Some situations require an absolute anonymity. This document aims to show those tools and precedures to take into consideration. To everyone concerns doing at their own risk.
Help me improve it. Suggestions? Errors?
cyberactivista@vespre.com or leave a comment below.
This text has been motivated by recent events, the shameless international persecution to
WikiLeaks.org,
european and worlwide very provable approval of the
ACTA and null willing of
politicians
to promote the
network neutrality,
or its direct violation by the
private sector.
Things got worse: UK prime minister David Cameron
threatens to close Facebook and Twitter accounts
to those suspected in participating in riots, USA aims to legalize censorship (SOPA)
About the author: Internet professional with over 13 years of experience
Last modification: 22/11/2011
Information I can easily know about you
No data is stored in my server (I can not tell the same about google analytics...)
We must avoid being tracked down; TOR is an open source software that talks P2P way and encrypted (Impossible to discover the information you are sending) and chained. Every message follows a different path among some of this worldwide TOR net, making it extremely difficult, not to say impossible, to be localized.
An alterative would be using an internet server acting as a bridge between your computer an the internet, guaranteeing that they do not hold any register of our activities; like this swedish company that for 5€/month is offering a VPN (Virtual Private Network) guaranteed by a bunch of very sensible laws on the subject.
It is essential to use one of this hidding IP services to guarantee our anonymity.
This is obvious Or not? but never ever tell any personal information Are we trying to be anonymous or not? Especially delicate: documents (excel, word, power point, pdf, open office) all of them store "meta data" (your name, company, email ...) Erase them! O even better: send only plain text (.txt) files.
Images: camera, original thumbnail, exposure time, date, Unique identifier? ... this data is stored on pictures taken by many cameras or edited by some software. Erase this meta data, the software Infraview helps us achieving this goal
Our friends onThe pirate bay are offering an untraceable, anonymous and volatile email service just in case we need to send something.
Not having a firewall is like parking your car with the keys inside and the doors opened, get one, windows has one and have it well configured
Make sure to have all your softwareand the operating system (Windows, MacOS, Linux...) update. An "old" software is more likely to have bugs (errors) that might allow an intruder/web page/virus/trojan get into our computer.
Use a pen drive To boot any computer without leaving any traces with this Amnesiac and incognito live USB linux, and forget the rest!
It is as easy as this: record the project into an external memory (or CD). Plug the pen drive into the computer, restart and that's it! When the computers starts it will detect an operating system in the Pen drive and will run it, with the peculiarity that this live Linux comes with the latest and best tools to achieve a great anonymity
A non-secured connection is vulnerable to a Man in the middlelike attack (Someone could potentially capture some or all your communications). Unlikely? May be, but lets guess your are using your Wi-Fi network; all your communications are potentially trappable by many Wi-Fi devices inside the range of your wireless signal. As of course by your internet provider. So under no circumstances you should so any "compromising" things unless using a secure/encrypted connection. Interact always with secure web pages httpS://encrypted.google.com/ instead of http://google.com (what is important in here is the padlock you will see in your browser, that tells us no one will be able to analize what are we doing )
The remote possibility, of some special situations, where a secure connection might be victims of an attak.
Only an open source browser, like Firefox or Chromium, is trustworthy enough for these purposes. With Internet Explorer, Opera, Safari o even Chrome we will never be 100% sure of not beeing spied. Anyway and to avoid leaving traces on the computer we are using we must use the private browsing (tools->Start private browsing) Known for many as porn mode. With this feature we will also disable all plug-ins, avoiding sending information to third parties.
If undisclosed documents are stored in the computer encrypt them, there is an encryption files and folders software, remember to use a strong password, Bruce Schneier have a list of password advises. And never those that allow you to recover the password.
There have been too many signs pointing out that Microsoft Windows sends "sensible" data to their own servers, as well as reasonable doubt that aims that there is some back door on these systems, if there is no other option go for it, but if you have a linux at hand do not doubt. Hey, MacOS is not a real alternative, may be a little bit stronger but as a good paranoid nothing overcomes linux.
Some viruses. toolbars, security bugs. keyloggers (someone might be capturing everything you write on your keyword and storing or sending it to a server), non updated software, plug-ins (flash, java...). Anyone can expose our system "easily" vulnerable to an attack, therefore be careful.
If you have an internet connection your IP is unequivocally linked to your bill so to your person, by law business offering internet connection mush store this data for at least 2 years (depends on the state). So a coffee on a bar with your laptop want be very suspicious and definitely will rise your anonymity. Have I made this out? If not, a link!
Actually disable all software that is not completely essential, specially those that use the internet (skype, messenger, emule, spotify, azureus ...) this programs send and receives many information constantly to companies central servers or many internet users, an indiscreet attitude.
But flash seems especially embarrassing for the number of failures that has shown. Do I take you a picture?
Each and every network device has it own unique identifier (MAC) therefore if the local network you are connect to keeps a log on the clients activities; Starbucks, airports ...? It would be technicaly possible to track down the genuine owner of the device (laptop/cellular ...). So If we want to be completely paranoid we better change our MAC, it is a second and we became a little bit anonymous.
There can be no loose ends. A good security system (we are talking about this in here) must the controlled entirely (and will be as strong as its weakness link), a single mistake and out.