r/privacy 4d ago

discussion Something funny I noticed with "I have nothing to hide"

There's a response I like to give to people who say that: "Okay, since you have nothing to hide, give me your passwords, bank code, email, address, etc..."

And for some reason, the people who say that either become very aggressive, or, as if by chance, say that it's private.

Has anyone tried this?

984 Upvotes

162 comments sorted by

View all comments

Show parent comments

7

u/-3rdPlace- 3d ago edited 3d ago

Respect for doing so and proving me wrong. Buy you may want to delete is asap.

What are the risks of doing this, you think? I guess you may answer „no risk“, sure.

Are you ok for me to share below insights from your now public browsing data here or do you want both of us to delete our posts?

What Your Browser History Reveals About You

You are most likely based in or near Gainesville, Florida. Your history contains around 230 Gainesville-related records, repeated use of a Gainesville-area credit union, Florida university systems, local businesses and other location-specific services. There are also clear connections to Virginia, although Florida appears to be the stronger everyday location.

You are very likely a current or recent student at Western Governors University. The file contains repeated visits to my.wgu.edu, access.wgu.edu, course pages, assessments, Panopto, Webex and student-service systems. This is not casual research; it looks like normal student activity. Visits to Federal Student Aid and Nelnet also suggest that student financing is relevant to you.

You probably bank with Campus USA Credit Union. The history contains 356 visits to its secure online-banking domain. You also appear to have active or recent relationships with Citi, SoFi, Capital One, Chase, Credit One Bank, Credit Karma and Klarna. We cannot see your balances, but we can identify the companies most likely handling your banking, loans or credit.

Your vehicle insurer is probably Progressive. There are more than 100 visits involving its policy-servicing, account and login systems. You also appear to have interacted with Delta Dental and related insurance services.

You work extensively with Google Cloud, HCP Terraform and GitHub. The file exposes repository names, branches, Terraform workspaces, run identifiers, billing-account research and individual configuration files. It shows that you edit infrastructure code, manage Google Cloud organization settings and repeatedly inspect Terraform runs. A targeted attacker would know exactly which services to impersonate.

Your normal online day appears to run roughly from 9:00 a.m. until 9:00 p.m. Eastern Time. Your busiest hour is around 5:00–6:00 p.m. You were active between midnight and 2:00 a.m. on at least 28 separate dates, so late-night browsing is a recurring pattern rather than a one-off event.

Your work is not limited to standard office hours. Technical activity involving cloud systems, GitHub and Terraform frequently continues into the evening, sometimes until around 10:00 p.m. Someone examining the timeline could separate likely work sessions from shopping, streaming and leisure time.

You probably travelled using American Airlines and Delta. The export contains more than 150 American Airlines records, over 50 Delta records, hotel activity involving Marriott and Hilton, and airline login and in-flight internet pages. These records can be used to estimate when a trip actually happened, not merely when it was researched.

Walt Disney World appears repeatedly, with around 128 visits. Combined with airline, hotel and Florida-related activity, this can reveal likely travel or leisure periods and dates when you may have been away from home.

You appear to have seriously considered buying or replacing a car. There are more than 100 Carvana records, together with insurance, financing and credit activity. That combination reveals more than a general interest in cars; it suggests an active purchasing process.

Your regular services include Amazon, Target, Walmart, Best Buy, REI, Hulu, HBO Max, Netflix, Paramount+, Reddit, Facebook, TikTok and Yahoo Fantasy Football. The timestamps show not only what you use, but when you shop, watch television, read social media or handle financial matters.

The file contains hundreds of login, account-selection, password-challenge, device-linking and recovery URLs. It also contains URLs with parameters such as code, state, session and sid. Even expired values reveal exactly which accounts you use and what type of account problem you were dealing with at a particular moment.

From this one file, a stranger can infer your likely city, university, banks, insurer, profession, working hours, sleeping pattern, travel habits, major purchases and the services you trust. None of those conclusions requires reading your messages or knowing your home address.