Live data from Hacker News

I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

bloomberg.com

81–90 of 97 posts

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#81
post #80

Earlier quoted context omitted.

I wonder how well uMatrix stacks against Firefox's reader mode? You can prepend `about:reader?url=` to most URLs and they'll load fine, fast, and have very clean UI elements. It's a lot less of a hassle than using uMatrix.

reader mode loads everything. umatrix prevents loading of a lot of stuff. I have configured umatrix to only load first-party content (I can always add 3rd party content back in using the menu and save it). Also, umatrix can be used first, then you can use reader mode. Weirdly I notice reader sometimes bypasses some umatrix protections.

If reader mode loads everything, does it also execute all of the javascript? That's ultimately what I want to avoid; I want effectively a static page with zero javascript.

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#82
post #35

Earlier quoted context omitted.

Not at all. Only from the beginning of a particular persona. Mirimir is about eight years old.[0] But I had numerous personas before Mirimir. Some you could maybe track back to, if you worked at it, and knew where to look. But some are just too old, and unconnected. I was lots sloppier, when I started going dark, in the late 90s. I even talked about it in meatspace. But gradually, I compartmentalized more and more. A…

How can you keep these various personas unconnected from each other and your 'meatspace' online identity (for family, banking etc I presume, where you simply can't avoid it) with the emergence of browser and device fingerprinting? Also do you always go online through each persona from behind a different VPN IP address so they can't be correlated (except by your VPN provider of course)?

For Mirimir and other ~low anonymity personas, I just use a different VM and nested VPN chain for each persona.[0] If keeping them unlinked is not critical, I use the same host machine, and don't obfuscate writing style.

And because I use nested VPN chains, no individual VPN provider can correlate stuff from different personas. It's the same distribution of trust thing that Tor does. Albeit far weaker, because I'm only using several VPNs, and not thousands of Tor relays. But still, it'd take some effort to obtain logs from enough VPN providers.

If I care more about keeping personas unlinked, I make sure to use different VM OS, given the risk of WebGL fingerprinting. Because using the same virtual graphics driver and physical GPU gives the same fingerprint.

If I care even more, I use Whonix via nested VPN chains. With a different Whonix instance for each persona, or group of somewhat linked personas.

If I care lots more, I do all of that, using a different host machine, on a different LAN, with different nested VPN chains.

0) https://www.ivpn.net/privacy-guides/advanced-privacy-and-ano...

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#83
post #58
post #35

Earlier quoted context omitted.

Not at all. Only from the beginning of a particular persona. Mirimir is about eight years old.[0] But I had numerous personas before Mirimir. Some you could maybe track back to, if you worked at it, and knew where to look. But some are just too old, and unconnected. I was lots sloppier, when I started going dark, in the late 90s. I even talked about it in meatspace. But gradually, I compartmentalized more and more. A…

But do you also segregate the devices and networks you connect to for this identity, or can a sufficiently advanced adversary connect the dots where you link up with the rest of the internet?

No. They all go through the same ISP. And through the same initial VPN, because simultaneously using multiple VPNs would be unusual. But after that, I branch out to multiple VPN chains, and multiple Whonix instances.

Like this: https://www.ivpn.net/blog/wp-content/img/Chains.png

VPN4 is OpenVPN via Tor.

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#84
post #47
post #35

Earlier quoted context omitted.

Not at all. Only from the beginning of a particular persona. Mirimir is about eight years old.[0] But I had numerous personas before Mirimir. Some you could maybe track back to, if you worked at it, and knew where to look. But some are just too old, and unconnected. I was lots sloppier, when I started going dark, in the late 90s. I even talked about it in meatspace. But gradually, I compartmentalized more and more. A…

Well, I actually can see where you're going with this, since my HN account is completely disconnected from almost anything else I do online, or even offline. Apart from the privacy benefits, however, I feel that it is a net negative, because it prevents me from sharing here a lot of interesting stuff that happens in FOSS projects I am a part of, or at work.

Yes, that is an issue. Each persona can share just a limited slice. But you could have multiple HN accounts, I think. Or at least, I see lots of throwaway usage. However, perhaps having multiple stable accounts violates the terms of use.

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#85
post #67
post #47

Earlier quoted context omitted.

Well, I actually can see where you're going with this, since my HN account is completely disconnected from almost anything else I do online, or even offline. Apart from the privacy benefits, however, I feel that it is a net negative, because it prevents me from sharing here a lot of interesting stuff that happens in FOSS projects I am a part of, or at work.

This is why granular voluntary information disclosure will be super important in the future. A good social network should allow you to post under a different identity, while still tying-in some attributes of your other identity to the new one. For instance you could easily share your real life experience under another name, while still proving you have between 1000 and 1500 karma on another account. This fixes the pr…

That is an interesting idea. If the karma proof were reliably blinded, anyway.

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#86
post #33

Earlier quoted context omitted.

Well, TFA is loaded with "gadgets" that I've never heard of. It could just as easily pointed to VirtualBox and Whonix. Or even running VPNs in host and VM to give a simple VPN chain. The AirVPN and IVPN clients for Windows are pretty much leak free. And dead simple. Buy account, download client, install, and run. And for Whonix, it's just download and install VirtualBox. And then download Whonix, import into VirtualB…

Well I've never heard of Whonix, AirVPN or IVPN, so I guess that invalidates those too?

It's not so much that I haven't heard of them. It's more that none of them seem very effective or reliable.

And if you really haven't heard of Whonix, I find it hard to believe that you've looked seriously into privacy protection. But maybe I'm just biased.

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#87
post #33

Earlier quoted context omitted.

Well, TFA is loaded with "gadgets" that I've never heard of. It could just as easily pointed to VirtualBox and Whonix. Or even running VPNs in host and VM to give a simple VPN chain. The AirVPN and IVPN clients for Windows are pretty much leak free. And dead simple. Buy account, download client, install, and run. And for Whonix, it's just download and install VirtualBox. And then download Whonix, import into VirtualB…

This is not realistic. Your conception of an average user is actually a power user. If I tried to imagine my mom doing this (who is highly intelligent but non-technical and not a power user), I would see her getting tripped up on: Whonix / VM: * Figuring out which version of virtual box is appropriate for her setup. The download page is not at all noob-friendly and there is no big "click this button to download for t…

OK, those are all good points. For several years, I've been writing about this stuff. And I have commonly gotten feedback that it's all too complicated. Even from people who clearly want more privacy.

That's what's so good about Tails. You just boot it, and have a secure Debian system with Tor. But there are some vulnerabilities. Especially because the Tor daemon and userland are not isolated.

It one point, I experimented with packing VirtualBox, a pfSense VPN gateway, and Whonix, in a LiveDVD. It required 8GB RAM, and took minutes to boot. But once it was up, it was quite snappy, because it was all in RAM.

Anyway, it would be cool if someone could pack all of that in an app.

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#88

I found myself wondering, "but why?" more than once reading this. >I realized that Signal is located in Mountain View, Calif. So I downloaded Burner... So, Signal is compromised because it's physically near Google? Okay. >and went to Amazon.com A company you can't shop at without leaving a digital trail? Okay. >seeing the 7-Eleven location listed there along with almost everywhere else I’d been in the last seven year…

Maybe you are taking the article to literally.

I thought it was a great read & enjoyed the writing style. I took it to be very tounge in cheek. It was a good overview of a number of cool products I was unaware of, while also being very funny and entertaining.

Pretty silly ending, he just went back to doing the same old stuff he used to do. Fun read!

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#89
post #88

I found myself wondering, "but why?" more than once reading this. >I realized that Signal is located in Mountain View, Calif. So I downloaded Burner... So, Signal is compromised because it's physically near Google? Okay. >and went to Amazon.com A company you can't shop at without leaving a digital trail? Okay. >seeing the 7-Eleven location listed there along with almost everywhere else I’d been in the last seven year…

Maybe you are taking the article to literally. I thought it was a great read & enjoyed the writing style. I took it to be very tounge in cheek. It was a good overview of a number of cool products I was unaware of, while also being very funny and entertaining. Pretty silly ending, he just went back to doing the same old stuff he used to do. Fun read!

You took it as "tounge in cheek". I took it as a strawman, and very sarcastic and dismissive toward people who protect their privacy.

Re: I Tried Hiding from Big Tech in a Pile of Privacy Gadgets

#90
post #89
post #88

Earlier quoted context omitted.

Maybe you are taking the article to literally. I thought it was a great read & enjoyed the writing style. I took it to be very tounge in cheek. It was a good overview of a number of cool products I was unaware of, while also being very funny and entertaining. Pretty silly ending, he just went back to doing the same old stuff he used to do. Fun read!

You took it as "tounge in cheek". I took it as a strawman, and very sarcastic and dismissive toward people who protect their privacy.

Go easy on him - we'll see who can laugh harder in a few years ;-)
Post reply on HN