Locking Down Your Identity: The Privacy Setup I Actually Use
A lot of what I write here is about taking back control: self-hosting your own services, keeping your data on hardware you own and stepping off platforms that treat you as the product. Protecting your identity is the other half of that same goal. If you are going to own your data, you also have to stop other people from using it against you.
This is the setup I run today. For each piece I explain what I do, why I do it and where you can check the claim yourself. None of this is theory. It is what sits on my accounts, in my wallet and on my desk right now. Start with whatever you can and add the rest over time. The layering is the point. No single control has to be perfect if the next one catches what slips through.
A note on the products here: I bought every item in this post with my own money and I actually own and use each one. Nothing is sponsored, and none of the links are affiliate links. These are my recommendations based on my own use and experience. I do not recommend anything I have not used myself, and if that ever changes I will say so.
Freeze your credit at all three bureaus
What I do: I keep a credit freeze in place at all three bureaus, Equifax, Experian and TransUnion. Where a bureau also offers a free lock, I use that too, but the freeze is the one that matters.
Why: While a freeze is in place, nobody can open a new credit account in your name, including a thief holding your Social Security number. Since a 2018 federal law, placing and lifting a freeze is free at all three bureaus and it does not affect your credit score. When I need to apply for something, I lift the freeze at the one bureau that lender uses, then put it back.
Freeze vs lock: These get mixed up on purpose. A freeze is free and guaranteed by federal law. A lock is a product the bureaus sell, and it can come with monthly fees. Use the freeze. If a free lock is offered on top for convenience, fine, but do not pay for a lock thinking it replaces the freeze.
Monitoring on top: I pay Experian directly for alerts and monthly monitoring, but you often do not have to. Many banks and card issuers include credit monitoring free. Capital One CreditWise is one example. Check what you already have before you pay for anything.
Benefit: This is the single strongest step, and it costs nothing. A frozen file is the difference between a thief opening ten accounts in your name and a thief getting turned away at the door.
A different password for every account, kept in a vault
What I do: Every account gets its own password. No duplicates, ever. I keep them in a password vault, Proton Pass in my case. Bitwarden and 1Password are both good choices too. I do not use the password store built into a browser or the operating system.
Why: Password reuse is how one leak becomes ten. Attackers take username and password pairs from one breached site and replay them everywhere else, which is called credential stuffing. A unique password per site means a breach at one vendor stays contained to that one vendor. NIST guidance backs this approach: length matters more than forced symbol soup, and password managers are encouraged, not discouraged.
Why not the browser or OS store: A dedicated vault keeps your secrets in one hardened, portable place instead of scattered inside a browser profile that is signed in everywhere you go. It also moves with you across operating systems instead of locking you into one ecosystem. For one reason to keep passwords out of the browser, see Microsoft Edge Held Your Passwords in Plain Text and Called It a Design Decision.
I have written more on this already: Why You Need a Password Manager (And How to Use One Right) and Mastering Strong Passwords.
Hardware security keys where possible
What I do: I use YubiKeys for login wherever a service supports them. I register more than one key per account and keep the backups locked away somewhere physically secure, so losing one key never locks me out.
Why: A hardware key is phishing-resistant. It uses the FIDO and WebAuthn standards, which tie your login to the real website. If you land on a convincing fake login page, the key simply refuses to authenticate, because the site is wrong. Codes from SMS or an authenticator app do not have that protection. They can be phished on a fake page or stolen through a SIM swap. CISA calls FIDO the gold standard for exactly this reason.
On backups: Register at least two keys on every account that allows it. One lives with me, the backups stay locked up. A single key is a single point of failure, and you do not want to discover that after you lose it.
Related reading: Two-Factor Authentication: What It Is and How to Set It Up.
Throwaway email aliases
What I do: My password manager can generate unique, disposable email aliases for one-off or junk uses. I make one when a site demands an address I do not trust, then delete it when I am done.
Why: Your email is the master key to your identity. It is where password resets land. Handing the same real address to every website means any one of them can leak it, sell it or get breached, and now that address is loose. A unique alias per vendor flips that around. If spam or a breach notice shows up on an alias, I know exactly who leaked it, and I delete that one alias without ever touching my real inbox.
Benefit: It contains the damage, kills spam at the source and breaks the cross-site tracking that quietly links your accounts together by your email address. For the bigger picture on why your email provider matters, see Why You Should Ditch Gmail (And What to Use Instead).
Scrub yourself from data brokers
What I do: I pay for a broker removal service that hunts down my personal information across the data broker sites and files removal requests for me. I use DeleteMe. It runs a first sweep, then keeps checking on a schedule because brokers relist you over time.
Why: Data brokers are the companies that quietly build and sell profiles on you: your name, past addresses, phone numbers, relatives and more. Anyone can look you up, and that same data feeds scams, spam and the kind of doxxing that starts with a single search. You can opt out by hand at each broker, and it is free to do, but there are hundreds of them and they refill the pond as fast as you drain it. A service automates the grind and repeats it, which is the part I do not have time to keep up with myself.
Worth knowing: No service removes you from everywhere. Brokers come and go, and some fight removal. Treat this as steady maintenance that shrinks your exposure, not a one-time wipe. If you would rather not pay, you can do the same opt-outs yourself with patience.
On price: DeleteMe runs a discount for Dave Ramsey’s audience. His team shares a code on his videos from time to time, so if you already watch him, look for it before you pay full price. Incognito is another service in this space. I have not used it myself, so I am only naming it as an option to compare, not a recommendation.
Benefit: Less of you floating around on lookup sites means fewer starting points for a scammer or a stalker, and a lot less spam that traces back to a broker selling your number.
Virtual cards for payments
What I do: I no longer hand my debit card to anyone. I use Privacy.com virtual cards. Most are merchant-locked, meaning one dedicated card per vendor, each with a spending limit. For one-off purchases I use single-use cards that die after the first charge.
Why: A merchant-locked card only works at the one vendor it is tied to, so a stolen number is worthless anywhere else. I set each limit to my normal spend, so a charge outside that range gets declined automatically. If a vendor is breached, I close that one card and issue a new one when it is safe, and everything else keeps working. My actual bank account is never exposed to the merchant at all.
Worth knowing: Privacy.com is a US service and links to your bank or debit card behind the scenes. The point is that the merchant never sees the real thing.
Benefit: It turns a card breach from an emergency into a two-minute cleanup. There is a privacy angle too. When vendors can tie every purchase to the real you, they can price accordingly, which I covered in Surveillance Pricing.
USB data blockers, charge only
What I do: I never plug my phone into a port I do not own and control without a charge-only adapter in between. That covers public charging kiosks, a friend’s computer, a work machine I am only borrowing for power and my own car.
Why, for public ports: A USB port carries data as well as power. A charge-only adapter physically has no data pins, so only power gets through. This guards against juice jacking, where a tampered port tries to pull data or push malware while you charge. I will be straight about this one: the FCC describes juice jacking as a demonstrated risk with no confirmed public cases yet. I treat the blocker as cheap insurance, not a reason to panic.
Why, for the car: This one is not hypothetical. Plug a phone into most modern cars and the infotainment system pulls your contacts, call logs and text messages as part of pairing. That data then lives in the car, and cars are shipping personal and driving data off to brokers and insurers. A charge-only adapter lets the phone take power without handing any of that over. I covered the tracking side of this here: Your Car Is Selling How You Drive to Your Insurance Company.
A Faraday sleeve for when a device should go dark
What I do: A signal-blocking sleeve, like the Refuge Ghost Sleeve, acts as a Faraday cage for a phone or a key fob.
Why: A device inside the sleeve cannot send or receive cellular, GPS, WiFi, Bluetooth or NFC. No location logging, no remote pings, no relay attack on a car key fob. It is useful for travel, for sensitive meetings or any time you want a device truly offline instead of trusting a setting to do it.
Benefit: It is an off switch you can actually trust, because it is physics, not a toggle that some app can quietly override.
Physical theft protection plus full disk encryption
What I do: I run a BusKill magnetic breakaway cable. One end connects to the laptop, the other is anchored to the metal arm of my table. If someone grabs the laptop and walks, the magnetic link separates and triggers the machine to lock or shut down. That sits on top of full disk encryption.
Why: Full disk encryption, LUKS on Linux, protects data at rest. Once the machine is powered off, a thief cannot pull the drive and read it on another computer, and cannot boot it without the key. The whole disk is scrambled, not just a folder. BusKill closes the one gap that encryption leaves open, which is a machine stolen while it is unlocked and running. The moment the cable breaks, the session dies and you are back to an encrypted brick.
Honest note: I am still new to BusKill, so I will not overstate what it does beyond this. Read their site for the exact trigger options. It is open source, which is a big part of why I trust the concept enough to run it.
Go deeper: For what encryption at rest actually protects against, read Encryption in Transit and At Rest. And for why it matters who holds the keys, read BitLocker and Microsoft Accounts: Why Your Encryption Keys Aren’t Really Yours.
Put it together
None of these is a silver bullet, and that is the point. Layered together, one failure is not game over. A phished password hits a wall at the hardware key. A breached vendor only burns one virtual card and one email alias. A stolen laptop is an encrypted brick. A frozen credit file turns a leaked Social Security number into a dead end.
Start with the free wins that cover the most ground: freeze your credit at all three bureaus, put a unique password on every account inside a real vault and turn on MFA with a hardware key. Add the rest as you go.
If you are looking at all this thinking it takes money or a degree, it does not. I never went to college. I learned this from library books, from friends who were willing to teach me, from free tutorials online and from salvaged computers other people threw away. I used to sit in the coffee shop at a bookstore and read whatever I wanted to learn about for as long as they let me, and the only cost was a coffee I would have bought anyway. The gear on this page is what I use now, but none of it is the reason I know any of this. Time and effort are free, and they are the only thing that ever really mattered.
This post covered identity. The follow-up moves to the devices and the network they sit on, clean Linux installs, camera covers, a throwaway number and a segmented home network: Locking Down Your Devices and Your Network, Part Two.
Related reading on this site
- Locking Down Your Devices and Your Network: The Privacy Setup, Part Two
- Why You Should Ditch the Microsoft Account and Stop Using Admin
- Client-Side Scanning: Reading Your Messages Before You Send Them
- How Police Buy Their Way Around the Fourth Amendment
Verify these claims yourself
- FTC, credit freezes and fraud alerts: consumer.ftc.gov/articles/credit-freezes-and-fraud-alerts
- FTC, why a freeze beats a paid lock: consumer.ftc.gov, free credit freezes are here
- FTC, what data brokers are and how they profile you: ftc.gov, data brokers report
- NIST SP 800-63B, password guidance: pages.nist.gov/800-63-3/sp800-63b.html
- CISA, more than a password and phishing-resistant MFA: cisa.gov/MFA
- FIDO Alliance, how the standard works: fidoalliance.org
- FCC, juice jacking and charge-only cables (archived copy, the FCC has since restricted the live page): FCC via the Internet Archive
- Krebs on Security, why juice jacking keeps coming up: krebsonsecurity.com
The tools I mention
Bought with my own money, owned and used by me. No sponsorships, no affiliate links.
- Credit bureaus: Equifax, Experian, TransUnion
- Password managers: Proton Pass, Bitwarden, 1Password
- Hardware security keys: Yubico
- Virtual cards: Privacy.com
- Data broker removal: DeleteMe
- Faraday sleeve: Refuge Ghost Sleeve
- USB data blocker, charge only: CableMart charge-only adapter
- Dead man switch for a laptop: BusKill
// comments