How I stay reasonably anonymous online (2022)
tmp.bearblog.dev
tmp.bearblog.dev
Ha! Wishful thinking with all of the auto-archivers. If you post on reddit, it's likely already crawled and archived somewhere.
Personally I put a lot of PHP and VB code out ~20 years ago that I could find easily until I couldn't. There's Myspace profiles I've tried to pull up, images posted by friends 15 years ago in random places. Early video. All gone.
I’m not sure which factor is more influential—the ability for data to persist, or the ability for it to then be found and interpreted. Would it matter if the content was still available in some forgotten corner of the internet if there weren’t effective tools available for finding it and connecting it back to its author?
It’s actually sort of entertaining to test the limits of this on yourself. I tried to find original media and references from a band I played with circa 2002. We were being ambitious with our publicity efforts, and consistently pumping audio, video, and images onto whatever nascent services were available at the time (from memory I can recall CD Baby, LastFM, Craigslist, miscellaneous forums, and towards the end, MySpace). I had already been designing websites for several years by that point, so we had a website, one that wasn’t just a Geocities/Anglefire template. That said, I am pretty sure that was at the height of my career with Macromedia’s Flash and ActionScript, so no real surprise that it didn’t get Archived in any functional form.
One strategy that my own experience has found quite effective is to avoid using unique or unusual identifiers. If you’re named something like Arthur Dent it is going to be considerably more difficult to find and associate information than if you’re name is Zaphod Beeblebrox. That’s obvious, but it extends to everything else, from usernames to product brand preferences—if you stick to the middle of every given bell curve then your needle will necessarily reside in a much larger haystack. The few things that tend to be unique, at least when correlated with things like timelines or location—things like telephone numbers, email addresses, usernames, account numbers, etc.—can usually be effectively obscured one way or a another. The things that can’t (government ID numbers) then become crucial to keep private. Except, at least one of those creepy services (TLOxp) was built by one of the three main credit rating agencies and so almost definitely has your social security number already, and has been attaching it to all manner of data for several years, all while also selling it off to anyone with a budget (not to mention losing it outright to hackers), so any concerted efforts to conceal oneself seems almost certainly doomed. It’d be an ideal problem for national governments to address using consumer protection laws and privacy regulations if it wasn’t also in our best interests to protect ourselves from said governments.
Sorry for the essay, this line of thought evidently yanked a pretty intertwined thread for me.
The issue is "deleting."
AFAIK, nobody's disagreeing that the internet can forget and deleting is "better" for privacy.
The question is "how much" better.
Here we're talking about the false sense of privacy through erasure when archivers should be assumed to be running everywhere and at all times. The latter weighs in favor of the parent's critique that deleting is not constructive.
I wonder if one could hook up a browser extension to do this
> launder your style through ChatGPT
> I wonder if one could hook up a browser extension to do this
It seems totally feasible. Though I think it would be far more interesting to make a purpose built anti-stylometry tool, that explicitly tries to analyze for and mute the signals stylometry uses.
Edit: what I'm talking about is apparently called "adversarial stylometry":
https://en.wikipedia.org/wiki/Stylometry#Adversarial_stylome...
Having an LLM rewrite a comment would do this entirely, no?
Are you just interested from an academic perspective how one might build something more surgical, that only changes some words in a comment?
> Are you just interested from an academic perspective how one might build something more surgical, that only changes some words in a comment?
Yes and no. ChatGPT seems like a blunt instrument, and given it's not purpose built, it could miss certain characteristics that could enable identification.
Also LLMs kind of have their own style, and adopting that particular style is likely self-defeating to getting a message out (e.g. I would tend to ignore something that sounded like it was written by ChatGPT). Manual correction then be needed, but it would be hard with such a system, because I think that would tend to re-introduce the author's style.
Just mention a "devil strip" in every post and call it a day.
The problem is while the user is moving the comments are not, only deleted
Which will probably damage another user more than hurt reddit
Besides the user might delete things that would be interest read years later
Should be mentioned the rights are retained by the user. Reddit only gets license to reproduce that content and allow others to do the same. Although also being perpetual, irrevocable, it's similar to ownership cannot say they're the same thing.
I can totally respect someone trimming all their online footprint to avoid that.
If you want to retain your online anonymity, you have to be thoughtful about what you share online.
There's another kind of privacy where your cousin sees your reddit user id and looks up your comment history and finds out you are [_____insert secret here___].
Deletion of your history is a protection against the second kind.
Anyway, that in and of itself doesn't bother me - The parent was trying to present a "holier than thou" attitude towards Reddit. I merely pointed out that HN is not all that great when it comes to that.
With the amount of time musk and trump have had in the spotlight and the awful shit they've objectively actually done, it should make people question your integrity if you are writing positively about them. Like it or not, downvotes are an expression of disapproval.
If you can't find a single positive impact of trump's (or any politician) policies or a single positive thing musk has done, consider that you maybe be in an echo chamber yourself, or you're just deluding yourself into thinking you have some kind of moral high-ground.
You're practicing whataboutism here.
>If you can't find a single positive impact of trump's (or any politician) policies or a single positive thing musk has done
A broken clock is right twice a day. So let's let broken clocks rule and profit as much as they want regardless of the consequences, I guess? That's what you're advocating for. trump and musk have very dubious ideologies, they are both awful businessmen that treat their employees like shit. They've proven this over and over. And yes, there is moral high ground and these two are not in the same category morally as many other politicians and business people. Your whataboutism doesn't make them seem any better than they actually are to anyone but yourself.
Like, yeah dude. You think me being pissed that Obama didn't close Guantanamo is a sign that I'm going to be more sympathetic about Trump's policies? Come on now.
But sure, he did nice things for the most wealthy and practically nobody else but himself. There, I said he did a good thing. lol
There are other reasons, unless you construe "trust" very broadly. Services that make it unreasonably difficult to cancel your account: you just cancel their credit card (and of course stop using the service).
You can also force an annual renewal, to prevent them from automatically renewing you.
And lastly, you can set a dollar limit on it, to avoid mistakes and "automatic" increases.
IANAL, but I have always heard that when you do this you have not broken the legal contract obligating your payment. In practice, especially for modestly priced services, the strategy will usually work. But in theory they could come after you legally for the money if you do this. It might be a real concern for very expensive services.
I would like to have this confirmed by a lawyer, though.
You couple the card cancellation with a message to them demanding they cancel your account. Just imagine a credit card collection company agreeing to come after you, when you made a good faith attempt to close the account.
Given the practices detailed here, I could very easily imagine it. https://news.ycombinator.com/item?id=37490241
> Broadly speaking, merchants only resort to force posts when they are faced with the potential for serious loss as a result of fraud. For instance, if you rent a car and don't return it, having a limit on a card or closing the card does not absolve you of the responsibility to return or pay for the car, and the merchant can force post the charge.
[1] https://support.privacy.com/hc/en-us/articles/360012288214-F...
They send you an email saying, "please update your payment information." Because this happens every day. Hey, sometimes the restaurant tells you your credit card was declined, when it's perfectly good.
That email is followed by another, saying your account is suspended. At that point, they might give you an option to cancel, OR they might forward you to the same impenetrable UI that led you to do this in the first place.
In any case, you'll most likely be cancelled with no further repercussions. Yes, bad things could happen, but they don't. YMMV.
> Spelling/grammar/phrasing > If there are words you often misspell, people can Google it to find other sources where you make the same error (if it's uncommon enough) and potentially identify your other accounts. Use spell checking and maybe Grammarly or similar to minimize this risk, but I tend not to worry about this too much.
It's not just about misspellings, it's that we all basically leave fingerprints in the way we write.
Show HN: Using stylometry to find HN users with alternate accounts
https://news.ycombinator.com/item?id=33755016 (676 points by costco 9 months ago | 519 comments)
Or better yet, replace social media with LLM’s, instead of reading individual posts you discuss topics with a sort of artificial gestalt average user. Maybe let people “join” a gestalt by tagging their discussions.
Then we can let the gestalts argue amongst themselves!
The one bit of leaked identity that really bugs me is my phone number. So many services require a phone number for text notifications and 2-factor auth and there's not good way (that I know of) to generate a random phone number that still works.
If the former, then you're the first one I've come across who's able to do so. Facebook/Google/Twitter/Microsoft etc. all block VOIP numbers. The providers you use probably aren't hit with enough malicious activity for them to care about it.
This bothered me as well, so I bought a completely unrelated domain to create a new trust ring. I'm sure you could link that domain back to me if you are buying information from a data aggregator, but at least that way I have the satisfaction of knowing people had to pay for the privilege ;)
> The one bit of leaked identity that really bugs me is my phone number. So many services require a phone number for text notifications and 2-factor auth and there's not good way (that I know of) to generate a random phone number that still works.
Ugh, yes. I had an old phone number that I moved to Twilio & set up SMS forwarding that used to work, but everyone seems to use phone verification APIs to block VOIP numbers.
Microsoft recently extorted my cell number out of me so I could keep using my paid for minecraft account.
My password manager offers to generate a password for me; I wish it would offer to generate those other fields as well.
Turns out you can fuzz your address too when validating a credit card. Autofill should handle that.
My experience is that only your ZIP code is used, not your street address or city.
Echoing: never actually answer security questions. Always treat them as additional (super annoying) passwords.
I've bypassed my own bank's security questions by telling them "the answer to 'my favorite ___' is a bunch of gibberish letters and numbers."
This seems a bit extreme to me.
(Did you know when you use PayPal, sites can see your email, name and address?)
Of course, for digital purchases, your point is completely valid.
Security rests more on pausing/resuming cards, locking them to vendors, or setting price limits.
It does annoy me that paypay doesn't let me enter custom email addresses to give the merchant. I've had to change my paypal email address several times now due to stores selling it to spammers.
Not using the same accounts between services, and distorting real details like city.
Seems to work pretty well. I'm pretty invisible based on my own research.
Can anyone break this down? If a person were concerned enough to follow all of the steps listed in the article to stay anonymous, why not also use a VPN or Tor as an additional layer that can thwart many types of tracking and provide additional risk mitigation?
The point is to not be found. People showing up at any address that isn't your actual home address aligns with that goal. Registering it in the same ZIP code is self-doxxing though.
It's an innocuous form of synthetic identity fraud. If you really want to be anonymous, do pre-applications for credit cards and utilities in your name at other people's addresses then abandon them. One case I worked had a guy doing this using AirBNB hosts' addresses. His profile had him supposedly living everywhere all at once. This had the benefit of mapping to actual homes instead of The UPS Store when Googled.
So that if someone tries to search about you, they are buried in all the noise and data of the other person.
https://www.reddit.com/r/nealstephenson/comments/czw5og/fall...
Personally I mostly don't bother and will use a throwaway if I really feel compelled to post some comment I wouldn't want to be linked to me. (I know even that isn't foolproof but the threat model is mostly not wanting a statement attributed to me professionally--not hiding a crime.)
I believe I saw an experiment of somebody doing this for HN content with a pretty high accuracy? Project that idea into the future.
Is your phone trackable with something like Pegasus? Although, an average Steve does not have to worry about that.
Even the Tor Browser doesn't fully mask your OS (javascript functions still return the real thing), making anything but Windows (what the majority uses) impossible to use for any real privacy if you're trying to blend in.