10 ms·
How I stay reasonably anonymous online (2022)
- CollinEMac 3y ago> I usually delete comments, threads, or other content I put up on the internet after it has served its purpose. That means for example deleting my Reddit comments after a month or two, keeping my email inbox near empty (in case it gets hacked), deleting old accounts, and similar things. This seems a bit extreme to me.
- SamuelAdams 3y agoWhy keep things around that serve no purpose? Companies have retention policies for this reason - anything that is retained is a potential liability, so unless it’s legally required it’s better to delete and destroy as soon as it is not needed.
- mortureb 3y agoThey serve a purpose. You may never have as many eyes on it besides the few days after it was posted but it breaks a lot of historical conversation, especially on sites with useful information/solutions.
- add-sub-mul-div 3y agoThe sooner the public loses faith in Reddit and Twitter, the better. Making their archives seem deserted or abandoned helps. I was not going to leave over a decade's worth of my content on those sites to benefit them.
- beaviskhan 3y agoDeleting comments, ugh, please don't do this :( If you must, make a throwaway account instead. It sucks to find a thread that promises to solve a problem you have, but when you go there critical context is missing due to deleted comments.
- notfed 3y agoLooking at you, Reddit...
- whimsicalism 3y agostylometry is far too strong
- caminante 3y agoDeleting protects you against stylometry (and further identity detection)? Ha! Wishful thinking with all of the auto-archivers. If you post on reddit, it's likely already crawled and archived somewhere.
- whimsicalism 3y agoIt is not great, but it is better (if you wish to not be identified) to keep it in fewer perhaps non-public or poorly indexed archives. The internet does forget, sometimes.
- nickstinemates 3y agoThat the internet never forgets is a myth. It forgets surprisingly quickly and I think will only accelerate. Sure, someone may have a copy of something somewhere, but discovering it via any search engine is impossible. Personally I put a lot of PHP and VB code out ~20 years ago that I could find easily until I couldn't. There's Myspace profiles I've tried to pull up, images posted by friends 15 years ago in random places. Early video. All gone.
- ghaff 3y agoI generally agree. It depends how Internet famous you were, how hard a person looks, how common your name is, whether there's something specific you're looking for about a person. But, yeah, I'm willing to bet that a lot of random casual searches wouldn't turn up some Internet scandal/controversy around a non-famous person unless you really knew what to look for.
- SirMaster 3y agoJust use a name and username of someone else that's well known enough. Not like famous, but someone that shows up in enough search results. So that if someone tries to search about you, they are buried in all the noise and data of the other person.
- lagniappe 3y agoOr take it one step further and use a PURDAH https://www.reddit.com/r/nealstephenson/comments/czw5og/fall_or_dodge_in_hell_question_on_the/ez4ahkx/ https://www.reddit.com/r/nealstephenson/comments/czw5og/fall...
- WithinReason 3y agoYou mean the pre-election period in the United Kingdom between the announcement of an election and the formation of the new elected government? Or a religious and social practice of female seclusion prevalent among some Muslim and Hindu communities?
- lagniappe 3y agono, that's not what I mean.
- WithinReason 3y agoWhat did you mean?
- ghaff 3y agoThat's sort of security by obscurity though. As soon as someone gets a few IRL data points, anonymity can break down pretty quickly. Personally I mostly don't bother and will use a throwaway if I really feel compelled to post some comment I wouldn't want to be linked to me. (I know even that isn't foolproof but the threat model is mostly not wanting a statement attributed to me professionally--not hiding a crime.)
- notfed 3y agoAnother tip: for online purchases, use privacy.com virtual credit cards. (Did you know when you use PayPal, sites can see your email, name and address?)
- brewdad 3y agoI kind of want the site to have my name and address so they know where to send my goods. Of course, for digital purchases, your point is completely valid.
- yomlica8 3y agoAre you saying that privacy.com also creates fake names and addresses for the purpose of charging? I always assumed it was just another number in your name. (never used this service, but it does seem useful)
- notfed 3y agoYou can type any name or address and privacy.com will accept the transaction. Security rests more on pausing/resuming cards, locking them to vendors, or setting price limits.
- mmh0000 3y agoWell, yes. How else will they mail the <useless junk> you ordered to you? It does annoy me that paypay doesn't let me enter custom email addresses to give the merchant. I've had to change my paypal email address several times now due to stores selling it to spammers.
- ranger_danger 3y agoI haven't seen spam in decades. What are you doing wrong?
- mmh0000 3y agoShopping at scummy web stores that accept PayPal.
- mandeepj 3y agoBesides that, make sure - your systems are not hackable (at least not easily). Use firewall, proxy server, vpn, or something like that. Is your phone trackable with something like Pegasus? Although, an average Steve does not have to worry about that.
- AlbertCory 3y ago> Temporary credit cards With privacy.com, Revolut, Klarna, and similar services one can generate virtual credit cards. This is mostly for when you don't trust the website owner or the payment provider. There are other reasons, unless you construe "trust" very broadly. Services that make it unreasonably difficult to cancel your account: you just cancel their credit card (and of course stop using the service). You can also force an annual renewal, to prevent them from automatically renewing you. And lastly, you can set a dollar limit on it, to avoid mistakes and "automatic" increases.
- jonahx 3y ago> you just cancel their credit card (and of course stop using the service). IANAL, but I have always heard that when you do this you have not broken the legal contract obligating your payment. In practice, especially for modestly priced services, the strategy will usually work. But in theory they could come after you legally for the money if you do this. It might be a real concern for very expensive services. I would like to have this confirmed by a lawyer, though.
- AlbertCory 3y agoThis always comes up when I mention privacy.com. It's always a theoretical possibility. No one's ever shown a case where that actually happened (and it's never happened to me). People also say, "oh, but they'll ruin your credit rating." You couple the card cancellation with a message to them demanding they cancel your account. Just imagine a credit card collection company agreeing to come after you, when you made a good faith attempt to close the account.
- sudobash1 3y ago> Just imagine a credit card collection company agreeing to come after you, when you made a good faith attempt to close the account. Given the practices detailed here, I could very easily imagine it. https://news.ycombinator.com/item?id=37490241 https://news.ycombinator.com/item?id=37490241
- jkubicek 3y agoI do most of the same things. My "randomized emails" all use my personal domain, so it's trivial for people who have access to the email to know it's me, but probably not trivial for dumb ad networks to link my accounts back to me. The one bit of leaked identity that really bugs me is my phone number. So many services require a phone number for text notifications and 2-factor auth and there's not good way (that I know of) to generate a random phone number that still works.
- ZeWaka 3y agoGoogle Voice?
- lazycouchpotato 3y agoMost services can detect and block VOIP numbers like Google Voice.
- brewdad 3y agoI've had my number with GV for years and get plenty of SMS delivered and sent, even with services where I never explicitly asked to use SMS as a 2FA or a method of contact. I guess my service providers don't care enough to block it.
- lazycouchpotato 3y agoDid you get the number from GV, or port into GV from a standard carrier? If the former, then you're the first one I've come across who's able to do so. Facebook/Google/Twitter/Microsoft etc. all block VOIP numbers. The providers you use probably aren't hit with enough malicious activity for them to care about it.
- ehaughee 3y agoFirefox Relay offers "randomized" phone numbers along with its emails: https://relay.firefox.com https://relay.firefox.com
- ta8645 3y agoIt's amazing how quickly 4chan often doxes someone who believes they are operating online anonymously. I think most of us remain anonymous online, only because nobody cares enough to figure out who we are.
- deleted 3y ago[deleted]
- mortureb 3y agoThey way 4chan normally doxes are pretty much thwarted by the basic methods mentioned here. 99% of the time it’s to trace the same username/email address across sites and link that to a person aggregator or Facebook/LinkedIn.
- deleted 3y ago[deleted]
- hn_throwaway_99 3y agoI think this can lull people into a false sense of security, and I don't think the author realizes how easy and powerful stylometrics is. E.g. the author says this: > Spelling/grammar/phrasing > If there are words you often misspell, people can Google it to find other sources where you make the same error (if it's uncommon enough) and potentially identify your other accounts. Use spell checking and maybe Grammarly or similar to minimize this risk, but I tend not to worry about this too much. It's not just about misspellings, it's that we all basically leave fingerprints in the way we write.
- ghaff 3y agoYou're not wrong and I assume it will become even more powerful--but it's almost certainly way more effective if you have reason to believe that throwawayxyz is so and so IRL.
- bluefirebrand 3y agoTime to start laundering all of our online posts through GPT I guess.
- bruce343434 3y agoRelevant (the site has since been deleted) Show HN: Using stylometry to find HN users with alternate accounts https://news.ycombinator.com/item?id=33755016 https://news.ycombinator.com/item?id=33755016 (676 points by costco 9 months ago | 519 comments)
- bee_rider 3y agoI wonder if privacy conscious people will eventually start feeding their posts into locally-run LLMs or something, and posting the output. Or better yet, replace social media with LLM’s, instead of reading individual posts you discuss topics with a sort of artificial gestalt average user. Maybe let people “join” a gestalt by tagging their discussions. Then we can let the gestalts argue amongst themselves!
- brantonb 3y agoI assume any anonymous surveys at work that roll up through my management chain aren’t anonymous at all. My manager will get responses from only ~10 people and my writing style will be unique within that small sample size.
- gumby 3y agoPassword managers help a lot. Site asks for a birthdate? Whatever I choose to enter goes in the password manager. My mother's maiden name? I guess I can reveal publicly: it's fgjlh%ngf9, so into the password manager it goes. My password manager offers to generate a password for me; I wish it would offer to generate those other fields as well. Turns out you can fuzz your address too when validating a credit card. Autofill should handle that.
- PopAlongKid 3y ago>Turns out you can fuzz your address too when validating a credit card. My experience is that only your ZIP code is used, not your street address or city.
- gabereiser 3y agoThere are levels. To authorize usually only billing zip is required. For a full ACH or a “full authorization”, you need the full billing address and name to match name on card. PCI-DSS.
- ranger_danger 3y agoIt depends entirely on the merchant and what checks they have enabled. Some people like authorize.net may even lower your fees/bills if you require stricter address verification for example.
- camgunz 3y ago> My mother's maiden name? I guess I can reveal publicly: it's fgjlh%ngf9, so into the password manager it goes. Echoing: never actually answer security questions. Always treat them as additional (super annoying) passwords.
- jstarfish 3y agoIf you do, at least give them a misleading but coherent response (my first pet: grandma). I've bypassed my own bank's security questions by telling them "the answer to 'my favorite ___' is a bunch of gibberish letters and numbers."
- tennisflyi 3y agoA password manger helps with keeping up with which fake names/DOBs you used if you need to reset the password/recover the account or whatnot.
- jacobwilliamroy 3y agoThe one thing I don't see mentioned in this article is using encrypted DNS. Right now I use firefox on my PC and Opera on my phone because both browsers have a setting to use encrypted DNS. I just turn it on and forget about it. I tend to use a lot of networks other people own and I like making sure my DNS queries are encrypted.
- PopAlongKid 3y agoGetting a commercial mailbox (e.g. UPS Store) in the same zip code as your primary residence can be helpful. I've had one long enough that on my credit report it is listed as an alternate residence address. Whenever I'm asked for an address online, that is usually the one I provide.
- 867-5309 3y agothat serves no purpose in anonymity whatsoever
- jstarfish 3y agoYes it does. It muddies the waters with false positives.
- noman-land 3y agoWouldn't this be a true positive?
- jstarfish 3y agoSemantically speaking, I guess so. It's just a proxy address. Maybe it's you, maybe it's someone else with your name. Who can tell? The point is to not be found. People showing up at any address that isn't your actual home address aligns with that goal. Registering it in the same ZIP code is self-doxxing though. It's an innocuous form of synthetic identity fraud. If you really want to be anonymous, do pre-applications for credit cards and utilities in your name at other people's addresses then abandon them. One case I worked had a guy doing this using AirBNB hosts' addresses. His profile had him supposedly living everywhere all at once. This had the benefit of mapping to actual homes instead of The UPS Store when Googled.
- PrimeMcFly 3y agoThrowaway accounts and fake names for everything as much as possible, as well as a fake address or a paid PO Box if a real one is needed. Not using the same accounts between services, and distorting real details like city. Seems to work pretty well. I'm pretty invisible based on my own research.
- ella-hashir 3y ago1. do not use any extension, believe me they acquire all your browsing history from all tabs, no extension no worry, only use those that have higher users but review their permission 2. use enhances protection this will save you from most of the time. makes sure do not store password on google , write them on paper no social media login from same computer. do not click on any ad and website, especially in email do not use your email to sign up on different sites, use disposable
- biogene 3y agoI don't know to what extent this person goes to hide their legal name, but with public records, its fairly easy to find your residence if you own a home or some other property.
- ilamont 3y agoTor, Tails, surfing from an open WiFi, VPN, encrypted emails, etc These things are usually outside my threat model. Can anyone break this down? If a person were concerned enough to follow all of the steps listed in the article to stay anonymous, why not also use a VPN or Tor as an additional layer that can thwart many types of tracking and provide additional risk mitigation?
- ranger_danger 3y agotor/vpn/proxy by itself does not provide adequate anonymity. creepjs proves that ALL browsers are unique (even TBB) if someone just probes the right bits.
- Bu9818 3y agoI don't disagree with you, except browsing creepjs from Tor Browser it says there have been hundreds of visits with my fingerprint since June (when the 12.5 series was released).
- ranger_danger 3y agocreepjs proves it is absolutely impossible to be anonymous when visiting more than one site from the same browser, regardless of your IP/network/VPN/proxy/etc. Even the Tor Browser doesn't fully mask your OS (javascript functions still return the real thing), making anything but Windows (what the majority uses) impossible to use for any real privacy if you're trying to blend in.
- iteratethis 3y agoThis entire list will soon be obsolete as AI will link all your accounts by just giving it some of your text input. I believe I saw an experiment of somebody doing this for HN content with a pretty high accuracy? Project that idea into the future.