12 ms·
How to Start an Anonymous Blog
- 1angryhacker 13y agogot you! Mr Lewis A Jackson!
- christiangenco 13y agoHah, I was thinking the exact same thing. Hopefully he didn't mess up the easiest part.
- lewisajackson 13y agoIt wasn't me haha, I just found the article interesting
- oskarth 13y agoMore relevant: where did you find the article?
- lewisajackson 13y agoReddit. Bitcoin subreddit. http://www.reddit.com/r/Bitcoin/comments/1wd0wx/how_bitcoin_helped_me_start_a_completely/ http://www.reddit.com/r/Bitcoin/comments/1wd0wx/how_bitcoin_...
- taybin 13y agoWhat is this a reference to?
- jdmitch 13y ago> One problem is that Google can see my original messages, and the NSA can probably see them too. If I wanted to avoid it, I could post some anonymous translation jobs and pay the translaters via Bitcoin. Wouldn't this then make it almost trivial for Google or the NSA to find you with textual analysis by matching what is pasted in translate with any other writing sample you've done? So the OP isn't really concerned about anonymity from Google or NSA at all... amiright?
- bo1024 13y agoI don't think identifying someone via textual analysis of a few hundred words is "almost trivial". In fact it seems really, really difficult...suppose your were the NSA and had obtained this sample from Google. Where would you start?
- grecy 13y agoI'd ask Google what the IP address was that accessed the analytic page
- af3 13y agowhy not just post to github pages with github.io domain?
- christiangenco 13y agoThis is fascinating, and rather scary that it's this hard to publish something on the internet anonymously, and not even be guaranteed that the NSA couldn't find you if they really wanted to.
- thomasfromcdnjs 13y agoAre you sure you didn't leave your feedburner url in the index source. http://feeds.feedburner.com/turkeltaub http://feeds.feedburner.com/turkeltaub Which leads to https://twitter.com/ethnt https://twitter.com/ethnt (Web Developer and Computer Science Student) Which leads to the homepage of http://ethnt.me/profile/ http://ethnt.me/profile/ Who doesn't design website templates. Edit: It is wrong, Github search finds the `turkeltaub` https://github.com/search?o=desc&q=turkeltaub&ref=searchresults&s=indexed&type=Code https://github.com/search?o=desc&q=turkeltaub&ref=searchresu... Though here is the github repo link https://github.com/untraceableblog/untraceableblog.github.io/commits/master https://github.com/untraceableblog/untraceableblog.github.io...
- taybin 13y agoThat is hilarious, and also sad. As in, sad that someone can be so confident but also wrong about their secrecy. Imagine how bad it is for non-technical people with actual things to hide.
- 0x0 13y agoYou might be on to something, at least both domains are using the same registrar and whois privacy protection service. Edit: Here is the ssh pubkey: https://github.com/untraceableblog.keys https://github.com/untraceableblog.keys
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- untraceableblog 13y agoYep, that's my SSH public key. And here's my PGP public key: https://gist.github.com/untraceableblog/8683769 https://gist.github.com/untraceableblog/8683769
- dangrossman 13y agoNo, you haven't found him, the blog is using an open source theme and that theme contains the commented out feedburner URL. The repo: https://github.com/elisehein/Pageturner https://github.com/elisehein/Pageturner The file that URL comes from: https://github.com/elisehein/Pageturner/blob/master/source/_layouts/default.html https://github.com/elisehein/Pageturner/blob/master/source/_... Theme demo: http://www.fivetonine.eu/ http://www.fivetonine.eu/
- cik 13y agoIt's definitely an interesting case. There's a general problem online nowadays, of enabling people to host truly anonymous information - allowing them to be free to protest. Personally, I hope his/her posting sparks a conversation about internet anonymity, or the lack thereof.
- diminoten 13y agoProtest where? There are no public grounds on the Internet. Even if there were, there aren't any public ways to get to those public grounds.
- taybin 13y agoThe hidden encrypted partition might make things worse for everyone: https://defuse.ca/truecrypt-plausible-deniability-useless-by-game-theory.htm https://defuse.ca/truecrypt-plausible-deniability-useless-by... They'll just keep hitting you with the wrench until you give them the second password. Sucks if you don't actually have a second encrypted partition.
- leobelle 13y agoDoes Truecrypt have the capability to provide a password that ruins the secret? You could give your tormentors a password that once used deletes or makes the protected content permanently inaccessible and yeah they'll still beat you to death, but now they can never have what they wanted from you.
- kordless 13y agoOr alternately, unencrypts only portions of the drive leaving the rest hidden.
- im3w1l 13y agoWhile such a scheme would be possible using quantum cryptography, it is not possible with truecrypt, no.
- misnome 13y agoNo, only if they then put a load of files into the opened partition. Which would be stupid. You can't have this sort of thing because it is easily circumvented by opening the encrypted volume on a read-only disk.
- uptown 13y agoIf you're referencing a CDN for your javascript, chances are somebody at your CDN provider can match your identity up against other data. For instance, since he's serving jquery from a Google CDN, couldn't Google match the call to load JQuery from an administrative page on his blog with an IP address to his GMail account (assuming he has one)?
- leobelle 13y agoNo that wouldn't work at all. You could thwart this just with an incognito browser and plugins disabled.
- uptown 13y agoHow does an incognito browser hide your IP address?
- leobelle 13y agoI thought tor was assumed. I meant with an incognito/private browser while using tor.
- uptown 13y agoWhat about your browser's "signature"? I know this tool's veracity has been debated, but your web browser is still very "leaky" even in incognito mode. https://panopticlick.eff.org/ https://panopticlick.eff.org/
- spindritf 13y agoIt's a static blog so I'm guessing no administrative page? Either way, when interacting with the blog, he uses Tails which means all outside connections go through Tor. And he explicitly writes about not creating a GMail account because Google requires phone verification. But even if they did all that, they'd learn that the author of Untraceableblog.com uses Tor which is what he wrote he does.
- deleted 13y ago
- pornel 13y agoBitcoin blockchain is public and can be partially de-anonymized. Everybody will see addresses where you spend your donated bitcoins: http://blockchain.info/address/1NkM7WekyZe6KoHYoyWX8s2YZXZjU2bhHy http://blockchain.info/address/1NkM7WekyZe6KoHYoyWX8s2YZXZjU... Similarly anybody who receives bitcoins spent by IT Itch will be able to see addresses where they got bitcoins from, and that may include bitcoin address of the person you bought bitcoins from. I guess that mass blockchain de-anonimization may be a big business (or NSA side-project) in the future, so I suggest "laundering" bitcoins for anonymity too (find somebody who will swap wallets with you, so you get coins with completely irrelevant history and no trace of that swap in the blockchain).
- leobelle 13y agoAs he said in the post he got his bitcoins face to face. Unless the person he met knew him, knowing the blockchain is useless.
- dllthomas 13y agoYou are never leaking less than you think. There is information in the bitcoin chain. It is not likely to be useful without pairing it with other information (and there are ways to make that harder), but I'd be more than hesitant to say "useless" - and certainly leery of betting my freedom or significant amounts of my privacy on it. That said, it is clearly better against at least some threats than other available payment systems, in terms of anonymity.
- zwily 13y agoFor that side of the transaction, sure. But one day he'll probably move those coins around, and he'll have to be careful not to be traced there too.
- vitalique 13y ago>find somebody who will swap wallets with you, so you get coins with completely irrelevant history and no trace of that swap in the blockchain Or use a BTC mixer.
- lispsil 13y agoproblem is your local isp sees you using Tor, so have to run tails in a VM and on the host tunnel all traffic through Jondo or something.
- icebraining 13y agoLots of people use Tor, that doesn't tell them much.
- steven2012 13y agoThe student who made a fake bomb threat at Harvard was tracked down because he used Tor on campus.
- endianswap 13y agoHe was what, one of six who was using Tor at the time and cracked almost instantly when questioned.
- Crito 13y agoOne of six is pretty damn good, and that is before you even consider other factors (such as, how many of those six had a final in one of those buildings at that time.)
- MichaelGG 13y agoThat was a lucky guess on Harvard/Police's part. If his local ISP suspected the admin of the blog was on their network (why would they?) then Tor access might help narrow down. Just like if you're the only person in a country using Tor, writing about stuff internal to that country, yeah, they might notice. In the Harvard case, as far as we know, they went to everyone running Tor and this kid freaked out immediately and it was case closed. If he has insisted on his rights and not talked about it, or provided another plausible reason (assuming he didn't leave evidence on his computer), they'd have had no solid leads. Or if he had used another network that wasn't Harvard's.
- mapmeld 13y ago> if I wrote a series of blog posts in the coming years, you could maybe analyize timestamps to determine my time zone. However, the compiled site shows only the date When I set up a pseudonym GitHub, I was shocked to find a script that linked the two accounts. The first giveaway is using the same languages. Not as much of a problem with a blog. The second was commit patterns and timestamps. This is the blog's commits, where you can find an e-mail and timestamps: https://github.com/untraceableblog/untraceableblog.github.io/commits/master https://github.com/untraceableblog/untraceableblog.github.io... You know the timestamps are accurate because Tor needs a valid system clock to keep a good connection. Solution: I developed a gem 'GitFog' to randomly backdate my commits up to 48 hours in the past. More about that here: https://github.com/msjoinder/gitfog/ https://github.com/msjoinder/gitfog/
- icebraining 13y agoYou know the timestamps are accurate because Tor needs a valid system clock to keep a good connection. No, you suspect they're accurate, but you have no way of knowing whether the author was connected to Tor when the commits were made. That said, GitFog sounds like a useful tool!
- deleted 13y ago[deleted]
- Blahah 13y agoI came here to say basically the same thing. If the author uses your gem, the timezone/active timeperiod identification route is greatly lessened. I actually think the combination of a custom domain and Github makes it much more likely he'll be discovered. Buying a domain means transacting bitcoin, which as others have pointed out, is not foolproof. And Github actually provide plots which make estimating the timezone easy... https://github.com/untraceableblog/untraceableblog.github.io/graphs/punch-card https://github.com/untraceableblog/untraceableblog.github.io...
- mattcwilson 13y agoIs the "ref" portion of the Amazon url for the USB drive traceable? If so, it's also found on this forum, posted by "turk", in reference to a different USB drive make/model. http://www.nsaneforums.com/topic/198758-usb-flash-drive-suggestions/ http://www.nsaneforums.com/topic/198758-usb-flash-drive-sugg... (Looks like the comment was edited to use a different link, but the original was quoted in the next comment down)
- martinml 13y agoYou're probably thinking of "tag". The "ref" parameter doesn't have anything to do with Amazon's affiliate program (which is what I understand you're talking about).
- mattcwilson 13y agoYup. zgbs is the correlator for "Best Sellers", and 3151491 seems to be thumb drives. http://www.amazon.com/Best-Sellers-Electronics-USB-Flash-Drives/zgbs/electronics/3151491 http://www.amazon.com/Best-Sellers-Electronics-USB-Flash-Dri...
- mrfusion 13y agoWould it be better to use namecoin for the domain name?
- ktorn 13y agoProbably, and since untraceableblog.bit already points to his host's IP address, all that's needed is for him to configure that domain on the github side (and probably also untraceableblog.bit.pe for folks without .bit resolution).
- mrfusion 13y agoWhat does the .bit.pe address do?
- ktorn 13y agoIt's just a proxy for the .bit domain since most users cannot access .bit sites directly (not yet anyway). For example, if you cannot access http://explorer.bit http://explorer.bit then you can just add .pe to the URL and access http://explorer.bit.pe http://explorer.bit.pe
- deleted 13y ago[deleted]
- gesman 13y agoToo complicated. Just search for hosting companies that offer free plans with basic wordpress hosting. Then use Tor to register and manage it. The only catch - you'd have to use their domain, like: yournickname.hostercompany.com But who cares - you can get your free, fully anon place to throw up :)
- fchollet 13y agoThe author of the 2008 Bitcoin whitepaper was identified through textual analysis of his writing. JK Rowling was also identified as the author of a pseudonymously published novel using the same methods. One important step towards real anonymity would to completely anonymize your writing style. Make sure the distribution of stop words in your writing is absolutely banal. Make sure to not use your favorite expressions, that can be found in your previous writing. Etc. Algorithmically measure your style before posting, and make sure it is non-identifiable.
- brubaker 13y ago"2008 Bitcoin whitepaper was identified through textual analysis" Maybe. That is up for debate. While interesting, JK Rowling is a bit of an edge case.
- logicallee 13y agoI don't think that your suggestions are reasonable. The most memorable phrases we use are also linked to our understanding of certain specific concepts, on a quite personal level. Essentially, you would be forced to generalize everything, and could be left only writing banal youtube-style comments rather than anything reflecting your best attempt at getting your thoughts down. At that rate, why bother writing? I think better protection is simply not to publish much under any alias. If there isn't a large body of text, an alias writing a few thoughts on one or two issues can't really be mined.
- EddieB 13y agoThe author briefly touches upon this under the section 'Word and character frequency analysis', but I'm not sure this would really help with writing style?
- fnsa 13y ago"The author of the 2008 Bitcoin whitepaper was identified through textual analysis of his writing." wait, what?
- shawabawa3 13y ago
- deleted 13y ago[deleted]
- malka 13y agoI think you could run through translation software (like english -> french -> english) in order to 'anonymise' your style. You'd still have to correct where the translator went wrong (which could leak some informations on your style), and the writing style would be akward, but it should protect you from textual analysis I guess. EDIT : well, there is a section about it in the post. That will learn me to read the comment first ;)
- mcherm 13y agoDid you read the article? He claims to have run it through a translator to and from a few languages to protect against this.
- deleted 13y ago[deleted]
- pilif 13y agoWhile OPs reasoning is sound (though the question of tracing how they spend their donations still remains open), the thing is that however well you started, you don't even get afforded one single mistake you can make. No matter how small the mistake, if you made it, the cat is out of the bag and you're screwed. No matter whether you notice and correct it - in light of the current spying climate, you can be certain that your mistake was logged somewhere. There's so many things to keep in mind in order to avoid mistakes, I can't even imagine them all. Misconfigured your browser to not use tor when posting? Sending the bitcoins donated to you to somebody who gets compromised later? Disconnecting from tor without first logging out of StatCounter and then checking your stats? Plugging your USB-stick into a machine infected with some BIOS malware? The possibilities are endless and you don't get even a single "extra life" (to use a gaming term). Screw up only once and you're screwed forever. It's kinda like software security: It has to be perfect. Even if it's mostly perfect and only one single vulnerability exists and is known, you're as screwed as if your software was open like a sieve. The days of anonymity on the internet are over. Yes, you can build sufficiently high hurdles to guard against most people, but those that really want to know, will know in time.
- theboss 13y agoTl;Dr. OpSec is hard. Like really hard. So hard you'll mess it up given enough chances.
- untraceableblog 13y agoThat's what really excited me about this challenge. I heard about how DPR got caught from a StackOverflow login, and I wanted to see how difficult it would be to maintain anonymity. It turns out that it's really fucking difficult. Also, it kind of sucks that I couldn't talk to any of my coworkers about being on the front page of Hacker News!
- mrspeaker 13y agoSo it's simple... Don't screw up and the days of anonymity on the internet are not over. The fact that it's possible should make us all happy: now we have a very low-level techy-only solution to anonymity. Like all low-level techy-only solutions, this can be built upon to make more general-purpose solutions and hey-presto - we're back in the game!
- lewisajackson 13y agoGoogling "untraceableblog" shows there is a tumblr with the same name: http://untraceableblog.tumblr.com/ http://untraceableblog.tumblr.com/ Whilst this may be nothing and I'm sure he/she wouldn't leave a trail like this, I thought it worth noting. This tumblr user has gone out of their recently to delete all of their past posts (even those made last month) and leave just one.
- gesman 13y agoPS: I agree with blockchain bummer - it's actually much harder to anonymize the fact of your bitcoin ownership and much easier to trace illicit bitcoin purchase back to you, than most people think.
- steven2012 13y agoI would probably try to track down the bitcoin used to purchase the URL. It might be anonymous to buy, but certainly the seller might not be as careful as the blog author. If the seller could be tracked down, then you would have a good idea of which city the person lived in. Then, if you really cared, you could set up malicious Tor nodes in hopes of getting traffic from that particular user. I only have a superficial knowledge of the Tor protocol, but I imagine if you set up a malicious first Tor node (a node that takes the initial incoming request from a Tor browser), you could track all the IP addresses, and mark any of them coming from that particular city. You wouldn't know what the person was seeing, but I imagine you could tell if there was activity on that particular IP address. From there, you could do some sort of analysis on the blog, and see if any updates correlate to traffic you see from that city based in the IP addresses that had activity at that particular time. Since the US has about 400k users in total, I would harbor a guess that maybe the top city might have 100k users max, and then if you could whittle down based on time, you should be able to narrow it down to 100 users. Then you start knocking on doors. The luxury organizations like the government have is that they can take their time and wait for you to make a mistake.
- mapleoin 13y agoYeah, maybe he should buy the BTC when vacationing in Venezuela.
- kalleth 13y agoForgive me for being potentially obvious, but can't you trace every single bitcoin transaction ever? So you can go from: Domain seller -> "Anonymous persons bitcoin address" -> Bitcoin address of the person who sold him those BTC. You then find that person (as i'm pretty sure they're not so focused on anonymity) and wrench-attack a description of this guy and location + time of the meet from him (and also the e-mail he sent to arrange it -- tone, etc). CCTV camera footage of the meet/people in that area at the time, etc. Home and dry.
- mr_luc 13y agoNot if he uses a mixer to pay you the bitcoins, no. Blockchain.info has a fantastic almost-free one.
- rikkus 13y agoDave's always doing this, and he always gets uncovered. Knock it off, Dave.
- vrikis 13y agoAren't the NSA a huge investor in TOR? ... I get what OP is trying to do, but in reality, since you're still using other people's pipes and fibre, you will never reach true anonymity, no matter what you try...
- debt 13y agoAnother idea would be to start a service which accepts blog posts through snail mail. The service asks that you add a unique string of numbers and letters to identify youself to the service. Someone on the other simply ocr's your blog post letter and posts it under the requested pseudonym which also matches the secret unique identifier. It's a simple username/password authentication via mail in each post. Just dont add a return address and you're solid.
- GigabyteCoin 13y agoThe fact that he admits to providing false domain registration information on a .com domain is enough to have his domain revoked by ICANN if I am not mistaken.
- leoplct 13y agoYour username on HN is not so anonymous, Jackson Lewis.
- galapago 13y agoAt least, his email is visible in every commit: > untraceableblog@outlook.com
- kzsee3 13y agowhy not a 2 part blog - accept scanned or mailed in documents. Scan it in and post as blog. Now you will be truly anonymous.
- snowwrestler 13y agoHere's how I'd improve the security. 1) Forget USB drives, they are a nightmare. In fact, forget any writable medium. Get an old laptop and take out the HD. Boot it from a live CD. Use only this machine to edit your blog. 2) Make your passwords complex and write them down on a piece of paper hidden somewhere. Don't host them in any digital form anywhere. You're much more likely to screw up the digital stuff than get pipe-wrenched. 3) Forget bitcoin or any other funding mechanism. Just pay for your computer yourself and use a free blog hosting company. Don't buy a domain, just use domain.wordpress.com or whatever. Don't let money touch the blog at all ever. 4) Don't collect stats on your blog. What do you need them for? 5) Do all your posting from public WiFi points like coffee shops. (Buy your coffee with cash.) To go deeper, consider the pattern of your traceable activities. Don't deny who you obviously are. For instance if you see one of your blog posts on Reddit, HN, Facebook, etc., click through and read it from your regular computer. After all it is probably a topic that you're demonstrably interested in, and the point is to pretend that you've never seen that post before.
- lifeformed 13y agoWouldn't #5 let attackers narrow you down to your city?
- jsnk 13y agoThis is probably where Tor would come in handy. Onion route to somewhere in Thailand or somewhere.
- snowwrestler 13y agoYup, I did not mean to exclude Tor with my suggestions above.
- falcolas 13y agoI'd amend 5 to use a Pringles wifi antenna, so you don't even have to go in the shop to use their wifi. 1, 2, 3 agree absolutely. As popular as computers are becoming, just keeping data in a physical form makes it a less obvious target, and easier to hide/dispose of.
- ronaldx 13y ago> counter this by running all my posts through Google Translate. This is smart, except... Google presumably records your translations, likely linking them with your Google account (and - even if not - could easily look up which translations led to your blog). So, textual analysis is not quite dead, and you may have given away your anonymity by taking this measure.
- Sir_Cmpwn 13y agoWhat if, instead, you limited yourself to some number of the most common English words?
- tbirdz 13y agoOne idea might be to spell check your writing using a modified English (simple) dictionary. This modified dictionary would only contain the most common and simplest english word, allowing you to easily prune out words that would reveal your fluency in the language.
- pg_is_a_butt 13y agohis name is lewisajackson... duh.
- elchief 13y agoI hope you bought your laptop with cash, far away from home.
- ta223 13y agoHere's how I'd trace him: 1) get access to the request logs of third-party includes on his page 2) look for requests made just before the page is published publicly
- untraceableblog 13y agoAll requests are made through Tor. The Tails OS is configured to allow absolutely nothing through the clear internet.
- elwell 13y agoUnless your name actually is Lewis A. Jackson
- lowglow 13y agoI tried building something similar with http://valleyanon.com/ http://valleyanon.com/ but for whatever reason, it never caught on. I don't know if people _really_ care about anonymity enough to consider it as a separate service.
- stevedekorte 13y agohttp://www.darklogs.com http://www.darklogs.com which uses bitmessage may be a significantly safer anonymous blogging service.
- ChrisNorstrom 13y agoQuestion 1): What's the difference between using Tor and http://www.hidemyass.com/proxy/ http://www.hidemyass.com/proxy/ 's Pro VPN option? Question 2): Can't you buy a domain name and hosting using https://www.nearlyfreespeech.net/about/mailing https://www.nearlyfreespeech.net/about/mailing and mailing in an anonymous cashier's check / postal money order? Question 3): Why not just (using Tor/VPN/Proxy) sign up for a Tumblr or Wordpress Blog anonymously and only logging in or editing the blog when using Tor/Proxy/VPN? Where there is a need and a poor solution, there is an opportunity for a startup. Anyone want to join up and contemplate starting "TABlog" Truly Anonymous Blogging platform?
- untraceableblog 13y ago1) Trust. I trust the Tor developers and nodes much more than HideMyAss, which is a single point of failure. 2) Looks like a good suggestion, I'll have to check that out if I ever start a Tor hidden service. 3) The main factors are having control over the HTML, and differentiating the site from just another wordpress blog. Anyone can start a Wordpress blog using Tor, and that wouldn't make a very interesting blog post. This was done mostly as an excercise and experiment. If the goal were just to publish sensitive articles, I would use a free blogging platform.
- arthurcolle 13y agoI can't imagine that using Microsoft's outlook.com email service is the best avenue to anonymize one's blog posts.
- untraceableblog 13y agoInterestingly enough, outlook.com is the only free email service that let me sign up over Tor. I access it securely, and it's just for verification purposes. Every service needs an email address.
- deleted 13y ago[deleted]
- diminoten 13y agoGuy's European, possibly British. Random guess based on "couldn't be fucked" and "you might have assumed that English was my second language". Also, the guy the author met could ID the author.
- joshfraser 13y agoThe key things I would add are: - buy a new laptop that has never been used to sign into any services that know your true identity - get rid of the camera and microphone - never connect to the internet from your own network or locations you frequent - rotate randomly through public wifi spots and use a long range wifi antenna whenever possible - obsessively monitor your network traffic so you know if your true IP is ever compromised so you can change your behavior in time
- davidbates 13y agoJason, I know its you.
- Stef911 13y agowhois 185.31.17.133 % This is the RIPE Database query service. % The objects are in RPSL format. % % The RIPE Database is subject to Terms and Conditions. % See http://www.ripe.net/db/support/db-terms-conditions.pdf http://www.ripe.net/db/support/db-terms-conditions.pdf % Note: this output has been filtered. % To receive output for a database update, use the "-B" flag. % Information related to '185.31.17.0 - 185.31.17.255' % Abuse contact for '185.31.17.0 - 185.31.17.255' is 'abuse@fastly.com' inetnum: 185.31.17.0 - 185.31.17.255 netname: FASTLY-EU-IPV4-2 descr: Fastly Frankfurt 1 Operations country: de admin-c: AB28187-RIPE tech-c: AB28187-RIPE status: ASSIGNED PA mnt-by: FASTLY source: RIPE # Filtered person: Artur Bergman address: 501 Folsom St. address: San Francisco CA phone: +1.415.568.8829 nic-hdl: AB28187-RIPE mnt-by: FASTLY source: RIPE # Filtered % This query was served by the RIPE Database Query Service version 1.70.1 (WHOIS1)