TLDR: I have a community with terrible privacy and security and I’m looking for ways to help them.
As you might already know, other people’s privacy affects your own.
Which is why it’s good to get your community involved in good privacy and security practices as it’s a win-win situation.
However I sometimes find it very hard to tell people why they should care about privacy without being either criticized for it or just told that none of what I’m doing matters.
I understand that threat models differ however I am talking about the kind of people that have TERRIBLE security and privacy (putting their date of birth as their main password, reusing the same password for everything, having their entire gallery on google drive etc…) (yes I can probably guess/bruteforce most of their passwords in a couple tries but I don’t )
I have already moved my close friends to signal and taught them good security practices (because they are actually willing to listen) as well as configured my family member’s phones in a more privacy conscious way.
-off topic- For those who are interested my biggest selling points were:
Ordered by most to least successful:
Password managers: you don’t have to remember a password ever again.
Brave: It doesn’t take as much storage space as Google (I’d set up automatic data removal to sell my point)
Nextdns (or any privacy oriented DNS provider): It stops showing you those annoying ads
Signal: it’s cross platform and its faster than emailing things to yourself
Newpipe: It’s youtube but without the ads and you can download all videos
-I’d also try my luck with 2FA every once in a while
However even after trying my best It still doesn’t feel enough.
The sad part is that a lot of people I know have been victims of phishing, online fraud, social media harassment, account stealing and so on… yet these same people are the ones that still don’t care about this! It’s honestly insane to me.
So my question is: How can I reach my community in a way that would matter to them and do my job as a privacy advocate?
Is it even possible considering that even the threats actually happening literally meant nothing to them?
Is it a lost cause and should I just focus on myself and the people that listen/matter?