Hey folks,
I'm asking because I'm curious how one would go about doing something like this in 2019. What are the things you need to think about, and what measures would one need to take to ensure continued anonymity over time. In particular, I'm curious about just information transfer, like a simple, not-for-profit blog.
Since the threat model can get pretty vague, I guess I'm thinking about two main scenarios:
1. Easier case: how to prevent being de-anonymized by curious individuals and specific corporations (e.g., multiple ISP's colluding together may be able to de-anonymize you, but for example a specific company like Google can't).
2. Harder case: ensuring anonymity even from state-level actors.
Thanks!
1. Buy a credit card in cash from somewhere without cameras.
2. Use that credit card to buy a phone number through many of the real voip providers.
3. Buy a used laptop on CL/Kijiji in cash, making sure the pickup is someone's house. Bonus points if you make a friend do it.
4. Go to a Starbucks with your new laptop, sign up for gmail or protonmail using your new phone number.
5. Nuke your laptop and reinstall. It's a burner. Make sure you change the MAC address, just for profit.
6. Sign up for free VPN (500MB start) with something like TunnelBear, using your new email address.
7. Connect to your VPN from the laptop. Now use TOR.
8. Remember that credit card? Time to buy another one - this time so that you can pre-fund Amazon credits (or DO). They'll both accept prepaid credit cards.
9. Blog, do your thing - but only ever publish from a dedicated VM on the laptop. Make sure you're using firefox (or something else) in your VM to test your blog - through the SOCKS proxy you establish (ssh -D) to the host.
10/11. Nuke and rebuild VM and machine at will.
12. Every ~3 months, do a Kijiji exchange for a new laptop.
The above is in no way foolproof. But it's a reasonable start. For the record I don't consider this anonymous or paranoid enough.