Friday, June 8, 2018

How to Create an Anonymous Email

 
Anonymity is a shield from the tyranny of the majority. . . . It thus exemplifies the purpose behind the Bill of Rights and of the First Amendment in particular: to protect unpopular individuals from retaliation . . . at the hand of an intolerant society. (McIntyre v. Ohio Elections Commission, 514 U.S. 334 (1995))


There are many reasons that someone might want to speak anonymously. Perhaps you are a whistleblower reporting fraud, waste, and abuse or security violations within your organization and fear retaliation for exposing these crimes. You may want to research and discuss a sensitive health or lifestyle issue without revealing your identity to others. It may be that you hold unpopular political and social beliefs and fear harassment and retaliation for expressing your opinion. Or, maybe you want to request public records without having your name and address entered into a government database.

Best VPN Services (May 22, 2018) published an interesting article, "How to Create an Anonymous Email". The article discusses the need for anonymous e-mail, and as the article's title suggests how to create one.

In addition to the information provided by Best VPN Services, I recommend that you always set up and access your anonymous e-mail accounts through TOR. By using TOR your IP address is not visible to the web-sites to which you connect, and your true IP address will not be contained in the headers of the e-mail you send from your web-based e-mail account, nor in the server logs of that e-mail service provider.

If the e-mail provider where you set up your anonymous account requires that you respond to a text message (SMS) to prove that you are human when setting up your account, try to accomplish this through a SMS Verification Message Web-Site. At a minimum, don't receive this verification text message on your personal cell-phone.

If your threat model includes the possibility of having your e-mail records subpoenaed, choose an e-mail provider in a country other than where you live. Records from foreign companies can be obtained through the Mutual Legal Assistance Treaty (MLAT); but having your e-mail account in a foreign country increases the effort that must be expended to obtain those records.

With an e-mail address that you signed up for using TOR, and to which you have provided no true information about yourself, you have an anonymous account. It is absolutely essential however that you never create a connection between your anonymous e-mail account and the real you. Never send an e-mail to yourself from this account or to anyone specifically associated with you such as close friends or family. Never use this account to sign up for anything that can be associated with you. And most importantly never log into this account without using TOR. One mistake can associate this anonymous account and every message ever sent from it with you. Carelessness got the Dread Pirate Roberts arrested, so keep this in mind.

If you truly want to remain anonymous in your communications it is essential that you are always careful to avoid leaving clues that can be traced back to the real you. Your writing style or use of unique words and phrases can give clues to your identity. Commenting about things that only you or a small group of people should have knowledge of can reveal your identity as well.

Never use your anonymous account to harass, threaten, or intimidate others. If you use your anonymous account for illegal purposes it will draw the attention of law enforcement, and focus greater scrutiny on your activities, thereby increasing your risk of being identified. Remember CIA Director David Petraeus and former military intelligence officer Paula Broadwell had their private communications uncovered by the FBI after Ms. Broadwell's on-line activity drew the attention of law enforcement. Don’t be Petraeus and Broadwell.

Finally, don’t use your anonymous e-mail account over a long period of time. Long term usage can create patterns that an analyst can use to identify you. When you have accomplished your purpose delete the account, and create a new one in the future if needed.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.