lol
- Use a VPN
- Limit personal identifying content that can be cross referenced. Example: I just got a plane ticket on Sunday to go to Bora Bora.
- Never post self identifying material. Example: here's my new tattoo!
- If you post something time related that can lead to 2 or 3, change details. Basically, lie. Example: last week I went to Bora Bora. Really it was Fiji 3 months ago.
- Don't give them a reason to want to investigate you. There's plenty of Left leaning folk (some of whom probably are pretty far up in corporate and/or government spaces) who quite frankly aren't worth going after. The time and energy it would take to round up people who just think differently, the opposition doesn't have (most likely).
- Change your profile on the reg. Personally I don't do this, or do I? (SEE #4)
- Go periods of time without posting. The more you post, the more you will likely have a signature in the way you post, what you post about, and who you interact with.
- Delete posts (not sure how effective this is but if I feel like my posts are rearing too close to #2 or #3 I'll go back and delete them).
Anyhow I just booked my trip to Uzbekistan via cruise liner where I intend on instigating the revolution by introducing vegan pilaf. During this time I will only post Kelly emoji to convey my progress. o7 o7 o7
Electronic Frontier Foundation has a good collection of articles and guides that are not just practical but teach you how to think about your own particular situation: Surveillance Self-Defense
First thing is you need to think about your "threat model". Which means what information are you trying to protect, and why? There is no universally "best" way to do anything. Tactics that might increase security/privacy in one situation might impair it in another. Like if you are trying to avoid getting doxxed by random internet people who take a dislike to you that's one thing, but if you are trying to avoid government (which government(s)?) spying that's another. If you are trying to avoid government spying, is it to avoid legal prosecution, or to avoid covert interference in your organizing (ala COINTELPRO)? They can be totally different kinds of surveillance so you need to have different strategies to avoid them.
Also need to consider that making an extremely elaborate or onerous plan that you will never bother to actually enact, or requires a high degree of technical skill or perfect execution might not be practical. They might interfere with your purpose too much.
This page covers the basics of how to think about your own goals, fears and priorities. It's very generic but is a good overview. It's really key to think about this ongoing to avoid falling into the trap of following advise that might be perfectly reasonable for another person but counter productive for yourself.
My biggest opsec is just deleting 90% of my post before I actually post them.
I have done that, but honestly hexbear is the one I've done the least with
Afaik the implementation of Lemmy this is a real problem due to federation to other instances, you can post things here that end up somewhere you don't want them to and if you delete them it's not certain if they will also be deleted there as well. It's been stated for a long time but it's one or the other really, you can't have a decentralized social media without federation, and you can't have full privacy with federation. I might very likely be wrong about the specifics of this, but this should be also taken in account when considering to post something more personal.
This is correct. Anyone can implement the activity pub specification (what Lemmy uses for federation) without implementing the delete parts. Sending delete to a federated site is nothing more than a "pretty please remove this"
Edit: to be fair, anything put publicly on the internet can be downloaded and saved forever, its just that activity pub also pushes (compared to normally where things are only stored on one entity's servers) stuff out to who knows which servers
In addition to this (and because of the inevitably of just flat being honest when posting) I have a tendency to 1.) add deliberate misinformation occasionally to poison the info (like saying I grew up on the west side of Philly, just spending most of my childhood days shooting basketball with the boys), and 2.) burn accounts after enough time has passed. My current one is long overdue for that treatment.
My pets are the cutest but my op sec game is too strong
Prove it
That's pretty much my reason for never posting any of my overwhelmingly cute animals. Plus if I was in their position I wouldn't want them posting my pictures online, no matter how cute I look.
There's definitely value in spiking your posts with false data to obscure who you are and where you live. Lie about where you live or travel to, what car you drive or where you work/have worked. If you think you've revealed a bit too much about yourself, burn your account and make a new one, or better yet, gradually move from one account to another so it's harder for people to track you to your new acct. Blur out backgrounds in photos you share that may have things like licence plates on cars, shop names or street signs. Think critically about how a drip feed of PII (personally identifiable information) may not be enough to pin you as one individual, but enough yo narrow it to, say, 100 or so who may go to a certain bar or venue, or live on a certain street. A sufficiently motivated chud may think that those odds are good enough to shift from online to offline work and potential harrassment.
For example, I once was a roadie for Pink Floyd, I drive a maserati and live at Mawson base in Antarctica where I research the interactions of penguin guano on endemic moss populations.
I've never heard anyone outside aad talk about the fucking moss lol
Yeh it's its own whole thing. We also have to be careful about our other excreta impacting local microbiota. With warming on the continent even the hormones from our thawing peepee can leech and throw stuff out of whack.
Also my Maserati is purple
Does your Maserati do 185?
Hoo wee you bet it does 185 kph. I've only ever driven it at legal and appropriate speeds, though
I’m just a straight man living it big in New Mexico. I HATE weed not a fan of that at all. Love to go out with the boys and hunt some feral hogs such is life in texas
I am a 52 year old white man living in New Hampshire, working on growing my general contracting business and writing letters to the J6 patriots
I used to delete all my comments on occassion. Nowadays I just add false information about my self at times
Actually I'm an ancap at heart, I work as a fintech consultant in a think tank and I believe the government should just let businessmen do business. Come at me
That’s crazy I work there too!
Wait a sec…..
Is that you Charlie?????? I’m frank we used to huff paint behind the Home Depot before work
No, I'm Charlie and damn I miss those days. I believe @iByteABit is Jeff in accounting.
This is the way.
Am I 20? Am I 40? Do I live in NYC or Arkansas? Who's to say?
I'm posting from loch ness
You MONSTER
I throw in a few lies here and there to keep em guessing.
Roleplaying as an argie fredo is fun sometimes
This is also my strategy, it's good to always be practicing such an important survival skill.
Good post and should be stickied.
The culture generally leans towards anonymity but there's some leeway for how much you personally.fond necessary. I've got a record, anything I post here really doesnt matter, it's posting consistent with my arrest record. But I still try to.be vague and keep a general culture of relative anonymity going on. I've described my tattoos but I'd never post a picture of them, I'll post pics of the inside of my house but not my house. If you go through my lists it's pretty easy to tell.ehat city I live in but I've never explicitly said so. I'd say probably my piss poor level of personal security is thr bare minimum and I'm a bit internationally sloppy cause if feds are looking me up.its gonna get a we'll established file and it's a waste of their time. Others, maybe not so much. Just be cautious, there's people out here to whom jail is less of a big deal. Be a cautious cat as standard practice.
I know I'm bad about it. I delete my account every couple of months but I bet a dedicated person could track me down based on my posts.
Though I'll say that in the real world I've gotten more guff for not having a mainstream social media account than for openly expressing my communist views. Even lost a job offer over it once (though I consider that a bullet dodged) because I had shared with them my linkdin acct that only has my resume and they wanted to check a Facebook acct that I've never had.
My OpSec has been lacking recently across all social media. I need to set up a new internet identity entirely but I'm too lazy for that.
For voicing your opinion about activism,
I'd recommend to at least use:
- A burner account,
do not post your opinion through your daily account. - A paid, no-log VPN or Tor when posting.
Above should cover the needs of most people.
But if you think you're a high profile target,
then following would also be smart:
- Alter you writing,
do not post in similar writing as your main account, e.g. if you usually capitalize each sentence, don't, if you usually use emoji's, don't etc etc. - Use a privacy oriented OS to post on,
e.g. no Windows, no Apple, no closed source Android fork, but do use QubesOS, or TailsOS, or GrapheneOS. - Only use chat clients with E2EE (End to End Encryption) and without identifiers, e.g. SimpleX.
Remember. We all live in Liberal Mt.
I've been doxxed
Not me, I'm the One True Communist™
Jokes on you, I live on Mount Wank, Germany!
I'm a strong advocate of regular account restarts. I've probably been through 20 since the site opened, due a new one now really.
I don't think there are any rules, just recommendations. If a person is already publicly known, it probably doesn't matter if they keep being open about it here.
4 years and counting.
The thing i personally think people should be focused on is compartmentalizing their internet activity. Cross-site tracking is pretty much everywhere these days. So if you have a twitter, instagram, lemmy, reddit, pintrest, whatever it is you do online. If you do not want your activity on lemmy to be linked back to those accounts you should be using a different browser for lemmy, preferably something like Librewolf. Privacy focused. If your really feeling paranoid go ahead and use TOR browser to login to lemmy. Assuming they dont block TOR connections here I've never tried.
Burning your accounts not a bad idea either. Back when i used reddit id make new accounts regularly and never use the old ones again. With lemmy i dont bother tho. Even if you make a new account regularly on a site as small as this its pretty easy to see if an account showed up around the time your old one went inactive and then followed all the same communities your old one did. Not a big assumption that is your new one then. the way you type, and words you use can also be fingerprinted and used to ID you across accounts. Of course you can take steps to prevent this type of tracking too if you want.
If what you want tho is to not get some chud sending you death threats thats pretty easy to accomplish. Make yourself a new account, dont post any personal photos, and only give very vague information about yourself. For example, How old are you? I'm in my 30s, 20s, etc. Dont say the exact number. Whats your name? Its Xiisadaddy as far as your concerned. Whats your gender? Irrelevant need to know only. Chuds arent that smart. They can only find you if you hand it to them on a silver platter.
Now let me see if i can find out some info about you from this account: Based on your profile just a quick glance tells me, your a woman, live in australia, seems like maybe you or someone you know was in the military, you live in an area with public transport that isnt good, a food desert, your landlord has a meth test cause in your lease, probably live in an apartment building, you have a niece, and siblings, and are autistic. I'm guessing late 20s, early 30s? Took me maybe 10mins to get all that. Don't feel like putting in more effort, but yeah id say you need a new account. Thats some pretty specific stuff an internet stranger just found out about you in 10 minutes. (reply to this and let me know if you want me to delete this comment btw so its gone too if you decide to get rid of your account)
Funnily enough ive been considering making a new one too this might be what pushes me to do it.
Even if you make a new account regularly on a site as small as this its pretty easy to see if an account showed up around the time your old one went inactive and then followed all the same communities your old one did.
Fortuntely, I only follow the defaults and the last time I burned my account Hexbear closed down new accounts for three days >.>
I think my main cross-account doxxing would come from artwork I personally have been created and I think both communities would enjoy. Reverse image search would out me pretty fast, especially if the post gets no traction (if a post goes viral, then its more likely it would be posted by a rando).
(I think being on hexbear and autistic doesn't actually change anything)
Hexbear + Autistic is pretty much just Hexbear
I think your overall answer on the social side of it was good. Compartmentalizing etc is a good way to think of it. But I feel compelled to challenge any specific technical advise. In general because it's impossible to give advice like this without knowing more details about the recipient. There are ways it could easily backfire by someone just blindly following it.
If you do not want your activity on lemmy to be linked back to those accounts you should be using a different browser for lemmy, preferably something like Librewolf. Privacy focused.
This plan doesn't really make any sense. The idea of breaking things up by browser doesn't scale like hardly at all. You can only have so many browsers installed on your computer. And they tend to be extremely resource-intensive so you can't be running many instances. A more reasonable way obtaining every benefit possible from this concept would be the use of profiles.
Even ignoring all that, I am still skeptical. Basically the benefit of the dedicated browser/profile concept is that it somewhat compartmentalizes system data which is exchanged with the remote host, ya? Is hexbear.net sharing a lot of cookies with gmail or facebook or cnn or whatever other websites you are going to? Does it make sense to pick 1 special website that will get the special secure treatment while all other browsing is done in.... an insecure environment? Are you opening external links in this special browser or are you copy/pasting them into your general purpose browser? And what about the large amount of fingerprinting that would remain consistent between browsers/profiles, such as IP address and other network infos, system environment, browser settings, session times etc? It doesn't really have much of a hope to accomplish the goal of keeping the accounts discreet.
It also doesn't consider use of mobile devices, apps etc.
Overall this kind of strategy could only even possibly be appropriate if you are considering a very specific adversary, namely one who has insider access to server logs, network traffic etc, of other computers you interact with on the internet. I guess multiple different remote systems in order to triangulate the information. So the owners/operators of servers, or someone who is able to obtain access (like by hacking or a warrant). If you have such an enemy this would hardly be sufficient and it'd be better advice to go straight to TOR. On the other hand, OP seems specifically concerned with "pervy men" who almost certainly do not have such access. It would be better to focus on the social compartmentalization to avoid divulging so much information that some creep can easily compile a dossier on you and track you down.
Setting and maintaining boundaries like that is not easy especially in a comradely social situation. I would avoid adding a bunch of dubiously-useful technically complexities. On the other hand it could possibly help to self-enforce. I like to use browser profiles to segregate off certain tasks. Like I have one for school work. It has a different color theme than my usual one and it reminds me not to wander off into other stuff getting distracted. I am not logged in to anything fun in that browser and I keep all the bookmarks on topic to school. The session can be opened and closed when I decide to start and stop working. It probably has a very minimal benefit in preventing my school-work online ID from getting mixed up with other online activities but I wouldn't rely on it at all. It's mostly just a mental thing.
chapotraphouse
Banned? DM Wmill to appeal.
No anti-nautilism posts. See: Eco-fascism Primer
Slop posts go in c/slop. Don't post low-hanging fruit here.