cross-posted from: https://lemmygrad.ml/post/10899106

AI Can Now Easily Unmask Your Secret Online Life for $4

A new research paper from ETH Zurich, Anthropic, and MATS demonstrates that Large Language Models can automatically de-anonymize users across platforms like Reddit and Hacker News.​

The AI acts like a digital detective using a method called ESRC (Extract, Search, Reason, Calibrate). It scans a user’s post history for subtle clues (hobbies, writing style, locations), searches the wider internet (LinkedIn, other forums) for matches, and uses complex reasoning to confirm the identity.​

The terrifying results:

  • It correctly linked secret Hacker News usernames to real people 67% of the time (with 90% accuracy when it made a firm guess).​
  • It successfully matched a person’s separate Reddit accounts from different years 68% of the time.​
  • The entire automated process costs only $4 per target.​

“Practical obscurity”-the idea that you’re safe online because it takes too much human effort to connect your digital breadcrumbs-is dead. Anyone with a few dollars and an LLM API can now mass-dox thousands of pseudonymous accounts in minutes.

  • tasho@leminal.space
    link
    fedilink
    English
    arrow-up
    3
    ·
    6 days ago

    kind of sad that you have to lie and obscure your identity for the sake of internet security and privacy. using your profile to connect to anyone makes your identity opaque so to be safe meaning we have to be as disconnected as possible :-l

  • Awoo [she/her]@hexbear.net
    link
    fedilink
    English
    arrow-up
    35
    ·
    7 days ago

    This is why your “secret online name” should be a meme that literally millions of people use and absolutely not something unique that can be identified across multiple services.

  • infuziSporg [e/em/eir]@hexbear.net
    link
    fedilink
    English
    arrow-up
    30
    ·
    7 days ago

    Once again, the early Internet opsec of “Assume that everyone on the internet wants to track you down, and don’t ever post your name, specific age, employer, or city in a publicly accessible online place” gives you an ample amount of protection.

    • KuroXppi [they/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      20
      ·
      edit-2
      7 days ago

      post your name, specific age, employer, or city in a publicly accessible online place

      Okay if you say so

      Name: Kurox Ppi
      Specific age: 23 years, 7 months and 9 days
      Employer: Mars Inc
      City: New York, USA

      Specifically, I work in the product design team which was responsible for putting the dick vein on the Snickers, a popular peanut and chocolate bar

      This information is all true and current to the best of my knowledge. Please do not use it to triangulate my identity based on other online and offline activity.

      Edit: peanut, caramel and chocolate bar

      Edit edit: peanut, caramel, nougat and chocolate bar

    • LadyCajAsca [she/her, comrade/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      4
      ·
      7 days ago

      My full name is actually

      Lady Caj Asca, so I’m using my middle name as my nickname because being called Lady is… well, actually who cares? You know what, call me anything, as long as I know it’s connected to this account on a leftist forum. My parents at birth named me Lady and Caj Asca is actually from a long line of Caj Ascas in Manila of the Filipinos with the sole purpose of shitposting since the arrival of humans in the islands.

      My age is permanently 21 years, 6 months and 9 days because I’m stuck in an unknown purgatory of sorts where I only know the current date and time through the computer, and I don’t seem to age, starve or get thirsty, though I find random bottles of suspicious pink liquid on the ground and drink them, I don’t know what it does, but it does taste sweet…

      My employer? Oh of course the great CPC, and MSS, they transfer me Xi bucks to my bank account that I exchange for internet connection, as somehow that’s still not free.

      I hope this isn’t used to track wherever I am, I’m perfectly content here in this room that only has a PC to post in the internet… Though, sometimes I do hope I find a way out… because the internet’s still bad here still and I find myself with nothing to do in these gray floors… And I’ve got nothing to do whenever Hexbear goes down…

    • post your name, specific age, employer, or city in a publicly accessible online place

      My real name is Donald John Hoxha, age 80 years old, not counting the dead ones. My employer is Deng Daping, leader of the Shanghai liberals, but I’m actually a remote volunteer all the way from Dongjing province.

  • oliveoil [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    27
    ·
    7 days ago

    Woah so they can know that I live in Berlin, Germany because I wrote equations like this:

    $50 / $1.500 = 3,33%

    Crazy. They infer based on my cues like a champ. Heckin awesome bro.

    Genial !

  • trabpukcip [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    28
    arrow-down
    1
    ·
    7 days ago

    Feel like the “writing style” one is pretty hard to nail down when every redditor anne frankly did nazi that coming

  • Thordros [he/him, comrade/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    19
    ·
    edit-2
    7 days ago

    This is gonna be really unfortunate for the federal agent that unmasks my real identity, and unearths hundreds of pics of me going hog out all over the place in sex clubs 30 years ago.