Privacy is Easier Than You Think
A lot of people think that taking back their privacy will require major life changes and advanced tech skills. Here's why that's probably not true.
People often conflate privacy with anonymity.
When I tell people that they should value their privacy, what they typically hear is that they should go live in a cabin in the woods with no electricity or internet.
Likewise, when people hear me talk about "cybersecurity," they assume that it requires them to have a deep knowledge of code, encryption algorithms, and system architecture.
Of course, privacy and cybersecurity can be hard but it's not all high-level, deeply technical work nor is that level of work always necessary.
Privacy improvements exist across a wide spectrum. Some require five minutes and zero technical knowledge. Others demand a weekend of setup, then disappear into your workflow. A few demand life-level restructuring.
To make matters worse, not all of them yield the same level of results, and it's not always easy to tell when the juice is worth the squeeze. So this week, let's talk about that.
The Paredo Principle
Many of you have likely heard of the "Paredo Principle," also known as the "80:20 Rule." For those who haven't, it's quite simple:
In many cases, 80% of your results come from 20% of the causes.
This is most often applied in business where 80% of your revenue typically comes from 20% of your customers (such as the ones who spend the most or the ones who come back most often). But it can also be applied to many other areas of life, too. For example:
- You might get a flu shot because it's quick and cheap and avoids potential weeks of sickness down the line.
- You only need to learn the top 1,000 or so words in most languages to have a functional level of proficiency.
- You can gain a decent level of knowledge about a subject by only reading a few of the foundational texts. You don't need to read every book ever written on the subject.
It's a reminder to be efficient by focusing on where you're getting the most "bang for your buck" and not to spend inordinate amounts of time on things that aren't really moving the needle.
I believe this is true of privacy, too. The vast majority of effective privacy protections come from just a handful of tool or lifestyle changes.
The challenge is trying to find the right balance between effort and reward. As I've covered many times before, this is the basic idea behind threat modeling: you can't possibly protect everything from everyone all the time at the maximum level, so instead figure out what actually needs protection and how much.

Outrunning The Other Hikers
A threat model is an essential part of doing privacy "right" because it cuts both ways: it tells you far you need to go to have a good, minimal level of protection but you can also use it the other way to decide where you can stop if you don't feel like going further. I've covered this topic in previous blog posts:
Still, a threat model is an incomplete picture for determining which changes to focus the most effort on. The other half of the picture is your personal context.
To explain this, I need to tell an old joke:
The other hiker yells "What are you doing? You can't outrun a bear!" to which the first hiker says: "I don't have to outrun the bear. I just have to outrun you."
The goal of any private business in a capitalist society is to maximize profits.
Data brokers (companies who collect data about us as a business model) want to collect as much data from as many people as possible, but they also have to do this in a way that maximizes profits. Therefore, companies will also exercise their own Paredo Principle: they know that they'll never get 100% of the people, but as long as they're getting enough people to keep turning a profit, that's fine.
Think of it like large-scale fishing: the goal is to make sure you catch enough fish to make a profit, even if some get away. Don't waste your time and energy trying to catch every tiny minnow that slips through the net. Focus on the giant tunas.
In this spirit, data brokers tend to focus their data collection efforts on the "lowest common denominator" stuff - services that everyone is using or techniques that almost nobody is defending against that are likely to work on the most number of people with the lowest amount of overhead.
For example, most people use the same phone number for everything: verifying a new online account, recovery method, two-factor authentication, getting notifications (from Amazon to "your table is ready" at a sit-down restaurant), and more. Therefore, it would be trivial for data brokers to automatically link various data sets together based on phone numbers as identifiers.
So the logical conclusion of all this is that - in theory - it should actually be remarkably easy to avoid the vast majority of automated surveillance capitalism. That's because you don't need to outrun the bear, only other hikers. The data brokers have so many other victims to feed on that it makes no economic sense to bother tracking down every individual. They're okay with letting some people go, as long as the spice continues to flow.
It's a bit of a harsh way of looking at the world, but it's also pretty freeing. You're not longer pressured to become Mr Robot. You just have to not be the slowest runner. And given that the vast majority of people aren't even doing the bare minimum - things like checking your account settings and blocking ads - the "score to beat" is practically in the negatives.
Personal Context
So what does outrunning the other hiker look like in practice, and how can we use to tell if we're getting enough bang for our buck?
Let's compare two people: Alice and Bob.
Bob is a privacy veteran. He's completely degoogled his life, erased his data from the internet, and uses Arch Linux. But lately Bob has been wondering if he should switch to Qubes, instead.
Arch and Qubes are two advanced-level Linux distributions. They have distinct differences and are built on different philosophies but both are solid choices for advanced users.
Alice, on the other hand, is just starting out in her privacy journey. She's still using Chrome but knows she wants to switch to a better browser, so she's trying to decide if Brave or Firefox is right for her.

In both cases, the choices that Bob and Alice make are essentially meaningless, but in different ways.
In Bob's case, going from Arch to Qubes will probably be a security improvement, but only a very small one. It would be like going from a salary of $10 million/year to $11 million/year. Relatively speaking, it's an insignificant change.
For Alice, the choice between Brave and Firefox is essentially meaningless (assuming she takes the steps I suggest on my website) because both offer solid privacy protections.
The key difference is that Alice is gaining way more privacy by switching off Chrome than Bob is gaining security by switching from Arch. In Alice's case, it would be like going from a salary of $100,000/year to $10 million/year. It's going to be a much more substantial change for her.
The difference is further exacerbated when you consider the effort involved in the switch.
Both Arch and Qubes have a steep learning curve.
Bob is already a Linux veteran, so moving to Qubes will probably a lot easier for him than it would be for Alice, but it will still require a huge commitment:
- Back up his data
- Install a brand new operating system
- Reinstall the programs he wants
- Restore the data
- Learn a completely new workflow and software philosophy
- Maybe even buy a new computer (Qubes has some hefty hardware requirements)
Alice, on the other hand, can switch from Chrome to Brave or Firefox while she's on a break at work - assuming her internet connection is decent.
With modern internet speeds, downloading a new browser takes less than a minute, and all modern browsers allow you to quickly and easily import data (like bookmarks, history, and sometimes even extensions) in just a few clicks.
She could make the move and be up and running in the time it takes to listen a modern pop song.
The New Oil is supported by our audience. If you're getting value out of our work, please consider supporting us. (It gets rid of this banner!)
The Effort Matrix
It's worth pointing out that my examples here were clean and simple: switching from Chrome to Brave/Firefox is quick, easy, and pays dividends while switching from Arch to Qubes is complicated and lengthy while offering very little return.
This isn't always the case.
For example: going from Windows to Linux offers a huge privacy improvement, but even switching to Zorin OS - which lets you easily recreate the Windows (or Mac) visual appearance to make the transition easier - will still require a significant amount of effort for a first-timer:
- Back up your data
- Install a brand new operating system
- Set up the new operating system
- Restore your data
- Potentially learn new software if the software you normally use isn't available or Linux (or doesn't work well on Linux)
- Understand how to troubleshoot and update your new operating system

In general, I would think of privacy & security changes like a table or matrix:
| High Effort | Low Effort | |
|---|---|---|
| High Payoff | ||
| Low Payoff |
Of course, this isn't a hard-and-fast rule either. Some things will take less or more effort depending what you're trying to do, or your skill level, or how complex it needs to be for your particular setup. And for some people, the "payoff" is more worth it if it fits your thread model. (And of course, some things are more like "medium effort/payoff.")
Fear of the Unknown
I think this commonly-ignored fact - that not all privacy changes necessarily have to be long, hard, and complicated - often scares away those who are potentially interested in privacy but have yet to act.
Without any sort of context or experience (even so much as a step-by-step tutorial to reference) people can only assume that even the simplest actions - installing an ad-blocker, removing unused apps, downloading Signal - are time-consuming and require a steep learning curve.
To be fair, I get that feeling.
At my last apartment, our Internet Service Provider had a firewall installed by default for everyone. They wanted me to pay extra to get a "static IP address" to allow me to self-host my Nextcloud instance. I decided instead to opt for Cloudflare Tunnel (which is free).
For weeks I put it off, wanting to make sure I had several hours to dedicate to making mistakes, troubleshooting, and getting it all done in one sitting. I didn't want to have come back a few days or weeks later and try to remember where I had left off or where I had seen that one helpful thing.
Turned out, it took less than five minutes. Literally.
Copy and paste two commands and I was up and running.
I felt kind of mad I hadn't done it sooner, but I didn't know it would be so smooth.
I can only assume that many people who put off some of the simpler privacy changes feel the same way. "That's it? Wow, I should've done that ages ago."
Getting Started
The Paredo Principle isn't the only pop psychology we can employ to help us in our privacy journeys.
Another productivity strategy that gets frequently ignored is breaking a larger task down into smaller, simpler steps.
Take passwords, for example.
The average user has over 100 accounts, so the idea of "changing all your passwords to something secure" is daunting for most people.
However, this ignores the fact that changing passwords can be broken down into steps:
- Research password managers and select the one you think is right for you.
- Download the password manager of your choice, create an account, and basically just get it ready for use.
- Import all your existing passwords from your browser (or wherever you store them) into your password manager.
- Update critical passwords first - bank, email, taxes, doctor's office, etc.
- Update other passwords using whatever system works for you: 5 per day, "as you go," or all at once next time you have a day off.
This can all be done one day at a time, one week at a time, or simply whenever you have a moment for the next step. It doesn't have to be all-at-once.
For some people, there may be other strategies they can employ to help make the switch, like the Pomodoro Technique or the Five-Minute Rule.
I'd also be remiss if I didn't note that I did specifically make a video earlier this year about getting started making changes in your life:

Whatever the case, I hope this helps dispel the stereotype that privacy will require you to upend your entire life and jump straight into the deep end.
Maybe you will eventually need to make big changes if your threat model calls for it, but even so it's unlikely you have to make them all right now.
You can start small and work your way up, learning lessons and building confidence and skills along the way, just like everything else in life.
Each tiny win is a building block for the next one.
What tiny but high-impact privacy change have you been putting off and how can you get started on it today?
Tech changes fast, so be sure to check out our website for all the latest recommendations, tools, services, and more.


