Skip to contentExploitQuest
← Writing

Nobody Is Caught by Broken Encryption

People picture deanonymisation as cryptography failing. It is almost always a username, an old account, and patience. Here is how the search actually runs, and what it costs an attacker when you make it fail.

When people imagine being found out, they imagine something breaking — encryption defeated, a password cracked, a clever attack landing. In practice, I search for a username. That is usually the whole technique. The rest is patience.

This is worth saying plainly because it changes what is worth doing. If people were caught by broken cryptography, the answer would be better cryptography, and you would have no part to play in it. They are not, so you do.

The search, as it actually runs

Open-source intelligenceOSINTOpen-source intelligence — finding out about someone using only public information: profiles, posts, records, and the links between them. is assembling public fragments into a picture. Nothing in it is hacking. Every step below uses something that was published on purpose, by the person it identifies, often years earlier.

anon_throwaway_2026   -> a new "anonymous" account: no name, no photo
the same handle       -> a 2019 forum post asking for help in a named town
the same handle       -> a gaming profile with a first name in the bio
the same handle       -> a review mentioning an employer
  1. Line 1This account is careful. Nothing on it names anybody. It does not need to.
  2. Line 3A first name arrives from a profile they forgot existed. The "anonymous" account now has a first name.
  3. Line 4An employer arrives from a review. First name plus employer plus town is usually a full identification. Nothing was hacked. Somebody was searched.

Aggregation is the mechanism

None of those facts is secret. Your city, your employer, your dog's name, the gym you go to — individually harmless, and people say so when they post them. Assembled, they are the answers to security questions, the words people build passwords from, and the details that make a phishing message land.

"Hi, it's about Rex's vet appointment" gets clicked, by someone who knows your dog and your town. The facts were public. The combination is a key.

You create a genuinely fresh account to post anonymously. What is the single most likely way it gets linked back to you?

The identifiers people forget are identifiers

A username is the obvious one, and the one most often reused. Under it sit three more that people rarely think of as identifying at all, because they are not things you typed into a field.

One careful account

- A fresh account, but the same username used everywhere else
- A "new" email that quietly forwards to the main one
- Posting from one timezone, in an unmistakable style, to the same circle

No links to sever

- A username with no history anywhere, generated rather than chosen
- A separate email, made for this identity and nothing else
- Awareness that writing, schedule and social graph are identifiers too
- Old accounts holding loose fragments deleted or locked down

You cannot make yourself unsearchable. You can make sure a search of the anonymous identity turns up nothing that connects to the rest of your life.

What this costs the person searching

Be clear about the size of the win here, because it is larger than it sounds. A person with real walls between their identities is genuinely hard work. I do not get to search one username and unravel everything; I have to defeat each identity on its own terms, and usually I cannot.

That is the difference between an afternoon and a project nobody funds. The point of compartmentalisationCompartmentalisationKeeping separate parts of your life in separate identities that share nothing — so a breach or a link in one cannot spread to the others. is not perfection. It is being expensive.

Where to start, in order

Search your own handles and old addresses, and check them against a breach list. Delete or lock what you find. Stop linking new accounts through one username. Give any identity you actually need to keep separate its own email, its own browser profile, and no shared recovery phone number — that last one links two accounts in the one place you cannot see, the provider's records.

Then match the effort to who you are actually hiding from. Against an advertiser, almost none of this matters. Against a determined person who already suspects it is you, it is everything.

The free course covers this properly — threat modelling first, then the browser, then accounts and identity, ending in an exam and a credential anyone can verify without an account.