Live data from Hacker News

LLMs can unmask pseudonymous users at scale with surprising accuracy

arstechnica.com

41–50 of 78 posts

Re: LLMs can unmask pseudonymous users at scale with surprising accuracy

#42

> If you request deletion of your Hacker News account, note that we reserve the right to refuse to (i) delete any of the submissions, favorites, or comments you posted on the Hacker News site Probably not GDPR-compliant then if comments can be deanonymised by LLMs.

My understanding is that the GDPR “right to be forgotten” applies to personal data. Are publicly available comments considered personal data?

If they can help to deanonymize you, they must contain something personal. Writing pattern are pretty personal, certain spelling errors too, or the choose of words.

Re: LLMs can unmask pseudonymous users at scale with surprising accuracy

#44

> If you request deletion of your Hacker News account, note that we reserve the right to refuse to (i) delete any of the submissions, favorites, or comments you posted on the Hacker News site Probably not GDPR-compliant then if comments can be deanonymised by LLMs.

My understanding is that the GDPR “right to be forgotten” applies to personal data. Are publicly available comments considered personal data?

From ico.org.uk: “ It is important to note that opinions and inferences are also personal data, maybe special category data, if they directly or indirectly relate to that individual”

From gdpr-info.eu: “ Subjective information such as opinions, judgements or estimates can be personal data.”

So yes. HN is in violation of the GDPR. I had already filed a complaint about this policy at my local GDPR authority.

Re: LLMs can unmask pseudonymous users at scale with surprising accuracy

#46
post #42

Earlier quoted context omitted.

My understanding is that the GDPR “right to be forgotten” applies to personal data. Are publicly available comments considered personal data?

If they can help to deanonymize you, they must contain something personal. Writing pattern are pretty personal, certain spelling errors too, or the choose of words.

Absolutely anything relating to an anonymous person could help deanonymization, so that implies that anything relating to any person is personal data. Is that the GDPR’s position?

Re: LLMs can unmask pseudonymous users at scale with surprising accuracy

#47
Anonymous account unmasking represents a new threat to anonymity. not just this technique with llms, but the earlier text similarity one.

But I think it would be generally easier to counter in the same way.

Use an llm or heuristics to pose as someone else.

not only do you erase your traces, you add false positives in to the system which reduces the overall effectiveness of these techniques in the future. A bit of poisoning the well.

I hope eventually an easy to use tool, with maybe a small local llm, can make it easy enough to do this, so that any future deanonymization attacks would be too untrustworthy to rely on

Re: LLMs can unmask pseudonymous users at scale with surprising accuracy

#48

Only if said users happen to commit OPSEC failures themselves. LLMs aren't magic... If someone can figure out who I am or what city I live in just by this username or my comments (with proof), I'll personally send you 500,000 JPY. I'm quite confident that's not going to happen though. The paper referenced in the article does not even explain their exact testing methodology (such as the tools or exact prompts used) be…

Anyone who says that they can maintain perfect opsec over an extended period of time is seriously mistaken. A sufficiently motivated investigator with enough resources will join the dots eventually. The would-be evader has to be lucky every time whereas the investigator only has to be lucky once.

Re: LLMs can unmask pseudonymous users at scale with surprising accuracy

#49
I thought this would be more about stylometry but it's mostly about users literally posting the same identifiable information across multiple services, including in one example their age, dog name, profession.

It's all classic dox profiling techniques. Even the things like spelling differences being regional signals and commonality to specific things being discussed.

It's why one has to think about what is being posted to which community if using different identities, rather than posting the same things across all of them. Though any such effort would be a waste if reliant on some non-public info that later was exposed in a database breach which tied together previously unrelated profiles.

Re: LLMs can unmask pseudonymous users at scale with surprising accuracy

#50
post #35

> If you request deletion of your Hacker News account, note that we reserve the right to refuse to (i) delete any of the submissions, favorites, or comments you posted on the Hacker News site Probably not GDPR-compliant then if comments can be deanonymised by LLMs.

This is probably the worst piece of policy on whole HN. It has a evil feel to it. If HN wasn't so interesting/valueable, this would be the single reason NOT to use it at all.

All these comments live forever in HN datasets that people download anyway
Post reply on HN