I don't have a second account so I checked stylometry and it gave me bunch of names that I know are not me. Maybe I will try with a new second account and confirm.
Second, stylometry can dox me how? My current handle is not attached to anywhere else on internet and even if someone did HN/reddit/twitter stylometry analysis, how will that reach my home and or identity of my passport? Its not like I post anything online in my own name. Haven't in actual years.
So assuming an adversary was trying to find me and did see my reddit or active twitter account, so... What? Short of breaking into it and checking the 2fa number (which I avoid at all costs) how ? Maybe amazon but I don't write reviews so ..... How would you go about this?
By themselves, none of the things we discuss are inherently bad. They are just tools. I open with this, because it is important to understand that stylometry by itself uncovers only a small facet of your online persona, by possibly identifying your footprint and allowing for ingestion and analysis for OTHER identifying information.
Using your example your passport may not be online, but lets say you link self-hosted project, your website may be registered to your company and, depending on how you set it up, your information may be relatively trivial to run against information broker database ( LX, TR ).
It is surprisingly easy to slip even if you are privacy conscious of it and it really only takes one time since internet does remember ( and it is saved somewhere ). I guess what I am saying is I would not dismiss it outright, but at the very least I would check the link parent added; it actually is kinda amazing.
Lets say you borrow your dads computer to post and it's logged in under his name. You log into a site with an incognito browser and post a message in Chrome and then close it out.
Well due to a bug in that version of Chrome the full path of user folder Chrome was in was added to the request logs on the server 'C:\users\ronald.t.devito\appdata\....'. This gets put in the servers logs with your username. That server had bad security and the logs leaked to everyone on the internet. A hacker realizes that 'belli' is also use 'causi', and a few other profiles. They see that username is pretty unique to a 54 year old male from the west coast, but the writing style is of a much younger, likely male, person which points at Ronald's son Jonny.
You are at risk of being disclosed/doxx on the internet because of security issues everywhere in the stack and its exceptionally difficult to cover all the bases.
You don't need to give out your name and address to be doxxed, there's enough information from your comments across your accounts to reasonably identify you if someone wanted.
MIT did a study on 'anonymised' data and found out it only took something like 2 data points to identify someone.
Oh, if a comment needs a personal detail it's randomized. Sometimes I'm married, sometimes I'm straight, sometimes I'm American, etc.