stripe payments.
TikTok clones. Short video feed, upload, likes.
Twitter clones. Feed, follow, tweet, retweet.
Slack clones. Channels, threads, real-time chat.
Trello clones. Boards, cards, drag and drop.
YouTube clones. Video player, search, comments.
And 90+ more.
Every clone has source code, a live demo, and the tech stack listed. React, Next.js, Node, Firebase, MongoDB, GraphQL, Tailwind. Every modern stack represented.
Here is why this matters.
Coding bootcamps charge $10,000 to $20,000 to teach you how to build apps like these.
Udemy courses charge $50 to $200 each. One app at a time. One framework at a time.
This repo gives you 100+ fully built apps with source code you can read, fork, and learn from. For $0.
Here is the wildest part.
The best way to learn to build Netflix is to look at someone who already built Netflix. Not a tutorial that teaches you one feature at a time. A complete, working clone with every feature connected.
You do not learn architecture from tutorials. You learn architecture from reading real projects.
100+ apps. 100+ demos. 100+ source codes. One repo.
Bootcamp: $10,000 to $20,000. Teaches 2 to 3 projects.
Udemy: $50 to $200 per course. One project each.
Clone-Wars: $0. 100+ projects. Every big app cloned.
34,555 stars. AGPL-3.0 licensed.
Every app you use. Cloned. Open sourced. Free to learn from.
(Link in the comments)
10 piracy repos you should NEVER use
SAVE IT
This is NOT a recommendation list. This is a do-not-touch list.
1. Awesome Piracy
A giant index of piracy tools, sites, and “free” content. One click and you’re deep in DMCA territory, not productivity heaven.
Repo → https://t.co/2pfwK86eOH
2. Seedbox‑Lite
A Netflix‑style UI on top of torrents. Streams straight from your seedbox. Also a perfect way to put your IP in every rightsholder’s crosshairs.
Repo → https://t.co/xLqt7rdp34
3. Webtor Self‑Hosted
Pick a torrent, stream it instantly in the browser. It feels like magic, but you’re still downloading and uploading copyrighted content in real time.
Repo → https://t.co/xLqt7rdp34
4. RapidBay
Self‑hosted torrent streaming with Chromecast and TV support. Clean UI, ugly risk. It turns your box into a 24/7 movie piracy hub.
Repo → https://t.co/KzAQmgTowX
5. Cloud‑Torrent
Remote torrent client with a web UI. Great dev work, terrible idea on a paid VPS tied to your real name and card.
Repo → https://t.co/8YCvqsjKuf
6. Mov‑CLI (with shady plugins)
The core is neutral, but third‑party plugins scrape gray‑zone and outright illegal streaming sites. One bad plugin choice, and you’re over the line.
Repo → https://t.co/Lj6zfKXB0V
7. Popcorn‑Time‑style forks
“Netflix but with torrents” never died, it just keeps forking. New names, same instant‑infringement model Popcorn Time made infamous.
Repo → https://t.co/56R7fRppYS
8. Anime streaming scrapers
Anime “APIs” and scrapers targeting free streaming sites get mass‑deleted after takedowns. If your stack relies on them, you’re building on legal quicksand.
Example → search “anime streaming scraper GitHub” / “aniwatch API GitHub”
9. Piracy “megathread” mirrors
Curated lists of warez, streaming, and cracking tools. Reading them isn’t the problem; using half the links absolutely is.
Repo → https://t.co/tMq0Nclc3G
10. “Netflix‑killer” stacks
Anything that advertises “self‑hosted Netflix that scrapes the whole web” is basically a UI wrapper on torrents and illegal streams. Slick, but not safe.
Repo → https://t.co/KFoB1WoHFL
Repo → https://t.co/25e7gplFGA
Fedora has officially removed Deepin Desktop Environment from its repositories, and the reasons are a mix of security concerns and plain old abandonment.
It started in 2025 when openSUSE's security team published a report flagging serious issues in Deepin's packages. Things like unsafe authentication in deepin-api and deepin-system-monitor, and D-Bus interface bugs in the file manager. Fedora had been shipping these packages all along without any real security review.
But the security side was only half the story. The Deepin packages in Fedora had already been falling apart on their own. Core packages couldn't build across Fedora 42, 43, and 44. The desktop had already been quietly dropped from Fedora spins because things simply wouldn't compile.
The group responsible for maintaining Deepin in Fedora, the DeepinDE SIG, had lost most of its key members over time. The one person still touching the packages wasn't responding to bug reports, maintainer pings, or direct emails. Whenever Fedora's system automatically orphaned a broken package, he'd reclaim it without actually fixing anything.
FESCo, Fedora's Engineering Steering Committee, sent a formal notice on May 5 and gave four weeks for someone to respond. Nothing came back. So they voted unanimously to retire the entire package set.
For now, Deepin is gone from Fedora. It could return someday if someone puts in the work for a proper fresh review. But given how things were left, that seems unlikely anytime soon.
Full story: https://t.co/RvUmLW58PW
🚨 @Bitwarden serait en train de subir une refonte discrète et inquiétante, sans aucune communication officielle. 🤔
👉🏼Le fondateur/ancien PDG Michael Crandell a été remplacé en février par un nouveau CEO (Michael Sullivan) dont la spécialité est les fusions-acquisitions et le private equity (il a géré des deals à 1 milliard $). Le CFO a aussi été changé.
👉🏼Le slogan « Always free » a disparu du site en avril. Le plan gratuit existe encore… pour l’instant.
👉🏼Les valeurs de l’entreprise (GRIT) ont été modifiées : Inclusion et Transparency ont été supprimées au profit de Innovation et Trust. L’annonce ? Un simple edit silencieux d’un vieux billet de blog de 2022 qui se contredit maintenant.
👉🏼Tout est fait en douce : pas de communiqué, pas de blog post, juste des changements enterrés.
L’auteur [source en commentaire], qui utilisait Bitwarden cloud, a déjà tout migré sur Vaultwarden, la version self-hosted.
Il voit un schéma classique : on gagne la confiance, on crée la dépendance, puis on change les règles petit à petit en vue d’une vente ou d’une exit (probablement à un gros acteur).
Risque pour les utilisateurs : le modèle open source et le self-hosting pourraient être fragilisés à terme (même si ce n’est pas immédiat).
Il conseille de passer à une instance personnelle tant que c’est encore facile.
En résumé : Bitwarden passe d’un projet communautaire à une boîte gérée comme une startup PE prête à être vendue.
Le gratuit et la transparence ne sont plus des priorités affichées.
‼️🚨 ALARMING: Google now treats privacy as suspicious behavior by default. Users of GrapheneOS, CalyxOS, /e/OS, and other deGoogled Android phones are being locked out of millions of websites unless they install the exact Google Play Services software they deliberately removed.
GrapheneOS is recommended by the EFF and used by journalists, lawyers, and activists in high-risk environments. The audience most likely to read Google's data practices and refuse its terms is now flagged as fraudulent for that exact decision.
What happened?:
▪️ Google announced "Cloud Fraud Defense" at Cloud Next on April 22-23, 2026, branding it "the next evolution of reCAPTCHA." Existing reCAPTCHA customers were auto-migrated.
▪️ When the system flags traffic as suspicious, the old click-the-bus puzzle is gone. Users get a QR code instead.
▪️ Scanning the QR code requires Google Play Services running on the device. Internet Archive snapshots show this requirement has been live since at least October 2025, silently rolled out for 7 months before anyone noticed.
▪️ No Play Services = no QR scan = locked out.
The bigger picture:
▪️ Google already tried this in 2023. It was called Web Environment Integrity (WEI), and it would have let Google decide which devices were "real enough" to access the web. Standards bodies and the public pushed back hard, and Google killed it. Three years later, the same idea is back, just hidden behind a QR code instead of a browser feature.
▪️ reCAPTCHA runs on millions of websites. Every developer who keeps using it is now, by default, telling deGoogled Android users they're not welcome...
YouTube Premium just raised prices. $15.99/month. Up from $13.99.
The family plan is now $26.99/month. That is $323 a year. To remove ads from a website.
YouTube Music: $11.99/month. $144 a year. To listen to songs without ads.
Every video you watch is tracked. Every search is logged. Every pause, every rewind, every rabbit hole at 2 AM. All of it fed into a profile that advertisers pay to access.
You are not the customer. You are the product. You always were.
There is an open source tool that strips every ad, every tracker, and every account requirement from YouTube. Same videos. Same creators. None of the surveillance.
It is called Invidious. 18,900+ stars on GitHub.
Here is what it does:
→ No ads. None. Ever. Pre-roll, mid-roll, banner, sponsored — all gone.
→ No Google account required. Subscribe to channels anonymously.
→ No tracking. No cookies. No fingerprinting. No watch history sent to Google.
→ No algorithm deciding what you should watch next.
→ SponsorBlock integration. Automatically skips sponsored segments inside videos.
→ Audio-only mode. Cuts data and battery use in half.
→ Background play on mobile. Free. Without Premium.
→ Download any video directly. Any quality. Any format.
→ RSS feeds for every channel. Subscribe in your reader.
→ Reddit comments shown alongside videos.
→ No JavaScript required. Works on any browser.
→ Self-host your own instance on any old laptop.
Here's the wildest part:
YouTube sent the developers a cease-and-desist letter on June 9, 2023. They told them to shut down within 7 days.
Invidious said no.
Three years later, they are still shipping. Last commit: 14 hours ago.
Google has spent three years trying to block, sue, and bury this project. They have failed. The repository keeps growing. The code keeps shipping. The community keeps coding.
Every commit is a middle finger to the ad industrial complex.
YouTube Premium Individual: $15.99/month. $192/year.
YouTube Premium Family: $26.99/month. $323/year.
YouTube Music: $11.99/month. $144/year.
Invidious: $0. Forever. No ads. No tracking. No account. No subscription.
269 contributors. 33 releases. 2,100+ forks. Built in Crystal. Battle-tested since 2018.
AGPL-3.0 licensed. The license Google cannot kill.
Your videos. Your privacy. Your choice.
100% Open Source.
(Link in the comments)
A newly disclosed vulnerability in Firefox (CVE-2026-6770) allowed websites to track users across different sites that lasted for the lifetime of the browser process.
This vulnerability let any website quietly build a stable tracking identifier that lasted for the whole lifetime of your Firefox process.
It didn’t steal data or abuse storage, it simply read the predictable order in which the IndexedDB API returned database metadata and that order never changed as long as the browser stayed open, so sites could link your activity across tabs, windows, and even after you cleared data or hit the Tor reset button.
After the issue was reported Mozilla rolled out the fix in Firefox 150 and ESR 140.10 on April 21 (Tor Browser got the same update).
The patch randomizes that metadata order so the trick no longer works.