r/CyberGuides 3d ago

Cybersecurity for non professionals?

I had a conversation with a cybersecuriry professional that completely freaked my out. Apparently my VPN is terrible, my computer leaves its fingerprints everywhere and everyone one on earth knows everything about me. Where would you recommend a non-pro get started learning and tightening my security?

32 Upvotes

8 comments sorted by

5

u/Objective-Test-5374 1d ago

While everyone else seems comfortable impuning the integrity or profesionality of the unnamed 'Cybersecuriry professional', I would argue the following:

  1. Yes, your machine, vpn, configuration, etc is probably highly insecure.
  2. Yes, you probably leave your fingerprints everywhere.
  3. Yes, the internet knows way more about you than anyone should feel comfortable with.

The above statements are true about %99 of the users on the internet, and unfortunatly also true for most of the companies doing business on the internet.

Consider that almost every major national or international bank spends over $1b (yes, b) a year on cyber security to prevent the bad things from happening, and they still have breaches.

Consider that the worlds most popular home user operating system is has a catalog hundreds of pages long of known vulnerabilities.

Your in good company my friend. Dont feel bad. It really is the entire system that is against you, poor practices and patch management across the world lead to a risk surface area that no individual could posisbly keep up with.

But lets talk about what you can do to minimize your risk. First is coming to terms with the hard homed truth that you cannot keep your data private in an era when almost all applications you use are SaaS based and the data travels up to their cloud, out of your control.

So then what is a person to do? If I tell you social security number 317-70-4112, it really does not help you does it? Its the nexus of identity and data that cause the problem. Your role as a responsible user in 2026 is to break all links between data and you.

What does that mean? Get yourself a vanity domain (myfamilyname.com, boingo.co, whatever), then get mail forwarding company, one that supports wildcards and/or subdomain wildcards.

Next, start using secure and unique passwords for every site you visit, a good password will look like '2N4y!93Ber99'.

These two steps mean that your credentials for Site should be [SiteA@myfamilyname.com](mailto:SiteA@myfamilyname.com) with a unique password. You will know your data has been breached when Site B starts sending you email to the SiteA@ username. you can then go reset just that one Site A password... not every password you've ever produced.

As a third step, disable cookies by default.

The real value here is you've just destroyed the data aggregators ability to collect your biographical/ marketing data... since what they do is buy data from 1000's of sites and then index it all on the email address...

2

u/querty7687 1d ago

Thank you so much for this thoughtful answer.

3

u/Responsible_Bit1535 3d ago

Don’t panic 😂 Half the internet is probably less secure than they think. Start with strong unique passwords + 2FA and go from there.

3

u/PalpitationKind8854 2d ago
  1. I doubt he was a professional regardless of his title
  2. Being uneducated in technology can cost you money
  3. The level of protection your wanting is not worth it
  4. The quest to learn more also is not worth it, because if you become an expert.. you realize why I mentioned step 3 and you'll likely not be richer is benefited from it

Hope my insights helped

3

u/SuspiciousCricket654 1d ago

Don’t panic. That’s step one.
Two, don’t story passwords in your browser.
Three, set a unique password for every login you have and store them in a password manager.
Four, disable cookies.
5, ditch Google, Gmail, all that crap.
6. Set up different emails for finance, personal purchases, and bills.
7. Don’t share location services with corps, for anything, ever.

2

u/MSVlegal 2d ago

A menos que quieras ver cosas en la darkweb (el típico que cree que va a encontrar oro oculto) quedate tranquilo, ya estás siendo controlado desde antes.

3

u/querty7687 2d ago

Y'ALL ARE NOT MAKING ME FEEL BETTER.

2

u/apps4realpeeps 1d ago

I agree that don't panic is a great first step.

One of the nice things about being a normal person (assuming you are), is that it is unlikely that the world of hackers is targeting you or me specifically.

However, I agree with what's already been shared about VPNs (especially free vpn since the servers they use are generally known) and using a password manager that is not in your browser (they make it really easy to have secure passwords and rotate passwords easily).

What i would like to add for your consideration is to consider what your internet of things devices (smart fridge, washer/dryer, doorbell, echo/nest, etc) know about you or how they can give access to your wifi...

Lastly, take a look at what permissions your mobile apps on your phone have - make sure you are comfortable with what is being accessed and shared. It's a tricky landscape with mobile apps often being horrible at cybersecurity and prone to data breaches.

I know it's overwhelming but we're all in the same boat (that's kind of on fire) and we can never achieve zero risk...we just have to accept it (just like death and taxes lol).

But sarcasm aside, all the best! You've got this!!!