Live data from Hacker News

Going dark: online privacy and anonymity for normal people

troyhunt.com

101–110 of 125 posts

Re: Going dark: online privacy and anonymity for normal people

#101

The article recommends going to Fake Name Generator (tm) to get a random online identity. The page is not encrypted and looks very, very fishy. That page recommends going to Social Security Number Registry. Again, an unencrypted totally scammy looking page. If you enter a random name and select a random state, it will 'verify' that your identity has been stolen. Then, if you click on 'Validate', you can enter your SS…

FWIW, there is a "secure" version of the fake name generator, but you have to pay $1.99/year and sign in with Google, which is hilarious.[1] Also, as explained by the creator[2], the SSN registry site is worthless and apparently a joke (although I'm not going to poke around on the site to verify). [1] https://www.fakenamegenerator.com/premium.php [2] http://www.forbes.com/sites/adamtanner/2014/02/03/the-mormon...

That really just makes everything worse, because this site, HN, presents the blog post as if it is a legitimate guide. The Fake Name Generator(tm) page states: "You should click here to find out if your SSN is online." Making no mention that the site is intended to be a joke.

Apparently, HN is a joke.

(Note that the only way to view the Forbes article you linked is through the cached version.)

Re: Going dark: online privacy and anonymity for normal people

#102

The article recommends going to Fake Name Generator (tm) to get a random online identity. The page is not encrypted and looks very, very fishy. That page recommends going to Social Security Number Registry. Again, an unencrypted totally scammy looking page. If you enter a random name and select a random state, it will 'verify' that your identity has been stolen. Then, if you click on 'Validate', you can enter your SS…

FWIW, there is a "secure" version of the fake name generator, but you have to pay $1.99/year and sign in with Google, which is hilarious.[1] Also, as explained by the creator[2], the SSN registry site is worthless and apparently a joke (although I'm not going to poke around on the site to verify). [1] https://www.fakenamegenerator.com/premium.php [2] http://www.forbes.com/sites/adamtanner/2014/02/03/the-mormon...

[deleted]

Re: Going dark: online privacy and anonymity for normal people

#103
It is so difficult to balance productivity/convenience and privacy/security.

Only recently did I stop worrying about privacy/security, and frankly my online experience is much better. I can now participate in any services/apps that catch my eye, I now save CC data at some sites, don't have a VPN/Tor slowing traffic and giving me cloudflare walls/"im not a bot" verification, don't have noscript/ublock/privacy badger breaking most sites, can sync across devices and backup online.

Having both secure & private online behavior is a massive inconvenience. You basically can't participate in the online world as it exists. (There are definitely opportunities to create secure/private versions of existing tools)

Re: Going dark: online privacy and anonymity for normal people

#104

I'm surprised he doesn't mention NoScript, Privacy Badger, etc. "Normal people" should be more concerned about about the highly detailed profiles that companies are building based on browsing habits. "Normal people" read about data breaches and embarrassing leaks that force politicians to resign. "Normal people" know nothing about the behind the scenes tracking that goes on when you google medical symptoms[0] or visi…

I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…

> anonymity is far down on the list

Is that your choice or user demand?

Confidentiality is one of the pillars of security, and beyond a doubt the most common attack on user security is on confidentiaility by commercial and government organizations.

Re: Going dark: online privacy and anonymity for normal people

#105
post #19
post #8

This is just a list of more things for them to clamp down on. I'm thinking about going in the opposite direction, and broadcasting all of my personally identifying information (credit card, SSN, etc). Obviously I would have to set aside a large amount of time to deal with issuing fraud reports, and make sure that I wasn't risking anything that I can't afford to lose--but it does seem simpler in some ways. After all,…

With the phrase "nothing to _hide_" you are starting from a bias: that if you have something that is not public knowledge then it must be wrong or evil and must therefore be hidden.

This is an excellent observation. Perhaps the phrase should be "If you have nothing private you have nothing to fear".

Re: Going dark: online privacy and anonymity for normal people

#106
post #99
post #81

Earlier quoted context omitted.

Please say more about "the potential of real overlay networks".

Well, tunneling your web traffic to some random "VPN" provider and having all traffic flow out in the open to the internet is just defending against your last mile ISP basically. A real encrypted overlay would be a fully connected mesh between all the nodes of the network. Like IPSec was originally meant to work (transport mode, anyone being able to set up a security association to any other IP address with common PK…

Thanks.

> Well, tunneling your web traffic to some random "VPN" provider and having all traffic flow out in the open to the internet is just defending against your last mile ISP basically.

People use VPN services because they can't trust their ISPs. ISPs log traffic, shape traffic, share data with adversaries, etc, etc. People instead choose to trust VPN providers. Typically, there are few ISPs to choose from. But there are numerous VPN services.

> A real encrypted overlay would be a fully connected mesh between all the nodes of the network.

Well, there are https://peervpn.net/ and https://www.onioncat.org/ (which connects through Tor). From years ago, I recall one from some Russian with a friend in Antarctica. But not even the name :(

Re: Going dark: online privacy and anonymity for normal people

#107

Earlier quoted context omitted.

If you primarily use honeywords, then you can filter out anything going to craigds@host.tld as spam. The hard part would be transitioning people you want to communicate with to craigds+{family,friends,correspondence}@host.tld. Optionally, retain craigds@host.tld for personal and professional communication/correspondence, and move everything else to craigds1+{something}@host.tld (or a different host).

I just bought an entire TLD for signups/spam and made it a catchall. One positive is I know when companies are breached often before they announce it as my pagerduty@domain.com told me a little while ago. http://www.theregister.co.uk/2015/07/31/incident_managers_pa...

This is a great idea! What's it like viewing email? Which client do you use? Is it easy to see which email address the email was sent to?

Re: Going dark: online privacy and anonymity for normal people

#108

Earlier quoted context omitted.

I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…

I do similar talks for regular users* and I try to explain how to prioritize risks, and why they might not be focused on what's really important. Purchasing an anti-virus suite and identity theft protection and worrying about online banking are way overrated. Strong consumer protections exist in many developed nations which limit your liability, it is the banks who stand to lose. No doubt it can be a hassle if your c…

I've found the Ghostery extension for Safari to require very little fiddling, breaking almost no sites and blocking ads and third-party trackers.

Re: Going dark: online privacy and anonymity for normal people

#109
post #53

Earlier quoted context omitted.

I do a lecture at local hackerspaces about basic security for the common person and anonymity is far down on the list. Much higher on the list are basic protection from dangers on the internet, like browser based exploits. So Noscript is one major selling point for Firefox due to most browser based exploits using Javascript. Even if you whitelist all the sites you're still more secure with noscript than without simpl…

I wonder if there's any demand for a pre-built whitelist for NoScript that includes stuff like Amazon, Google, Apple, banks, and most other popular sites. The admin would err on the side of allowing scripts to run, while the default-block rule would still block unknown and ad/tracker domains. It would obviously be less secure than an intelligent user making all their own decisions, but it would make the barrier to us…

I'm finding uMatrix is useful, and have deployed it with ongoing support for non-technical users.

It's possible to whitelist (and blacklist) specific targets, including local site, and a set of specified third-party targets.

That said, overall, it's a bit of a complexity bunghole, and may not be for the general public. But then, computers in general aren't, in many ways, either.

Re: Going dark: online privacy and anonymity for normal people

#110
post #44

I appreciate the intention of this article. Written for people only starting to change their surfing habits in light of Snowden. But the example of the tools they should use are not thought out very well. First: Freedome by F-Secure is closed source and there is no OpenVPN alternative. Always choose a VPN that has OpenVPN so that users can configure the connection to their needs. No need for this bloated mess. Second…

> Second: Whilst disposable Google accounts might seem like a good idea, there are any number of ways for Google to cross-correlate

In all fairness, the author does mention multiple times that a fake Google account is not meant to protect you from Google, but from the site you're signing up on.

Post reply on HN