Slashdot Log In
Researchers Can ID Anonymous Twitterers
Posted by
timothy
on Thu Mar 26, 2009 05:48 PM
from the 140-shady-characters dept.
from the 140-shady-characters dept.
narramissic writes "In a paper set to be delivered at an upcoming security conference, University of Texas at Austin researchers showed how they were able to identify people who were on public social networks such as Twitter and Flickr by mapping out the connections surrounding their network of friends. From the ITworld article: 'Web site operators often share data about users with partners and advertisers after stripping it of any personally identifiable information such as names, addresses or birth dates. Arvind Narayanan and fellow researcher Vitaly Shmatikov found that by analyzing these 'anonymized' data sets, they could identify Flickr users who were also on Twitter about two-thirds of the time, depending on how much information they have to work with.'"
Related Stories
[+]
Swedish ISP Deletes Customer ID Info 177 comments
NewYorkCountryLawyer writes "A Swedish internet service provider, Bahnhof, has begun deleting customer identification information in order to prevent it from being used as evidence against its customers under Sweden's new legislation against copyright infringement via peer-to-peer file sharing. According to this report on 'The Local,' it is entirely legal for it to do so. The company's CEO, Jon Karlung, is identified as 'a vociferous opponent of the measures that came into force on April 1st,' and is quoted saying that he is determined to protect the company's clients, and that 'It's about the freedom to choose, and the law makes it possible to retain details. We're not acting in breach of IPRED; we're following the law and choosing to destroy the details.'"
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Who promised? (Score:5, Insightful)
Re:Who promised? (Score:5, Informative)
Who ever promised this data would be anonymous? Do you really expect privacy when posting personal stuff on line, even if you don't sign your name in advance?
1) People still assume that if don't sign their name on the internet then its anonymous. People need to be educated otherwise. Articles like this help.
2) While a lot of people are still grappling with #1 above, there are a lot of more sophisticated people who need to learn that even if they ARE behind 7 proxies, using tor, ssh, on a hacked wifi they are accessing via a pringles can-tenna from across state or even national lines... and then use that super anonymous connection to participate anonymously in 'social networking' sites like twitter, facebook, etc... even if they never reveal a single personal detail about themselves, their place within the social network itself can be reliably used to unmask them once they've had their anonymous account linked to real friends.
People REALLY need to be educated about this.
Parent
Re: (Score:2, Insightful)
So, to be anonymous, I need to get behind 7 proxies, use tor and ssh on a hacked wifi that I'm accessing via a pringles can-tenn from across state or national lines and make sure that all of the social network connections I have are to similarly protected people (behind 7 proxies, use tor and ssh on a hacked wifi that they are accessing via a pringles can-tenn from across state or national lines).
;)
That said, I agree. =D
Re: (Score:2, Insightful)
So, to be anonymous, I need to get behind 7 proxies, use tor and ssh on a hacked wifi...
RTFA - I think you missed the point:
Our de-anonymization algorithm is based purely on the network topology
Re: (Score:2, Insightful)
I think you missed the point actually.
or should I say... wooosh!
maybe try reading past the first 19 words before replying to a post?
Re:Who promised? (Score:5, Interesting)
The important thing is that anyone or anything that links your "real persona" and your "anonymous persona" is a potential threat to your anonymity both through things they willingly or mistakenly do and through things they could be coerced or forced into doing.
It's all too easy to put lots of thought into making it bloody hard to trace your connection but then link your "anonymous persona" to your "real persona" through common friends, accidently logging into a site using the wrong account for the connection you are using, forgetting to flush cookies (and any similar tracing objects) when moving between your "nonanoymous connection" and your "anonymous connection" and so on.
Parent
Re: (Score:3, Interesting)
Years back, I used my real name for all of my online activities. After my kids were born, though, I reconsidered using my real name and address. So when I started a blog, I made up an "anonymous" name. I'm under no illusion that it is 100% anonymous, but I do my best to keep my "real name identity" and my "blog identity" separate. I'm go "blog identity" on all of the sites I frequent, but I'm unwilling to disappear as "Jason Levine" and either a) pretend to be a newbie at the site for awhile or b) revea
Re: (Score:3, Insightful)
"all of the social network connections I have are to similarly protected people"
No, for you to remain anonymous, you must disavow all knowledge of anybody in your social network, for all 'accounts' or whatever, for all postings that you want to not be readily linked back to you. And they must not have any links to these accounts either (so the easiest way is to not tell them about these 'anonymous' accounts).
Re:Who promised? (Score:5, Insightful)
don't you use those services to be noticed?
Parent
Re: (Score:2)
Re: (Score:2, Insightful)
so the first step on concealing your identity is to not use the public social networks.
Re: (Score:2)
so the first step on concealing your identity is to not use the public social networks.
Bingo!!
Re: (Score:2)
how 'bout not using twitter, myspace, facebook, etc??
What do you think /. is?
Re: (Score:2)
Re: (Score:2)
- Super-anon guy has Bobby, Jim, and Sandra on his facebook friends and he's got Bobby, Jim, and Jessica on his MySpace
- Logically, Bobby and Jim must know each other, and therefore they both must know Super-anon guy.
- Bobby and Jim have a lot of pictures on Facebook with a guy tagged "A
Re: (Score:2, Interesting)
2) While a lot of people are still grappling with #1 above, there are a lot of more sophisticated people who need to learn that even if they ARE behind 7 proxies, using tor, ssh, on a hacked wifi they are accessing via a pringles can-tenna from across state or even national lines... and then use that super anonymous connection to participate anonymously in 'social networking' sites like twitter, facebook, etc... even if they never reveal a single personal detail about themselves, their place within the soci
Re:Who promised? (Score:4, Insightful)
Then again, some of us are very well aware of it and just don't care so much. If I want to post thoughts to a blog that I don't want linked back to me (and I've done so in the past), I'll set up something entirely separate, with a name I've never used before, linked to a new gmail account.
Anyone with half a brain can figure out exactly who I am, where I live, and what I do for a living, starting from this post, in about 20 seconds. Medical conditions and sexual preference might take a little more work, but I'm sure some of it is out there.
Frankly, I don't care. I'm self-employed and don't worry about what an employer might think of me. My friends and family seem to like me well enough despite already knowing that stuff. So long as it's not information that's going to result in identity theft (account numbers and such), there's not much that's worth the effort to conceal.
Parent
Re: (Score:2)
Ditto.
I'm not self-employed, but similar holds true. I'm pretty sure you could identify me from just this online handle, based on posts from this and similar discussion boards.
Fact is, you won't learn much out about me that I wouldn't have told you to your face anyway. I'm on pretty friendly terms with my employer, and am close with my friends, and I doubt anything I've said online would be news to them.
And even if you can find out some more intrusive facts about me (medical history, salary, what have you)
Re: (Score:2)
There are plenty of good reasons that somebody, particularly somebody with limited social power in the real world, might want a separate persona online.
Re:Who promised? (Score:5, Interesting)
I agree, but I think it's an age and culture issue. These issues are new.
In 10 years, no one would expect that a Twitter account couldn't be connected to your FB account any more than they would think you could cheat on your partner by taking your partner-in-crime to a pub you and your date frequent. The principle is no different - if two social spheres overlap, you've given up your relative anonymity.
That's why Larry Craig tapped his toe in an airport bathroom in a stop-over airport - low likelihood of running into someone who might know him.
Parent
Re: (Score:3, Funny)
I thought it was just because he had a "wide stance".
Re: (Score:3, Insightful)
Re: (Score:2)
Your still anonymous if all the profile data is fake. All the data associated with this Slashdot account is completely fictitious and in no way related to accounts hosted elsewhere that have nothing to do with tech blogs. Anytime I am presented with the option, or forced to provide, name and address data anywhere I use completely fictitious information. Everywhere. Also, different every time.
So, if somebody from Slashdot here either liked or hated me and was including me in their online social profiles i
Re: (Score:3, Informative)
Re: (Score:2)
Pretty Damn Sure (tm)
You mean the exit node's, proxy's, internet cafe's, etc. public IP address right? Yeah, I realize that. Any IP address that has been assigned to me by a corporation that ALSO possess my name, address, social security number, telephone number, etc. has never been recorded by the destination. I am sure that plenty of TOR nodes and proxy's have that IP address, but I am reasonably sure o
Re: (Score:2)
Re: (Score:3, Informative)
True, but that is not the same thing as what we are talking about in the article.
If you search my comments and find any postings with my real name, references to my place of work, real people, events, etc. then I do agree you could possibly do research in the real world to identify who I am. Sort of a 20 questions kind of deal.
Remember... that is identify , as in gain a positive identification of my real world identity to the point you could then actually find me. Learning about my likes, dislikes, relig
The "Sorta-Anonymous" principle. (Score:2)
This & other tricks are possible, yes, but *harder*. I really don't have the creds to pull the tech side of your Point 2, but I have quietly worked to keep the other side down to a whisper, earning strange looks from friends who can't imagine why I Just Don't Wanna Share.
The Mayans got lucky. Their 2012 date is just accidentally shaping up to be the Data Implosion.
~tag: "Let's give everyone what used to be studio grade cameras in their phones, 12 types of mechanisms and reasons to aggregate and pummel c
Re: (Score:2)
hey my internet aliases were damn anonymous, until Mozilla went and ruined it all but as i don't post much that i wouldn't say to peoples faces it doesn't really matter anyway.
Re:Who promised? (Score:5, Informative)
Parent
Re: (Score:2, Informative)
Re:Who promised? (Score:4, Funny)
Clearly, you're both me.
Parent
Re: (Score:2)
Tin foil! (Score:5, Funny)
Re: (Score:2)
Just don't cover the naughty parts.... it.. chafes.....
Or at least on the outside of the underwear.
Twits (Score:5, Insightful)
Re:Twits (Score:5, Insightful)
However, I don't think a lot of people fully understand the negative side of placing your life online for all to see. They fail to realize that placing their discussion about smoking pot (or other dubious activity) on twitter might one day cause them a job.
Parent
Re:Twits (Score:5, Funny)
That's right - The Netherlands are hiring again!
Parent
Re: (Score:2)
Re: (Score:2)
Obviously, I know that everyone doesn't do it every 5 minutes. It is just an exaggeration...but despite that, the fact stands that most people on these sites care little about privacy.
I do think Twitter is stupid. It has some very limited useful purposes (like the guy who used Twitter to notify people he was jailed in a foreign country), but f
You mean like willyhill? (Score:5, Informative)
Social network can-o-worms (Score:5, Insightful)
Are there really any surprises here? Social networks behave a lot like the Internet, with many routes pointing to your front door.
For example, use whatever falese names you want. Your email address makes a dandy primary key squirreled away in all your friends mailboxes, just waiting for Facebook to Hoover it up and join the dots.
Your privacy and anonymity is defined by the aggregate social stupidity of your friends.
Xix.
This is new technology to me (Score:4, Funny)
The thing that confuses me is the acronym "FRIEND", I have looked in all my technical references and I can't find that tool.
Please read our FAQ (Score:5, Insightful)
Please do not go and work for google (Score:2, Insightful)
http://www.guardian.co.uk/technology/2009/mar/26/seth-finkelstein-google-advertising [guardian.co.uk]
"Google recently took another step along the path of surveillance as a service, launching what it called "interest-based advertising", and which everyone else calls "behavioural targeting". These are systems that collect extensive personal data, for marketing purposes. To best understand the issues,"
http://sethf.com/infothought/blog/archives/001422.html [sethf.com]
I once upon a time worked for a statistics agency and even without names
Re: (Score:2)
A variety of networks including the phone call network
Old news actually. Techniques for identifying networks of friends and co-workers have been applied to call records for years. And that info is for sale.
A friend of mine in the security biz told me that when Dick Cheney outed Valerie Plame, link analysis probably revealed the identities of several hundred CIA employees.
I can ID anyone using Twitter (Score:3, Funny)
Re: (Score:2)
RT
This is a standard timing attack (Score:2)
The application to twitter anonymous accounts is creative, but otherwise it's a standard timing attack. If user A is active while anonymous data B is passed, user A has a higher chance of having generated data B than the rest of the population.
Looks like there's some number-crunching using timing of past tweets and whatnot to see if the user is likely to be on, too. I like that.
Or it could be I'm completely misreading it.
Anvil of Stars (Score:2)