Good to see! Standard Notes recently completed security audits for cryptography (Trail of Bits) and penetration testing (Cure53).

blog.standardnotes.org/standar

@Privatepower42 Oh they do? I think only on their site and blog they use Matomo (matomo.org/). And on their iOS app at least they use Bugsnag (bugsnag.com/) but with the ability to opt out.

@andreas my bad. I checked it again and you’re right. I’m thinking of bitwarden. The blue accent of their brands made my wires crossed. Speaking of passwords: I would like to use bitwarden but due to their use of google analytics, is there a suitable alternative? What do you think of buttercup.pw/ buttercup?

@Privatepower42 I think Bitwarden used to use GA but now doesn't (found this PR removing it from the mobile apps: github.com/bitwarden/mobile/pu). It also doesn't look like their web app (vault.bitwarden.com) uses GA 🤔

Buttercup looks really nice actually, thanks for sharing. What gives me pause is it hasn't undergone a formal security audit like Bitwarden has (bitwarden.com/help/article/is-) but maybe this is on their roadmap (hopefully)..

@andreas okay, interesting. I see it still mentioned on their bitwarden’s privacy policy page, so maybe they have not updated their policy as of yet. Where in the app can I disable GA? Don’t know how to use the pull requests.

@Privatepower42 So a pull request just represents a change in a code base, and from that one they added an opt-out option but at some later point they removed it entirely (can't find a PR related to that). So Bitwarden's apps currently don't use any analytics looks like.

Follow

@Privatepower42 huh, it does appear that the web app uses GA (I'm assuming server-side since no connection to GA is made client side 🤔):

"I will be adding an opt out flag soon for the browser and mobile products, but won't be here for the web project. If you are worried about google analytics on the web you can always use a nice extension like ghostery." - github.com/bitwarden/web/issue

@Privatepower42 Correction, Bitwarden doesn't use GA anymore.

github.com/bitwarden/browser/i

"Essentially Angularlytics has now been "black holed". There is nothing in the apps that is connected to or makes calls to Google Analytics. You could verify this by monitoring your network tab in the browser's dev tools."

@andreas thank you for clarifying. Bitwarden needs to update their policy to not have this confusion. On another note. I sent you a friend request. Your content is good.

Sign in to participate in the conversation
nitrohorse Ⓐ

Personal instance of nitrohorse (nitrohorse.com).