this post was submitted on 10 Nov 2023
65 points (92.2% liked)

Privacy

32165 readers
307 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

For me it would be the following:

  1. Don't reuse usernames/names
  2. Avoid using social media
  3. Use Tor/VPN when you can
top 50 comments
sorted by: hot top controversial new old
[–] nik282000@lemmy.ca 50 points 1 year ago (9 children)

For normies it's easy:

  1. Password Manager
  2. Firefox
  3. Adblocker

Those three will make up for 90% of peoples bad habits.

[–] Gutless2615@ttrpg.network 6 points 1 year ago

Literally this. This is the answer.

[–] Schlemmy@lemmy.ml 4 points 1 year ago

Password manager is something I've been preaching but they seem to find it to much of a hassle. Set up Ubikeys for my MIL. Works like a charm.

[–] CCMan1701A@startrek.website 4 points 1 year ago

Password Manager that is not LastPass lol

[–] multicorn@programming.dev 3 points 1 year ago

I would add: turning off telemetry, especially windows and other ms products

load more comments (5 replies)
[–] auf@lemmy.ml 43 points 1 year ago (1 children)

Here's the ultimate tip for securing your private information.

  1. Keep away from the Internet
[–] otter@lemmy.ca 17 points 1 year ago (1 children)

Yea a lot of this advice "don't use anything from Google/Microsoft/Facebook/amazon" or "avoid social media" is just going to tell newcomers that privacy isn't for them

Instead go in order

  • secure private messaging since that's where a lot of your personal private info is going (use Signal)
  • switch to Firefox over chrome, it'll do all the same things
  • use bitwarden (or keepass, but that one is a bit more technical) to manage your passwords, and generate random passwords for things you can reset easily

All of these are easy, don't have much of a learning curve, and will give them significant gains privacy wise. Also I'm betting they will continue to learn and do more stuff after that.

[–] ChaoticEntropy@feddit.uk 8 points 1 year ago

"Use Signal" is great, but every other person you know insisting on using WhatsApp makes it moot.

[–] cooopsspace@infosec.pub 26 points 1 year ago* (last edited 1 year ago)
  1. Password manager such as Bitwarden, generate long strong passwords for everything.
    1a. Corpo SSO (By which I mean "log in with Google/Microsoft/Apple/Whatever") nothing.
  2. Hardware keys, MFA on anything that doesn't support one.
  3. Degoogle, de-megacorp.
  4. Use Linux, stop the Stockholm syndrome that is Windows.

VPN shouldn't even be in the top 10. The benefits are dubious at best and the jury is still out on whether it makes you more of a target or if you can trust ANY provider meaningfully.

[–] RiQuY@lemm.ee 20 points 1 year ago (1 children)

I think you are confusing privacy with anonymity.

[–] ChaoticEntropy@feddit.uk 15 points 1 year ago* (last edited 1 year ago) (1 children)

Don't be afraid to lie when it doesn't matter. Unless it is for something official or that will impact the service, use the wrong DoB, enter the wrong name, etc... if it isn't going to need verification then there is no need to give valid data that can be stolen or misused at a later date.

[–] ReversalHatchery@beehaw.org 3 points 1 year ago

But be sure to take note of that piece of information that you have lied, in case they will ask you when the time comes for account recovery.

  1. Ditch Chromium.
  2. Use a Password Manager instead of "log in with Google/Facebook/whatever"
  3. Keep tabs on Mobile App permissions and revoke as many as you possibly can. I revoke location permissions from every single app except Navigation apps, which have to ask for location permissions. If possible, remove apps in favor of Native Alpha / Hermit web apps
[–] hperrin@lemmy.world 10 points 1 year ago (2 children)

I disagree with your #3 point. There is nothing stopping you from disclosing personally identifiable information through Tor or a VPN. They can help you with keeping private, but they don’t do anything if you don’t know how to use them for privacy.

The Tor browser resists fingerprinting, but a VPN doesn’t. A VPN only keeps your IP address private, and your IP address isn’t really that interesting to the big tracker companies.

I would say something more like Firefox’s container tabs is way more useful for privacy.

load more comments (2 replies)
[–] SaltyIceteaMaker@lemmy.ml 10 points 1 year ago (1 children)

Got some disagreements here:

I'd say you can reuse names/user names but then you should seperate your internet personality from your reallife personality.

Choose the right social media (fedi verse stuff that doesn't spy on you)

Also tor is a bit much for most things. for staying private a vpn you can personally trust should be enough

But the tips you listed are great for staying anonymous

[–] hperrin@lemmy.world 2 points 1 year ago

Fediverse stuff can still be scraped and used to profile you, but since there’s no targeted advertising on the platform, if you’re anonymous, that’s extremely unlikely.

[–] beefpeach@infosec.pub 8 points 1 year ago (11 children)
[–] hperrin@lemmy.world 5 points 1 year ago

Brave’s track record on privacy has been really good. It’s all the other terrible shit they do that you should avoid them for.

load more comments (10 replies)
[–] atimehoodie@lemmy.ml 8 points 1 year ago

Wow. Lemmy's user base has really pidgeon-holed itself in these comments. Just observing, not critcizing. Interesting to see. Privacy to most people here means privacy from big tech and government. Responses are also largely technology-focused solutions rather than personal practices.

I'm going to throw "Don't give out your personal information" into the ring to round things out.

[–] sour@kbin.social 7 points 1 year ago

don’t reuse usernames

but sentimental value ._.

[–] ReversalHatchery@beehaw.org 6 points 1 year ago

I would put "Alwayse use uBlock origin, and decline any data consents" instead of the third point, and swap it with the 2nd

[–] isa@leminal.space 6 points 1 year ago

i think everyone’s threat model is different so the first step would be to decide what urs is and the lengths in which ur willing to go to protect ur data and privacy. for some people, there’s no need to go so far as to assume complete anonymity on the internet and that’s fine.

[–] chicken@lemmy.dbzer0.com 5 points 1 year ago* (last edited 1 year ago)
  1. Don't say too much about yourself or post photos
  2. Burn old accounts and make new ones periodically
  3. Turn off features that notify people when you get online or what you're doing like Steam and messaging clients
[–] dangblingus@lemmy.dbzer0.com 5 points 1 year ago
  1. Use a trustworthy VPN and encrypt your DNS lookups
  2. Set up a Pihole for DNS filtering and ad server blocking/use UBO on FF
  3. Don't associate your online usernames with your real name or any identifying information like your birthyear (so like, don't use Facebook)
[–] bbbhltz@beehaw.org 5 points 1 year ago
  1. Password manager
  2. Adblocker
  3. 2FA

Next steps are a Quick software audit: how do you check your email, what chat apps are you using, what browser are you using, etc.

Always keep things low-friction to stat out

https://bbbhltz.codeberg.page/blog/2022/03/low-friction-introduction-to-digital-privacy/

[–] anothermember@beehaw.org 5 points 1 year ago* (last edited 1 year ago)

1: Use Linux

2: Mullvad browser (Firefox-based) - while I don't use it myself (I have my own customised Firefox in-keeping with my threat model) for an average "normie" user this seems to have the most sane defaults for privacy including uBlock Origin installed by default (and fingerprint resistance).

3: Keep your software updated (too overlooked by so many users).

[–] faintwhenfree@lemmus.org 4 points 1 year ago* (last edited 1 year ago)

It all depends on risk rewards. Everybody has a different case. I don't think generic advice is possible. Only what works for specific individuals. Yours sounds like is good advice for you.

Edit: there is no defense against a threat vector with unlimited resources.

[–] Gutless2615@ttrpg.network 3 points 1 year ago

Use an adblocker

[–] jecht360@lemmy.world 3 points 1 year ago (1 children)

Just some off the top of my head.

  1. Don't use Google, Microsoft, or any other major company (or subsidiaries) for email.
  2. Use a privacy-focused browser (aka not Chrome).
  3. Don't sign up for every rewards program or app, they all harvest data.
[–] NaibofTabr@infosec.pub 3 points 1 year ago* (last edited 1 year ago) (9 children)
  1. Don't sign up for every rewards program or app, they all harvest data.

IRL tip, instead of signing up for the grocery store's discount program, at most stores you can use local area code + Jenny's number. It's usually in the system already. ###-8675309

You won't be able to use the coupon/reward points system but they're usually not worth much anyway.

load more comments (9 replies)
[–] walter_wiggles@lemmy.nz 2 points 1 year ago (3 children)
  1. Don't open email attachments from your family.
load more comments (3 replies)
[–] WTF@feddit.ch 2 points 1 year ago
  1. Don't let the phone use You.
  2. Use a firewall with ads blocker. (Like InviZible Pro)
  3. Make an Encrypt-first habit, be it for files, notes, contacts, or passwords.
[–] Zerush@lemmy.ml 1 points 1 year ago* (last edited 1 year ago)
  • Common sense
  • Don't store relevant or important data in your Mobile, disconnect GPS
  • Use a VPN

But there are way more measures needed to patch the biggest privacy holes. Giving fake data is better than hiding data, ⚠Search engines, read TOS and PP, use ad and trackerblocker, extensions like JShelter or similar, check your browser in Browserleaks and adjust it corresponding to the results. don't use centralized chats or social networks, use front-ends as much as possible, don't share private photos, at least not without deleting EXIF data before, use Tuta.mail, Proton Mail or Nextcloud Mail (Murena), instead of Gmail or 🤢utlook, DON'T USE Imgur.......

load more comments
view more: next ›