Earlier quoted context omitted.
You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…
From what I remember about that case, he was one of 8 people who were on the network at the time, but the authorities told him he was the only one, leading to his quick confession. Meaning that if he had stuck to his guns and denied it there wouldn't have been a good way to prove he was the one who did it.
Be anonymous
211–220 of 260 posts
Re: Be anonymous
#212Earlier quoted context omitted.
Not nearly on the level as what is being suggested but my company has had several anonymous surveys and I started thinking about writing style when taking them. If you're prone to certain phrases, words, use of contractions or lack thereof, especially when the pool of people is small and you're providing critical (but needed) criticisms, you could potentially be identified by your immediate supervisor. Introducing ty…
I am open to ideas for how to mitigate this remaining vulnerability even further
It would hopefully keep the sentiment while changing the words.
Re: Be anonymous
#213Earlier quoted context omitted.
> Don't buy domain names I'm not sure I understand this one - anyone have an explanation? Even if you put bogus contact info (this is not a problem, honestly) you still need to pay for it somehow. If you would use your own CC for this then... Bonus/prepaid/gift cards are usually not accepted (too much fraud), so the best solution would be to actually steal someone's CC data and hope they wouldn't notice 10 bucks.
Even so, as mentioned, the problem is that they detect the fraud and yank the site.
John Doe from WI, paid his dues.
Once a year "John Doe" receives the e-mail with WHOIS info and a question if that info is still valid:
> We are required by ICANN to send you the whois information for these domains once a year. If the information is correct, no action is needed. Otherwise please visit our website and update your whois information
That's all.
Just don't use GoDaddy or some other shit registrar what can yank everything from you just because they are a stupid behemoth without humans in support.
Or do you think registrar has nothing to do all day and casually stalks it's customers? Sends their info to FBI to check? HOW?
Re: Be anonymous
#214As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…
What you said and much more. For example, you buy a burner phone, but the place you bought it from, even if a second hand shop, had a security camera. Maybe they also record IMEI's before selling phones. Or you carry your burner phone together with your real phone. Or alternatively, you leave one at home when using the other. Both of these things can be linked by a sufficiently determined actor (FBI/NSA level). Or th…
Re: Be anonymous
#215Earlier quoted context omitted.
You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…
Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…
Living in no-extradition countries, using GrapheneOS on an Android phone, using Jabber/OTR chat for communication.
Re: Be anonymous
#216Earlier quoted context omitted.
Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…
Not nearly on the level as what is being suggested but my company has had several anonymous surveys and I started thinking about writing style when taking them. If you're prone to certain phrases, words, use of contractions or lack thereof, especially when the pool of people is small and you're providing critical (but needed) criticisms, you could potentially be identified by your immediate supervisor. Introducing ty…
Re: Be anonymous
#217Earlier quoted context omitted.
Who's more harmful, someone who facilitate the selling of illegal items or those who define what is legal? In a lawless society what this guy was doing would have been a respectable trade like any other.
You can twist your way into thinking any very bad thing or practice isn’t so. We can extend your line of thinking to murder and rape— does that sound acceptable too? No, this guy was much worse and more harmful than the norms of our society and those that propagate those norms.
Re: Be anonymous
#218The article presents a spectrum, dismisses both extremes, and advocates that people aim for the middle. The problem is, you may think you are hanging out in the middle, but you probably have much less privacy than you think you do. Even if you are making the right choices for today, you can't trust that the future will keep things private (advances in ML, ubiquitous surveillance) and you don't know that futures isn't…
What do we want to achieve by protecting our online identity?
For me, escaping the pervasive tracking and profiling by FAANG is one goal. I'm sure that tracking me across the internet is a lot more difficult (not impossible) than tracking the average user. Hopefully it can't be done in an automated fashion. That way tracking me is hopefully just not worth doing just for a few advertising dollars.
Re: Be anonymous
#219Earlier quoted context omitted.
Not nearly on the level as what is being suggested but my company has had several anonymous surveys and I started thinking about writing style when taking them. If you're prone to certain phrases, words, use of contractions or lack thereof, especially when the pool of people is small and you're providing critical (but needed) criticisms, you could potentially be identified by your immediate supervisor. Introducing ty…
Most "anonymous" surveys I've been asked to take through work require listing more than enough information for unique identity. One assured I would be anonymous, then asked me to fill in the name of my manager, my team, and job title.
Re: Be anonymous
#220if you must do things online that are best kept detached from your IRL/govt identity, setup a box running something like Tails that doesn’t accept any non-Tor traffic, and interact with it through a text-only interface (i.e. a shell, or links-like keyboard-driven web browser).
people sometimes discourage using obscure setups because they allow better fingerprinting but that’s not always as bad as it’s made out to be. primarily you want to break the link between your pseudonymous identity and your IRL identity. it doesn’t matter how fingerprintable your pseudonym is so long as the overlap between it and your IRL identity is small. and that’s the reason to prefer simpler interfaces like text-only: they prevent leaking things like cursor movements which might otherwise build a tie between those identities.