Live data from Hacker News

Be anonymous

kg.dev

51–60 of 260 posts

Re: Be anonymous

#51

The article touches on a good point: one mistake and you're out. It doesn't even have to be your mistake - you didn't choose to put your SSN out there after all, yet here we are. This gave me a radical company idea, on the other end of the spectrum: spam as a service. Something that'll take your name, email, and other things and put it all over the internet in questionable and plausibly denial ways. That way, even wh…

Name it something catchy…like equiphax

"equip hax"

Re: Be anonymous

#52
post #38

As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…

> keyboard frequency on anonymized accounts can be de-anonymized

Whonix uses Kloak to mitigate this [1], but unfortunately it isn't available in Qubes-Whonix.

> Mixers and tumblers will eventually leak

Don't use mixers and tumblers, use Monero and/or Monero atomic swaps.

But, you are right that it is futile to maintain defense against a determined 3 letter agency.

[1]: https://www.whonix.org/wiki/Keystroke_Deanonymization#Kloak

Re: Be anonymous

#53
post #45
post #44

Earlier quoted context omitted.

I believe Brave browser has fallen out of favor but I'm not an expert on why

Interesting. Please let me know if you have a better alternative. Ideally I'd like to just run chromium but then I have to build it myself or use some build by some untrusted person so I've decided I'll trust Brave for now...

Aside from Tor Browser, Firefox with arkenfox/user.js is ideal for privacy [1].

Chromium-based browsers like Brave are ideal for security [2].

An ideal solution for privacy and security would be running Firefox+user.js in Qubes OS [3], or for even more anonymity, Tor Browser in Qubes-Whonix [4]. However, even this isn't bulletproof, and a 3 letter agency can still determine who you are with techniques like keystroke deanonymization [5] or other techniques [6] like traffic analysis. Tor is also not reliable for anonymity because the project is kind of a shitshow [7], so there's really nothing you can do to truly hide.

[1]: https://github.com/arkenfox/user.js

[2]: https://madaidans-insecurities.github.io/firefox-chromium.ht...

[3]: https://www.qubes-os.org/

[4]: https://www.whonix.org/wiki/Qubes

[5]: https://www.whonix.org/wiki/Keystroke_Deanonymization

[6]: https://www.whonix.org/wiki/Warning

[7]: https://www.hackerfactor.com/blog/index.php?/archives/906-To...

Re: Be anonymous

#54
Notably missing aspect is precise time of events.

Personas like someone who posts content during 08:34:40 - 09:23:23 except 08:43:30-08:55:23, never seems to be active during 22:00 - 06:00, can be narrowed down to something like a person commuting via bus route A from stop B to C changing to a train route from C to D through passageway E in the station.

From there you can look for a man looking down at a phone, or couple information with other factors, or throw in a bait like a giant stinking dead fish or a rare and loud car in front of him and watch for responses he'd make. IMSI catchers and Bluetooth scanners can be useful as well if your adversaries are resourceful. Time and location of transmissions and time of receptions can be correlated, in theory.

This type of attacks can't be mitigated on fast-paced social media at all; both posts and requests has to be queued and obfuscated for time.

Re: Be anonymous

#55
post #31

The article touches on a good point: one mistake and you're out. It doesn't even have to be your mistake - you didn't choose to put your SSN out there after all, yet here we are. This gave me a radical company idea, on the other end of the spectrum: spam as a service. Something that'll take your name, email, and other things and put it all over the internet in questionable and plausibly denial ways. That way, even wh…

Kidding aside, this is exactly how it will go down. Politician in a scrape of financial corruption or etc.? Deepfake s*x video or other viral blatant misinformation & obfuscation; what's the risk? Upside, no one knows what to believe. Exactly what various "countries" are doing. It will be extreme; to the point where, don't believe half of what you actually see.

It should be noted that this is a pretty bad end state. Reporting is already an extremely weak force for preventing corruption on the part of the powerful. Journalists entering a state of total uselessness is only going to make the problem bigger.

In a realm of total bullshit the winners are the one who are best at lying. "I don't know what to believe and everyone involved is probably corrupt" is usually just an excuse to disengage and follow base instincts.

Re: Be anonymous

#56
post #54

Notably missing aspect is precise time of events. Personas like someone who posts content during 08:34:40 - 09:23:23 except 08:43:30-08:55:23, never seems to be active during 22:00 - 06:00, can be narrowed down to something like a person commuting via bus route A from stop B to C changing to a train route from C to D through passageway E in the station. From there you can look for a man looking down at a phone, or co…

That's a bultin feature of messaging systems like I2P-bote (running on I2P darknet). It's been a while since experimenting with Bitmessage but I think they queue/batch messages as well. But for forum like software that's definitely true, can't easily have variable delayed posting.

Another aspect that's important and often ignored, is writing style anonymization. You practically want an offline tool, that removes idiosyncrasies from the text you write and makes it sound as bland as possible.

edit:

A related story. Around 2010-2012 I was working for a company, and I was part of a somewhat managerial group. At one point we decided to pull in direct employee feedback in an anonymous free-text form. Due to their writing style being reflective on the way they spoke, it was possible to point exactly who wrote what message. Of course, few exceptions existed, I didn't personally know all the employees in the company.

Re: Be anonymous

#57
post #9

Privacy is on a spectrum, but is also compounded by time and once the cats out the bag it can be impossible to turn back. In the example given of Alex Cazes he could change the from email but the damage was already done - there's no way to recall the emails already sent that led a trail back to him.

The article states that anonymity is on a spectrum. Privacy is a different issue. You can lead an entirely private but non-anonymous life.

Re: Be anonymous

#58
post #38

As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…

You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him.

https://theprivacyblog.com/blog/anonymity/why-tor-failed-to-...

Re: Be anonymous

#59
It's good advice. The problem with anonymity in an environment of ubiquitous surveillance is that it's paradoxical. The point of anonymity is achieving freedom, but staying anonymous expends energy and makes you a target, so you can't actually do any things that anonymity was supposed to get you.

If what you really want is sovereignty, which is what most people confuse anonymity with, the goal is to be like what Ernst Jünger called the anarch (in contrast to the anarchist), which is someone who complies and renders herself indifferent to authority, rather than standing out and drawing attention.

A much better practice is to be as open as possible about the boring stuff, so you're not constrained and can do what everyone else does. Trying to be absolutist about anonymity is automatically like wearing a straitjacket.

Re: Be anonymous

#60
I have been afraid of sharing my ideas, post history, etc. in a way that could be easily traced back to my identity for years. I made sure my accounts and usernames bore no personally identifiable tid-bits. I use a VPN religiously (that won't change).

I've since decided that I am done with all that.

I was afraid my employer might question my Reddit posting history (they wouldn't.) I was worried someone who Googled me would think my past self was dumb (who cares).

Now my ideas are almost all public and growing more so by the day. I am working up the energy to start a personal blog, if anything just to document my ideas over time. I am adding my real name and email to my Github, HN, (not Reddit, yet, though it would not be hard to connect), IH, etc.

I want someone to be able to Google me and find my best work.

On the other hand, there are clearly cases and types of info/accounts that should remain private. I self-host as much as possible. I encrypt personal files before uploading. I have multiple Protonmail accounts. I use custom DNS, etc.

Ideas should be public. Information is a case by case basis, but I generally care a lot less than I used to.

Post reply on HN