Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

[recommended] safety prioritized


Note

tries to protect against as many threats as possible while remaining usable

for vulnerable people (& their allies) who need to protect themselves

this checklist seeks to maximize safety on the software & hardware side
to truly prioritize safety, more learning and behavioral changes are needed


what we are avoiding:

using services where you are the product
this is not limited to free services, but they are often free
think google, meta, microsoft, and other similar companies
stop letting mega corps know and sell /everything/ about you

your isp is big brother’s best friend
stop your internet service provider from snooping
a vpn is great, but owning your own hardware is important too
without protection, your isp likely tracks every web domain you visit

your proprietary os is also big brother’s friend
microsoft, especially, is not to be trusted
if you need convincing, read [this][]
linux isn’t perfectly safe, but drastically more so than microsoft
openbsd and qubes os are much more secure options but decrease usability

android is deeply insecure
you can read more about this [here][], if you are curious
thankfully graphene os is easy to install
switching will make you much more safe vs both targeted & passive attacks

increase your protection from targeted attacks and supply chain attacks
own your hardware, use local encryption, & zero knowledge & e2ee services
apply security patches quickly & take effort to reduce your attack surface


use a dedicated email & device(s) for work use:

unless truly necessary, only use personal accounts on personal devices and only use work accounts on work devices.

only use linkedin, facebook, instagram, google docs, outlook, etc. for work - if at all possible only use them on work only devices. if that truly isn’t possible, create a virtual machine to run work accounts and software inside)


use privacy focused services for your personal use:

switch away from:----------------------------------------
outlook or gmailwith mailbox.org & thunderbird
existing cloud storageexisting cloud storage + cryptomator
onedrive docs or google docswith cryptpad
outlook or google calendarwith mailbox.org & thunderbird
androidto graphene os
windowsto linux
sms textto molly (hardened fork of signal)
google maps or apple mapsto organic maps
google chrome (on pc)to librewolf for default browsing
to mullvad browser for secure browsing
googleto startpage (or duckduckgo)
proprietary 2fa appsto aegis authenticator
redditto lemmy
twitterto mastodon
youtubeto freetube
grammarlyto harper (avoid the browser extension)
microsoft officeto libreoffice

 

start using:-------------------------
password managerkeepassxc or vaultwarden
vpn paid w/ monero via local wallet or cashmullvad vpn w/ anon pay
desktop calls, messaging, and screensharingmatrix
javascript blocker extensionnoscript
adblock extensionublock origin
password managerbitwarden
vpn check extensionmullvad
internet hardwareyour own hardware

 

stop using:--------------------------------------------------
meta servicesfacebook, instagram, whatsapp, etc.
google servicesdocs & photos, waze, gboard, 2fa, etc.
microsoft servicesonedrive (without cryptomator), etc.
hostile serviceslinkedin, etc.

action item checklist:

get the following tools or services & follow the associated instructions instructions and additional info can be found for each of these tools or services in the ‘recommendations’ section of this wiki

if you use an android phone:

  • graphene os
  • f-droid
  • molly
  • aegis authenticator
  • organic maps

use a non-proprietary operating system:

  • switch to linux or another foss os
    • i would recommend arch, cachyos (easy install arch), or debian
    • depending on your threat model consider openbsd, tails, or qubesos
    • consider using raid for your non-game, non-os local files if possible

own your own hardware:

  • router (pick one that can run open-source firmware)
  • modem (pick one that your isp supports for your connection type)

for your main device:

  • keepassxc (non-softlocking backup) or vaultwarden (self-hosted)
    • ensure your vault backup isn’t behind a password you need keepassxc for
      • (it should be behind a v good password - just one you /know/ you know)
  • mullvad vpn
    • also add to your phone
  • libreoffice
  • librewolf
    • noscript extension
    • ublock origin extension
    • bitwarden extension
    • mullvad extension
  • mullvad browser
    • noscript extension
    • ublock origin extension
    • bitwarden extension
    • mullvad extension

virtual machines:

  • work software and accounts
  • especially risky websites & files
  • proprietary software
  • software development

minimize attack surface:

  • install and run any software possible in virtual machines
  • keep browser extensions to an absolute minimum
  • do software development in virtual machines
    • package managers like npm, pip, and cargo are /major/ attack surfaces
  • avoid smart tvs - tvs without microphones and internet are available
  • for more security run as much software in virtual machines as possible
    • where this isn’t possible (like gaming on steam) try dual booting
      • one os for just gaming (still avoid windows)
      • one os for everything else (using vms for as much as possible)
        • encrypted drive for this one so the other can’t see into it

main services:

  • mailbox.org
  • thunderbird
  • cryptpad
  • matrix
  • cryptomator + most cheap, fast, & reliable cloud storage you can find

other services:

  • lemmy (if you currently use reddit)
  • mastodon (if you currently use twitter or bluesky)
  • freetube (if you currently use youtube)
  • harper (if you are already using grammarly)

backup your most important files:

  • one online backup (using cryptomator)
  • two local backups
    • use two usbs or two external drives
    • alternate - do a backup to the drive with the older copy weekly
    • each should be disconnected when you aren’t actively backing up to it
    • this arrangement protects your most important files from ransomware
    • other arrangements exist are both ransomware safe & automatable
      • you could look into using zfs or btrfs or other options

delete (or only use for work on work devices):

  • google chrome
  • reddit
  • twitter
  • google calendar
  • outlook
  • facebook
  • instagram
  • whatsapp
  • google docs
  • google photos
  • google maps or apple maps
  • waze
  • google authenticator
  • linkedin
  • unprotected cloud storage (not using cryptomator)
    • google drive
    • onedrive
    • dropbox
  • any other proprietary services