Глава 1
Digital Footprints in a Surveillance Age
In 2013, comedian John Oliver interviewed people about Edward Snowden's NSA revelations. Most Americans couldn't identify Snowden or explain what he'd done. Yet when Oliver framed privacy in personal terms-like government collection of private photos-people suddenly cared deeply. This disconnect perfectly captures our paradoxical relationship with privacy: we claim to value it, yet willingly surrender it daily through our digital devices.
"The Art of Invisibility" by Kevin Mitnick has become a modern privacy bible, praised by security experts like Mikko Hypponen and embraced by privacy advocates worldwide. As a former "most wanted" hacker turned security consultant, Mitnick brings unique credibility to the subject. The book has influenced everyone from corporate security policies to everyday users' digital habits, with its practical approach to privacy protection resonating in an era of constant data breaches and surveillance revelations. Beyond technical circles, it's gained cultural relevance as concerns about digital privacy have entered mainstream consciousness, with celebrities like Edward Snowden and journalists like Glenn Greenwald citing its importance in understanding modern surveillance.
Глава 2
The Illusion of Privacy in Our Digital Lives
We live with a dangerous illusion of privacy. I once demonstrated this to a skeptical young reporter by quickly finding her Social Security number, birthplace, and complete address history using investigative databases. Her shock was palpable-she had no idea how exposed her personal information was.
This vulnerability extends beyond personal data to our online activities. In 2014, "theFappening" exposed private photos of Jennifer Lawrence and nearly 300 other celebrities when hackers targeted their iCloud accounts. While Apple denied any system breach, attackers likely used specialized tools to access complete iPhone backups stored in the cloud.
Most people remain shockingly careless with passwords. The most common choices-"123456" and "password"-offer virtually no protection. Even corporate executives use weak passwords, creating serious security risks.
To protect yourself, use passphrases of at least 20-25 characters or employ a password manager to generate and store complex, unique passwords for each site. Password-protect all your devices, especially at work where someone could access sensitive information during your absence. Consider Bluetooth-based screen-locking that automatically secures your computer when you step away.
For mobile devices, avoid simple four-digit PINs in favor of longer passcodes or text-based passwords. Android lock patterns can work if you avoid predictable shapes. Biometric locks like fingerprint scanners add convenience but should be used alongside traditional passcodes, not as your only security measure.
Password reset functions represent another vulnerability. In 2008, student David Kernell accessed Sarah Palin's Yahoo email by using the password reset function and answering her security question with information Palin had shared publicly. This illegal access resulted in prison time for Kernell.
For critical accounts, enable two-factor authentication (2FA) that requires both your password and a verification code sent to your phone or generated by an authenticator app. This significantly improves security by requiring two verification methods: something you know (password) and something you have (phone). While SMS-based 2FA has vulnerabilities, it's still better than passwords alone. For better security, use authenticator apps like Google Authenticator that generate time-based codes directly on your device.
For financial transactions, consider using a dedicated device-a $200 Chromebook used exclusively for banking and medical tasks. While less convenient, this separation significantly reduces the risk of malware compromising your financial information.
Глава 3
The Hidden Eyes Reading Your Email
Most of us check email first thing in the morning without considering who else might be reading it. Even if you immediately delete an email, copies exist on servers worldwide if you use cloud-based services like Gmail, Yahoo, or Microsoft. These companies scan your emails-allegedly to filter malware, but also to serve targeted ads based on your content.
This practice came to light when Stuart Diamond and David Sutton noticed Yahoo was displaying ads related to their email content, even from non-Yahoo accounts. They filed a class-action lawsuit alleging illegal wiretapping. Similarly, Google accidentally revealed details about its email scanning processes during a lawsuit, showing they'd moved from scanning archived emails to scanning all Gmail in transit.
Companies can secretly access your emails too-Microsoft once scanned a Hotmail user's inbox to investigate software piracy. And if you use work email, your IT department likely scans and archives everything you send.
To protect your email privacy, encryption is essential. Most web-based services encrypt emails in transit, but messages may be unencrypted between Mail Transfer Agents. The most popular method is PGP (Pretty Good Privacy), with free alternatives like OpenPGP and GNU Privacy Guard (GPG).
Email encryption uses asymmetrical encryption-you generate a private key that stays on your device and a public key you share freely. When someone wants to send you a secure message, they use your public key to encrypt it, and only your private key can decrypt it.
Even with encryption, your email's metadata remains exposed. This includes To and From fields, subject lines, timestamps, and server IP addresses-all readable by third parties. Don't underestimate what can be learned from this information.
I once performed metadata analysis on phone records by hacking into PacTel Cellular to obtain call detail records of people contacting an FBI informant. By analyzing these records-showing call times, numbers dialed, call durations-I identified FBI agents, located their safe houses, and tracked their operations.
To truly disappear digitally, you must address three critical areas: removing your true IP address (your digital fingerprint that reveals your location and provider), obscuring your hardware and software configuration (which websites can detect), and defending your anonymity (by avoiding actions that link your physical and online presence).
The most effective tool for IP concealment is Tor (the onion router), originally developed by the US Naval Research Laboratory. Unlike standard browsing where your device connects directly to websites, Tor routes your connection through multiple nodes that change every ten seconds, making it nearly impossible to trace back to you.
Creating truly anonymous email requires starting fresh with each secure contact. Set up new accounts using Tor, avoiding any connection to your real identity. Maintaining anonymity demands perpetual vigilance-always access anonymous accounts through Tor, never search for anything related to your identity while logged in, and use end-to-end encryption for all communications.
Глава 4
Your Phone Is a Tracking Device
Cell phones are essentially sophisticated tracking devices. They constantly emit unique identifiers (IMSIs) that ping nearby cellular towers, creating detailed records of your movements. Law enforcement uses IMSI catchers to intercept these signals at events like rallies, identifying attendees without their knowledge. By analyzing data from multiple towers, authorities can triangulate your exact location through your phone.
Even "burner" phones aren't truly anonymous. Under the Communications Assistance for Law Enforcement Act, all phone IMSIs are reported regardless of payment method. Usage patterns can still reveal identity, as demonstrated by Australian drug dealer Pat Barbaro, whose multiple burner phones connected to the same towers as his personal phone, creating a traceable pattern that led to his conviction.
Cell phone technology has evolved from analog 1G networks in the 1980s to digital 2G networks in 1991 (introducing GSM, CDMA, and SMS), and now to 4G/LTE with 5G on the horizon. Despite these advances, all generations rely on the signaling system protocol (currently version 7 or SS7), which manages call routing between towers but also enables surveillance capabilities.
Security researchers Tobias Engel and Karsten Nohl demonstrated that SS7 vulnerabilities allow attackers to listen to calls, record encrypted communications for later decryption, and track any cell phone user's location. Using functions like call-forwarding through SS7, attackers can insert themselves into conversations, creating three-way calls where they silently monitor communications.
Voice over Internet Protocol systems use SDES encryption which has significant security flaws. Unlike true end-to-end encryption, SDES requires sharing encryption keys with carriers, creating vulnerabilities. When Bob calls Alice, the encryption key passes through both carriers, potentially exposing conversations.
Fortunately, Signal from Open Whisper Systems offers genuine end-to-end encryption for mobile VoIP. Its key advantage is that encryption keys are handled only between calling parties, not through third parties. Keys exist only on the devices, and are destroyed after each call. Signal also uses perfect forward secrecy (PFS), generating slightly different encryption keys for every call, ensuring that compromising one key doesn't expose other communications.
Глава 5
Securing Your Text Messages
Our unlocked mobile devices expose tremendous personal data, from emails and social accounts to banking information and intimate text messages. This vulnerability has serious real-world consequences, as demonstrated by numerous legal cases. In 2009, police accessed Daniel Lee's text messages after seizing his phone, then impersonated him to orchestrate a sting operation that led to multiple arrests. Similar cases have emerged where unlocked phones provided law enforcement with complete access to years of personal communications - all without requiring a warrant.
Text messages aren't truly point-to-point but pass through short message service centers (SMSCs) in plain, unencrypted text. While carriers like Verizon and AT&T claim they only retain texts briefly - typically 3-5 days - evidence suggests much longer retention periods. Court documents have revealed carriers storing messages for months or even years. More troublingly, documents exposed by Edward Snowden revealed the existence of NSA's secret rooms in AT&T facilities, designed to systematically filter and collect communications data through programs like PRISM and UPSTREAM.
To protect text messages, users should avoid native carrier messaging services - which offer minimal security - and instead utilize third-party apps with strong encryption. When evaluating security software, open-source and nonprofit options typically provide better protection than proprietary solutions for several reasons. They undergo constant peer review, security researchers can verify their claims, and they're less likely to include backdoors. My personal experience with Norton Diskreet in the 1990s illustrates this principle - after examining its source code, I discovered it only used 30 bits of encryption despite advertising 56-bit security, making it far less secure than claimed.
While popular messaging apps now commonly provide transport layer security - encrypting data in transit - many don't encrypt archived messages stored on their servers. Apps like AIM, BlackBerry Messenger, and Skype store message histories in unencrypted format, allowing service providers to read content and potentially share it with law enforcement, advertisers, or malicious actors. Even supposedly "deleted" messages often persist in these archives.
The most secure messaging apps provide true end-to-end encryption where encryption keys exist only on user devices. Look for apps implementing the Off-The-Record (OTR) messaging protocol, which provides encryption, authentication, deniability, and Perfect Forward Secrecy (PFS). PFS ensures that if an encryption key is compromised in the future, it can't be used to decrypt past messages. Recommended options include:
• ChatSecure: Works on Android and iPhone, featuring certificate pinning and encrypted conversation logs
• Signal: Created by Open Whisper Systems, available for iOS and Android with robust security features
• Cryptocat: Supports iPhone and major browsers with user-friendly encryption
• Tor Messenger: Adds IP address anonymization to prevent tracking
These apps are superior because they ensure message privacy even if service providers' servers are compromised through hacking or legal demands. With traditional messaging services, your conversations remain vulnerable to both authorized and unauthorized access. End-to-end encryption puts you in control of your communications rather than forcing you to trust third parties with your private conversations. This is particularly crucial for sensitive personal, business, or political communications where privacy is paramount.
Глава 6
Navigating the Web Without Leaving Traces
Deleting your browser history can be a criminal offense in the United States under the Sarbanes-Oxley Act of 2002. This law, created after the Enron scandal, requires data preservation including browser histories. Khairullozhon Matanov was sentenced to thirty months in prison partly for deleting his browser history after dining with the Boston Marathon bombers, while college student David Kernell faced similar charges for clearing his browser after hacking Sarah Palin's email.
Since you can't legally delete your browser history, consider using private browsing modes available in Firefox, Chrome, Safari, and Microsoft browsers. These modes don't record your search history during a session, though your ISP can still see your traffic. For better protection, use HTTPS Everywhere, an EFF browser plugin that forces encrypted connections whenever possible.
Remember that browsers track your location through IP addresses. When sites request your location, you can disable this feature in browser settings. In Firefox, type "about:config" and disable "geo" settings. In Chrome, go to Options>Under the Hood>Content Settings>Location. You can even fake your location using plugins like Geolocator or Chrome's Developer Tools.
Beyond hiding your location, you can obscure your IP address using Tor or proxies. Proxies act as intermediaries between you and websites, but they're not bulletproof-each browser must be manually configured, and clever Flash or JavaScript can still detect your real IP address. Be wary of free proxy services-they often push advertising and can even be malicious.
Browser synchronization creates serious privacy risks. When you sign into Chrome or Firefox across devices, your bookmarks, history, and preferences follow you-convenient but dangerous. If you log into your Google account on a public terminal and forget to sign out, your entire browsing history becomes available to the next user.
Syncing also means all interconnected devices show the same content. This led to disaster for Elliot Rodriguez, who gave his old tablet to his eight-year-old daughter while keeping it connected to his iCloud. When he took intimate photos with his mistress in New York, they automatically synced to his daughter's iPad in Colorado, exposing his affair.
Even if you delete browser history locally, copies remain in the cloud. This can have serious consequences, as Michele Catalano discovered when Homeland Security agents showed up at her home questioning her family's searches for pressure cookers and backpacks shortly after the Boston Marathon bombing. Though innocent-she wanted to cook quinoa and her husband needed a backpack-their combined searches triggered an investigation.
To protect yourself, use Google's privacy tools to turn off personalized ad tracking and search history. Better yet, don't log into accounts while searching, or use privacy-focused alternatives like startpage.com or DuckDuckGo. Unlike major search engines, DuckDuckGo doesn't track users or filter results based on past searches, avoiding the subtle censorship that occurs when search engines decide what you might want to see.
Глава 7
The Invisible Web of Tracking
Be extremely cautious about what you search for online-every website tracks your habits. Even health websites expose private information, with 70 percent of health site URLs containing specific conditions or treatments in plain text. While HTTPS Everywhere encrypts site content, it doesn't hide the URL itself.
When you visit a website, your browser uses Domain Name Service (DNS) to translate the hostname into a numerical IP address-like translating "Google.com" to https://74.125.224.72. After connecting to the server, your browser receives information to build the webpage, but often this includes hidden elements that call out to other websites for additional scripts or images, many designed specifically for tracking your behavior.
Your browser reveals extensive metadata about your computer configuration-browser version, operating system, add-ons, screen resolution, and memory capacity-creating a surprisingly unique digital fingerprint that can identify you across websites. Sites like Panopticlick from the Electronic Frontier Foundation can reveal how unique your browser configuration is compared to others.
Marketers and hackers employ invisible techniques like one-pixel image files (web bugs) that silently call back to third-party servers, recording your IP address and interests. Nearly half of third-party tracking requests use blank pop-up windows that generate silent http requests, while another third use small JavaScript files that can identify your computer through its IP address.
Mozilla's Firefox offers NoScript, a powerful plug-in blocking potentially harmful elements like Flash and JavaScript. Chrome users can employ ScriptBlock for similar protection. For complete coverage, Adblock Plus blocks dangerous ads, though it does track browsing history. Ghostery identifies and blocks web trackers while giving you control over which to allow.
Cell phones aren't immune to tracking. AT&T and Verizon were caught appending unique identifier headers (UIDH) to every web page request made through mobile browsers-temporary serial numbers that advertisers use to identify users. These codes tracked users without their knowledge, even those using privacy plug-ins.
Cookies are text files passed from websites to your browser, storing preferences and authentication data. Originally created for e-commerce functions like shopping carts, they now enable sites to remember your preferences and track your visits. While not inherently dangerous, cookies provide valuable tracking data that companies store in customer record management systems.
Facebook has expanded beyond social media into an authentication platform, with 88 percent of US consumers using existing social network identities to log into websites and apps. This OAuth protocol offers convenience but sacrifices privacy, allowing Facebook to collect information about all sites where you use its login. Facebook's tracking continues even after logout, monitoring your location, site visits, and clicks to deliver personalized ads.
Even with private browsing and cookie deletion, websites can still track you through HTML5 features like canvas fingerprinting. This technique invisibly draws a unique image in your browser, converts it to a number based on your hardware and software configuration, and uses this identifier across websites. Cross-device tracking companies like Drawbridge, Tapad, and Oracle's Crosswise go further, linking your activities across phones, tablets, and computers through machine learning and IP address matching.
Глава 8
The Internet of Things: A Privacy Nightmare
The evolution of household devices from simple manual tools to internet-connected smart appliances has created new privacy and security vulnerabilities. What began with programmable thermostats has evolved into a world where our homes are filled with devices constantly collecting and transmitting data about our personal habits to companies like Google, who eagerly seek to dominate the Internet of Things marketplace.
Once-simple devices like thermostats have become security risks. Researchers at Black Hat USA 2014 demonstrated how Nest thermostats could be compromised with physical access, creating what one researcher called "a literal fly on the wall" that users couldn't protect with antivirus software. Despite Nest's reassurances about remote security, the researchers found they couldn't disable the automatic reporting feature sending data back to Google without creating their own tool.
Beyond direct attacks on home systems, insecure Internet of Things devices can be hijacked into botnets-armies of compromised devices under central control. The October 2016 attack on Dyn, which disrupted major websites across the eastern United States, used the Mirai malware to commandeer devices like CCTV cameras, routers, DVRs, and baby monitors through simple password guessing.
Baby monitors present serious privacy concerns. Analog models use retired wireless frequencies (43-50 MHz) easily intercepted with cheap radio scanners. Digital monitors offer better security but require immediate firmware updates and password changes. The Belkin WeMo monitor has a critical design flaw-once an app connects to it on your home network, it remains active from anywhere in the world.
Voice-activated TVs listen continuously for wake commands, recording everything spoken after activation until turned off. Disturbingly, Samsung TVs transmit these recordings unencrypted to both Samsung and voice-recognition company Nuance. This allows potential eavesdropping by anyone on your network. While Samsung offers ways to disable voice recognition through settings, companies like Sensory are pushing for TVs that remain "always on, always listening."
Amazon Echo constantly listens for wake words while potentially recording other conversations. Though Amazon provides ways to delete voice data, it's unclear what happens during device "downtime." Samsung's Internet-connected refrigerators, despite using encrypted connections to Google Calendar, failed to properly verify certificates-allowing man-in-the-middle attacks that could steal Google credentials.
Home webcams pose significant privacy risks when misconfigured. The Shodan search engine exposes countless Internet-connected devices with minimal security, including approximately 100,000 webcams transmitting daily. D-Link cameras without default authentication are particularly vulnerable, allowing attackers to access private video streams through simple Google searches.
Глава 9
Becoming Invisible: A Comprehensive Approach
To truly disappear online requires creating a completely separate identity unrelated to your real self, which demands rigorous discipline and specific equipment.
For true anonymity, purchase a separate low-cost Windows or Linux laptop with cash in person (not online). Never use this device for personal activities-a single login to personal email destroys anonymity. Avoid creating Microsoft accounts during setup. Install Tails and Tor instead of using the native operating system. Never use this laptop at home or work, as your service provider could capture your MAC address. Change your MAC address each time you connect to public Wi-Fi to prevent tracking through network logs.
To avoid being traced through financial transactions, use a "cutout"-someone hired anonymously to purchase prepaid gift cards like Vanilla Visa or Vanilla MasterCard from retail stores. Avoid refillable credit cards that require identity verification under the Patriot Act.
When connecting to public Wi-Fi, sit in adjacent businesses to avoid surveillance cameras that might capture your presence. Consider hiring a second cutout to purchase a personal hotspot from a cellular provider, allowing internet access without relying on public networks. Never use a personal hotspot in a fixed location for too long, as this was how Mitnick himself was caught-through radio-direction finding techniques that located his cellular signal.
Always use Tor browser to create and access online accounts, as it constantly changes your IP address. Set up multiple anonymous email accounts through services like ProtonMail or Tutanota that don't require phone verification. For Bitcoin transactions, convert prepaid gift cards to Bitcoin (at a premium cost of around 50-70%), then use "tumbler" services to launder the cryptocurrency, obscuring the original ownership.
The most critical aspect of digital invisibility is maintaining absolute separation between anonymous and real identities. A single slip-using your anonymous hotspot at home or powering on personal devices near your anonymous setup-can destroy your entire operation. Forensic investigators can correlate your presence by analyzing cellular provider logs.
While perfect invisibility is nearly impossible against a persistent attacker with sufficient resources, creating enough obstacles will deter most threats. The level of anonymity needed varies by situation-from basic password protection to complete identity separation for whistleblowers.
We must think proactively about our digital footprints, realizing that even seemingly benign actions-sharing photos with addresses visible, providing real birth dates on social media, browsing without HTTPS Everywhere, sending unencrypted communications-carry lifelong ramifications. This book aims to help everyone stay online while preserving their essential privacy through the art of invisibility.