It makes pervasive tracking a lot harder.
Also when you do any research on health related topics, be extra privacy conscious.
It makes pervasive tracking a lot harder.
Also when you do any research on health related topics, be extra privacy conscious.
Doing the multiple account thing isn’t as easy as it sounds though. Some sites like Reddit make switching between accounts incredibly easy while others aren’t so much. Plus laziness kicks in and soon enough your Brand Name Account gets tainted and you have to consider taking it out back to the dumpster.
Such is life I guess.
And it's as easy to dox yourself by responding with the wrong account, as I have seen multiple times on Reddit.
I do this at work too.. where I have to have different user profiles to emulate working as an admin, staff, client, sub-client. Blue seems adminny :)
There was a "show hn" many months ago that did stylometry on HN commenters to show which accounts were most stylistically similar; I ran a throwaway account of mine through it, and it showed my account in the top 3 - which was impressive.
Having multiple accounts won't save you when your own word choice, grammar and style can uniquely identify you to anyone sufficiently motivated to link your disparate identities at any point in the future. The author even said their tool was rather basic; IIRC the basis was all pairs similarity on n-grams
I can't get the site to load
Self-censor you mean?
I personally like that information anonymous account `William Shakespeare` posted around 1585–1613.
so don't re-use email accounts across sites. SecOps matter
Any comercial sites - dating, gambling etc. end with verification attempts
let's face it, we're not talking about Joey Beercan doing this. Anyone even tossing around the term SecOps is already moved out of mass populace and into the somewhat informed. Someone practicing SecOps would definitely be the type to use some sort of credentials management. So I don't think unique totally unrelated emails is too much of a burden. Using different free email providers is even better.
It just so happens that email servers tend to recognize the usage of "+" as a "tag" and route incoming mail using the tag to the root email that precedes the plus and tag.
But, as the sender, you cannot assume that this is always the behavior. You must assume that those are two different emails.
Microsoft is worse: they'll let you create an account, then lock it the next day, after you've already used it for something, if you don't link your phone number.
Phone number is used because it costs money to get, is hard to get in bulk, and in many countries is always tied to your identity.
I wonder what the market for throwaway phone number verification is worth.
In the past you could use BlueStacks android emulator to register Gmail accounts without sms verification even with VPN IPs. This year I've created a few Gmails without sms verification, once on desktop chrome (with Firefox they would've required sms) and a couple of times using the Gmail app on an Android phone.
I pondered this recently, and it seems to top out at a couple bucks per shot.
The problem is that the phone number tends to need to be persistent for the sake of security. You can't typically sign up for something that requires a phone number and then expect to be able to keep the account safe without maintaining exclusive access to that number.
I'm sure if it were cost effective, one of the password managers would have some kind of SMS integration, like Apple's hide my email, but for phone numbers.
If you're adding your phone number to a throw away account you use on Target or Walmart, it's likely okay.
The IP comment was likely because if someone can get your phone number from the Walmart service (via subpoena), to track you down, they can also get your IP address too.
Not in OAuth/OIDC compliant identity providers. As one example, I frequently use + email addresses for testing on auth0-secured apps, where I use the + text to tag a role or some other user attribute that identifies what makes the test account special. eg stult+admin-staging@example.com or stult+user-declined-gdpr-prod@example.com. Each plus variant resolves to its own separate account with its own password (which I do in fact manage via a credential manager), without requiring me to set up multiple full email addresses to simulate multiple users with verified email addresses.
When maintaining an official online public presence, or if you are privacy minded you likely want to "plant the flag" to stop others from impersonating you.
How do you even determine anymore if something is really written by someone?
Websites are already for a huge part written by bots/LLMs and we all know to take them with a huge grain of salt.
How long until we consider users posts aren't to be trusted anymore either?
It already started (impersonating usernames) for sure.
So what is this even tracking?
Heck, at this point it's nearly a guarantee we already have bots trained on outputs of other bots.
I wonder what the implication of all this is going to be.
Actually I was disappointed by the post, I was hoping it will be able to find the same person regardless of the username through analyzing the writing style, what they are talking about, the timezone etc.
The username doesn't prove anything, anybody can take any username anywhere. If someone targets you, they can take usernames on platforms you haven't claimed your username yet and pretend being you and damage your reputation.
Whatvabout the platformsthat I don't know of? Or that don't exist yet?
Even major corporations don't bother with all TLDs.
It's far more plausible to not seek to have the same identity behind the same handle.
And I’m saying you should reserve your main handle - you can still have a unique one that you actually use.
>Sherlock: Hunt down social media accounts by username
I don't know why you would have been hoping for this. The title isn't exactly ambiguous.
They are just gonna make fake accounts that look like yours and shitpost ahead anyways.
Social media has multiple problems, including authenticity, transparency, validity and verifiability. All of which don't exist and make it the optimum propaganda machine (referring to the criteria that Chomsky described) because it can be corrupted through multiple attack vectors.
If we want to survive this hellhole of misinformation, the mentioned criteria has to be implemented for the "next big platform" so that censorship and other legislative processes can be encountered with increased transparency and openness.
On a network/society scale it can't be driven by financial incentives to prevent corruption, ergo it must be financed by taxes. Preferably on an EU or UN legislative level to prevent political corruption of single state actors.