Hi! 2 and 4 months ago @Hellfire103 and @Charger8232 made a post about their privacy setup. So I though I would also share mine.

Remember these rules:

  • Be respectful! Some people are early on in their privacy journey, or have a lax threat model. Just because it doesn’t align with yours, or uses some anti-privacy software, doesn’t mean you can downvote them! Help them improve by giving suggestions on alternatives.

  • Don’t promote proprietary software! Proprietary software, no matter how good it may seem, is against the community rules, and generally frowned upon. If you aren’t sure, you can always ask! This is a place to learn. Don’t downvote people just because they don’t know!

-** Don’t focus solely on me!** I want to mention that this thread is not designed to pick apart only my setup. The point is to contribute your own and help others. That doesn’t mean you can’t still give suggestions for mine, but don’t prioritize mine over another.

  • Be polite! This falls under “Be respectful”, but be kind to everyone! Say please, thank you, and sorry. Lemmy is really good about this, but there will always be someone.

Here is my setup:

Web browsing

  • I use Librewolf for almost everything.
  • For 3D stuff (games, 3d modelling) I use Brave.
  • On mobile I use Vanadium.
  • My preferred search engine is Kagi.
  • Most if the time I have MullvadVPN enabled.

Desktop and laptop

  • I have self-build Ryzen + Radeon PC and Ideapad with Ryzen CPU.
  • I use Arch Linux BTW!
  • I have disk encryption and Nitrokey as a decryption key (or a long password of course).
  • I have secure boot with locked BIOS.
  • I’m running self-compiled linux-hardened kernel.
  • I’m using Gnome (Wayland).
  • I have only open-source apps installed.

Mobile

  • I have Google Pixel 7a with GrapheneOS.
  • I have different 5 profiles: main, google, school, finance, anonymous.
  • I have PIN on every profile and also fingerprint for main and school profiles.
  • I always use VPN, either Mullvad or self-hosted Wireguard.
  • I don’t use a privacy screen protector (for now).

Messenger

  • Signal for my family.
  • Viber for my schoolmates.
  • MS Teams for school.
  • Matrix for help with some open-source projects.
  • Discord for voice chat and local scouts group. I have Aliucord on mobile and Armcord on desktop.

Online accounts

  • Passwords are safe in self-hosted Bitwarden (Vaultwarden).
  • I use 2FA if I can. Either hardware 2FA - Nitrokey, or TOTP with Aegis.
  • I use SimpleLogin for email aliases and randomly generated usernames and passwords.

Video streaming

  • I watch only Youtube. Newpipe on mobile and Invidious on desktop.

AI

  • I do not use AI a lot, but if I do I use locally running LLama3 8B or Duckduckgo’s LLama3 70B

Social Media

  • I had Instagram, Snapchat and Viber accounts, but I’ve deleted them.
  • I use only Lemmy on clearweb and Dread on darkweb.
  • I have Mastodon account, but I don’t use it.

Email

  • I use ProtonMail.
  • One of the best privacy things you can do is use SimpleLogin (or other email alias service).

Shopping/Finance

  • IRL I use cash most of the time.
  • Online I use Monero if I can, otherwise just my credit card.
  • Cashew app for helping managing my purchases.

Music streaming

  • I use only RiMusic on my phone, that’s it.

TV shows

  • I use a VPN, that’s all I’m gonna say…

Gaming

  • Minecraft, Veloren, SuperTuxKart, and some Steam games.

Programming

  • I forgot how to code in Python, because Rust is so much better.
  • VS Codium.

Productivity

  • LibreOffice for simple stuff.
  • Typst for proper documents.

Paid services

  • ProtonMail - 4$ per month
  • SimpleLogin - 30$ per year
  • MullvadVPN - 5$ per month
  • Kagi - 10$ per month. For 5$ you get 300 searches, I use ~350 searches so I will try to lower my searches.
  • Domain - 13$ per year

Self-hosted

  • Everything runs on Raspberry Pi 4 with encrypted micro SD card.
  • Pi-Hole for blocking ads on network level.
  • Bitwarden (Vaultwarden) for storing all my passwords.
  • Wireguard server (with pihole as DNS) for connecting back home from anywhere.
  • Ntfy for self-hosted push notifications.
  • MollySocket for Signal push notifications.
  • FindMyDevice if I lost my phone.
  • Cloudflare DDNS, because I don’t have static IP.
  • Nginx Proxy Manager.
  • Watchtower automatically updates docker containers.
  • My website.

Misc

  • I have Samsung Galaxy Watch 4 classic. I’m trying to do something about it…
  • I’m using Syncthing to sync documents and pictures between my devices.
  • I don’t have a car (because I can’t - I’m 17) and I won’t have one for quite some time. I have a bicycle and my parents have 2 (smart/spy) cars.
  • I’m into crypto (mostly XMR) and I’m trading a little (making a trading bot) on MEXC. I also have Ledger Nano S Plus.
  • I have a 3d printer and it’s fun and usefull :)

TODO

  • self-host Git repos for my projects.
  • Buy a privacy screen protector when I break my current one.
  • Buy a faraday bag, just in case.
  • Do something about my spywatch (maybe sell).
  • Make backups… Yep, I don’t have any yet.
  • Monitor and harden all my devices.
  • Memorize cryptowallet’s private key in case it gets lost.

Thanks for reading!

11 points
*

Kagi isn’t private and it is misleading to advertise it as such. Neither is Duckduckgo and similar products but at least with DDG you don’t need sign in and give it payment information. DDG is also compatible with free software as it doesn’t need JavaScript.

Both Arch and Graphene OS ship proprietary software and encourage its use. In the case of Graphene they encourage the use of Google play and play services and in the case of Arch there isn’t any distinction between licenses and it ships with proprietary firmware and media codex. It is hard to get around such limitations if you want a phone and a newer computer but you state in your post that proprietary software should not be promoted.

Be mindful of dread and the dark web. You can get yourself into trouble if your not careful. Also dark web forms are a most certainly a honeypot

As far as your age goes you should be mindful of your parents and there wishes. Don’t grow up to fast. (Generic but true)

Overall not a bad setup.

permalink
report
reply
12 points
*

Grapheneos does not encourage the use of Google Play services, it provides the option if you want them, but by default they are not installed.

All cellular phones have proprietary binary blobs for the hardware drivers. Unless we’re talking about the completely open source Replicant project, which supports maybe two phones, and poorly… But even then, replicants still has proprietary binary blobs just less so than others

permalink
report
parent
reply
1 point

Kagi isn’t private and it is misleading to advertise it as such.

What is your reasoning for this statement?

Going directly from Kagi’s own privacy policy, “To ensure your privacy and security, we don’t monitor, log or store your queries or associate them with your account”.

Of course you have to believe them, but that’s the same for every service that you do not host or compile yourself, and for which you’ve read the entire source code yourself.

permalink
report
parent
reply
1 point

They require your payment information and you sign in to use it.

permalink
report
parent
reply
1 point
*

First of all, you can pay with crypto and use a burner email, but secondly, they don’t link searches to your payment or sign in. (Assuming of course you take their word for it, but that’s the same for every service that you do not host or compile yourself, and for which you’ve also read the entire source code yourself.)

I’m not saying people should use Kagi, I’m merely pointing out you can’t claim it’s “misleading and not private” without providing some sort of proof.

At best you can say you can’t verify for yourself that they are indeed private as they claim.

permalink
report
parent
reply
1 point
*

not trying to argue the fact Kagi isn’t private.

kagi gives me some very very good search results, i haven’t been able to find better anywhere else with no fine-tuning or anything. works great out of the box.

permalink
report
parent
reply
1 point

That’s completely fair. My problem is when people say it is private.

permalink
report
parent
reply
11 points
*

So all of your internet searches are tied to one kagi account? That doesn’t sound very private.

permalink
report
reply
4 points

I know but it’s way better than Google.

permalink
report
parent
reply
5 points

Google is the worst. There’s many options better. Try ddg or quant

permalink
report
parent
reply
4 points

I did and every other search engine is slower than google which is very important to me. But when I tried Kagi it was so quick, even faster than Google.

permalink
report
parent
reply
3 points

That’s not a comparison as both Google and Kagi require a sign in

permalink
report
parent
reply
1 point

So all of your internet searches are tied to one kagi account?

Kagi states in their privacy policy, “To ensure your privacy and security, we don’t monitor, log or store your queries or associate them with your account”.

Of course you have to believe them, but that’s the same for every service that you do not host or compile yourself, and for which you’ve read the entire source code yourself.

permalink
report
parent
reply
8 points

You seem to be aware of many things.

Just for communication you are using more unfree tools then free and more then in the other categories.

permalink
report
reply
3 points

Yep, its how it is. I converted my family from Viber to Signal, but whole my class… Thats maybe too much.

permalink
report
parent
reply
5 points
*

This is missing a critical piece of context. What is your threat model? Its impossible to know if what your doing even makes sense without that. What are you trying to protect and who are you trying to protect it from?

permalink
report
reply
-8 points

Probably hates Google for tracking his every move online (hence the Google Pixel phone).

permalink
report
parent
reply
4 points

Running GrapheneOS.

permalink
report
parent
reply
2 points

Anything trying to run “private” that introduces anything Google into the environment should be considered compromised. Why would want anything from the biggest corporate ad business in the world in your environment?

permalink
report
parent
reply
5 points

For 3D stuff (games, 3d modelling) I use Brave.

Can you elaborate on this? What exactly are you doing?

permalink
report
reply
2 points

I have a 3d printer and linux. The only good 3d modelling software I found is OnShape which is online.

permalink
report
parent
reply
6 points

Forgive me if it sounds preachy, but have you tried Blender?

I use that for my 3d printing and game-ready modelling.

permalink
report
parent
reply
2 points

Yes I did but it was too complex for me at the time. Maybe I’ll give it a second go.

permalink
report
parent
reply
1 point

Is there any special way that you use Blender that makes it good for CAD? I also love using blender for my 3D printing projects since I have lots of experience using it for animation projects and can make models very fast. It is just that it becomes much harder when exact dimensions are important which is where software like Fusion and FreeCAD shine, not to mention the parametric modeling.

permalink
report
parent
reply
1 point

I’ve just started the hobby and stumbled upon plasticity. Seems to be the new kid on the block, doing things a bit different than the established CAD tools, but for me it’s been perfect. And I was looking for a solution without subscription, which is almost nonexistent

permalink
report
parent
reply
1 point

Looks nice, I’ll try it!

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 4.4K

    Monthly active users

  • 1.7K

    Posts

  • 24K

    Comments