Why privacy matters
"I have nothing to hide"
Nobody considers it suspicious to close the bathroom door, to seal an envelope or to keep a salary and a medical file out of public view, and yet the same people often say they have nothing to hide online. Privacy is not secrecy. It is the power to choose what you share, with whom, and when, which is the normal boundary between you and the rest of the world.
When that choice disappears, behaviour tends to change. After the Snowden revelations of June 2013, the researcher Jon Penney measured a statistically significant drop in visits to Wikipedia articles on terrorism-related topics, a result published in the Berkeley Technology Law Journal in 2016. Nobody had forbidden those pages. Readers who felt observed opened them less, and the same reflex can hold back people who would like to disagree, to report abuse or simply to be different.
"Nothing to hide" also rests on 2 assumptions, that the rules will never change and that whoever holds your data will always be well-meaning, competent and never hacked. The history of this region, within living memory, gives reasons to doubt the first. The Finnish case described below gives reasons to doubt the second.
Metadata says more than the words
Almost everything you do online leaves a trace, from your searches and your location to the people you write to and the time you do it.
Even when the content of a message is encrypted, the metadata usually is not, meaning who talks to whom, how often and from where. A call to an oncologist, then to a lawyer, then to an insurance company tells a story without a single sentence being read. General Michael Hayden, a former director of both the NSA and the CIA, said it in a public debate at Johns Hopkins University in 2014: "We kill people based on metadata." His opponent that day, the law professor David Cole, reported the sentence in the New York Review of Books.
These traces do not stay where they were created. Data brokers combine them into profiles sold to advertisers, insurers or political campaigns, and part of what is stored ends up leaking. In Finland, tens of thousands of therapy records were stolen from the psychotherapy chain Vastaamo, and from October 2020 some 22,000 patients reported emails demanding 500 euros to keep their session notes unpublished. A leaked password can be changed, whereas a date of birth, a home address, a face or a medical history cannot.
5 habits remove a large part of the exposure
You do not need to disappear or to become an expert, because privacy is not all or nothing and every step reduces what is exposed.
Start by asking who you realistically want to protect yourself from, whether advertisers and data brokers, scammers, an ex-partner, an employer or a state, since the answer decides how far you need to go. For most people the first 2 come first, and a handful of habits removes a large part of the exposure:
- a private messenger,
- unique passwords and a second factor,
- a browser that blocks tracking,
- email aliases,
- a protected network connection.
These are the 5 chapters of this part. They are independent, so start with the one that looks easiest rather than the one that looks most important. Each of them ends with a checklist of 5 actions, and in every chapter at least 1 of those actions takes 5 minutes.
Sources
- Chilling Effects: Online Surveillance and Wikipedia Use, Jonathon W. Penney, Berkeley Technology Law Journal, 2016.
- "We Kill People Based on Metadata", David Cole, The New York Review of Books, 10 May 2014.
- Man Who Mass-Extorted Psychotherapy Patients Gets Six Years, Krebs on Security, 30 April 2024.