.MKITOS

Week 3 of rm -rf

umask

In Unix, umask sets the default permissions for every new file you create. Instead of locking each one down after the fact, you set the defaults once and everything new is born restricted.

That's this week. You've spent two weeks cleaning. Now you set defaults so anything new doesn't leak you by default.

Think of it like brushing your teeth. You don't deep-clean once and call it done forever. (If you do, please see a dentist and a therapist.) Privacy is the same — a habit, not a project.

Task 1: Email Aliases — The Single Most Important Change

Your email address is the master key to your digital identity. If every service has the same email, a breach on any one of them leaks the key to all of them. The solution: unique email aliases for every service.

A quick trick: Gmail and some providers let you use you+servicename@gmail.com. This does not hide your real email — anyone who sees it can strip the + part. It only helps you track where your data leaked from. Use it as a supplement, not your main privacy strategy.

How It Works

Instead of giving each site your real email address, you create aliases that forward to your real inbox. If an alias gets compromised, you simply disable it — the breach is contained.

Free Options

What to Do

  1. Pick one alias provider (SimpleLogin recommended)
  2. Create an account using your primary email
  3. Go through every active account you have and swap the email to a unique alias
  4. For new sign-ups, generate a fresh alias each time
  5. Critical: Never reuse the same username or password across platforms. Unique email + unique username + unique password = three locks on every door.

Caveat: You're trusting the alias provider with your email routing. SimpleLogin and AnonAddy are open source, which means the code is auditable, but you still rely on their servers. Self-hosting is the ultimate option if you have the technical ability.

India Note

If you primarily use Indian services (Zomato, Swiggy, Flipkart, Amazon.in, Paytm, etc.), alias them too. Indian services have had significant data breaches. Your Flipkart email + password being leaked shouldn't compromise your Reddit account.

Task 2: Browser & Search Privacy

Your browser is the single biggest vector for digital fingerprinting. Every extension, every setting, every site you visit contributes to your profile.

See for yourself: visit Cover Your Tracks by EFF to see how uniquely your browser can be fingerprinted. Check Browser Leaks to see what data your browser leaks in real time.

Browser Choice

Essential Extensions (All Free)

Search Engine

What to Do This Week

  1. Switch to Firefox or LibreWolf
  2. Turn on Enhanced Tracking Protection (strict)
  3. Install uBlock Origin
  4. Install CanvasBlocker (Firefox only)
  5. Set DuckDuckGo as your default search engine
  6. Disable third-party cookies in browser settings
  7. Clear all existing cookies and site data

Task 3: Password & Authentication Hygiene

You can't secure your accounts if you reuse passwords. One breach exposes everything.

Password Manager (Free Tier)

What to do: Pick one. Generate a unique, random 20+ character password for every account. Write down your master password on paper and keep it somewhere physical. Not a sticky note on your monitor. Somewhere actually safe.

Passphrases Over Passwords

P@ssw0rd123! gets cracked in seconds. correct-horse-battery-staple takes centuries. Your call. This isn't opinion — it's math. Read the logic on Wikipedia, then try it yourself with an entropy calculator to see the numbers live.

Use 5-6 random words. Your password manager can generate them. Let the machine do the heavy lifting — that's what it's for.

Two-Factor Authentication

Audit Existing Accounts

  1. Change passwords on all accounts you kept (use the password manager)
  2. Enable 2FA where available (authenticator app preferred)
  3. Remove unused apps and devices from "authorized sessions"
  4. Revoke old API tokens and OAuth grants

Task 4: Ongoing Monitoring Schedule

Privacy leaks are like weeds — pull one out, two more pop up somewhere else. New breaches happen. New data brokers appear. Old opt-outs expire. You need a schedule. Not a fun one, but neither is getting your identity stolen.

Quarterly (Every 3 Months)

Yearly

Ongoing Habits

🌍 Region-Specific Maintenance

India (🇮🇳)

European Union (🇪🇺)

United States (🇺🇸)

Asia-Pacific (🌏)

Wrapping Up — You Are Not Done, But You Are Ahead

You are not invisible now. But you've gone from being an easy target to someone who requires actual effort to track. Most data brokers will move on to easier prey. Congratulations — you are now privacy-annoying. It's the best kind of annoying to be.

The internet's memory is long. New data will accumulate. Old opt-outs will expire. Breaches will happen. The habits you built this week are what keep you ahead — not a one-time fix, but a permanent mindset shift that costs you a few minutes every quarter.

Need Help?

If you want us to perform OSINT on your exposure or help you navigate takedowns, reach out to us at afterthedot@proton.me. We can help identify where your data is circulating and guide you through the opt-out process.

⚠ SELF-CHECK: Did You Actually Build the Habits?

☐ Did you set up an email alias system and swap your accounts?

☐ Did you harden your browser and install privacy extensions?

☐ Did you set up a password manager with unique passwords?

☐ Did you enable 2FA on all critical accounts?

☐ Did you create a recurring monitoring schedule?

☐ Did you memorize the "edit to fake" habit for abandoned accounts?

☐ Did you set a policy for yourself on app permissions going forward?

☐ Did you handle region-specific maintenance steps?

☐ Did you set a SIM lock (if in India)?

Less than 5 ticks? Your future self will leak data. Go back and fix it.

And if you ticked all 9 — go treat yourself. You've earned it.

← Week 2: PULL THE PLUG    Back to Module Home