Regarding information that Boredat has on file
Types of information that I have readily available:
- I can tie anonymous posts with the ones posted using a screen name.
- I can usually connect posts from one user across multiple accounts, though this is case-by-case.
- I can usually identify with a "pretty good" degree of confidence that someone is posting from campus. It has to be taken with a grain of salt as it's not always correct and the failure rate is unknown.
- I can tell the age of an account, how often the user posts, how active the user is on the site, and other sorts of behavioral information, but this takes some investigative work on my part and not something I do regularly. I usually look at this type of information when I’m making a decision on whether to ban someone. For instance, an account created recently that is doing nothing but attempting to harm the community is obvious when looking at the data and an easy decision.
I do look at this data though when necessary. Over the years, some of the behaviors I’ve discovered can sometimes be baffling, but if you can think of it, it has probably been done. I have seen cases where some users will post their own name or harass themselves and then turn around and complain about their name being posted. I have also seen student organizations post the same kind of content that they themselves protest. I have seen users have long, long winded conversations with themselves that can appear like multiple people are participating (it can be pretty convincing!). However, in all cases when looking at this behavior, if a user is causing harm to the community, I take action.
Types of information that *I* do not have available:
- Given a specific post or account, I cannot provide the person's email address.
I should emphasize that *I* do not have this information, but since Snowden began releasing information, a closer look at how the internet works fundamentally and how SMTP outbound messages are sent makes me pretty sure that the trace of those emails (and their contents) can be easily stored by an internet service provider (or university network) and certainly is being stored by the NSA (presumably, indefinitely). The metadata information about those emails or their contents could be used to identify the user’s posts if matched up with the data in the Boredat server.
Types of information that are not readily available to me, but I could acquire in extreme circumstances if compelled with a court order:
- The contents of private messages between accounts or screen names.
- IP address information.
Regarding information that an administration or law enforcement could acquire if they felt it were necessary
For all intents and purposes, you should assume that law enforcement agencies can collect pretty much ANYTHING, period. I cannot stress that enough. They can discover identities if they were determined to do it, with or without the help of information stored in Boredat servers. These facts are now known given Snowden's revelations. Here are some hypothetical scenarios (I am not suggesting, nor do I have any proof, that any one of these scenarios has been used):
- If you are using a university email system, it is trivial to store records of all incoming and outgoing emails regardless of who’s sending them. From outside the university network, all information about inbound and outgoing emails (sender, recipient, contents) can be read in plain text when they are traversing the web. SMTP email is fundamentally unencrypted unless deliberately encrypted. It is now known that the NSA is making a copy and storing all emails (or at least as many as they can get their hands on).
- As an internet service provider (Comcast, ATT, Verizon, any cell phone service provider)... ALL records of what sites you’ve accessed and what pages you view are almost certainly stored. It would be possible for a university network to do the same if configured proerply. Sadly, major commercial internet service providers sell this information to lord knows how many 3rd parties. Your “digital footprint” is unfathomably huge and more people, government and commercial organizations already have access to this information than you’d like to believe.
- Secured SSL connections (like the connections made to Boredat) CAN be intercepted by an Internet Service Provider that is determined to do so. There are different techniques and specialized equipment you can buy to do this. It is most often called a man-in-the-middle attack. The contents of your browsing activity (i.e. the posts you make on Boredat) could theoretically be encrypted, decrypted to be read and stored, and re-encrypted before it leaves the network without the user or the server having any knowledge of this. This means any site you connect to (i.e. Facebook, your bank account, anything) could be intercepted and read in plain text if one of a growing list of techniques is deployed.
* * *
What Boredat protects you from:
It is pretty simple. Boredat anonymizes you from your peers and from the Boredat system itself. It was built with the intention of obfuscating traces of personally identifiable information as much as possible. Boredat protects you from a potential information leak. If you look at the raw data in the database, it would be very difficult to make positive IDs of the people who posted them. If I hired an intern and gave them access to the server, your identities would still be protected.
What Boredat DOES NOT protect you from:
This is also simple. Boredat does NOT protect you from breaking the law. (i.e. sexually harassing someone, cyberbullying, drug related activities, etc). Given the information that I’ve described here, please understand that if a law enforcement agency is determined to identify someone, they will catch them. There are hundreds of ways to investigate activity online and they know how to use them. They have very smart people on the job. Some techniques are easy and some are difficult. Local, state and federal authorities all have different tools with different degrees of investigative capabilities at their disposal, but they work together when it’s necessary.
So what does all this mean?
This is the simplest of all. Don’t be an idiot on the Internet, period. Not on Boredat, not on any site. Don’t give law enforcement a reason to track you down. Don't draw unnecessary attention to yourself. You should acknowledge that nothing on the internet (or at least the one we have today) is truly anonymous without fail. Just read about how the FBI took down the Silk Road. Read about how services like Tor, which is presumably the most sophisticated, industry standard anonymous system to-date, can still be taken down with good old fashioned detective work.
Understand that the intention of this service, from the very beginning, was to create a means of communication that might otherwise not exist. The intention was to create a place where truly honest discourse could occur. It was not built for people to harm each other. It was not built for people to conduct illegal activities. In the 7 years of Boredat existence, this has never been encouraged or accepted. The site has even been taking offline completely if it wasn't reasonably under control.
With all that said, please recognize that I am doing everything that I possibly can with the limited resources that I have to make Boredat a safe place for everyone. As an immediate countermeasure to recent events, I have adjusted the moderator policy to require only 3 votes to have something removed rather than 5. I am also making plans to implement new capabilities in the coming weeks to help curb the small handful of users who intentionally harm the community.
As always, should you ever find that a post needs to be removed more quickly than the moderator system alone, please email me the post in question directly at jaedaemon(at)gmail.com and it will be dealt with as soon as possible.
Jae
I feel like you should make people read this before they even create new accounts. It's all pretty common sense to me, and you've even said a lot of it before, but people get all crazy whenever something like the recent case happens.
ReplyDelete<3