HN user

cirosantilli

194 karma

Check out: https://OurBigBook.com I am: https://cirosantilli.com Proof: https://cirosantilli.com/accounts

Posts5
Comments97
View on HN

Could be just some entity that buys websites with good expired domain names to late resell? But yes I don't understand why they are not empty.

Nowadays at least, wonder if they could just pick a few of the most popular unblocked HTTPS websites with a private messaging system a la Twitter DM. Email possibly too. A GitHub private repo would be perfect for that as dictatorships relaly hate to block it and lose all the IT value. Maybe at the time things weren't so simple with less HTTPS adoption.

I suspect the agents knew little about the comms tech and were deeply reassured of their security.

Ah, I didn't implement RSS unfortunately. What you can do now is if you follow a user when they announce an article (there's an announce button), you get an email with a link. I suppose it could be modified to also put announced articles in an RSS feed. I never did much RSS for whatever reason. PRs open :-)

It is hard to balance both aspects. I tried to summarize more interesting things on initial sections and from "Methodology" downwards it is definitely not for casual reading. Also huge images and table, so don't be afraid of the bar.

Thank for the submission! This was also previously posted at: https://news.ycombinator.com/item?id=36279375 from before my recent update that added ~75 new websites with a new technique: https://twitter.com/cirosantilli/status/1717445686214504830

Except the previous one was at: https://cirosantilli.com/cia-2010-covert-communication-websi... which is the corresponding static website version of https://ourbigbook.com/cirosantilli/cia-2010-covert-communic...

I would love to know... even finding the source of those stock photos would be awesome. My initial suspicion is that the image split is just an ancient webdev thing (which they used much after it was popular) to reduce the size of each individual image. But who knows!

Exactly. The best bet is to use a service that is used by a huge number of users and try to hide your traffic in it. I wonder why they didn't do gmail -> gmail for example. Maybe there are good reasons.

I have researched this now.

According to https://tools.whoisxmlapi.com/whois-history-search the domains were registered June 11, 2023, shortly after my article came out.

They are therefore likely just made by wakatime's founder Alan Hamlett: https://www.linkedin.com/in/alanhamlett/ as a bit of Guerrilla Marketing. Fair play.

When I saw on LinkedIn that he worked for a web security contractor until September 2013, I almost flipped. But appears unrelated however unfortunately except for his general interst in WEBSEC, so another dead end.

If anyone has any more precise information on this, do let me know. I do suspect there's some kind of "protocol legel" fingerprint, as I can't find anything in the content that would be searchable so far.

I think it is pretty safe to assume that essentially all opponents are capable. In particular, intelligence is one of the first things dictatorships will invest in, partly to spy on their own people, which the leaders fear above all else.

The ideal communication mechanism is one that blends in with a huge number of other "legitimate" users. E.g. for Tor, it only works if many people are also using Tor for other non-spy things. I wonder why not just email.