How To Protect Your Online Privacy With Threat Modeling

Поделиться
HTML-код
  • Опубликовано: 21 окт 2024

Комментарии • 59

  • @b1ffdanger
    @b1ffdanger 7 лет назад +5

    As a parent I am not opposed to my child's school tracking information on them but I am going to teach her when she is older the importance of privacy and how to protect herself on the internet. I think that it is a safe rule to always assume that someone can see what you are doing on the internet and if you wouldn't want someone to see/know then you probably shouldn't do it. I am not condoning a surveillance state but it is the world we live in today that the government or businesses are always tracking you.

    • @AboveTheNoise
      @AboveTheNoise  7 лет назад +1

      Thanks for bringing a parent's perspective into this conversation. We think it's a great learning opportunity for teens to understand how data is tracked and used by various interests, and build their own "threat models" so that can have some control over their own level of risk.

    • @hijarahpolangi6407
      @hijarahpolangi6407 3 года назад +2

      Shouldn't it be better if a child learn about online privacy at the early stage?

  • @foobargorch
    @foobargorch 7 лет назад +3

    The "correct horse battery staple" theory of passwords is misleading, you need *REAL* randomness (generate/pick words with dice or a cryptographically secure random number generator) and far more entropy per password than 4 simple words offer (even if they are long in the number of characters, the number of choices or "surprisingness" is what matters, to an attacker using a limited dictionary, 4 words is definitely a lot less to try than the space of possible passwords with a similar length but where the variation is in the individual characters).

  • @ItsGroundhogDay
    @ItsGroundhogDay 7 лет назад +10

    3:13 Now I have to change my password.

  • @tannisbhee7444
    @tannisbhee7444 6 лет назад +2

    Do not communicate or share information that you consider sensitive on any electronic format if you can help it. Consider any action you take electronically to be compromised.

  • @factsverse9957
    @factsverse9957 6 лет назад +2

    To be honest, I have said my passwords to my significant other (well he's my brother, not a partner. Not gay.) and he has forgotten it. It's 20+ characters long. I use passwords 20+ characters long if possible and 16 characters if not possible.

  • @InfectedChris
    @InfectedChris 7 лет назад +13

    Tor, VPN, custom HOSTS files, no script

    • @ashknoecklein
      @ashknoecklein 7 лет назад +2

      Don't post stuff publicly with your real name either lol

    • @nibblrrr7124
      @nibblrrr7124 7 лет назад

      Second NoScript, and maybe hosts & Tor. uBlock origin is much less annoying than NoScript and offers some. Privacy Badger & HTTPS everywhere just work, so I always recommend them. uMatrix is neat for obsessive people who know what they're doing.
      VPNs cost money, help for some threat models but not others, and *an untrustworthy VPN is worse than nothing*. Tor is awesome (more people should start behaving "vaguely suspicious" >:3), but both of these are overkill against many non-state adversaries, like scammers, nosy parents, or abusive partners.

    • @Ruby_V_
      @Ruby_V_ 7 лет назад +1

      +nibblrrr noscript isn't just for security... it also drastically cuts down on webpages' memory footprint (which is important for my potentially problematic tab hording). My current strategy is to just switch browser to chromium if I can't be bothered with noscript for a particular task.
      Thanks for pointing out uMatrix, it looks interesting.

    • @car7862
      @car7862 4 года назад

      To many big boy words..

    • @InfectedChris
      @InfectedChris 4 года назад

      @@car7862 90% of computer stuff is reading and learning with 10% doing. A little bit adds up. If you're interested in learning code or anything, a 35 dollar Raspberry pi can go a long way.

  • @7ion7ion42
    @7ion7ion42 7 лет назад

    How does the US Navy, Air Force track the internet? What information like phone number they have to know to start the trace?

  • @ericvilas
    @ericvilas 7 лет назад +1

    Personally, I don’t care what Google sees. The weirdest, most embarrassing stuff I do? If there’s a picture of it then Google has access to it and I really don’t care.
    The only thing I’m concerned about is hackers/scammers. But that’s easily solved by just being careful of what you enter in what sites
    Also, as for passwords? I’ve been hacked before so now I just use 2-factor for Google, which is my all-purpose main account for everything.

    • @foobargorch
      @foobargorch 7 лет назад +1

      check out the recent PNAS paper "psychological targeting as an effective approach to digital mass persuasion" and chomsky's concept, "manufacturing consent"... the combination of the two is pretty terrifying and precisely what google is positioning itself to do with your data and what it sees of it.

    • @ericvilas
      @ericvilas 7 лет назад

      I haven't read it but from what I imagine, it's a paper on just how scarily effective "targetting what you see to make you believe and do certain things" is, right?
      Yeah, makes sense. I've noticed just how targetted the ads I see are, for instance. And yeah, that's just the tip of the iceberg, I imagine. I do know I myself am pretty damn susceptible to a well-made psychologically persuasive thing like an ad.
      It's a thing that I know is happening, but I doubt Google would use it for eeeeevilll nefarious purposes, just. Maybe get me to do stuff that makes them get more money, like spend more time watching ads for them or buying stuff from people who have partnerships with them, or use their services instead of someone else's.
      _shrug_
      I think it's a worthwhile price for convenience, tbh.

    • @AboveTheNoise
      @AboveTheNoise  7 лет назад +1

      Whoa, fascinating paper! Thanks so much for sharing. For those that want a link to it, it can be found here:
      www.pnas.org/content/early/2017/11/07/1710966114.full

  • @BalazsVarga
    @BalazsVarga 7 лет назад +2

    Regarding passwords: please don't reuse them across sites. Often sites, plaforms gets hacked, sometimes the email+password can be extracted and criminals will try it on other sites. Check and subscribe for haveibeenpwned.com too... just in case

    • @AboveTheNoise
      @AboveTheNoise  7 лет назад

      Good point, yeah you shouldn't use the same password for everything. Thanks for bringing that up.

    • @foobargorch
      @foobargorch 7 лет назад +1

      Password Hasher Plus or Twik are deterministic password managers, that generate a unique, random password for a given website based on a master password, so that you don't need to back up the database of all generated passwords every time you sign up for a new password but still derives a unique password for each website.

  • @Darth_Pro_x
    @Darth_Pro_x 7 лет назад +1

    can you please make a video about the venus project and their proposal of a resource based economy? it proposes a new socioeconomic system based on science, it is really faceting in my opinion :)

    • @AboveTheNoise
      @AboveTheNoise  7 лет назад +1

      We will look into it! Thanks for the suggestion.

    • @Darth_Pro_x
      @Darth_Pro_x 7 лет назад

      Above The Noise you can also learn more about this direction and do some of your research over at tromsite.com
      Thank you for looking into it and for the great videos! :)

  • @countlessbathory1485
    @countlessbathory1485 4 года назад

    Very good video

  • @nachrichtentweet3842
    @nachrichtentweet3842 7 лет назад +2

    Apple is a US-Company. I never would recommend a US-Company when it comes to data security. However. Generation Facebook sacrificed our privacy. Iam online since the millenium. our Generation is influenced by 1980's hacker movies. which stand for anonymity at any cost, the condition of being anonymous..

    • @nibblrrr7124
      @nibblrrr7124 7 лет назад

      Well, one hacker credo is "don't trust anyone if you don't have to" - E2E-encryption is a huge win against mass surveiillance, and with Apple not knowing the content of your messages, the US gov seizing their servers is not as much of a problem (metadata is a somewhat different story).
      Besides, where do you run? Germany has comparatively privacy-friendly laws, and I heartily recommend e.g. Posteo e-mail. But the BND & Telekom have cooperated with the Five Eyes (US, UK & co), and our own government is trying to expand their reach and can hit you closer to home. Russia/China/... have their paws who knows where.
      Defending against targeted surveillance by a nation state actor is much harder than against mass surveillance. Threat modeling ftw.

    • @nachrichtentweet3842
      @nachrichtentweet3842 7 лет назад

      read about blackberry and hushmail. what I tried to say was: the mass traded privacy for publicity at any cost. today people create facebook pages for (their) newborns. while their pets create GPS-based motion profiles of their owners.

    • @nibblrrr7124
      @nibblrrr7124 7 лет назад

      Yeah, you can't protect data people are just giving out like candy, without understanding or concern for the consequences. I agree that social media worsened the bad culture around privacy, also about what people share about others.
      Hushmail is based in Canada (Five Eyes), offers no E2E encryption (they know your keys), and has cooperated with government requests in the past. I'd recommend *Posteo* or *Protonmail* over it, but Hushmail is still better than Google/Yahoo/...
      I like Blackberry, but they don't really have a better track record than Apple? Not trying to shill for Apple, but there are good reasons their devices have a good rep among infosec activists, despite being proprietary. I'm just confused why you are singling out US corps.

  • @IcyeFaethyvve
    @IcyeFaethyvve 3 года назад

    good video

  • @thelastcube.
    @thelastcube. 7 лет назад +1

    Snoop Dogg ?

  • @andrewgeorge2666
    @andrewgeorge2666 7 лет назад

    Not really worried about people hacking me, feel free to hack into my computer and watch all my minecraft lets plays

  • @shirinmokhtabady8535
    @shirinmokhtabady8535 2 года назад

    Only the Utopia ecosystem can help me to be anonymous. No options!

  • @ghadermokhtabady2787
    @ghadermokhtabady2787 2 года назад

    Don't be paranoid use the utopia ecosystem. Enjoy your time on the Internet.

  • @katherinecheng3544
    @katherinecheng3544 4 года назад

    chicken nugget!!!!!!!

  • @oyuk4618
    @oyuk4618 5 лет назад

    Incognito, VPN

  • @katherinecheng3544
    @katherinecheng3544 4 года назад

    what

  • @katherinecheng3544
    @katherinecheng3544 4 года назад

    mi pan shu shu shu shu shu shu mi pan asa custechs nom nom nom mi paaaaaaaaaaaan shu shu shu shu shu shu lev a like if u no that song

  • @Ubaidyy
    @Ubaidyy 3 года назад

    Yoooooo

  • @tqxxr1639
    @tqxxr1639 7 лет назад

    The eff link is malware...

  • @veroth_1289
    @veroth_1289 6 лет назад

    =D

  • @deekmen2761
    @deekmen2761 7 лет назад

    frist