Sherlock: Hunt down social media accounts by username across 400 social networks
sherlockproject.xyz
sherlockproject.xyz
It makes pervasive tracking a lot harder.
Also when you do any research on health related topics, be extra privacy conscious.
so don't re-use email accounts across sites. SecOps matter
let's face it, we're not talking about Joey Beercan doing this. Anyone even tossing around the term SecOps is already moved out of mass populace and into the somewhat informed. Someone practicing SecOps would definitely be the type to use some sort of credentials management. So I don't think unique totally unrelated emails is too much of a burden. Using different free email providers is even better.
Microsoft is worse: they'll let you create an account, then lock it the next day, after you've already used it for something, if you don't link your phone number.
Phone number is used because it costs money to get, is hard to get in bulk, and in many countries is always tied to your identity.
I wonder what the market for throwaway phone number verification is worth.
If you're adding your phone number to a throw away account you use on Target or Walmart, it's likely okay.
The IP comment was likely because if someone can get your phone number from the Walmart service (via subpoena), to track you down, they can also get your IP address too.
I pondered this recently, and it seems to top out at a couple bucks per shot.
The problem is that the phone number tends to need to be persistent for the sake of security. You can't typically sign up for something that requires a phone number and then expect to be able to keep the account safe without maintaining exclusive access to that number.
I'm sure if it were cost effective, one of the password managers would have some kind of SMS integration, like Apple's hide my email, but for phone numbers.
In the past you could use BlueStacks android emulator to register Gmail accounts without sms verification even with VPN IPs. This year I've created a few Gmails without sms verification, once on desktop chrome (with Firefox they would've required sms) and a couple of times using the Gmail app on an Android phone.
Not in OAuth/OIDC compliant identity providers. As one example, I frequently use + email addresses for testing on auth0-secured apps, where I use the + text to tag a role or some other user attribute that identifies what makes the test account special. eg stult+admin-staging@example.com or stult+user-declined-gdpr-prod@example.com. Each plus variant resolves to its own separate account with its own password (which I do in fact manage via a credential manager), without requiring me to set up multiple full email addresses to simulate multiple users with verified email addresses.
It just so happens that email servers tend to recognize the usage of "+" as a "tag" and route incoming mail using the tag to the root email that precedes the plus and tag.
But, as the sender, you cannot assume that this is always the behavior. You must assume that those are two different emails.
Any comercial sites - dating, gambling etc. end with verification attempts
Self-censor you mean?
I personally like that information anonymous account `William Shakespeare` posted around 1585–1613.
Doing the multiple account thing isn’t as easy as it sounds though. Some sites like Reddit make switching between accounts incredibly easy while others aren’t so much. Plus laziness kicks in and soon enough your Brand Name Account gets tainted and you have to consider taking it out back to the dumpster.
Such is life I guess.
And it's as easy to dox yourself by responding with the wrong account, as I have seen multiple times on Reddit.
I do this at work too.. where I have to have different user profiles to emulate working as an admin, staff, client, sub-client. Blue seems adminny :)
There was a "show hn" many months ago that did stylometry on HN commenters to show which accounts were most stylistically similar; I ran a throwaway account of mine through it, and it showed my account in the top 3 - which was impressive.
Having multiple accounts won't save you when your own word choice, grammar and style can uniquely identify you to anyone sufficiently motivated to link your disparate identities at any point in the future. The author even said their tool was rather basic; IIRC the basis was all pairs similarity on n-grams
I can't get the site to load
Actually I was disappointed by the post, I was hoping it will be able to find the same person regardless of the username through analyzing the writing style, what they are talking about, the timezone etc.
The username doesn't prove anything, anybody can take any username anywhere. If someone targets you, they can take usernames on platforms you haven't claimed your username yet and pretend being you and damage your reputation.
Whatvabout the platformsthat I don't know of? Or that don't exist yet?
Even major corporations don't bother with all TLDs.
It's far more plausible to not seek to have the same identity behind the same handle.
And I’m saying you should reserve your main handle - you can still have a unique one that you actually use.
>Sherlock: Hunt down social media accounts by username
I don't know why you would have been hoping for this. The title isn't exactly ambiguous.
They are just gonna make fake accounts that look like yours and shitpost ahead anyways.
Social media has multiple problems, including authenticity, transparency, validity and verifiability. All of which don't exist and make it the optimum propaganda machine (referring to the criteria that Chomsky described) because it can be corrupted through multiple attack vectors.
If we want to survive this hellhole of misinformation, the mentioned criteria has to be implemented for the "next big platform" so that censorship and other legislative processes can be encountered with increased transparency and openness.
On a network/society scale it can't be driven by financial incentives to prevent corruption, ergo it must be financed by taxes. Preferably on an EU or UN legislative level to prevent political corruption of single state actors.
How do you even determine anymore if something is really written by someone?
Websites are already for a huge part written by bots/LLMs and we all know to take them with a huge grain of salt.
How long until we consider users posts aren't to be trusted anymore either?
It already started (impersonating usernames) for sure.
So what is this even tracking?
Heck, at this point it's nearly a guarantee we already have bots trained on outputs of other bots.
I wonder what the implication of all this is going to be.
When maintaining an official online public presence, or if you are privacy minded you likely want to "plant the flag" to stop others from impersonating you.
Tools like these insult the users' intelligence and generate needless drama[1] the only data needed are the urls from https://github.com/sherlock-project/sherlock/blob/master/she...
[1] https://www.reddit.com/r/github/comments/1at9br4/i_am_new_to...
Staying anonymous is very difficult
Fun post applying it to HN, not sure if the site is still live: https://news.ycombinator.com/item?id=33755016
For example, on YouTube I use twitch slang, and on Reddit I use TikTok slang, and on TikTok I use reddit slang. On hackernews a use a slightly whimsical pedantically-infused undergrad tone.
It makes people realize that actual anonymity online is a smokescreen.
so what are you lesser relevant people worried about exactly?
Unenforceable rules are never followed.
EDIT: Looks like there is an English translation. See section 4 of: https://finlex.fi/en/laki/kaannokset/2004/en20040759_2019034...
If you're trying to figure out anything about me from social media or other such random web pages, I don't care to have anything to do with you, and I don't care what you're led to believe about me. I suppose this is born of privilege, but the only contacts I care to make are directly via people I already have a relationship with.
Edit: the site I found was "zoominfo".
There are several things that are a security issue or simply a privacy issue. These include:
- Your username (as I assume this tool is demonstrating)
- Your email address. While this is treated as your "public identity" to some extent, I think we're rapidly approaching a point where we need to not do this;
- Your phone number; and
- Your profile pic. I would advise to never use the same pic across accounts and certainly don't use services like gravatar (if that's still a thing).
Email is particularly problematic because you can end up on spam lists if a site is compromised and you can't really identify where it comes from.
What I think we need is a more integrated solution for logging in and creating throwaway addresses (eg like SimpleLogin) so it's basically seamless. Gmail seems well-positioned to do this. I honestly don't know why Google hasn't done this.
Interestingly, Facebook Groups seem to handle this kind of anonymity reasonable well. Each group your in is a separate profile. You can't find out what other groups someone is in from either their personal identity or any group's identity. Weirdly, your FB profile is associated with any pages or profiles you comment on.
It should be clear to these companies by now that people want to silo their public identities (aka pseudonomity).
No, I don’t, and I’m well-aware of EUI-64.
IPv6 uses 128-bit addressing because some on the design committee or making comments on the drafts thought that 64 bits might not be enough.
Privacy addresses are random and periodically rotated.
The IPv6 equivalent of a port is a port.
'Have you read Gaboriau's works?' I asked. 'Does Lecoq come up to your idea of a detective?'
Sherlock Holmes sniffed sardonically. Lecoq was a miserable bungler,' he said, in an angry voice; 'he had only one thing to recommend him, and that was his energy. That book made me positively ill. The question was how to identify an unknown prisoner. I could have done it in twenty-four hours. Lecoq took six months or so. It might be made a text-book for detectives to teach them what to avoid.'
The UI presents a text field which is for entering search terms.
You click it and expect to type - but NO! - SURPRISE!!! it's actually a button!!
And now the page changes, pops up an actual text field, somewhere else and new, and you abruptly are forced to set aside your thoughts about search to process the page layout a second time and go and click again to type in a term.
Why on God's clean Earth would anyone ever do this?
Things like advice in an alcohol recovery forum would be prime evidence for a liability suit.
There are also groups that vacuum the internet for offensive posts, and use them to try to get people fired for things they said 10 years ago.
At this point, I assume all internet activity can and will be de-anonymized, and restrict my speech accordingly. I'm sure there are some meaningful precautions and nuances, but it is too much to keep up with.
I’m kind of glad that the value of blackmail futures has plummeted to zero
I always thought millenials would be the culprit because millennials have so much online, but nope, it was just old fashioned baby boomers that have spearheaded it and double down on their indiscretions to be the role models for the country’s top offices
"no sir."
"for god's sake Baldrick, you're running for parliament. I'll put fraud and sexual deviancy."
(Ironically, Dems eat their own for that stuff, so maybe "politically motivated" doesn't quite capture it... compare e.g. Al Franken and Katie Hill vs Roy Moore or Matt Gaetz)
Pretty sure it's pretty close to true at this point that he actually could get away with literal cold-blooded murder in public at this point and his cult would fold themselves in half backwards tryin' to justify it somehow. [0]
[0]: https://www.snopes.com/fact-check/donald-trump-fifth-avenue-...
https://www.pewresearch.org/2024/03/21/views-of-the-u-s-role...
I’ve been told “I’m making someone uncomfortable” and I said “they’re making me uncomfortable”, and follow that up with “why are you privileging their discomfort over mine” and when they or the mob say something gendered or sexist as the explanation, then I get to cancel all of them or get a nice fat paycheck
No, its not.
The preferred image may be more combative, aggressive, and anti-social than in the recent past, but as always adherence to it is more important than actual authenticity.
> I’m kind of glad that the value of blackmail futures has plummeted to zero
It hasn’t, though the value function for current negative information is different, so things that were once valuable for blackmail or otherwise harmful to public image are less so (and things that were not are moreso.)
> I always thought millenials would be the culprit because millennials have so much online, but nope, it was just old fashioned baby boomers that have spearheaded that double down on their indiscretions and are the role models for the country’s top offices
The only boomer I can think of that you might be talking about denies them constantly (even if there is past documentation of his acknowledging them in a general sense) and is supported by favor-currying media magnates who either actively promote propaganda favoring his messaging on that or, at a minimum, actively spike critical coverage.
And even within his movement and with the support of his cult of personality and the same favorable media, others in his orbit have often been less successful in having their indiscretions given a pass (see, e.g., Matt Gaetz’s nomination for Attorney-General of the United States.)
Yeah, if you can fake that, you've got it made.
I don't think this is an automatic negative as you are implying. There's definitely lots of qualifiers involved though. There would have to be significant evidence to show that the sentiment expressed is still no longer held which could be more than problematic to prove. If it was someone up for supreme court justice that posted pics showing how much they liked beer and their antics as a party person could be shown as lack of maturity by comparing that they no longer drink now. Someone posting racist comments would be much harder as you don't really know if they've changed their view or just learned not to post publicly their views.
Edit: automatic negative should really read automatic disqualifier
Don't post something harmless today that will be deemed a "dog whistle" in 2035 so that you don't have to prove a negative?
I don't mean to be critical here, it's a genuine ask.
And to add to the above, my post is the kind of post that would be gone. If I was taking a similar stance.
Age of post should just not be an automatic "but it was 10 years ago" get out of jail free card. If there's compelling evidence it was just a stupid thing someone did as a teen, then we can have that conversation. If it is a post from someone in some position of leadership that is 10 years old but was made in their 40s is not the same "I was an immature teen" situation.
This card will be played over and over again by politicians, influencers, prosecutors, police, etc, until the smartphone-from-birth generation reaches office. At that point, it'll be so easy to dig up dirt on anyone, people will just stop caring (as they should anyway).
We're just in a weird transition period right now.
https://www.bookbrowse.com/expressions/detail/index.cfm/expr...
One of the parents saw the post, and raised a stink.
Now that I'm retired, it doesn't really matter that much, but I do my best to behave well (this joint is pretty much the only place I post much). In the past, I was not so circumspect. In fact, I was a troll.
I remember once, signing up for Disqus, and they came back, and said something to the effect of "We found all these posts from around the Internet. Would you like to claim any as yours?"
Included, were some of the worst troll posts I'd made, many years ago, under the [obviously mistaken] assumption that they were anonymous.
I nuked the signup, and went and had a lie-down.
Since then, I have never bothered to try being anonymous. I probably could, if I wanted to, but I'd rather just stay public, and not say stuff that I'd regret.
I assume the implication here is that the thing they said 10 years ago was less inappropriate back then. So how do you predict sensitivity changes 10 years in the future to limit your speech today? Even if you delete posts after, say 1 year, archives exist. Shouldn’t you just not say anything if you’re afraid of this? Maybe discussion of self-censorship like this will be taboo in 10 years and the ship has already sailed.
My thought was more about time and distance. Something can be unpopular or even wrong when it's first said too. People are dynamic and change over time. The mechanism of change is living their lives.
Taboos can change as well, so there is a motivation to steer clear of controversial topics in recorded media. You can use discretion to judge risk. It's unlikely that someone's going to fire you for discussing ice cream in 10 years.
There is no way to know what people are going to get offended about in the future, but the clear trend is people getting offended about more and more things over time, rather than fewer and fewer things.
https://github.com/sherlock-project/sherlock/blob/master/she...
I'd argue instead why is this not a GUI? Making it a CLI makes it less user-friendly.
Edit: added “to prevent”
No pkg package.