Home/Grown Part II – Building the Veil

How layered security changed the way I used the internet.

In Breaking the Feed I rather casually skipped over what happened during the two years I spent away from Facebook. Gmail gave way to Proton Mail, Chrome disappeared in favour of Brave, Google Search was replaced by DuckDuckGo and somewhere along the way I started learning about VPNs, DNS, browser fingerprinting and the countless other ways information leaks from one service to another.

That paragraph covered rather a lot of ground.

Leaving Facebook had removed one particularly visible problem but what followed was a much deeper exploration of how the modern internet works behind the scenes and how much control I could realistically take back. By the time I eventually returned to Facebook almost two years later, quite a lot had changed. Not Facebook particularly but me.

During those two years I became much more conscious of the machinery operating behind the websites and services I used every day. Advertising networks, analytics platforms, tracking scripts, cookies and numerous other mechanisms were quietly helping to construct connections between one piece of activity and another.

Most of this is largely invisible to the person sitting in front of the screen. You visit a website, read something and leave. What you don’t necessarily see are all the other connections which may have taken place while you were there. Advertising systems, analytics companies and tracking networks can all become involved in loading what appears to be one simple webpage.

There is an enormous industry behind this.

The scale is worth contemplating for a moment. In the UK alone, digital advertising expenditure reached £40.5 billion in 2025. Meta reported more than $196 billion in advertising revenue that same year and Google reported almost $295 billion. This isn’t a cottage industry involving a few companies putting irritating banners at the top of websites. It is a huge global economy built around attracting attention, understanding audiences and making advertising increasingly effective.

That leads to a fairly obvious question which I don’t think most of us asked often enough during the internet’s rapid expansion: if all these services are free, how are they making their money?

There is an old saying that if you aren’t paying for the product then you are the product. Like most sayings it is an oversimplification but there is an important truth lurking underneath it. Facebook doesn’t charge me an entrance fee. Neither does Instagram, Google Search or YouTube. Running services of that scale is spectacularly expensive so the money clearly has to come from somewhere.

In large part it comes from advertising.

That doesn’t mean somebody at Facebook or Google is literally selling a folder with my name written on it to an advertiser. The reality is more sophisticated than that. Platforms can use information about interests, behaviour, activity and audiences to decide which advertisements should appear in front of which people and to measure how effectively those advertisements work.

In that relationship I may be the user of the service but I am not necessarily the customer paying the bill. My attention has value. My behaviour has value. Knowing enough about me to decide which advertisement I am most likely to respond to has value.

Once I properly understood that, online tracking stopped looking like some slightly irritating technical side effect of using websites. There was a reason for it.

It also made me start looking differently at the services I was already using. Email was an obvious one.

For years I had used Gmail without giving the underlying model much thought. Google historically did use the contents of consumer Gmail messages as part of its advertising personalisation system, although it stopped doing that in 2017 and today says Gmail messages are not used to select advertisements.

By then my thinking had moved beyond the narrow question of whether somebody was currently using a particular email to decide which advert to show me. Email can contain an extraordinary amount of personal information: conversations, receipts, travel arrangements, account notifications, medical appointments, financial information, personal relationships and password resets. In many ways an email account becomes one of the most detailed records of a person’s life.

I simply became uncomfortable storing all of that inside an ecosystem whose wider business was so heavily dependent on advertising and behavioural data. That was one of the reasons I moved my personal email to Proton Mail.

Proton approaches email from a different direction. Messages stored in a Proton mailbox are protected using zero-access encryption and messages exchanged between Proton users can be end-to-end encrypted so that only the sender and recipient can read them. There are limits of course. Email arriving from an ordinary external provider cannot magically become end-to-end encrypted before it reaches Proton and basic metadata such as sender and recipient addresses still has to exist for email to work.

Again, perfection wasn’t the point. I preferred the philosophy. If I am entrusting somebody with years of private correspondence, I would rather use a service designed around collecting as little information as reasonably possible and technically restricting access to the contents of my mailbox.

Search engines were another obvious place to look.

Consider the things we type into a search box: health concerns, financial questions, products we’re thinking of buying, places we’re considering visiting, political questions, relationship problems and things we might not dream of asking another human being. Taken individually, a search might mean nothing. Viewed as a history extending over months or years, those searches could potentially form an extraordinarily intimate picture of somebody.

I can’t actually remember the last time I used Google to search for anything. DuckDuckGo has been my normal search engine for years.

The attraction is simple. DuckDuckGo says it doesn’t save or share an individual’s search history or build a profile connecting searches back to that person. It still makes money from advertising but those adverts can be based on what somebody is searching for at that moment rather than a behavioural profile accumulated over time.

Search for guitar strings and you might see an advert for guitar strings. The search engine doesn’t need to know that you looked at an amplifier last Tuesday, watched three guitar videos yesterday and bought a fuzz pedal six months ago in order to reach the conclusion that somebody currently searching for guitar strings might conceivably be interested in buying some.

That distinction is important because advertising itself isn’t necessarily the problem. Tracking doesn’t have to be a prerequisite for advertising. A newspaper can put an advert for a guitar shop next to an article about guitars without first needing to spend six months following the reader around town.

The internet somehow persuaded us that the more information an advertising system knew about somebody, the more normal that became.

DuckDuckGo isn’t a magic anonymity machine and using it doesn’t remove every other source of information about what I do online. It is simply another example of choosing a service whose model better matches what I am comfortable with. For everyday searching I haven’t found that choice particularly difficult either. I changed the default search engine and then largely forgot about it.

That became another recurring theme in all of this. Some privacy improvements require almost no ongoing effort once they have been made.

Not every service was so easy to replace though. YouTube was the obvious exception.

I never really disconnected from it because for what I used it for there simply wasn’t a realistic alternative with the same combination of content, audience and ubiquity. That was an early lesson in pragmatism. Privacy can very easily turn into a purity test where the only acceptable answer is to abandon every large commercial platform immediately but real life is rarely that tidy.

Some services are genuinely useful. Some have become effectively infrastructural and some are simply where the people, communities or material you actually want to reach happen to be. YouTube fell into that category for me.

So I continued using it while trying to reduce unnecessary tracking around it rather than pretending I could remove Google completely from my life. The objective wasn’t ideological purity. It was making better choices where better choices were practical.

My first technical investigations concentrated on the browser. I moved most of my normal browsing to Brave, largely because privacy protections are built into it rather than being something which has to be assembled afterwards. Its Shields system blocks a significant amount of advertising, tracking scripts, third-party cookies and other unwanted material before it gets much opportunity to do anything useful.

At roughly the same time I started using uBlock Origin. I had used conventional ad blockers before but uBlock Origin made me realise that the words ad blocker don’t really describe what these tools do very well.

An advert on a webpage isn’t necessarily just a picture sitting there waiting to annoy you. Loading a modern website can result in connections being made to numerous other services. Some provide perfectly legitimate parts of the site. Others belong to advertising platforms, analytics companies, social media networks or organisations interested in measuring and correlating what people do online.

Those connections can reveal that your browser visited a particular page even though you never consciously interacted with the company receiving the information. Tools such as uBlock Origin can prevent many of those requests from completing and remove unwanted elements from the page itself so that you don’t simply end up staring at large empty boxes where the adverts used to be.

Brave already does a lot of similar work natively so running the two together can be slightly belt-and-braces. At that point, belt-and-braces suited me just fine.

This was the period when I started throwing the privacy kitchen sink at things.

Once you become aware of online tracking there is a slightly dangerous stage where every answer appears to reveal another problem. You discover cookies so you block them. Then somebody mentions browser fingerprinting. Somebody else tells you about WebRTC. Another guide suggests changing half a dozen browser settings. You install another extension, add another blocklist and run another privacy test, only for the privacy test to tell you that your browser is still identifiable.

Then somebody points out that installing an unusual collection of privacy extensions can itself make your browser more distinctive, so you change everything again.

There is always another potential hole.

I experimented with different browsers, extensions and ways of separating activity. Some stayed and some didn’t. Gradually I began to understand what the individual tools were actually doing rather than simply treating privacy as a competition to see how many shields I could fit around a web browser.

Browser separation turned out to be one of the simplest ideas and one of the most useful.

A browser accumulates information as you use it: cookies, login sessions, local storage and various other bits of state which allow websites to recognise that one visit is connected to another. If everything you do takes place inside the same browser profile then all of those activities inhabit the same environment.

Separating them reduces that crossover.

That can be as simple as using one browser for services where you are routinely logged in and another for general browsing. Separate browser profiles can achieve something similar while technologies such as Firefox Containers go further by creating boundaries between particular services inside the browser itself.

It isn’t anonymity. It is compartmentalisation, and sometimes keeping two things apart is considerably easier than trying to make either of them invisible.

I also discovered Mullvad Browser during this period. Developed by Mullvad with the Tor Project, its philosophy is somewhat different from endlessly adding blockers. Browser fingerprinting can distinguish users by combining lots of apparently insignificant characteristics such as screen dimensions, fonts, language, graphics capabilities and details about the browser itself.

One piece of information might tell somebody very little. Combine enough pieces and a browser can become surprisingly distinctive.

Mullvad Browser therefore concentrates heavily on making its users look more alike. That taught me another useful lesson: more privacy software does not automatically equal more privacy. If everybody begins with a deliberately standardised browser and I then customise mine beyond recognition, I may have defeated part of the object.

Brave remained my normal everyday browser while Mullvad Browser became another tool available when I wanted a more deliberately privacy-focused session. Different tools for different jobs rather than one impossibly hardened browser trying to do everything.

The browser could only take me so far though. The next major discovery was DNS.

DNS stands for Domain Name System and it is one of those fundamental pieces of the internet which most people use constantly without ever needing to know that it exists. Humans are good at remembering names such as outpost10.uk while computers ultimately communicate using numerical IP addresses. DNS is essentially the directory which joins the two together.

The traditional comparison with a telephone directory still works quite well. You know the name of the person you want to call but you need something which can tell you their number. When you enter the name of a website your computer asks a DNS server which IP address belongs to it and once it has the answer it can make the connection.

Normally all of this happens invisibly and very quickly. Your internet provider generally supplies a DNS service automatically so most people have absolutely no reason to give it another thought.

Once I understood what was happening, two things immediately interested me. Firstly, DNS provides an extremely convenient point at which to block unwanted traffic. If a computer, phone or smart television asks where a known tracking server lives and the DNS server refuses to provide the address, the connection never really gets started.

Secondly, those lookups reveal information in their own right. Ordinary DNS wasn’t originally designed with much privacy in mind. Somebody in a position to observe unencrypted DNS traffic can potentially see which domains a device is trying to find.

There is a very simple improvement almost anybody can make at this point without buying anything or building a server: change the DNS provider supplied by their ISP.

Quad9 is one example. Instead of asking your internet provider where a particular domain lives, your computer or router asks Quad9. Its standard service also refuses to resolve domains which have been identified as security threats such as malware and phishing sites.

It doesn’t replace an advertising or tracker blocker but it moves DNS resolution away from the automatic ISP default while providing a useful security layer at the same time. It takes a few minutes to change and costs nothing. For many people that alone is already a worthwhile improvement.

I, naturally, didn’t stop there.

My first investigation into network-wide DNS filtering led, as many people’s do, to Pi-hole. Pi-hole takes some of the basic thinking behind a browser blocker and moves it onto the network. DNS requests can be compared against lists of known advertising and tracking domains before a connection is ever attempted.

If something asks, “Where is tracker.example.com?”, the answer can effectively be, “nowhere you need to know about”.

That was something of a lightbulb moment because a browser extension protects the browser it is installed in while DNS filtering can protect almost everything using the network: phones, tablets, televisions, games consoles, applications and assorted smart devices which often seem remarkably enthusiastic about contacting analytics services for no immediately obvious reason.

Pi-hole introduced me to the idea but I eventually discovered AdGuard Home and found it a much better fit for what I wanted. That isn’t a criticism of Pi-hole. It remains an excellent project and for many people it will do exactly what they need.

AdGuard Home simply pulled together more of the things I was interested in. Alongside network-wide DNS filtering it gave me convenient control over devices, filtering rules, caching and encrypted DNS upstream.

Caching itself turned out to be another small but useful optimisation. When AdGuard Home looks up a domain successfully, it can keep the answer locally for a period of time rather than immediately asking an external DNS service again the next time another device requests the same thing. Provided that cached answer is still valid, the response can come straight from inside my own network.

Increasing the amount of cache available means AdGuard Home can retain more of those answers at once. Frequently used DNS requests therefore have a better chance of being answered locally rather than repeatedly travelling out of the house to an upstream provider.

That has two benefits: fewer DNS queries need to leave my network and repeated lookups can be faster because the answer is already sitting a few feet away rather than somewhere on the wider internet. Cached records still expire when they are supposed to but it fitted neatly with the philosophy I was developing. If something can sensibly be dealt with locally, why send it somewhere else at all?

The encrypted upstream side was another rabbit hole.

Traditional DNS queries aren’t necessarily encrypted. Technologies such as DNS-over-HTTPS and DNS-over-TLS allow those requests to be carried inside an encrypted connection instead. My devices could therefore ask AdGuard Home for an address, AdGuard Home could decide whether the request should be blocked locally, answer it immediately if a valid result was already sitting in its cache or securely forward the request elsewhere when it genuinely needed an answer.

I eventually settled on NextDNS for that upstream role.

The basic arrangement became:

device → AdGuard Home → encrypted DNS → NextDNS

AdGuard Home provided the filtering, caching and visibility inside my own network while NextDNS provided another controllable DNS layer beyond it. The communication between them could be encrypted.

It is important to understand what that encryption does and doesn’t achieve. Encrypted DNS protects the conversation in which you ask where something is. It does not magically make everything else you subsequently do on the internet anonymous.

That distinction became increasingly important as I stopped thinking of privacy products as competing solutions and started seeing them as different layers.

Around the same period I discovered GL.iNet routers. Built around OpenWrt, GL.iNet equipment occupies a useful middle ground between the sort of appliance an internet provider gives you and building an entire networking system yourself. They can function perfectly happily as ordinary routers while exposing considerably more flexibility underneath.

One particularly useful feature on supported models is the ability to run AdGuard Home directly on the router. That changed things significantly because instead of configuring DNS filtering individually on every device I could make it part of the network itself. Connect to the Wi-Fi and the protection was simply there.

A television didn’t need an ad-blocking application and a phone didn’t need special configuration. They were using my DNS infrastructure because the router handed it to them automatically.

Browser-level protection remained useful because DNS has limits. DNS understands domains but it doesn’t understand the contents of a webpage in the way that uBlock Origin does. If an advert and the article I actually want to read are both served from the same domain, DNS can’t necessarily block one without breaking the other.

Brave and uBlock Origin can work at the page level. AdGuard Home can work across the network and NextDNS can provide another layer further upstream. Different layers see different things.

GL.iNet also made using VPNs extremely straightforward.

VPN is another term which marketing has managed to turn into something almost mystical. Connect to a VPN and, according to some adverts, you apparently become an invisible digital ninja.

You don’t. If I connect to a VPN and then log into Facebook, Facebook still knows exactly who I am because I’ve just logged in and told it.

A VPN addresses a different part of the problem. Ordinarily internet traffic leaves home through your internet provider and travels towards its destination. With a VPN it first enters an encrypted tunnel to the VPN provider. The ISP can see the connection to the VPN but has less direct visibility of the destinations beyond it. The website at the far end also sees the public IP address of the VPN server rather than the one assigned to your home connection.

I have used both ProtonVPN and Mullvad for this. Putting VPN capability onto the router meant I could apply it to an entire network if I wanted to or selectively route particular devices through it rather than installing and maintaining VPN software everywhere.

Again, it wasn’t replacing the other protections. A VPN doesn’t stop tracking scripts. AdGuard Home doesn’t isolate a Facebook login. Browser separation doesn’t stop a television contacting an analytics domain and uBlock Origin doesn’t change the public IP address websites see.

They are solving different problems.

By the time I started considering whether to return to Facebook, all of this had already happened. I had been away for nearly two years and I wasn’t particularly keen on simply logging back in and carrying on exactly where I had left off.

If anything, this was when the kitchen sink came back out.

Facebook received its own browser environment and Firefox’s Facebook Container provided another boundary around Meta services. Facebook, Messenger and related sites could operate inside their own container rather than casually sharing browser state with unrelated activity.

I also used F.B. Purity to attack the problem from the other direction. F.B. Purity doesn’t hide you from Facebook. It changes what Facebook shows you by filtering sponsored posts, suggested content and various other pieces of algorithmic clutter.

I wasn’t returning because I had suddenly decided everything which had driven me away was fine after all. Facebook was useful again, particularly for music and maintaining connections, so I wanted to extract that usefulness while reducing as much of the baggage as I reasonably could.

The return was consequently much more deliberate than my original use of the platform had ever been. Facebook lived in its box. Tracking was filtered at the browser, DNS filtering operated underneath that, the network had its own protections and a VPN could alter the external route when appropriate.

Some of this was undoubtedly excessive. At the time I was quite happy with excessive because after two years away I was acutely conscious of what I was reconnecting to.

There was another part of Facebook’s data model which bothered me even more by this point: the phenomenon generally described as a shadow profile.

That isn’t Facebook’s terminology but arguing over the name rather misses the point. The Facebook profile you can see is not necessarily the sum total of the information Meta can associate with you.

You do not need to type every piece of that information into Facebook yourself. Other people can upload address books containing your name and telephone number. Photographs can contain you. Websites and applications using Meta’s advertising and business tools can feed activity back into the same ecosystem. Meta can receive information about people who aren’t currently logged into Facebook and information about people who don’t have a Facebook account at all.

That is the bit I think people should find uncomfortable.

I can decide not to give Facebook my telephone number but that doesn’t prevent somebody else’s phone from uploading an address book which contains it. I can choose not to tell Facebook who I spend time with but those relationships can potentially be inferred from other people’s contacts, photographs and activity. I can deliberately avoid interacting with Facebook on a website, yet Meta technology embedded in that site may still create another piece of information.

Call that a shadow profile, inferred data, off-platform activity or whatever terminology makes everybody feel more comfortable. The important point remains the same: the information a company can associate with you can extend well beyond the information you knowingly placed in your visible account.

That also changes the way I think about the reassuringly simple idea of deleting data.

Deleting a Facebook account is not meaningless but neither is it equivalent to pulling a giant lever marked ERASE ME and watching every trace disappear from every system. Deletion can take time, backups exist and information can sometimes be retained for legal, security or safety reasons. Messages sent to other people may remain in their inboxes because those copies form part of their accounts rather than mine.

More fundamentally, information which came from somebody else’s address book, photograph or activity was never entirely under my control in the first place.

That is the uncomfortable reality of modern privacy. Your data is not always produced by you.

You don’t exist online by yourself.

I can be extremely careful about whether I upload an address book containing other people’s telephone numbers but I can’t control whether somebody else uploads one containing mine. I can carefully separate social media activity from other browsing but somebody else can post a photograph containing me, tag me in something or mention where we have been. I can decline to tell a service who my friends are while my friends quite innocently provide information which establishes exactly the same relationships.

Modern data collection doesn’t require one person to consciously hand over a complete dossier. Connections can be inferred from fragments and much of the information surrounding us belongs partly to other people as well as ourselves.

Privacy is therefore partly social.

That can initially make the whole exercise feel rather futile. What’s the point in carefully managing your own data if everyone around you is happily carrying a device full of information about you and handing parts of it to third parties?

For a while that thought feeds the same paranoia as trying to plug every technical hole. Eventually I came to the same conclusion about both.

Perfection isn’t the objective.

Perfect privacy doesn’t exist. Neither does perfect security and genuine anonymity is another problem entirely. The more useful question is what I am actually trying to protect and who I am trying to protect it from.

That is threat modelling in its simplest form. It sounds like something conducted by people wearing black polo necks in secure rooms but the principle is quite ordinary. What are the realistic risks? Which ones matter to you? What can you reasonably do about them and how much inconvenience are you prepared to tolerate?

My threat model isn’t an intelligence agency deploying unlimited resources to uncover my identity. I mostly want to reduce routine commercial tracking, minimise unnecessary data collection, prevent devices making pointless connections to advertising and analytics platforms, reduce what my internet provider can casually observe and make it more difficult for individual companies to build an unnecessarily complete picture of my online life.

That is a much more realistic problem to solve and it also means partial protection is not failure.

If somebody else has my phone number in their address book, that does not suddenly make blocking tracking on thousands of websites pointless. If one company can associate two pieces of information about me, it does not mean I should therefore give every company everything. If one tracker gets through, blocking the other hundred wasn’t a waste of time.

This is probably where my attitude has changed most over the years. I am considerably less paranoid about it now, not because privacy has stopped mattering to me but because I understand the limitations rather better.

There is a danger in treating privacy as an all-or-nothing proposition. Once perfection becomes the standard, everything short of disappearing into a forest and communicating exclusively by carrier pigeon begins to look inadequate.

That isn’t useful.

Any good practice is better than no good practice.

Use a browser with decent privacy protections. Install a reputable content blocker. Separate heavily tracked services from everyday browsing. Change away from your ISP’s default DNS resolver. Use encrypted DNS. Choose privacy-respecting alternatives for things like search and email when they work for you. Use a VPN when it solves a problem you actually have. Use proper unique passwords and multifactor authentication and think for a moment before handing over information simply because a website asks for it.

Most of those things cost absolutely nothing and require remarkably little effort. Some of the most effective everyday privacy improvements can be made in an evening without buying a Raspberry Pi, learning Linux or constructing anything remotely resembling my network.

You don’t have to follow me down the rabbit hole, although personally I found the rabbit hole rather interesting.

There was another unexpected benefit too. Removing tracking, advertising and unwanted content simply made the internet nicer to use. Pages became cleaner and some loaded faster. Devices stopped making quite so many inexplicable connections and Facebook became something closer to the useful communication tool I wanted rather than an environment entirely dictated by whatever its algorithms wanted me to look at.

The larger change was psychological though. I had started replacing defaults with decisions.

Which browser should handle this? Does this service need to share an environment with everything else? Who should perform my DNS lookups? Should those requests be encrypted? What should be blocked for the entire network? Which devices actually need to use a VPN? Which companies am I comfortable entrusting with years of personal information? Does my search history really need to be tied to an account? What am I giving away simply because nobody ever asked me to think about it?

None of this appeared as a grand design. It accumulated.

Leaving Facebook led me to think more seriously about tracking. That led to looking at the wider services I used, moving my email to Proton, replacing Google Search with DuckDuckGo and thinking about what I could realistically replace and what I couldn’t. Browser privacy led to isolation, which led to DNS filtering. DNS filtering led to taking greater control of the router and the router made encrypted DNS and network-wide VPN connections straightforward.

By the time Facebook came back into my life, the network it returned to was a very different place. So was I.

The early instinct to block absolutely everything had gradually given way to understanding what each layer actually did, accepting what it couldn’t do and concentrating on protections which made sense for the way I actually used the internet.

I still think people should understand what is happening behind the screen though.

Using privacy tools isn’t about believing advertising itself is somehow evil or expecting every online service to operate for nothing. Companies have to make money and advertising has funded everything from newspapers to television for generations. What changed with the internet was the extraordinary amount of information which could be gathered, connected and used to decide who should see which advertisement.

That is something I think people deserve to understand.

If you understand the bargain and are happy with it, fair enough. At least it is then a choice.

Somewhere along the way I had also stopped treating my home network as the anonymous plastic box supplied by an internet provider and started regarding it as something I could actually design.

That turned out to be quite a significant change in outlook because once you realise you can control how your own network reaches the internet another question begins to suggest itself.

What else could you make it do?

That was where privacy tinkering started becoming something else entirely.

The homelab was next.


Discover more from Outpost 10

Subscribe to get the latest posts sent to your email.

Similar Posts