Post
Topic
Board Meta
Re: Bitcointalk account
by
Blazr
on 10/05/2015, 15:13:51 UTC
You're right, on both points. Mainly because both are shit discipline on my part. My meh excuse is "good 'nuff" & laziness - the outdated TOR bundle is non-virgin, set up to work with several plugins & automation scripts. The flashing warning's a handy way to tell it apart from the current version, which lives on the same box. The pix posted are .png (no EXIF data), posted through TOR/proxy.
But I'm no 3V01 M4s73r H4x0r, so I'm guessing my slack opsec is "good 'nuff" Cheesy

You are probably the perfect example of "a little information is dangerous".

If you are running a modified Tor browser, it is almost guaranteed whatever changes you made will be fingerprintable in some way, especially if you installed addons. This means that everything you do on your modified copy of Tor browser can be linked together, so even though you made this account "anonymously" it could be possible for someone to find out what else you've been up to on your copy of Tor browser and find out your identity that way.  So really your "opsec" is probably much lower than that of an average user.

Also even though the screenshot doesn't have any exif data, it is still possible to extract information about your system from it. for example, right away I can tell your running windows 7 or above, but careful analysis of that screenshot will allow an attacker to extract much more information. I was able to determine your timezone as being approximately gmt+10, which means you are likely in Australia/Russia  Wink

With some more careful analysis an attacker could possibly be able to determine which image processing libraries you have installed on your PC and based on that what other software you have installed on your computer and what versions. It is also really easy to figure out what your screen resolution is too. It is then possible to to use this information to link it to other screenshots you may have posted online.

How to stay somewhat anonymous: Download Tor, run it, update it, and don't post anything through it other than short amounts of text, even though techniques exist that can identify your writing style with >90% accuracy from even miniscule amounts of text. Don't modify anything and don't try to "improve" the security unless you seriously know what you are doing, and if you think you know what you are doing then you don't.