#deanonymization

Kevin Karhan :verified:kkarhan@infosec.space
2026-01-05

@b The sherr fact that @signalapp ties stuff to a #PhoneNumber is inherently bad and gives them the same stench as #EncroChat & #ANØM did.

It"s just #deanonymization with a single step in between from demanding "#KYC" with an #ID!

brainwashed by lentilspelle@veganism.social
2025-12-14

@rysiek
> Signal is safe.

#signal has long had issues with phone number leaks: even when set to hidden, phone numbers can sometimes be revealed. 🔓

this means that adversaries can get the phone numbers from an entire network of #signal users from just one compromised device. 🛂

this puts real people in real danger, but #signal is such a strong brand now that many would rather blame those who get hurt than take a critical look at their favourite chat app. ⚠️

more info, including links to some relevant #github issues:
veganism.social/@pelle/1156735

#signal doesn't take the phone number leaks seriously, and it's not clear to me from their replies whether they've fixed it. 🪲

#deltachat / #arcanechat (#decentralized #securityaudited #e2ee chat app) avoids accidentally revealing phone numbers by not asking for them. also, allowing for multiple profiles makes it harder for adversaries to track people across different chats, as opposed to #signal with its one profile per device policy. 👥

if #deanonymization is a risk for you, then #signal is not safe. 🥸

unfortunately i had to experience this first hand, which is why i consider »signal is safe« unhelpful advice. 😐

2025-10-30

#Republican plan would make #deanonymization of #census data trivial

But now, a little-known #algorithmic process called “differential privacy,” created to keep census data from being used to identify individual respondents, has become the right’s latest focus. WIRED spoke to six experts about the #GOP ’s ongoing effort to falsely allege that a system created to protect people’s #privacy has made the data from the 2020 census inaccurate.

arstechnica.com/tech-policy/20

2025-07-29

I get wanting to protect #ICE agents from #doxxing. I also get wanting to ensure #LawEnforcement #LEO can't avoid #accountability by masking. Why not allow masks, but require large print, unique ID numbers on the mask and uniform to allow #deanonymization if an abuse surfaces?

Kevin Karhan :verified:kkarhan@infosec.space
2025-06-17

@thenewoil which it inevitably does!

Anthony Acciolyanthony@accioly.social
2025-06-03

I really like this kind of content that breaks down research papers for the rest of us. I had no idea that BGP hijacking was such a threat.

I wonder if any security folks out there have more up-to-date information on the resilience of OVH, Hetzner, DigitalOcean and other major provider networks. Are Counter-RAPTOR guards, counter-fingerprinting measures, BGP monitoring and RPKI being deployed in the wild?

youtu.be/XDsLDhKG8Cs

#Security #BGP #Networking #Tor #AttackVector #Deanonymization

2025-02-03
One issue I consider to remain with low-latency mixnets and overlay networks is that downtime can be deanonymizing.

Even if one has constant bitrate with randomly-selected short downtime/network degradation simulation, that doesn't really help when one's town loses power entirely a few times in a year or whatever and someone bothers to try and map the downtimes onto known locations of power outages over the same year.

Is there any sensible model for handling this failure case?

#Mixnet #TimingAnalysis #SideChannels #Anonymization #Deanonymization #WhyNoDirectTagEditingInAPObjectsYet
Kir4ik52 :blobfoxnerd:kir4ik52@mastodon.ml
2024-11-18

Администраторов Telegram каналов теперь можно деанонимизировать по кастомным стикерам и эмоджи.

Уязвимость заключается в том, что UID стикер-пака позволяет извлечь ID его создателя, что помогает раскрыть профиль пользователя.

Авторы Telegram-каналов заказывают у дизайнеров фирменные наклейки и «регистрируют» их в мессенджере с помощью бота Stickers, не подозревая о том, что это раскрывает их аккаунт всем.

Для популярной OSINT-утилиты Maltego даже уже разработали модуль позволяющий автоматизировать данную задачу.

src: github.com/vognik/maltego-tele

#blacktriangle #anonymity #deanonymization #maltego #telegram #opensource #osint

Kevin Karhan :verified:kkarhan@infosec.space
2024-09-19

Apparently the @CCC has some infos @torproject needs, and it seems they're desperate to get their hands onto that intel.

  • Dear folks at the #CCC, do the right and responsibe thing and send the details to #TorProject so they can assess the relevance re: #Tor and take appropriate steps!

Anyone who has details is asked to sent them in a #PGP/MIME-encrypted eMail to [security@torproject.org]( malto:security@torproject.org ) using the Pubkey [ 835B 4E04 F6F7 4211 04C4 751A 3EF9 EF99 6604 DE41 ]( keys.openpgp.org/vks/v1/by-fin ].

#ITsec #InfoSec #OpSec #ComSec #TorNetwork #dread #CyberSecurity #News #PleaseBoost #FollowerPower #CyberSecurityNews #forensics #FLOSS #FOOS #OSS #hardening #CyberAttacks äDigitalForensics #TorBrowser

h o ʍ l e t thomlett@mamot.fr
2024-05-22

#Urgence à FranceTélévisions : inventer le #floutage de demain
larevuedesmedias.ina.fr/urgenc
#FranceTV is creating a new #anonymity charter with strict #guidelines on #voice and face anonymization to protect #sources, as current anonymization methods are susceptible to #AI-driven #deanonymization. After reviewing 1100 news segments, 30 were unpublished due to high deanonymization #risk.

Judith van Stegerenjd7h@fosstodon.org
2023-10-21

arxiv.org/abs/2310.07298v1

Just tried to replicate the deanonymization technique proposed in this paper by giving it some of my old Reddit posts. My reddit profile is really puzzling to GPT-4: "Their interest in traditionally stereotyped masculine (computer science) and feminine (tea, Harry Potter books) domains makes it rather challenging to guess their gender accurately." :')

#llms #privacy #reddit #gpt4 #deanonymization

2023-06-16

@iampytest1 @dalias @campuscodi So basically this is the same old "don't expose #darknet servers to the #clearnet" thing?

I'd be wary of even reusing the same server across different #darknets, and spinning up a VM for each is cheap-enough to do with little-enough hassle there's really no good reason not to do it.

#Anonymization #DeAnonymization

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2023-03-10

Princeton Prof. Arvind Narayanan about (not so) #anonymous users in data sets, de-anonymization, #tracking, #PIM, #fairness in machine learning and AI snake oil

quantamagazine.org/he-protects

There is also a video v=oKkzVII_wHQ (e. g. yewtu.be/watch?v=oKkzVII_wHQ, pick your frontend)

#machinelearning #ml #ai #snakeoil #deanonymization #princetonuniversity #cs #adm

2023-01-05

#deanonymization
I'm Mark Ruffalo and this is my Mastodon account.

CK's Technology NewsCKsTechnologyNews
2022-08-17

NoScript - Cross-tab Identity Leak Protection

Protection, see picture.

Cache-based Targeted Paper + Info
leakuidatorplusteam.github.io/

2022-07-18

Cache-based Targeted Deanonymization Attacks can unmask anyone on any browser. Btw, Leakuidator+ is a browser extension that can successfully block this attack, you should install until browser vendors implement countermeasures to this type of attack.

leakuidatorplusteam.github.io

github.com/mjz3/LeakuidatorPlu

wired.com/story/web-deanonymiz

#browser #chrome #chromium #deanonymization #firefox #tor #torbrowser

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst