7 ms·
Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts
- SanjayMehta 3y agoHow do they define “toxic?” A list of naughty words? Strange topic of research for an economist.
- skulk 3y agoNo, it's more than just words. Would you want to participate in a profession where roughly 50% of your colleagues go behind your back to spew outright hatred at your ethnic group? Do you think you have a right to know about such behavior? Here's a direct quote the paper has from EJMR: "And America lost its war against blks. [...] At least until we resolve to final solution" Do you have any empathy at all for those on the other side of this?
- SanjayMehta 3y agoI’ve heard worse to my face and I’ve shrugged it off. And not across countries mind you, in my home country itself.
- cratermoon 3y agoWait, what? EMJR quoted ChatGPT for a legal opinion on the study? Over a subtle legal question? That's both hilarious and disturbing.
- bagels 3y agoIt's at best parroting a the most common layman beliefs, which may not agree with the law. That stood out to me too. Now I want to read about what dumb thing the site did to even make this possible. Ods should have been random, not hashes of pii
- iudqnolq 3y agoI can see why this would seem to be a clever way to implement passwordless sticky pseudonymous usernames, but it is indeed quite stupid.
- bagels 3y agoThe paper: https://www.insidehighered.com/sites/default/files/2023-07/ejmr_paper_nber(1).pdf https://www.insidehighered.com/sites/default/files/2023-07/e...
- bagels 3y agoUsername = hex(sha1(topic_id + ip))[10-14] Notably, no salt used
- upon_drumhead 3y agothe topic_id could be considered a salt, no?
- fbdab103 3y agoThe topic_id would be shared for everyone who posted on it. For each topic_id, it is then a matter of hashing 4 billion IPs to match each post to the topic. A different salt applied to each user so that would require the 4 billion hashes for each user post to a topic (topic_id+IP+salt).
- usaar333 3y agoThere's no user accounts on the system. I would consider the topic a salt - the problem is that the input is so small - just a 32 bit number which makes the "password" (user ip) fast to break. The sane solution would be to generate large random ids per ip address, topic. And burn the mapping after some time.
- bagels 3y agotopic_id is public information, and predictable. It's neither secret, nor random.
- rawling 3y agoThis is a weird use case (deliberately making the hash public) and the usual concept of a salt feels weird here. Any kind of server-side secret would have effectively stopped this attack, even if it was the same in every hash.
- mutant_glofish 3y agoSince when trying to dox people is called academic "research"?
- mcpackieh 3y agoThey call it "A study into toxicity". I call it gonzo research.
- mcpackieh 3y agoI think I wooshed some people with this comment. Gonzo journalism is when the journalist participates in the story. Gonzo research then is when the researcher participates in what they're studying. In this case, the researchers ostensibly researching toxicity are doxing people, which is toxic behavior. This makes them gonzo researchers.
- pbjtime 3y agoIntent matters. Both the police and kidnappers restrain people and lock them in rooms. Are they both criminals? Revealing people for their toxic behavior is in no way the same as toxic people doxxing others purely for what those other people believe.
- mcpackieh 3y agoBasically everybody who doxes thinks they have some ends that justify the means. That kind of mentality is toxic because every dirtbag uses it.
- psd1 3y agoThat's a logical fallacy. Breathing must be toxic because dirtbags breathe. AIUI, doxxing requires either publishing a subject's days or taking action against the subject. The authors of this paper day they have no intention of doing so. It's mild.
- 3y ago
- randomgg 3y ago"found" aka ran 3 quadrillion hashes on an A100 to crack the IPs
- flangola7 3y agoEnd result is the same.
- ShrigmaMale 3y agothis is rly awful "research". ederer prob got bullied on there and got mad, cause he has a reputation as a bitch. more importantly, ejmr has been important in uncovering multiple cases of research fraud (including one of the literal damn authors, this is some vindictive ass bs) and is the best source for actual unfiltered info on opinions of econ departments. includes important info like info abt people's political biases, potential toxic departmental cultures (or rather, which are more or less toxic, this being econ), and even info on sexual harassment allegations that depts would rather cover up. chilling effect of stripping anonymity is awful.
- olliej 3y ago> this is rly awful "research". ederer prob got bullied on there and got mad, cause he has a reputation as a bitch. No. Also name calling, while commenting on something you clearly don't understand is not a good look. EJMR claimed to be anonymous. It was not, and what they were doing skipped the most absolutely trivial of steps for actual anonymization. The only difference between this week and last week, is that now people know that their IP addresses were leaked rather than believing that they were anonymous. I would argue, it is beneficial to people to know that anyone could have done exactly what this researcher did, and we would have no way of knowing. Blaming the person who found out how terrible EJMR's "anonymization" was, is classic shooting the messenger. It's also a really good example of why we so "don't roll your own crypto". Any person who specializes in cryptography (or hopefully anyone who has done a basic intro to cryptography course) should have been able to point out the issues. > more importantly, ejmr has been important in uncovering multiple cases of research fraud and is the best source for actual unfiltered info on opinions of econ departments. chilling effect of stripping anonymity is awful. This sounds like the kind of thing where people need anonymity, it's a good thing that this research has demonstrated that ejmr was not providing such. Again, this research has not "stripped anonymity", there was none to begin with.
- throwawaytarp 3y ago>Blaming the person who found out how terrible EJMR's "anonymization" was, is classic shooting the messenger. Found out! They had an enemy: a small forum that they did not control. They looked for ways to screw it. This isn't some good-natured happenstance, they targeted someone they didn't like so they could screw them. The result, the point, wasn't, "Hey, security is important, kids, let me highlight your errors" it was, "Hey, you goddamn blasphemers, you have trod upon my fickle religious beliefs, so with the institutional and state power vested in me I will screw you." So you're saying its good that the obviously vindictive "researcher" targeted them for personal reasons because he dislikes political/religious opinions displayed on their casual rumors forum. "It was a public service," he claims! I understand that you probably want to white knight for your team, but perhaps take a moment to realize how ghoulish your disingenuous equivocation is.
- droptablemain 3y agoSo what's next? Get these people fired from their jobs for having unapproved ideas? Also, who decides what is or is not toxic?
- Paul-Craft 3y agoYou make it sound like it's a matter of academic freedom. It is not. Do you or do you not think that it should be acceptable to use language like "d4mn j3ws" in an academic forum?
- tivert 3y ago> Do you or do you not think that it should be acceptable to use language like "d4mn j3ws" in an academic forum? Of course it's not acceptable. It's not acceptable for any academic to disagree with me period. All those posters need to be rooted out, fired, and blacklisted.
- skulk 3y agoSorry if this sounds harsh, but you need to have a little more empathy for those aren't part of your "white boys club." Don't you think women and minorities need to know if their colleagues are posting their horribly sexist and racist thoughts online? Read the examples in the paper and then tell me that the colleagues of these people don't have a right to know.
- mutant_glofish 3y agoWell, if you don't mind being harsh, I'll tell you this: In your woke-scolding, you are assuming the both the gender and race of the person who you are replying to; probably based on a single comment.
- Natsu 3y agoI remember a short time when posting "hacked materials" was a thing people were up in arms about, but that ship seems to have sailed.
- philprx 3y agoUsing ChatGPT for a "neutral and expert question" is really broken: it gives the public the opinion that ChatGPT output could be trusted whereas it's so often wrong... That's really dangerous (beyond the immediate stupidity of asking such question to a LLM) because it may give an impression that ChatGPT answers should be trusted and neutral... It's neither.
- wildrhythms 3y agoRight, who told these people that ChatGPT is 'neutral' or an 'expert' in any topic?
- 14 3y agoMy dad has been saying for years, even before the internet took off, never write anything you don’t want the whole world to see. When the internet came along he reiterated the same message saying don’t write anything online you don’t want your friends, your boss, the police, a judge or anyone else to see. Anyone who goes online with the belief that they are anonymous and writes things that can seriously hurt their career or something that might put them in jail is foolish.
- protomolecule 3y agoWhat about saying things you don't want your friends, your boss, the police, a judge or anyone else to know you said? What about reading or watching things you don't want your friends, your boss, the police, a judge or anyone else to know you read or watched?
- mcpackieh 3y agoIndeed. Don't say, read, write, watch or do anything you wouldn't want your friends, boss, police, or judge to know... and now you are no longer your own person but rather an inoffensive amalgam of the beliefs of others.
- olliej 3y agoBecause people keep on acting like these researchers have retroactively removed the anonymity of this forum, or somehow everything was anonymous before this published, lets go over the facts: 1. ejmr made a system that includes hashes that could be trivially linked to ip addresses 2. ejmr claimed posts were anonymous 3. this researcher realized that the hashes could be trivially linked to ip addresses 4. the researcher presumably informed ejmr (as ejmr changed their scheme prior to publication) 5. the researcher published the findings The posts made on the forum could be linked to ip addresses from step 1, if this series of events stopped at step 2 or 3, the posts would still not be anonymous, and forum users would still believe that they were. We know that at step 3 this researcher realized that the forum posts were not anonymous, we have no way of knowing how many other people may have also discovered this. At step 4, we know ejmr changed their hashing scheme to actually make it [maybe] anonymous, and despite now knowing their existing scheme was not anonymous they did not inform any existing users that their posts were not anonymous. At step 5 the people using these forums finally discovered that their posts were not actually anonymous, because they were never anonymous. People on that forum, and commenters on HN, act like the researcher was responsible for the technical failure of ejmr, and somehow the act of telling people that their posts were not anonymous is what actually removed anonymity. Because people continue to struggle with this, let's imagine I made a forum where every post had an id that was computed as the first 10 characters of base64(rot13(ip || iso date)). A decade later someone goes "hang on, this looks like base 64", and then publishes their findings: you can get a post's IP address by decoding the truncated base 64 and reversing rot13. Is that person responsible for de-anonymizing the users of my forum, or is it my fault for misrepresenting the anonymity of my forum?
- throwaway290 3y agoI think the mainstream take is that black or white hat hinges on responsible disclosure? If that happened, the forum has completely mishandled this and the blame is squarely on them. If it didn't then I guess it's an open question.
- olliej 3y agoNo. Black vs white hat is "did you break this and then use it to <do something illegal>. The responsible vs. irresponsible disclosure question is "do you tell the responsible party ahead of time and give them time to repair it". From articles it certainly appears that ejmr learned how broken their code was prior to this paper being published. But responsible vs irresponsible disclosure is not a question of "should this be disclosed at all?", which the security community as whole seems to have determined that the answer is "yes". The problem is that ejmr was not anonymous, and if you publish something that is not anonymous, it is forever not anonymous. The only option would be to not disclose that there was any problem, not notify people that their posts were not anonymous, and this paper (the actual "research" about where posters lived/worked?) could also not be published. Because any acknowledgement or indication that the you could get form id to ip in any forum would cause people to go "huh, how did they do that?" a Streisand effect your way to everyone knowing. This is of course assuming that no one else interested in commenter identities has ever looked at ejmr either, because these researchers did not do anything clever to break the scheme.
- NotYourLawyer 3y agoDoxxing people for wrongthink isn’t research.
- protocolture 3y agoEven with the IP address, how do they determine identity? Do they have the NAT translation logs for all major universities?
- hypercube33 3y agoGood points however some universities at least in the US that I've bothered to poke around at give clients public ip addresses. It blows my mind, it's unsafe and wasteful but they do it. This may have changed or been unique to the ones I found looking around for open RDP not believing how dumb people were to expose it to the Internet
- skulk 3y agoThe paper explicitly claims that it doesn't identify users, merely links posts to IP addresses which belong to autonomous systems that are owned by universities or other elite institutions.