logoalt Hacker News

suslik • yesterday at 10:07 AM • 16 replies • view on HN

I am at a point where I simply stopped worrying and began to love the bomb. I did my best, I really did - degoogled before it was trendy, dropped all social media, built a homelab for complete data ownership, set up matrix messaging with family, and so on - but it feels like a wasted effort at this point.

All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.

The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.


Replies

shit_game • yesterday at 10:27 AM

>I simply stopped worrying and began to love the bomb

This may apply to the consequences of ones data being subject to so many breaches and leaks and thefts, but it should not be the attitude one adopts towards the idea of ones data being taken and used by so many parties. At some level, my data is my personhood - it is my evidence of myself, and my record of myself, and my proof of myself. It encodes who I talk to, what I'm interested in, where I go, and what I do. My health, my finances, my habits, vices, schedule, family, friends, coworkers, beliefs. People more clever than myself use this data to advertise to me; people more powerful use this data to surveil me. When will people more malevolent use this data to persecute me?

I should not have to love the bomb because the bomb will kill me.

thomassmith65 • yesterday at 12:19 PM

To be zen about one's privacy is easier for some people than others.

There are situations in many a person's life that if revealed to the public would have life-altering consequences.

Rather than the world give up, we should have better tools and laws to flood the internet with spurious personal data.

clickety_clack • yesterday at 4:49 PM

It’s not the current use of the data that’s concerning, it’s its future use. Who’s to say that some facet of your life that is ordinary now will not one day paint you as the target of some future regime? It happened in Europe a few decades ago, and in many other countries around the world.

➕ show 1 reply
ruszki • yesterday at 10:28 AM

Similarly. My browser was carefully containerized, with a ton of anti fingerprinting measures, VPN, Linux, Librewolf, everything. Even on my phone, I restricted whatever possible. Then one day I went to the YouTube main page, and I saw that Google somehow got to know that I played Minecraft again after a decade. I gave up right there. I suffered to avoid this, and it was pointless. I knew at that point already that probably all my PI is public information anyway, but I wanted to restrict whatever possible, and no, everybody sells my data anyway, and it seems that avoiding fingerprinting is impossible without turning off the internet completely, and ditching smart phones.

➕ show 3 replies
hypfer • yesterday at 11:08 AM

These swings can be avoided by not doing stuff so hard but instead more effectively.

For example, matrix sucks ass. It's terrible. Everything about it is a bad experience. Of course you'd want to eventually stop using it and go back to the previous life.

But that is not the correct take-away.

The correct take away is to include UX (and honesty to yourself about it) in the calculation and to not go all in on an unsustainable compromise, just to then snap back to doing the opposite ca 3 months later.

Same as with loosing weight, really. If you replace 100% of the pleasure of eating with the "right" but unpleasant solutions, you will not be able to keep that diet going indefinitely.

➕ show 1 reply
PatronBernard • yesterday at 1:40 PM

This makes me think: how would someone like Mark Zuckerberg handle this for his own internet presence? Or does he sidestep this issue completely by having assistants for nearly everything? I can imagine he doesn't do much more than look at .ppts and fire off emails. Do data brokers have any information at all on this guy?

➕ show 2 replies
gentlerain • yesterday at 10:26 AM

The next frontier is to maintain 'limited privacy'.

That's denying most culprits the opportunity to use the collected data against you.

Like always on VPN, turning off personalization, ad guards and using open source products where possible.

➕ show 2 replies
_the_inflator • yesterday at 11:46 AM

I agree.

And most people on the behavioral side do too, but not at the cognitive level. EU is the best example with EU AI Act, strict data regulation as well as privacy rights, on the other hand demanding that Apple does serve the EU with AI.

I have mainly one distinction: the state is the worst protector of your data and the most ruthless gatherer of all your details.

Opposite to the open sourcing of your data in the end by the state are private companies who live by your data but do this for 20+ years - battle tested protection and hardening against malicious hackers.

Security is their business while security for the state is a cost factor.

Being at the mercy of some ignorant politician is not the best way to talk about data security.

Berlin, Denmark - those are the known one. And there are many more to come.

And regarding cognitive dissonance: politicians demanding high standards and punishing data loss ruthlessly on the one hand, giving oneself a pass on a hack is nothing to increase trust into the system.

X got fined for a missing blue mark. Berlin? Denmark? Others?

A second aspect is that the average guy doesn’t get that part of the whole spectrum must be the degooglers, the home server guys.

So it is relatively easy to get data on them as well just by filtering out the other data.

In other words: 95% not doing degoogling makes for a great small sample of 5%. Negating and interpolating other demographic and psychographic factors and you get a great way of gaining insights.

And remember: being the one who is not using google when being around other guys who do - magic.

So my idea is simple: what’s in it for me, and the state offers way lower value than Google and co.

Pick your fate.

➕ show 1 reply
thewizzardofnl • yesterday at 10:56 AM

I think both are possible. To have a goal and to accept reality. I would not draw the conclusion that all privacy measures are meaningless. It is hard, but I think it is still worth working towards a goal of better privacy for citizens.

mdp2021 • yesterday at 12:04 PM

> wasted effort

That depends. One thing is following precautions, another the Principles. Precautions may have a limit ("due diligence done, I'll stop there"), Principles do not.

Remember also that many phenomena occur because the individuals in the masses have not said "no". Acceptance enabled them. So the acceptance of some ill conceived systems is criminal - it is what lets them exist.

adverbly • yesterday at 1:46 PM

Two problems with that:

1. I don't want to love it. I hate it. You can learn to live with things you hate though, and not have it impact your day to day life or mental health though.

2. Its still a bomb. Until we find out how we can de-value the data, it will have an incentive to be stolen.

One thought here that I don't personally agree with, but might be important regardless:

Imagine a society without secrets or privacy at all for example.

I don't personally like the sounds of it, but it is sort of where we're headed at the moment, and if the fundamental reality is that obtaining data is much more easy than defending it, then perhaps we need to come to terms with a world without privacy, and how to create the best version of that unconstrained world.

Again, I don't like the sounds of this, but I'm curious to read more about it. Can someone give a philosophical pitch of why GDPR style regs on personal and company data are so important?

robwwilliams • yesterday at 4:19 PM

LoL. We are all dancing naked on the table and hoping our clothes and wallet or purse and some of our pride will be where we left them.

TeMPOraL • yesterday at 10:44 AM

Evidence is pretty clear after decades of this: big data breaches are inconsequential for an average person.

They happen all the time, nobody cares, criminals who want to target you will target you anyway, criminals who don't target don't care about you specifically, legitimate entities cannot use this data anyway, and legitimate scammers (marketing) will find different ways to get you to give them the data you need.

At this point I thing privacy obsession is modern copium, a way for people to deal with the fact that we're all individually a speck of dust on the face of human civilization. It's about asserting, "I am not an NPC, I have this richness of experience", and then trying to hide it all in case the world wants to check.

➕ show 2 replies
swozey • yesterday at 1:56 PM

All of the popular surveillance apps correlate your email address and phone numbers mostly, but if you used [email protected] to sign up for [email protected] google knows and marks it as your altnerate account, it could give them all your 30 rando gmails, you're then linked by phone activations through those emails to everything else, whatsapp, telegram, credit card purchase, etc. the biggest link in the chain is always the phone number though. They also have a big "Alternate Emails" button. Everything fans out from those.

I don't know how deep palantir can build profiles on someone, like digging into comment histories and extrapolating you are x y or z sort of stuff. I'm sure they've learned a lot about people via public irc logs and discord servers. But the only screenshots I've seen have been way more simple than that, basically a facebook UI that gives them buttons for all the apps with the phone # that has been identified as you the user, so it would be your list of social media apps accounts and they just click in and read messages. These screenshots have popped up in court cases recently.

We need to stop using the same phone numbers and rotate them constantly. Ideally back to something like fi that masks your "real" isp account phone number. They need to stop being a 2fa and especially stop being able to identify a person. Carry a dumb 2fa. I've always been on the "dont ask for my phone number to use your service" bandwagon but absolutely now.

And now some banks are doing instant voice recognition. I don't pick up my phone for any number I don't know anymore.

sillyfluke • yesterday at 11:37 AM

>I just don't want to stop living - flying abroad, going to doctor

Good, you're not throwing out the baby with the bathwater. I don't get why you think throwing out the bathwater itself was wasted effort though.

The point is to get rid of things you can live without. If you're going to get rid of something but then spend every day thinking of its absence, then yes, that may be bridge too far. Otherwise, getting rid of it has some value.

I don't see the harm of asking, "Do I need this entity's services enough to justify forking over this data" for every entity that you interact with. Everyone draws their line in the sand at a different place. Data hygiene is a good phrase for that reason, everybody's acceptable level of hygiene (or lack thereof) is different.

ionwake • yesterday at 10:19 AM

I gave up when i realised Firefox had google analytics and noone even knew or cared. That was about 10 years ago now.

➕ show 1 reply