[recommended] safety prioritized
Note
tries to protect against as many threats as possible while remaining usable
for vulnerable people (& their allies) who need to protect themselves
this checklist seeks to maximize safety on the software & hardware side
to truly prioritize safety, more learning and behavioral changes are needed
what we are avoiding:
using services where you are the product
this is not limited to free services, but they are often free
think google, meta, microsoft, and other similar companies
stop letting mega corps know and sell /everything/ about you
your isp is big brother’s best friend
stop your internet service provider from snooping
a vpn is great, but owning your own hardware is important too
without protection, your isp likely tracks every web domain you visit
your proprietary os is also big brother’s friend
microsoft, especially, is not to be trusted
if you need convincing, read [this][]
linux isn’t perfectly safe, but drastically more so than microsoft
openbsd and qubes os are much more secure options but decrease usability
android is deeply insecure
you can read more about this [here][], if you are curious
thankfully graphene os is easy to install
switching will make you much more safe vs both targeted & passive attacks
increase your protection from targeted attacks and supply chain attacks
own your hardware, use local encryption, & zero knowledge & e2ee services
apply security patches quickly & take effort to reduce your attack surface
use a dedicated email & device(s) for work use:
unless truly necessary, only use personal accounts on personal devices and only use work accounts on work devices.
only use linkedin, facebook, instagram, google docs, outlook, etc. for work - if at all possible only use them on work only devices. if that truly isn’t possible, create a virtual machine to run work accounts and software inside)
use privacy focused services for your personal use:
| switch away from: | ---------------------------------------- |
|---|---|
| outlook or gmail | with mailbox.org & thunderbird |
| existing cloud storage | existing cloud storage + cryptomator |
| onedrive docs or google docs | with cryptpad |
| outlook or google calendar | with mailbox.org & thunderbird |
| android | to graphene os |
| windows | to linux |
| sms text | to molly (hardened fork of signal) |
| google maps or apple maps | to organic maps |
| google chrome (on pc) | to librewolf for default browsing |
| ⬑ | to mullvad browser for secure browsing |
| to startpage (or duckduckgo) | |
| proprietary 2fa apps | to aegis authenticator |
| to lemmy | |
| to mastodon | |
| youtube | to freetube |
| grammarly | to harper (avoid the browser extension) |
| microsoft office | to libreoffice |
| start using: | ------------------------- |
|---|---|
| password manager | keepassxc or vaultwarden |
| vpn paid w/ monero via local wallet or cash | mullvad vpn w/ anon pay |
| desktop calls, messaging, and screensharing | matrix |
| javascript blocker extension | noscript |
| adblock extension | ublock origin |
| password manager | bitwarden |
| vpn check extension | mullvad |
| internet hardware | your own hardware |
| stop using: | -------------------------------------------------- |
|---|---|
| meta services | facebook, instagram, whatsapp, etc. |
| google services | docs & photos, waze, gboard, 2fa, etc. |
| microsoft services | onedrive (without cryptomator), etc. |
| hostile services | linkedin, etc. |
action item checklist:
get the following tools or services & follow the associated instructions instructions and additional info can be found for each of these tools or services in the ‘recommendations’ section of this wiki
if you use an android phone:
- graphene os
- f-droid
- molly
- aegis authenticator
- organic maps
use a non-proprietary operating system:
- switch to linux or another foss os
- i would recommend arch, cachyos (easy install arch), or debian
- depending on your threat model consider openbsd, tails, or qubesos
- consider using raid for your non-game, non-os local files if possible
own your own hardware:
- router (pick one that can run open-source firmware)
- modem (pick one that your isp supports for your connection type)
for your main device:
- keepassxc (non-softlocking backup) or vaultwarden (self-hosted)
- ensure your vault backup isn’t behind a password you need keepassxc for
- (it should be behind a v good password - just one you /know/ you know)
- ensure your vault backup isn’t behind a password you need keepassxc for
- mullvad vpn
- also add to your phone
- libreoffice
- librewolf
- noscript extension
- ublock origin extension
- bitwarden extension
- mullvad extension
- mullvad browser
- noscript extension
- ublock origin extension
- bitwarden extension
- mullvad extension
virtual machines:
- work software and accounts
- especially risky websites & files
- proprietary software
- software development
minimize attack surface:
- install and run any software possible in virtual machines
- keep browser extensions to an absolute minimum
- do software development in virtual machines
- package managers like npm, pip, and cargo are /major/ attack surfaces
- avoid smart tvs - tvs without microphones and internet are available
- for more security run as much software in virtual machines as possible
- where this isn’t possible (like gaming on steam) try dual booting
- one os for just gaming (still avoid windows)
- one os for everything else (using vms for as much as possible)
- encrypted drive for this one so the other can’t see into it
- where this isn’t possible (like gaming on steam) try dual booting
main services:
- mailbox.org
- thunderbird
- cryptpad
- matrix
- cryptomator + most cheap, fast, & reliable cloud storage you can find
other services:
- lemmy (if you currently use reddit)
- mastodon (if you currently use twitter or bluesky)
- freetube (if you currently use youtube)
- harper (if you are already using grammarly)
backup your most important files:
- one online backup (using cryptomator)
- two local backups
- use two usbs or two external drives
- alternate - do a backup to the drive with the older copy weekly
- each should be disconnected when you aren’t actively backing up to it
- this arrangement protects your most important files from ransomware
- other arrangements exist are both ransomware safe & automatable
- you could look into using zfs or btrfs or other options
delete (or only use for work on work devices):
- google chrome
- google calendar
- outlook
- google docs
- google photos
- google maps or apple maps
- waze
- google authenticator
- unprotected cloud storage (not using cryptomator)
- google drive
- onedrive
- dropbox
- any other proprietary services