Live data from Hacker News

Be anonymous

kg.dev

121–130 of 260 posts

Re: Be anonymous

#121
post #58

Earlier quoted context omitted.

You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…

Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…

You thought this through too well. Probably should be traced back, put in a list and investigated just for this comment.

Re: Be anonymous

#122
post #82

Earlier quoted context omitted.

Linux is definitely more anonymous than Windows/Mac, but if you seriously want to be anonymous, you should use Qubes with Whonix.

Is there a good virtualbox/vm of these yet?

Hasn't Whonix always been provided as a pair of VMs? https://www.whonix.org/#download

Qubes is a hypervisor itself, it's not designed to be virtualised.

Re: Be anonymous

#123

Or you can just be a known drug lord, launder billions of USD through a respected international bank, no one goes to jail, small fine, and they're probably still laundering 10 years later and no one cares. No one is anonymous. They're probably all using SMS and corporate email. Sell a little bit of drugs through the silk road and you'll get royally f-ed! Sell all the opioids in the world through a public pharma corp…

Your comment echoes today's Credit Suisse news:

https://www.theguardian.com/news/2022/feb/20/credit-suisse-s...

“The pretext of protecting financial privacy is merely a fig leaf covering the shameful role of Swiss banks as collaborators of tax evaders.”

And it's more than tax evasion, "include a human trafficker in the Philippines, a Hong Kong stock exchange boss jailed for bribery, a billionaire who ordered the murder of his Lebanese pop star girlfriend and executives who looted Venezuela’s state oil company, as well as corrupt politicians from Egypt to Ukraine".

Re: Be anonymous

#124
post #38

As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…

Having to be right “every time” is why it’s insane we still rely on things like SSNs and phone numbers that are difficult to replace but highly valuable and damaging if leaked.

We need to be exchanging personal data only in forms that become worthless and unidentifying in a short period of time, requiring secure refreshes to maintain.

Re: Be anonymous

#125
post #58

Earlier quoted context omitted.

You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…

Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…

Not nearly on the level as what is being suggested but my company has had several anonymous surveys and I started thinking about writing style when taking them. If you're prone to certain phrases, words, use of contractions or lack thereof, especially when the pool of people is small and you're providing critical (but needed) criticisms, you could potentially be identified by your immediate supervisor. Introducing typos and avoiding phrases you commonly say, adjusting your "tone" is a lot of effort when you can just disengage entirely and/or behave like everything is public (which it may as well be at this point).

Re: Be anonymous

#126
post #58

Earlier quoted context omitted.

You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…

Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…

Just some suggestions for the connection part.

Using a phone is probably the first mistake. If you are going to use your home network you are better off using a machine you control and an operating system that is open source.

I suggest these steps: Step 1: Connect to a popular vpn. Step 2: Connect to tor Step 3: Get free vps or pay with cryto you trade for gift cards purchased or some other method Step 4: Connect to vps with desktop running. Use virtual desktop. Step 5: Use vpn. This time use vpn with best rep to be accepted as regular traffic. Step 6: Signup for services

Step 1 solves the k issue. Many people using that vpn will connect to tor

Step 4: Seems slow but at the virtual desktop level out things are fast from that machine to new hosts. Use scripts could help.

Re: Be anonymous

#127

Or you can just be a known drug lord, launder billions of USD through a respected international bank, no one goes to jail, small fine, and they're probably still laundering 10 years later and no one cares. No one is anonymous. They're probably all using SMS and corporate email. Sell a little bit of drugs through the silk road and you'll get royally f-ed! Sell all the opioids in the world through a public pharma corp…

>Or you can just be a known drug lord, launder billions of USD through a respected international bank, no one goes to jail, small fine,

Are you referring to some specific drug lord? Who?

Re: Be anonymous

#129
post #126

Earlier quoted context omitted.

Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…

Just some suggestions for the connection part. Using a phone is probably the first mistake. If you are going to use your home network you are better off using a machine you control and an operating system that is open source. I suggest these steps: Step 1: Connect to a popular vpn. Step 2: Connect to tor Step 3: Get free vps or pay with cryto you trade for gift cards purchased or some other method Step 4: Connect to…

Iirc phones will broadcast previously connected access point max addresses. I doubt gp truly understands what it takes to be anonymous (imo it’s probably impossible).

Re: Be anonymous

#130
post #50

> Don't buy domain names Can anyone explain this? Assuming your data isn't in the WHOIS record, why does this increase your exposure more than any other company knowing your name? A search shows up options for anonymous domain name services.

If you don't provide a real name when registering a domain, you lose the domain as soon as the registrar gets served with papers. This is an ICANN policy, you can't escape it.

All the registrars sell access to the real names behind their "privacy protection" service. They do not bother checking if the requester has a warrant or is even affiliated with law enforcement. They simply charge a fee (around $50 per request) to prevent bulk extraction, and possibly review the top 50-100 highest-volume requesters.

njalla is really the only way around this, but you have to trust them with legal ownership of your domain.

Post reply on HN