Can you be on the internet and avoid the collection of metadata that can eventually be accessible for the NSA or other TLA? You have an ISP which logs everything, same for your destination endpoint, and those logs are already being correlated.
Can I even hide from NSA level adversaries without employing extreme methods? Assuming "no", then for this particular threat model do the tools employed next matter?
There is some evidence that Tor has posed significant problems for three-letter-agencies in the past, so it's not like there is nothing to be done at all.
But there is a bigger point to be made: in my experience most privacy activists argue that taking an absolutist stance personally is counter-productive -- just because it is almost impossible to completely eliminate risks from your life does not mean you should give up and not try to minimise them. And of course, the goal for most people isn't to protect against targeted attacks (since that means you already need to take fugitive-on-the-run-level precautions), it's to avoid becoming a target in the first place.
Most privacy activists are already taking an absolutist stance.
Reality is, for normal people there's no point where worrying about spooks and taking actions to protect themselves is reasonable. As you say, there's nothing one can do against a targeted attack. But same is true for broad, untargeted sweeps - if they really care, they will find you anyway, and attempting to reduce your data exposure just flags you as an anomaly, making you more interesting, not less.
The whole "privacy vs spooks" threat analysis is not relevant to regular people.
What I mean to ask was related to the mention made above, that Tailscale shouldn't be used by privacy conscious people.
> If you're privacy conscious, please be aware that Tailscale by default is creating behavioral metadata from all of those computers for the Room 641As of the world about everything you do on your supposedly “private” network
Is Tailscale creating additional metadata that doesn't already exist in "concentrated" form with my ISP? As a regular person trying to live a normal "internet enabled" life (self hosting a few things, sharing things with family or friends....) are there alternatives to Tailscale that leave substantially fewer traces for "Room 641s" and other similar entities, and doesn't just move the metadata collection to the hosting provider or the ISP?
And finally, does disabling logging in Tailscale mitigate those concerns? After all Tailscale will always be a target for data collection whether they cooperate or not by virtue of where they placed themselves. Similar to Cloudflare probably.