this post was submitted on 19 May 2024
108 points (88.6% liked)
Privacy
31981 readers
483 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I really appreciate privacy articles that talk about threat modeling as it seems like its the biggest part of privacy people miss.
The problem with a threat model is that higher threat models are plainly dismissed by the community. For example, if your threat model is to escape the NSA, it doesn't matter if you're using a burner over TAILS to post this message, you will be dismissed.
The problem is not the tech, it's the community that doesn't want to engage
Let be honest, If your threat model is truly to escape the NSA you probably shouldn't be risking being on social media.
I think part of the reason people dismiss the idea that someone could have that big of a threat model is in most cases it would be unbelievably bad opsec to risk talking about your threat model on social media or something like the privacy guides forum.
Except that forums are exactly the best place to talk about (at least in theory) better OPSEC practices. Crowd-sourced knowledge is fairly good in technical spheres, even if they try to influence it
Not only that but I think there's not enough middle road. The very tech-savvy people either seem to not care about privacy at all, or they think glowies are out to get them. Of course, it's not paranoia if they're really out to get you. But most people are not as interesting as they think they are, and their threat models do not match their reality.
Threat modeling is hard.
Just like anything, that beginning step to assess where you are, and where you want to go, is critical.
Frankly my threat model is way too ambiguous...and I'm trying. I can't imagine trying to convince non-tech folks they need a threat model assessment and then walk them through it, design a plan to improve their security/privacy.
Hmm, well, sounds like I just described a consultancy.
Yeah I'm not really trying to hide from the govt, but I would vote on limiting their power if given the chance. Anyway, what I don't want is every corporation I deal with (car, bank, phone, apps, isp, etc) to track me so excessively.
If the govt did get curious it would take zero leg work, just ask those companies that are very willing to hand over my data to damn near anyone, or hold onto it long enough to have it stolen.
So with that in mind limiting corporate surveillance and limiting ease of govt surveillance is essentially the same thing, but the govt has the ability to put in the work and get you if they really wanted to.