







How I registered a Linux machine with Apple's private services, received an existing Find My People key over IDS, and decrypted the live location without a Mac.
AT Explore MCP Server
Resolve handles to DIDs, find user profiles, and explore identity metadata across the network.
Scam Number Check Free Reverse Phone Lookup - Who Called Me? | Malwarebytes
Check any phone number for scams, spam, and unknown callers. Our free reverse phone lookup tool identifies who called you. No signup required. Try it now.

Registering Identity Recovery Keys via PDS, using goat | bryan newbold
One of the big design goals for atproto is for users to "own their network identity". If something goes wrong with a hosting provider, it should be possible recover accounts by independently updating their identity to point at a new home. Every account in the network has both a handle and a DID. Th...
How to Track the People Tracking YOU
Meeting notes april 1st, 2025
Quick catch up with [[Sam Gbafa]], founder of [[TinyCloud]], who I've worked with hacking on various local first / user owned data / identity stuff for a whi...

Large-scale online deanonymization with LLMs
We show that large language models can be used to perform at-scale deanonymization. With full Internet access, our agent can re-identify Hacker News users and Anthropic Interviewer participants at high precision, given pseudonymous online profiles and conversations alone, matching what would take hours for a dedicated human investigator. We then design attacks for the closed-world setting. Given two databases of pseudonymous individuals, each containing unstructured text written by or about that individual, we implement a scalable attack pipeline that uses LLMs to: (1) extract identity-relevant features, (2) search for candidate matches via semantic embeddings, and (3) reason over top candidates to verify matches and reduce false positives. Compared to classical deanonymization work (e.g., on the Netflix prize) that required structured data, our approach works directly on raw user content across arbitrary platforms. We construct three datasets with known ground-truth data to evaluate our attacks. The first links Hacker News to LinkedIn profiles, using cross-platform references that appear in the profiles. Our second dataset matches users across Reddit movie discussion communities; and the third splits a single user's Reddit history in time to create two pseudonymous profiles to be matched. In each setting, LLM-based methods substantially outperform classical baselines, achieving up to 68% recall at 90% precision compared to near 0% for the best non-LLM method. Our results show that the practical obscurity protecting pseudonymous users online no longer holds and that threat models for online privacy need to be reconsidered.

Large-scale online deanonymization with LLMs
We show that large language models can be used to perform at-scale deanonymization. With full Internet access, our agent can re-identify Hacker News users and Anthropic Interviewer participants at high precision, given pseudonymous online profiles and conversations alone, matching what would take hours for a dedicated human investigator. We then design attacks for the closed-world setting. Given two databases of pseudonymous individuals, each containing unstructured text written by or about that individual, we implement a scalable attack pipeline that uses LLMs to: (1) extract identity-relevant features, (2) search for candidate matches via semantic embeddings, and (3) reason over top candidates to verify matches and reduce false positives. Compared to classical deanonymization work (e.g., on the Netflix prize) that required structured data, our approach works directly on raw user content across arbitrary platforms. We construct three datasets with known ground-truth data to evaluate our attacks. The first links Hacker News to LinkedIn profiles, using cross-platform references that appear in the profiles. Our second dataset matches users across Reddit movie discussion communities; and the third splits a single user's Reddit history in time to create two pseudonymous profiles to be matched. In each setting, LLM-based methods substantially outperform classical baselines, achieving up to 68% recall at 90% precision compared to near 0% for the best non-LLM method. Our results show that the practical obscurity protecting pseudonymous users online no longer holds and that threat models for online privacy need to be reconsidered.

Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year.
From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we̵…

bsky.app | WhoTracks.Me
Explore the tracking landscape of bsky.app on WhoTracks.Me, revealing the most common trackers like Sentry and their impact on privacy

Exposed Persona Frontend Reveals Extensive Biometric Surveillance Stack Behind Age Verification - ID Tech
Security researchers investigating Discord’s age-verification implementation have discovered a publicly exposed frontend belonging to Persona Identities, Inc., revealing that the identity-verification vendor’s platform performs far more extensive checks than users […]

Own Your Data
Delete your account or access the personal data organizations have on you using this free service.


Keyoxide Docs
Keyoxide is a privacy-friendly tool to create and verify decentralized online identities.
New: a new tool called DecryptAds unmasks the shadowy world of ad companies that track your phone's location. It is incredibly difficult to investigate this world, but DecryptAds pulls together public data in a wholly unique way to make digging through this possible 404media.co/this-tool-unmasks-the-shadowy…
This Tool Unmasks the Shadowy World of Ads that Track Your Location
www.404media.coAnnouncing: keytrace.dev Take your @bsky.app / @atproto.com account and connect it to your other accounts around the internet. Keytrace cryptographically verifies your connected accounts so other social apps can trust the data. Learn more: keytrace.dev/blog/introducing-keytrace
Keytrace - You be you, everywhere.
keytrace.dev