Online Privacy: A Practical Threat Model
A useful privacy approach starts with who you're actually trying to protect yourself from and what data matters most — not a generic checklist that treats every threat and every reader the same.
Practical online privacy guides covering IP data, browsers, VPNs, DNS, WebRTC, tracking, and fingerprinting.
A useful privacy approach starts with who you're actually trying to protect yourself from and what data matters most — not a generic checklist that treats every threat and every reader the same.
Hiding your IP address changes what a website can infer about your location and network — it doesn't touch account logins, browser fingerprinting, or other signals that remain fully visible regardless.
Browser privacy spans far more than clearing history — storage, permissions, fingerprinting exposure, sync settings, extensions and update status all shape what a browser actually reveals.
A VPN doesn't eliminate what's visible about your connection — it redistributes visibility, moving what your ISP could see to your VPN provider instead, while other observers keep their own separate view.
Browser fingerprinting identifies you through the combination of many ordinary browser characteristics, not any single trait — uniqueness comes from the combination, which is why it works even without cookies.
Device fingerprinting extends beyond the browser to mobile advertising IDs, app telemetry and hardware traits — a broader category than browser fingerprinting, with its own distinct correlation risks.
Canvas fingerprinting exploits tiny, consistent rendering differences between devices — a specific, well-studied fingerprinting technique with known browser-level defenses available.
IP-based tracking links visits through a shared or repeated address — but shared addresses, address changes, and correlation with other signals all limit how confidently an IP alone can identify one specific person.
IP, GPS, Wi-Fi positioning and account history each offer different precision and require different permissions — treating them as one undifferentiated 'location tracking' signal misses meaningful, practical distinctions.
Browser tracking spans first-party and third-party cookies, tracking pixels, link decoration, storage APIs and fingerprinting — a layered ecosystem that's evolved specifically in response to earlier defenses.
Cookies and fingerprinting differ in storage, deletability, consent requirements, and stability — practical differences that shape which defenses actually work against each.
Incognito mode does not hide your IP address — its real, useful protections are local: no saved history, cookies, or form data after the session ends, not network-level anonymity.