#InfoSec#privacy#OpSec Here's a longish 🧵 about what it takes to maintain anonymity online in a world where a service like Twitter can screw up its security and let anyone in the world find out the email address associated with your account. The basic rule is this: if you need to be anonymous online, you cannot give enough info to any single service to compromise that anonymity in the event of a breach. 1/9
@aral I don't understand why I keep seeing you and others citing email as an example of this. There are hundreds of thousands of SMTP servers happily interoperating with each other, many different IMAP server implementations, and many IMAP clients that can talk to them, and many of the above are open source. I've run my own mail server for 30+ years. There are a few big players, but they're really not the same as the social media walled gardens.
he/hisDigital Services Expert at #USDS (https://usds.gov/), detailed to #VA.I work primarily in #infosec, #IT, and #SaaS infrastructure. Prior to USDS, I was a #tech #startup #CISO.Dad, old-school hacker, Righteous Indignation Man. Opinions are my own. You can follow my blog from the Fediverse via @jikblog.#MaskUp #COVID #CovidIsNotOver #USPol #MAPol #BosPoli #Boston #MA #politics #resist #linux #FOSS #OpenSource #ConsumerActivism #privacy #programmer #hacker #fedi22