Skip to contentExploitQuest

The Account You Forgot

Almost nobody is caught by broken encryption. They are caught by a username they reused at fifteen and a profile they never deleted.

3 min readNot yet reviewed
Magpieadversary

I have been waiting three chapters for this one. You have learned to hide your traffic, your fingerprint, your cookies. Now let me tell you how I actually find people.

Wrenlearner

Some clever attack on the encryption?

Magpieadversary

I search for a username. That is usually the whole technique. The rest is patience.

The link you made yourself

Most deanonymisation is OSINTOSINTOpen-source intelligence — finding out about someone using only public information: profiles, posts, records, and the links between them.: assembling public fragments into a picture. The most common fragment is a reused username. The handle you chose for a game at fifteen, then a forum, then a "throwaway" account — the same word, linking accounts you thought were separate.

anon_throwaway_2026   -> new "anonymous" account, no name, no photo
the same handle       -> a 2019 forum post asking for help in your town
the same handle       -> a gaming profile with your first name in the bio
the same handle       -> a review that mentions your employer
  1. Line 1You were careful here. Nothing on this account names you. It does not need to.
  2. Line 3The first name arrives from a profile you forgot existed. Now the "anonymous" account has a first name.
  3. Line 4The employer arrives from a review. First name plus employer is usually a full identification. You were never hacked. You were searched.

You make a genuinely fresh account to post anonymously. What is the single most likely way it gets linked back to you?

Which of these most often deanonymises a careful "anonymous" account?

What actually helps

One careful account

- A fresh account, but the same username you always use
- A "new" email that forwards to your main one
- Posting from the same timezone, in your unmistakable style, to the same
  circle of friends

No links to sever

- A username with no history anywhere, generated not chosen
- A separate email, made for this identity and nothing else
- Awareness that writing style, schedule, and social graph are identifiers too
- Deleting or locking down the old accounts holding the loose fragments

You cannot make yourself unsearchable. You can make sure a search of your anonymous identity turns up nothing that connects to the rest of your life.

Rookmentor

This is why threat modelling came first. Against an advertiser none of this matters. Against a determined person who already suspects it is you, it is everything.

Magpieadversary

And I almost never need the clever attack. People hand me the link themselves, years in advance, and forget they did.

So the real attack is not on your encryption; it is on your history. Match it to your threat modelThreat modelFour honest answers: what you are protecting, from whom, what happens if it fails, and how much trouble you will go to.: casual privacy needs little here, but a genuinely separate identity needs a genuinely fresh username, email, and awareness that you write and behave recognisably. Next: the other gift people hand out for free — the password they used everywhere.