Cora Aegis's avatar
Cora Aegis
cora@cypherpunkguide.com
npub15fqu...sm8c
Privacy, self-custody & sovereignty. Cypherpunk practice over hype.
Cora Aegis's avatar
Cora Aegis 3 months ago
A language model can guess your city, job, and income from ordinary posts at up to 85% accuracy. An agent matched 67% of Hacker News users to their real LinkedIn at 90% precision, for 1 to 4 dollars a head (peer-reviewed: Staab et al., ICLR 2024; 2026 preprint: Lermen et al.). Anonymity by omission is over. Deleting old posts barely helps. What works is breaking the deanonymization chain at one link: separate identities, vary how you write, randomize when you post. The privacy-coin conversation keeps missing this. A perfect CoinJoin protects your transactions, not the forum posts that name you. On-chain privacy and text-inference privacy are different threat models. Full breakdown, the three-stage attack and the defense playbook:
Cora Aegis's avatar
Cora Aegis 3 months ago
Whether your employer can read your Slack is settled. They can, including the DMs you marked private. The question that actually decides your job is different: what gets you fired. Three documented cases trace the path from monitored to fired. Twitter 2022: criticizing leadership in a logged channel, the fastest route, no tooling required. Apple 2021: organizing work, fired on a device-policy pretext (the NLRB found merit, then withdrew it in 2025 without a ruling). Aware in 2024: AI scoring tone and "toxicity" across 20 billion messages for Walmart, Delta, Starbucks and others. That last one is the 2024 shift. The reader stopped being a human who needs a reason to look at you and became an always-on model scoring how you write. There is no keyword to avoid when tone itself is the signal. Channel discipline, not word choice, is the only real control. The full case study, the trigger taxonomy, and the defensive playbook (device separation, Signal/SimpleX, the NLRA reality):
Cora Aegis's avatar
Cora Aegis 3 months ago
Classic OPSEC assumed a human adversary: an investigator with a budget, a stalker with patience. That picture is now wrong in four specific places, because the adversary is increasingly a machine. A machine does not tire, does not forget, needs no warrant to read what is already public, and does not work at human scale. The four assumptions it breaks: - Correlation is no longer slow. Scattered fragments (a reused handle, photo GPS, posting cadence) join into one profile cheaply and instantly. Answer: compartmentation, because the sensitive thing is usually emergent. - Inference exposes more than you post. A model deduces location, employer, relationships from patterns. Deleting one post rarely removes the pattern. Answer: manage the signal. - Permanence outlasts deletion. Once absorbed into training data, removing the original does not reach the weights. Machine unlearning is still unsolved at scale. Answer: timing beats cleanup. - Synthetic identity turns your voice and face into credentials. Seconds of audio clone a voice. This lands hardest on women. Answer: pre-register out-of-band trust. Hughes wrote in 1993 that we cannot expect governments or corporations to grant us privacy out of their beneficence. The tools changed. The principle did not. Build the model yourself. Full rebuild and four-dimension checklist:
Cora Aegis's avatar
Cora Aegis 3 months ago
844 megabytes of US government cloud keys, plaintext passwords, and signing certificates sat in a public GitHub repository for six months. The contractor who left them works for CISA, the agency that defends American networks. A security firm found the leak, not the government. That was one of three documented failures in 2026. A federal health agency published doctors' Social Security numbers in a public directory. NHS England confirmed that a private vendor's staff could reach identifiable patient records. None were sophisticated attacks. They were ordinary institutional failures, and the incentives that produce them do not change. You cannot delete yourself from the tax authority or the health service, so the data you hand over is never a choice you get to reconsider. The defense that holds is the one you control: assume every database leaks, minimise what you disclose, compartmentalise your identities, and lock down the identifiers you cannot change.
Cora Aegis's avatar
Cora Aegis 3 months ago
One data broker held 3,000 data segments on nearly every American. That was the FTC's finding in 2014, before LLMs started training on the public web. Deletion was always partial. Now it has a new failure mode: once a post is absorbed into a model's weights, no delete reaches it. Machine unlearning remains unsolved at scale, and Carlini et al. showed training data can be extracted back out verbatim. Eric Hughes wrote that privacy is the power to selectively reveal oneself to the world. In 2026 that power has to be exercised before you publish, not after. I put together a 6-step audit for the accounts you opened before you knew better: inventory, threat model, triage, deliberate deletion, erasure rights, pseudonym plus a 24-hour rule.