Live data from Hacker News

Large-Scale Online Deanonymization with LLMs

simonlermen.substack.com

141–150 of 258 posts

Re: Large-Scale Online Deanonymization with LLMs

#141

Despite being pseudonymous, I don’t take great pains to hide who I am. I am in my 50s and live on the West coast. I don’t have socials and I don’t post anywhere else. Have at it! If you are semi-retired, you’re free from the threat of cancellation. As long as you aren’t posting about crimes, there’s limits to what anyone can legally do to you. (Still, it’s good to be prudent and limit sharing.)

Unless you're in the nebulous situation of being Hispanic in the US, in which case you might get profiled. Or you might have family with jobs that are subject to pressure -- and right now, that seems like most jobs, because calling employers spineless is an insult to worms. Or if you'd like to travel by air, because watchlists are back, and carriers may just refuse service.

Re: Large-Scale Online Deanonymization with LLMs

#142

I post under my real name here, pretty much the only place I post. It keeps me honest and straight in what I say when I choose to say it. I tried talking to my children about leaving as clean of a footprint on the internet as one can in anticipation of future people/systems taking that into consideration. I don't know what it will be but I would expect some adversarial stuff. Trying to keep clean is what I'd prefer f…

How would "flooding the zone" actually work in that case?

AFAIK the strategy is usually used to divert attention from one subject that could be harmful to a person to some other stuff.

Wouldn’t spamming in that case provide more information about you?

Re: Large-Scale Online Deanonymization with LLMs

#143

I post under my real name here, pretty much the only place I post. It keeps me honest and straight in what I say when I choose to say it. I tried talking to my children about leaving as clean of a footprint on the internet as one can in anticipation of future people/systems taking that into consideration. I don't know what it will be but I would expect some adversarial stuff. Trying to keep clean is what I'd prefer f…

I expect more people over time to use local LLMs to write every single post they make online.

At this point, where everyone is using an LLM to post and I'm having to use an LLM to keep up and summarise it, I think I'll just ...stop and go outside for quite a while...

Re: Large-Scale Online Deanonymization with LLMs

#144

many people tend to overlook how little information is needed for successful de-anonymization. i like to introduce students to de-anonymization with an old paper "Robust De-anonymization of Large Sparse Datasets" published in the ancient history of 2008 ( https://www.cs.cornell.edu/~shmat/shmat_oak08netflix.pdf ): " We apply our de-anonymization methodology to the Netflix Prize dataset, which contains anonymous movie…

Throwaway accounts using "clever" turns of phrase can often be anonymized by double click, right-clicking -> googling their witty pun and seeing their the sole instance elsewhere, on Twitter, Facebook, etc If I see a couple words I dont know in a row, I can infer a posters real name. Id be more specific but any example is doxxing, literally so

I assume one's vocabulary is basically a fingerprint, even if one doesn't use unique turns of phrase. Domain knowledge just leaks in and we aren't conscious of it being identifiable.

Re: Large-Scale Online Deanonymization with LLMs

#145

Earlier quoted context omitted.

>So maybe this is a plus for passing any text published on the internet through a slopifier for deanonymization? Or vice versa, Indian scammers online can now run their traditional Victorian English phrasing through an AI to sound more authentically American. Interviewers now have to deal with remote North Korean deepfaked candidates pretending to be Americans. Just like the internet, AI is now a force multiplier for…

Seems like this could also be used by call centers to realtime adjust their accents. Text is obviously easier to analyze (no realtime required) but I imagine that audio is not that hard to process real time. Calling for home internet support and getting the person on the other end (in a US Southern or Boston accent) asking you to "do the needfull" could be pretty entertaining :-D

Why bother with accents when you can replace the call support workers alltogether with AI? Isn't that why all AI companies have gorillions in valuation?

Re: Large-Scale Online Deanonymization with LLMs

#146

Earlier quoted context omitted.

> That is not possible and it is extremely suppressive to express yourself. Also for the fact that you cannot predict how future powers will view past comments - for instance, certain benign political views 20 years ago could become "terroristic speech" tomorrow. I operate by a simple, general rule - I don't often say anything online I wouldn't say directly to someone's face in real life.

Interesting. You could probably get into trouble in those two places for extremely different things you said.

what two places?

Re: Large-Scale Online Deanonymization with LLMs

#147

Earlier quoted context omitted.

> That is not possible and it is extremely suppressive to express yourself. Also for the fact that you cannot predict how future powers will view past comments - for instance, certain benign political views 20 years ago could become "terroristic speech" tomorrow. I operate by a simple, general rule - I don't often say anything online I wouldn't say directly to someone's face in real life.

> I operate by a simple, general rule - I don't often say anything online I wouldn't say directly to someone's face in real life. More people should keep this same energy. I try to stress this to my kids and it feels like it's falling on deaf ears in regards to my teen. Alas.

I can be a rude prick online sometimes, but I can be in real life too - basically though the reason I do this is I never want it to be some huge surprise IRL if someone sees what I write online and be like, "wow, I didn't know that about him." I'm pretty much what I am online and IRL the same. For some reason this seems to matter for me, at least in the past when people have tried to like, send employers stuff I may have written online. The reaction is like "oh, yea, we knew that already about him."

Nothing terrible, maybe slightly embarrassing, but you know how online spaces can be. just be yourself basically, at least I try to be.

Re: Large-Scale Online Deanonymization with LLMs

#148
Could another mitigation be polluting identities online with fake ones so that real identities become hard to sift out.

For example if I tell my bot to clone me 100x times on all my platforms, all with different facts or attributes, suddenly the real me becomes a lot harder to select. Or any attribute of mine at all becomes harder to corroborate.

I hate to use this reference, but like the citadel from Rick and Morty.

Re: Large-Scale Online Deanonymization with LLMs

#149
I want to use "slower" methods of identification more. Like say for instance within a few blocks of you a human can identify who you are for any service that wants to do some kind of verification/proof you are/have XYZ.

We could designate specific individuals to do for you and me just like we do for today's trust authorities for website certificates.

No more verified profiles by uploading names, emails and passports and photographs(gosh!). Just turned 18 and want to access insta? Go to the local high school teacher to get age verified. Finished a career path and want it on linked in? Go to the company officer. Are you a new journalist who wants to be designated on X as so but anonymously? Go to the notary public.

One can do this cryptographically with no PII exchanged between the person, the community or the webservice. And you can be anonymous yet people know you are real.

It can be all maintained on a tree of trust, every individual in the chain needs to be verified, and only designated individuals can do actions that are sensitive/important.

You only need to do this once every so often to access certain services. Bonus: you get to take a walk and meet a human being.

Re: Large-Scale Online Deanonymization with LLMs

#150

Earlier quoted context omitted.

> Most adversaries who would want to deanonymize people at scale (governments, corporations) already have access to far more direct methods. Easier methods probably means more adversaries.

And different agendas. Governments and corporations doesn't try social engineering attacks, scams or do things that end in i.e. ransomware attacks.

[dead]
Post reply on HN