De-anonymizing programmers from binaries (2017)
arxiv.org
arxiv.org
De-anonymizing programmers from executable binaries - https://news.ycombinator.com/item?id=16598962 - March 2018 (39 comments)
When coding style survives compilation: De-anonymizing programmers from binaries - https://news.ycombinator.com/item?id=10806956 - Dec 2015 (67 comments)
Has anyone tried to use the source code and white paper to figure out who Satoshi Nakamoto might be?
If you can figure it out from binaries, surely there is a lot more info. And you have the github and the blogosphere to compare.
There are allegations that Satoshi may have accidentally slipped up and leaked IP address that was not a Tor exit-node or other anonymous-proxy.
Could either be Satoshi fucking up and not using Tor all the time (has happened to other 'anonymous' entities) or perhaps they needed a clearnet connection for some reason and managed to use another internet connection not attached to any identifiers that would lead back to them despite that.
The confidence level of the identification will be reduced as the sample size increases.
Interesting research anyway.
You just say that someone imitated your style. It's not like binary has cryptographic signature of person who compiled it, even then you can say that someone stole your private key.
Practically I don't expect this to have any impact beyond state surveillance, where obtaining a binary for a virus (or, you know, drm-defeat code) can identify its creator against any public code they would have posted elsewhere.
The second party has the obligation not the first. Ultimately all risk of exposure of personal data derives from the second party. For example if you mail in an executable to a client and put some code on github under your own real name the holder of the exe has no obligation because it is impossible for your identity to be exposed by it or indeed an infinite number of similar executables.
It is only when combined with your github profile where you willingly shared a work sample and your real info that you could possibly be exposed.
If it's true.
Are they sure it's not from text within the programs or other fingerprints?
I wish they gave examples of the fingerprints. It's hard to even know how to move forward without that.