Working Through Dayna Lorentz No Safety In Numbers
Dayna Lorentz's piece on mass surveillance and the myth of collective privacy is one of those reads that lands somewhere between technical breakdown and genuine frustration. She lays out the argument that being part of a large dataset doesn't protect you — it makes you more visible. I came across her work after spending too many late nights digging through FOIA documents and finding myself agreeing with almost everything she wrote. The core thesis is straightforward: aggregate data collection doesn't anonymize anyone. The more people involved, the easier it becomes to re-identify individuals through cross-referencing. Lorentz walks through concrete examples — location pings, metadata trails, commercial data brokers — rather than staying at the level of abstract worry. She references specific cases where supposedly anonymized datasets were trivially reversed. The writing isn't trying to scare you. It's trying to show you how the mechanism works. What's useful about her approach is that she doesn't just cite academic papers. She tracks down the actual implementation details — the kinds of things companies tell you they do versus what they actually do. I found her breakdown of how data brokers purchase and sell location intelligence particularly accurate because it matched documentation I'd pulled from state-level FOIA requests.
Here's the practical takeaway: if you're relying on the idea that you're safe because you're one among millions, that's the exact condition that makes targeting easier. The math works against you, not for you.
Why Most People Get This Wrong
The common misunderstanding is assuming that more data about more people means less data about any single person. K-anonymity models suggested this used to be true under very narrow conditions. In practice, those conditions have been gone for a decade. When you combine even two independent datasets — your phone's location history with your purchase records, for example — the uniqueness of your patterns skyrockets. A 2006 Netflix dataset study showed this already, and everything since has only worsened the problem. Lorentz gets at something most coverage misses: the asymmetry. You don't control what data exists about you. Companies accumulate it. Governments access it through multiple channels, some legal, some not. The burden of protection sits entirely on the person being watched, which is structurally impossible when the watcher controls the infrastructure. I hit a wall once trying to verify exactly how much data a specific broker held about me after reading her piece. The standard approach — requesting deletion through their websites — barely moved the needle. What actually worked was filing a California Consumer Privacy Act request directly to the parent company of one of the major data aggregators. You get a proper response, including the categories of data they hold and where they obtained it. It took about three weeks and required mailing a signed form, but it was the first time I saw a concrete inventory of what was already known about me.
Get the Full Details

What Actually Works (And What Doesn't)
Virtual private networks help with some traffic but not all of it. They route your internet traffic through an encrypted tunnel, which prevents your ISP from logging every site you visit. But they don't stop apps from reporting to their own servers, and they certainly don't prevent third-party trackers embedded in websites. If you're using a VPN while browsing ads, the ad networks still know who you are through cookies and fingerprinting. Browser fingerprinting is the more insidious problem. It's the practice of collecting details about your browser version, screen resolution, installed fonts, operating system, and other attributes to create a unique identifier. No cookies needed. Even in strict privacy mode, your fingerprint remains consistent enough to track across sessions. I learned this the hard way when I switched to a privacy-focused browser, deleted all my cookies, and then realized I was still being identified at a consistent rate because my fingerprint matched previous visits. The tools that actually reduce your surface area tend to be unglamorous. Disabling JavaScript on sites that don't need it eliminates most tracking scripts. Using privacy-respecting search engines prevents query logging. Limiting app permissions on your phone — specifically location access — cuts off a major data source. These aren't perfect. They don't make you invisible. They reduce the signal available to people who want to use it.
A realistic expectation matters here: complete anonymity online is essentially impossible if you use any standard internet service. The goal is reducing the quality and quantity of data available about you, not eliminating it entirely. That's a meaningful difference that most guides fail to make clear.
The Limits of Individual Action
Lorentz doesn't pretend that personal configuration changes solve the structural problem. No amount of browser hardening addresses the business model that depends on selling attention. The real leverage points are regulatory — restrictions on data collection, requirements for meaningful consent, limits on how long data can be retained. These are slow to change and inconsistent across jurisdictions. The GDPR in Europe provides some protection for European residents, but it doesn't extend to everyone. US federal privacy law remains fragmented. State-level laws like those in California and Colorado add patches but leave gaps. What's more immediate is recognizing that the problem isn't primarily your fault. The systems are designed to extract data efficiently. Your reasonable expectation of privacy doesn't match the legal reality. That's not a personal failing — it's a design choice made by organizations that benefit from the opposite arrangement.

If you want to act on this, start by understanding what data exists about you before trying to change your behavior. The FOIA and CCPA routes I mentioned are worth the effort. After that, reduce exposure where it's practical — turn off unnecessary permissions, question what information you're providing to apps and services, and recognize that the default settings on most consumer products are optimized for data collection, not privacy. The work itself isn't glamorous. It's mostly reading terms of service you'd rather not read, filling out forms, and making small adjustments that compound over time. Lorentz's writing helps because it explains why the adjustments matter without pretending they're enough on their own. They're not. But doing nothing is worse.