Video summary
How to protect your online privacy in 2019 | Tutorial
Main summary
Key takeaways
Summary of the Tutorial (Online Privacy Using “Compartmentalization”)
The video argues that online privacy isn’t primarily about using the “right” tools—it’s about using a process called privacy by compartmentalization. Since no system is perfectly secure, you should assume breaches will happen and design your digital life so attackers (or curious third parties) can only access a limited portion of your data—not the full “package.”
Key Concept: Privacy by Compartmentalization
- Create separate “virtual compartments” (isolated pools of data) for different parts of your identity.
- Use strong separation so information from one compartment can’t easily be linked to another.
- Consider threats beyond hackers, including:
- service providers
- governments
- employers
- spouses
- and any party able to access your data
Why Compartmentalization is Needed
Modern tracking is described as multi-channel and cross-platform, using:
- cookies
- tracking scripts
- advertising IDs
- AI-assisted data aggregation
- cross-platform tracking across mobile/desktop, and even offline/online interactions
Without compartmentalization, each new site/app visit effectively adds to a single long record.
The Tutorial’s Practical “Compartments” and Tools
Compartment 1: Professional Identity (Work Identity / Business Activity)
Goal: Separate your real name/work activity from social/private browsing to prevent linking.
Browser setup (desktop)
- Use a privacy-hardened Firefox
- Install extensions:
- uBlock Origin
- HTTPS Everywhere
- Cookie AutoDelete
- Configure Firefox to:
- always browse in Private Mode
- enable content blocking
- frequently close the browser to clear cookies/trackers
- Advanced uBlock Origin configuration:
- use medium mode / enable advanced privacy settings
- disable or strictly control third-party scripts and frames
- ability to re-enable JavaScript per-site when needed
Email separation
- Avoid using mainstream, tracking-heavy email “as-is” from the same browsing identity.
- Recommended “privacy-friendly” email client:
- Mozilla Thunderbird (same Mozilla ecosystem as Firefox)
- If you can’t fully separate email:
- close the browser frequently, since providers/websites can use real-time cookies tied to accounts.
Work contact tools mentioned
- ProtonMail for work-related email (including mention of paid features and integration with email clients).
- Alternatives for messaging/video:
- Signal (end-to-end encrypted)
- Wire and Jitsi (messaging/video conferencing)
- ProtonMail migration via forwarding is described as easy.
Compartment 2: Social Media Identity
Goal: Keep social profiles, likes, shares, and interactions from linking back to your professional identity or private browsing.
Desktop browser isolation
- Create a separate Firefox profile (new profile with the same settings/add-ons)
- Optionally copy browser profile data manually to avoid sharing.
- Use this profile only for social media (with an exception for YouTube).
uBlock granularity
- Option to disable third-party requests globally or allow only what’s required per site.
Mobile mitigation for social apps
- Use Web Apps-style sandboxing so each social site gets its own restricted environment (forced encryption and third-party blocking mentioned).
- Recommended default link-opening browsers on phone:
- Firefox Focus or Firefox Klar (to keep browsing separate)
Account hygiene guidance
- Don’t use the same real-name/work email with social media.
- Create random-looking email addresses for social accounts.
- Recommend burner phone numbers to reduce social graph linkage:
- use a cheap throwaway “dumb phone” and pre-activated SIM bought anonymously
- avoid GPS/Wi-Fi/Bluetooth; pay with cash
Messaging app recommendation
- Prefer ditching social-media messaging in favor of Signal:
- end-to-end encrypted by default
- claims not to record contacts/conversation lists/location/user data/sender info on Android (as described in subtitles)
Facebook special case
- ProtonMail is mentioned as partnering with Facebook for PGP-encrypted notification emails (as long as your work email isn’t used).
Compartment 3: Private Identity (General Browsing, YouTube, News, Online Purchases)
Goal: Prevent long-term purchase/browsing records from linking to your real identity.
Primary tool: Tor Browser
- Use Tor Browser (also mentions an Android Tor variant via apps)
- Strict rule:
- Never change default Tor settings
- Don’t install extensions/themes/plugins
- Allowed modifications:
- Tor network settings if blocked
- security level adjustments (with guidance to use a “NoScript”-like approach)
- Includes guidance on learning to re-enable scripts only as needed.
Purchases strategy
- When buying, open product links in regular Firefox (not Tor), but use separate purchase accounts:
- don’t use professional/social email
- create separate purchase email/account without real name
YouTube viewing alternative
- If YouTube/watch time is heavy, use a Chromium-based browser:
- Brave or Vivaldi
- Vivaldi privacy tuning described:
- use the “four horsemen” privacy extensions (e.g., uBlock Origin, HTTPS Everywhere, Cookie AutoDelete, etc.)
- opt out of Google Safe Browsing
- keep history for session only
- block third-party cookies
- disable WebRTC leaks
“Wall Building” After Compartment Separation (Security Hardening)
Protect accounts from hackers
- Use a unique strong passphrase per account
- Password management mentioned:
- Bitwarden (autofill only helps if combined with 2FA)
- 2FA recommendations:
- authenticator apps using OTP:
- free and open-source OTP app mentioned
- or hardware keys:
- Nitrokey devices cited as the “best”
- authenticator apps using OTP:
- Warning:
- SMS-based verification is no longer secure
Prefer transparent/open-source tools
Migrating away from proprietary ecosystems:
- Alternatives mentioned:
- Inkscape for Adobe tools
- LibreOffice for Microsoft Office
- Nextcloud for syncing
- Etesync for contacts/calendar
- F-Droid as an open app repository
- Also suggests replacing proprietary apps wherever possible.
The “Connections” That Still Leak: IP Address + Device
Even with compartmentalization, two links remain:
- IP address
- device identifiers / fingerprinting (partially)
VPN Discussion (Threat-Model Approach)
- Tor is framed as good for anonymizing searches, but not ideal for high-bandwidth services like YouTube, and can be risky for online banking.
- After compartmentalization, a reputable VPN can help:
- mask IP
- hide browsing from your ISP
- Constraints:
- VPNs require trust
- avoid free VPNs
- avoid providers based in the Five Eyes countries
- Suggests checking privacy aggregators (one privacy site dotnet referenced).
Scaling the Approach: Linux, Virtualization, and Hardened OS Concepts
Reduce ecosystem trust and expand control
- Encourage replacing closed ecosystems with open platforms, focusing on Linux for desktop.
- Mentions Linux compatibility improvements for creators/entertainment, including tools like:
- DaVinci Resolve
- other Linux editor options (as described)
Virtualization as a way to test/contain
- Use VirtualBox to run Linux in a VM.
- Example workflow:
- Linux Mint / Ubuntu ISO in a VM
- allocate ~2GB RAM or more
- Mentions stronger isolation ideas:
- UNIX-in-VM routing traffic through Tor (as described)
“Cubes OS” for deeper compartmentalization
- Cubes OS is introduced as an “ultimate” tool concept:
- compartmentalization baked into the OS
- creates a virtual machine per application to reduce attack surface
- Notes mobile OS lacks similar alternatives.
Device encryption
- Final hardening step:
- encrypt entire devices when possible
- Mentions VeraCrypt for file/partition/system encryption.
Reviews / Guides / Tutorial Structure Highlighted in the Video
- A step-by-step guide to set up Firefox compartments with:
- specific extensions
- private browsing
- uBlock Origin advanced rules
- separate Firefox profiles
- Practical how-to items for:
- email/account separation
- burner phone usage for social media
- Tor rules (what not to change)
- VPN selection guidelines (what to avoid)
- 2FA and password management hardening
- optional migration to Linux/VMs and mention of Cubes OS
Main Speakers / Sources (As Inferred from Subtitles)
Main speaker
- Main speaker: an unnamed creator/host (referred to as “my” approach throughout; no name given in subtitles)
Referenced external sources/tools
- Mozilla Foundation / Mozilla (Firefox/Thunderbird)
- Tor Project (Tor Browser)
- ProtonMail
- Signal
- Nextcloud
- F-Droid
- VirtualBox / Oracle
- Cubes OS
- VeraCrypt
- Linux Mint / Ubuntu / Linux-related communities
- Referenced YouTube channel: “Techlore” (and his “Go Incognito” series)