It's also interesting that the sflc.in domain is giving 403 and it's first noticed by the attendees. The session seems to be about use facing tools to protect personal data than it is about code.
The session starts with by defining what privacy and personal information. And how data breach and data leak happen.
The volunteers from the sflc.in introduce tools like haveIbeenpwned.com and how and what visitor data is being tracked on your browser.
They also have developed a web tool, cateyes.softwarefreedom.in to demonstrate what all data can be captured and send and email and figure if it was opened or not through a script.
Then the volunteer later demonstrates how website scripts and the network of data sharing scripts. The availability of the trusted extension can be helpful here.
The lightbeam extension is also presented to visualise the common data sharing network for targeted advertisement.
Temporary email providers for one time usage are also advised. An attendee makes a reference to Firebox Relay that is kind of alias over your root email.
The next chapter is about threat modeling. And Kiran starts with how everyone's privacy needs are different and threat modeling helps you with personalizing your definition of protections.
Kiran suggests to use strong passport and other hygiene. Ihaveibeenpwned and other managers also flag is your password choicd is breached.
Some of the suggested password managers were Bitwarden, KeypassXC and other disroots of Bitwarden like Vault warden.
Passbolt is a nice reference that can be self hosted for teams that need to share passwords.
There are also U2F keys that is a physical device that you will require as a protective layer to the access.
Kiran then explains what encryption is and shift cypher with character shifts. Suggests disk encryption for linux and windows users as well.
Being aware of malware and having an habit of regularly updating your software. Continued software updates is good to have.
After a long exchange from the audience and the sflc.in audience on encryption flow etc, we have a volunteer rooting back it into the legal aspects.
A very few and high level government agencies have Authorization to conduct surveillance. But Union Home Secretary and State Secretary can Authorize time bound surveillance for specific reason.
Surveillance policies are really ideal on paper, but the Digital Personal Data Protection Act of 2023 intercepts this and can furnish data
Google has a test that gives email or sms scenarios that you will have classify as phishing or legit. That's a good test.
Domain names and sender identities are often the camaflaged and are good give aways. Sometimes phising can happen through legit platform where the notifications can be customised heavily as well.
All Bloqs
xxx
Sep 25, 2026
2 min read
Digital Security for Journalists and Everyday Users Hands-on workshop by Anuvind Praveen
my raw notes from sflc.in's workshop session on internet security hygiene for general users and people who might be prone to phishing and similar attacks.
#live