🚩security alert🚩...the #telehealth / #teleconferencing platform #doxy.me uses the #amazon #aws servers to store all their #data...(of course they say its #encrypted and no video or audio is logged or recorded, buuuut this is #genocide, mass #surveillance, sells data to #dhs and whichever gov dept wants it, amazon, we are talking about here)...so heads up.

from the doxy help articles:

"All doxy.me data are stored within the highly secure Amazon Web Services (AWS) datacenter infrastructure with their industry standard physical controls. The doxy.me support system, help center, and public facing website are independent services to ensure uptime and availability across the platforms. For a list of AWS current security accreditations, see the AWS Compliance Programs page...."

AND...

"We partner with #Stripe to manage payments on doxy.me. Stripe is certified as a PCI Level 1 Service Provider."

...so, watch out.

https://help.doxy.me/en/articles/95911-security-and-privacy-overview

#boycottaws #boycottamazon #fckbezos
Security and privacy overview | Doxy.me Help Center

HIPAA, PHI, encryption and data storage standards, and more

Is Doxy.me down for you? Users are reporting problems with Doxy.me. Repost if you are having issues. #doxy-medown
https://isdown.app/status/doxy-me?c=1767722852
---
https://bsky.app/profile/isdown.app/post/3mbrkah22cj2z
Is Doxy.me down for you? Users are reporting problems with Doxy.me. Repost if you are having issues. #doxy-medown
https://isdown.app/status/doxy-me?c=1767367089
---
https://bsky.app/profile/isdown.app/post/3mbh6vw3kjl2x

does anyone know what's up.with the #doxy website technical issues and when they might be back up?

https://doxymassager.com/packaging-delivery/

#doxymassager

"To love oneself is the beginning of a lifelong romance." - Oscar Wilde

In diesem Sinne habe ich mich mit dem #doxy ausgiebig selbst verwöhnt! ☺️🖤

"I don’t think I’ve ever seen her come more quickly. And I’m not talking about her usual fare: I’m talking a full-on eye-rolling, spasming, practically-levitating-from-demonic-possession crescendo which elicited the kind of sounds you’d more readily expect to hear from… well, me."

Jenby is back to try out the NEW limited-edition HOT PINK Doxy Die Cast. Correct me if I'm wrong but I think she likes it?

https://www.girlonthenet.com/blog/doxy-die-cast-best-orgasms/ #SexToys #doxy #masturbation

Doxy Die Cast: "Easily the best orgasms she's had in her life"

How do you improve on the Doxy Die Cast, the ultimate powerful wand toy? Well... maybe you make a HOT PINK version, and use profits to help fight cancer.

Girl on the Net

With great sadness I must report that my Doxy is on its last legs. I feel genuinely bereft, and I think I may actually have to write it a proper farewell.

It was the first sex toy I ever 'reviewed' on my site, and the first one I truly fell in love with.

https://www.girlonthenet.com/blog/doxy/

(I was so impressed by the Doxy that my ex kindly wrote some extra code so I could embed wanksounds into the post. Heroic)

#SexToys #Doxy #Vibrator #NSFW

The Doxy massager does amazing things to my clit

The most enthusiastic sex toy review ever. It's not even a review: it's evangelism. Ladies and gents, here's why the Doxy massager rules the world.

Girl on the Net

TITLE: hipaalink.net security initial testing

A therapist on another list asked if anyone had experience with hipaalink.net televideo service.

This looks like a promising small company with some neat features at only $9.95 per month. See below first however. I really don’t like that Facebook Connect is being contacted from the client’s browser when they login!

I spent a lot of time fighting to sign-up (had to change my settings to see their Captcha challenges). More of a problem – there was a very basic malfunction in the password selection process. Some “special characters” (you have to have one in the password) would not work (+ and #). I eventually got “-” to work. I got an almost immediate call-back when I sent a message about trouble picking a password (bug in our system, thank you for finding it, our programmers are fixing “special characters” this evening).

Did eventually set-up a 30-day free trial. So I can further tests later if I want to.

I noticed that https://hipaalink.net/<mysite> works, but https://www.hipaalink.net/<mysite> does not – another simple thing for their programming team to fix. (Older people are very used to “www” in front of everything, so this redirect should function.)

I kinda feel like I ought to be charging for debugging services.

I have not actually tried out video sessions yet. I’ve just run Privacy Badger and Ghostery browser plug-ins in both Opera and Firefox. Results:

CLIENT LOGIN PAGE: Privacy Badger: www.googletagmanager.com – cookies blocked fonts.gstatic.com – cookies blocked

Ghostery: Facebook Connect – BLOCKED! Google Tag Manager – allowed

CLIENT IN-SESSION: Privacy Badger: www.googletagmanager.com – cookies blocked fonts.gstatic.com – cookies blocked

Ghostery: Facebook Connect – BLOCKED! Google Tag Manager – allowed

++++++++++++++++++++++++++++++++++++++++++++++++++

THERAPIST LOGIN PAGE: Privacy Badger:

www.googletagmanager.com -- cookies blocked
fonts.gstatic.co -- cookies blocked

Ghostery: Google Analytics – “tracking not detected” it says Google Tag Manager – allowed Google APIs – allowed Google Static – allowed

THERAPIST IN-SESSION: (The same) Privacy Badger: www.googletagmanager.com – cookies blocked fonts.gstatic.co – cookies blocked

Ghostery:

Google Analytics – “tracking not detected” it says Google Tag Manager – allowed Google APIs – allowed Google Static – allowed

++++++++++++++++++++++++++++++++++++++++++++++++

It’s necessary for some cookies and tracking to the functioning of a website. Privacy Badger and Ghostery are both detecting some of this from Google libraries which they choose to allow. I don’t have enough security engineering knowledge to know if these are harmless or not. I do know they are very common on most websites. Yet – Privacy Badger says they are blocking some cookies…

Facebook should not be contacted on the client side! I don’t know what Ghostery is blocking from being sent to Facebook, but this should not be on a HIPAA site. The connection between therapist and client seemed at first glance to work fine with Facebook blocked. I will discuss this with Hipaalink.net before I test it with actual clients. For now I give them the benefit of the doubt. I am told by a computer engineer that Facebook supplies some code libraries (like Google) which websites can use – maybe this is not intentional tracking, just their developers needing to fix this?

There is more tracking taking place on the home page and more public sections of the website than inside the login and televideo areas. So some effort to decrease tracking has been made for actual clients. I see different trackers on the public areas of the website today than I did when I first checked on 7/24/23.

It’s a maybe… But at $9.95 per month hipaalink.net could be a nice option if they clean up minor tracking concerns. Again, I have not tested the video yet.

#psychology #neurology #socialwork #psychiatry @psychology @socialwork @psychiatry #mentalhealth #psychotherapists @psychotherapists #cookies #tracking #hacking #3rdpartytrackers #HIPAA #privacy #dataprivacy #webbeacons #telehealth #video #doxy #healthcare #dataprotection #hipaalink #hipaalinknet

HIPAA LINK

HIPAA LINK