Back to Silas S. Brown's home page

Precautions I take online

When an anxious autistic adult asked me for rules to stay safe online, I replied that perhaps a professional therapist or publicity agent might be more qualified to help with their specific situation than a computer scientist (which is a bit like asking a car designer about whom you should visit by driving) but here's what I do:
  1. I never publish or give strangers my street address---no address and no photograph of the house. I don't want someone who doesn't like something I said online to make problems at the house, nor to figure out when I'm away and burgle it. Sometimes I've published papers that insist on displaying an address: the Computer Lab said I can use their address for that. Trusted businesses needing to deliver things can have my real address, but not just anybody. Because I have an unusual name, I opted out of being on the edited version of the electoral register so I'm not listed by companies like TraceGenie. Real authorities can still find me via the unedited register. (Yes, TraceGenie et al do say they have an address for my name, but if you actually pay, they'll tell you where I was in 2001---I'm not there anymore so don't bother.)
  2. I don't give out my date of birth. I don't do birthday celebrations, but if I did I wouldn't post one because date of celebration minus age in years equals date of birth, which is too useful for a liar to pretend to be you or your relative when talking to someone who has it on their screen. It annoys me how platforms like Telegram repeatedly nag for a date of birth to broadcast to all contacts: I believe whoever designed that is irresponsible and makes me hesitant to recommend the entire platform. Some people enter a fake one like 1st January 1970 (messes with Unix engineers) or 1st April (April Fools Day) or 29th February (a Pirates of Penzance reference) but I prefer to leave it blank especially when a rule says all information must be real: liars will lie but I don't have to risk joining them. Just no to date of birth, unless it's a genuine government department or a bank or a doctor etc. Verification services can have it only if I've confirmed it won't be published.
  3. I don't publish my mobile phone number---I do let some people have it, but only if I'm pretty sure they too will not publish it online. I might be able to block harassing calls, but a determined criminal who knows my number and knows too much about me might be able to convince a phone company worker that they're me trying to recover a stolen phone, and from there take over my number and use it to get into other platforms. This is unlikely, but multiplied by the large numbers of people who might read a public post it's a risk I'd rather not take, and that's why I prefer messaging platforms with usernames to messaging platforms with just phone numbers. The reason why I'm not quite as strict with this rule as I am with my address is that changing my mobile number is easier than moving house if I find somebody did post it, but I'd still rather avoid the hassle.
  4. Other people's names: only with permission. I try to remember to ask permission before posting or giving away names, contact details etc of any other person who isn't me; after all they should be in control of their information. If I'm posting a picture to any public platform and the picture has people in it, I censor out all non-public faces that I haven't explicitly been given permission to post.
  5. Strictly no intimacy. (Well I wouldn't do this anyway but it's worth saying.) Even if the country says it's legal for adults, it's still an incredibly bad idea: it leaves you open to manipulation or blackmail, especially if it turns out they're not who they say they are (there are very well documented scams involving this). If someone tries to push you into it, block and report (or if it's someone you know, my suggestion would be don't block because that might destroy evidence, just stop interacting and show your device to someone who can help you report it). Asking for my address or date of birth would just get a 'no' (not their fault they don't know it's a bad idea) but asking for intimacy is far more serious.
  6. Remember online "friends" might just be contacts. If there's one thing I wish I could get all the companies to do, it would be replacing the word "friend" with "contact" on all platforms everywhere. I mean, the Contacts list on your mobile phone hopefully isn't called "Friends" so why call it that on another platform? A real friend can know where you live; an online contact should not. Yes you can be friendly and you can even call each other "friends" but remember the platforms are using that word differently and you can and should walk away from any conversation that's making you uncomfortable or taking up too much time. (Some people do restrict their online friends to people they are actually friends with in real life, but I'm assuming if you're reading this page it's because you want to talk with others but carefully.)
  7. The "front-page news" test. If I post something online, how would I feel about my words becoming front-page news? If the answer is "it would embarrass the newspaper that they made a big deal out of nothing" then that's different from "it could actually land me in trouble for the rest of my life" but worth thinking about just in case somebody actually forwards something to a journalist on a slow-news day. Remember also that people can put together posts from different days to make a more detailed picture than you planned. Some people mitigate this by using a pseudonym but you'd better make sure you have good operational security if relying on that. (Yes I have in the past used pseudonyms and later decided it's OK to let the op-sec lapse, but that's a decision not made lightly. At any rate it can be a way to postpone the "do I want my name to this" decision if you're careful to maintain the separation until you know, having consulted professional advice if necessary.)
  8. If someone claims to work somewhere, I'll wait till I've seen an email from their work address before believing it and I will check that the domain (after the @) is owned by the real version of the company or organisation. It's still possible to fake From headers but it's getting harder thanks to SPF especially if you know how to check full headers or are using an email system that does it for you. But even if they really work there, that still doesn't mean they can bypass your red lines.
  9. Stay on guard around posts too. Although most of this page has focused on direct interactions with people online, another danger is believing misleading articles (even without interacting with their authors or others)---I suggest you try Cambridge's Bad News Game which puts you in the position of a fake-news producer to raise your awareness of it.

Rules that don't work

I've seen people try to use these as rules but they don't work:
  1. Talk only with people of similar age to you? That's a non-starter if people lie about their age. Sure, if someone's claimed age makes you feel uncomfortable it's up to you if you want to talk to them or not, but you must assume people who say they are a similar age to you could be lying so don't drop any guard based on claimed age.
  2. Ask for pictures and see if they look genuine? Sorry, but either you'll be taken in by fake and/or stolen pictures anyway, or you'll go to the other extreme and cut off an actually-good contact because something looks off about an actually-normal picture (yes I've seen this happen). Some people feel they can judge by looks but this does not work online---you need another way.
I think rules that don't work actually increase your risk if they give you a false sense of confidence in a meaningless result, so don't just add more ideas thinking "more must be better" but focus on good practices that work.
Copyright and Trademarks: All material © Silas S. Brown unless otherwise stated.
Javascript is a trademark of Oracle Corporation in the US.
Telegram is a trademark of Telegram Messenger LLP.
TraceGenie is a registered trademark of 1st Locate UK Ltd.
Unix is a trademark of The Open Group.
Any other trademarks I mentioned without realising are trademarks of their respective holders.