Cautious or Paranoid?

You can spend a weekend hardening your accounts or a year on it. How much privacy is enough is a real question, and the honest version is: how much of that effort actually buys you something? Privacy is a dial, not a switch. Where you set it depends on your own situation, and also on something most privacy writing skips over: the people around you are not going to move the dial with you.

“Cautious or paranoid” is the usual way this gets framed, and it sorts people by temperament when the real question is fit. Does the effort match what you are worried about, and can you keep it running for years without coming to hate it? Picture two people. One has an ex who tracks them and runs a locked-down setup to shut that down. The other reuses one password everywhere because they figure no one would bother targeting them. The first gets called paranoid, the second sensible, and both labels point the wrong way.

This post is about finding your setting, starting from the assumption that you already think whether privacy is worth caring about at all is settled. Calm read, no scolding, a self-check at the end.

Yes, the surveillance is real. No, you don’t have to vanish.

First, so this is not mistaken for a shrug: the data collection is real, and it is large. Brokers you have never heard of keep files on you, assembled from purchase records, location traces, public records, and app data, and they sell access to them. Ad companies follow you between sites to build a profile. Every few months another company spills its user database, and those do not un-leak. None of that is in dispute here.

The question is what follows from it for you. One answer is to disappear: no real name on anything, separate identities that never touch, a phone running nothing mainstream, cash for what matters. That is the right call for some people. A reporter chasing a story in a country whose government would jail them for it needs it. So does someone with a court case against them, a well-resourced stalker, or a police service actively working to attach a name to what they do.

If that describes you, this post is not the one you need, and general advice like this is a poor substitute for resources written for your situation. For everyone else, the question is how far up the dial to go, and the test is whether the juice is worth the squeeze.

The baseline that asks nothing of anyone else

A handful of measures are worth doing almost regardless of who you are, because they cost little to maintain and they close the gaps that get ordinary people hurt. Do these before anything more involved.

Use a password manager and let it generate a different password for every account. This protects you against one thing specifically: a leak at one site being used to walk into your accounts everywhere else, which is the most common way people get compromised. The manager built into your browser or phone is fine to start with. Paid ones add cross-device sync and shared vaults. What a password manager does not do is help with data already collected about you, and it puts a lot behind one master password, so that password and its recovery need to be strong.

Turn on two-factor authentication for your email, your bank, and anything that can reset another account. Encrypt the disk on any laptop or phone that leaves the house, so a stolen device is a lost object and not a data breach. Keep the operating system and browser updated. Use a browser that blocks third-party trackers by default, or add an established content blocker to one that does not.

Every item on that list works without asking a single other person to change what they do. That is the cautious end of the dial, and for a lot of readers it is genuinely enough.

Past the baseline, each step buys less

After the baseline, the returns start shrinking, and some moves only pay off if you go most of the way.

Switching one account to a privacy-focused email provider is the clearest example. If your main address still runs through a mainstream provider, and most of your contacts are on one too, the new address protects a thin slice of your mail while the shape of your life stays just as visible. It starts to matter once most of your correspondence runs through it, and that is a migration measured in months.

A VPN is the one people most often misjudge. It hides which sites you visit from your internet provider, and it hides your home IP address from the sites you load. That is close to the whole list. It does not make you anonymous, it does not stop a site identifying you once you log in, and it does nothing about browser fingerprinting or the trackers already covered above.

The deeper moves, separate identities that never cross, a phone stripped down to hardened software, paying cash, a mail-forwarding address, do give real protection against being profiled and located. They work as a system or not at all. One slip that links your real name to your private identity undoes much of the rest, and the upkeep never stops.

What the far end actually costs

Say you decide to go further anyway. Here is the bill in full, because most guides only show you the download links.

Money. A private email provider, a VPN subscription, virtual card services, a mail-forwarding address, sometimes a second device. Call it a few hundred dollars a year, ongoing.

Time. The first migration eats a weekend, or several. Then there is upkeep, and then there is the day a provider shuts down or changes its terms and you redo that piece from scratch.

Fragility. Lock yourself out of a burner email and you can lose every account attached to it, permanently, because there is no support line that will verify a person who does not officially exist. Aggressive session and cookie clearing means logging in again constantly and solving a lot of puzzles about which squares contain a bus.

Reach. This is the one people underestimate. Asking friends to move to Signal sometimes works. Asking them to move to SimpleX, or to run Pidgin, does not, especially the ones who are not technical, and they are most of everyone. Dating runs on mainstream apps and phone numbers, so a no-mainstream rule either shrinks the field hard or becomes a negotiation on every match. Group plans happen in a group chat, split payments go through an app, shared documents sit on a platform you have sworn off. You turn into the person things route around.

Picture the weekend-trip thread: eight people, one chat app, and you asking them to install a second one so you are included. Once or twice they will. After that they sort out the details without you and tell you the plan afterward.

Your setup touches other people too

There is a second cost, and it lands on people who never opted in.

Some of it is friction you hand them: the extra app, the workaround, the plan that needs re-explaining. People absorb a little of that and then quietly stop offering.

The rest is other people’s data moving through your choices. Your contacts app, synced to some service, uploads your friends’ numbers and names along with yours. Your photos carry other people’s faces and the places they were standing. A shared album, a group thread, a family calendar: each is only as private as the least careful person in it, and sometimes that person is you. Part of setting your dial is deciding how much of other people’s information your setup exposes, and how much inconvenience you are entitled to pass on to them.

Effort in the wrong place is worse than none

Effort aimed at the wrong threat is not free. It costs you time, and it hands you a sense of safety you have not actually earned.

A VPN does nothing about the person who can pick up your unlocked phone. Deleting one social media account while a dozen apps keep feeding the same data to the same brokers changes very little. A separate email for private things helps only if you never open it in the same browser session as everything else.

The way to tell useful effort from theatre is to name the specific thing you are defending against before you add a tool. Without that, you are collecting security habits the way people collect exercise equipment, and getting about the same use out of them.

The version you’ll actually keep

The setup that helps you is the one you will still be running in a year. An abandoned one is worse than a modest one, because it leaves wreckage: burner accounts you can no longer open, a half-moved password vault, a VPN you stopped paying for but still assume is on, friends who have two numbers for you and pick the wrong one.

So aim for a level you can hold. Two ways to check whether you are off.

Signs your dial is set too low for your situation: you reuse passwords, your email or bank has no second factor, your laptop travels without disk encryption, and you would not find out for months if one of your accounts were breached.

Signs it is set higher than your situation calls for: you have accounts you created for privacy reasons and can no longer access, the upkeep costs you more hours than it saves, people regularly cannot reach you, you are defending against a threat you cannot actually name, and you have started to dread your own system instead of trusting it.

The maintainable middle is a real place to land, and it is not a compromise you owe anyone an apology for.

What to do with this

If you take one thing from this, make it this: the question worth answering is not whether you are paranoid, it is what you are actually protecting and who from. That answer makes every decision after it smaller and clearer.

And if the baseline from earlier is not done, start there this week. Unique passwords, two-factor on the accounts that matter, disk encryption, an updated browser that blocks trackers. It is an afternoon of work, it asks nothing of anyone else, and it covers most of what actually goes wrong.

You lock your front door. You do not dig a moat around the house. Online is the same judgement call, it just feels less familiar because nobody grew up doing it.

Leave a Comment