Not to be a doomer, but it feels like the skill floor to protecting my privacy is unbearably high and getting higher. Does anyone have a good resource about it?
post
No, mostly because the main tenet of data security is that nobody should ever be trusted - not fully, at least.
I believe it's phrased, Trust AND Verify.
Trust but verify, if you're using the Russian axiom.
I wasn't aware of the Russian origin of the axiom. And it's been quoted to me, and I use "trust and verify." I see from wikipedia that it's a Russian proverb in Russian: доверяй, но проверяй, romanized: doveryay, no proveryay.
https://en.wikipedia.org/wiki/Trust,_but_verify
I guess I'm neither a good Russian, nor a good Reaganite. Not in the least bit surprised to know this about myself.
TL;DR - No trust. None. For anyone or anything.
Extreme you say? Sure, maybe. But we've been burned so many times, yet we still say things like "oh but its convenient". That simply means most people dont care or dont have the time to deal with it, which is fair.
I don't blame them, in this day and age, we have PLENTY to worry about, other than our online privacy and anonimity.
Personally, I've went with the scorched earth approach. Foss, privacy respecting, self-hosted, encrypted. If I don't have control of it, I will keep it in a different place than the things I have control over.
Unfortunately, for most, this comes at a very large technical overhead. Frankly, I don't see other ways forward. Look at france, sweeden, UK, they all want backdoors and the encryption keys to everything.
The way forward will be trustless, self-hosted services. The next steps are to simply lower the technical bar, because even as a skilled engineer, sometines I hit my head against things that need a serious amount of figuring out.
Making these services easy to host and use would be amazing. Trust nothing.
all 23 comments