← All writing

Technological Privacy Crises

In this article

Going down the rabbit hole

A person holds a phone and gathers a thread of personal data as photographs, an envelope, and a location pin drift toward distant servers.

Let me make a TikTok quickly. Look at this food—I have to post it on Instagram. Everything is backed up automatically to the cloud. Thank you, Google. I will trust you forever.

Convenience makes it easy to stop asking questions. Where does that photograph go? Who can read the message? What does the keyboard app know about me? When I began looking beneath the surface of everyday technology, I found that each layer introduced another relationship of trust.

I used to reject almost any application whose source code I could not inspect. I still prefer open software: it gives people a way to examine what runs on their devices, challenge claims, and build alternatives. But published code is a starting point. Someone still needs to review it, and the application you install needs to correspond to that code.

Privacy, security, and anonymity solve different problems. Privacy concerns who can learn about your life. Security concerns who can access or alter your devices and accounts. Anonymity concerns whether an activity can be connected to your identity. A tool can improve one while leaving the others largely unchanged.

Encryption deserves better questions

End-to-end encryption means content is encrypted on the sender's device and decrypted on the recipient's device, with the service unable to read it in between. Encryption in transit protects the connection to a server; the server may still be able to read the content. Encryption at rest protects stored data, but the important question is who holds the keys.

The client—the software on your device—is therefore critical. Open client code, independent audits, and reproducible builds give us stronger evidence than a phrase like “military-grade encryption.” None of them protects a message after an attacker compromises the device where it is being read.

Governments and companies want data

Edward Snowden's disclosures made large-scale surveillance harder to dismiss. The US Privacy and Civil Liberties Oversight Board's report on Section 702 describes PRISM and upstream collection. It also explains the foreign-intelligence targeting framework and the collection of Americans' communications within it. That is more specific than saying the programme exists simply to collect everything about every citizen.

My concern is still straightforward: a detailed record of someone's life creates power over them. Advertising systems, data breaches, and government demands can expose information collected for an entirely different purpose. We do not need to assume every company has a secret backdoor to ask whether it should hold that information in the first place.

There is concrete evidence of the gap between privacy promises and practice. In July 2019, Facebook agreed to a US Federal Trade Commission settlement with a $5 billion penalty over charges that it had deceived users about control of their personal information and violated an earlier order. The FTC described information reaching third-party apps through users' friends. Your own sharing choices did not necessarily determine where your data ended up.

Hardware is part of the problem

Our operating systems sit on top of firmware and hardware we often cannot fully inspect. Intel's Management Engine, for example, is an embedded controller on some Intel chipsets that runs its own small operating system. Its existence raises questions about transparency and attack surface; it does not establish that every Intel processor contains a government backdoor.

A documented vulnerability makes the concern more tangible. Intel's 2017 advisory INTEL-SA-00075 described a critical privilege-escalation flaw in certain management firmware, including network access on provisioned AMT and ISM systems. Intel explicitly excluded consumer PCs with consumer firmware from that advisory. The lesson is to understand the components and update them, while distinguishing a demonstrated flaw from speculation about a universal backdoor.

Software choices cannot remove every dependency on opaque hardware. They can still reduce the data we hand over voluntarily. That is where I want to begin: with changes that make daily life more private without making it impossible to live.

Desktop operating systems

A hand arranges separate paper workspaces on a laptop screen beside a plant and a sunlit window.

Windows and macOS can be configured to share less information, but both leave substantial parts of the system under their vendors' control. I prefer Linux for the freedom to inspect, replace, and choose more of those parts. That preference should not become a claim that Linux is automatically secure or that every proprietary system is spying on everything.

Start with a live USB to test your hardware. Dual booting can make the transition easier, provided you back up your files and follow the distribution's installation guide. You can learn the new environment while keeping access to software you still need.

  • Linux Mint is my starting point for someone coming from Windows who wants a familiar desktop.
  • openSUSE offers several approaches to desktop and server systems. Commercial SUSE support is a separate offering; openSUSE itself is a community project.
  • Debian suits people who value a conservative stable release. Older application versions do not necessarily mean missing security fixes.
  • Qubes OS is worth studying when compartmentalisation matters. It separates activities into virtual machines, rather than ordinary application containers, and asks more of your hardware and attention.

Choose a supported system you can maintain. Keep security updates, use disk encryption, and install applications from sources you trust. Removing security protections to obtain a supposedly cleaner desktop can leave you worse off.

Mobile systems and apps

Hands lift a paper layer of a phone to reveal separate compartments for a camera, a map, and an envelope.

Phones deserve special attention because they travel with us and hold our conversations, photographs, and location history. Android and iOS both use application sandboxes and permission controls. Neither label alone tells you whether a particular device is a good choice.

Targeted spyware is a real concern. Kaspersky's June 2023 disclosure of Operation Triangulation documented an iOS spyware campaign using iMessage exploits that required no interaction from the recipient. This demonstrates that device-level compromise can undermine the applications you trust. It does not by itself prove the manufacturer's cooperation or identify who was responsible.

For someone who wants a privacy-focused Android system, GrapheneOS is an option I would examine closely. Check its current supported-device list before buying a phone. Its sandboxed Google Play lets compatible apps use Google services without giving those services the special privileges they normally have on Android.

This is a concrete reduction in privileges, rather than a promise that Google's code has vanished. GrapheneOS also documents relocking the bootloader after installation to restore full verified boot. That detail matters: more control over the software should preserve the checks that detect unauthorised changes to it.

LineageOS provides another route to more control on supported devices. A custom system is not automatically a security upgrade: firmware support, timely patches, and verified boot matter. Follow the exact installation instructions for your model rather than a generic flashing tutorial. Root access also expands what a compromised application could do.

You can improve the phone you already own by removing unused apps and reviewing permissions. On Android, these projects are useful places to explore:

  • F-Droid distributes free and open-source applications. Read its anti-feature labels: open source does not guarantee that an app has no tracking, network dependencies, or vulnerabilities.
  • NewPipe offers a separate interface for services such as YouTube, with background playback and downloads. It is not an anonymity service, and changes to those services can interrupt it.
  • Fossify continues the idea of simple, open-source utilities for tasks such as managing contacts, calendars, and photographs. It replaces the old Simple Mobile Tools recommendation in this revision.
  • AdAway can block domains through Android's local VPN interface or, on rooted devices, a hosts file. Its local VPN mode can compete with another VPN app for the same interface, and domain blocking will not catch every advertisement.

Web browsers

An open paper window overlooks a garden while a fine screen catches rust-coloured advertising scraps.

The browser is where much of our daily life meets the internet. It can also become a single archive of our searches, passwords, habits, and accounts. Changing it is one of the more approachable privacy steps.

I have used Brave for years. Its Shields block many ads and trackers without requiring an extension. LibreWolf and Mullvad Browser are alternatives for people who prefer a Firefox-based browser. Mullvad Browser aims to reduce tracking and fingerprinting; it does not route your traffic through Tor or include a VPN connection.

On Firefox, uBlock Origin remains a useful content blocker. Do not assume the same extension works in every Chromium browser: browser extension support has changed since this article first appeared. Use the project's current installation instructions and distinguish the full extension from uBlock Origin Lite.

PrivacyTests.org provides reproducible tests of browser privacy behaviour. Treat its results as evidence about particular settings and features, rather than a complete ranking of security. Keep the browser updated and choose extensions sparingly; each extension is another piece of software you trust with your browsing.

VPNs and Tor

A traveller follows a winding paper path through several separate archways, beside a shorter covered passage.

A VPN changes who can observe your connection. Your internet provider sees a connection to the VPN rather than the same direct destinations, and websites generally see the VPN's address. You have moved part of your trust to the VPN operator. Logging into an account, accepting tracking cookies, or sharing personal information can still identify you.

I would look at Mullvad and its published policies rather than choose a service because a video sponsorship promises complete anonymity. Ownership, independent audits, and the data required to create an account are worth checking. A “no logs” slogan is a claim to evaluate, not a magic property.

For a different approach, Tor Browser uses the Tor network to route browsing through several relays. It is designed to make it harder to connect your address with the sites you visit. It often costs speed, and it protects the browsing done inside it—not every application on your device.

Keep HTTPS in use, avoid adding extensions to Tor Browser, and remember that signing into your usual account identifies you to that service. The choice between a VPN and Tor begins with what you are trying to protect and from whom.

Email providers

Hands fold a letter into a sealed envelope while an open postcard rests on a wooden table.

Email is difficult to make private because a message usually crosses providers and remains in more than one mailbox. A service can protect stored mail without making every outgoing message end-to-end encrypted.

Proton Mail is an alternative I like for its interface and encryption features. Its encryption documentation explains the difference between messages within Proton and messages sent to other providers. Ordinary mail sent to an outside address is not automatically end-to-end encrypted; additional arrangements such as PGP or a password-protected message are needed.

Tuta, formerly Tutanota, is another encrypted-mail option. Disroot offers community-run email, but it should not be confused with automatic end-to-end encryption. Choose according to how you communicate, how you recover an account, and what your correspondents can actually use.

A provider's independence and the ability to export your mail matter as much as its first impression.

Cloud storage

A person stores folders in a cabinet connected to distant cloud shapes, with a spare copy in a separate box.

I enjoy the convenience of files that follow me between devices. I also want a say in where they live and who can read them.

Nextcloud offers file synchronisation, sharing, and collaborative tools on a server you or a chosen provider runs. Self-hosting gives you control over the server, along with responsibility for updates, access controls, and backups. A managed provider may be a better fit if you do not want that work.

Read the Nextcloud encryption documentation before assuming the server cannot read your files. Server-side encryption and end-to-end encryption have different purposes, and collaboration features affect which approach is practical.

If you want to encrypt files before placing them in an existing cloud service, Cryptomator is worth considering. Keep a separate backup and test recovery. Synchronising an accidental deletion across all your devices is still synchronisation; it is not a substitute for a backup.

Photos

A family sorts printed photographs into a personal album while duplicate memories travel through layered paper clouds.

Photographs contain more than images. They can reveal where we were, who we know, and how our lives change. Automatic backups are useful, but an intimate archive deserves more thought than a default setting.

I use Ente Photos because it combines the convenience I want with end-to-end encryption. Its architecture documentation explains that files and associated metadata are encrypted before they leave your device. The software is open source, which gives that design a chance to be examined.

Its March 2023 cryptographic audit, carried out by Cure53 with Symbolic Software, provides more substantial evidence than a privacy slogan. Ente published the report and said that the auditors verified a fix for the high-severity finding: its web app had allowed weak passwords. An audit is useful because it exposes a design to scrutiny and documents problems and responses; its scope and date still matter.

An encrypted service still depends on your devices, recovery information, and sharing choices. Save your recovery key somewhere safe and keep an independent copy of photographs you cannot replace. Check what a shared album or link gives another person access to before sending it.

For me, the aim is to keep the pleasure of revisiting memories while reducing how much of that archive I expose to a provider.

Messaging

Two people exchange folded paper messages through a sheltered passage, with other conversations separated into distant rooms.

The most private messenger is not always the one your friends will agree to use. Convenience matters, but encryption defaults matter too.

Signal is a practical place to start for private conversations. Its documentation explains that messages and calls are always end-to-end encrypted. Verify your contact's safety number when it matters, and consider what notifications, linked devices, and backups reveal.

Telegram needs a clearer distinction than I gave it originally. Its FAQ confirms that ordinary private chats and groups are cloud chats, not end-to-end encrypted conversations. Secret Chats add end-to-end encryption for device-specific, one-to-one conversations. They do not turn Telegram groups into private encrypted rooms.

There are other approaches to explore:

  • SimpleX Chat avoids a permanent user identifier, making different trade-offs in how contacts connect.
  • Session offers messaging without registering a phone number. Check its documentation for the properties of the conversation type you intend to use.
  • Element uses Matrix, with federated servers and support for encrypted conversations. Check the room's encryption and device verification.
  • XMPP is a protocol, not a single application. Privacy depends on the client, server, and encryption mechanism you choose.

No messenger can prevent a recipient from copying what you send, and no encryption design makes an unlocked, compromised phone safe. Choose the tool and the people you share with together.

Social media

Small paper houses share messages along threads in a garden, suggesting a network of independently tended communities.

Facebook, Instagram, and X make it easy to find people and hard to leave. A platform can change its rules, feed, ownership, or business model while your social life remains tied to it. I would rather build connections that give people more choice about where they gather.

Mastodon is one entry into the fediverse: independently operated servers communicating through shared protocols. You can choose a community with rules and moderation that suit you, or operate a server yourself. Distribution changes who controls the space; it does not make everything posted there private.

Nostr takes another approach, using signed events and relays. It is a separate protocol rather than another ActivityPub platform. Its openness is useful, but public posts can be copied and retained by other people. Removing something from one server or relay does not recall every copy.

I no longer want to judge a platform's privacy by promises about “free speech” or a published recommendation algorithm. What matters here is what data it collects, who can access it, whether I can leave, and how much control the people using it retain.

Choose public networks for public conversation. Use a suitable encrypted messenger for things you want to keep between a smaller group of people.

Passwords and two-factor authentication

A person arranges distinct handmade keys beside a small personal notebook and a separate token on a desk.

Unique passwords are one of the most useful changes you can make. If one service loses your password, it should not unlock the rest of your life. A password manager makes that practical without asking you to memorise dozens of secrets.

Bitwarden offers an encrypted vault with synchronisation and open-source clients. Its encryption documentation explains why the provider is not meant to have your plaintext vault. Protect the master password and recovery information carefully.

KeePassDX is an Android option for a KeePass-compatible local database. You decide how to back it up or synchronise it. LessPass takes a different route, deriving passwords from inputs instead of storing each one in a vault. That can be useful, but you must preserve the exact settings and account for password changes; remembering only a master secret may not be enough.

Two-factor authentication adds another layer. Aegis Authenticator on Android and KDE Keysmith on desktop can generate time-based codes. Keep encrypted backups and the service's recovery codes. For accounts that support them, passkeys or hardware security keys can also reduce the risk of signing into a convincing fake website.

Open source does not make a password manager immune to breaches, and a breach does not automatically mean a provider stored every password in plaintext. Look at the design and the incident details. If a separate manager feels like too much today, using your browser's manager for unique passwords is a useful first step.

Finding your own way

A traveller follows stepping stones from a crowded town toward a small workshop and an open landscape.

Finding alternatives takes time. Staying with a familiar service can feel easier than asking friends to move or learning a new system. I do not think the answer is to change everything in one exhausted weekend.

Begin with something that will help now: unique passwords, supported software, fewer unnecessary apps, or a private conversation moved to an encrypted messenger. Make a backup before a bigger change. Give yourself time to see whether the new tool fits your life.

AlternativeTo can help you discover similar applications, but a listing is not a security review. Look for maintained projects, clear documentation, independent scrutiny, and a way to export your data.

The hardware question remains. Projects such as PINE64, Fairphone, and System76 explore different combinations of openness, repairability, and user control. Those are valuable goals, but they are different from a guarantee that every chip or firmware component is open or secure.

I want an ecosystem in which we can understand our tools, repair them, and decide what to share. Every change that reduces unnecessary collection makes that future a little more practical. Privacy grows through the choices we can keep making, and through people helping one another make them.

If this article helped, share it with someone who could use a first step. Your aunt, your grandmother, and perhaps the stranger down the road might appreciate it. Your pets may be harder to convince.

You can also support my independent work. Thank you for reading.

← All writing