In times of the NSA scandal, not only net-savvy users are asking themselves the question of whether and how they can move anonymously on the net to escape the data collection mania of the authorities and secret services. However, this often leads to mistakes and false assumptions. A central misconception is the reduction of anonymity to the concealment of the IP address.
There are various other parameters that play an important role in user recognition, not only for the advertising industry: In addition to cookies, browser fingerprinting is playing an increasingly central role. Each user leaves behind an often unique combination of many factors, from the browser and screen resolution to the installed fonts. Panopticlick demonstrates this impressively. Below, I will focus on IP address masking and present four methods for concealing this personal data from external parties.:
- Proxy servers: Proxies act as representatives and forward their own data traffic to the actual destination. In addition to public proxy servers, various services such as CheapPrivateProxies offer private proxies. In all cases, you have to place a lot of trust in the providers, who are usually based abroad. Man-in-the-middle attacks and honey pots are just two dangers that can be mentioned at this point.
- VPN services: Through an additional virtual network card, all (usually fully encrypted) data traffic is passed on to a VPN gateway - this means significantly more protection and speed than proxy servers, but again requires trust in the VPN provider such as HIDE.IO. In numerous cases, providers have, contrary to their full-bodied promises, handed over user data to authorities, which is why the entire reason for their existence collapses like a house of cards.
- Onion routing: In the age of crypto parties, the number of users of the Tor project has skyrocketed. Data packets are routed through numerous intermediate nodes, which in turn never know the entire path from source to destination. The disadvantage: All data, which is transmitted (preferably unencrypted), must pass through the final node, the so-called exit node – and this node can read everything without any further action on the part of the user. Consequently, law enforcement has discovered Tor and is specifically targeting users for surveillance.
- Mix cascades: The only known company pursuing this approach is JonDonym . Mix cascades are interconnected servers located in different countries, all audited and certified by the operator. Penetrating the mix cascade would mean that all parts of the cascade are subject to government access, which is considered highly unlikely, not least because of the geographical dispersion of the servers. A disadvantage is the high price that private users must pay for the commercial service.
To put it simply: Absolute anonymity is impossible. Even if you use online services like social networks responsibly, you are still online and automatically leave traces that can be analyzed after a certain time, even if they are encrypted. Although the measures mentioned above (and especially their combination) can significantly hinder tracking, the completely anonymous internet user is a myth.