Starting a new digital identity
k3tan.com
k3tan.com
Not that I want to have two identities, but I would like to be able to distinguish between them. It was not difficult, but required some effort to create separation (I didn't want twitter suggesting my "business" account to my friends I already followed on my personal account).
Facebook was another story. I have never had a Facebook account until a couple of weeks ago. I took on a new hobby recently, and the most active community around this topic is exclusively on Facebook. I joined and immediately disabled the ability to be seen to the extent I saw possible. But then Facebook disabled my account within 24 hours – the irony! They allowed a review process, which required a selfie (they clearly know my identity through facial recognition, despite having never supplied a picture myself). They let me back in fairly quickly. But I hate having to "support" the ecosystem. And it turns out I cannot friend anybody without allowing their friends to view my account.
There are existing, well-established online communities outside of Facebook for this particular topic I am interested in. And now that I have found out about the Facebook group, I see why they appear to be slowly dying. OP seemed to imply it's Facebook or nothing. I disagree with that.
And I think there are many examples of communities outside of Facebook that do it well in a privacy-friendly way that are well supported by its members.
I am definitely making an un-forced choice to join to have access to their content. The trade-off, of course, is that I have to agree to their terms and offer my pseudo "support."
I only had to activate a Facebook account because the Oculus Quest 2 required it. I’d rather not have an account
(also, Monero > bitcoin)
Mexico already tried something like this in 2008 IIRC, and it was aborted because the database was leaked and sold for like 20-30 USD a copy. That database empowered fraudsters then, and I fear this new one, having recent biometric data, would be even worse if passed, as our government is an even less capable digital steward now. If this law gets enforced, an loophole like the one DigitalCourage uses would be closed quickly.
There will be some delay until it's implemented and apparently there are plans to contest it.
(This seems to be common for people churning/abusing new account bonuses.)
- Take the cost and go physically to such a country
- Use online services such as dtmf.io and pay with Monero (there are others but I didn't test them and some are "sketchy" to say the least)
But you could also just ask someone you trust in such a country to buy one for you (carefully) and mail it to you including a top-up voucher paid by cash.
Otherwise well just don't use services that require phone numbers for verification. No other way I'm afraid.
With mandatory (and otherwise widespread) masking policies right now, it's even easier than under normal circumstances.
And the godfather, depending on how local laws are written.
Theoretically possible, yes, but in practice, I think the only option is if you have the "right" connections with organized crime. I don't think you'd be able to solicit on the streets, even in the capital.
Agree, but IMO both are old tech since they're proof of work. Any good privacy-focused crypto like monero that's efficient?
Pretty recent rundown of privacy coins posted on reddit: https://www.reddit.com/r/CryptoCurrency/comments/md3toy/2021...
First, the OP describes an eSIM for his mobile phone - in this case with a provider named "silent.link". In my experience, eSIMs provide "voip" numbers and not actual "mobile" numbers. This is an important distinction since most 2FA verifications[1] come not from a phone number, but from a "short code"[2] and voip numbers cannot receive SMS from a short code. So you are quite limited in what services you can sign up for and maintain with just an eSIM.
Second, the term "threat model" does not appear in the article. This is important because if your threat model is "everyone except state level actors" or "everyone but state level actors AND my bank" the possibilities open up dramatically. I think there is a tremendous amount of benefit in remaining anonymous in relation to your carrier and the FAANGs and (various vendors) that is realistic to achieve - but anonymity in relation to state level actors is practically impossible.
Third, there is a big, giant blind spot in the entire chain of identity and that is the following: VISA/MC do not validate name and address[3]. It seems like they do - and merchants believe that they do - but they do not. This means you can use your bank card with any name you like and the minimal address match (which, in the US, is zip code). I'm not going to diagram this out for you but if your threat model is (everyone except bank and state level actors) you now have the basis for a working pseudonym.
Fourth, a second blind spot in the chain of identity is a business tax ID (which you can get for free at[4]). Many providers (like mobile carriers) ask for things like SSN, etc., but if you say "business" and give them a tax ID, it's like their brains turn off. They typically don't even ask for ID. You can initiate service over the phone. You may be forced to pay a higher rate for "business service".
[1] gmail, your bank, even twilio (ironically).
[2] https://en.wikipedia.org/wiki/Short_code
[3] AMEX does.
It was a special kind of hell getting them to fix that, because of course any discussion about it, or changing anything else on the account would take the form "what's your SSN to verify your identity?" / "Well, I can tell you my real SSN, but I don't know what wrong SSN you have there...", etc, etc.
Eventually I sat down with some poor staff member at a retail location who spent an hour or two getting transferred around at the head office to fix it.
Are you conflating eSIMs (which are just equivalent to physical SIMs) with "burner phone" apps? I guess it's possible that the MVNO uses voip numbers rather than "real" phone numbers, but several large mobile providers (eg t-mobile) use eSims.
> This is an important distinction since most 2FA verifications[1] come not from a phone number, but from a "short code"[2] and voip numbers cannot receive SMS from a short code
jmp.chat is a voip service and supports short codes just fine.
I am thinking specifically of eSIM providers like truphone who do all kinds of nice and interesting things, but the numbers are voip numbers. Yes, you do get a physical SIM from truphone but the numbers terminate to (non-mobile) numbers. You can't get SMS from shortcodes with truphone.
"jmp.chat is a voip service and supports short codes just fine."
I'm not so sure ... the issue here is receiving SMS from shortcodes (which is how gmail, for instance, sends 2FA auth to you) and I don't see that jmp.chat can receive SMS from shortcodes ... see[1] which says:
"Unfortunately it did not. I was not consistently able to receive short code SMS. I've since fallen back to using cellphone service from Telus which allows me to receive shortcodes."
[1] https://www.reddit.com/r/VOIP/comments/8z44iu/mobile_voip_ca...
Hi there! One of the lead devs at JMP.chat here -- our service definitely supports receiving SMS from short codes. We cannot currently support Canada-only short codes (only north-america-wide short codes).
I personally use my JMP number for receiving 2FA codes all of the time (and I have not had another phone number in 4 years).
Can you comment on this:
https://www.reddit.com/r/VOIP/comments/8z44iu/mobile_voip_ca...
... and why the author might have experienced that ?
That has nothing to do with eSIM though? That’s just the operator terminating VoLTE to VoIP numbers. eSIM is the equivalent of OTA flashing in good old CDMA2000, just in LTE.
You are right but this issue is even bigger as many smaller providers too use something that is more VOIP than anything else. My actual phone number gets redflagged ~80% of the time. Meaning i use shady SMS verification services most of the time.
The covert lifestyle can be mentally taxing, and you will make mistakes (if you're not consistently careful). Here's a good quote from that Grugq article:
As I phrased it in my “The Ten Hack Commandments” — be proactively paranoid, it doesn’t work retroactively.Catch the flu or a cold, get shorted on sleep for one or more nights or have one distracted moment for any random reason and that can make the whole thing fall apart. People seem to vastly underestimate this reality.
Also: In practice, people who are in earnest on the run are often identified based on things like subscribing to their favorite magazines related to their hobby.
I think for most people that's the harder thing to address: How do you just stop being yourself and develop entirely new interests?
Trying to just not do X because it's closely associated with who you are is amazingly hard and can rapidly start making people actually crazy. This is much harder to do than breaking a bad habit which is infamously hard for most people under the best of circumstances.
But why? There's countless people that enjoy the same things you do. Unless you're into very niche activities, it should dilute in the noise. Maybe drop the least popular activities/subscriptions/toys?
You’d be surprised.
Anyone have the link? I can’t seem to find it.
Furthermore, no contact with people from prior life. Access to healthcare. Access to money if you didn't take a big pile out (and then where do you keep it?) Where do you live without a bank account? Driving is a big risk. The list goes on.
Protonmail faces a lot of spammer signups for their free plan and require a reCaptcha, Email, or SMS to create a free account[0]. In practice I've always been asked for a email or SMS.
They do clarify:
>We don’t save reCaptcha results. If you are presented with Email or SMS verification, we only save a cryptographic hash of your email or phone number which is not permanently associated with the account that you create.
so it seems okay, but there is a temporary trail (I remember reading that they delete these after some time) to your original email/mobile to maintain rate-limits.
Something to keep in mind.
[0]: https://protonmail.com/support/knowledge-base/human-verifica...
I suspect it depends on your IP reputation. A VPN or tor exit code would definitely get hit with those measures, given how much abuse emanate from them. The IP reputation of a local library would be relatively clean.
The person looking into you might shrug and be like, "this is all we have on them."
... committed identity theft, punishable by 20 years in the can.
I have sometimes thought it would be (more) interesting doing this with a real identity. I suspect it wouldn't actually be that hard to find an identity / birth certificate for someone from an obscure county, perhaps with poor / lost records and try to build up a paper trail from there, as much as a sport as anything else.
I have a suspicion that it would be fairly doable to get quite far with it, but of course one slip-up and you could end up in prison.
Felonies are funny that way.
That would not get you a driver's license in the US. You're also required (probably in all states--certainly to get a REAL ID-compliant card), you need proof of citizenship or lawful presence.
Criminals have been doing it for ages though, by keeping a low profile. You cannot reliably hide from the state, but if you seem insignificant you can go unnoticed for a long time. Low-level dealers in many countries just use WhatsApp, some straight up text and call, despite knowing police could always be listening. If you're selling to a couple dozen people, the police won't bother tracking you down. They have bigger fish to fry. Higher-level dealers engage in much more OPSEC: using fake names, not letting anyone not involved see them, meeting in person etc. This is a consequence of the fact that they are more likely to be noticed.
What is nym in this context? That's a new word for me.
The pseudonym a person selects and uses to sign his or her postings to websites, blogs, etc. so as to create a unique online identity without revealing their actual name/identity.
"With his most recent idiotic post, Little_Brain really lived down to his nym."
It is shorthand for pseudonym.
Although it depends who your adversary is at the end of the day.
In fairness, using contactless payments is super convenient and although it leaves a data trail, the sheer convenience of being able to buy a beer without fumbling around in my pockets is great. It's the old privacy versus convenience argument. But then, here in the EU you can compartment your card use with things like Revolut, and you can even secure your card by setting a limit on how much you can spend with contactless (no affiliation with Revolut, I just enjoy their app).
Of course in an ideal world, there would be no such (transparent) data trail and you would pay for everything with Monero, over Tor lol
I had the same dirty feeling whenever I paid with my Revolut cards as I do when someone I legit want to connect with adds me on Facebook.