ranok

joined 1 year ago
MODERATOR OF
[–] ranok@sopuli.xyz 4 points 1 year ago

I pay for Kagi.com for search, I use NextDNS over my personal Tailscale network that blocks all the commercial social networking sites and their CDNs, as well as a ton of ad networks. I use uBlock Origin in firefox to further remove content that may be served 1st party. Opted out of as many analytics services as I can and frozen my credit with all four US credit agencies. I alternate between using a VPS as a Tailscale exit node, or ProtonVPN for country-specific location egress.

[–] ranok@sopuli.xyz 3 points 1 year ago (3 children)

I think it comes down to the threat model that you implicitly or explicitly operate under. Most people don't think about it, and so they equate "more" with better, and VPNs are easily marketed as more, turn it on and rather what whatismyip.com showing a map near your house, now you're magically somewhere else!

If you are paranoid about everything, then again there is the "defense in depth" mindset, which in theory couldn't hurt. That said, having a clear mental model for what you are aiming to be protected from is the best way to find a suitable suite of protections. To agree with a number of others in this thread, ad-blockers (I recommend NextDNS personally) are a great step to stop organizations with a financial incentive to learn all they can about you to sell you stuff, or sell your data. There have been large US ISPs that have experimented with injecting ads or other content either into default DNS responses (e.g., if you mistype something in the search bar it will bring you the ISP's terribad search portal), or even HTTP responses. If you are stuck with one of those ISPs (I'm sorry, and the US monopolies on ISPs are terrible), then a VPN will help you against your threat (the ISP).

If you are an EU resident, and protected by GDPR (or some of the US states that are enacting similar protections), then moving to a more centralized service can be a good thing, since you have a single place to request data deletion, etc., whereas for a non-EU resident, "smearing" your data over multiple non-coordinating entities is a good move to limit the view of you from any single organization.

If you are worried about government surveillance, you have bigger issues. Most people who want to think they are uber valuable to the government are not, and act in counter-productive ways, but co-mingling their data with that of actual baddies, so it all gets revealed in a warrant search. The Lavabit hosting service was used by extreme privacy wonks, and some actual criminals, and when the government went after Snowden, they got all of Lavabit's data, so being on that platform may have been counter-productive for people hiding from the G-men. The OPSEC needed for countering government-level is beyond what you'll learn on a public post, and must be incredibly well-curated and maintained; it will cost you, but if someone will outspend you to get you, then it's table stakes.

view more: ‹ prev next ›