If you want to understand the surveillance machine, don’t start with your name. Start with your email address. Your name gets repeated by thousands of people. Your email address is one single string of characters — and it is the same string you’ve been handing out since 2004 to the shoe store, the gun shop, the news site, the medication outlet, the political donation page, the Bitcoin exchange. Whoever holds that string can stitch every one of those purchases and signups into a portrait of you. It is the master key the watchers use to assemble a stranger into a person — and you have been photocopying it for everyone who asked, free of charge, forever.
And blocking cookies won’t save you here. Brave and I have spent years shutting down the trackers that ride inside your browser. But the email match doesn’t happen in your browser at all. It happens on the company’s servers. You sign up at a sneaker shop with your Gmail address, and that shop uploads its customer list to Google, Meta, or LinkedIn — they call it server-side audience matching, and they advertise it openly. Meta already has that exact address from the Facebook account you made years ago. The records snap together. Meta now knows, specifically, that you bought the expensive running shoes. No ad-blocker on earth can stop a database comparison that never touches your computer.
Worse, that address is never safe even where you left it. Sites get hacked constantly; the dumps end up with data brokers and scammers, and your address circulates for a decade, surfacing in phishing attacks aimed at you by name. Every database that holds it is a future breach.
Why this matters more every month: KYC is everywhere now
You have probably heard the word KYC. It stands for “Know Your Customer” — the demand that you show who you are, ID in hand, before you are allowed to use a service. It used to mean just banks and stock brokers, and that was defensible. Antifraud, antimoney laundering, fine. That was the whole world of it. Not anymore.
Today KYC is crawling into every corner of online life, and the regulators are in a race with each other to be the most thorough. Crypto exchanges already make you photograph your license and your face. The British Online Safety Act forces age verification on whole categories of websites. American states are passing age-verification and ID-check laws for apps and online stores in droves — this September, the U.S. Treasury formally blessed the phone-resident mobile driver’s license as valid ID for opening bank accounts, which tells you exactly where this is going.
Across the ocean they are further along and not shy about it. Under the EU’s new digital identity rules, every EU member state must hand its people a government digital ID wallet by the end of 2026 — voluntary in name, universal in practice. The EU’s anti-money-laundering regulation that kicks in for 2027 will oblige banks, crypto platforms, and — this one should get your attention — even luxury-goods and jewelry traders to verify every customer against official sources. The Commission is rolling out age-verification technology for every citizen by the end of 2026, and this September it proposed a “KIDS Act” to reshape the whole internet around children’s identity. What Europe builds today becomes America’s template tomorrow. It always does.
Here is the part nobody in the paperwork business wants you to think about. KYC only works if your records can be attached to a person — and the cheapest, easiest stitch in that needle is your email address. Governments will tell you their digital ID is private and secure, “selective disclosure,” cryptographically sealed. Then a shoe store, an ad network, and three hacked marketing databases quietly hand the same regime the email string that ties all your other half-revealed records together. When KYC is the price of admission to everything — banking, exchanges, apps, forums, maybe your news site — the one address you gave every one of them becomes the thread they all pull on. Stop handing it out and you take away the thread.
Which brings me to a personal request about this very website: register with michaelheath.org using your alias. I don’t need to know who you are. I don’t want to know. I am not assembling customer dossiers; I am trying to reach minds. The state can have your identity when it demands it at gunpoint — that is obedience, and you give it cheerfully enough. But handing your private self to a publisher who never asked for it is the habit that will be your undoing everywhere else. So sign up as a stranger and stay one. Read what you want, think what you think, and if you ever decide to support the work, the tip button is indifferent to your name as I am. From now on I would rather know you by what you value than by what is printed on your driver’s license.
The fix is free, and it is sitting in the browser you should already be using
On August 27, 2026, the Brave browser — the one I have been telling you to use for years — launched a feature called Email Aliases, and it is exactly the kind of quiet, practical act of defiance I like. Even the mainstream tech press noticed that Brave just did what Chrome never would.
An alias is a unique, fake-but-live email address that Brave invents for each website you sign up with, and forwards everything from it to your real inbox. The sneaker store gets random-letters-1@yourbravealias. The forum gets a different one. The newsletter gets a third. None of them ever see your real address, so none of them can match their customer list against Meta’s or Google’s. The cross-website link is broken at the source — not hidden, broken. And when one alias starts collecting spam, because some site got hacked or sold out, you delete that one alias and every future leak from that site dies at the door. Your real address never surfaces. It stays in your pocket, known to your friends and no one else.
Five aliases are free right now, and mobile support is coming. Run the numbers: five strangers can now be kept from assembling your portrait, at a cost of two minutes and zero dollars.
Set it up — five minutes, start to finish
- Install or update the Brave browser on your desktop — you want version 1.94 or newer. Download it at brave.com.
- In the address bar, type brave://settings/email-aliases and press Enter. Click “Log in or create a Brave account” and follow the prompts with your real email and a strong password. Yes, Brave gets your real address — but it needs it to forward your mail, and by their own architecture (they use a protocol where your password never even reaches their servers), that is about all they get.
- Now go sign up for anything. Click into the email box on any website and Brave pops up offering a New Email Alias. Take it. If the popup doesn’t appear, right-click the email box and select “New Email Alias.”
- Want to see what you’ve handed out? Settings → Autofill & Passwords → Email Aliases. That screen is your own little map of your online life — one address per site, spam trap included. Deactivate any alias that turns bad.
- Make it a habit: one new alias for every new signup. Never reuse one across two websites. That is the whole trick.
What this does not do — and I would rather hear it from me
I won’t sell you a fantasy. An alias is not a disguise before the state. Your bank, the tax man, the doctor, the mortgage — show your face and your true name there, like a Christian should. This is not deception; it is refusing to give the advertiser, the data broker, and the inevitable hacker a bonus they never paid for. And when you sign up with an alias, don’t then hand them your real name, your real phone number, your real birthday — don’t take the key off the table with one hand and put it back with the other. An alias is only as strong as the stranger it describes.
Understand what is happening here, because it is not small. The surveillance economy does not depend on you being careless with passwords. It depends on you being lazy about the little things — on every one of you being too busy to bother. The state builds the KYC scaffolding, the advertisers buy the matching, the brokers do the stitching, and the lazy customer supplies the master key from his own mouth, over and over, free. Every alias you generate is a small refusal to participate. It is the cheapest thing you can do today — short of prayer — to keep your life out of their dossier tomorrow.
Five free aliases. Two minutes. Do it before the next law — and there is always a next law — makes handing over your identity as routine as a handshake. You heard it here first: the era of anonymous life online is ending, and the people who kept a trick or two up their sleeve will find they own something nobody else has left. Freedom, in this age, starts by never giving a stranger your real address again.

