Everything online gets leaked, lost, sold or stolen eventually. This is a fundamental reality that catches up with everyone. BTW this is not a recently acquired conviction: https://web.archive.org/web/20190216141214/https://twitter.com/briankrebs/status/1045091640480804864

But please, convince me I'm wrong if you can!

I know that over the years I've radically overhauled how I interact with companies I chose to do business with. For starters, I assume breach, which means that any information I share with them is likely going to be on the Internet at some point.

E.g., I no longer sign up for a new account somewhere without also doing it in a local, hardened VM and VPN.

I assume that the IP address I used to sign up there will be leaked in connection with my other account details, and probably the last IP I used. I assume records of what I'm doing or buying there will also be leaked.

Hell, I do pretty much all of my news reading now in the same kind of (separate) setup. No way I'm agreeing to run 97 pieces of Javascript from 22 uncertain destinations on the web. I know a lot of my readers unfortunately swear by ad blockers and rarely make exceptions (I'm not a big user of them myself for a variety of reasons), but being able to reset your system after a weekend of wantonly browsing the web is also nice.

Those are just a few basic examples. But I'm curious to hear from others -- How have the folks here altered the way they live and work online in response to the incessant reminders that everyone gets pwned?

Some food for thought over the, er...food coma the next few days :) Cheers!

briankrebs on Twitter

“Being in infosec for so long takes its toll. I've come to the conclusion that if you give a data point to a company, they will eventually sell it, leak it, lose it or get hacked and relieved of it. There really don't seem to be any exceptions, and it gets depressing.”

Twitter

@briankrebs signing up for websites makes no sense to me in a vm. That honestly just sounds like you're looking for additional points to make.

Nowhere did I see you mention that you then re-access those websites through that specifically created VM, thusly obviating the need for it in the first place.

I want to think that this is all meant in good honest intentions but I mean it really sounds a little bit like fear mongering.

Maybe that's just what you have to do these days, and I don't mean that a shot at you, I mean generally, just to earn eyeballs.

I fully understand that the threat models are different for you and myself, but I don't understand the holes in yours as you laid them out.

@stoXe @briankrebs Yes, exactly. At this point I assume everything ends up online or in the wrong hands so I mitigate risk where I can. I’ve had former employers’ external payroll services get breached with my entire identity and bank account information. I mitigate my risk with virtual credit cards and browser extensions. You can’t live offline so no point in “security theater”.