HN user

sweetbitter

192 karma

Anonymity is a treasure.

Posts2
Comments159
View on HN

You could just use onion services to to hide the server, and store some backup onion services (whose private keys are kept offline) within the application or its files. When the server goes down due to seizure, you spin up a new one under the backup service's pubkey, and sign a list of new backup keys which will also be kept offline until the next seizure.

You could also combine encryption with steganography, if you strip non-random 'protocol information' from your encrypted bits. Doing that, it would not be easy to prove that you are sending encrypted messages at all without having obtained your keys.

If you just want to track a few individuals... Enumerate all those who possess the data. Now look for data brokers that they deal with (as commenter korse said) and recurse. Find all the employees of every company in question. Muster a few hundred bucks or so, seems to be the market price, and there you go[0].

For research I dunno. You'd probably have to make a deal directly with one of these companies, one way or another, so I would start by talking to them.

[0] https://www.vice.com/en/article/nepxbz/i-gave-a-bounty-hunte...

It helps to think of it this way, if it touches your phone or the internet in any way, it's part of the public record. No matter what app you were using. So be cognizant of that, it can come back to bite you 10 years later in ways you never would have imagined.

Meh. If that's the case, why bother caring at all? Bring it on!

If you're serious about it, check out this article: https://www.vice.com/en/article/nepxbz/i-gave-a-bounty-hunte...

What you need to do is pick an entity that has the information you desire, and recursively enumerate the graph of all business deals which involve the sale of that information (their downstreams, effectively). After that, you do OSINT to map out all of the employees of every organization that has access to these databases. After you have mapped out these tens of thousands of individuals and their likely social graphs, all you have to do is pay one of them a relatively small sum to do a query on your behalf.

Not quite. The guy who wrote Tor can be clearly seen to have been studying a lot of these things in the later 90s, and it was pretty much always public, but only developed after he got the Navy to get him an NSF grant. Hell, in one slide he had made back then, he was even well-aware of some of the fundamental vulnerabilities in the protocol, and the (still too expensive) mitigations for those flaws, so it can't even be said that anything was concealed.

If we go back further to the original concept of chained anonymous remailers as envisioned by Chaum 40 years ago, it gets even harder to claim something like this.

If someone wants you compromised, you will get compromised, it only matters how many resources they are willing to throw at you.

Wants who compromised? What are they going to do against people who use no pseudonym and never originate from the same machine or the same physical location?

For very obvious reasons you don't need to run any nodes, craft any malware, or scrutinize a target's layer 3+ OPSEC, in order to break Tor. You simply go to tier 1 ISPs and buy up IP datagram headers going to/from entry nodes and you win. The only solution is a constant rate of fake traffic to the guard node.

can just wait for you to make a mistake.

Anyhow, if one slip-up is enough, you're doing it wrong. Imagine you were a mad scientist testing out a jetpack- you are confident yes? But I imagine you would feel more confident with a bunch of nets, and a trampoline underneath that, and a lightning rod in case of a storm, and a requirement that you hold down multiple buttons at once to play with the controls, etc.

That is, if you are serious you will put in multiple safety nets at every layer of the stack so that "one slip" is not enough.

You like to talk to people, but you know that a long-term pseudonym is the gravest danger of them all.

You like virtualization, but you keep some crucial data and keys(treams) on a un-networked machine.

You like anonymizing networks, but you know the caveats of traffic tunneling and didn't connect from your home router.

You connect to a randomly-chosen wireless AP, but you know that just in case your MAC-spoofing fails or you get pwned or something, you are glad that you bought the device with cash and never tied its characteristics to your identity.

You are glad that the only transceiver connected to the device is an external wireless dongle so that when you are done, you don't accidentally connect with your device from home.

You are glad you waited for an overcast day so that you could thwart spy satellites that use visible/infrared light, and that you connected to the AP from afar to thwart cameras.

The list goes on. The guy whose face you see plastered in the news? Yeah, that guy thought his experimental jetpack was the shit. And it was- until it wasn't.

Thanks for the advice. I use synchronous media like chat protocols much more often, and was blind to this- and yep, it does seem like the primary objection to that argument was born out of a flawed understanding of the analogy.

Cryptocurrencies are a qualitatively new thing humanity has never had to deal with ever, no matter how insistent are cryptocurrency aficionados’ in calling it merely “a digital version of cash”. This serves their wallets, by suspending deserved wariness and encouraging unsophisticated people to invest into a financial pyramid, but not truthful description of reality.

Holding no cryptocurrency myself (I don't need to buy anything with it atm :D) I would hardly call myself an 'aficionado'. But you must understand that to compare does not mean to equate. All I was saying is that cryptographic currencies have some of the properties that cash has, but that they also have the ease of transport and storage afforded to us by credit.

I don't see the issue with being able to transport cash across the 'net. Governments can still regulate businesses, banks, so if you go and buy a car and your government wants to know to tax it, the business selling you the car can just report this income. If a bank held your asset for you, they could just be subject to similar regulations as when they hold other assets for you. Once you stop treating it like credit or like some amorphous blob that cannot be regulated, this stuff gets pretty simple to understand.

Kinda sorta. Wasn't that back when people assumed cryptocurrency provided the same kind of privacy that cryptography does, which was (in retrospect), pretty dumb?

Well, there are currencies that do provide strong anonymity, so no?

But yeah agreed that cryptocurrency doesn't have that many use cases, just as cash has a declining number of them. I hope someone makes an Amazon-like platform for it.

The entire purpose of cryptocurrencies are to avoid those things, so while you technically could have them with a cryptocurrency, you would end up with no good reason to have a cryptocurrency at all.

I will substitute a word from your post that will help you understand this easier:

"The entire purpose of cash is to avoid those things, so while you technically could have them with cash, you would end up with no good reason to have cash at all."

Cryptocurrency is not antithetical to banks just like cash and gold are not. It is a digital version of cash, not credit.

Well, you should consider what exactly would be hacked. Banks don't really hold huge amounts of gold or physical cash anymore, most of what they have is 'credit' and debt.

Cryptographic currencies are not credit, they are the gold. They are what gold would be if it were easily divisible and could be transferred anywhere, instantly, for only several cents worth of transaction fees.

Despite how quickly you can transfer cryptocurrencies, you could secure it as well as you physically secure gold if you really wanted to. The problem is that there are a bunch of businesses who are holding peoples' gold for them in such a way that bidirectional channels exist between front-end machines and back-end machines that have the private keys on them, and there is no regulation instructing these wannabe banks to perform cryptographic signatures on airgapped machines. It is as if Fort Knox were just leaving all of its entrances open.

Several kilometers of range seems tolerable with enough collaboration. I do wonder though, whether mesh networks for bidirectional (synchronous) comms are a good idea in hostile environments. It seems too easy to map out the positions of the nodes. Systems that support distrbuted, asynchronous comms and use of wireless protocols on phones seem like a good match for them though.

They seem to be online via Tor, but have temporarily taken down whatever proxy/server their .net domain points to for the last ~week for reasons. It's likely that they will put their stuff back online though. And before that they were online on clearnet for many weeks and thwarting DDoS fine.

I was speculating that the notion of a laser-based mesh network could deserve more attention, if it is economically viable. That seems like a better choice than something like WiFi, because you do not have to share a channel with huge amounts of other devices.

Maybe it is too much data for devices that have to share a channel. But lasers (think: old TV remotes using infrared) do not have to share channels with each other, and can be very high-bandwidth and more difficult to snoop on indeed. Mirrors could even be used for relaying, to save lots of compute. Like fiber cables piercing through the air itself!