How I’m locking down my cyber-life
Drafted Jan. 4, 2019; updated occasionally since then; most recently updated May 11, 2019
Three problems of computer technology
My 2019 New Year’s resolution (along with getting into shape, of course) is to lock down my cyber-life. This is for three reasons.
First, threats to Internet security of all sorts have evolved beyond the reckoning of most of us, and if you have been paying attention, you wonder what you should really be doing in response. My phone was recently hacked and my Google password reset. The threats can come from criminals, ideological foes and people with a vendetta or a mission (of whatever sort), foreign powers, and—of special concern for some of us—the ubiquitous, massively intrusive ministrations of the tech giants.
Second, the Silicon Valley behemoths have decided to move beyond mere moderation for objectively abusive behavior and shutting down (really obvious) terrorist organizations, to start engaging in viewpoint censorship of conservatives and libertarians. As a free speech libertarian who has lived online for much of my life since 1994, these developments are deeply concerning. The culprits include the so-called FAANG companies (Facebook, Apple, Amazon, Netflix, Google), but to that list we must add YouTube, Twitter, and Microsoft. Many of us have been saying that we must take ourselves out of the hands of these networks—but exactly how to do so is evidently difficult. Still, I’m motivated to try.
A third reason is that the same Big Tech corporations, with perhaps Facebook and Google being the worst offenders, have been selling our privacy. This is not only deeply offensive and something I refuse to participate in, it again puts my and my family’s safety at risk, creating new “attack surfaces” (to use the information security jargon) that corporations must protect on our behalf. They may not do a good job of that. Similarly, governments have taken it upon themselves to monitor us systematically—for our safety, of course. But if you’re like me, this again will make you feel less safe, not more, because we don’t know what bad actors are at work in otherwise decent governments, we don’t know what more corrupt governments might do with the information when we travel abroad, and we don’t know the future shape of our own governments.
At the root of all problems is simply that the fantastic efficiency and simplicity of computer technology has been enabled via our participation in networks (especially cloud networks) and agreement to user agreements offered by massively rich and powerful corporations. Naturally, because what they offer is so valuable and because it is offered at reasonable prices (often, free), they can demand a great deal of information and control in exchange. This dynamic has led to us (most of us) shipping them boatloads of our data. That’s a honeypot for criminals, authoritarians, and marketers, as I’ve explained in more depth.
The only thing we can do about this systematic monitoring and control is to stop letting the tech giants do it to us. That’s why I want to kick them out of my life.
The threats to our information security and privacy undermine some basic principles of the decentralized Internet that blossomed in the 90s and boomed in the 00s. The Establishment has taken over what was once a centerless, mostly privacy-respecting phenomenon of civil society, transforming it into something centralized, invasive, risky, and controlling. What was once the technology of personal autonomy has enabled—as never before—cybercrime, collectivization, mob rule, and censorship.
Perhaps some regulation is order. But I don’t propose to try to lead a political fight. I just want to know what I can do personally to mitigate my own risks. I don’t want to take the easy or even the slightly-difficult route to securing my privacy; I want to be hardcore, if not extreme.
I’m not sure of the complete list of things that I ought to do (I want to re-read Kevin Mitnick’s excellent book The Art of Invisibility for more ideas), but since I started working on this privacy-protection project in January of 2019, I have collected many ideas and acted on almost all of them as of the current edition. I will examine some of these in more depth (in other blog posts, perhaps) before I take action, but others I have already implemented.
- Stop using Google Search. (Done; needs more research though.) I understand that sometimes, getting the right answer requires that you use Google, because it does, generally, give the best search results. But I get surprisingly good results from DuckDuckGo (DDG), which I’ve been using for quite a while now. Like Brave and unlike Google, DDG doesn’t track you and respects your privacy. You’re not the product. It is easy to go to your browser’s Settings page and switch. Here’s a trick I’ve learned, for when DDG’s results are disappointing (maybe 10% of the time for me): I use another private search StartPage (formerly Ixquick), which reportedly is based on Google search results, but I see differences on some searches, so it’s not just a private front end for Google. You might prefer StartPage over DDG, but on balance I still prefer DDG. Still, I should research the differences some more, perhaps.
- Start using (better) password management software. Don’t let your browser store your passwords. And never use another social login again. (Done.) You need to practice good “password hygiene.” If you’re one of those people who uses the same password for everything, especially if it’s a simple password, you’re a fool and you need to stop. But if you’re going to maintain a zillion different strong passwords for a zillion different sites, how? Password management software. For many years I used the free, open source KeePass, which is secure and it works, but it doesn’t integrate well with browsers, or let me save my password date securely in the cloud (or maybe better, on the blockchain). So I’m got a better password manager and set it up on all my devices. I switched to EnPass. This is essential to locking down my cyber-life. Along these lines, there are a couple of other things you should do, and which I did: set my browsers to stop tracking my passwords, and never let them save another one of my passwords. (But be aware that your ability to log in to a site is more secure if a site ue a cookie, called a token, to do so; that doesn’t include a plain-text stored password. When a website asks me if I want to log in automatically, with checkbox in the login form, I say yes; but when a browser asks if I want it to remember my password, the answer is always no. Finally, one of the ways Facebook, LinkedIn, et al. insinuate themselves into our cyber-lives is by giving us an easy way to log in to other sites. But that makes it easier for them to track us everywhere. Well, if you install a decent password manager, then you don’t have to depend on social login services (based on the OAuth standard). Just skip them and use the omnipresent “log in with email” option every time. (I haven’t encountered a website that absolutely requires social media logins yet.) Your password manager will make it about as easy to log in as social media services did.
- Stop using gmail. (Done.) This was harder, and figuring out and executing the logistics of it was a chore—it involved changing all the accounts, especially the important accounts, that use my gmail address. I had wanted to do this for a while, but the sheer number of hours it was going to take to make the necessary changes was daunting (and I was right: it did take a quite a few hours altogether). But I was totally committed to taking this step, so I did. Another reason is that I figured that I could get a single email address for the rest of my life. So my new email address resides at sanger.io, a domain (with personalized email addresses) that my family will be able to use potentially for generations to come. Here’s how I chose an email hosting service to replace Gmail. And here’s how I set up private email hosting for my family.
- Stop using iCloud to sync your iPhone data with your desktop and laptop data; replace it with wi-fi sync. (Done.) If you must use a smartphone, and if (like mine) it’s an iPhone, then at least stop putting all your precious data on Apple servers, i.e., on iCloud. It’s very easy to get started. After you do that, you can go tell iTunes to sync your contacts, calendars, and other information via wi-fi; here’s how. And I’m sorry to break it to you, but Apple really ain’t all that. By the way, a few months after writing the above, I looked more carefully at the settings area of my iPhone for data stored in iCloud; it turns out I had to delete each category of data one at a time, and I hadn’t done that yet. They don’t make it easy to turn off completely, but I think I have now.
- Subscribe to a VPN. (Done.) This sounds highly difficult and technical on first glance, maybe, but in fact it’s one of the easiest things you can do. I set mine up in minutes; the thing that took a few hours was researching which one to get. But why a VPN? Well, websites can still get quite a bit of info about you from your IP address and your ISP (or governments that request the data) can listen in on any data that happens to be unencrypted via your web connection. VPNs solve those problems by making your connection to the Internet anonymous. One problem with VPNs is that they slightly slow down your Internet connection; in my experience so far, it’s rarely enough to make a diference. They also add a little new complexity to your life, and it is possible that the VPN companies are misrepresenting what they do with your data (some of the claims of some VPNs have been tested, though). But it’s a great step to take if you’re serious about privacy, if you don’t mind the slight hit to your connection speed. A nice fallback is the built-in private windows in Brave that are run on the Tor network, which operates on a somewhat similar principle to VPNs.
- Get identity theft protection. (Done.) After my phone was hacked, I finally did something I’ve been meaning to do for a long time—subscribe to an identity theft protection service. If you don’t know or care about identity theft, that’s probably because you’ve never seen weird charges pop up on your card, or had your card frozen by your bank, or whatever. BTW, LifeLock’s customer service isn’t very good, in my experience, and also according to the FTC. There are others.
- Switch to Linux. (Done.) I used a Linux (Ubuntu) virtual machine for programming for a while. Linux is stable and usable for most purposes. It still has very minor usability issues for beginners. If you’re up to speed, in which case, it’s simply better than Windows or Mac, period, in almost every way. On balance the “beginner” issues aren’t nearly as severe as those associated with using products by Microsoft and Apple. I’ve put Ubuntu on a partition on my workstation, and switched to that as my main work environment. I also gave away my Mac laptop and got a new laptop, on which I did a clean install, also of Ubuntu. Linux is generally more secure, gives the user more control, and most importantly does not have a giant multinational corporation behind it that wants to take and sell your information. Read more about how I switched to Ubuntu on my desktop and also my laptop.
- Quit social media, or at least nail down a sensible social media use policy. (Done.) I’m extremely ambivalent about my ongoing use of social media. I took a break for over a month (which was nice), but I decided that it is too important for my career to be plugged in to the most common networks. If I’m going to use them, I feel like I need to create a set of rules for myself to follow—so I don’t get sucked back in. I also want to reconsider how I might use alternative social networks, like Gab (which has problems), and social media tools that make it easy both to post and to keep an easily-accessible archive of my posts. One of my biggest problems with all social media networks is that they make it extremely difficult to download and control your own friggin’ data—how dare they. Well, there are tools to take care of that… Anyway, you can read more about how I settled on a social media use policy.
- Stop using public cloud storage. (Done.) “Now,” you’re going to tell me, “you’re getting unreasonable. This is out of hand. Not back up to Dropbox, iCloud, Google Drive, Box, or OneDrive? Not have the convenience of having the same files on all my machines equally available? Are you crazy?” I’m not crazy. You might not realize what is now possible without the big “public cloud” services. If you’re serious about this privacy stuff and you really don’t trust Big Tech anymore—I sure don’t—then yeah. This is necessary too. One option is Resilio Sync, moving files between your devices via deeply encrypted networks (via a modified version of the BitTorrent protocol), with the files never landing anywhere but on your devices. Another option is to use a NAS (network attached storage device), which is basically your very own always-on cloud server that only you can access, but you can access it from anywhere via an encrypted Internet connection. There are also open source Dropbox competitors that do use the cloud (the term to search for is “zero-knowledge encryption“), but which are arguably more secure; at any rate, you’re in control of them. Yet another option is to run a cloud server from your desktop (if it’s always on), using something like NextCloud. At first, I decided to go with Resilio Sync. Then I changed my mind, because it was a pain to be able to sync only when both devices are on, so I took the plunge and got a NAS after all. It took quite a while both to deliberate on what type of solution to go with (after Resilio), and to choose a specific NAS. It took quite a few hours altogether, but it turns out to be so useful. If you want to consider this more, check out my explanation of why they’re such a good idea.
- Nail down a backup plan. (Done.) If you’re going to avoid using so much centralized and cloud software, you’ve got to think not just about security but about backing up your data. I used to use a monster of a backup drive, but I wasn’t even doing regularly-scheduled backups. In the end what I did was, again, to install a NAS. This provides storage space, making a complete backup of everything on my desktop (and a subset of files I put on laptop) and on the other computers in the house (that need backing up; perhaps not all of them do). It also keeps files instantly backed up a la Dropbox (see next item). But even this isn’t good enough. If you really want protection against fire and theft, you must have an off-site backup. For that, I decided to bite the bullet and go with a relatively simple zero-knowledge encryption service, iDrive, that works nicely with my NAS system. It simply backs up the whole NAS. It bothers me that their software isn’t open source (so I have to trust them that the code really does use zero-knowledge encryption), but I’m not sure what other reasonable solution I have, if I want off-site backup.
- Take control of my contact and friend lists. (Partly done.) I’ve been giving Google, Apple, and Microsoft too much authority to manage my contacts for me, and I’ve shared my Facebook and other friends lists too much. I’m not sure I want these contacts knowing my contacts and friends, period; the convenience and value I got out of sharing those lists was of very limited value to me, but evidently of great value to Big Tech. I don’t know what they’re doing with the information, or who they’re sharing it with, really. Besides, if my friends play fast and loose with privacy settings, my privacy can suffer—and vice-versa. So I am now maintaining my own contacts, thanks very much, and I have fully deleted the lists I gave to Google, Microsoft, and Apple (on iCloud). One problem this does leave you with, mind you, is that you can completely lose all your contacts if they’re only on your own devices, and you’re not syncing them anywhere. So you’d better back up your contacts, if you follow my need. Ideally, the next step I’d need to do is to start using my NAS’ built-in contacts server, which makes it possible to sync contact info across your devices using your own personal server.
- Stop using Google Calendar. (Done.) I just don’t trust Google with this information, and frankly, Gcal isn’t all that. I mean, it’s OK. But they are clearly reading your calendar (using software, that is; that means the calendar data isn’t encrypted on their servers, as it should be). So after I got my own NAS server, I was able to install a calendar server that could be accessed and synced from all of my devices. I had to transfer my data from Gcal to the server, which wasn’t very hard. The hardest part was that I had to teach a colleague how to make appointments for me using the new system. Here are my notes on how I made the change to interfacing with my own NAS’s calendar info via a protocol called CalDAV.
- Study and make use of website/service/device privacy options. (Done semi-regularly.) Google, Apple, Facebook, Twitter, YouTube, etc., all have privacy policies and options available to the user. It is time to study and regularly review them, and put shields up to maximum. Of course, it’s better if I can switch to services that don’t pose privacy threats; that’s generally been my solution, but I have looked at quite a few privacy options and read privacy policies in order to do my due diligence about how my information is being used.
- Also study the privacy of other categories of data. Banking data, health data, travel data (via Google, Apple, Uber, Yelp, etc.), shopping data (Amazon, etc.), even automobile (onboard computer/networked) data—it all has unique vulnerabilities that is important to be aware of. I’m not sure I’ve done all I can to lock it down. So I want to do that, even if (as seems very probably) I can’t lock it all down satisfactorily, yet.
- Figure out how to change my passwords regularly, maybe. (Not started.) I might want to make a list of all my important passwords and change them quarterly everywhere, as a sort of cyber-hygiene. Why don’t we make a practice of this? Because it’s a pain in the ass and most people don’t know how to use password management software, that’s why. Besides, security experts actually discourage regular password changing, but that’s mainly because most people are bad at making and tracking secure passwords. Well, if you use password managers, that part isn’t so hard. But it’s also because we really don’t have a realistic plan to do it; maybe the main thing to do is to regularly change a few important passwords every so often, not all of them. I’ll figure that out.
- Consider using PGP, the old encryption protocol (or an updated version, like GNU Privacy Guard) with work colleagues and family who are into it. (Not started.) Think about this: when your email makes the transit from your device to its recipient’s device, it passes through quite a few other machines. Hackers have ways of viewing your mail at different points on its journey. Theoretically, they could even change it, and you (and its recipient) would be none the wiser. Now, don’t freak out, and don’t get me wrong; I’m not saying email (assuming the servers in between you and your recipients use the standard TLS, or Transport Layer Security, protocol) isn’t perfectly useful for everyday purposes. But if you’re doing anything reallyimportant and sensitive, either don’t use email or use a higher encryption standard, because basic email is insecure. Now, I’m aware that some think PGP is outmoded or too complex (that’s why I never got into it, to be honest), but the general idea of encrypting your email more strongly isn’t going out of style, and improvements on the PGP protocol are still actively maintained. Still, when information security might matter quite a bit, then it might be easier to do what I’m doing now with my boys: using a chat tool with end-to-end encryption built in.
- Moar privacy thangs. Look into various other things one can do to lock down privacy. Consider the new Purism Librem 5 phone, or some other privacy-friendly phone. Look into a physical security key for laptop and desktop. Encrypt my hard drives. Encrypt the drives on the NAS. Etc., etc.
What have I left out?
Are you going to join me in this push toward greater privacy and autonomy? Let me know—or, of course, you can keep it to yourself.