Live data from Hacker News

Be anonymous

kg.dev

81–90 of 260 posts

Re: Be anonymous

#82

Earlier quoted context omitted.

Linux part is perfecly valid IMO, though the rainforest was I think a bit deliberate exaggeration.

Linux is definitely more anonymous than Windows/Mac, but if you seriously want to be anonymous, you should use Qubes with Whonix.

Is there a good virtualbox/vm of these yet?

Re: Be anonymous

#84
post #76

Maybe Eric S. Raymond's advice from 21 years ago is no longer true in today's internet: > Concealing your identity behind a handle is a juvenile and silly behavior characteristic of crackers, warez d00dz, and other lower life forms. Hackers don't do this; they're proud of what they do and want it associated with their real names. So if you have a handle, drop it. In the hacker culture it will only mark you as a loser…

In the late 90s I remember being advised to always use an anonymous handle by my older privacy and security conscious friends. I don't think that Raymond's advice was widely accepted.

Re: Be anonymous

#85
post #19

Earlier quoted context omitted.

> I don't know about you, but I don't want to do all of that. [...] I don't recommend being on either extreme of this spectrum. It's a list of extreme techniques for protecting ones' identity online. Of course, completely sanitizing your online presence is difficult, and probably unnecessary. I thought the two lists were a nice rhetorical framing - present a dilemma (total openness vs. total anonymity) and then wiggl…

> It's a list of extreme techniques for protecting ones' identity online. The items I quoted do nothing to protect ones' identity online. Snark is only effective if relevant.

Of course they do. On top of being OSS and easier to inspect and analyse, Linux is less likely to be a target, there is no online account connected to your system account

Living in the rainforest is an extra step to get outside of spying jurisdictions. As long as something doesn't eat you.

Re: Be anonymous

#86
There’s been a push in recent years to teach the non-tech public that reusing passwords is bad, in part because if there is a leak in one service it’s easy to try the same somewhere else. Easy enough to relate to.

I wish the messaging would include email addresses as well. It’s easy for everyone to use different passwords nowadays with deep integrations everywhere. But generated email addresses still require a lot of extra steps for most users.

To change this has to first become a mainstream concern.

Today there is iCloud email forwarding. But it’s still new and not as convenient to use outside of iOS.

Also I have no idea about the longevity of that service. Wouldn’t trust it as recovery mail for important accounts

Re: Be anonymous

#87

I have been afraid of sharing my ideas, post history, etc. in a way that could be easily traced back to my identity for years. I made sure my accounts and usernames bore no personally identifiable tid-bits. I use a VPN religiously (that won't change). I've since decided that I am done with all that. I was afraid my employer might question my Reddit posting history (they wouldn't.) I was worried someone who Googled me…

Unfortunately, not everyone has this luxury. I know many people who are LGBT and still hiding from family.

I’m bipolar, which I really do not want anyone hiring me to know. I don’t want people at work (or my family!) knowing and reading what I write.

As a friend put it: once your coworkers find your Reddit account, it’s over.

Re: Be anonymous

#88
post #58
post #38

As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…

You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…

I remember being shocked at the time that he had the foresight to use Tor but not to use literally any wifi network other than the campus wifi. That being said, there are a whole list of things he'd have to do to keep anonymous and it only takes one slip to identify someone.

Re: Be anonymous

#89

> Don't use macOS or Windows -- only Linux > Move to Brazil and live in the rainforest Juvenile, snarky, irreverent and irrelevant advice I'd expect to read on a 12 year old's Reddit post.

[deleted]

Re: Be anonymous

#90
post #52
post #38

As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…

> keyboard frequency on anonymized accounts can be de-anonymized Whonix uses Kloak to mitigate this [1], but unfortunately it isn't available in Qubes-Whonix. > Mixers and tumblers will eventually leak Don't use mixers and tumblers, use Monero and/or Monero atomic swaps. But, you are right that it is futile to maintain defense against a determined 3 letter agency. [1]: https://www.whonix.org/wiki/Keystroke_Deanonymiz…

I made this Firefox extension to defend against keyboard deanonymization on desktops https://git.voidnet.tech/kev/PrivateKeyboardAddon

I'm about to publish an update to it that uses a toolbar popup to fill out forms instead of the current lag approach, which will also protect against keyboard layout leaks[1] (which Tor browser/privacy.resistFingerprinting protects against anyway)

https://bugzilla.mozilla.org/show_bug.cgi?id=1222285

Post reply on HN