# Stop Confusing Privacy & Anonymity (and Security)

**URL:** https://discuss.privacyguides.net/t/stop-confusing-privacy-anonymity-and-security/25775
**Category:** Videos
**Created:** 2025-03-14T02:01:15Z
**Posts:** 32

## Post 1 by @jordan — 2025-03-14T02:01:15Z

> **[Stop Confusing Privacy & Anonymity (and Security)](https://www.youtube.com/watch?v=RRt08MvK4tE&feature=youtu.be)**
>
> Are you mixing up privacy, security, and anonymity? Don't worry, it's more common than you might think! In this week's video we break down each term, so you ...

Hey everyone, this week we’re tackling some common misconceptions with privacy, security, and anonymity. Often privacy and anonymity are used interchangeably; however, there are distinct differences between the two. In this video, we aim to explain and discuss the differences so you can make better decisions on your privacy and security journey.

Thank you all for checking out the video. I hope you enjoy it! I’m also looking forward to hearing what you think about the direction I took with the video!

---

## Post 2 by @anon36940904 — 2025-03-14T02:13:10Z

Yay! New video.

Busting myths! I like it. It informs the general public from/at the ground level with the differences with it all.

Great video. That’s the only feedback I have.

---

## Post 3 by @anon802255 — 2025-03-14T03:01:10Z

Nice video.

Would it be worth adding a categorisation for each of the tools on PG with some sort of tagging system, or other method to easily show what each tool is specifically for?

---

## Post 4 by @Niek-de-Wilde — 2025-03-14T09:28:57Z

Could you expand a bit on what you mean with this?

We already have some categorisation on threat models as you can see below, telling you what type of tool attacks you from what.

 ![Screenshot 2025-03-14 102517](//forum-uploads.privacyguidesusercontent.com/original/2X/4/4ea593c171c8ffe8753c9f1ed4ef39f83ad454fb.png)

You can Hover your mouse over the icon to get an explanation over what each icon means, and click on it to be taken to the common threats page with more information.

 ![Screenshot 2025-03-14 102743](//forum-uploads.privacyguidesusercontent.com/original/2X/b/bcfc98c914375e4f39366134c7c4e02795b3664a.png)

---

## Post 5 by @anon802255 — 2025-03-14T10:24:52Z

Unfortunately the threat model icon hover over doesn’t work properly on iOS Safari, it just redirects to the Common Threats kb, and when going back to the previous page the hover over is stuck in front of the information on the page.

Ignore my suggestion, I had some confusion linking the information already provided on the website in the Common Threats video to the video., whereby the video was focusing on security, privacy and anonymity in a broad sense, and PG focuses on categorisation by threats or goals.

---

## Post 6 by @Niek-de-Wilde — 2025-03-14T11:02:35Z

Yeah the hovering part is sadly not possible on mobile browser as a whole. Tapping it should at least bring you to the specific threat with its explanation though.

---

## Post 7 by @dogeyes — 2025-03-14T12:25:57Z

“Surveillance capitalism” is an ideological and deliberately misleading term. If I referred to China’s activities as “surveillance socialism,” many people would simply laugh with good reason. “Digital data economy” is a much better term to describe how personal data is exploited.

That being said, the video is really good.

---

## Post 8 by @phnx — 2025-03-14T13:15:20Z

How is it an ideological term? You are conflating state surveillance with corporate surveillance. Surveillance capitalism accurate describes corporations gathering as much data about their users as possible for the purposes of profiting off of that data.

---

## Post 9 by @dogeyes — 2025-03-14T14:02:01Z

It accurately describes the situation if we absurdly reduce the term “making money” to its capitalist component. But that’s just it: a reductionist, ideological term—a deliberate, and likely malicious, oversimplification of what it really is. State surveillance and corporate surveillance are essentially the same; the only difference is the form in which the benefits manifest.

---

## Post 10 by @anon36940904 — 2025-03-14T14:12:46Z

Having read the book The Age of Surveillance Capitalism - I see no issue with this term being used in the video. The book is written by one of the authorities on the subject matter. Are you disagreeing with how the book explains it and defines it too?

And if if it’s a deliberate oversimplification of what it really is - then what is it really?

---

## Post 11 by @anon36940904 — 2025-03-14T14:23:48Z

Also, please elaborate on what makes the term ideological and misleading exactly to begin with?

---

## Post 12 by @KevPham — 2025-03-14T14:25:31Z

The author of that term wanted to emphasize the “accumulation” aspect of surveillance from corporations. They want to gather as much information from as many people as possible to maximize profits. Information becomes a resource that can be collected and exploited.

I do admit “Capitalism” is way too overused in academic literature but “Surveillance Capitalism” is probably the best term to describe the motivations of corporations.

---

## Post 13 by @Cyber-Typhoon — 2025-03-14T15:14:23Z

Hey guys, I think some already noticed but maybe is off your radar. So, it is just a heads up. This time I don’t see the video available in Peertube.

Can we make it available there as well?

---

## Post 14 by @taivlam — 2025-03-14T15:18:04Z

Maybe there is still a time delay for the PeerTube instance to sync with the YouTube channel?

---

## Post 15 by @sgp — 2025-03-14T15:25:45Z

The easiest way to watch it on PeerTube is to use the Privacy Guides video links. It defaults to PeerTube.

> **[Latest Videos - Privacy Guides](https://www.privacyguides.org/videos/)**
>
> This is our home for the latest video content from the Privacy Guides team. Be sure you are subscribed to find out about our latest uploads, and share these videos with your family and friends if you find them helpful!

https://neat.tube/videos/embed/4SmJxn7Q2XRp7ZGDCxvNUV

---

## Post 16 by @Cyber-Typhoon — 2025-03-14T15:34:49Z

> [@sgp](#):
>
> The easiest

For me the most convenient is to have it available in a source mapped that shows in the Grayjay app.

For some reason is not showing available in the [Spectra](https://spectra.video/c/privacyguides@neat.tube/videos?s=1) instance so I just realized that I may need to switch to Neat instance as the source.

Edit: Even in the [Neat instance](https://neat.tube/c/privacyguides/videos?s=1) it doesn’t show, so yeah not sure what is happening.

---

## Post 17 by @taivlam — 2025-03-14T15:40:22Z

First, thanks for another great video. Although I don’t fault others for getting the words of privacy, security, and anonymity mixed up; the effects of not using the correct term will add up over time. This reminds me of my professor’s words when I took abstract algebra: know the words and know what they mean (where your only way to get through a proof-based class is to learn the definitions of terms).

A tangent: this reminds me of when some talk a security vulnerability in the news and afterwards they will incorrectly call everything a “backdoor” as a hyperbole. Although I understand where they come from, it’s bad because it dilutes the actual meaning of the word. I’m not superstitious with literal words, or that you need to remember your name so that you can return home, such as in the plot of _Spirited Away_. However, it’s sort of like yelling that there’s a fire when there’s none or crying wolf - this repeated desensitization will come the point where no one will respond accordingly when the danger is actually here.

My only constructive feedback is that sometimes the subtitles had wrong words. What is used to generate the subtitles? And is there any way for fellow users here to help fix them if they notice them?

Here are two inconsistencies with timestamps, when transcribing the word “Chromebook”:

- “Objects” at 3:36
- “Facebook” at 4:04

I didn’t exhaustively double check the correctness of the subtitles, but that’s what I noticed.

---

## Post 18 by @dogeyes — 2025-03-14T16:28:15Z

> [@anon36940904](#):
>
> And if if it’s a deliberate oversimplification of what it really is - then what is it really?

> [@anon36940904](#):
>
> Also, please elaborate on what makes the term ideological and misleading exactly to begin with?

Let’s consider KevPham’s reply:

> [@KevPham](#):
>
> The author of that term wanted to emphasize the “accumulation” aspect of surveillance from corporations. They want to gather as much information from as many people as possible to maximize profits. Information becomes a resource that can be collected and exploited

Now, let’s swap “they” (referring to corporations) for “The state”:

> The state wants to gather as much information as possible from as many people as possible to maximize ‘profits.’ Information becomes a resource that is collected and exploited."

I can almost describe state surveillance word for word with that definition. This shows that the only difference lies in the term “profits,” which is interpreted differently. If that’s the case, then “surveillance capitalism” isn’t an accurate term—it’s hard to link an entire economic system to a specific action like surveillance. As I’ve mentioned, “digital data economy” is much more precise; it succinctly defines an economy where digital data is bought and sold.

At the same time, it’s equally difficult to connect surveillance in China with socialism. “Surveillance socialism” isn’t a real concept any more than “surveillance capitalism” is. Thus, the term is deliberately used as an ideological weapon.

---

## Post 19 by @anon36940904 — 2025-03-14T16:40:23Z

> [@dogeyes](#):
>
> it’s hard to link an entire economic system to a specific action like surveillance.

I think what “surveillance capitalism” means is in this context is that surveillance is being capitalized and does not necessarily mean that capitalism as an economic concept has been fully overtaken by surveillance and that there’s only surveillance when it comes to capitalism. There’s a difference here. Anything you can make money with doing whatever you can to make it happen is capitalism. We are just talking about surveillance in this case and that’s why it’s called that.

> [@dogeyes](#):
>
> As I’ve mentioned, “digital data economy” is much more precise; it succinctly defines an economy where digital data is bought and sold.

But it also downplays the egregiousness of the what you want to call it. It’s like calling a huge cut on your arm from an accident a scratch. The extensive no rules invasive nature of it warrants the term “surveillance capitalism” and not what you want to define it as, even though it may be true to call it that too. In the accuracy spectrum of what this can be called, surveillance capitalism is a more accurate term given the egregiousness of it.

> [@dogeyes](#):
>
> Thus, the term is deliberately used as an ideological weapon.

What in your mind is damaging something that you feel it is an “ideological weapon”. What’s the damage being done that you think its ideological based and that its a weapon. Also, everything we all think stems from some dogma and ideology so that itself makes calling it “ideological” somewhat moot.

---

## Post 20 by @anon36940904 — 2025-03-14T16:42:15Z

> [@anon36940904](#):
>
> Are you disagreeing with how the book explains it and defines it too?

> [@anon36940904](#):
>
> Also, please elaborate on what makes the term ideological and misleading exactly to begin with?

Also, if you can specifically respond to these specific comments, that’d be helpful to understand your POV.

You quoted the questions but did not, in my opinion, answer it. But let me know if your previous comment itself was an answer because I felt it was a non answer.

---

## Post 21 by @jonah — 2025-03-14T18:23:44Z



---

## Post 22 by @anon32558482 — 2025-03-14T20:18:33Z

Why are staff posts always pinned?

---

## Post 23 by @jonah — 2025-03-14T20:19:21Z

We do it to all articles and videos for a few days: [Pin new articles for a period of time](https://discuss.privacyguides.net/t/pin-new-articles-for-a-period-of-time/24942)

You can unpin them by just clicking the pin icon, or they should be unpinned automatically once you interact with the post.

---

## Post 24 by @jordan — 2025-03-14T20:24:11Z

Thanks for the feedback on the subtitles I will double check this today, and get it fixed! Thanks :folded_hands:

---

## Post 25 by @anon32558482 — 2025-03-14T20:24:42Z

Thanks, I thought we had to open the post and scroll all the way to the bottom which is a pita.

---

## Post 26 by @jonah — 2025-03-14T20:31:38Z

> [@dogeyes](#):
>
> “Surveillance capitalism”

> [@dogeyes](#):
>
> “Digital data economy” is a much better term to describe how personal data is exploited.

I am not sure these terms actually refer to the same thing. When people talk about the “data economy” they are usually referring to the collection and sale of data by data brokers, whereas “surveillance capitalism” refers to the widespread collection and use of data by large corporations. (Sure, these are highly _related_ concepts)

Google arguably does not participate in the _digital data economy_ because they do not really have or participate in an ecosystem where data is shared between parties. However, they certainly benefit from their own private mass surveillance programs when it comes to targeting their own advertising programs.

> [@dogeyes](#):
>
> If I referred to China’s activities as “surveillance socialism,” many people would simply laugh with good reason.

This is different than what we are doing, because we are not referring to the United States’ (or other Western governments’ activities) as “surveillance capitalism” in the first place. We are referring to mass surveillance programs **run by private corporations**.

When it is the United States (or other governments) doing it to its citizens, we just call it “mass surveillance.”

---

## Post 27 by @AtomicBug — 2025-03-15T03:31:49Z

I love how well made these videos are!

Okay help me out here.

Using signal as an example of privacy (“the assurance that your data is only seen by the parties you intend to view it”) makse sense to me

The definition of security also makes sense. But then saying HTTPS certificates are about security seems a little less clear. (“Certificates prove you’re talking directly to the websites you’re visiting. And keeping attackers from reading or modifying the data sent to or from the website”)

It seems like we’re almost describing the same thing. Obviously, HTTPS encryption (to the server) isn’t the same thing as end-to-end encryption (to another user). But the general idea is still the same: in both examples (Signal and HTTPS), we’re trying to make sure no one can read or modify our data. Right?

As someone who both geeks out on this stuff a lot AND still has a hard time explaining the difference between security and privacy, I’d love to see an example for security that is more clearly different than the privacy example. My two cents!

---

## Post 28 by @jonah — 2025-03-15T06:15:05Z

The difference is mainly that end-to-end encryption (e.g. Signal protocol) protects you from _all_ intermediaries (including the service you’re using itself), whereas mere transit encryption (e.g. HTTPS) only protects you from attackers in the middle of your network connection.

The example with HTTPS certificates does probably make the _most_ sense in the context of apps like instant messengers though, where there are two parties communicating, plus a server in the middle.

In cases where the _only_ two parties are involved are you and the server, you could certainly argue that HTTPS is acting in the same way Signal E2EE is (ensuring that the party you are connecting to is the only one able to read the data) and that there is a _privacy_ benefit. So yes, I will give you that this example is a bit ambiguous, and we’ll consider that when we give future examples.

* * *

A different example for security could be adding Two-Factor Authentication to an account. It doesn’t change at all who can access your data under normal circumstances, but it significantly improves your protection against data breaches, credential stuffing, etc.

---

## Post 29 by @ignoramous — 2025-03-15T09:24:06Z

> [@jordan](#):
>
> misconceptions with privacy, security, and anonymity

There isn’t a misconception, but conflation?

An interesting point I’ve come across is:

From information privacy perspective, some (mostly, advocates of _privacy as control / choice_) argue that anonymity is an incomplete (!) take on privacy, and that anonymity is table stakes. That is, a service / app that doesn’t have anonymity is not private (since the choice / control to go anonymous has been already made by the developer / provider).

---

## Post 30 by @WhinyHamletPayer — 2025-03-16T18:08:59Z

My number one frustraton when speaking with people about privacy is that they assume I’m talking about anonymity. They think I’m trying to go under and hide from the government.

---

## Post 31 by @maqp — 2025-03-17T07:09:45Z

**Intro**

- The video started good wrt Signal not being private because it requires a phone number.
- Addressing the nuance of threat models in the beginning was also very good.

**Definitions**

> “Privacy: The assurance that your data is only seen by the parties you intend to view it.”

I prefer saying this as “The ability of an individual to selectively disclose themselves” but it’s practically the same definition.

> “In the context of an instant messenger for example, E2EE provides privacy by keeping your messages visible to only yourself and the recipient.”

This is not the definition of IM privacy. Instant messengers have two aspects to their privacy, content and metadata. Unless you’re going to explain which ones are protected, and how, you’re not doing any favors by just using blanket statements like “it’s private”. E2EE only provides content-privacy.

* * *

> “Security: The ability to trust the applications you use, that the parties involved are who they say they are, and keep those applications safe.”

No, security means you remain secure from your absolute threat model. Also, the sense of security means you remain secure from your perceived threat model. These two are not the same. The issue is only an oracle would know your absolute threat model with utmost certainty, so you need to utilize different heuristics, an publicly available information on threats to create an estimate, then do cost-benefit-analysis for your situation about where you should take precaution and where you should take risks.

Computer security is a wider concept than

- Trusting company policy, or using trustless (privacy by design) systems, i.e. ones that you can verify from open source and preferably, reproducible builds.
- Authenticity (to verify parties involved), and
- “Keeping applications safe”? This is way too vague and sounds like a circular definition. Safe in what way? Patched from vulnerabilies? Latest in protocol design and primitives used?

E.g. availability is an integral part of computer security, not covered by these.

> “In the context of browsers, security is provided by certificates”

Certificates are about providing confidentiality, integrity and authenticity, i.e., the cryptographic CIA triad.

Confidentiality means content-privacy. When browsing, TLS is effectively end-to-end encryption between you and the server('s load balancer). Integrity ensures data isn’t changed during delivery, and authenticity tells you that you’re really talking to [privacyguides.net](http://privacyguides.net) server infra.

Certificates do NOT protect the source/destination IP that tells to which service you’re talking, and if my threat model includes a threat where my ISP learns I visited the IP hosting [fightthefascism.com](http://fightthefascism.com), then certificates do not provide security.

* * *

> “Security and privacy without anonymity”

Calling Signal private is meaningless because it conveys nothing about its constraints.

It’s end-to-end encrypted, this means it provides content-privacy. It’s open source, with some reproducible builds, it’s content-privacy can be provided by users. This is the gold standard, so we call it **content-privacy by design**.

Signal requires your phone number, and its server has the theoretical ability to collect user metadata, just like WhatsApp does. Signal chooses not to do that, and we have court docs to show this, so we know it’s protected by Signal’s policy. Thus we say signal provides **metadata-privacy by policy**.

> “Your messages are metadata are encrypted”

This is lazy. Messages are end-to-end encrypted, metadata such as phone numbers are encrypted with key Signal controls, so the best you could say, is the phone number is providing mediocre protection against someone compromising Signal’s servers. Signal has no trouble handing out the limited set of metadata of user by phone number based on court orders, so lumping encryption of phone numbers together with the state-of-the art end-to-end encryption it provides, either dilutes the E2EE nature of content, or, it misleads about the level of security phone numbers have on server side.

> “Privacy without security or anonymity: A VPN shifts the traffic from your ISP to your VPN provider. By making this change, you’re controlling who can see your internet traffic. Your IP-address is still known by the VPN provider, so that they can provide you with the service. This means you won’t be anonymous. VPNs also don’t offer security benefits over not using one.”

If my threat model includes my ISP doing DPI over my data going to some server, a VPN absolutely provides security against that particular threat. VPN provides content-privacy for HTTP sites against the ISP and script kiddies hanging around the airport WiFi. A VPN anonymizes your queries to your non-VPN DoH DNS provider.

> “Chromebooks are considered some of the most secure computing devices. However, they are deeply embedded with Google’s software. Google is known for tracking and profiling their users, and invading their privacy.”

If your threat model includes loss of anonymity or privacy, they you don’t have security with Chromebooks.

If you do not care about Google or NSA exploiting your data, but your threat model includes some criminal breaching the device, then, sure, it’s providing decent security against your threat model. Yes, the author talked about the nuance in the beginning, yet it seems to be missing in these examples. My main gripe is not with the general intention, but extremely poor definition of security.

> “Anonymity without security: Cash”

And now security widens to the non-digital world: “you can’t get your money back”. Yes that’s a **threat** in your overall **threat model**. Security is a larger topic than computer security.

* * *

> “Targeted attacks: Being protected from hackers or other malicious actors who are trying to gain access to your data or devices specifically. Common attacks include sending malicious documents by email, exploiting vulnerabilities in e.g. in browser/OS, and physical attacks. If you’re worried about targeted attacks, you should be focused on utilizing tools that offer additional security benefits. Depending on the level of the risk, this may mean sacrificing privacy for the benefit of extra security.”

No example was given here, but from what I read between the lines, is using Chromebook or iDevice to guard against state surveillance. This might work if your threat model includes CCP. Not if it includes the NSA. So again, it depends on your threat model.

> “Anonymity: Anonymity is the complete dissociation of your online activities from your real life identity. Conversely, you shouldn’t use tools that provide anonymity when your anonymity is known. For instance, logging into your bank account while using Tor is likely to trigger security measures from your bank, and it will link your real life identity to your Tor session.”

This is good OPSEC advice. But anonymity is much more complex topic, as it includes mainly metadata-privacy, but also content-privacy. What you know and say, and how you say it (vocabulary, use of parenthesis etc) can many times deanonymize you.

> “Surveillance capitalism: For many people, tracking and surveillance by private corporations is a growing concern. Pervasive ad networks such as those operated by Google and Facebook, span the Internet far beyond just the size they control, tracking your actions along the way. Utilizing browsers that thwart tracking technologies can trow off advertising tracking, and protect you against these types of privacy risks. However, using a privacy-focused browser doesn’t make you anonymous, but it does make you more private by reducing the ability for web-sites to track you across the internet.”

Web tracking is like a game of guess-who, where you expose yourself with small pieces. You like to browse red Audis? That filters out 80% of web users. You like to check available movies after that? That filters out 99.999999% of Internet users. You have unique persistent canvas fingerprint ID? Now enabling the VPN is useless in protecting your identity against the server.

> “Just because one tool doesn’t offer privacy, security and anonymity, doesn’t mean you shouldn’t use it. You need to evaluate what you realistically need for your situation.”

The part that talks about adjusting different tools to fit your threat model is sound advice. Messing up the definitions once again, does disservice to the community.

* * *

Security is not lack of vulnerabilities, or general defensively programmed system. Security is state of being safe from your absolute threat model.  
Privacy is not the same as E2EE. Anonymity is not “using Tor”.

I beg everyone here, especially the staff, reads what I wrote in [The collective misunderstanding of Privacy vs Security vs Anonymity](https://discuss.privacyguides.net/t/the-collective-misunderstanding-of-privacy-vs-security-vs-anonymity/24514).

We really, really, really need to fix these distinctions, and this video once again failed to understand the relationship between these terms, and thus, miseducated the community.

---

## Post 32 by @Niek-de-Wilde — 2025-03-17T08:24:59Z

Thanks for you extensive feedback markus, very much appriciated, we will be discussing this and come back on this.
