Live data from Hacker News

Large-Scale Online Deanonymization with LLMs

simonlermen.substack.com

181–190 of 258 posts

Re: Large-Scale Online Deanonymization with LLMs

#181
I tried this today with this username and other usernames on this and other platforms with Claude Code

- First it told me it couldn't do this, that this was doxxing

- I said: its for me, I want to see if I can be deanonymized

- Claude says: oh ok sure and proceeds to do it

It analyzed my profile contents and concluded that there were likely only 5 - 10 people in the world that would match this profile (it pulled out every identifying piece of information extremely accurately). Basically saying: I don't have access to LinkedIn but if I did I could find you in like 5 seconds.

Anyway, like others have said: this type of capability has always been around for nation state actors (it's just now frighteningly more effective), but e.g. for your stalker? For a fraudster or con artist? Everyone has a tremendous unprecedented amount of power at their fingertips with very little effort needed.

Re: Large-Scale Online Deanonymization with LLMs

#182

Earlier quoted context omitted.

> I operate by a simple, general rule - I don't often say anything online I wouldn't say directly to someone's face in real life. More people should keep this same energy. I try to stress this to my kids and it feels like it's falling on deaf ears in regards to my teen. Alas.

I can be a rude prick online sometimes, but I can be in real life too - basically though the reason I do this is I never want it to be some huge surprise IRL if someone sees what I write online and be like, "wow, I didn't know that about him." I'm pretty much what I am online and IRL the same. For some reason this seems to matter for me, at least in the past when people have tried to like, send employers stuff I may…

As someone who gets dopamine hits from downvotes on HN, I approve of your behavior!

>just be yourself basically

Yea, it is boring when everyone is the same. I would like a rude but interesting world (even if I might not survive long in one), than a nice, boring one.

Re: Large-Scale Online Deanonymization with LLMs

#183
That's honestly quite terrifying. If you're posting somewhere else under a pseudonym, this technology can get you doxxed. The safest thing to do is to not participate in communities at all. Avoid posting, avoid social interactions, just be a ghost. The future is bleak.

Re: Large-Scale Online Deanonymization with LLMs

#184

Maybe I missed something, but I see little evidence that there is a concerning ability to deanonymize. Many people post under a pseudonym but then link to their GitHub etc. In fact by construction the HN dataset _only_ consists of people who are comfortable with their real identity being linked to it. The real question is whether someone who is pseudonymous and actually attempting to remain so can be deanonymized.

> The real question is whether someone who is pseudonymous and actually attempting to remain so can be deanonymized.

They can. That's the point. This site serves as a dataset against which pseudonymous posts can be evaluated.

Re: Large-Scale Online Deanonymization with LLMs

#185

Earlier quoted context omitted.

I can be a rude prick online sometimes, but I can be in real life too - basically though the reason I do this is I never want it to be some huge surprise IRL if someone sees what I write online and be like, "wow, I didn't know that about him." I'm pretty much what I am online and IRL the same. For some reason this seems to matter for me, at least in the past when people have tried to like, send employers stuff I may…

Your framing is interesting. You may feel that you can’t change who you are in real life, but people have a choice on how they behave online (or choose not to engage at all). So you could choose to be nice (or at least not a jerk); I’m pretty sure you wouldn’t get people writing to your employer complaining. I’d argue that if you know you’re sometimes a jerk, it’d be less stressful for you and others if you didn’t br…

Sure, there is a choice. it’s rarely/never been stressful for me though, and I value being who I am for my own reasons as a strength and not a weakness. I always try to play by the moderation rules as I can possibly and realistically do. some of what I’ve written online has gotten me opportunities it wouldn’t have if i’d been more hesitant.

My point is if you have a good track record what you maintain online vs irl doesn’t matter as much to people as you’d maybe think as long as you are being true to yourself. I’m an elder millennial though, so that’s always been the case online for me and i dont think i often get out of pocket online anyway.

maybe that won’t be the case in the future. I could write a lot more than I’d care to publicly about personal and implied threats I’ve received based on my writings, but caving to that to me would betray my own values and I choose to consume the web how i choose knowing possible consequences - plus the fact moderation standards and what is “rude” drastically differs amongst platforms.

Re: Large-Scale Online Deanonymization with LLMs

#186

I'm not sure the practical implications are as dramatic as the paper suggests. Most adversaries who would want to deanonymize people at scale (governments, corporations) already have access to far more direct methods. The people most at risk from this are probably activists and whistleblowers in jurisdictions where those direct methods aren't available, not average users.

Wait till activist groups start doing this to shame people, get them fired, etc. It's going to be interesting.

Re: Large-Scale Online Deanonymization with LLMs

#187
The real-world benchmark approach is the right direction. Most agent evals I've seen test for task completion on clean inputs. That's not how production use looks.

What tends to break agents in the wild: ambiguous instructions that have multiple valid interpretations, state that changes mid-task, and error recovery when a sub-step fails silently rather than loudly.

The hardest thing to benchmark is graceful degradation. A good agent should know when to stop and ask for clarification rather than confidently completing the wrong task.

Re: Large-Scale Online Deanonymization with LLMs

#188

I post under my real name here, pretty much the only place I post. It keeps me honest and straight in what I say when I choose to say it. I tried talking to my children about leaving as clean of a footprint on the internet as one can in anticipation of future people/systems taking that into consideration. I don't know what it will be but I would expect some adversarial stuff. Trying to keep clean is what I'd prefer f…

>I post under my real name here, pretty much the only place I post. It keeps me honest and straight in what I say when I choose to say it.

I do the same thing, and I think I'm a much better person for it. The Internet is not, in my final analysis, some indiscriminate dumping ground for my personal issues and moods. It's a place where I can relax and practice putting forward a more prosocial form of myself, even when what I actually have to say is uncomfortable.

While we can't predict how the adversary will read and respond to our moves, I suspect the easier marks are the people who choose to publicly drench everything they touch in negativity and cynicism. It's a sign of an already compromised social immune system.

Re: Large-Scale Online Deanonymization with LLMs

#189

Earlier quoted context omitted.

> Same comment read after 1 Dec 2020 (Transition coming out): Insensitive, demeaning, in accurate. I genuinely don't understand this. Are you sure you're not imagining possible offenses against some non-existent standard?

well, how about "abortion legal" to "abortion murder"... possible to see this coming, but I know doctors in NY who are now afraid to travel to Texas. How about DEI initiatives as good things in 2024 and a mark of evil in 2025? Lots of people were fired because in 2024 their boss told them to work on DEI and they did what their boss told them to do. Turns out this was a capital offense.

> because in 2024 their boss told them

I am not commenting on your specific example of DEI but I want to make the general point that you are always responsible for what you do, irregardless of whether you were told to do it by your boss, or commanding officer, or whatever.

So again, I don't care about the specific example you used but if something is 'in fashion' and you go along with it, including at work, then you are ultimately responsible for that choice. Because it is always a choice, including being a hard choice that results in you losing your job.

Re: Large-Scale Online Deanonymization with LLMs

#190

I post under my real name here, pretty much the only place I post. It keeps me honest and straight in what I say when I choose to say it. I tried talking to my children about leaving as clean of a footprint on the internet as one can in anticipation of future people/systems taking that into consideration. I don't know what it will be but I would expect some adversarial stuff. Trying to keep clean is what I'd prefer f…

I view posting online with a real name like getting a permanent tattoo. My values or priorities may significantly change over decades, especially as a child, so why would I want to jeopardize the reputation of a potential future identity with something I may post today?

One could just as easily make the opposite argument. Given that your values and priorities may change significantly over the decades, a smart investment now into a solid, stable, and prosocial public identity may reap considerable and wide-ranging benefits in ways you couldn't even predict. This is especially true if you take seriously the idea that it's not what you say but how you say it that matters in the end.
Post reply on HN