Live data from Hacker News

Ask HN: What do you do for online privacy?

news.ycombinator.com

61–70 of 82 posts

Re: Ask HN: What do you do for online privacy?

#61

It matters to me that my digital data (PII or not) is not tracked aimlessly and sold to 3rd parties without my consent. So, I use a VPN because I don't trust my ISP. I use LineageOS with microG because I don't trust the phone manufacturer and Google to not track me. I use Linux coz fuck Windows. Hardened with secureboot and FDE with TPM. I use ungoogled chromium with uBlock and NoScript. I also selfhost most of the s…

I'm gonna pick out one thing I'm always really curious about; what makes you trust a VPN provider more than an ISP? I've never quite understood this especially with how iffy and downright wrong VPN marketing (e.g. ad-reads on YT) can be.

- Why trust a VPN company more than your ISP? To me it seems like a commercial VPN could have equal or more incentive to do questionable things with your info.

- Is it somehow easier for an ISP to track my activity vs. a single VPN company whose servers I'd tunnel all my traffic through?

Sure, the ISP knows where I live and all that but it seems like a VPN could easily identify/know me to the same degree.

( - or is it like a self-hosted VPN sitting in the cloud, and would such a thing be practical/effective at all)

Re: Ask HN: What do you do for online privacy?

#62
I'm not that serious about it, since I think online privacy is kind-of a farce. PiHole on the home network; AdGuard Home on my travel router; Tailscale into my home network as an exit node if I want more protection; AdGuard DNS on my iDevices when they are on 5G.

Re: Ask HN: What do you do for online privacy?

#63
post #4

I don't have accounts at any major online businesses, except Visa. Can't really avoid that one easily. My browsers block connections to trackers and 3rd party cookies. Sometimes scripts too, for good measure, and some selected stuff from user.js ( https://github.com/arkenfox/user.js ). Separate profiles for each service just to make really sure important stuff doesn't get affected by casual browsing, and vice versa.…

> No google- or apple- owned phone. What device do you use, then?

No mobile device at all. But there are Linux phones like the Librem 5 or PinePhone, as well as degoogled Android phones.

Re: Ask HN: What do you do for online privacy?

#64
It's not much, but I do a couple of things:

- NextDNS configured to block ads, trackers and unnecessary domains (including all Facebook domains) across my home network and mobile devices

- Use multiple browsers on desktop and mobile, all configured with privacy settings, to keep Google-related tasks separate, i.e. use Chrome only for Google stuff, Bromite/Vivaldi/Firefox for everything else.

- Use uBlock Origin on all my desktop browsers.

- Sticking with Windows 10 for the time being. But highly configured to turn off telemetry and remove Microsoft's general crap they include in Windows.

- Been learning how to self-host stuff and slowly migrate apps and things to my server where possible.

Re: Ask HN: What do you do for online privacy?

#65
post #61

It matters to me that my digital data (PII or not) is not tracked aimlessly and sold to 3rd parties without my consent. So, I use a VPN because I don't trust my ISP. I use LineageOS with microG because I don't trust the phone manufacturer and Google to not track me. I use Linux coz fuck Windows. Hardened with secureboot and FDE with TPM. I use ungoogled chromium with uBlock and NoScript. I also selfhost most of the s…

I'm gonna pick out one thing I'm always really curious about; what makes you trust a VPN provider more than an ISP? I've never quite understood this especially with how iffy and downright wrong VPN marketing (e.g. ad-reads on YT) can be. - Why trust a VPN company more than your ISP? To me it seems like a commercial VPN could have equal or more incentive to do questionable things with your info. - Is it somehow easier…

Obviously people have different reasons for using VPNs. But how I see it, between the ISP and a commercial VPN, which provider would you trust more with your internet activity?

The one with more PII data on you or the one with less? Noting that some VPNs even allow you to pay with Bitcoin.

My ISP knows where I live right to my doorstep. A VPN only knows roughly from which city I'm accessing the service from. And for mobile data, it is worse since the carrier I use has a copy of my govt issue ID (as mandated by law).

Between the two, do you trust the one whose core business is competitively providing privacy products? or .... the local private entity (some operating as a market monopoly) susceptible to government interference & anti-privacy laws .... and who basically answers to no one with regard to customer data/privacy?

Am sure all this PII data could be made to be used against you on a worst-case scenario basis but still...

I do have a self-hosted VPN tunnel that I use occasionally, but it's not as effective for privacy as a commercial VPN is if we put all device fingerprinting aside. And besides, the cloud provider still has my credit card so this route doesn't provide any greater privacy benefits than a VPN does.

Re: Ask HN: What do you do for online privacy?

#66
post #13

Earlier quoted context omitted.

Fully agree. Om this note, I had a brief discussion with an employer I collaborated with once, about some potential employees being forced to work in the open because they open sourced their work. I was terribly surprised to get no understanding that this could be perceived as a problem. Especially since work tasks may not be something you would want on your public record necessarily.

In this case, I would recommend that you get an employer-specific GitHub account, so you can compartmentalize it that way. A bit of a hassle, yes, but then, you're definitely not tying yourself in git history to that employer for your entire career.

Can't find it now but I faintly remember this being against their ToS, maybe even before the Microsoft days.

Docs say that it's no problem now, but they "suggest merging multiple accounts" but probably because of less fuckups and support questions.

Re: Ask HN: What do you do for online privacy?

#67
- 1Password

- Fastmail (block images in email, which are often used for tracking)

- Privacy.com

1Password integrates with both of the above, so that any time I sign up for a new service it will get a random, unique email from Fastmail (masked email), a unique credit card from privacy.com, and I use 1Password to generate not only a unique, strong password but also a unique username (hence my current username here, squeegee_scream).

- sync.com for online storage. it's e2ee

- MFA everywhere it's available

- 1Blocker

- nextdns

- use privacy-respecting alternative frontends:

  - use invidious instead of youtube
  
  - libreddit or teddit instead of reddit
  
  - nitter instead of twitter
- macos, following https://github.com/drduh/macOS-Security-and-Privacy-Guide for hardening (I haven't compared this to other hardening guides, but doing something is better than nothing)

- rotate my usernames on social sites on a regular basis. I'm really only active on reddit and HN, but I'm still concerned about being doxxed

- avoid buying things from amazon

- Signal app for communication as often as possible

Re: Ask HN: What do you do for online privacy?

#68
use a network snitch[1] on desktop and mobile. the original slogan says it all: makes the invisible visible. i’d love to use a filesystem snitch too, but none exist yet afaik.

it’s interesting to observe firefox or any other legitimate app i’m using make many unsolicited requests to weird domains. it feels good to interactively deny those connections.

make sure that cloud[2], which includes git hosts[3], are untrusted. unencrypted data should never hit remote. keys should never leave local.

consider the tradeoffs with online interactions. engaging with other humans in public on github and hackernews is likely worth. engaging in impassioned op-ed debate with bots on engagement monetization platforms like twitter or youtube is likely not.

pay for things like kagi search. trading money for a product or service that improves your life is a good deal. no free lunch.

cover unused cameras with black stickers. ios faceid still works without a forward facing camera.

1. https://github.com/nathants/mighty-snitch

2. https://cryptomator.org/

3. https://github.com/nathants/git-remote-aws

Re: Ask HN: What do you do for online privacy?

#69
> Let's not confuse anonymity vs privacy vs tin-foil hat level paranoid.

First I set out a threat model, which allows me to switch context depending on level of opsec needed. (Do I really need a disposable VM in Qubes just to read a PDF document versus opening it in Google Docs, for example).

Then any number of tools and best practices from these fine websites:

https://www.privacyguides.org/

https://ssd.eff.org/

https://www.amiunique.org/

https://www.youtube.com/c/TheHatedOne/videos

https://anonymousplanet.org/

https://www.whonix.org/wiki/DoNot

Post reply on HN