27 karma · joined May 19, 2022
pub rsa4096/0xA6D8C811594901DD 2024-04-11 [SC] [expires: 2025-04-11]
A85566159EA0890DC4A34074A6D8C811594901DD
uid Ron Marken <RonaldMarken@protonmail.com>
sub rsa4096/0x0DD06D9873F3FA98 2024-04-11 [E] [expires: 2025-04-11][1]: https://proprivacy.com/vpn/guides/openvpn-scramble-xor-obfus...
[1]: https://gizmodo.com/report-facebook-helped-the-fbi-exploit-v...
If anyone has any contact with the NYTimes ops' team perhaps this issue could be raised with them.
There are allegations that Satoshi may have accidentally slipped up and leaked IP address that was not a Tor exit-node or other anonymous-proxy.
Could either be Satoshi fucking up and not using Tor all the time (has happened to other 'anonymous' entities) or perhaps they needed a clearnet connection for some reason and managed to use another internet connection not attached to any identifiers that would lead back to them despite that.
With pseudonymous usage of public services information minimisation to maintain operational-security against private user-data being disclosed by external hackers or rogue insiders is a mantra that needs to be followed religiously.
(If you are more concerned about traffic correlation perhaps be more careful where you are entering the Tor network)
Unfortunate that talk is not publicly available.
It will be interesting to see what third-party researchers discover about these new protections. Might remember something about Apple rewriting format parsers for iMessage in memory-safe language with sandboxing as Blastdoor and it was discovered there was still plenty of attack-surface in the unprotected parsers.
One omen of advice is that if you are not taking measures preemptively to actively remain anonymous that itself could be a means of exposure and makes this entire exercise futile. For longer-term anonymous identities merely picking a pseudonym and casually using it makes it easy to slip-up and potentially lead to correlation. Slightly dated now but suggest you read-up on 'OPSEC for hackers' and other publications by The Grugq as a starting point.
It would not be surprising if some bored prosecutor with a grudge attempts to throw this out the window. In addition litigation by private-companies using the same laws could attempt to win by the virtue of having better funding and/or lawyers than the defendant.
Too cynical? Maybe.
Yawn. All I have seen is some angry techbro who can dish out an hour of time for an attorney to write angry letter when he does not have things his way. That is not to say this is a criticism of victims but rather a damn shame more people do not stand up to this nonsense.
Incidentally this 'notoriously litigious' individual is also being sued over alleged sexual-harassment committed by him at his previous company London Trust Media[1]. However not sure of the latest status given the sale(s) of certain companies.
[1]: http://web.archive.org/web/corrupt.tech/1708590130-ocr-compr...
In a technical sense one skill that can help realise these 'big daunting ideas' is to break the goals of a project into many 'micro-projects' that may seem more attainable in the short-term (ie. "I want to write some client/server application to do $X". Start by sketching out what APIs need to coexist in both sides, mock-up the business logic on paper, etcetera).