5 ms·
I'm impressed by the skill that goes into this but it doesn't seem like an even-handed technology -- it empowers governments, major corporations, and other larg
by dstorrs 15y ago
I'm impressed by the skill that goes into this but it doesn't seem like an even-handed technology -- it empowers governments, major corporations, and other large organizations more than it does private individuals.
As a specific example, people writing political blogs in China could be seriously harmed by this technique even at the levels that it's at now.
I applaud you for including the link to "manually changing your writing style will defeat these attacks" but that's a link to an academic paper. Could you please also write some good, layperson-oriented docs on "how to beat this"? For that matter, I'll do the writing grunt work if you'll provide the expertise. If you're interested, use the GMail address in my profile.
- Jach 15y agoI'd also be interested in what anonymizing techniques come from this, but the way to specifically beat the Chinese government here is to carefully guard the border between your online presence and your offline government-issued identity. At minimal this means anyone in China should be encrypting everything before it leaves their machine and goes to the network through a connection with their name on it, and if they're in the business of writing anti-China political blogs, they need to treat everything they do publicly as a threat to their identity. You can't expect to carelessly leak your identity today and try to hide it tomorrow. You either don't leak your identity at all or what you're trying to keep anonymous has to be so low-bit in information content that it's probably worthless because it would be like everything else.
- gtani 15y agohttp://news.ycombinator.com/item?id=3582490 http://news.ycombinator.com/item?id=3582490
- randomwalker 15y agoThat's a good question. First, I believe that intelligence agencies are already well aware of the potential of technology like this, and at least some, like the NSA, could very well be ahead of public research. Second, research such as ours is intended to demonstrate a proof of concept, and it takes a lot of work to turn it into a reliable tool — for example, we restrict ourselves to English text. For those two reasons, I think our work does little to directly help governments and other oppressive entities. On the other hand, publicly available research is effective (we hope) in raising awareness of the threat, so on balance it does more good than harm to people writing political blogs. As for practical tips to defeat stylometry and such, organizations like the EFF specialize in doing that, so I will leave that to them. Comparative advantage, etc. If you would like to help, you are more than welcome.
- bediger 15y agocould very well be ahead of public research - does that mean you've had meetings with groups of 3 federal employees, one of whom does nothing but ensure the other 2 don't say too much? You know, like the feds that visited IBM to make DES more resistant to differential cryptanalysis (http://en.wikipedia.org/wiki/Data_Encryption_Standard#NSA.27s_involvement_in_the_design http://en.wikipedia.org/wiki/Data_Encryption_Standard#NSA.27...)?
- gyardley 15y agoResearchers at Drexel have released some software to help subvert stylometry - see 'Anonymouth', linked from here: https://psal.cs.drexel.edu/index.php/Main_Page https://psal.cs.drexel.edu/index.php/Main_Page There's an interesting presentation here: http://events.ccc.de/congress/2011/Fahrplan/attachments/2019_28C3-authorship.pdf http://events.ccc.de/congress/2011/Fahrplan/attachments/2019... I'd be interested in seeing more tools in this vein. I already know that if I want to camouflage my writing, I have to cut way down on the dashes, but it'd be neat to upload a few large documents and see a nice list of the top ten traits that could be used to identify me.
- nodata 15y agoAnonymouth is way too complicated for an above-average user to use.
- derrida 15y agoI attended 28c3 and from memory there was a tool called JStylo for discovering authorship and Anonymouth for defeating authorship recognition. Check the Chaos Computer Club site.
- dhx 15y agoThe technology must be assumed to exist as there is plenty of commercial incentive to develop and use the technology. A threat model that fails to account for future advances in technology vs. expected period of protection is unacceptable. Making this technology available and easily accessible for widespread public use encourages development of counter-authorship-detection techniques. If tools are available that allow authors to easily assume the identity of other people (through morphing of writing styles), this technology rapidly loses value.