October 9, 2026
Shrinking Your Digital Footprint: A Practical OpSec Guide
How to clean up your data, lock down your devices, and stay low-profile online, with a basic look at Tor.

By Yehia Zakaria
9 min read
You can't be invisible online. What you can do is make yourself expensive to track, so most adversaries move on to easier targets.
This guide walks through threat modeling, cleaning up what's already out there, swapping your tools, hardening your browser and devices, and the basics of Tor. You don't need to do everything. Pick what fits your situation.
1. Threat Modeling (Keep It Simple)
Before installing anything, answer five questions. Write the answers down, even briefly. Everything else follows from them.
- What am I protecting? Home address, real name, browsing history, finances, location, messages.
- Who am I hiding it from? Advertisers, data brokers, an ex or stalker, an employer, hackers, a government.
- What can they actually do? Buy my data for a few dollars, dox me, phish me, subpoena my provider, run mass surveillance.
- What happens if I'm exposed? Spam, doxxing, swatting, job loss, physical danger.
- How much inconvenience can I tolerate? "Install an extension" is very different from "run a separate OS for everything."
If your adversary is advertisers and data brokers, sections 2 to 5 are enough. If it's a determined individual or a state-level actor, you need everything here plus professional help.
VPN vs Tor vs Email Aliasing
These solve different problems, so they stack rather than compete.
VPN
- What it does: Hides your traffic from your ISP and swaps your IP for the VPN's.
- Good against: ISP snooping, public Wi-Fi risks, basic IP tracking, geo-blocks.
- Where it fails: You're trusting the VPN company instead of your ISP. It doesn't stop cookies, fingerprinting, or tracking when you're logged in.
- Usability cost: Low. It's a toggle, with somewhat slower speeds.
Tor
- What it does: Routes traffic through three relays so no single relay knows both who you are and what you're doing.
- Good against: Sites and observers tracing you by IP, and censorship.
- Where it fails: It won't help if you log into personal accounts or install random add-ons. Exit relays can see unencrypted traffic, and many sites block Tor.
- Usability cost: Medium to high. It's slower, there are more CAPTCHAs, and some sites break.
Email aliasing
- What it does: Gives every site its own forwarding address.
- Good against: Data brokers, spam, breach correlation, tracking by email address.
- Where it fails: It doesn't hide your IP or browsing, and the alias provider can see mail passing through.
- Usability cost: Low. Set it up once and it's mostly automatic.
2. Cleaning Up Existing Data
Run a passive OSINT check on yourself
Do this in a private window, logged out, ideally on a VPN so results aren't personalized to you. Swap in your own details:
"Firstname Lastname"
"Firstname Lastname" "City"
"Firstname Lastname" site:linkedin.com OR site:facebook.com OR site:x.com
"Firstname Lastname" filetype:pdf
"you@email.com"
"555-123-4567"
"Firstname Lastname" intext:"address" OR intext:"phone"
"yourusername" -site:yourknownsite.com"Firstname Lastname"
"Firstname Lastname" "City"
"Firstname Lastname" site:linkedin.com OR site:facebook.com OR site:x.com
"Firstname Lastname" filetype:pdf
"you@email.com"
"555-123-4567"
"Firstname Lastname" intext:"address" OR intext:"phone"
"yourusername" -site:yourknownsite.comUsername correlation. If you reuse handles, anyone can link your accounts. Tools to check:
- Sherlock and Maigret are open-source tools that check a username across hundreds of sites.
- WhatsMyName does the same in your browser, with nothing to install.
Search your old usernames, emails, and phone numbers too, not just your name. Also reverse-image search your profile photos with Google Lens or TinEye. PimEyes searches by face, but uploading your own face to it carries its own privacy trade-off.
Check breach exposure
- Check every email you've used at Have I Been Pwned (haveibeenpwned.com) and turn on notifications.
- Change any exposed passwords and move to a password manager, such as Bitwarden or KeePassXC, with a unique password for every account.
- Enable 2FA with an authenticator app or hardware key (YubiKey). Avoid SMS where you can.
Delete old accounts
JustDelete.me is a directory of direct deletion links, rated by difficulty. To find forgotten accounts, check your password manager and search your inbox for phrases like "welcome to" and "verify your account."
Before deleting, edit your profile and replace your real details with junk. Some services keep data after "deletion," so this costs you nothing.
Opt out of data brokers
Brokers like Whitepages, Spokeo, Radaris, BeenVerified, and LexisNexis compile and sell your address, relatives, and phone history. You have two options:
- Manual (free): Search yourself on each site, find its opt-out page, and submit the form. It takes hours, and listings often reappear, so repeat it every few months.
- Paid services (DeleteMe, Incogni): They send removal requests continuously and report back. This is worth considering if you're in the US.
Manual tips:
- Use an email alias for the confirmation emails.
- Keep a simple spreadsheet of sites, dates, and status.
- Use the data-request or opt-out portals that LexisNexis and similar aggregators offer.
- Check which privacy laws apply to you (CCPA in California, GDPR in the EU and UK). They give you legal grounds to demand deletion.
Use Google's "Results about you"
Google lets you request removal of search results showing your phone number, home address, or email.
- Go to myactivity.google.com/results-about-you, or find it in the Google app under your profile.
- Add your details so Google can monitor for them and alert you.
- Submit removal requests for specific results.
This removes the result from Google Search only. The page still exists, so you'll need to contact the site owner or host to remove the source.
3. Privacy Alternatives: The Swap List
Don't switch everything at once. Pick the two or three swaps that matter most for your threat model and add more later.
Search: Replace Google with DuckDuckGo, Brave Search, or SearXNG. DDG and Brave are the easiest. SearXNG is a self-hostable meta-search engine that doesn't profile you.
Browser: Replace Chrome or Edge with Firefox (hardened), Brave, or Tor Browser. Use Firefox for daily browsing and Tor Browser for sensitive sessions.
Email: Replace Gmail or Outlook with Proton Mail or Tuta. Both offer end-to-end encryption between their own users, and Tuta also encrypts subject lines and contacts.
Chat: Replace WhatsApp, Messenger, or SMS with Signal or Session. Signal is the best default. Session needs no phone number and routes messages through an onion-style network.
DNS: Replace your ISP's default with Quad9 (9.9.9.9), Cloudflare (1.1.1.1), or NextDNS. Quad9 blocks known-malicious domains. NextDNS offers custom filtering and logs you control.
Passwords: Replace browser-saved passwords with Bitwarden or KeePassXC.
Maps: Replace Google Maps with Organic Maps or OsmAnd, which work offline with no account.
Cloud storage: Replace Google Drive or iCloud with Proton Drive, or put Cryptomator on top of any cloud so files are encrypted before upload.
4. Browser Hardening and Masking Your Identity
Essential Firefox tweaks
- Enhanced Tracking Protection โ Strict (Settings โ Privacy & Security). This blocks trackers and fingerprinters, and includes third-party cookie isolation.
- Delete cookies and site data when Firefox closes. This flushes tracking state automatically.
- Clear history on close (Privacy & Security โ History โ custom settings).
- HTTPS-Only Mode. This forces encrypted connections.
- Turn off optional telemetry under Firefox Data Collection.
- Disable WebRTC by setting
media.peerconnection.enabledtofalseinabout:config. It stops your real IP leaking past a VPN, but it can break video calls. - Resist fingerprinting by setting
privacy.resistFingerprintingtotrueinabout:config. It makes you look more generic, but may break some sites and change your time zone and window size.
Shortcuts: The Arkenfox user.js project applies a researched set of hardened settings. It's strong but opinionated, so read its wiki first. LibreWolf is a pre-hardened Firefox fork with less setup.
Key extensions
- uBlock Origin: Turn on advanced mode (Settings โ "I am an advanced user") to block third-party scripts and frames by default, then whitelist what you need.
- Privacy Badger: It learns and blocks trackers heuristically, and complements uBlock.
- Multi-Account Containers: Isolates sites in separate cookie jars. Put social media in its own container.
Don't stack too many extensions, because your extension list is itself a fingerprint.
Isolate your identity
The goal is that your real name, email, and card never touch the sites you use every day.
Email aliases. Use one alias per site. If one starts getting spam, you know exactly who leaked it, and you can kill it without touching your real inbox.
- SimpleLogin (owned by Proton): open source, supports custom domains, can reply from the alias.
- addy.io (formerly AnonAddy): open source, generous free tier, self-hostable.
- Firefox Relay: easy browser integration, limited free aliases.
- Apple Hide My Email: built in if you have iCloud+.
Virtual cards. Privacy.com (US only) creates virtual cards with spending limits and can lock a card to a single merchant. Revolut and some banks offer similar disposable cards elsewhere. Paired with an alias, you can sign up without exposing your real email or card number. Shipping addresses still need separate handling, such as parcel lockers or a mail-forwarding service.
Phone numbers. Use a VoIP number (Google Voice, MySudo, Jmp.chat) for signups instead of your real mobile number. Some services block VoIP numbers.
5. Reducing System Telemetry and Network Leakage
Telemetry settings by platform
Windows 10/11
- Settings โ Privacy & security โ Diagnostics & feedback: turn off optional diagnostic data, tailored experiences, and inking and typing improvements.
- Turn off the advertising ID and activity history, and disable Recall if it's present.
- Use a local account where possible.
- O&O ShutUp10++ gives you a guided list of toggles.
macOS
- System Settings โ Privacy & Security โ Analytics & Improvements: turn everything off.
- Turn off Personalized Ads under Apple Advertising.
- Review Location Services โ System Services.
- Enable FileVault and the firewall.
- Add LuLu (free) to control outbound connections.
Android
- Settings โ Google โ Data & privacy: pause Web & App Activity and Location History.
- Delete your advertising ID and turn off usage and diagnostics.
- Audit app permissions with the Privacy Dashboard.
- For the strongest option, GrapheneOS on a Pixel is the gold standard.
iOS
- Settings โ Privacy & Security โ Analytics & Improvements: turn off.
- Under Tracking, deny "Allow Apps to Request to Track."
- Turn off Personalized Ads and review Location Services.
- Consider Lockdown Mode if you're a high-risk target.
Network-level fixes
- Encrypted DNS: Set NextDNS, Quad9, or Cloudflare (DoH/DoT) at the OS or router level so your ISP can't log every domain you visit.
- A reputable VPN: Mullvad (no email needed, accepts cash) or Proton VPN. Both have undergone independent audits. You're shifting trust from your ISP to them.
- Router-level blocking: Pi-hole or AdGuard Home blocks tracker domains for every device on your network, including smart TVs.
- MAC randomization: On by default on modern iOS and Android. On Windows, check Settings โ Wi-Fi โ Random hardware addresses.
- Outbound firewall: LuLu or Little Snitch shows which apps are phoning home.
- Disk encryption: BitLocker, FileVault, or LUKS protects your data if a device is lost or seized.
- Updates: Keep your OS, browser, and router firmware current. Most real-world compromises exploit known, already-patched bugs.
Reality check:_ On Windows, macOS, and stock Android or iOS, you can reduce telemetry but not eliminate it. If that's not acceptable for your threat model, look at Linux, GrapheneOS, or Tails._
6. Tor and Dark Web OpSec Basics
What Tor is and isn't
Tor hides where you are from the sites you visit, and what you're visiting from your ISP. It does not anonymize you if you hand over identifying information yourself. Using Tor Browser and visiting .onion sites is legal in most countries, and journalists, activists, and everyday privacy-minded people use it daily.
Basic Tor hygiene
Do:
- Download only from torproject.org, and verify the signature if you can.
- Use the Safer or Safest security level for sensitive sessions.
- Leave the window at its default size. Maximizing it makes you more unique.
- Use bridges (obfs4, Snowflake) if Tor is blocked or you don't want your ISP to see you using it.
- Use New Identity between unrelated sessions.
Don't:
- Install random "Tor" apps from unofficial sources.
- Add extra extensions, since they change your fingerprint.
- Log into personal accounts or use your real name anywhere.
- Torrent over Tor. It leaks your real IP and strains the network.
- Open downloaded documents (PDF, DOCX) while online, because they can phone home.
Higher-risk setups
- Tails OS boots from a USB stick, routes everything through Tor, and is designed to leave no trace on the machine. It suits journalists, whistleblowers, and anyone facing a serious adversary.
- Whonix is a VM-based setup that isolates Tor traffic from your main system.
- Don't combine a VPN with Tor unless you understand why. For most people it adds complexity without a clear benefit.
Using onion sites safely
- Verify addresses from trusted sources, such as the site's clearnet page or an official directory. Fake links and phishing clones are common.
- Never reuse usernames, passwords, or writing style from your normal online life.
- Assume nothing is private by default. Many onion sites are scams, honeypots, or malware vehicles.
- Don't share personal details, including your location, job, or schedule.
- Use PGP for sensitive messages on platforms that support it.
- Avoid illegal marketplaces. Beyond the legal risk, they're a primary source of scams and law-enforcement stings, and OpSec failures there are what lead to arrests.
The most common ways people get deanonymized
- Logging into a personal account over Tor
- Reusing usernames or emails
- Browsing at a low security level with JavaScript enabled
- Mixing Tor and non-Tor sessions under the same identity
- Human error: oversharing, posting photos with metadata, mentioning real-life details
A Realistic Order of Operations
- Password manager and 2FA on important accounts (1 to 2 hours)
- Switch browser and install uBlock Origin (30 minutes)
- Check Have I Been Pwned and delete old accounts (1 to 2 hours)
- Set up email aliases for new signups (30 minutes)
- Opt out of data brokers, or subscribe to a service (2 to 4 hours)
- Telemetry settings and encrypted DNS (1 hour)
- Install Signal (15 minutes)
- Tor, Tails, or advanced setups, only if your threat model calls for them
Privacy is a habit, not a one-time project. Re-check your footprint every few months, because brokers re-list you and new accounts pile up.
โ Yehia Zakaria
- Avoid illegal marketplaces. Besides the legal risk, they're a primary source of scams and law-enforcement stings, and OpSec failures there are what lead to arrests.
Common ways people get deanonymized
- Logging into a personal account over Tor
- Reusing usernames or emails
- Enabling JavaScript-dependent features at a low security level
- Mixing Tor and non-Tor sessions with the same identity
- Human error: oversharing, posting identifiable photos with metadata, talking about real-life details
A Realistic Order of Operations
Priority Action Time 1 Password manager + 2FA on important accounts 1โ2 hrs 2 Switch browser, install uBlock Origin 30 min 3 Check HIBP, delete old accounts 1โ2 hrs 4 Set up email aliases for new signups 30 min 5 Opt out of data brokers (or subscribe to a service) 2โ4 hrs 6 Telemetry settings + encrypted DNS 1 hr 7 Signal for messaging 15 min 8 Tor Browser, Tails, or advanced setups, if your threat model needs them As needed
Privacy is an ongoing habit, not a one-time project. Re-check your footprint every few months, because brokers re-list you and new accounts accumulate.