// PRIVACY WORKSHOPS FOR DUTCH UNIVERSITIES

Your data trail is
longer than
you think it is.

hardtocrack is a series of practical, no-nonsense privacy workshops for students — starting at TU Eindhoven. We show you exactly which everyday apps are watching, and how to swap them for free alternatives without losing convenience.

a typical student's attack surface~14 services
after one workshop3 kept, deliberately
01 — the problem

"Free" software is rarely free of a cost.

Most students accumulate accounts one app at a time — a note-taking tool here, a group chat there — without ever weighing what each one collects, sells, or leaks. Attack surface isn't just about hackers; it's about how much of your life is exposed by default.

Default settings favor collection

Most apps ship with tracking, ad personalization, and broad permissions switched on. Turning them off is possible, but it's never the first screen you see.

Convenience hides the trade-off

Single sign-on and "log in with Google" feel effortless, but they quietly link every account back to one profile of you.

Students are a specific target

University email addresses, shared housing Wi-Fi, and public study spaces all widen what's reachable if one account is ever compromised.

02 — first session

Kicking off at TU Eindhoven

A 90-minute, hands-on session — bring your own laptop and phone. You'll leave having actually changed your settings, not just heard about it.

LOCATION: TU/e CAMPUS TBD Date to be confirmed — join the list below to get it first.
  • Mapping your own attack surface: the apps and services you actually use, and what each one can see.
  • Locking down the accounts that matter most: email, cloud storage, and student ID logins.
  • Free, privacy-respecting swaps for browsers, messaging, notes, and file storage.
  • Two-factor authentication and a password manager, set up live, on the spot.
  • Open Q&A — bring your weirdest "is this actually tracking me" question.
03 — the toolkit

What we cover, category by category

Every recommendation is free or has a generous free tier, works on both phone and laptop, and is realistic to switch to mid-semester.

CategoryCommon defaultWhat we set up instead
Browser Stock mobile / Chrome, default settings Firefox or Bravetracker blocking on by default
Search Signed-in Google search DuckDuckGo or Startpageno query-to-identity linking
Messaging SMS, unencrypted group chats Signalend-to-end encrypted by default
Notes & docs Notes tied to one account, synced everywhere Standard Notes or local-first appsencrypted at rest
Password habits Reused passwords, browser autofill only Bitwardenfree tier, unlimited passwords
Email One inbox for every sign-up Alias addresses via your providercontain breaches when they happen
"Privacy at a university shouldn't depend on which course you happen to take. It should be something every student picks up in their first year, like using the library catalogue."

hardtocrack started as a small campus initiative with one goal: make privacy practical, not political. We're not selling a product — every tool we teach is free, open, and something you keep control of after the workshop ends.

TU Eindhoven is our first stop because it's where a technical student body meets a genuinely under-served need — most security education on campus is aimed at researchers and IT staff, not the everyday student inbox.

We're planning to bring the same session to other Dutch universities through 2027. If you'd like it at yours, tell us below.