21
submitted 3 days ago by ProtozoanDusk@lemm.ee to c/privacy@lemmy.ml

I was thinking about personal data security and let my mind wander. I decided that if you were exceptionally paranoid then........

When thinking about personal data it may occur to you that, once you have implemented an adequate 3 stage backup system to avoid data loss, your main risk is the exfiltration and use of that data for nefarious purposes.

Personal data, e.g. the pictures or messages on your phone or pc, can imply many different things such as religion, sexual orientation, health details, political views etc. that could potentially be used against you by a bad actor.

As such, it would seem rather inadvisable to hold any data on any device that is not encrypted in a fashion whereby only you hold the encryption key.

Further, if you are going online using the device then, even if the device has a trusted os that implements full disk encryption, then it would also seem inadvisable to hold any data on the device that isn't seperately encrypted within the operating system. The data would be protected before first unlock by the os encryption and after first unlock by the seperate encryption.

As the password for this seperate encryption would neccessarily need to be complex you would be best storing this within a trusted password manager that employs zero-knowledge encryption or even better one that does not employ cloud-based syncing. You would also probably want to pepper the password with memorised additional digits.

You might then consider that, as encrypted data, while not especially useful now, may be seen as potentially more valuable should it be exfiltrated and stored for future decryption once technology allows, it may not be the best idea to store this encrypted personal data on any device that connects to the internet or even in a zero knowledge encrypted cloud-based storage solution.

You would then presumably decide that it is best to carry all the data you may wish to access at short notice encrypted on a portable simple data storage device that you could connect to any devices you wish to access the data on. You make the assumption that whoever mugs/holds you up/pickpockets and takes the data device is less likely to hold onto the encrypted data than an online attacker.

It is possible that you would then adjust your 3 stage backup system to be based on 3 non-internet-connected simple data storage devices kept in 3 seperate locations, one of which you carry around with you.

It was at this point that I decided to stop thinking about it. Lol. As noted, this train of thought would probably only occur if you were exceptionally paranoid and it could be theorised that at that point it is debateable whether you are more at danger from data exfiltration and exploitation or the very angry rabbits that want to know why you are so far down the rabbit hole. Lol.

you are viewing a single comment's thread
view the rest of the comments
[-] sudoer777@lemmy.ml 5 points 2 days ago* (last edited 2 days ago)

The most important part is balancing your own safety with limited time and resources. Perfection is not achievable, getting as close as you can is not practical in most cases, and prioritizing safety a lot of times limits what you're able to do. So you need to do a cost/benefit analysis on these sort of solutions and decide whether they're worth doing, which is very contextual (and in the end, you're going to need to trust something somewhere unless you reinvent everything on your own).

For instance, in the US if you're a middle class cishet white male citizen who ignores politics, you're biggest problem is probably ads, companies knowing your financial info, and tools being more locked down, so the reasonable response would be to use an ad blocker and switch to open source/self-hosted software when it's convenient, but not to the point where you have to program all sorts of things yourself unless you really enjoy that. If you're working class, time and finances is more limited so the extent to which self-hosting, paid services, and CLI tooling becomes impractical might be sooner. If you're a minority, there's not really much that can be done that doesn't severely affect quality of life (like living in the middle of the woods with no technology if you know you're being hunted by the government, which sounds fucking terrible but probably better than being sent to a concentration camp in a remote country). If you're an activist or an immigrant or doing something illegal, compartmentalizing data that would probably get you in trouble onto devices (that you can afford) with a strong security setup that doesn't touch anything else you own and doesn't cross borders while verifying that the people you communicate with are also on a similar setup and doing other "paranoid" security/privacy measures (while being careful not to draw suspicions) is probably a good idea. If you're trying to be private for the sake of advocating for privacy, then do what you want to do.

this post was submitted on 30 Mar 2025
21 points (100.0% liked)

Privacy

36417 readers
728 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS