Re: paranoia about stuff watching me in my home.
Iām actually quite paranoid about this topic, but Iām also kind of bad about it. I donāt cover cameras or microphones (though I might do in the future), and I recently caved and began using Google Now with the āOK Googleā, though it only works when the device is unlocked. I need to stop it, but I have some RSI, and typing on the phone is pretty bad for it, so I find the voice recognition to be very useful.
On the other side, Iām sort of an exhibitionist, and I kind of get a kick out of the idea of people secretly watching me naked. I doubt anyone else gets a kick out of the idea of watching me naked, but, eh, they are welcome to do so.
I donāt forward ports on my routers ever. They came without any ports open, and I havenāt changed that. The only way into my home network from the outside is through one server I have reversed tunneled to a VPS, and itās only available on that server if you log in from localhost, so youād have to have my private keys and are prepared to do a lot of SSH inception to get very far. I have to forward the port with the reverse tunnel on the VPS to the remote machine, and then ssh into that port. Itās kind of a pain/kind of awesome.
I do the same with web-based administrative interfaces for services, even on my LAN. You can only access them remotely through tunnels, the exception being the Emby server, but thatās on a different NAT than what I give guests, and Iām not sure there is a way to stop it. The one really insecure thing on my home network is my NFS share, which accepts any IP address and has no other protection. Thatās on the same private NAT as the media server, though, plus security by obscurity. Only people who know what NFS is and are specifically looking for it (and get on my private NAT with a password of 40 random characters) are going to find it.
Other than that, I only use syncthing for sync, have no IoT āthingsā. All my passwords for things that matter are randomly generated and stored in a keepass vault with a 30 character passphrase (the vault is only shared over syncthing), Browser doesnāt get to store my passwords. Cookies from all websites I visit are automatically destroyed when I leave the site, except those I whitelist (i.e. not Facebook, Google or Amazon). I still have JavaScript and Flash enabled, like an idiot.
I do the majority of my communication with friends and family over Telegram. I have a Facebook account that I never use, and what I do post (like, on a less-than-monthly basis) is all public to avoid the delusion that there is such a thing as privacy on facebook. I read things from G+ and Twitter, but I post, like, once a year. I donāt SMS much and call even less. I do email (with Gmail, no less), but I never use it for anything I wouldnāt want to be in the public recordā¦ anymoreā¦ (yikes!)
I use Arch Linux exclusively on all my PCs, so I know whatās happening in the background because I enabled all the services myself, and I donāt have any game consoles since the PS2, so Iām safe there. I also dabble with Ubuntu occasionally, and I kinda mostly trust it also. I even leave the ads turned on.
So, Iām pretty good in general, but pretty bad when it comes to my phone, which is probably the worst thing of all. Luckily, Iām moving to Europe in a few days, and Iāll be out of phone service for a bit, so Iāll have a chance to re-evaluate my habits with regards to the phone. I canāt completely give up navigation, though. New city, terrible sense of direction, too lazy to read maps (and not great at it anyway). Google is probably the scariest company on the planet if you think about it for more than a few seconds, but their ability to present helpful data at the right time and tailored to my terrifyingly specific needs is soooooo useful. When they give me route information about somewhere I was actually heading or remind me to pay my bills on time, Iām both freaked out and thankful.
P.S. Caring about any form of sports-ball is so not geek-chic. Some of you people are in danger of loosing your l33t h4x0r cred! Repent and get ye a calculator watch!
edit: holy balls. This was going to be a āshort post.ā