Be anonymous
kg.dev
kg.dev
- if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could easily flag you to your government. If you use wifi at a common point you're likely to be flagged and there isn't an easy way other than keeping on the move. But moving often is another anomalous event, and it's very difficult to do even for Drug Lords ( El Chapo ) or Terrorists that it behooves to do. This puts you in a sort of Zugzwang, to borrow a chess term.
- there's always leakage, for instance, in the way you talk with people in the real world. At some point you send enough communication for sophisticated frequency analysis.
- and there are other patterns of usage that could be used to identify you, like searches or even keyboard frequency on anonymized accounts can be de-anonymized by very specific markers ( ML works! ).
- off ramps for crypto aren't very good. If you're in e.g. Brazil, haha, yeah, good luck spending bitcoin or any other crypto and going unnoticed. Mixers and tumblers will eventually leak and you'll be caught.
- you're very vulnerable to social engineering by people you do business with. one slip where you stop communicating in a transactional mode of communication and that's a weak link in your armor.
In the end, the FBI only has to be right once, and you have to be right every time.
https://theprivacyblog.com/blog/anonymity/why-tor-failed-to-...
People he spoke to, witnesses they could....encourage....
The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did).
First step is to understand that any system could be bugged. Every IRL confidant could sell you out. Every keyboard could have a keylogger, etc. Every store could have a security camera. Phones are giving out their MAC numbers to every cell tower and wifi radio. They now have chips you can’t turn off, and so forth.
You should also assume there is no such thing as an “anonymous” account and that every service COULD sell out whatever information you gave it. (Yes, even Telegram or ProtonMail, however unlikely that may be.)
The below is a playbook for how to become truly anonymous. Continue to live your everyday life but the below is only for your “anonymous” identities, which you can gradually bootstrap as a hobby:
The first thing you do, therefore, is bootstrap your identity by taking advantage of unlinkability that is available to you. Buy a bunch of Android phones on Craigslist for cash, for example. (Or pay a homeless guy to buy a phone in a store for you.) Do not use SIM cards at all, only WiFi. Never take photos, etc. Keep your phone off or in a faraday cage until you use it. For extra points, always use it through a VPN on WiFi at home, which you purchased using the accounts below:
Then make an anonymous google account on the Android phone. Make some ProtonMail accoung usinf such an anonymous Google account. Now you can bootstrap from email addresses.
Buy some Google Play gift cards and download some apps to get a second number. Now you can bootstrap from a phone number. Sign up to Telegram, Signal and other accounts using this. Now you have end to end encrypted messaging.
Frankly, though, realtime messaging is a bit of a luxury to continue to stay in normie world. To stay truly anonymous, you should continue to:
1. Schedule posts and mail send/receive at random times. Do not ever use realtime audio or video because it might be recorded. You might make an exception for early days of your projects when people would have no reason to go out of their way to record you — just to give them confidence you’re a real person. But afterwarss, stop doing that. Let the people build your movement for you.
2. Never mention your anonymous identity or projects from your real one, and vice versa. This means your anonymous identity MUST NEVER have confidants or colleagues IRL. Build up a network of colleagues who are “fronts” for what you do. Eventually you can step back and let the movement do things for you.
3. Pay and get paid in cryptocurrency. Have smart contracts send you the money (think Richard Heart’s Hex origin address, but actually anonymous).
4. You will only ever be able to spend the crypto on paying people for services and DeFi protocols. You can never cash out to fiat, because the IRL purchases catch up with you when they follow the money. There is a surprising amount of online services you can spend $97 million dollars on, while staying anonymous ;-) If you really do need to spend money IRL (because you went broke somehow in your everyday life) then you can cashout using cross-chain bridges and Monero to pay for goods. But still, never get ostentatious wealth IRL!
5. The weakest link then becomes your writing or coding style. Never publish any code or writing, let others do it for you. Make your communication to others from your anonymous identity sufficiently different than anything saved later would not identify you (this is the weakest link, but you can consider “playing a character” when speaking to others).
6. Any private keys that you used to sign your messages can be periodically published in some conspicuous place, effectively giving you plausible deniability about all your previous and future posts. It’s hard to prove a negative (that no one else has access to your private keys before your public disclosure.)
Alright, Hacker News. I have given away the non-amateur anonymity playbook using https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle
Go ahead and try to deanonymize this in the comments below. Assume you are a state actor with all tools at your disposal.
Is it not, for the non-criminal user? My HN, Reddit and Twitter accounts are "anonymous" (pseudonymous would be more accurate), and it matters to me to the extent I share thoughts I would not on Facebook or if Googling my name lead straight to it - not that I'm ashamed of them, I try to be decent (tho I slip at times and am more brash than I would IRL), it's just that they hold some personal opinions and matters, kind of like that lady in OP's post (except I wouldn't reuse pseudonyms, especially not openly cross-linked to identified accounts). Obviously, a governmental agency that had any reason to look for me would link them in the blink of an eye, but it is "anonymous" enough for my needs: people who matter to me or people like prospective employers do not know of them and hardly could. Even if they leaked to some dark corners of the Internet like my SSN (screw you, Equifax), that hardly doxes me as far as regular humans are concerned. If someone emailed me with my online usernames, it would creep the fuck out of me, but ultimately be inconsequential, at worse it would threaten to shame me for my opinions.
So how's that not on a spectrum of anonymity? OP's post obviously does not say your anonymity when it comes to three letter US agencies is on a spectrum, that is black and white and s-he recognizes it, but rather the link-ability of your online presence(s) to your real life identity. With that Tinder lady at the "IDGAF"-end of it, your paranoid (or criminal) Jane Doe on the other end and me somewhere in between (but much closer to the former).
Per Wikipedia:
>Anonymity describes situations where the acting person's identity is unknown. [...] The important idea here is that a person be non-identifiable, unreachable, or untrackable.
Using a phone is probably the first mistake. If you are going to use your home network you are better off using a machine you control and an operating system that is open source.
I suggest these steps: Step 1: Connect to a popular vpn. Step 2: Connect to tor Step 3: Get free vps or pay with cryto you trade for gift cards purchased or some other method Step 4: Connect to vps with desktop running. Use virtual desktop. Step 5: Use vpn. This time use vpn with best rep to be accepted as regular traffic. Step 6: Signup for services
Step 1 solves the k issue. Many people using that vpn will connect to tor
Step 4: Seems slow but at the virtual desktop level out things are fast from that machine to new hosts. Use scripts could help.
They still had to somehow link your online identity to your phone. And how would they do that? The phone is simply a computer that you use, through VPNs, to send and reveive mail and post messages to groups etc. They’d have to approach ProtonMail, then your VPNs in order, and then get security footage from the place where you were accessing the VPN at that time. And then cross-reference your gait etc. to a database. Maybe in 10 years they would have such coordination, and we will need better tactics.
What’s far more interesting is what to do if VPNs are banned in a country. You can’t be using one there. You’d have to have set up anonymous hosting and port forward stuff yourself.
Again, it’s possible that all anonymous hosting, VPN etc. is shut down and requires KYC by say 2050. That is why you must bootstrap from what are valid but essentially “compromised* accounts now while you still can, and hope they are grandfathered into the new totalitarian surveillance system. Buying phones on craigslist is one example.
Another example is those eyes Anderton installs in Minority Report, but security in that movie is like a bad joke, IRL he’d be outed instantly by his gait, heart patterns via wifi and so on. In fact they didnt even change the access keys after he ran LMAO
It seems that this would work for a while, but if we're trying to bootstrap well into the future, a shiny new phone of the hour Samsung S22 showing up new on the network only 15 years out in 2037 would stick out like a beacon, and that's assuming it would even connect to the then-current comms protocols.
This is nontrivial
but you can't find the "Don't automatically connect to this network" flag that stops a device from doing what you described?
Don't tell people what is and isn't possible unless you're sure.
Your opinion is purely speculation, and only true for people of your skillset.
It would hopefully keep the sentiment while changing the words.
The hardest investigation to defend against is the rubber hose investigation. Gotta give them what they want, without them even suspecting you could be that mysterious founder. The only way people suspect you’re someone is if your k is small, eg how many people could be Satoshi?
If you’re efficient, you can retire the mysterious founder identity and simply have multiple “early adopter” addresses that generated rewards early, among actual adopters. Make an exit from your projects as early as you can after they gain momentum with the wider crowd.
There is no way to stop people from starting open source projects, accruing the early rewards and then selling those rewards to others in a decentralized exchange or async OTC deal. If every country worldwide ever closes down all such anonymous mechanisms (maybe by 2050) and makes register in order to sell your rewards, you simply sell your private keys to the wallet in an async OTC deal. The buyer will have to trust that you won’t move the money after they register the address and before they move it.
https://m.youtube.com/watch?v=wUJccK4lV74
https://m.youtube.com/watch?v=SYZqC7EGMfM
To not share how you secure anonymity is to rely on security by obscurity. Now I think it’s better to lay out the playbook using Kerchkoff’s principle so k will become far larger than 150. Remember… to improve anonymity, at some point you have to publish your private keys. And where better than Hacker News?
The playbook is yours. Improve it!
Step 1: try to break it. Post how you’d defeat the anonymization scheme. The threat model is that you’re all state level actors combined. I’d love to see what you come up with.
Nice try, Feds! :P
My first question about this plan is "what are you getting paid for and how do you advertise your services"? You need to never meet the people paying you in person, and ideally you are selling some purely digital good. So, something like underground illegal programming or hacking or such? Is there anything else that would work?
No, you don’t do work for money. You start an open source project and get many people to run your software. You meanwhile generate as many early rewards as you can (you can even do it under multiple accounts) and when the ecosystem is up and running, you’ll be the mysterious founder, generating millions (or billions) in passive income.
Sounds familiar? It should…
Simply never move money using your first few accounts, and whoever early people you pay, have them stake your currency for a long time, and borrow against it on decentralized lending marketplaces, to avoid spooking people that the mysterious founder has moved their money.
That's one of the problems with trying to stay anonymous, right? The playbook constantly goes out of date.
Living in no-extradition countries, using GrapheneOS on an Android phone, using Jabber/OTR chat for communication.
It’s a modular system. The key is Kerchkoff’s principle — I can describe it to you all day long, but as long as I don’t reveal each identity from the other, you all won’t know what projects I am doing, even if they earned $97 million already.
The timing could have been conincedental. Even if he was the only person online on campus at the time, it proves nothing.
South America is the greatest tumbler of all. I spent years in Argentina under the currency restrictions and paid my rent in Bitcoin, bought USD and pesos at black market rates in Bitcoin, all with people I met on localbitcoins and never using an exchange. I don't know about Brazil, but there is a huge market for peer to peer BTC in AR and UY, and you can just trade an envelope of cash over the table at a Starbucks in Buenos Aires for anywhere up to $10K USD.
In the USA I would be scared of being on camera, but I really doubt you would have that problem if you meet someone in a bar or on the beach in Brazil.
[edit] Just to explain this comment for people who think of BTC as something that you have to buy or sell on an exchange where you're allowing the endpoints to be tracked; the original reason for cryptocurrency was that you don't have to show your passport or link it to a bank account. That still obtains in lots of places in the world where people will happily give you their shitty paper money for bitcoin, and you can use the paper to pay your rent. Don't buy BTC on an exchange, and don't sell it on an exchange. Buy it from someone in person in a phone-to-phone transfer, or win it in a poker game. Keep it in a private wallet, not an exchange. Sell it P2P in person when you want to. You don't need to use an exchange at all.
For example, you buy a burner phone, but the place you bought it from, even if a second hand shop, had a security camera. Maybe they also record IMEI's before selling phones.
Or you carry your burner phone together with your real phone. Or alternatively, you leave one at home when using the other. Both of these things can be linked by a sufficiently determined actor (FBI/NSA level).
Or they track you to using a public square WiFi one day. Again, cameras are everywhere.
If they got your real name, no matter how, it's game over. You will be surveilled and they will find proof to link you. This is why all those posts "if only DPR used this kind of encryption or dead-men-switch" are ridiculous. Once they knew his real name it was just a matter of time and building a case.
The surveillance state is already here. The dragnet is on for everyone, and if they miss anything it's because it's hidden in the noise, not that the signal isn't being sent.
We're cooked, it's over. Forget being anonymous.
I.e. cash, rural, paper letters for last mile
The internet is by definition centralized and the government has privileged access, from a surveillance perspective. Luckily, the number of people who really need this level of anonymity (i.e. I am wanted by every world government as a top priority) is pretty low.
I think this is the only way to feel truly at ease with the state of things, really. Keeping a whole self in public or in private is asking a bit much.
You have layers and layers of technology in even the simplest modern computers, and core network infrastructure subject to tapping or worse.
And much of this that can be done from anywhere on the planet.
Analog requires physical proximity, a strength and a serious inconvenience. But it also has the property of being legacy, in that you are now immune to state of the art digital methods, and susceptible to older ones that may be out of institutional memory and practice.
**SPOILERS** Once the US that's basically our world discovers the existence of "world walkers" when they nuke the Whitehouse, it quickly steps into an authoritarian surveillance hellstate capable of realtime surveiling the population around the country to the point where they can track people entering their timeline because they were on camera exiting a building they were never recorded entering, or were flagged buying a plane/bus ticket from a city they shouldn't have been in according to previous records, or in one case for leaving a coffee shop with a noticeably empty backpack when she'd entered the shop with it completely full, having passed the contents to a world walker she was meeting. That irregularity automatically flagged everyone entering/leaving that building for review in their system and they backtracked all of these people through their paths that day until finding the gap where he'd stepped through to their world. That all happened in a matter of minutes and then quickly homed in on him.
Anyhow,it goes into detail about the lengths they go to to avoid detection by these systems and honestly didn't strike me at as all farfetched. The technology and capacity exists and it's a concentrated effort on part of the government is all it would take to implement it.
I get 93.22% for defendants in US District Court in 2019. And 93.16% for 2018. (Edit: Fixed some math & dates)
Edit: Found the referring agency line item. 91.12% for FBI-referred in 2019, 91.34% in 2018.
If you're going to quote statistics, don't just pull them out of thin air. The government is required to report this stuff, you know?
Like "being super careful isn't enough" _might be true_, but if you did everything on this list and get caught anyways, you are in a super minority of people getting caught.
The example in the article (a hotmail-based email address being used). Everyone sees this and immediately goes "OK the feds can get this info". If such a basic opsec failure was happening, how is it that this person was still able to get as far as they did building up their website?
Being worried about the feds finding you from speech analysis of your posts online seems a bit silly when it's always _not_ that and much more just "finding the one simple thing you did wrong".
Sure, if u piss off the wrong agent and they spend a few years on the case you may get busted. But the vast majority?
Tor is the definition of deceptively simple, and there are a lot of impressionable people who read articles like this on the web when they’re first starting out who could easily be lulled into a false sense of security and then start transacting on the darknet and think they can’t be touched. OGs on HN know better and remember the threads where tptacek and cperciva would routinely dismantle this notion of tor or VPN anonymity/security.
Whonix uses Kloak to mitigate this [1], but unfortunately it isn't available in Qubes-Whonix.
> Mixers and tumblers will eventually leak
Don't use mixers and tumblers, use Monero and/or Monero atomic swaps.
But, you are right that it is futile to maintain defense against a determined 3 letter agency.
[1]: https://www.whonix.org/wiki/Keystroke_Deanonymization#Kloak
I'm about to publish an update to it that uses a toolbar popup to fill out forms instead of the current lag approach, which will also protect against keyboard layout leaks[1] (which Tor browser/privacy.resistFingerprinting protects against anyway)
Monero doesn’t make your transactions anonymous, it makes them ambiguous. your wallet might default to using an n=6 ring signature, meaning it picks 5 random addresses with balances and creates a transaction that could have plausibly originated from any of those 5 or your own. so you get plausible deniability, but also if your threat actor can unmask the other 5 addresses (which might not be so hard if those accounts are regularly interacting with exchanges) then you’re done.
zcash gets you actual transaction-level anonymity, not just ambiguity. fewer places accept it, but in theory you can still break the link by obtaining zcash and then exchanging it for the currency of your choice on any exchange that doesn’t ask for PII (e.g. a DEX)
Yes, working from home is very suspicious. :P
(That said, the VPN companies that work in the B2C segment for those who can't set up their own VPN server is small and they're all well-known to the government.)
Getting to 99.99999% reliability is very difficult for one person, it usually takes a highly diligent team with very well-sorted processes.
Privacy is never a guaranteed thing when you introduce ubiquitous computing to the mix, even things outside of computers can profile you like being captured in CCTV around the time when your signals are picked up from a computer/smartphone phoning home or unusual internet activity, like the scene out of Mr. Robot.
We need to be exchanging personal data only in forms that become worthless and unidentifying in a short period of time, requiring secure refreshes to maintain.
Sell a little bit of drugs through the silk road and you'll get royally f-ed! Sell all the opioids in the world through a public pharma corp and you can keep enjoying your jet-set life and yacht.
The allegedly smartest people in the world are focusing on the dumbest problems while being reamed by the frat-boys that went to Wall Street and Politics, guns and drugs. LULZ.
https://www.theguardian.com/news/2022/feb/20/credit-suisse-s...
“The pretext of protecting financial privacy is merely a fig leaf covering the shameful role of Swiss banks as collaborators of tax evaders.”
And it's more than tax evasion, "include a human trafficker in the Philippines, a Hong Kong stock exchange boss jailed for bribery, a billionaire who ordered the murder of his Lebanese pop star girlfriend and executives who looted Venezuela’s state oil company, as well as corrupt politicians from Egypt to Ukraine".
Are you referring to some specific drug lord? Who?
My point being, this went on for a long time before they got "busted" and the bank people knew who they were dealing with.
They didn't have to use crypto or tor or whatever to stay anonymous. They just used cash, everyone knew each other. They probably had dinners with coke and champagne. And when they did get "busted", somehow no one goes to prison, there's a small fine (relatively speaking), and everyone walks.
My guess is they're all still in business doing the same thing. The bankers, the regulators, the cartel people...
Having worked in banks, you absolutely don't need to assume moustache-twirling villains to explain what happened; ordinary people doing the best they could to help out small businesses and families doing remittances would have had exactly the same outcome. Having spent a couple of months getting access to my own savings after moving overseas, the AML rules are plenty rigid enough already. Bankers are never going to be 100% perfect judges of whether someone is selling drugs and we shouldn't expect them to be.
>Since 2009, the investigation has resulted in the arrest, extradition, and conviction of numerous individuals illegally using HSBC Mexico accounts in furtherance of BMPE activity.
https://www.justice.gov/opa/pr/hsbc-holdings-plc-and-hsbc-ba...
I don't think you can compare a legitimate business publishing public accounting figures, operating within the law, subject to policy by elected officials with the illicit drug trade who's supply chains operate in the dark. These supply chains are probably responsible for thousands of deaths, human trafficking, and unfathomable suffering whose actors you have no possible way of mitigating their actions.
I grow weary of hearing this recurring argument that the relatively minor side effects of a free market being compared to pure evil.
"Three major drug distributors and the pharmaceutical giant Johnson & Johnson have agreed to a $26 billion settlement with states to resolve thousands of lawsuits over the country's opioid crisis, officials announced Wednesday."
https://www.nbcnews.com/news/us-news/4-companies-near-26-bil...
None of these executives were anonymous or ever had to be. They made a ton of money doing bad things, they'll keep most of the money and they'll never go to prison.
They way you deal with this is, obviously in my mind, through the rule of law and a robust functioning society that regulates commerce. Not wild-west free market.
But they did? They just did it 100+ years ago. Does that matter?
If what you really want is sovereignty, which is what most people confuse anonymity with, the goal is to be like what Ernst Jünger called the anarch (in contrast to the anarchist), which is someone who complies and renders herself indifferent to authority, rather than standing out and drawing attention.
A much better practice is to be as open as possible about the boring stuff, so you're not constrained and can do what everyone else does. Trying to be absolutist about anonymity is automatically like wearing a straitjacket.
One thing I noticed out of many of the list items given in the post here:
> Only use Tor > Always use a VPN > Never use Google -- only DuckDuckGo > Disable JavaScript on your browser > Watch all incoming and outgoing network calls regularly and scan for abnormalities > Encrypt your laptop and any external drives > End-to-end encrypted communication only > Don't use Gmail -- use ProtonMail > Never pay with cards. Use cryptocurrencies. > Turn off all location services from your laptop and phone
Is that these can actually be solved with technology in a way that these are thedefault and popular behavior (as TLS 1.3 is in HTTPS). So it's important that we realize that these technologies (or something like them) are important anddesired by everyone, but just need a bit of development to work. Https and signal are great examples. Many of my parents and grandparents are on signal now, because it's better than most other apps (whatscrap, Facebook msg, imsg, etc). Is the Loki network and Session better? Sure. Of course. But grandparents aren't using it yet because not everyone they know is on it yet like signal, just the tech knowledgeable, or many of their grandchildren.
But ultimately, None of this should require any effort whatsoever.
The rest of the points about concealing your name or not is more obviously a choice by the user, as they have to provide it knowingly - so it's less of an issue because they're more likely aware of their choice.
> Don't buy domain names I'm not sure I understand this one - anyone have an explanation?
When you buy a domain name, you are supposed to supply accurate ownership information. If you do not, the registry can yank your domain when they discover that. Most registrars obfuscate/hide the information in their whois service, but they still need to have it to comply with the rules of the registry. That information can be subpoenaed.
The purchase/renewal transaction(s) also leave a trail that can be followed.
Even if you put bogus contact info (this is not a problem, honestly) you still need to pay for it somehow. If you would use your own CC for this then... Bonus/prepaid/gift cards are usually not accepted (too much fraud), so the best solution would be to actually steal someone's CC data and hope they wouldn't notice 10 bucks.
John Doe from WI, paid his dues.
Once a year "John Doe" receives the e-mail with WHOIS info and a question if that info is still valid:
> We are required by ICANN to send you the whois information for these domains once a year. If the information is correct, no action is needed. Otherwise please visit our website and update your whois information
That's all.
Just don't use GoDaddy or some other shit registrar what can yank everything from you just because they are a stupid behemoth without humans in support.
Or do you think registrar has nothing to do all day and casually stalks it's customers? Sends their info to FBI to check? HOW?
Your adversary disputes the ownership of example.com claiming they're the real John Doe, but the victim of a crazy stalker-hacker who hacked their e-mail and forced them to change address and phone number.
The registrar looks at the details they have on record. The adversary can't prove any of the details - but neither can you.
This works right up until the thing you want to do - or the person you find yourself to be - is something authority is not indifferent to.
This gave me a radical company idea, on the other end of the spectrum: spam as a service. Something that'll take your name, email, and other things and put it all over the internet in questionable and plausibly denial ways. That way, even when someone is trying to find things out about you, it'll be hard to find, and easy to deny. (I'm kidding of course).
This is the crucial piece. It doesn't matter how careful you are; everyone who knows you has to be careful too. I have a... well, I hesitate to use the word stalker, because that makes them sound more motivated than they really are. But someone on that spectrum, anyway. After a few years of being harassed I managed to elude them. Then they found me again. You know how? They pieced together two pieces of information posted publicly by other people. That's all it took.
What if instead of spamming the correct information out, spam slightly incorrect information out.
Correct address, incorrect middle initial, wrong birth month, and a machine generated SSN would be from the right time period, area number, but with an incorrect group and serial number.
Example A: Apparent Nazi sympathizers planted inside the Canadian protests- some people thought they were provocateurs, others assumed they were legit and cast a negative light on the protests overall
Example B: Hunter Biden's laptop (before it was acknowledged to be real). Saying he was a target for disinformation campaigns mostly worked
In a realm of total bullshit the winners are the one who are best at lying. "I don't know what to believe and everyone involved is probably corrupt" is usually just an excuse to disengage and follow base instincts.
I agree. The parent poster didn't ask what's the downside, and I think it's this: when no one knows what to believe and starts to distrust most things, society may start to fall apart, as society relies on us trusting each other.
So while I think disinformation is one of the best privacy strategies (not so different from differential privacy efforts by Google and others, suggested by the OP but without the term name), I think the more we lie to hide, the more we spin others and ourselves in circles.
I really like Sam Lessin's essay on this at The Information, where he talks about how, with the nature of the internet being so easy to share info, we have to start spreading disinfo to even close colleagues, so far as even lying to ourselves.
I think this paradox is one of the most challenging paradoxes of our time: the internet makes it so easy for us to open up and share and yet it makes it so hard for us to not open up and share.
[0]: https://www.theinformation.com/articles/the-future-of-privac...
A similar take from YouTube (about modern-day Greece) that I happened to come across just this morning: https://youtu.be/404IeUzGNZ4
It is ALSO the primary goal of dezinformatsia and "flood the zone with bullshit" (promoted by e.g., Steve Bannon) techniques. While some will believe even the most stupid conspiracy theories put out there, many more will just conclude that finding the real truth is impossible/impractical and just disengage. This is a deadly threat to democracy and a key tool to anyone who wants to destroy a society or own it as an autocrat.
Yeah, that's how you win referenda and presidential elections nowadays.
Personas like someone who posts content during 08:34:40 - 09:23:23 except 08:43:30-08:55:23, never seems to be active during 22:00 - 06:00, can be narrowed down to something like a person commuting via bus route A from stop B to C changing to a train route from C to D through passageway E in the station.
From there you can look for a man looking down at a phone, or couple information with other factors, or throw in a bait like a giant stinking dead fish or a rare and loud car in front of him and watch for responses he'd make. IMSI catchers and Bluetooth scanners can be useful as well if your adversaries are resourceful. Time and location of transmissions and time of receptions can be correlated, in theory.
This type of attacks can't be mitigated on fast-paced social media at all; both posts and requests has to be queued and obfuscated for time.
Another aspect that's important and often ignored, is writing style anonymization. You practically want an offline tool, that removes idiosyncrasies from the text you write and makes it sound as bland as possible.
edit:
A related story. Around 2010-2012 I was working for a company, and I was part of a somewhat managerial group. At one point we decided to pull in direct employee feedback in an anonymous free-text form. Due to their writing style being reflective on the way they spoke, it was possible to point exactly who wrote what message. Of course, few exceptions existed, I didn't personally know all the employees in the company.
Or you can lead a double life. One for your public persona, where you don't care at all about security, and your real persona, where you do. This has been my approach on the internet since basically it started and handles were a common thing.
No, it's not.
Every online account (that doesn't involve money or legal paperwork) can have its own name. Then you can decide whether to have _some_ accounts ultimately link back to your legal name, or all accounts, or none.
> Or you can lead a double life. ... This has been my approach on the internet since basically it started and handles were a common thing.
That's exactly what I'm doing, and neither of us are living in the Brazilian rainforest, so anonymity really is a spectrum.
No, you don't. Someone else could, if there is one with high enough affection to you. I think you'll have to think of bulk ingestion and on-prem processing to be sure your activities won't trace back to you.
But for the most part these people are anonymous, and get to enjoy some of the benefits of that.
* Use Brave browser with ublock origins and privacy badger
* Use pihole + unbound to resolve my own DNS and do not use google
* Run wireguard on my home network that I connect to when I'm out and need to use wifi
* Be anti-google as much as possible. I'm still in the process of this, i'll switch my domain based email off of google soon
* Be anti-facebook and delete all accounts (whatsapp and insta included)
* Be anti-reddit
* Be anti-cloud and host everything internally as much as possible (except for encrypted backups, say for video cam footage)
* All of my home automation is local and blocked from the internet. If I want access, I'll connect to my VPN.
* Use signal with disappearing chats to communicate with my friends.
Still a lot to do, but it's a start...
Chromium-based browsers like Brave are ideal for security [2].
An ideal solution for privacy and security would be running Firefox+user.js in Qubes OS [3], or for even more anonymity, Tor Browser in Qubes-Whonix [4]. However, even this isn't bulletproof, and a 3 letter agency can still determine who you are with techniques like keystroke deanonymization [5] or other techniques [6] like traffic analysis. Tor is also not reliable for anonymity because the project is kind of a shitshow [7], so there's really nothing you can do to truly hide.
[1]: https://github.com/arkenfox/user.js
[2]: https://madaidans-insecurities.github.io/firefox-chromium.ht...
[3]: https://www.qubes-os.org/
[4]: https://www.whonix.org/wiki/Qubes
[5]: https://www.whonix.org/wiki/Keystroke_Deanonymization
[6]: https://www.whonix.org/wiki/Warning
[7]: https://www.hackerfactor.com/blog/index.php?/archives/906-To...
You know what's a challenge? Finding a good robot vacuum without the cloud connectivity stuff. After all this degoogling I'm not keen on the idea of syncing the plans of my house to whichever cloud service.
> Concealing your identity behind a handle is a juvenile and silly behavior characteristic of crackers, warez d00dz, and other lower life forms. Hackers don't do this; they're proud of what they do and want it associated with their real names. So if you have a handle, drop it. In the hacker culture it will only mark you as a loser.
ESR has long injected his own personal biases as established fact. The consistent fact noted here is that specific error, not the claims made through them.
That said, it was the gradual intrusion of ever-more insistent exhortations to use real names, and the rise of surveillance services which convinced me that the practice of using given names was no longer advisable. I'd date this to well before Facebook and Google+, notably with the rise of information brokers in the early 2000s. By the time Google+ rolled out as an "identity service", I pretty much declared last straw and ceased virtually all my own real-name interactions. Call that circa 2011, or over a decade ago.
I'd already been curtailing any such use for about a decade.
ESR was thinking about ppl like Daniel: https://twitter.com/bagder
However, over time I drop enough clues that people could figure my real identity with a little work. That leaves me with the worst of both worlds. It seems safest to assume that your identity is always tied to everything you do online.
It can even improve the original text, making it more clear and anonymous-style.
Then it would again boil back down to who forgets to run that to get caught/doxxed.
That's some REALLY good Solid advice.
I make sure that I can be found and attributed. I deleted my last anonymous account, a couple of years ago. In the Days of Yore, I was pretty much "Dick From the Internet." A real neckbeard troll.
There's a lot of reasons that I do it. The biggest, is that I want to be in control of my narrative. I learned from a couple of folks that are really good at curating their SEO results.
Also, these days (for a change), I'm pretty well-behaved. Doing it this way, helps to keep it that way.
Many people on HN probably know your handle/identity, if only by virtue of you referring to it in your comments somewhat systematically.
You manage your identity with an SEO mindset indeed. I do not mean to offend, but it does read just as fake as any SEO search results.
https://www.wired.com/story/alphabay-desnake-dark-web-interv...
Most "normal" people, and even many tech people, don't know what companies like Google and Facebook are capable of. If you showed someone exactly what information of theirs was collected, for how long, the predictions they could make with it,and god knows what else is being done with it, I think many people would change their behavior. But they don't know, and this is not an accident.
Most people do not even know what the business model of Facebook and Google are. If you ask, they'd probably say something like "oh they're an email company" or "they help me share photos of my grand kids" or god-forbid, they're "helping connect people connect". Both are surveillance-based, personal information-driven ad companies. That's it. No amount of Google X or Android or Gmail or Libra or FB Live or any other program will change what their business is. And they will never, ever admit to this.
Personally, I hang out at the fully open end of that spectrum. This has worked out pretty well for me; I don't think I've run into any downsides.
What do we want to achieve by protecting our online identity?
For me, escaping the pervasive tracking and profiling by FAANG is one goal. I'm sure that tracking me across the internet is a lot more difficult (not impossible) than tracking the average user. Hopefully it can't be done in an automated fashion. That way tracking me is hopefully just not worth doing just for a few advertising dollars.
Or rather: these are very basic and very naive recommendations, certainly good first steps, but absolutely nowhere near enough to guarantee strong anonymity on the internet.
Remaining truly anonymous on the net is extremely hard, especially in these days where ML can be used to statistically narrow down and pinpoint who wrote a specific piece of text only based on things like use of punctuation, vocabulary, sentence structure and style.
I think you can fight ML with ML - for example, use GPT-like algorithms generate text for you. But then you must also be careful about when you post - I remember some of the Russian trolls were exposed because their bursts of activity coincided with 9am-6pm Moscow time. So you have to use a random number generator decide when to appear online if you want to hide your location. There's always something which can narrow down their search. One small mistake and you are busted. They don't even need to pinpoint you exactly, if it's narrowed down to 1000-10000 people who meet the criteria, they already win because they have the capacity to go through the list one by one and eventually find you.
Generate via GPT-3 a text giving roughly the impression you want to make and then copy/paste sentences from online news media if you need the names of particular persons or events.
Would be rather crude though, but less tedious than literally cutting and pasting letters was.
> Move to Brazil and live in the rainforest
Juvenile, snarky, irreverent and irrelevant advice I'd expect to read on a 12 year old's Reddit post.
It's a list of extreme techniques for protecting ones' identity online. Of course, completely sanitizing your online presence is difficult, and probably unnecessary. I thought the two lists were a nice rhetorical framing - present a dilemma (total openness vs. total anonymity) and then wiggle out of it to a compromise.
The items I quoted do nothing to protect ones' identity online. Snark is only effective if relevant.
Your aggressive negativity is far less interesting than this blog, and serves no purpose whatsoever.
Living in the rainforest is an extra step to get outside of spying jurisdictions. As long as something doesn't eat you.
Qubes is a hypervisor itself, it's not designed to be virtualised.
>I don't know about you, but I don't want to do all of that.
> Don't use Gmail -- use ProtonMail
"ProtonMail logged IP address of French activist after order by Swiss authorities" https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
Which is about as good as it gets. Unless you know of a reputable email provider that ignores court orders? (bit of an oxymoron)
In fact, the article is the anti-thesis of itself. Blanket anonymity advice is the worst anonymity advice.
I've since decided that I am done with all that.
I was afraid my employer might question my Reddit posting history (they wouldn't.) I was worried someone who Googled me would think my past self was dumb (who cares).
Now my ideas are almost all public and growing more so by the day. I am working up the energy to start a personal blog, if anything just to document my ideas over time. I am adding my real name and email to my Github, HN, (not Reddit, yet, though it would not be hard to connect), IH, etc.
I want someone to be able to Google me and find my best work.
On the other hand, there are clearly cases and types of info/accounts that should remain private. I self-host as much as possible. I encrypt personal files before uploading. I have multiple Protonmail accounts. I use custom DNS, etc.
Ideas should be public. Information is a case by case basis, but I generally care a lot less than I used to.
I’m bipolar, which I really do not want anyone hiring me to know. I don’t want people at work (or my family!) knowing and reading what I write.
As a friend put it: once your coworkers find your Reddit account, it’s over.
It is a matter of choosing what to disclose. I think most people in free countries can disclose a lot, if not most about themselves while withholding things like their sexuality or medical/mental challenges without withholding everything.
And reddit is a special case, even I am tempted to open that up.
If I was ultra-privacy focused, I'd probably go with the DNS provided by my VPN or a self-hosted resolver like unbound+pihole.
As an experiment, a few years ago I put my mobile phone number on my blog, and to date I've only received 2 anonmous messages on Signal but no calls besides recruiters.
The old adage "No one is thinking about you as much as they are thinking about themselves" is true.
While it's good to practice good security hygiene, be mindful of also being practical.
Or "No one is thinking about you as much as you are".
It's liberating to be able to silo your social interactions. We used to have this.
There're times when I wished I had concealed myself saying certain things (or just haven't said it), and times when I felt the joy of recognition when people connected dots about me and became closer friend. Now as I'm getting old, it's just a habit, no longer about risks or rewards.
Yet, both younger me and older me will probably be very indecisive about doing this if they've never done it and are told about all the fortune/misfortune this has brought to me, including meeting my wife and thinking about suicides.
Me too.
> So all the good reputation and bad reputation followed me through, and surprised me in best and worst way.
Not so much for me, AFAIK. I think quite simply, pretty much nobody could be bothered to look for it.
This is the place where I lost OP. How can anybody be blackmailed with publicly available info?
On the topic: I believe that the serious level of anonymity makes life extremely inconvenient and uncomfortable. Always using VPNs, keeping small hosts in different places as exit points, checking and rechecking everything when connecting to WiFi or roaming. Keeping separate hardware, for that matter.
I don't see how all this parafernalia justified. Identity stealing? Just use 2FA for your key service accounts. Don't reuse passwords, use a password manager - those are today's basics every schoolchild knows. Use debit card instead of credit and never keep it's balance above $100. Turn on 3D-security on all your cards. Don't get involved into drug dealing. Things like this.
By pointing out to people who haven't gone looking for that info, or who might have come across it but not connected it to you, that it is indeed about or by you.
Non-carrier numbers won't work for many services, and unless I'm mistaken, you are required to provide an address, recurring payment method, and a phone number for 2FA to sign up.
I wish the messaging would include email addresses as well. It’s easy for everyone to use different passwords nowadays with deep integrations everywhere. But generated email addresses still require a lot of extra steps for most users.
To change this has to first become a mainstream concern.
Today there is iCloud email forwarding. But it’s still new and not as convenient to use outside of iOS.
Also I have no idea about the longevity of that service. Wouldn’t trust it as recovery mail for important accounts
Can anyone explain this? Assuming your data isn't in the WHOIS record, why does this increase your exposure more than any other company knowing your name?
A search shows up options for anonymous domain name services.
All the registrars sell access to the real names behind their "privacy protection" service. They do not bother checking if the requester has a warrant or is even affiliated with law enforcement. They simply charge a fee (around $50 per request) to prevent bulk extraction, and possibly review the top 50-100 highest-volume requesters.
njalla is really the only way around this, but you have to trust them with legal ownership of your domain.
if you must do things online that are best kept detached from your IRL/govt identity, setup a box running something like Tails that doesn’t accept any non-Tor traffic, and interact with it through a text-only interface (i.e. a shell, or links-like keyboard-driven web browser).
people sometimes discourage using obscure setups because they allow better fingerprinting but that’s not always as bad as it’s made out to be. primarily you want to break the link between your pseudonymous identity and your IRL identity. it doesn’t matter how fingerprintable your pseudonym is so long as the overlap between it and your IRL identity is small. and that’s the reason to prefer simpler interfaces like text-only: they prevent leaking things like cursor movements which might otherwise build a tie between those identities.
Anything else and either your crimes are small enough or you won't have protection.
You give hints about your age, where you have lived, maybe about hobbies, education, work history, time when you are online. Each individual bit is not much, but when you combine few of these, they actually identify you exactly.
If you actually need to be anonymous the daunting but doable tactics on https://anonymousplanet.org/ are a much better bet.
You should not accept the state you're in without knowing what state that is. Most people should have more anonymity than they're giving themselves.
"Defend your rights. Nobody else will do it for you."
-- ReactiveJelly
I don't like seeing white lines as an after image on my retinas.
well, I got tired of caring already, but maybe others havent.
OK but why?
The dodgy guy who ran that website had to own the domain name somehow?
It requires 43 bits of defining information to identify a single entity online.
Those bits might be your name and date of birth.
Or they could be your home and work postal code (effective for better than 90% of the population, at least when commuting to work was a thing).
It could be your activity patterns, and what that says about your sleep/wake cycle, and possibly travel patterns.
EFF's Panopticlicck found enough distinctive information within Web browser characteristics to uniquely identify the vast majority of people submitting data to the project.
If you want to duck most casual observation ... then yes, standard precautions can be effective, though it's quite likely you'll slip and leak information at some point. Those clues can wait years, or decades, to be unraveled. Against law enforcement or state-level actors, you'll probably need to try considerably harder, though it's helpful to realise that what such entities have is typically far more data and the motivation to look through it for patterns and correlations, rather than superhuman cracking skills.
An area that's been of interest to me for some time has been the question of just how many investigations might be possible under various security or investigative services. My suspicion is that capabilities are constrained --- that is, there are fewer investigations than one might think --- but that the resources which can be brought to bear are considerable.
As an example, the US Federal Bureau of Investigation had a 2019 budget of $9.6 billion, with 13,412 special agents and 20,420 support professionals, as of 2009.
By news stories, the January 6, 2021 investigation has been the largest in the Bureau's history, with 350--400 arrests and 1,300--1,500 grand jury subpoenas.
I haven't seen data on how many investigations the FBI conducts annually, or how many cases are submitted for prosecution, but suspect it's on the order of thousands. The Bureau no longer seems to produce blunt gun-in-your-face reports typical of the Hoover era as with the 1969 annual report showing a chart of convictions by fiscal year (over 13,150 for 1969, here: https://archive.org/details/FBIAnnualReport1969/page/n5/mode...), though I suspect levels are at least roughly similar. That was an average of three arrests per agent, and the 1969 report states 2.8 million name searches were conducted that year, along with 2.6 million pieces of mail and 241,000 telephone and telegraph communications.
I looked up his e-mail address in his profile (I'm the admin). I punched it into google, which led to what looked like a public chat log. The e-mail address he used to register his account there was listed right next to his old username, which we recognized as the stalker's.
We banned his account and the stalked member had to contact their solicitor, again.
anyway tl;dr never post your e-mail address or a variant thereof publicly, especially if you're trying to be anonymous.
Become ungovernable
I don't think the lesson we should take from AlphaBay is "Take better privacy safeguards" but "Don't set up an illegal dark web operation."
In a lawless society what this guy was doing would have been a respectable trade like any other.
No, this guy was much worse and more harmful than the norms of our society and those that propagate those norms.
Holy shit, that fucker is still alive!