So I followed a couple privacy guides recently. The main ones were a post I made asking the community for guidance about privacy and that quick privacy guide from redsails. They were helpful but honestly left me kinda unsatisfied

They just felt like quick start checklists, not really an education. I’m looking for something more thorough and most importantly a way to keep learning long term instead of just a one time setup

Where can I find stuff that goes deeper? Like actual resources and knowledge, not just steps to follow

Also what about the privacy paradox? The more you hide the more you stand out

    • octbear [none/use name]@hexbear.net
      link
      fedilink
      English
      arrow-up
      6
      ·
      3 days ago

      Seconding this. I’ve read the tech sections and its a very thorough guide

      I started by torrenting on libgen which gives you everything from when that torrent was created (usually an early revision) but he’s constantly experimenting and issuing updates as services change which is awesome cause the instructions are incredibly specific and get dated whenever a referenced software has an upgrade so buying is worth if you end up following the guides

  • IranOuttaOil [none/use name]@hexbear.netB
    link
    fedilink
    English
    arrow-up
    10
    ·
    3 days ago

    Well the long-term solution is to control your infrastructure completely. Digital sovereignty.

    And to use technology in a way that meets your expectations, that means putting trust into other people.

    The long-term solution is to have a community to develop and maintain tooling that meets your needs. If you are dependent on untrusted infrastructure, it’s just going to be one battle after another, as your adversary just keeps trying to fuck you.

    The actual privacy and security education is very mathematical or technical on hardware or software principles. It is the responsibility of engineers to make those considerations.

    In your case most technical engineers are adversarial. This is why you have to even consider this problem.

  • dead [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    7
    ·
    3 days ago

    There is no definitive set of rules for “privacy”.

    You have to know what you are trying to hide and who you are trying to hide it from.

    You cannot hide that you are a communist/socialist/leftist/whatever. Hiding your affiliation to these is antithetical to the goals. You have to get together (in real life, not on the internet) with other like-minded people to accomplish the goals of these causes.

    Electronic Frontier Foundation (EFF) is the best source of privacy information that I’ve known. The organization has lawyers that sometimes provide pro-bono legal representation in cases related to internet stuff. They have lots of educational material and guides on the website.

    Go to the link at the bottom, scroll to the bottom of the page. There are buttons that says like “I am a (abortion patient | protestor | academic | journalist | lgbt youth)”. Click whichever button is most relevant to you and it will give you a list of privacy suggestions.

    https://en.wikipedia.org/wiki/Electronic_Frontier_Foundation

    https://ssd.eff.org/

  • alexandra_kollontai [she/her]@hexbear.net
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 days ago

    I’ve been in a similar mindset to you and for me I found it was very easy to get overly conspiratorial, paranoid and afraid of the state of things. So just keep in mind to do things that are proportional and healthy, ok?

    That aside, the most important thing to think about is to have a threat model. You can’t defend yourself until you know what you are trying to defend yourself against.

    For example, “encrypt your hard drives” is only practical advice if your threat model includes authorities coming to your house, taking your computer, and reading what’s on it.

    You need to define which data you want to be private from whom. Then you can look at how they’re getting it, and only then can you take measures to stop them.

    Feel free to reply with your threat model and I could maybe give actionable advice.

  • LaughingLion [any, any]@hexbear.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    2 days ago

    I won’t get into a great debate about this but I will tell you that 90% of what I see as advice to online privacy is absolute snake oil.

    To put it bluntly, privacy online is almost completely dead and the myriad of ways each person is tracked via cookies, IP, logins, MAC, browser fingerprinting, behavioral telemetry and so on on are so pervasive and integrated into the internet at this point that anyone who needs to know who you are will know who you are

    You can certainly take steps to be a little more obfuscated but the simple analogy is if you take a walk down the street and buy a bagel with cash anyone can see you are (describes you) and that you went to that shop and bought a bagel and then walked back into that apartment/home. If you are doing that every single day then anyone watching you has a pretty good idea that the person of your description lives in that apartment/home and buys a bagels at that shop. The internet is no different and is, in fact, worse, because everyone is the watcher and they are all listening to your conversations with the shop keeper and standing outside your doorway and looking over your shoulder every second of every moment and all talking to each other. Trying to whisper in your conversations isn’t going to help you nor is putting on a medical mask and baseball cap. They still see the person leaving their apartment/home and going to the bagel shop every day to buy that bagel.

    EDIT: My point isn’t to discourage people to practice OPSEC and implement some basic privacy methods into their internet use. My goal is to discourage anyone here from thinking that stuff if genuinely hiding you from the corpos and feds. Don’t trick yourself into thinking you are untraceable with some basic OPSEC. Don’t get caught, comrades.

    • Sleepless One@lemmy.ml
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 days ago

      If you are doing that every single day then anyone watching you has a pretty good idea that the person of your description lives in that apartment/home and buys a bagels at that shop. The internet is no different…

      I’m no privacy expert, but this seems true to me. I lurk a lot and find myself remembering and correlating details about users in my mind all the time, without even doing it intentionally. I imagine others here do this as well. And that’s not even touching on bad actors doing this intentionally and automated scraping wit bots.

      • LaughingLion [any, any]@hexbear.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        oh, yeah, and companies have even more access than you do. they see a million pieces of data on you that nobody sees

        you could create a ghost on the internet but its an extremely deliberate act for a very specific purpose in which almost nobody here is doing or plans to do

        and even then most people will slip up somewhere and start leaking identifying information about themselves, their location, and so on

    • AssortedBiscuits [they/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 days ago

      Another thing to consider: you might do everything right, but your friends won’t. In the end, you have to either completely sever your connections with people who can’t or won’t follow opsec or you allow yourself to be found out because all of your friends still use Discord.

      It’s like walking to buy bagels with the same 10 people except the 10 people all hand out business cards with their addresses, some of which include your address, to random people.

      • LaughingLion [any, any]@hexbear.net
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        2 days ago

        There’s that, too.

        I’ll put it this way: if you really wanted to be a ghost you’d need to be very deliberately about it for a very specific reason. Let’s say you wanted to run some spokesperson account for a clandestine organization.

        Well, you’d need a completely clean device. Maybe an old laptop. Something that preferably has no internal tracking on it, so we are avoiding an android phone here. You’ve disabled the mic and webcam. You’ve installed all the proper security measures that block cookies and tracking data and all that. Nothing about the install contains any identifying information at all. This is where most people stop and think they are covered.

        You know of a bunch of open wifi areas around your city. Places you can access without being on CCTV. You connect to one, jump through some obfuscation methods to hide your real IP. You create your email and social media accounts, all having nothing to do with any identifying information at all in regards to you. Now you post ONLY the information about your clandestine group. You never, ever log into any of your real social media accounts from those wifi access points or this device. You never browse on this device or do anything on it that isn’t just to boot it up from a random location, secured connection to make your posts. You never ever access any of those accounts from any insecure device or on any insecure network.

        Congrats, you now have a ghost account that you can never ever slip up on or you risk being exposed to the right organizations if they really want to find you. Don’t make a mistake. Technically you only have to slip up one time.

        Now ask yourself, is that really going to be you? It’s probably not. Sure, you should practice OPSEC and not tell everyone on the internet who you really are if you are fearful of your safety. Most people don’t need this kind of OPSEC. Most organizations aren’t capable enough to find you even if you made mistakes. So there is a sliding scale.

        However, if you are doing your daily browsing and logging into personal accounts no amount of OPSEC is going to protect you. Blocking cookies and “tracking data” and all that is pretty pointless to advertisers and big companies like facebook because there are many techniques they have to track people beyond that stuff and chances are after a very short while, they’ve associated this “ghost” with your real identity in short order because your habits have exposed you.