all 21 comments

[–]FlickingMarvellous 16 insightful - 1 fun16 insightful - 0 fun17 insightful - 1 fun -  (0 children)

It’s been a bit wobbly for the last day or so. The admins have said it’s something at their end, not an external attack, and they’re working on it.

[–]BEB 11 insightful - 2 fun11 insightful - 1 fun12 insightful - 2 fun -  (3 children)

If you have friends who are hesitating to sign up for SAIDIT because of being able to be traced by their IP, tell them to use TOR brower to sign up without giving an email address.

Then use TOR every time view/ sign in to SAIDIT.

Tor is very easy to download and doesn't slow down the internet too much, especially if you only use it for accessing SAIDIT.

[–]anonymale 11 insightful - 1 fun11 insightful - 0 fun12 insightful - 1 fun -  (2 children)

No email address is needed to open a Saidit account. This is poor advice. Tor is not impregnable. Using it naively is asking for trouble, and taking countermeasures before assessing threats is risking either security blind spots, or wasted effort/inconvenience: probably both.

There is a process called threat modelling which we have probably all done intuitively and which should be applied deliberately to our online presence. The idea is to prioritise privacy threats by likelihood or hazardousness. In a nutshell:

  • What do I want to keep secret? Real identity? Location? Occupation? Account passwords?

  • Who wants to know my secrets? TRA on Twitter? Stalker? Government agency?

  • What resources do they have? My public tweets and lots of spare time? Public property records? The ability to hack a web server where I have an account? Court-ordered access to web server or ISP records?

  • How much effort are they likely to go to? Comb through old tweets? Hang around where I live? Develop a custom exploit and try spearphishing me? Dedicate a team of full-time agents to apprehending me?

  • What are the consequences for me and others if they succeed? Lose an important social media profile? Forced relocation? Career damage? Prosecution? Death?

  • What can I do to stop them? Guard what I say online to prevent accidentally giving away biographical or location details? Make social media profiles as private as possible? Learn to use more technical measures like Tor? Buy a gun and learn to shoot?

  • Have I done a good enough job? Have I been doxxed, correctly or incorrectly? Have I been hauled in by HR for wrongthink? Am I being stalked?

Everyone will have a different threat model, if only because differing information about us is already public, so it's important to sit down, do this for yourself, and review it regularly. It should be clear that there is no magic solution.

Let’s take your case of a would-be Saidit user worried about being doxxed. This is much more likely to happen because of

  • what they post on Saidit

  • what they post or have posted elsewhere if it can be linked to what they post on Saidit, e.g same username

I cannot emphasise this enough: doxxing is made much easier by lack of caution.

It’s rare that doxxing is achieved by discovering an IP address. That would be little use unless the victim’s ISP gives up the subscriber info for that IP address. Which means the adversary got either legal or covert access to the ISP’s records. They would also need similar access to Saidit’s servers to discover the IP address in the first place. This is much less likely than getting doxxed by someone who put together public information. Giving out naive security advice like ‘use Tor’ is just stupid. Please stop doing it. It does nothing on its own to prevent doxxing.

[–]BEB 4 insightful - 1 fun4 insightful - 0 fun5 insightful - 1 fun -  (1 child)

Sorry! I thought I made clear to NOT use an email address when signing up for SAIDIT.

I'm not clear as to what you're saying: Don't use TOR? Let your IP address be seen? Use a VPN or not?

The reason I was told to use Tor by someone was because they said they'd received death threats from TRAs who said that were going to find the person via their IP.

Could you please clarify for us what we should do when you get a chance? Thanks!

[–]anonymale 4 insightful - 1 fun4 insightful - 0 fun5 insightful - 1 fun -  (0 children)

https://saidit.net/s/GenderCritical/comments/67vr/operational_security_dont_get_doxxed/

You have to decide for yourself what precautions to take, informed by your threat model. If you don't have a picture of the threats you face, or might face in future, you have no basis from which to decide on effective precautions and countermeasures. I don't know how to make that clearer.

[–]Mr_Dork 9 insightful - 1 fun9 insightful - 0 fun10 insightful - 1 fun -  (0 children)

Yeah. It's been hit or miss for me today. I wonder if you're right and it is just from more traffic. (The chapo thread was very eye rolling. 'Terfs' waiting in bathrooms to catch trans people etc. Yikes.)

[–]Tikiri 7 insightful - 1 fun7 insightful - 0 fun8 insightful - 1 fun -  (3 children)

I was just on it and then it crashed! Chapo Traphouse people were planning a brigade.

[–]iguanidae[S] 15 insightful - 1 fun15 insightful - 0 fun16 insightful - 1 fun -  (2 children)

They and gencyn have been losing their minds about the existence of Ovarit- to the point of where I'm seeing users ask for it to remain invite only. We'll see how that plays out.

[–]Tikiri 21 insightful - 1 fun21 insightful - 0 fun22 insightful - 1 fun -  (1 child)

Yes, I saw that! Women being scared of getting attacked by men in their own private space, even on the internet. I’m So. Fucking. Angry.

[–]iguanidae[S] 12 insightful - 3 fun12 insightful - 2 fun13 insightful - 3 fun -  (0 children)

We're the Order of the Phoenix, and these dudes are LARPing as Umbridge lol.

[–]blahblahgcer 5 insightful - 1 fun5 insightful - 0 fun6 insightful - 1 fun -  (0 children)

Yeah it's been doing it since yesterday

[–]onemoredaydream 4 insightful - 1 fun4 insightful - 0 fun5 insightful - 1 fun -  (0 children)

Why the fuck does Chapo care so much? I didn't realize they were TRA types. That's sad.

[–]BettysBitterButter 3 insightful - 1 fun3 insightful - 0 fun4 insightful - 1 fun -  (6 children)

Trying to register but need an invite code.

[–]iguanidae[S] 3 insightful - 1 fun3 insightful - 0 fun4 insightful - 1 fun -  (2 children)

If I can ever log onto the site again I can get you one!

[–]BettysBitterButter 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (1 child)

Yes, please. Thank you.

[–]iguanidae[S] 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (0 children)

Please dm me and I can send an invite. Thanks!

[–]iguanidae[S] 3 insightful - 1 fun3 insightful - 0 fun4 insightful - 1 fun -  (2 children)

I seem to be back in now, let me know if you still need an invite code!

[–]WhyDoesHeDoThat 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (1 child)

Can I have an invite code too please?

[–]iguanidae[S] 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (0 children)

Sure! DM me and I will send an invite.

[–]MadLass 2 insightful - 1 fun2 insightful - 0 fun3 insightful - 1 fun -  (1 child)

Im not a member of ovarit but I did check it out earlier and it was definitely giving me an error page not found.

[–]BEB 9 insightful - 1 fun9 insightful - 0 fun10 insightful - 1 fun -  (0 children)

Earlier today and last night (?) SAIDIT seemed to come under attack too. I read that when GC first came onto SAIDIT, SAIDIT started getting massive attacks.

These men are so childish.