Reply to comment
Newsletter Sign-up
Newsletter Sign-up
Security news and analysis with expert opinion and perspective from the Threatpost editors.
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.


"There is a wrong perception about Internet anonymity – very few people realize that it does not exist for ordinary users. But the worst part of the story is that the ones who are truly anonymous are professional cyber criminals, because they know what to do to hide their real identities in the Internet."
This almost makes it sound like people who do bad things online have some magical ability that differentiates them from "common users" online. For anyone that chooses to remain ignorant of why they might want to blend into the crowd a little better, too bad for them - when the time comes and their idea of what is "right" is suddenly at odds with their Government (for example), they're doomed.
For every other "common user", it's the easiest thing in the world to learn how to use most (if not all) of the same methods deployed by bad actors to keep themselves a little more hidden. The REAL reason there are so many people out there getting away with virtual murder isn't because they're super smart at hiding; it's because for the longest time law enforcement across the globe either has no clue about these things, or don't have the resource, or are on the take, or a combination of all three.
All it takes is a little bit of effort and more often than not, you can get away with pretty much whatever you feel like. This can be seen from script kiddies as young as 11 dealing in stolen credit cards right the way up to the illegal porn dealers tying their junk into malware installs. A little push in the right direction, and law enforcement are left scratching their heads. You couldn't even report cybercrime directly to tech crime units in the UK until recently - you had to go through a local station where you'd be met with confused looks and rolling eyes.
This is the reality.
"When I say "no anonymity" I mean only "no anonymity for security control." I don't care about the way people behave on blogs, forums, social networks and pirate torrent portals."
We may not, but lots of dubious goverments the world over (including our increasingly antagonistic UK government) DO care. And they'll use the slightest reason for dumping you into a situation you'd rather not be in.
I've lost too many good friends in China as a result of the above, and stripping away their attempts at anonymity in a place that NEEDS some to balance the odds is a terrible idea.
"It is only the provider who needs to know your real identity."
And yet a Government will easily take this info if it wants it. How is an ISP going to stop them?
The moment you create a net passport like this, bad people will create a market for it, steal them, get around it, whatever. The ONLY people who will come off worse will be those "common users" you mention; the bad guys will be too busy pretending to be them and getting around the same system to care.
Their income *depends* on getting around these kinds of systems; you really think they won't be able to do it?
"Imagine that everyone flying in your plane is anonymous, so you don’t know who they are and what they’re up to – are you really going to approve of this?"
Being anonymous on a plane is not a big deal. Assuming you manage to pull off an elaborate con job, grab someone elses plane info (and manage to ensure they don't arrive at the airport for their flight while you're pretending to be them) - in fact, scratch that - assuming you (very easily) manage to print out a fake name for your boarding card and (say) have a fake passport that matches the name - so what?
Worst case scenario, you've ripped off someone elses ticket or managed to give yourself a fake ID for a plane flight. If you WERE a person into blowing up planes - you still have to go through security, screening, bag check, pat down, metal detector etc. Your assumed identity means nothing at that point.
In short, whether the airline knows your real identity or not, you've not got any closer to doing something malicious onboard simply by having a fake identity. You can't blow something up with a name.
I think there's a number of very valid reasons for wanting to resist the obsession with collecting huge vats of data on individuals for the alleged purposes of "safety" - especially when tying that into (no doubt) "infallible" digital markers that will be used and abused with the "common users " coming out of it with the short end of the wedge.