Generated synthesis

Recommendations Report

Synthesized from the Personal Security Playbook, Stack Builder, and OPSEC Field Manual

This is the capstone document — it pulls the highly-recommended picks and best-practice guidance out of the other three files into one report, and documents exactly where every claim in this project came from. Both interactive tools (the Stack Builder and OPSEC Field Manual) also have a Generate Report button that exports a version of this same report reflecting your actual live selections — this document is the reference version; theirs is the personalized one.


Part 1: Highly Recommended Stack — Top Pick Per Category

If you only take one thing from each category, take this. These are the picks that showed up as the strongest option across independent testing, audits, or documented track record, not just the most expensive.

Category Highly recommended Why this one specifically
Password manager Bitwarden Premium or Proton Pass Open source (Bitwarden), independently audited, cross-platform, hardware-key lockable
Email + aliasing Proton Unlimited Bundles Mail, aliasing (SimpleLogin Premium), Drive, VPN, Calendar under one zero-knowledge provider — best per-dollar coverage if you're not diversifying on purpose
Hardware 2FA 2x YubiKeys (primary + offsite backup) Phishing-resistant in a way TOTP codes structurally can't be; the second key solves the lockout failure mode the first one creates
Desktop OS Fedora Atomic (Silverblue/Kinoite), or Secureblue for a hardened fork Immutable/atomic model limits persistence of malware and config drift by design
Mobile OS GrapheneOS (Android path) or iOS Lockdown Mode as standing default De-Googled hardened AOSP with real sandboxing; Lockdown Mode is the practical ceiling if staying on Apple hardware
VPN Mullvad or Proton VPN No-logs, privacy-preserving payment options (Mullvad takes cash/Monero, no email required), WireGuard support
Browser Firefox + uBlock Origin Highest value-per-minute-of-setup control in the entire stack; Mullvad Browser as the upgrade when fingerprinting resistance matters more than convenience
Messaging Signal Free, minimal metadata collection, easiest adoption curve for non-technical contacts; SimpleX Chat as the ceiling for zero-persistent-identifier needs
Voice/video masking Google Voice (free) Covers most "give this out instead of my real number" needs at zero cost; upgrade to Burner or Hushed (~$5/mo) only when the number itself needs to be disposable, not just separate from your primary line
Cloud storage Proton Drive (sensitive/small) + Filen or Cryptomator + Backblaze B2 (bulk media) Splits by data sensitivity rather than forcing everything into one provider's pricing tier
Data broker removal EasyOptOuts ($19.99/yr) Outperformed DeleteMe on actual documented removal rate in Consumer Reports' 2024 test (65% vs. 27%) despite costing a fraction as much; layer in DeleteMe or Optery only if phone/fax-gated brokers matter to your exposure
DNS/Router OpenWrt + encrypted DNS (Mullvad DNS/Quad9) Router firmware is the higher-leverage control; DNS provider alone is commonly oversold
Backup 3-2-1 (local + Syncthing local sync + encrypted offsite) The structure matters more than any single product choice inside it
Card masking Privacy.com (free tier covers most usage) 12 virtual cards/month, no monthly fee, funded from your bank account — a leaked merchant database exposes a disposable card number, not your real one
Credit freeze Free freezes at all 3 bureaus (Equifax, Experian, TransUnion) Prevents new-account fraud outright rather than just alerting you after it happens — the highest-leverage financial control and it costs nothing

Part 2: Best Practices & Techniques — Closing the Gap to 100%

Organized to match the OPSEC Field Manual's six domains. If a domain isn't at 100%, this is the "how," not just the "what."

Social Engineering & Human-Layer Defense

Physical Security

Legal & Documentation

Operational Discipline

Incident Response Readiness

Maintenance & Audit Cadence


Part 3: Sources This Report Draws On

Primary methodology sources (the four foundational sources this project synthesizes)

Independent testing and journalism used for specific claims

Official vendor documentation (pricing, feature, and platform-support claims)

Referenced but not directly cited


Part 4: Recommended Sources to Keep Building From

The tools above will be stale within a year — this space moves fast. These are the sources worth following on an ongoing basis rather than just consulting once.

Source Best for Cadence
Privacy Guides (site + forum + blog) Living, versioned tool recommendations — check before any purchase decision, not just once As-needed, before any purchase
The New Oil Sequencing/prioritization when you're adding a new domain to your setup you haven't tackled yet As-needed
IntelTechniques podcast + workbook updates (Bazzell) OSINT methodology evolution — data broker landscape changes constantly Quarterly check-in
Techlore (YouTube + Discord) Hands-on setup walkthroughs, especially for anything with a fiddly install process As-needed
EFF Surveillance Self-Defense (ssd.eff.org) Foundational threat-modeling framework and guides that don't chase every product trend Read once in full, revisit the threat-modeling section every 6 months
Consumer Reports Security Planner / digital security coverage Independent, non-affiliate-driven testing — the source that actually caught the DeleteMe vs. EasyOptOuts gap Annual, around when you reconsider any paid subscription
Have I Been Pwned (haveibeenpwned.com) Breach monitoring — set up email alerts once, it notifies you going forward Passive/ongoing once configured
ToS;DR (tosdr.org) Quick terms-of-service/privacy-policy ratings before signing up for anything new As-needed, before new signups
Krebs on Security General infosec news with a track record of being first and accurate on major breaches As-needed / breaking news
r/privacy, r/degoogle Community discussion — useful for surfacing questions to research further, not as a primary source on its own; verify anything specific against one of the sources above Optional, treat critically

One habit worth adopting from this list specifically: before renewing or newly subscribing to any paid privacy/security tool, check Privacy Guides and Consumer Reports first — both this project's own EasyOptOuts/DeleteMe comparison and the Firefox critical-patch finding cited in Part 3 only surfaced because those sources get checked at the point of decision rather than relied on from memory.