Personal security / Internet opsec / anti-doxxing 101

A practical guide to protecting yourself online.

About this version: This page is the canonical version, updated September 2026. It grew out of a Google Doc I started in 2018, and some tool picks have changed since then.

Cyberpolice

This started as a Google Doc, back when the LinkedIn and Adobe breaches were recent news. People left their own picks in the comments: NoMoRobo and RoboKiller for robocalls, BrandYourself as a DeleteMe alternative, and a PrivacyDuck tip via Jessie Frazelle. In January 2021 I pointed jamiedubs.com/personal-security at the doc, and in December 2025 I turned it into this page.


The Reality

Security is about trade-offs. Perfect security doesn’t exist, but you can make yourself a much harder target with just a few hours of setup.

First step: Check haveibeenpwned.com to see if your email/passwords have been exposed in data breaches. That password you’ve been using since high school is probably sitting in a leaked zip file somewhere. This will motivate you.


Mandatory (Do These Now)

1. Use a Password Manager

Use 1Password or Bitwarden. Always, always, always.

Why? When a service gets breached (and they all do eventually), attackers try those credentials on other sites. If you reuse passwords, one breach compromises everything.

A password manager lets you use unique, strong passwords for every site without having to remember them. After you set it up, reset your passwords on the important sites first: email, banks, social media.

If you only do one thing from this list, do this.

2. Enable Two-Factor Authentication (2FA)

Turn on 2FA for all important accounts: email, banking, social media.

Use an authenticator app (1Password, Authy, Google Authenticator) rather than SMS. SIM-jacking attacks can intercept text messages.

Better still, use passkeys or a hardware security key where a site supports them. Phishing can trick you into typing an app code into a fake site, but passkeys only work on the real one. CISA explains why.

Priority accounts:

3. Freeze Your Credit

Lock your credit reports with all three bureaus to prevent identity theft:

This stops most new credit accounts from being opened in your name. It does not protect accounts you already have, so keep watching those. You can temporarily unfreeze when you need to apply for credit.

4. Lock Your Phone Number

Call your cell carrier and say: “I am concerned about my security. Please do not allow porting my number under any circumstances without additional verification.”

This makes SIM-jacking harder. That’s when someone convinces your carrier to move your number to their SIM card, then uses it to bypass 2FA. It won’t stop every attack, which is another reason to avoid SMS for 2FA.

5. Secure Your Devices


Keep Everything Updated

Enable automatic updates for your operating system, browsers, and apps. Most attacks exploit known vulnerabilities that have already been patched.

Use a Virtual Phone Number

Services like Google Voice give you a separate number you can use for signups, reducing exposure of your real number.

Audit Your Accounts

Periodically review:

Use Encrypted Messaging

Cover Your Webcam

A piece of tape works. Paranoid? Maybe. But it costs nothing and eliminates a real (if unlikely) attack vector.


Advanced

Network Monitoring

Little Snitch (Mac) shows you every network connection your computer makes. Eye-opening.

VPN

A VPN encrypts your traffic and hides your IP address. Useful on public WiFi and for privacy from your ISP.

Reputable options: Mullvad, ProtonVPN, IVPN

Encrypted Email

Proton Mail is encrypted email based in Switzerland. Mail between Proton users is end-to-end encrypted. Mail to other providers is not, by default, and subject lines never are.

DuckDuckGo doesn’t track your searches.

Canary Tokens

Canary Tokens are tripwires that alert you if someone accesses your files or accounts. Try dropping one in a file called “bank account and passwords.”


Data Brokers

People-search sites aggregate and sell your personal information. You can opt out, but it’s tedious.

DeleteMe is a paid service that handles opt-outs for you automatically.

Manual opt-out guide:


More Resources


Originally written 2018 as a Google Doc. This page is now the canonical version. Updated September 2026.