As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…
Be anonymous
221–230 of 260 posts
Re: Be anonymous
#222As careful as some of the things he suggests are...if you're truly wanted by a state-level actor or sufficiently motivated attacker, you won't be able to hide by simply using VPN and Tor. Especially if you're running something with many transactions like AlphaBay. You would need to obfuscate quite a bit more: - if you're using VPN traffic but most people "around" you aren't, you're a suspicious node; your ISP could e…
> keyboard frequency on anonymized accounts can be de-anonymized Whonix uses Kloak to mitigate this [1], but unfortunately it isn't available in Qubes-Whonix. > Mixers and tumblers will eventually leak Don't use mixers and tumblers, use Monero and/or Monero atomic swaps. But, you are right that it is futile to maintain defense against a determined 3 letter agency. [1]: https://www.whonix.org/wiki/Keystroke_Deanonymiz…
Monero doesn’t make your transactions anonymous, it makes them ambiguous. your wallet might default to using an n=6 ring signature, meaning it picks 5 random addresses with balances and creates a transaction that could have plausibly originated from any of those 5 or your own. so you get plausible deniability, but also if your threat actor can unmask the other 5 addresses (which might not be so hard if those accounts are regularly interacting with exchanges) then you’re done.
zcash gets you actual transaction-level anonymity, not just ambiguity. fewer places accept it, but in theory you can still break the link by obtaining zcash and then exchanging it for the currency of your choice on any exchange that doesn’t ask for PII (e.g. a DEX)
Re: Be anonymous
#223Earlier quoted context omitted.
Most "anonymous" surveys I've been asked to take through work require listing more than enough information for unique identity. One assured I would be anonymous, then asked me to fill in the name of my manager, my team, and job title.
Fortunately mine have not but at a certain point they're useless because no matter no low the scores go nobody in their right mind wants to provide long-form feedback to identity actionable fixes because product teams are usually small even if there are a lot of developers in the pool your pain points will be unique to what your working on.
Re: Be anonymous
#224Earlier quoted context omitted.
Not nearly on the level as what is being suggested but my company has had several anonymous surveys and I started thinking about writing style when taking them. If you're prone to certain phrases, words, use of contractions or lack thereof, especially when the pool of people is small and you're providing critical (but needed) criticisms, you could potentially be identified by your immediate supervisor. Introducing ty…
I am open to ideas for how to mitigate this remaining vulnerability even further
Re: Be anonymous
#225Earlier quoted context omitted.
I would say that if you're caught and ... somehow manage to delete all the evidence linking you ( you have device explosives or, idk, 2048 bit encryption ), you may be able to escape, but come on, who are we kidding: the FBI has like a 99.96% conviction rate and that's without even going to into the "parallel construction" or other conspiratorial lines of attack.
The FBI has "like a 99.96% conviction rate"?
Re: Be anonymous
#226Earlier quoted context omitted.
From what I remember about that case, he was one of 8 people who were on the network at the time, but the authorities told him he was the only one, leading to his quick confession. Meaning that if he had stuck to his guns and denied it there wouldn't have been a good way to prove he was the one who did it.
No, it just means they couldn't have stopped digging at that point. Having dramatically reduced the search scope to a small number of people, they would have just needed to find one other small piece of evidence to narrow down the group suspects further.
Re: Be anonymous
#227Earlier quoted context omitted.
>Anonymity is not on a spectrum Is it not, for the non-criminal user? My HN, Reddit and Twitter accounts are "anonymous" (pseudonymous would be more accurate), and it matters to me to the extent I share thoughts I would not on Facebook or if Googling my name lead straight to it - not that I'm ashamed of them, I try to be decent (tho I slip at times and am more brash than I would IRL), it's just that they hold some pe…
Changing the definition of anonymous to include pseudonymous is not a compelling argument that anonymity is the same as pseudonomity.
Per Wikipedia:
>Anonymity describes situations where the acting person's identity is unknown. [...] The important idea here is that a person be non-identifiable, unreachable, or untrackable.
Re: Be anonymous
#228Earlier quoted context omitted.
In that vein you have to also prosecute alcohol distilleries, tobacco companies, fast food companies, casinos, lotto companies, ice cream makers, and any other company that makes something that people struggle to control their own consumption. And we do, that's why we have government. At least you have a recourse when these companies operate within the law.
There are some important differences. Alcohol distilleries didn't label/market their products as beneficial ailments intended to cure diseases. Pharmaceutical companies should be bound, at least morally, by the same hippocratic oath that govern the medical profession. Clearly they are not.
But they did? They just did it 100+ years ago. Does that matter?
Re: Be anonymous
#229Earlier quoted context omitted.
You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…
From what I remember about that case, he was one of 8 people who were on the network at the time, but the authorities told him he was the only one, leading to his quick confession. Meaning that if he had stuck to his guns and denied it there wouldn't have been a good way to prove he was the one who did it.
Re: Be anonymous
#230Earlier quoted context omitted.
You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him. https://theprivacyblog.com/blog/anonymity/why-tor-fa…
Tor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could…