How to Avoid Leaving Tracks Around the Internet
nytimes.com
nytimes.com
I’m not sure I can recommend Ghostery, as their business model is a bit suspicious: https://en.wikipedia.org/wiki/Ghostery#Criticism
> Using websites whose addresses begin with https are also safe; they, too, encrypt their data before it’s sent to your browser (and vice versa).
Safe from your public Wi-Fi operator. Not from the company with a tracking script on the page.
> You don’t sign into Apple Maps or Safari (Apple’s web browser)
You sign into the OS, though.
> You never want to tell Facebook where you were born and your date of birth. That’s 98 percent of someone stealing your identity!
I can literally Google this information. We need to stop treating knowledge of public data like this as some sort of identity metric.
For websites I like, I turn off uBlock Origin but leave Privacy Badger enabled.
So far to me that's been pretty good to the point I stopped using Privacy Badger (which I agree is pretty good too!).
You should stop printing nonsense
And one step further, such public data should not be used by corporations / governments to validate (or inform much, beyond "details") the identity of someone. It's just too unreliable and can't be verified.
Maybe PGP or similar, hashed from some source biometric data, to allow multiple 'IDs' over a lifetime but 100% verifiable.
I love how it's easier to steal my identity than to intercept my encrypted web traffic.
Society really could do with a cryptographically sane method of authentication - think an PKI-type verification but in replacement for '100 points of id' / Social Security Number / Tax File Number etc.
Surely the cost of implementation wouldn't outweigh the cost of identity theft and other types of fraud which can occur due to the current flawed system?
Maybe the costs are/would be paid for by different parties, but indirectly we all pay for them through insurance premiums and taxes which cover the (preventable) financial damage anyway.
* Disable 3rd party cookies
* uBlock Origin
* Privacy Badger
* HTTPS Everywhere
These things are all dead simple and will significantly reduce your trackability. Of course they are far from comprehensive or perfect, but it's the Internet equivalent of washing your hands after you go to the bathroom.
We've actually developed a self-hosted private cloud solution as a substitute to Dropbox for exactly these reasons. Basically a private Dropbox at home (no complicated installation and no server needed)
We're currently in beta, could interest a few in this thread! https://www.duple.io/en/
The point is to have a product that works just like a Dropbox, as simple and straightforward, but that is actually private with no one interfering, playing, accessing or reading your data.
Good luck on your product. Seems promising. But I didn't like how your site loaded slowly (just a subjective feedback)
Maybe I've misunderstood, but this sounds just like Syncthing with an always-on client - except for the file versioning, that sounds like an interesting feature to me.
I've been using SyncThing for over 4 years and while it has a few rough edges (synced/shared/global file ignore would be great) still it's been fully reliable and a generally great user experience. So if you're trying to cater to existing SyncThing users don't mince words to make it appear that something which you claim is a negative with SyncThing doesn't exist in your product - which it clearly does.
SyncThing has a huge advantage: years of trust. They have been around since 2013 and continue to crank out features and builds consistently. Duple hasn't been around for one year at the time of this writing. Beyond that it's clear from the Duple site that it's main goal is to take my data and file replication hostage via licensing fees. I'm curious how or why I'd donate before I've even installed the Beta (based on your click flow to even reach the downloads page)? No thanks.
Also, let's clarify something Duple has wrong...
Duple states: "Syncthing is P2P, so you get the disadvantages along with it e.g. all your devices need to be turned on at the same time. If not, you get a desynchronisation between your devices and create conflict." - This is wrong. You do not need all your devices on at the same time with SyncThing. Yes, it is true that it's good to have a device with a consistent state, however it's not required. The second part of the statement is FUD. When conflicts happen it's generally around odd permissions or file updates with regard to versioning. This was more problematic in versions prior to 1.0. At this point in time I haven't run into this issue other than because of disparate problems caused by file permissions which SyncThing does a great job preserving.
Duple also states SyncThing has no IOS support and yet, itself, has neither IOS or Android. Or Windows... Or an open source repo of what I'm supposedly using.
In my mind Duple doesn't compete with SyncThing and, really, never will. But here's the thing... Don't pretend to compete where you don't. SyncThing users aren't looking for Duple. You'd do yourself a better service to take that verbiage out because all it did for me was give me the impression that Duple is lying about competitors that they simply didn't take the time to understand. That leaves a bad impression in my mind.
Of course this is fixed by simply having the desktop on all the time, which would then make it similar to a client server setup.
If I take photos on vacation and throw them in a sync'd folder the next time both devices are online they will resolve the new file delta between that shared folder. That doesn't imply I always need one or the other device online. The more devices syncing the less likely it is that only one would be online at a time, but again there's no requirement there for an always on device.
Anyway... SyncThing is fantastic for users who are willing to invest some time learning how the software works. Every paid for product seems to cater to the "it just works" mentality thereby sacrificing control to me, the user, to handle situations that can't be handled by overly simplified, cloud-first, lock the user into our licensing model solutions. And don't get me wrong, those are fine for many people. For users who want more control via more responsibility - then SyncThing is great. But I don't like how they are spreading FUD about it just to get some name association.
Regarding the synced/shared/global file ignore, there's an imperfect but usable work-around:
You can use #include statements in your .stignore, so you can include another file that contains the global ignore list, then sync that file. You have to set up the .stignore with the include statement for all of your devices/folders, but after that, it's essentially a global ignore list.
Hope that helps.
Where is link to github with ALL code?
But there's no mention of Tor, which is arguably the best available way to "avoid leaving tracks around the Internet". And better yet, using Whonix, which prevents leaks around Tor.
Using multiple email addresses is good. But if you're sloppy about browser hardening, they'll all get linked.
More generally, there's compartmentalization. Not just multiple email addresses, but multiple VMs, connecting through different VPNs, and/or Tor instances. Modern machines can run several Linux VMs, and switching among them is as easy as switching among app windows.
So basically you can present online as many different personas. Even if everything that each persona does gets linked, it won't get linked to other personas. If you're careful, anyway.
Shout out to https://www.qubes-os.org/ Qubes OS, an Open Source research implementation of this concept on the OS level. BYO OPSEC.
The learning curve for that is steeper than for VirtualBox, however. As is, with absolutely no doubt, the security level. In that it uses a hardened version of the Xen hypervisor. That also means tighter hardware requirements, however.
While I was at it, I used multiple pfSense VMs to create nested VPN chains. Sort of like Tor circuits, but static (so much less anonymous) but also much faster.
Then Whonix came along. And it works very well with nested VPN chains.
The NYT is a content website in a sea of content websites. Getting you on their email list is valuable in the way that getting you to install their app is valuable; they can send you notifications and a few free articles that can maybe upsell you into a subscription.
They have no choice but to do this because we still think text and pictures on the internet should be free. We've come around to paying for music and videos, but it still seems too much of a hurdle for traditional news outlets.
Not linked... in a way visible to you.
Google is just one of 100+ ad networks that show you personalized ads. You can turn off ads personalization from Google or any of the other participating ad networks here at http://optout.aboutads.info/
Source: https://adssettings.google.com
Evil corporation never lies to you
But I really wanted to opine about the optout.aboutads.info link. I suppose that using that can't hurt, but I didn't find it to be particularly helpful. I gave up on it entirely quite a while back.
Is the author assuming the absence of https encryption here, or is there some widely available exploit I don't know about?
All "antiviruses" use it
Edit: sorry, my bad, cloudflare 1.1.1.1 resolves it as 127.0.0.5. Someone ought to check that out...
Edit2: apparently this is a deep rabbit hole: https://community.cloudflare.com/t/archive-is-error-1001/182...
> “Create a different email address for every service you use,” wrote Matt McHenry. “Then you can tell which one has shared your info, and create filters to silence them if necessary.”
Obligatory mention - for gmail you can suffix your email address with a service name by using +, e.g., johndoe+adobe@gmail.com will be delivered to johndoe@gmail.com. So if a service leaks your data or sells your email, you’ll know who to blame.
Although the article recommends not to use gmail, it’s a neat trick if you’re stuck with it.
"Forget password" becomes unusable though, since you’ll probably forget what suffix you used for each service.
Useful workaround is to have unique aliases on a domain name you control. Can’t get around that with a minute of work!
For example, my Twitter address might be twitter@mydomain.com, my Google address google@mydomain.com and so on. All of those go straight to my inbox unless I decide to set up individual filters for them.
The downside is that I can’t easily migrate to a service that doesn’t support this.
Not affiliated, just a happy customer.
I guess I could use a hash of the domain (eg asdffdsa@accounts.mydomain.net) to make my strategy less visible, but that feels like I'm probably overthinking it.
You can put that in a safe wallet. OneDrive provides that now
My CVS coupons are nearly always for an antacid, nicotine cessation, or allergy medicine - then I usually get a few extra coupons for something that surprises me like beauty products or facial cleanser.
There’s nothing Google involved with the CVS coupons, I’d bet money on that.
We have a /48 at home using IPv6 privacy extensions for the full address but that isn’t a useful component of a strategy if I’m being identified by the /48 rather than the full 128-bit address.
* declare you are from EU even if you are not
then any provider is damned scared of messing with your privacy
> Log in or create a free New York Times account to continue reading in private mode."
quite ironic :)
My suspicion is that few know, and fewer are doing it.
An important goal? Help those who care enough become aware enough to take action.
And that is not even funny
https://twitter.com/runasand/status/1186775481615605760?s=20