How We Uncovered the Real Identity Behind “Startup L. Jackson”
syrah.co
syrah.co
I'm having a hard time seeing how it could possibly be anything but "doxing."
I think there's a clear difference between correlating a pseudonym to a real-life identity, and malicious "doxing" that could cause harm.
People use pseudonyms for a reason. Deanonymizing them can cause them harm, ranging from getting fired to getting arrested to causing severe social strife. Not your decision to make.
Luckily I committed no crimes, or I would have had a hat trick.
> Not your decision to make.
There's actually a lot of debate and discussion about this issue; I am always surprised at the number and tenor of those who wholeheartedly support making this kind of decision.
Your secrets don't have to be criminal to be secrets.
"The strict 'hacker' definition of 'dropping dox,' as it was initially phrased, involves the publication of documentation (or 'docs'/'dox'). As Schneier points out, these can be addresses, phone numbers, financial information, medical records, emails, and so forth. The part where the definition of 'doxing' gets murky is that the word's prominent appearances in the media haven't involved dropping dox at all. Rather, it's come (sometimes!) to signify the unmasking of anonymous internet users without their consent. ....
"The idea that a 'full name' can constitute a dox represents an understanding that in some contexts, the publication of a legal name serves as an incitement to drop a full dox. Through Google and other databases, a full name can lead to other details...."
While I absolutely think no good would have come out of de-anonymizing SLJ, it wouldn't really be doxing (unless they had somehow attracted people that had an interest in attacking their home, embarrassing them in front of their employer, etc.).
In both cases the desired outcome is achieved: the 'war' is expanded, taking on either new dimensions (personal knowledge of the doxxing victim) or new avenues to attack them with.
That section of the book argues for distinguishing them because, in some cases, de-anonymizing someone (but no more) is legitimate self-defense by a community, but doxing always intends harassment (which is not legitimate self-defense). If there are rules for actual war, there are absolutely rules for "war" in scare quotes; not inciting crime is one of them. I don't think I can make the full argument here concisely, but it is well set-out in the book. (While she has a blog post saying much the same thing, I actually thought that was a much poorer defense of de-anonymization, since it's missing context.)
Obviously in this specific case there is not even "war," just curiosity, so that defense of de-anonymization doesn't apply. But we've gotten on a tangent about the term itself.
Regarding 'unmasking': many doxxers use this argument: when they do publish people's information, they're unmasking bad actors, when their opponents do it, they're doxxing. For example Sarah Jeong, the author of the book you mention, wrote for The Verge, which tacitly endorses doxxing by ignoring it when performed by political groups it supports.
In some contexts, a full name is a full dox, to anyone who has Google access and 10 minutes to spare. There's not really a functional difference. The presence or absence of malicious intent may determine how we judge the doxer, but the potential effect on the doxee is the same either way.
Everyone thinks that until it happens to them. Trust me on this.
So I'd rephrase that: If you haven't done anything that resourceful adversaries consider wrong, you don't have anything to hide.
I can be such a pedant ;)
First answer me: Why do you think they chose to use a pseudonym? I can think of many answers to explain why. Most include risk of harm to the individual in various forms.
For example - there is a reason I use a pseudonym. I always have and always will.
There's a clear difference, yes, but it's only really relevant to how we judge the doxer. It's comparable to outing a closeted queer person: whether it's done maliciously or out of pure, naive innocence, the fallout for the subject is the same.
The harder question is when doxing is justifiable. Maybe it can arguably be self-defense. But even then, consequences are typically disproportionate. And there's no process for trial, opportunity for rebuttal, judgment by neutral third parties, etc.
SLJ is great because, due to his anonymity, his ideas stand on their own merit. Being outed killed Fake Steve Jobs; it'd do the same to SLJ.
[0] I'm sure there's a nice, concise word that fits what I'm unable to articulate here.
An interesting question is "How would you rate the ability of e.g. investigative journalists on this score?", to which I answer "Equivalent to their ability to ask someone in their social circle to tell them what the answer is."
Many people who might think that the risk of being fired is worth having the inside scoop on a story might reconsider when the threat is a lawsuit from Google/Facebook/Twitter.
The story about them doing this will quickly shoot to the top of search results for their name, and probably stick with them forever. Who wants to hire someone who is infamous for violating their previous company's privacy policy and abusing their access privilege? Who wants to stay on as a customer of a company where that person now works?
True, but the danger is not only with large enemies. I have had the network admin of my internet provider read my emails because he was bored. I know because we later became friends and he told me about it - with proof. (This was before gmail and everything-important-is-on-ssl.)
I also come live in a country where "government employees are reading your emails" is up there with "the water is wet", so large enemies are pretty much assumed to know everything they care to know.
Now SwiftOnSecurity is so huge people who remember/know this don't really talk about it. I imagine a lot of these things that blow up start like SwiftOnSecurity and then the person realizes "I'm kind of getting a lot of visibility. It could really help me but it could really hurt me. Maybe I should keep this separate from myself".
Beyond basic opsec of keeping your mouth shut, nothing is really necessary...
You might want to throw in a bit of sanitizing with respect to the linguistic analysis side, but generally speaking if you use a clean laptop and a random public connection it will be very difficult for anyone to out you.
This is very similar to the strange (to me) idea that people wouldn't use GMail because they're worried Google will steal their corporate secrets. Seriously? There would be riots in Mountain View if anything like that ever happened...
1. Find the people who were within SLJ's first few hundred followers (the API gives an account's followers in the reverse order they followed the account).
2. Assuming some of the early followers knew SLJ's real life identity, find which accounts many of them were following prior to following SLJ.
3. Accounts which are followed by relatively many of SLJ's early followers, but relatively few of SLJ's later followers, are candidates for SLJ's real identity.
Ultimately I couldn't make it work, although my guess is that SLJ has some connection to Pivotal (either is a former employee or has worked with them on projects).
Looks like HN has hugged it to death...
Any idea why the images aren't working?
javascript:void(_(document.styleSheets).chain().pluck('rules').map(_.flatten).flatten(true).findWhere({selectorText:"body::-webkit-scrollbar"}).value().style.removeProperty('width'))I guess everyone in the whole world has a scrollwheel and/or touchscreen. Screw anyone who doesn't, you can just read the top of the page...
But really, we just don't have everything done yet, I wrote everything on my own. We'll fix it in an upcoming update, sorry for the issues.
Ummm, yeah, lots of them.
Scrollbars work perfectly when you don't write anything.
I use the scroll bar as my first choice, and I'm pretty sure I'm not alone.
Note to web-devs. If you modify scrolling, you're doing it wrong.
I'd even go so far as to say browser-devs shouldn't allow scrolling to be modified. It's an OS feature, not an application feature.
I was able to view this story without enabling Javascript by using a basic feature of Firefox.
View -> Page Style -> No Style
Fortunately this particular website's brain damage had a simple workaround. Some don't. And if they don't, I simply move on and forget about the site.Really. I mean it. If a site is too hard to read, it literally drops out of my memory. No regrets. Life is too short to tolerate brain-dead websites.