Everyday questions
Security and privacy.
Let’s get practical.
A password to choose, a setting to understand, a tool that promises a lot. Find a clear answer here, with sources and explanations when you want to go deeper.
Frequently asked questions
Start here. Follow the details.
Where should I start with online privacy?
Pick a service you use often. Check what data it asks for, the permissions you granted and what you can decline without losing a useful feature. That gives you one practical change to make and check, rather than an endless list of settings.
Read more: Examine a service you already use #Link to this answerIs a long password enough to protect an account?
It also needs to be unpredictable and unique to that account. A famous quote can be long and easy to guess. Use a password manager’s generator for everyday accounts, then enable a second factor where the service supports it.
Read more: Choose the format for the way you will use it #Link to this answerDoes a VPN make me anonymous online?
No. A VPN protects the connection between your device and its server for the traffic it handles. It moves some trust to the provider. Signed-in accounts, cookies and your browser fingerprint can still identify you.
Read more: Who are you trusting with your traffic?- WireGuard: protocol and cryptographic primitives ↗
- Tor Project: limitations and combining Tor with a VPN ↗
Does encrypted email protect every message I send?
Protection depends on the recipient and the sending method. A message between accounts using compatible end-to-end encryption follows a different path from ordinary email sent to another provider. Check how you would recover old messages before changing addresses.
Read more: Who are you writing to? #Link to this answerHow can I keep cloud files confidential?
You can encrypt files before syncing them, using a vault whose key you keep. The provider then receives encrypted files. You still need to protect the device that opens the vault, keep recovery information and maintain an independent backup.
Read more: Example 2: encrypt a folder before synchronising it #Link to this answerWhat should I avoid sharing with an AI service?
Do not share passwords, private keys or confidential documents without checking that the service and intended use are appropriate. For an everyday request, replace names, remove contact details and include only the relevant passage. A redacted copy is often enough.
Read more: Provide useful context, keep the rest #Link to this answerWhich phone settings help reduce data collection?
Start by removing apps you no longer use. Then review access to location, the microphone, contacts and photos. Access limited to when you use the app is often enough. Histories stored in online accounts have separate controls.
Read more: The first fifteen minutes: remove and reduce #Link to this answerIs my router’s firewall enough for my computer?
It protects a network boundary. The computer’s own firewall still helps against other local devices and when you join a different Wi-Fi network. Review allowed applications, network profiles and exceptions left behind by old software.
Read more: Router and computer: two useful positions #Link to this answerDo Pi-hole and AdGuard Home remove every ad?
No. They can block domains on their lists when devices actually use their DNS service. Ads served from the same domain as the content may remain. A device using another DNS service can also bypass the filter.
Read more: What you can expect to block #Link to this answerIs hosting data at home always safer?
You gain control, but you take responsibility for updates, access, backups and failures. A poorly maintained server can expose more data than a managed service. Decide one use case at a time, based on the time and skills available.
Read more: Security and privacy do not always improve together- AWS · Modèle de responsabilité partagée / Shared responsibility model ↗
- Nextcloud · Durcissement du serveur / Server hardening ↗
How can I avoid losing my accounts with my phone?
Prepare recovery methods that do not all depend on that phone: recovery codes, a spare second factor or the service’s recovery process. Keep them somewhere safe and check that you can reach them without signing in to the account you are trying to recover.
Read more: Avoid losing all your backups at once- Google: signing in with backup codes ↗
- Bitwarden: scope of the two-step recovery code ↗
- Apple: verification codes and trusted devices ↗
These answers are informational. Settings and services change; the guides explain the context, limitations and source dates. Our method ↗