Live data from Hacker News

Be anonymous

kg.dev

171–180 of 260 posts

Re: Be anonymous

#171

Earlier quoted context omitted.

>Or you can just be a known drug lord, launder billions of USD through a respected international bank, no one goes to jail, small fine, Are you referring to some specific drug lord? Who?

https://www.investopedia.com/stock-analysis/2013/investing-n... My point being, this went on for a long time before they got "busted" and the bank people knew who they were dealing with. They didn't have to use crypto or tor or whatever to stay anonymous. They just used cash, everyone knew each other. They probably had dinners with coke and champagne. And when they did get "busted", somehow no one goes to prison, the…

I've never seen any evidence that that's how it went. All the reporting is long on rhetoric and short on evidence; the only things that actually, provably happened is that HSBC used their judgement in a way that the law said they were supposed to use their judgement, and did not automatically assume the most suspicious possible interpretation of payment flow that was happening.

Having worked in banks, you absolutely don't need to assume moustache-twirling villains to explain what happened; ordinary people doing the best they could to help out small businesses and families doing remittances would have had exactly the same outcome. Having spent a couple of months getting access to my own savings after moving overseas, the AML rules are plenty rigid enough already. Bankers are never going to be 100% perfect judges of whether someone is selling drugs and we shouldn't expect them to be.

Re: Be anonymous

#172

Feels like the article is slanting this Alex guy as a hero of sorts? I don’t like the tone of the article and wish I hadn’t clicked on it now..

Who's more harmful, someone who facilitate the selling of illegal items or those who define what is legal?

In a lawless society what this guy was doing would have been a respectable trade like any other.

Re: Be anonymous

#173
post #118
post #13

Earlier quoted context omitted.

I don’t think it’s all or nothing. Look at anonymous public personas like Banksy or Dril. People have tracked them down, and you can look up who they are if you try. But for the most part these people are anonymous, and get to enjoy some of the benefits of that.

Handles like that provide plausible deniability, not bulletproof anonymity.

Which is kind of the point. You can choose where you stand on a spectrum of how hard it is to identify you. It's a tradeoff between how much effort you make and how hard you want to make it for others.

Re: Be anonymous

#174
post #48

The article touches on a good point: one mistake and you're out. It doesn't even have to be your mistake - you didn't choose to put your SSN out there after all, yet here we are. This gave me a radical company idea, on the other end of the spectrum: spam as a service. Something that'll take your name, email, and other things and put it all over the internet in questionable and plausibly denial ways. That way, even wh…

This is essentially the premise of Neal Stephenson's Fall or Dodge in Hell.

Reading this now, am 3/4rds into it - bit of a slow burn, but highly fascinating.

Re: Be anonymous

#175

I mix @realname and @pseudonym accounts. I'm generally pretty careful about what I post under my real name and less so under an alias. However, over time I drop enough clues that people could figure my real identity with a little work. That leaves me with the worst of both worlds. It seems safest to assume that your identity is always tied to everything you do online.

I do this and accept that the cost of finding my real identity would be fairly low. I think most people do something similar. I don't want my employer searching "I work at $EMPLOYER_NAME" and finding me, but I don't mind if people paying attention can figure it out. I wouldn't post my address directly for any bored person to cause trouble with, but I don't particularly worry about people knowing where I live. Etc.

Re: Be anonymous

#176
post #76

Maybe Eric S. Raymond's advice from 21 years ago is no longer true in today's internet: > Concealing your identity behind a handle is a juvenile and silly behavior characteristic of crackers, warez d00dz, and other lower life forms. Hackers don't do this; they're proud of what they do and want it associated with their real names. So if you have a handle, drop it. In the hacker culture it will only mark you as a loser…

The ESR idea of "a hacker" has nothing to do with someone running illegal markets on darknet.

ESR was thinking about ppl like Daniel: https://twitter.com/bagder

Re: Be anonymous

#177
post #140

There's a middle ground somewhere here, in between "Don't be a criminal" and "Don't be stupid." I don't think the lesson we should take from AlphaBay is "Take better privacy safeguards" but "Don't set up an illegal dark web operation."

'Don't be a criminal' is trite. Something being criminal doesn't mean it's wrong to do. If you're saying not to do something specific then specify.

> “Don't set up an illegal dark web operation."

Re: Be anonymous

#178

Earlier quoted context omitted.

Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…

You thought this through too well. Probably should be traced back, put in a list and investigated just for this comment.

And what would they find?

The hardest investigation to defend against is the rubber hose investigation. Gotta give them what they want, without them even suspecting you could be that mysterious founder. The only way people suspect you’re someone is if your k is small, eg how many people could be Satoshi?

If you’re efficient, you can retire the mysterious founder identity and simply have multiple “early adopter” addresses that generated rewards early, among actual adopters. Make an exit from your projects as early as you can after they gain momentum with the wider crowd.

There is no way to stop people from starting open source projects, accruing the early rewards and then selling those rewards to others in a decentralized exchange or async OTC deal. If every country worldwide ever closes down all such anonymous mechanisms (maybe by 2050) and makes register in order to sell your rewards, you simply sell your private keys to the wallet in an async OTC deal. The buyer will have to trust that you won’t move the money after they register the address and before they move it.

Re: Be anonymous

#179
post #38

As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…

It's very odd to list all these (pretty theoretical!) things when, in practice, everyone gets owned by much more basic operational security concerns (except for the last "social engineering" one, where moving to a different communication network is a super common way for law enforcement to close the loop on an investigation).

Like "being super careful isn't enough" _might be true_, but if you did everything on this list and get caught anyways, you are in a super minority of people getting caught.

The example in the article (a hotmail-based email address being used). Everyone sees this and immediately goes "OK the feds can get this info". If such a basic opsec failure was happening, how is it that this person was still able to get as far as they did building up their website?

Being worried about the feds finding you from speech analysis of your posts online seems a bit silly when it's always _not_ that and much more just "finding the one simple thing you did wrong".

Re: Be anonymous

#180
post #76

Maybe Eric S. Raymond's advice from 21 years ago is no longer true in today's internet: > Concealing your identity behind a handle is a juvenile and silly behavior characteristic of crackers, warez d00dz, and other lower life forms. Hackers don't do this; they're proud of what they do and want it associated with their real names. So if you have a handle, drop it. In the hacker culture it will only mark you as a loser…

Practices had long varied across the spectrum. You can find plenty of examples of people who used real names, or variants of them, or pseudonyms or handles, going back to the earliest days of the Net.

ESR has long injected his own personal biases as established fact. The consistent fact noted here is that specific error, not the claims made through them.

That said, it was the gradual intrusion of ever-more insistent exhortations to use real names, and the rise of surveillance services which convinced me that the practice of using given names was no longer advisable. I'd date this to well before Facebook and Google+, notably with the rise of information brokers in the early 2000s. By the time Google+ rolled out as an "identity service", I pretty much declared last straw and ceased virtually all my own real-name interactions. Call that circa 2011, or over a decade ago.

I'd already been curtailing any such use for about a decade.

Post reply on HN