So I followed a couple privacy guides recently. The main ones were a post I made asking the community for guidance about privacy and that quick privacy guide from redsails. They were helpful but honestly left me kinda unsatisfied
They just felt like quick start checklists, not really an education. I’m looking for something more thorough and most importantly a way to keep learning long term instead of just a one time setup
Where can I find stuff that goes deeper? Like actual resources and knowledge, not just steps to follow
Also what about the privacy paradox? The more you hide the more you stand out


Another thing to consider: you might do everything right, but your friends won’t. In the end, you have to either completely sever your connections with people who can’t or won’t follow opsec or you allow yourself to be found out because all of your friends still use Discord.
It’s like walking to buy bagels with the same 10 people except the 10 people all hand out business cards with their addresses, some of which include your address, to random people.
There’s that, too.
I’ll put it this way: if you really wanted to be a ghost you’d need to be very deliberately about it for a very specific reason. Let’s say you wanted to run some spokesperson account for a clandestine organization.
Well, you’d need a completely clean device. Maybe an old laptop. Something that preferably has no internal tracking on it, so we are avoiding an android phone here. You’ve disabled the mic and webcam. You’ve installed all the proper security measures that block cookies and tracking data and all that. Nothing about the install contains any identifying information at all. This is where most people stop and think they are covered.
You know of a bunch of open wifi areas around your city. Places you can access without being on CCTV. You connect to one, jump through some obfuscation methods to hide your real IP. You create your email and social media accounts, all having nothing to do with any identifying information at all in regards to you. Now you post ONLY the information about your clandestine group. You never, ever log into any of your real social media accounts from those wifi access points or this device. You never browse on this device or do anything on it that isn’t just to boot it up from a random location, secured connection to make your posts. You never ever access any of those accounts from any insecure device or on any insecure network.
Congrats, you now have a ghost account that you can never ever slip up on or you risk being exposed to the right organizations if they really want to find you. Don’t make a mistake. Technically you only have to slip up one time.
Now ask yourself, is that really going to be you? It’s probably not. Sure, you should practice OPSEC and not tell everyone on the internet who you really are if you are fearful of your safety. Most people don’t need this kind of OPSEC. Most organizations aren’t capable enough to find you even if you made mistakes. So there is a sliding scale.
However, if you are doing your daily browsing and logging into personal accounts no amount of OPSEC is going to protect you. Blocking cookies and “tracking data” and all that is pretty pointless to advertisers and big companies like facebook because there are many techniques they have to track people beyond that stuff and chances are after a very short while, they’ve associated this “ghost” with your real identity in short order because your habits have exposed you.