Live data from Hacker News

Be anonymous

kg.dev

211–220 of 260 posts

Re: Be anonymous

#211
post #58

Earlier quoted context omitted.

You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…

From what I remember about that case, he was one of 8 people who were on the network at the time, but the authorities told him he was the only one, leading to his quick confession. Meaning that if he had stuck to his guns and denied it there wouldn't have been a good way to prove he was the one who did it.

No, it just means they couldn't have stopped digging at that point. Having dramatically reduced the search scope to a small number of people, they would have just needed to find one other small piece of evidence to narrow down the group suspects further.

Re: Be anonymous

#212

Earlier quoted context omitted.

Not nearly on the level as what is being suggested but my company has had several anonymous surveys and I started thinking about writing style when taking them. If you're prone to certain phrases, words, use of contractions or lack thereof, especially when the pool of people is small and you're providing critical (but needed) criticisms, you could potentially be identified by your immediate supervisor. Introducing ty…

I am open to ideas for how to mitigate this remaining vulnerability even further

Maybe you could run all your communications through a translator twice (e.g. English -> French, French -> English), and fix any typos?

It would hopefully keep the sentiment while changing the words.

Re: Be anonymous

#213
post #114

Earlier quoted context omitted.

> Don't buy domain names I'm not sure I understand this one - anyone have an explanation? Even if you put bogus contact info (this is not a problem, honestly) you still need to pay for it somehow. If you would use your own CC for this then... Bonus/prepaid/gift cards are usually not accepted (too much fraud), so the best solution would be to actually steal someone's CC data and hope they wouldn't notice 10 bucks.

Even so, as mentioned, the problem is that they detect the fraud and yank the site.

Lel, how?

John Doe from WI, paid his dues.

Once a year "John Doe" receives the e-mail with WHOIS info and a question if that info is still valid:

> We are required by ICANN to send you the whois information for these domains once a year. If the information is correct, no action is needed. Otherwise please visit our website and update your whois information

That's all.

Just don't use GoDaddy or some other shit registrar what can yank everything from you just because they are a stupid behemoth without humans in support.

Or do you think registrar has nothing to do all day and casually stalks it's customers? Sends their info to FBI to check? HOW?

Re: Be anonymous

#214
post #68
post #38

As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…

What you said and much more. For example, you buy a burner phone, but the place you bought it from, even if a second hand shop, had a security camera. Maybe they also record IMEI's before selling phones. Or you carry your burner phone together with your real phone. Or alternatively, you leave one at home when using the other. Both of these things can be linked by a sufficiently determined actor (FBI/NSA level). Or th…

That's why step 0 if you plan on stepping on the U.S. governments toes is: Move to a country with no extradition treaty with the U.S. and be prepared to spend the rest of your life only traveling between such countries. Make sure to also account for edge cases like countries without an extradition treaty that still enforce it (i.e. Maldives) and countries WITH an extradition treaty that do not enforce it (like Venezuela).

Re: Be anonymous

#215
post #58

Earlier quoted context omitted.

You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…

Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…

I would also add:

Living in no-extradition countries, using GrapheneOS on an Android phone, using Jabber/OTR chat for communication.

Re: Be anonymous

#216

Earlier quoted context omitted.

Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…

Not nearly on the level as what is being suggested but my company has had several anonymous surveys and I started thinking about writing style when taking them. If you're prone to certain phrases, words, use of contractions or lack thereof, especially when the pool of people is small and you're providing critical (but needed) criticisms, you could potentially be identified by your immediate supervisor. Introducing ty…

Most "anonymous" surveys I've been asked to take through work require listing more than enough information for unique identity. One assured I would be anonymous, then asked me to fill in the name of my manager, my team, and job title.

Re: Be anonymous

#217

Earlier quoted context omitted.

Who's more harmful, someone who facilitate the selling of illegal items or those who define what is legal? In a lawless society what this guy was doing would have been a respectable trade like any other.

You can twist your way into thinking any very bad thing or practice isn’t so. We can extend your line of thinking to murder and rape— does that sound acceptable too? No, this guy was much worse and more harmful than the norms of our society and those that propagate those norms.

It is difficult to articulate how much worse Henry Kissinger and Phil Bokovoy are for the world than Alexandre Cazes and Ross Ulbricht.

Re: Be anonymous

#218
post #32

The article presents a spectrum, dismisses both extremes, and advocates that people aim for the middle. The problem is, you may think you are hanging out in the middle, but you probably have much less privacy than you think you do. Even if you are making the right choices for today, you can't trust that the future will keep things private (advances in ML, ubiquitous surveillance) and you don't know that futures isn't…

I think we have to ask ourselves:

What do we want to achieve by protecting our online identity?

For me, escaping the pervasive tracking and profiling by FAANG is one goal. I'm sure that tracking me across the internet is a lot more difficult (not impossible) than tracking the average user. Hopefully it can't be done in an automated fashion. That way tracking me is hopefully just not worth doing just for a few advertising dollars.

Re: Be anonymous

#219

Earlier quoted context omitted.

Not nearly on the level as what is being suggested but my company has had several anonymous surveys and I started thinking about writing style when taking them. If you're prone to certain phrases, words, use of contractions or lack thereof, especially when the pool of people is small and you're providing critical (but needed) criticisms, you could potentially be identified by your immediate supervisor. Introducing ty…

Most "anonymous" surveys I've been asked to take through work require listing more than enough information for unique identity. One assured I would be anonymous, then asked me to fill in the name of my manager, my team, and job title.

Fortunately mine have not but at a certain point they're useless because no matter no low the scores go nobody in their right mind wants to provide long-form feedback to identity actionable fixes because product teams are usually small even if there are a lot of developers in the pool your pain points will be unique to what your working on.

Re: Be anonymous

#220
live offline. as long as you’re not completely socially incompetent you can be largely yourself in most situations, find people you jive with, and then be completely yourself with them. unless your threat level is “my phone’s recording everything in the room 24/7 and sending that to authorities”, you’re free to do all the illegal drugs you want with your friends, use the N-word, do all the other things which you thing you should be able to freely do but for some reason aren’t able to do comfortably in public.

if you must do things online that are best kept detached from your IRL/govt identity, setup a box running something like Tails that doesn’t accept any non-Tor traffic, and interact with it through a text-only interface (i.e. a shell, or links-like keyboard-driven web browser).

people sometimes discourage using obscure setups because they allow better fingerprinting but that’s not always as bad as it’s made out to be. primarily you want to break the link between your pseudonymous identity and your IRL identity. it doesn’t matter how fingerprintable your pseudonym is so long as the overlap between it and your IRL identity is small. and that’s the reason to prefer simpler interfaces like text-only: they prevent leaking things like cursor movements which might otherwise build a tie between those identities.

Post reply on HN