Online Privacy in Practice: The Steps That Actually Make a Difference

Date:

Share post:

The Gap Between the Ideal and the Achievable

Full online privacy — a state in which no entity can track, profile, or monetize your online behavior — is effectively unachievable for anyone who uses mainstream internet services, communicates with people who use them, or lives in a country with surveillance capability. The practical privacy question isn’t how to achieve the unachievable ideal; it’s which improvements are achievable with reasonable effort and which threats are worth protecting against for your specific situation.

The most useful privacy framework is threat modeling: identifying who might want to access your information, what they might do with it, and how they’d likely try to get it. This produces targeted protection rather than an overwhelming list of everything that could theoretically be done. The privacy steps that matter for resisting data broker tracking are different from those that matter for resisting surveillance by a government actor; both are different from the steps that matter for protecting against corporate data collection for advertising targeting.

Browser Settings and Extensions That Help

Browser choice and configuration are the most impactful privacy improvements for general web browsing, because the browser is involved in every web interaction. Firefox with default tracking protection enabled, or Brave (which blocks trackers and ads by default), provide meaningfully better tracking protection than Chrome or Edge with default settings. The privacy difference between browsers is real and measurable: cross-site tracking (the mechanism by which an ad network tracks you across many websites) is substantially harder in Firefox and Brave than in Chrome with default settings.

Extensions that provide additional protection: uBlock Origin (the most effective and least performance-impacting ad and tracker blocker, available for Firefox and Chrome-based browsers), Privacy Badger (Electronic Frontier Foundation’s tracker blocker that learns which trackers to block based on behavior), and Facebook Container (Firefox-specific, isolates Facebook’s tracking to only occur on Facebook rather than across the web via embedded tracking pixels). These extensions reduce the tracking that generates the advertising profiles that follow you across the web.

Search Engine and DNS Privacy

Google Search collects and stores search queries associated with your account (or, if not logged in, with your device and IP address fingerprint) and uses them to build advertising profiles. Switching to a privacy-respecting search engine for queries where this matters — DuckDuckGo (no query collection, no tracking), Brave Search (independent index, no tracking), or Kagi (paid, no ads, no tracking) — removes one of the most valuable data collection points in the advertising ecosystem.

DNS queries — the lookups that resolve domain names to IP addresses that occur for every website you visit — reveal your complete browsing history to your ISP by default, because your ISP’s DNS servers handle these queries. Switching to an encrypted DNS provider (DNS over HTTPS using Cloudflare’s 1.1.1.1 or Quad9’s 9.9.9.9, configurable in modern browsers and operating systems) prevents your ISP from seeing which sites you’re visiting. This isn’t a complete privacy solution, but it removes one significant visibility point.

The Data Broker Problem and What Can Be Done

Data brokers (companies like Acxiom, LexisNexis, Spokeo, and hundreds of others) compile profiles on individuals from public records, purchased data, and various other sources, and sell this information for background checks, direct marketing, people searches, and other purposes. These profiles contain name, address history, phone numbers, relatives’ names, property records, and sometimes financial and behavioral data — all publicly available or legally purchased.

Reducing data broker exposure requires manual opt-out requests to individual data broker sites (each has a different process), which is time-consuming enough that services like DeleteMe or Privacy Bee have emerged to automate the process for a subscription fee ($100-130/year). The opt-outs are not permanent — data brokers re-acquire information over time, so ongoing maintenance is required. The process is worth doing for specific threat scenarios (stalking concerns, public figures, people with privacy-sensitive professions) but may not be worth the ongoing effort for users whose data broker profile doesn’t represent a specific risk.

The Achievable Privacy Minimum

For most users who want meaningfully better privacy without investing significant ongoing effort: use Firefox or Brave as the primary browser with uBlock Origin installed, switch to DuckDuckGo or Brave Search for general searches (especially for sensitive topics), enable encrypted DNS in the browser settings, use Signal for sensitive personal communications, and review app permissions on the phone quarterly (revoke location, microphone, and camera access for apps that don’t need it).

These steps require one-time setup of approximately an hour, are fully reversible, and meaningfully reduce the data collection that produces the most persistent advertising tracking and data broker profiles. They don’t require giving up mainstream services — they’re configuration improvements to how those services are accessed rather than service replacements. The privacy improvement is real; the effort is bounded; and the trade-off with convenience is minimal for most users compared to the incremental privacy protection these steps provide.

MUST READ

Related articles

Fibre vs. Cable vs. 5G Home Internet: Choosing What’s Actually Worth It

The Options That Have Multiplied Without Getting Simpler Home internet technology options have expanded significantly over the past five...