this post was submitted on 25 Jul 2026
36 points (100.0% liked)

libre

10237 readers
101 users here now

Welcome to libre

A comm dedicated to the fight for free software with an anti-capitalist perspective.

The struggle for libre computing cannot be disentangled from other forms of socialist reform. One must be willing to reject proprietary software as fiercely as they would reject capitalism. Luckily, we are not alone.

libretion

Resources

  1. Free Software, Free Society provides an excellent primer in the origins and theory around free software and the GNU Project, the pioneers of the Free Software Movement.
  2. Switch to GNU/Linux! If you're still using Windows in $CURRENT_YEAR, try a GNU/Linux distribution.

Rules

  1. Be on topic: Posts should be about free software and other hacktivst struggles. Topics about general tech news should be in the technology comm or programming comm. That doesn't mean all posts have to be serious though, memes are welcome!
  2. Avoid using misleading terms/speading misinformation: Here's a great article about what those words are. In short, try to avoid parroting common Techbro lingo and topics.
  3. Avoid being confrontational: People are in different stages of liberating their computing, focus on informing rather than accusing. Debatebro nonsense is not tolerated.
  4. All site-wide rules still apply

Artwork

founded 5 years ago
MODERATORS
 

So I followed a couple privacy guides recently. The main ones were a post I made asking the community for guidance about privacy and that quick privacy guide from redsails. They were helpful but honestly left me kinda unsatisfied

They just felt like quick start checklists, not really an education. I’m looking for something more thorough and most importantly a way to keep learning long term instead of just a one time setup

Where can I find stuff that goes deeper? Like actual resources and knowledge, not just steps to follow

Also what about the privacy paradox? The more you hide the more you stand out

top 19 comments
sorted by: hot top controversial new old
[–] IranOuttaOil@hexbear.net 9 points 1 month ago

Well the long-term solution is to control your infrastructure completely. Digital sovereignty.

And to use technology in a way that meets your expectations, that means putting trust into other people.

The long-term solution is to have a community to develop and maintain tooling that meets your needs. If you are dependent on untrusted infrastructure, it's just going to be one battle after another, as your adversary just keeps trying to fuck you.

The actual privacy and security education is very mathematical or technical on hardware or software principles. It is the responsibility of engineers to make those considerations.

In your case most technical engineers are adversarial. This is why you have to even consider this problem.

[–] BaggedEarful@hexbear.net 9 points 1 month ago (1 children)

I haven't read it myself, but I've seen Extreme Privacy by Michael Bazzell recommended on this topic before.

[–] octbear@hexbear.net 5 points 1 month ago

Seconding this. I've read the tech sections and its a very thorough guide

I started by torrenting on libgen which gives you everything from when that torrent was created (usually an early revision) but he's constantly experimenting and issuing updates as services change which is awesome cause the instructions are incredibly specific and get dated whenever a referenced software has an upgrade so buying is worth if you end up following the guides

[–] kleeon@hexbear.net 9 points 1 month ago

Don't use technology. Retreat into the woods and wage a protracted insurgency against the state

[–] eclipse7@feddit.nu 6 points 1 month ago* (last edited 1 month ago)
[–] Enjoyer_of_Games@hexbear.net 6 points 1 month ago (2 children)

There is an instructional video titled One Battle After Another.

[–] peanutbuttercupola@hexbear.net 10 points 1 month ago (1 children)

Step 1: buy an old phone that can't even connect to anything anymore

Step 2: drink and smoke a lot

[–] kristina@hexbear.net 6 points 1 month ago (1 children)

Step 3. Talk about pussy a lot??

[–] miz@hexbear.net 4 points 1 month ago* (last edited 1 month ago)

wow, I've been preparing for revolution this whole time??

[–] EveningCicada@hexbear.net 8 points 1 month ago (1 children)

If you don't have an escape tunnel under your bed then what are you even doing with your life

[–] peanutbuttercupola@hexbear.net 6 points 1 month ago

Digging the escape tunnel, I hope.

[–] dead@hexbear.net 5 points 1 month ago

There is no definitive set of rules for "privacy".

You have to know what you are trying to hide and who you are trying to hide it from.

You cannot hide that you are a communist/socialist/leftist/whatever. Hiding your affiliation to these is antithetical to the goals. You have to get together (in real life, not on the internet) with other like-minded people to accomplish the goals of these causes.

Electronic Frontier Foundation (EFF) is the best source of privacy information that I've known. The organization has lawyers that sometimes provide pro-bono legal representation in cases related to internet stuff. They have lots of educational material and guides on the website.

Go to the link at the bottom, scroll to the bottom of the page. There are buttons that says like "I am a (abortion patient | protestor | academic | journalist | lgbt youth)". Click whichever button is most relevant to you and it will give you a list of privacy suggestions.

https://en.wikipedia.org/wiki/Electronic_Frontier_Foundation

https://ssd.eff.org/

[–] LaughingLion@hexbear.net 2 points 1 month ago* (last edited 1 month ago) (2 children)

I won't get into a great debate about this but I will tell you that 90% of what I see as advice to online privacy is absolute snake oil.

To put it bluntly, privacy online is almost completely dead and the myriad of ways each person is tracked via cookies, IP, logins, MAC, browser fingerprinting, behavioral telemetry and so on on are so pervasive and integrated into the internet at this point that anyone who needs to know who you are will know who you are

You can certainly take steps to be a little more obfuscated but the simple analogy is if you take a walk down the street and buy a bagel with cash anyone can see you are (describes you) and that you went to that shop and bought a bagel and then walked back into that apartment/home. If you are doing that every single day then anyone watching you has a pretty good idea that the person of your description lives in that apartment/home and buys a bagels at that shop. The internet is no different and is, in fact, worse, because everyone is the watcher and they are all listening to your conversations with the shop keeper and standing outside your doorway and looking over your shoulder every second of every moment and all talking to each other. Trying to whisper in your conversations isn't going to help you nor is putting on a medical mask and baseball cap. They still see the person leaving their apartment/home and going to the bagel shop every day to buy that bagel.

EDIT: My point isn't to discourage people to practice OPSEC and implement some basic privacy methods into their internet use. My goal is to discourage anyone here from thinking that stuff if genuinely hiding you from the corpos and feds. Don't trick yourself into thinking you are untraceable with some basic OPSEC. Don't get caught, comrades.

[–] sleeplessone@lemmy.ml 4 points 1 month ago (1 children)

If you are doing that every single day then anyone watching you has a pretty good idea that the person of your description lives in that apartment/home and buys a bagels at that shop. The internet is no different...

I'm no privacy expert, but this seems true to me. I lurk a lot and find myself remembering and correlating details about users in my mind all the time, without even doing it intentionally. I imagine others here do this as well. And that's not even touching on bad actors doing this intentionally and automated scraping wit bots.

[–] LaughingLion@hexbear.net 2 points 1 month ago

oh, yeah, and companies have even more access than you do. they see a million pieces of data on you that nobody sees

you could create a ghost on the internet but its an extremely deliberate act for a very specific purpose in which almost nobody here is doing or plans to do

and even then most people will slip up somewhere and start leaking identifying information about themselves, their location, and so on

[–] AssortedBiscuits@hexbear.net 3 points 1 month ago (1 children)

Another thing to consider: you might do everything right, but your friends won't. In the end, you have to either completely sever your connections with people who can't or won't follow opsec or you allow yourself to be found out because all of your friends still use Discord.

It's like walking to buy bagels with the same 10 people except the 10 people all hand out business cards with their addresses, some of which include your address, to random people.

[–] LaughingLion@hexbear.net 3 points 1 month ago* (last edited 1 month ago)

There's that, too.

I'll put it this way: if you really wanted to be a ghost you'd need to be very deliberately about it for a very specific reason. Let's say you wanted to run some spokesperson account for a clandestine organization.

Well, you'd need a completely clean device. Maybe an old laptop. Something that preferably has no internal tracking on it, so we are avoiding an android phone here. You've disabled the mic and webcam. You've installed all the proper security measures that block cookies and tracking data and all that. Nothing about the install contains any identifying information at all. This is where most people stop and think they are covered.

You know of a bunch of open wifi areas around your city. Places you can access without being on CCTV. You connect to one, jump through some obfuscation methods to hide your real IP. You create your email and social media accounts, all having nothing to do with any identifying information at all in regards to you. Now you post ONLY the information about your clandestine group. You never, ever log into any of your real social media accounts from those wifi access points or this device. You never browse on this device or do anything on it that isn't just to boot it up from a random location, secured connection to make your posts. You never ever access any of those accounts from any insecure device or on any insecure network.

Congrats, you now have a ghost account that you can never ever slip up on or you risk being exposed to the right organizations if they really want to find you. Don't make a mistake. Technically you only have to slip up one time.

Now ask yourself, is that really going to be you? It's probably not. Sure, you should practice OPSEC and not tell everyone on the internet who you really are if you are fearful of your safety. Most people don't need this kind of OPSEC. Most organizations aren't capable enough to find you even if you made mistakes. So there is a sliding scale.

However, if you are doing your daily browsing and logging into personal accounts no amount of OPSEC is going to protect you. Blocking cookies and "tracking data" and all that is pretty pointless to advertisers and big companies like facebook because there are many techniques they have to track people beyond that stuff and chances are after a very short while, they've associated this "ghost" with your real identity in short order because your habits have exposed you.

[–] alexandra_kollontai@hexbear.net 2 points 1 month ago

I've been in a similar mindset to you and for me I found it was very easy to get overly conspiratorial, paranoid and afraid of the state of things. So just keep in mind to do things that are proportional and healthy, ok?

That aside, the most important thing to think about is to have a threat model. You can't defend yourself until you know what you are trying to defend yourself against.

For example, "encrypt your hard drives" is only practical advice if your threat model includes authorities coming to your house, taking your computer, and reading what's on it.

You need to define which data you want to be private from whom. Then you can look at how they're getting it, and only then can you take measures to stop them.

Feel free to reply with your threat model and I could maybe give actionable advice.

[–] red_giant@hexbear.net 1 points 1 month ago* (last edited 1 month ago)

You need to define your threat profile and expectations.

If you want to hide from Google and Facebook advertising, then using a VPN and a privacy-focused browser will get you basically everything you really need.

Likewise, hiding from local law enforcement, buying drugs online or whatever, TOR really gives you what you need. And really a good no-logs VPN is probably already enough.

If you want to hide from the CIA or NSA, then you need to not use the internet.