
The Internet has given the world a form of pseudo-telepathy, permitting people in distant continents to connect by mutual interest, need or affiliation. Near-free sharing of information, whether as a personal note or a music file, is now trivial in many parts of the world and possible with some effort in almost the entire world. The impact of this technology is unparalleled; in only 20 years, the Internet has shaken the foundation of globalism, culture, and government. It changes everything it touches, bringing a culture of openness, value for achievement rather than money, and shared intellectualism.
However, the internet has also enabled a new level of personal intrusion, whether it be the ease of reading email as it flies through the aether, or Facebook and Google's ability to perform face-detection searches on unimaginably vast and growing collections of photographs. Your whereabouts and behaviour on any given day could be inferred by your presence in the background of Facebook users' photographs, correlated with the social network's granular information about your friends, family and workplace.
Some of this is inevitable and unavoidable, unless you plan to take direct action to obscure yourself in daily life. However, some practical measures will allow you to enjoy the full richness of the Internet while protecting a modicum of personal privacy.
Without going into too much detail, let it be said that the first step to securing your privacy in every regard is to choose a secure and fully-featured Operating System. No measures you take to protect yourself will do any good if your system is infected with a virus, and only one operating system is known to routinely collect viruses; Windows. Before you think of switching to OSX, the only reason that OSX has fewer viruses is because of reduced demand, not because it is more secure.
If you want security, freedom to choose your software suite, and excellent performance, choose Linux. Ubuntu is an excellent form of Linux that is designed for maximum usability and user-friendliness, with near-unparalleled software support through its huge userbase and its connection to the popular Debian distribution of Linux.
Ubuntu (like almost all Linuxes) is completely free to download and use. In fact, you can try Ubuntu by booting your computer into a "live session", which will not change your computer at all but allows you to try the desktop. Just bear in mind that because Live Mode runs entirely outside the Harddrive of your computer, it has less room to move: it will be much, much slower than a true install. When you want to install Ubuntu, you will have to option to install alongside Windows if you want to preserve the latter, but it is very prudent to back up your Windows documents first because irreparable errors can occur when the two OSes cross paths.
Immediately and permanently stop using Internet Explorer. Never go back. As the slowest, least secure and least featured browser in the market, Internet Explorer has almost nothing going for it. Compounding this, IE is a commercial product whose inner workings are entirely hidden from scrutiny; as mentioned above, there is speculation that tracking may be built-in to the IE browser.
While Opera and other alternative commercial browsers offer more features and better security against viruses and trojans, they remain closed-source software with fewer features and no accountability compared to the Open Source offerings.
There exist two excellent Open Source browsers in particular that will both deliver a superior and more secure browsing experience:
Firefox
Firefox is an entirely open source browser, created by users and employees of the Mozilla Foundation. Firefox is highly recommended provided you are willing to install the correct plugins, as it has superior support from the Open Source community and fewer ties to commercial entities. It supports all technologies you will ever need online, and more besides.
Firefox will work as-is, but it provides no specific privacy guards as given. Don't expect the "Private Browsing Mode" to do anything; this merely deletes local information on your computer after you finish browsing, without preventing people out in the world from seeing what you are doing at all.
To prevent tracking by cookies and flash-based "super-cookies", you will need to configure some settings and install several plugins. This is easier than it sounds. First, disable Third-Party (or all) cookies and change a few default settings to regularly clear cookies:
Now, to install some powerful plugins to extend Firefox's protections:
Chromium
Chromium is an Open Source browser best known for being the foundation beneath Google Chrome. Chromium works perfectly without the Google Branding, and plugins work just fine; given the choice between an Open Source and branded offering, the former is always preferable on balance. However, Chromium has less support than Firefox and fewer plugins to protect privacy and system integrity.
Chromium will work as-is, but it provides no specific privacy guards as given. Don't expect the "Incognito Mode" to do anything; this merely deletes local information on your computer after you finish browsing, without preventing people out in the world from seeing what you are doing at all.
Many of the plugins described above for Firefox are available also for Chrome and may be set up in the same way.
After choice of browser and suitable plug-ins are settled, it will be difficult or impossible for web services to track you unless you permit them to do so. This is where your own behaviour becomes an important determinant of your privacy and security.
Facebook are the most brazenly insecure, anti-privacy web service in the world. If you value your privacy, you'll suspend (because you're not permitted to delete) your account with Facebook and "Forbid" them in NoScript.
Alternatives to Facebook: Diaspora
Diaspora*, an open-source, federated social network, provides an extensible and highly flexible social network for the privacy conscious. Because Diaspora can be installed on a local server if desired, a community could decide to host their own social network but have access to the full meta-network of other Diaspora users. This federated network model means that user data can be saved in a country that respects user data and privacy while communicating fully with users in less respectful countries.
For single users, there are already many Diaspora "pods" that allow open signup for members, in a selection of countries. These servers, known as "Pods", can be chosen by their "uptime" (the amount of time a server spends functional and online) and their jurisdiction to give a good balance of privacy, protection and convenience.
Gmail and Google Docs
Google, while they began with a very transparent agreement on user privacy, have fallen victim to competition with Facebook (which has severely lowered their ethical standards) and interference from the US government, with whom they comply quietly and completely on almost all demands no matter how baseless or unreasonable.
Alternatives to Gmail: Hushmail or Own Email Server
Hushmail is a commercial service based in Canada that offers secure webmail email, though accounts must be paid for if they are to reliably last longer than a month. Accounts supporting IMAP or POP (necessary for accessing email via any means other than webmail) cost about $50 per year. Hushmail are dedicated to protection of user rights, and though they will hand over user data to legitimate legal requests (as any service should), they will only do so after verifying that legitimacy. Additionally, Hushmail is based outside the US, providing a measure of legal insulation from that country's surveillance excesses.
Personal Email Server - If a technical person in a community can set up and maintain an email server for other members of the community, a web-of-trust is formed in which everyone knows who can access and read their email. The primary manager of the email server should be assumed to have access to everyone's email if he or she chooses to read it. However, this is no different from Gmail, Yahoo or Hotmail services, where potentially thousands of employees can access a user's email.
Alternative to Google Docs: Owncloud
See below under "Alternative to Dropbox" for a round-up on OwnCloud's functionality as a virtualised folder and rich-interface online file manager. For document management, plugins for Owncloud are due soon that will enable basic file editing, and more functionality is expected over time.
Alternatively, by accessing files through a synchronised folder on a local computer or Android phone, documents can be edited locally with your favourite application; changes will then be synchronised to the Owncloud server. For mobile workers, this means that an Android Phone could be plugged into a computer at an Internet Cafe, the documents on the phone edited as needed, and when the phone next synchronises with OwnCloud the changes will be made to the server copies and new files uploaded. In this way, Owncloud already offers more flexibility than Google Docs for document management and editing.
Owncloud is not trivial to set up, and so a technical community member would be required for normal users to have access to Owncloud.
Twitter, while it has behaved more ethically than any other company on its scale, is still worthy of moderate suspicion for two reasons:
Alternative: Identi.ca OR Status.net
Identica is the flagship server for Status.net, an open-source Federated Microblogging Client that can be installed on a home server if desired and still communicate with the greater network.
If a community server is established, Status.net software would be preferable, while for individuals Identi.ca offers a nice blend of Twitter-integration, application support and maintenance-free use.
Dropbox
Dropbox, a virtual file hosting and folder virtualisation system, allows users to treat a local folder on their PC as a "shared folder" with other computers, and to access the contents of this folder from elsewhere through an online interface or to share those documents with others. It has a free plan for 2GB of storage and paid hosting for greater amounts.
Alternative: OwnCloud
OwnCloud is an Open Source software system that allows you to set up your own "Cloud" on your Personal PC or home server, which you can then access from around the world to load files on and off, modify documents, log into web services via OpenID, listen to music, etc. It behaves in may ways as a particularly rich alternative to Dropbox, as it can integrate with the desktop of a remote computer through WebDAV to provide a virtual folder.
As mentioned in "Alternatives to Gmail", Hushmail stand out as a good commercial alternative to Gmail that provide full functionality, although they require yearly payments in order to provide the full suite of functions. That's to be expected; Gmail is free because users are the product, whereas Hushmail provides the email service itself as a product, and users must pay for the privilege of respectful email hosting.
Also as mentioned above, the option exists for a community or individual to establish their own Email server, which has more advantages than one might expect provided a pair of technical users can be found or hired to maintain the server.
Your email is not secure. When you send email, it is not sent like a "letter", with an envelope keeping the contents hidden: it's more like a postcard, that anyone along the way can read. When it reaches the mail server, it's open to the managers of the mail server to read whenever they like. When you download it from the server (if you're not using https://), anyone can see what you're reading and possibly even hijack your email.
Encryption means securing your email so that only you and the intended recipient can read the email, whether they have access to your inboxes or are listening in the middle or not. Provided they cannot break the cypher system used, they cannot read the email no matter where it is.
The most common method of email encryption used is Pretty Good Privacy (PGP), and the most common system used to apply PGP to email is the Gnu Privacy Guard, known as GnuPG or GPG.
PGP functions on a public key/private key basis. Visualise it thusly; every email user has a "public key" that enables anyone to "lock" email destined for them. However, the email cannot then be "unlocked" with the public key: for that, you require the private key. When a user starts using PGP/GPG, the first step is to generate a key-pair for the email address it will be used with. How this is accomplished depends on the key management system chosen/used.
It is important to know without needing to understand that with the public key, a person can technically decode email, but to do so is impractical because an enormous amount of computing power and time is needed. However, with the rapid advancement of technology, your key pair will eventually be too "weak" to be considered secure. For this reason, it is best to start out with the strongest key pair you can generate; this is not the same as having a strong password, but you should have a strong password to protect the actual keys from prying eyes that might get access to them.
Keys have a strength measured in "bits", roughly equivalent to the actual length of the key: a 64 bit key is virtually useless today, as computer power is enough to crack them easily enough. Keys are now measured in thousands of bits; over two thousand is strongly advised, over four thousand is preferable. This means it will take more computing power to encrypt and decrypt email at either end, but it means the privacy of the emails will be preserved for longer.
Keys, once generated, are managed thusly: The Key Pair can be exported to an "Armoured Ascii File", which contains the keys in an encrypted way; this means that someone who accesses the file can't just read the keys without a password to decrypt them. This password should be as good as you can manage; a long (greater than 20 letters ideally), non-predictable (no poetry, favourite quotes or names of famous people) sentence with some numbers is ideal. If you can remember symbols, throw some in there, but the length is most important, not the complexity. Keep it long and memorable, not short and arcane.
The "public Key" is usually broadcast widely; your key management system will allow you to publish the keys to key-servers, which will probably be loaded into the defaults so you simply select a menu item saying "publish key". This allows anyone to search for your email address from the key server and download your public key. Many people also include their public key in email attachments, link to it from their signature, keep it on their personal webpage, or digitally "sign" their email with the key (this also ensures that recipients with GPG/PGP can see that the email was not tampered with on its way to them).
GnuPG is easiest to set up and interface with email on Linux. In fact, GPG is already installed on most distributions of linux, patiently awaiting the user to set it up.
Insert instructions for users of other platforms
First things first: as with most products of that suite/family, just stop using Outlook. Outlook doesn't comply with many web standards, meaning other email users won't be able to correctly decode Outlook emails and vice versa sometimes, and it doesn't support PGP/GPG. Also, as a commercial email offering, there is no way to know how secure your email is in Outlook.
For modern systems, the latest version of Mozilla Thunderbird is an excellent choice of Email client (Debian/Ubuntu users: Download it from the site, not the Software Center; the SC version is very outdated). For slower computers, Sylpheed is a great client with built-in GPG support, as is Claws Mail. For truly antique systems, a Terminal-based email client such as [www.mutt.org Mutt] will function speedily but requires arcane user configuration.
Assuming you are using Thunderbird, you will need to install a plugin named Enigmail to manage GPG. Enigmail can be downloaded from the above site or through the add-ons manager within Thunderbird. Enigmail is perfectly integrated upon install, and includes its own key management system which makes it easier for the user to manage friends' keys, upload their own public key, etc.
Settings in the Enigmail preferences allow you to choose whether to auto-encrypt email or leave it to your choice as you write your emails. It also allows you to choose whether to "sign" your outgoing mail: this function allows recipients to know that:
Other people using PGP will get a warning if the signature is wrong, which would imply either tampering or an attempt to forge your digital signature. Bear in mind; unsigned mail won't show any warnings, so if your friends don't expect tampering and don't demand a signature, this won't prevent people spoofing your email address and pretending to be you (which is a lot easier than it sounds).
The Key Manager in Enigmail allows you to search for public keys of your friends or acquaintances: search for their email, and you'll get their public key if they have one. Their keys can be imported into the key manager, and if your settings support it then they will automatically receive email encrypted for their eyes only. You can also export keys; your own key pair, as an armoured (encrypted) .asc file for import into another email client (for your desktop and laptop, or a work computer for example), or a collection of public keys for your friends for import into another client.
For some reason likely related to extreme paranoia on the part of the creators, you can't bulk-search-import keys from all of your contacts at once, and you can't set up Enigmail to search for a key whenever you send an email for recipients with no key already loaded. You have to manually search for a key for each individual, one at a time. Once you have them however, export and import is easy.
Try a search through your email history for "PGP public key" and see how many people have you shared email with that have a key in their signature; you might be surprised!
| License | CC-BY-SA-3.0 |
|---|---|
| Cite as | Cathalgarvey (2011–2025). "Internet privacy". Appropedia. Retrieved October 3, 2026. |