Sidebar
Resources I use:
- Liberation Toolbox by YK Hong (paywalled site)
- Where's Your Ed At by Ed Zitron
- Pluralistic by Cory Doctorow
- Addie LaMarr on Instagram and YouTube
- Good Work by Dan Toomey and Morning Brew
- 404 Media
- Casual Finance on YouTube and Instagram
- Simon Willison's Weblog
Posts tagged with "big tech"
Privacy frontends: Eat cake without showing ID
2026-09-17 / tags: big tech, guides, meta, privacy, social media, spacexai
Just here to find a privacy frontend? Jump to the list of services.
Ever heard the phrase "have your cake and eat it too"? Social media companies love doing this. Thoroughly enshittified platforms like Reddit, YouTube, and Instagram gathered goodwill by offering a fun product to the public for free, then they leveraged the critical mass of people they attracted to shove ads down their throats once they were too locked-in[1] with network effects to want to leave. Any time you browse a social media site, or especially a mobile app installed on your phone, these companies are collecting thousands upon thousands of valuable data points to construct a profile of who you are that they can sell to advertisers, whether or not you're logged in to an account.
Never let it be said that I begrudge people their choice of digital junk food. Today I will show you how to doomscroll without giving away your data.
Enter privacy frontends
Privacy frontends are a unique adversarial tool in the fight against big tech. They are web applications that access centralized social media services on behalf of users who want to avoid trackers and bloatware as they watch cat videos or peruse dank memes. In addition to avoiding data collection, users benefit from lighter resource usage and, much of the time, fewer technical issues. The downsides are that this tech goes directly against social media companies' business model, so they have a big incentive to go after them with whatever tactics they can, whether it's changing their code to be more difficult to work around or filing legal challenges, as X is repeatedly attempting with the Nitter project, to varying degrees of success (shout out to the Nitter project for refusing to take these attacks lying down).
Because of the adversarial nature of these projects, they are hosted in a decentralized manner in multiple instances. In computer[2], an "instance" is jargon for an item that does the same thing as other items like it, as defined by its "parent", which it inherits from. In practice, this means that you'll need to find a list of instances for a particular privacy frontend you want to use, and pick from them depending on which is currently accessible, and any other criteria you'd like, such as where the server is located. Then, just navigate to that instance's URL in your web browser, and go bananas. A well maintained privacy frontend will have a list of instances available as part of its code repository, with a pointer to that list in the README (front page).
From there, you can use the frontend as a web application, starting from the home page and going where you'd like; or, you can find a link to the original social media site, copy the path (everything after the top-level domain, usually .com, including the first slash), and paste it at the end of the URL of the frontend's homepage.
Just as a quick demonstration, let's say I got a link from my buddy of an unfortunate typo someone made as they were getting mercilessly slaughtered online:
https://www.reddit.com/r/2007scape/comments/zdo61b/killed_this_noob_at_chaos_elemental_today_pleae/
I definitely want to see what's going on there, but I don't want to give Reddit my birthday, social security, and first born child for the privilege. What's a girl to do? I'll have a list of projects for various services at the end of this post, but we can start with a privacy frontend for Reddit called Redlib. That page shows its README, which has a link to their instance list. I'm in the US, so I'll pick one of the US based ones, https://redlib.catsarch.com. Now I'll just copy the path from my original link (remember, this is everything after the top-level domain, usually .com, including the first slash) and paste it at the end of this one to get:
Now I can view this extremely embarrassing moment of some random gamer's career, enshrined in history, without giving up my identity. Pretty neat! Note also that many of these services have instances accessible via Tor hidden services, I2P, and Yggdrasil for extra layers of protection.
List of services
I'll try to keep this section reasonably up to date with new info, but I can't promise that it will be current at all times. That being said, if you know of something that currently works for a major social media site, is actively maintained, and isn't listed here (or if something listed here is broken), feel free to drop me a line!
- Gelbooru: Gelbooru-Go (instances)
- Reddit: Redlib (instances)
- Imgur: Rimgo (instances)
- Instagram: Kittygram (instances)
- Tenor: Mezzo (instances)
- YouTube: Invidious (instances)
-
Not to be confused with the type of "locked in" I am when I'm writing this blog after my second La Colombe latte of the day. 190mg caffeine each btw. ↩
-
Someone recently called my field by this term without a second word attached and honestly, I'm here for it. Besides, I'm good at all of computer, not just the science. ↩
Post somewhere other than Instagram
2026-06-06 / tags: big tech, meta, quick reads, rants, social media, social movements
Note: This post is primarily aimed at participants in social movements.
I'm really tired of people thinking that posting their events, news, and writing only on Instagram and nowhere else is acceptable. It makes me angry. More importantly, it only includes that grouping of people who are both in Meta's good graces and actively choose to use their services.
Guess who can't fit in there? Mad people and all those who choose to prioritize their emotional and mental wellness over participation in the attention economy. Radicals whose speech has gotten them banned from the platform. And anyone who isn't interested in giving Meta personally identifiable information like an email address, phone number, and their behavioral data.
There are so many other options to disseminate information over the Internet and otherwise, and organizers are too comfortable ignoring the masses of people that can only be reached in other spaces in favor of what's easy and comfortable.
I happen to be in a position in my life where I have a lot of free time that I would love to spend going to community events and participating in building that I am not invited to because I choose to care for my Mad crip bodymind by not bending over backwards to get a second phone number to use for the billionaire-owned brain poison app.
I am not asking for people and orgs to move off of Instagram. I recognize that it is a powerful tool for outreach and engagement, and, in many ways, a necessary evil. I am, however, demanding that folks do the absolute bare minimum by publishing the details of your activity elsewhere as well. Or, alternatively, accept and sit with the fact that your allegiance to corporate social media as your only communications outlet is actively alienating people who want to build with you and, often, people you claim to be in solidarity with.
This post sponsored by my manic episode last year spurring me to stop using Instagram, which has considerably improved my overall wellbeing.
GitHub and enshittification
2026-05-14 / updated 2026-06-17 / tags: ai, big tech, data sovereignty, github, microsoft, sidebar updates
The open source software ecosystem collectively putting all its eggs in one basket may not have been the best decision.
I'm going to start with a brief timeline of events.
June 29, 2021: GitHub launches Copilot Technical Preview (Wayback Machine link).
June 30, 2022: The Software Freedom Conservancy launches their Give Up GitHub campaign, in response to GitHub and Microsoft's refusal to engage with critiques of their use of publicly available code uploaded to GitHub for training Copilot models regardless of how that code is licensed.
August 11, 2025: GitHub CEO Thomas Dohmke resigns, and Microsoft folds it into its CoreAI group, eliminating GitHub's independence from Microsoft management (paywalled link).
April 28, 2026: GitHub CTO Vlad Fedorov apologizes for serious issues GitHub had on April 23 and April 27 that brought usage to a complete halt twice in one week.
April 28, 2026: The same day, HashiCorp cofounder Mitchell Hashimoto says GitHub is "no longer a place for serious work" in his blog post announcing the migration of the Ghostty project to another hosted git platform. Damningly, the decision to migrate Ghostty was made before the April 27 outage.
May 4, 2026: dayswithoutgithubincident.com is posted to Hacker News. When I first saw it, it showed 0 days since last incident; as of writing, it shows 1. It's also got a neat little "High Score" widget, showing the longest streak of days in 2026 with no incidents (6, from April 2 to April 9).
You might notice a trend here, which is tied together by that word Cory Doctorow coined and I've included in the title of this post[1]. Priorities undoubtedly changed for GitHub once they were acquired by Microsoft back in June 2018, first slowly, then quickly. The AI bubble has needed significant engineering effort to sustain itself, which Redmond was more than happy to allocate when GitHub was all upside; seemingly limitless access to training data for AI coding models, vendor lock-in for thousands upon thousands of widely used open source projects, and a breezy talent pipeline to push engineers from GitHub enthusiasts to Azure DevOps professionals.
So much for "embrace, extend, extinguish"; right now it looks more like GitHub has exploded and everyone else is sprinting away.
The downsides to the world's reliance on Silicon Valley for critical services are making themselves more and more apparent over time. When Karim Khan, a prosecutor at the International Criminal Court, was blocked from accessing Microsoft services following the Trump administration placing sanctions on the ICC, a lot of people all over the world took notice. Digital sovereignty isn't a pie-in-the-sky ideal anymore – for many organizations, it's a base requirement urgently needing to be met.
I recently came across this post entitled "Why I'm leaving GitHub for Forgejo" that makes a lot of salient points related to these topics. I encourage you to read it and come back here when you're done. I'll highlight a specific idea pointed out by the author, Jorijn Schrijvershof, that isn't getting enough airtime:
The reliability story is downstream of the AI story. GitHub is not slowing down on AI features. It is doubling down on them. The outages are what doubling-down looks like in production.
The AI bullshit is wrecking the actual reason people ever came to GitHub in the first place: to come together and make software. These sort of antics were telegraphed in 2018, but decision makers were not listening to pundits in comments sections ranting about how it's time to move off of GitHub. Those network effects are strong, and concerns about espionage, software supply chain attacks, and managerial trust that were voiced in HN comments didn't reach the ears of decision makers. Now that organizations' bottom lines are being hit, whether their attitudes will change remains to be seen, but it seems clear now that to know who will burn you tomorrow, you should investigate who smells smokey today.
Speaking of Cory Doctorow, my initial sidebar had some glaring omissions. These have been rectified, as I have now added:
- Pluralistic by Cory Doctorow
- Addie LaMarr on Instagram and YouTube
- Good Work by Dan Toomey and Morning Brew
I could say a lot about Cory Doctorow and how much he's influenced my thinking and action, and I likely will at many points as I get further into this blogging thing.
Addie LaMarr's YouTube channel contains plenty of useful resources for folks wanting to get up to speed on seeing past cybersecurity hype and getting to the real heart of the matter.
Good Work just won a few Webby awards for their disgusting(ly hilarious) videos drilling down into such topics as "why is oil still such a big deal?" and "what does {Meta,Palantir,Oracle} actually do?" Oh, and peptides. Being in New York, a lot of the tech industry happenings I interact with get exported from the Bay Area, so having Dan and co help me recognize that, no, I'm not insane, everything really is that ridiculous is super helpful.
While I've got my sights on Microsoft, maybe next time I could talk about their irresponsible security posture, evidenced by a newly revealed exploit that unlocks any BitLocker drive by copying some files to it. Until then...
Addendum 6/17/2026: It was reported two nights ago that Microsoft is now buying compute from Amazon to keep GitHub afloat. So much for GitHub being a strategic asset to acquire...