Sidebar
Resources I use:
- Liberation Toolbox by YK Hong (paywalled site)
- Where's Your Ed At by Ed Zitron
- Pluralistic by Cory Doctorow
- Addie LaMarr on Instagram and YouTube
- Good Work by Dan Toomey and Morning Brew
- 404 Media
- Casual Finance on YouTube and Instagram
- Simon Willison's Weblog
Posts tagged with "guides"
Privacy frontends: Eat cake without showing ID
2026-09-17 / tags: big tech, guides, meta, privacy, social media, spacexai
Just here to find a privacy frontend? Jump to the list of services.
Ever heard the phrase "have your cake and eat it too"? Social media companies love doing this. Thoroughly enshittified platforms like Reddit, YouTube, and Instagram gathered goodwill by offering a fun product to the public for free, then they leveraged the critical mass of people they attracted to shove ads down their throats once they were too locked-in[1] with network effects to want to leave. Any time you browse a social media site, or especially a mobile app installed on your phone, these companies are collecting thousands upon thousands of valuable data points to construct a profile of who you are that they can sell to advertisers, whether or not you're logged in to an account.
Never let it be said that I begrudge people their choice of digital junk food. Today I will show you how to doomscroll without giving away your data.
Enter privacy frontends
Privacy frontends are a unique adversarial tool in the fight against big tech. They are web applications that access centralized social media services on behalf of users who want to avoid trackers and bloatware as they watch cat videos or peruse dank memes. In addition to avoiding data collection, users benefit from lighter resource usage and, much of the time, fewer technical issues. The downsides are that this tech goes directly against social media companies' business model, so they have a big incentive to go after them with whatever tactics they can, whether it's changing their code to be more difficult to work around or filing legal challenges, as X is repeatedly attempting with the Nitter project, to varying degrees of success (shout out to the Nitter project for refusing to take these attacks lying down).
Because of the adversarial nature of these projects, they are hosted in a decentralized manner in multiple instances. In computer[2], an "instance" is jargon for an item that does the same thing as other items like it, as defined by its "parent", which it inherits from. In practice, this means that you'll need to find a list of instances for a particular privacy frontend you want to use, and pick from them depending on which is currently accessible, and any other criteria you'd like, such as where the server is located. Then, just navigate to that instance's URL in your web browser, and go bananas. A well maintained privacy frontend will have a list of instances available as part of its code repository, with a pointer to that list in the README (front page).
From there, you can use the frontend as a web application, starting from the home page and going where you'd like; or, you can find a link to the original social media site, copy the path (everything after the top-level domain, usually .com, including the first slash), and paste it at the end of the URL of the frontend's homepage.
Just as a quick demonstration, let's say I got a link from my buddy of an unfortunate typo someone made as they were getting mercilessly slaughtered online:
https://www.reddit.com/r/2007scape/comments/zdo61b/killed_this_noob_at_chaos_elemental_today_pleae/
I definitely want to see what's going on there, but I don't want to give Reddit my birthday, social security, and first born child for the privilege. What's a girl to do? I'll have a list of projects for various services at the end of this post, but we can start with a privacy frontend for Reddit called Redlib. That page shows its README, which has a link to their instance list. I'm in the US, so I'll pick one of the US based ones, https://redlib.catsarch.com. Now I'll just copy the path from my original link (remember, this is everything after the top-level domain, usually .com, including the first slash) and paste it at the end of this one to get:
Now I can view this extremely embarrassing moment of some random gamer's career, enshrined in history, without giving up my identity. Pretty neat! Note also that many of these services have instances accessible via Tor hidden services, I2P, and Yggdrasil for extra layers of protection.
List of services
I'll try to keep this section reasonably up to date with new info, but I can't promise that it will be current at all times. That being said, if you know of something that currently works for a major social media site, is actively maintained, and isn't listed here (or if something listed here is broken), feel free to drop me a line!
- Gelbooru: Gelbooru-Go (instances)
- Reddit: Redlib (instances)
- Imgur: Rimgo (instances)
- Instagram: Kittygram (instances)
- Tenor: Mezzo (instances)
- YouTube: Invidious (instances)
-
Not to be confused with the type of "locked in" I am when I'm writing this blog after my second La Colombe latte of the day. 190mg caffeine each btw. ↩
-
Someone recently called my field by this term without a second word attached and honestly, I'm here for it. Besides, I'm good at all of computer, not just the science. ↩
Mitigating supply chain attacks with package cooldowns
2026-08-25 / tags: guides, quick reads, security, technical
Software developers and the libraries and applications they write are prime targets for attackers seeking to grab all sorts of valuable prizes: cloud service credentials, downstream users, cryptocurrency wallet keys, networks of all kinds... the list goes on and on. As such, software supply chain attacks have been ramping up for the past several years, and they're now reaching a fever pitch. I can't recall a month of this year I didn't read about a popular software library getting compromised, leading to downstream libraries and applications being accessed by the attacker in turn.
Fear not, though! Waiting to use new versions of software packages for a time after they are published can help avoid getting pwned by a supply chain attack. Updates to dependency management tools for a variety of programming languages allow this to happen automatically as part of regular dependency updates, meaning this protection doesn't come at the expense of a smooth workflow.
Cooldowns.dev is a cool[1] reference website that details how to configure various package managers to include cooldowns. As of writing, it's got instructions for over a dozen package managers supporting six language ecosystems, and because its source is hosted on GitHub and open to pull requests, it can get updates for new functionality quickly.
That's all for this post. Check out Cooldowns.dev when you want to add a quick, easy, and effective mitigation to protect yourself and your projects from supply chain attacks!
-
I will never apologize. Never! ↩