But anyway, there's no way to know. So your best bet is nested VPN chains. Including providers from jurisdictions where cooperation is less likely. Insorg is Russian, for example. Also, AirVPN, IVPN and Riseup have said that they'll shut down before they'll log.
Personally I can recommend Autistici/Inventati. More smaller services/servers seems like a much better way to go.
It is possible to set up an anonymous DigitalOcean account funded by a Visa gift card and associated with an anonymous email provider.
Perhaps the best privacy-preserving tool would be a pool of anonymous, public accounts to public and private VPN services, and a client app that dynamically builds and connects via nested VPN chains.
Cash bills are marked with unique codes, and the trip from bank->(consumer->seller)*->bank tends to be relatively short, often 1 or 2. Systematic/sustained transfers are easily detected with graph theory & statistics... Especially if most other actors are carrying their cell phone with them all the time!
Even if they did, how would they associate those serial numbers to your identity?
When you buy a prepaid card does the cashier link the serial numbers to the transaction?
If other actors have their cell phones with them, how does that allow graph theory to tie the prepaid card to you?
Bank knows: Alice-17.
Alice buys cell phone charger from cashier/seller Bob with bill 17.
Seller Bob deposits his cash (including bill 17) to the bank, and only the bank needs to scan the unique number, and associate with who brought it in:
Bank predicts: bill 17: Bank->Alice->Bob->Bank
For a lot of people even this simple automatable case is controversial, or supposedly too expensive to be true...
average joes and janes do not need to track and note down serial numbers for this to work...
====
Most convenience stores have a unified interface for printing the unlock codes for each type of product, and print the unlock code at time of buying. If you carry a cell phone, then the space-time event of cell phone position at the same location as the convenience store at the same time as printing the code identifies you. If other actors have their cell phones with them, the path of their bills is very much revealed. One is then trying to hide in among a very small set of unexplained connections...
Really we should have some kind of open source simulator of a market, and the surveillance state perspective of it, so we can prove in practice what is possible to deduce...
A variation of https://en.wikipedia.org/wiki/Random_forest might get the job done (the risk is an overfitted model).
Random citizen Randy who does not try to anonimize carries a 10$ bill will hence call Randy's bill Random citizen Rachel who also doesn't try to anonimize carries a 5$ bill.
Both carry phones gossiping location history to surveillance state. If any of those bills are brought to a bank by some seller, neither Randy nor Rachel will have visited the sellers store recently, so the spooks know it switched hands.
Find any consumption place (bar/shop/...) which both Randy and Rachel have visited "shortly" after each other (location history), since they were last known to carry the bill.
They apparently both went to the same bar.
1) You better not carry your cellphone when anonimizing your 20$ dollar bill in the bar.
2) You better (in the bar) not be within the "light cones" of 2 events: going absent from your phone (forward speed cone), rejoining your phone (reverse speed cone). So locomote very fast!
1) and 2) frustrate each other, better just don't own a phone.
Your phone can detect from noise, motion (accelerometer/gyro),etc if its owner has left it behind or returns, and you will be one of only few people in a large radius who is not carrying his phone like a good boy.
They are not directly interested in tracking Randy and Rachel, they track them to track those who anonymize. They are not directly interested in tracking you probably, they track you to track the hard targets. When most substantial (i.e. bills) money flows are fully explained, only a sparse amount of bill transmissions, and a sparse amount of suspicious behaviours need to be matched.
EDIT: 1) When you anonimize a large bill by splitting it, and you get multiple bills back, you must destroy the lower amount bills. (EDIT 2: CORRECTION better keep it and leave it on a train, different trains for each superfluous bill)
2) Lets pretend the introduction of smartphones was the start of surveillance state, say 15 years ago. Individually we have potentially 15 man-years of experience with surveillance, on the other hand a 250 million population nation state has 15*250 million man-years of experience with surveillance!
3) Given a sequence of hypothetical events, it is easy for me to attack a known strategy, but how can the state collect anonymizing strategies? "Easy" : for each flawless execution of anonymization, there will be hundreds of flawed executions: a person not realizing he shouldnt carry a smartphone but correctly splitting his bill after ATM: if enough cases like this are found, you can try find other patterns in their common behaviour, for example after using the anonymized $10 bill on whatever, doesnt see harm in using the extra $5 bill (in conjunction with say his phone, or in conjunction with a fresh $20 bill from ATM)
From all the known (but failed) attempts, we can try and look for alternative ways we could have anonymized them. Some will turn out to be aware of other side-channels and will have found original remedies for one problem, introducing a second sidechannel, which can be taken into account in the future
If another customer comes in and gets Alice's note in their change (which is fairly likely since it's sitting at the top of the stack) then that note becomes entirely disassociated from the original purchase.
I.e. is the code printed at the time of buying? Or does it have a scratch-off code and packaged in plastic wrap? Is it scanned under a device while selling?
Even if there dont seem to be any unique codes, an IR fluorescent barcode could be used on the card, or its plastic wrap.
Even if there are no unique codes, the cards might come from a rack or pack in sequence, and the cashier instructed to scan a new pack of cards when opening a new pack!
Yes, they have unique numbers, and the time/date/location of purchase is known for each card's number. Like I said, this is not secure enough to defend against targeted attacks by well-resourced actors, but good enough to stay out of the dragnet, at least for now.
Sorry for my English. I hope my question is understandable.
I love that idea. Algo[0] creates IKEv2 servers using mainstream VPS. There are also scripts for creating clients for iOS and macOS devices. However, in my experience, it's hard to get IKEv2 with strong crypto working on Linux. There's also streisand,[1] which creates OpenVPN, WireGuard, etc servers.
Also, there is VPN-Chain,[2] which alters default routing pushed by OpenVPN servers, to create nested VPN chains, without using pfSense etc VMs. And it does create iptables rules to prevent leaks.
However, although compartmentalizing VPN clients in different VirtualBox VMs is far more resource-intensive, it's arguably more secure. Indeed, sometimes I compartmentalize VPN clients in different hardware. But anyway, perhaps there are lighter compartmentalization approaches with adequate security. And one could use vagrant etc to create and configure the compartments.
Even so, client apps for nested VPN chains would be nontrivial. They're far more complicated than simple VPN clients, and so far more error-prone. You'd clearly want them to fail closed overall.
You'd also want feedback to diagnose failures, but nothing that connected directly to "inner" VPNs, which would normally be reached through other VPNs. In my experience, you optimize at each stage of building the nested chain. You may have a general plan. Which VPN services to use, in which order. But to minimize latency and maximize bandwidth, you need to experiment with various combinations of servers. It's likely a BGP-routing thing.
But sure, that could be automated. Most VPN clients have an automatic mode, where they identify servers with lowest latency and maximum bandwidth, within some constraint for exit location. So your app would just need to do that recursively, in building the nested VPN chain.
> It is possible to set up an anonymous DigitalOcean account funded by a Visa gift card and associated with an anonymous email provider.
I'd rather pay with Bitcoin. You can arbitrarily anonymize by using multiple mixing services, with independent local wallets. I use Whonix instances in VirtualBox, each with an Electrum wallet.
Each Whonix client can hit Tor through a different nested VPN chain. So you have some anonymity, even if Tor has been compromised. Even after the first mix, you should have different Bitcoin. But with three mixes, you've got anonymity even if one of the mixing services is a honeypot.
If you want better anonymity, just mix more times. And Whonix instances require very little setup, so they're disposable. Mix some Bitcoin, then nuke the intermediate Whonix instances.
0) https://github.com/trailofbits/algo
There are still some legal restraints on US agencies and military conducting signals intelligence within the United States.
But they are unrestrained outside the US. And we've seen that foreign networks are thoroughly compromised by US agencies.
So wouldn't it actually be safer for a US resident to select a provider based in the US?
That is likely a fantasy. The NSA is a military organization. And the US is always at war. So there's no expectation that the NSA will respect US law. At best, it will pretend to do so.
> So wouldn't it actually be safer for a US resident to select a provider based in the US?
It is true that there's no mandatory logging requirement for VPN services in the US. And PIA has prevailed so far on that basis. However, there are also National Security Letters, which might require logging without public notice.[0]
0) https://www.calyxinstitute.org/sites/all/documents/08_28_201...
I assume you mean anonymizer.com? If so, can you point me to some reliable source for this info? Would like to know more...
> Abraxas Corporation focuses on services, system and technology solutions, and training programs across the United States National Security community, the United States Government, and the United States military markets.[1]
It was founded in 2001
> by a group of former high-ranking agency employees, led by Richard "Hollis" Helms, a longtime overseas officer in the Middle East and onetime head of the CIA's European division, and Richard Calder, who was the agency's deputy director for administration.
0) https://www.socaltech.com/anonymizer_acquired_by_abraxas/s-0...
1) https://www.bloomberg.com/research/stocks/private/snapshot.a...
2) http://articles.latimes.com/2006/sep/17/nation/na-abraxas17