12 ms·
You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made
by 3s 5y ago
You're absolutely right. It is not enough to use anonymity tools, you also have to make sure everything else around you doesn't compromise your anonymity. Made me think of a Harvard bomb threat incident where the student posting a fake bomb threat (through Tor) to avoid final exams was the only person using Tor on campus at the time, which trivially identified him.
https://theprivacyblog.com/blog/anonymity/why-tor-failed-to-hide-the-bomb-hoaxer-at-harvard https://theprivacyblog.com/blog/anonymity/why-tor-failed-to-...
- klysm 5y agoMany anonymity tools have the k-anonymity property. It’s really unfortunate for k to be 1.
- 323 5y agoThis is the big problem of crypto coin mixers. 99% of their users are trying to launder illegal bitcoin.
- sfilmeyer 5y agoI remember being shocked at the time that he had the foresight to use Tor but not to use literally any wifi network other than the campus wifi. That being said, there are a whole list of things he'd have to do to keep anonymous and it only takes one slip to identify someone.
- deleted 5y ago[deleted]
- notsoanonynous 5y agoTor is amateur hour. The Feds can easily deanomymize things where a server is up 24/7 servicing requests. The author of this article is also very wrong: Anonymity is not on a spectrum. It’s all or nothing. Like a Mario game where any mistaken encounter makes you start over (and that’s if you don’t get in trouble for what you did). First step is to understand that any system could be bugged. Every IRL confidant could sell you out. Every keyboard could have a keylogger, etc. Every store could have a security camera. Phones are giving out their MAC numbers to every cell tower and wifi radio. They now have chips you can’t turn off, and so forth. You should also assume there is no such thing as an “anonymous” account and that every service COULD sell out whatever information you gave it. (Yes, even Telegram or ProtonMail, however unlikely that may be.) The below is a playbook for how to become truly anonymous. Continue to live your everyday life but the below is only for your “anonymous” identities, which you can gradually bootstrap as a hobby: The first thing you do, therefore, is bootstrap your identity by taking advantage of unlinkability that is available to you. Buy a bunch of Android phones on Craigslist for cash, for example. (Or pay a homeless guy to buy a phone in a store for you.) Do not use SIM cards at all, only WiFi. Never take photos, etc. Keep your phone off or in a faraday cage until you use it. For extra points, always use it through a VPN on WiFi at home, which you purchased using the accounts below: Then make an anonymous google account on the Android phone. Make some ProtonMail accoung usinf such an anonymous Google account. Now you can bootstrap from email addresses. Buy some Google Play gift cards and download some apps to get a second number. Now you can bootstrap from a phone number. Sign up to Telegram, Signal and other accounts using this. Now you have end to end encrypted messaging. Frankly, though, realtime messaging is a bit of a luxury to continue to stay in normie world. To stay truly anonymous, you should continue to: 1. Schedule posts and mail send/receive at random times. Do not ever use realtime audio or video because it might be recorded. You might make an exception for early days of your projects when people would have no reason to go out of their way to record you — just to give them confidence you’re a real person. But afterwarss, stop doing that. Let the people build your movement for you. 2. Never mention your anonymous identity or projects from your real one, and vice versa. This means your anonymous identity MUST NEVER have confidants or colleagues IRL. Build up a network of colleagues who are “fronts” for what you do. Eventually you can step back and let the movement do things for you. 3. Pay and get paid in cryptocurrency. Have smart contracts send you the money (think Richard Heart’s Hex origin address, but actually anonymous). 4. You will only ever be able to spend the crypto on paying people for services and DeFi protocols. You can never cash out to fiat, because the IRL purchases catch up with you when they follow the money. There is a surprising amount of online services you can spend $97 million dollars on, while staying anonymous ;-) If you really do need to spend money IRL (because you went broke somehow in your everyday life) then you can cashout using cross-chain bridges and Monero to pay for goods. But still, never get ostentatious wealth IRL! 5. The weakest link then becomes your writing or coding style. Never publish any code or writing, let others do it for you. Make your communication to others from your anonymous identity sufficiently different than anything saved later would not identify you (this is the weakest link, but you can consider “playing a character” when speaking to others). 6. Any private keys that you used to sign your messages can be periodically published in some conspicuous place, effectively giving you plausible deniability about all your previous and future posts. It’s hard to prove a negative (that no one else has access to your private keys before your public disclosure.) Alright, Hacker News. I have given away the non-amateur anonymity playbook using https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle https://en.wikipedia.org/wiki/Kerckhoffs%27s_principle Go ahead and try to deanonymize this in the comments below. Assume you are a state actor with all tools at your disposal.
- majormajor 5y ago> 3. Pay and get paid in cryptocurrency. Have smart contracts send you the money (think Richard Heart’s Hex origin address, but actually anonymous). My first question about this plan is "what are you getting paid for and how do you advertise your services"? You need to never meet the people paying you in person, and ideally you are selling some purely digital good. So, something like underground illegal programming or hacking or such? Is there anything else that would work?
- dento 5y agoSome blockchain project offer grants for (completely legal) programming work, and some of them wont require real world identification.
- notsoanonynous 5y agoI thought it was obvious, but I guess not. No, you don’t do work for money. You start an open source project and get many people to run your software. You meanwhile generate as many early rewards as you can (you can even do it under multiple accounts) and when the ecosystem is up and running, you’ll be the mysterious founder, generating millions (or billions) in passive income. Sounds familiar? It should… Simply never move money using your first few accounts, and whoever early people you pay, have them stake your currency for a long time, and borrow against it on decentralized lending marketplaces, to avoid spooking people that the mysterious founder has moved their money.
- CRConrad 5y agoSo lemme spell it out: This is what you're claiming Satoshi did / is doing.
- majormajor 5y agoWell that's not interesting at all, then. How repeatable do you think that is? That's one of the problems with trying to stay anonymous, right? The playbook constantly goes out of date.
- 5y ago
- missingrib 5y agoFrom what I remember about that case, he was one of 8 people who were on the network at the time, but the authorities told him he was the only one, leading to his quick confession. Meaning that if he had stuck to his guns and denied it there wouldn't have been a good way to prove he was the one who did it.
- cywick 5y agoNo, it just means they couldn't have stopped digging at that point. Having dramatically reduced the search scope to a small number of people, they would have just needed to find one other small piece of evidence to narrow down the group suspects further.
- missingrib 5y agoWhat type of evidence could they have found?
- aaaaaaaaata 5y agoDepends how much of his shit they tossed, and for how long. People he spoke to, witnesses they could....encourage....
- zxcvbn4038 5y agoIt was indeed his immediate and voluntary confession that did him in. If he had not snitched on himself he would have just been a person of interest. He was one of several people who happened to be using Tor on the campus at the time, but that doesn’t mean anything, the person making the threat could have been someone in LA or Moscow or Beijing just looking to cause mischief and having no connection to the school at all. If he had kept his cool he probably would have gotten away with it.
- nly 5y agoIf the threat was posted via Tor, how did they know it was posted by someone on their campus network? The timing could have been conincedental. Even if he was the only person online on campus at the time, it proves nothing.
- borski 5y agoYes, but the confession that ensued after they told him he was the only one using Tor proved everything. :)