
We leave many digital traces on the Internet: names and surnames, dates, information about family and work, stories about habits and hobbies, data about property and location, photographs of ourselves and our loved ones. Most often, this does not bother us, does not affect business or online entertainment. But if a motivated attacker is included in the game, the situation is changing. Such a character can collect a lot of personal data in order to provoke persecution or cruel injury. This is called "Doxing". Our expert Sergei Smirnov thinks about how to reduce the risks.
Once a warm August evening in 2017, an employee of the University of Arkansas Kyle Kuinn visited his friends with his wife. The phone rang. The excited colleague was looking for Kyle: “Urgently look at Twitter!” Kyle did this and was stupid. Twitter was full of fierce and contemptuous messages addressed to him. The same thing was going on in the email box. In the photograph that was scattered throughout the Internet, Kuinn was captured with a torch on the march of the “ultra -right”. Someone found and published his home address. Strangers demanded that Racist Quinna be immediately fired from the university. Threats poured. Fearing for their lives, the couple decided to spend the night with friends.
At his native university, Kyle Quinn was engaged in the problems of diagnosis and treatment of complications of diabetes. He had nothing to do with the racists and did not participate in the march. But online activists did not know this. They compared the ill -fated photograph with open data from the Internet. External resemblance (complexion, hair color, beard) and T -shirt with the inscription "Arkansas" pushed the pursuers to the conclusion that in the photo it was Kuinn. The poor fellow became a victim of a doxing error.
“Draw and make public” - this is what “doxing” is. Information about a person is collected on social networks, forums, chats. Data from different sites is compared, analyzed, clarified. In addition to collecting public information, hacking, social engineering, and phishing can be used. The doxers are not easy to identify a person - they publish his personal information, compromising materials, or transmit them to someone who resolutely takes the matter into their own hands. The ultimate goals: to attract the attention of the public, organize a tough campaign of pressure and persecution, call on the state or some group to bring down force on the sacrifice. Network conflicts and persecution are powerful weapons. They are often not limited to the network and can break life to a person.
In December 2017, 18-year-old Casey Weiner from Ohio and 20-year-old Shane Gaskill from Kansas played the team network shooter Call of Duty. They virtually shot each other and lost the mission, and with it a monetary rate. The furious Weiner dumped the guilt on Gaskill and threatened that he would deal with him in the real world. Gaskill dictated his address with a mockery and said that he would wait. Weiner contacted his reckless friend Tyler Barriss, who lived in California, behind which the tail of criminal stories reached out. Barris called Kanzassian cops from a public telephone, called himself a fictional name and said: the murder occurred at such an address, and the killer holds two more people under the sight. The police rushed to the place. Alas, they were not at all prepared for operations to free hostages. One of the police officers opened fire and shot the owner of the house. The 28-year-old father of two children, Andrew Finch, was killed, who had nothing to do with this whole story. Gascill called the wrong address. The amount of the rate due to which the players quarreled was one and a half dollars.

In Russia, LGBT activists become victims of online persecution. Members of Nazi, Xenophobic groups, as well as just online cheaters repeatedly engaged in doxing-posted the addresses and phones of participants in the LGBT community with hints or even direct calls to people to “pay a visit” to their enemies. In 2018, the site of the “homophobic game of saw” even appeared, where money was offered for the beating of people of “non -traditional orientation”. The site, in particular, told about individual LGBT activists, their photos and contact information were published.
In July 2019, journalists suggested the connection of the “saw” with the murder of civil and LGBT activists Elena Grigoryeva in St. Petersburg. On the website of the "saw" of Grigoryeva was designated as one of the "targets". For her civil position, the woman was repeatedly subjected to threats and pressure of haters, including online. The Russian LGBT network has released a brief legal memo on how to act if you notice a site like a “saw”.
Doxing is not always purely negative. For example, the dissemination of data on the Reutov stomach Daria Smirnova , who tormented animals and threatened the zoo defenders (2018), ultimately made it possible to catch a sadist and her accomplice (they were hidden under pseudonyms) and hold them accountable. On social networks, photos, the address of the place of work and the details of the biography of Smirnova were distributed.
Sometimes doxing is considered to be the disclosure of only confidential information, for example, data from the patient’s medical card, but this is a mistake. Doxing involves the disclosure of any information about the victim that facilitates the task of the pursuers. For example, if a person has a car, this is usually no secret to anyone. However, the disclosure of details in the appropriate context can lead to the fact that the attackers will damage or destroy the car parked in the yard.
The legal side of the doxing is not easy. Usually we can talk about violation of the legislation on personal data. But when it comes to the consequences, it is difficult to hold a specific villain to justice. As in cases of persecution (stalking) or bullying (bullying), law enforcement agencies allow the application of Article 119 of the Criminal Code of the Russian Federation (“threat of murder”) only on condition that the threat “can be realized” . Persistent messages in WhatsApp, notes in the mailbox and aggressive comments on the social network, as a rule, are not considered sufficient grounds for initiating a criminal case. “Suitable” except that the outbreak of the door with an ax, as in the film “Shine”, and even then in the presence of witnesses.
Alas, a person usually gets acquainted with the concept of doxing, already sharing a fair amount of data about himself with the Internet.
Self-clinking is an independent formation of the picture "What they can find about me on the Web." Imagine yourself in the place of an attacker who intended to put a pig for you or fulfills someone's order. To what information, where and how will he get? In the course of the case, you can try to delete some data and change the settings of accounts.
Looking through the network in search of information about yourself, you may want to save some of the discovered documents, photos, video files, hyperlinks, as well as make text notes. Probably, these data will contain private information about you. In order not to multiply risks, it is better to maintain the collected data on a protected (for example, encrypted) medium.

During a self-clicking, you should not create a new “digital trace”, so use a protected browser, for example, Tor .
“When you arrange a“ hunt for yourself ”, there is a risk of finding something unpleasant, ” experts from the organization of Access Now. “If you feel that you may need emotional support, make sure that close people are nearby.”
Perhaps the main source for doxing is publicly available profiles and publications on social networks and on different discussion venues. By the way, there is often a conflict that pushes the attacker to seek and analyze information about the victim. View all your accounts one by one: Facebook, Vkontakte, Instagram, Twitter, dating sites, travelers, sites dedicated to your hobby, in a word, wherever you filled the registration questionnaire, invented logins and passwords and at least spent a noticeable time. It will be easier for users of password managers to do this, having on hand the entire list of such resources. Get rid of extra data. It is amazing how many people who are not engaged in journalistic activities or public policies that are not “celebrity” or officials of their organizations and companies consider it necessary to inform the world about each change of work indicating the position.
You can not only remove unnecessary personal information from the profile, but also if you want to “twist” the account settings to make it less public. Here are some possible changes for Facebook:

Facebook admits the limitation of the audience of previously published messages. The “Journal of Actions” will help manually look for among the previous publications those where personal information may have been revealed. Both Facebook and VKontakte allow you to download all your information entirely, which can be useful for self-classing.
Hard settings are not suitable for everyone. The choice depends on your risk model. So, a journalist who needs to be easier to find potential sources of information, is unlikely to want to "go into the shadow."
More on the topic: Video lesson of the greenhouse: Protect your traffic using the HTTPS EVERYWERE plugin
Particular attention should be paid to the photo. An innocent personal picture is able to reveal such details as the appearance of the house and entrance, the brand and car number, the favorite place of the evening walk. Many are happy to share photos of children and grandchildren, but is it so safe? If you are in a “risk group” because of a kind of activity, denomination or anything else, or you are brewing a personal conflict with a potentially dangerous person, a child can become a simpler target than you yourself. Should I share private photos with the whole world of those who cannot protect themselves?
The search within the resources themselves, in particular, social networks, is useful. Yandex even has a search service for several popular social networks at once, try.
Have you met information that should not be on a particular site?
Unused, outdated accounts make sense to simply delete. Read about this procedure first. What time will the removal take? Will backups and magazines (logs) be removed? How about your comments and correspondence with other service users? You may have to remove something manually.
And let's publish personal information only for online “friends”, not for everyone, and the doxing will disappear. Yes?
Unfortunately no.
The first reason is the reckless addition of unfamiliar and completely strangers to the “friends”, among whom a person may be, to put it mildly, you are not sympathetic. “Squeezing” to read “sub -subsidiary” messages, is a common practice in social networks.
The second reason is the vulnerability of friends themselves. If the attacker one way or another receives access to the account of your online “friend”, he will see all your “friendly” publications.
Do not rely on the filter “only for friends” as a guarantee of security. Feel free to go through the profiles of “friends” that they write in their ribbons (or why they don’t write at all), see with whom they lead network friendship, in which groups they are. Do not add to your friends anyone.
Try to use search engines to find information about yourself on the Internet. Start with the usual text search for Google and Yandex . What are we going to look for? Your name and surname, nickname, the city where you live, the name of the organization/editorial office where you work, email address, phone number. Combining this data, an attacker can reach other information. Will he get something on you?
For a more successful search, you can use operators and clarify requests .
Use the search for the pictures (your photo, avatar). Such services usually offer to download an illustration or, if it is already posted on the network, enter the address:

Having discovered your personal information on any site, which, it seems to you, there is no place there, you can try to delete it. Of course, when it comes to the Internet, you have to take the word “delete” in brackets: what has been published at least once, it can be copied, archived, stored in the cloud in the form of backups (to which no search engine will get to the contents) or offline. But still you can reduce the chances of dark forces. Less prepared and motivated attackers, having failed at the first steps, can abandon their plan.
Look at your employer's website. Is there information about you there? Does this publication reveal any excess details? (For example, your hobby or marital status.)
If you have your own business card site, pay attention to published data about your life, career, interests.
Are you the owner of the domain name and indicated when registering your data (name, surname, mailing address, email address)? Any Internet user directly from the browser can make a request to the Whois database regarding any domain. If your domain in the .ru or. RF zone, information about you will not be “declassified” (the observer will only see the line “private face”). But if you own a domain name, for example, in the .org zone, your name will be visible. Until 2018, Whois requests also allowed to see contact information (up to the home address), now - no. If the connection of the domain and your name creates risks for you, think about contacting the company where the domain name is registered (the company you regularly pay for the support of the domain), and find out if it can provide protection of your personal data. Large domain name registrars have such services (for example, NameCheap has such a service called Whoisguard, for Godaddy - Domains by Proxy).
There are special resources that store the history of changes in the entries of the base of Whois (Domaintools, Domainiq). They allow subscribers on a paid basis to view the data of the owners. If the attacker is motivated enough to upload money for such data, he can use such a service. Protecting privacy from the domain registrar (in the previous paragraph) will help, but if the data was previously opened, there is a chance to detect them in such a service.
There is a motley fair of all kinds of state and commercial institutions, where our compatriots endlessly present documents and fill out questionnaires. Motorists, survey holders, customers of railway tickets, bank account owners, individual entrepreneurs, participants in discount programs, promotions and lottery, hotel guests, premises of parcels and parcel, all those who are supposed to be preferential medicines, who arrange a child in school or draw up a mortgage - all of them reserve a trace of personal data. And, of course, there are databases formed against our desire. Some of these bases are openly published on the Internet, for example, you can look for people in the Russian bailiff base .
Caution should be treated with inviting promises like “instant search in the base of the Ministry of Internal Affairs” and “we will find any person by name”. Fraudsters often act on this field. If you see a free service with such a design, then it usually does not work, or relies on outdated bases, unknown by anyone and how to do not know who and how. Впрочем, есть вероятность, что и злоумышленник отправится тем же путем, поэтому можно попробовать бесплатные сервисы просто чтобы убедиться: ваших данных там нет.
Another topic: where will your digital traces lead?
Иногда в публичном доступе оказываются «взломанные» или «слитые» базы. (Владельцы ресурсов, бывает, не спешат объявить об этом пользователям.) Американский аналитик Трой Хант поддерживает сайт «Have I Been Pwned?» . Я наудачу указал в форме один из своих электронных адресов и узнал, что он был в базе музыкального сайта Last.fm, взломанной несколько лет назад. Что-то подобное случилось с вашим адресом email? Как минимум это причина, чтобы сменить пароль, установить в соответствующем аккаунте двухфакторную аутентификацию (если есть такая возможность), а то и просто удалить аккаунт. Но, увы, сам факт вашей связи с конкретным сайтом станет известен злоумышленнику – запрос может сделать любой.
Поговорку «что упало, то пропало» удачно иллюстрирует интернет-архив archive.org . Если вы еще не пользовались его инструментом Wayback Machine, попробуйте. Сайт содержит миллиарды копий веб-страниц. С помощью Wayback Machine можно увидеть, что представлял собой сайт два, пять и даже десять лет назад. Для этого достаточно ввести адрес нужной страницы в форму.

Не все страницы индексируются. Если вы убрали какие-то данные со своего сайта, но по-прежнему видите их в копиях на archive.org, попросите администратора вашего сайта разобраться – он знает как (подсказка: внести изменения в файл robots.txt). Будьте готовы к тому, что для достижения результата, возможно, придется переписываться с администраторами archive.org (некоторые владельцы сайтов жаловались на неповоротливость технического решения). Когда в ответ на запрос в Wayback Machine вы увидите строчку «This URL has been excluded from the Wayback Machine», это значит, что результат достигнут.
Юридически в соответствии со ст. 9 Федерального закона РФ № 152 «О персональных данных» при предоставлении персональных данных вы даете свое согласие, которое в соответствии с частью 2 этой статьи может быть вами отозвано. Даже если сервис не предлагает удобной формы удаления данных, вы можете использовать это свое право, написав его владельцам и сославшись на эту статью. Некоторые сайты и сервисы содержат описание процедуры удаления персональных данных в своих пользовательских соглашениях, а учреждения предлагают вам подписать документ о согласии, где мелким шрифтом написано, как это согласие можно отозвать. Так, например, поступают частные клиники. (Вот пример заявления на отзыв согласия на обработку персональных данных от Ситибанка.)
В некоторых случаях отзыв не поможет. Закон позволяет оператору (тому, кто обрабатывает ваши данные и, в частности, хранит их) продолжать свое дело. Список исключений содержится в той же статье 9 закона «О персональных данных», он довольно велик и включает, например, ситуацию, когда вы сами опубликовали свои данные для неограниченного круга лиц.
«Все пользователи услуг связи на территории России находятся (должны находиться) «под колпаком» СОРМ (система технических возможностей оперативно-розыскных мероприятий), – дополняет главный инженер хостинговой компании «Комтет» Михаил Ивановский. – Оператор связи передает на оборудование СОРМ регистрационные данные клиентов и их платежей, журналы доступа и весь трафик, включая голосовые звонки и переписку по открытым каналам. То есть все наши действия в сетях связи. СОРМ курируется сотрудниками ФСБ. Запретить оператору связи этим заниматься или добиться удаления уже собранных персональных данных от ФСБ не выйдет. Кто, когда и как с помощью СОРМ получал доступ к вашей переписке, переговорам и другим вашим данным – вы не узнаете. Предотвратить такого рода вторжение в частную жизнь со стороны государственных органов можно, используя защищенные каналы связи, шифрование, VPN».
Все рекомендации, которые специалисты по безопасности публикуют в связи со сталкингом, буллингом, доксингом и онлайновым шантажом, содержат настойчивую просьбу не делиться в Сети избыточной информацией о себе и своих близких. И это действительно хороший совет. Люди часто забывают про него, потому что ощущают себя комфортно «здесь и сейчас» в атмосфере обжитой «онлайновой комнатки», где собеседников всего несколько человек и каждому можно доверять. Но злоумышленник может получить доступ к аккаунту вашего друга, которому вы отправляли интимные фотографии. Или вы пропустите строчку мелким шрифтом в пользовательском соглашении (которое, кстати, владелец сервиса может менять по своему усмотрению), и данные о вашей учебе, семейном положении, хобби, поездках и планах утекут третьей стороне. Если можете не делиться персональными данными – не делитесь.
More on the topic: Binding of accounts: risks and recommendations
В некоторых случаях бывает разумно указать не настоящее имя, а псевдоним, да и обнародовать адрес email не всегда есть смысл.
Успех доксинга зависит от способности злоумышленника связать разные данные о вас между собой, а затем сопоставить онлайновый профиль с реальной личностью. Вы можете этому превентивно противостоять: снижайте связанность данных. Старайтесь не оставлять однотипных «цифровых следов», например, не использовать один и тот же никнейм/логин или пароль на разных сайтах. Избегайте ситуации, когда несколько важных аккаунтов оказываются привязаны к одному адресу email или телефону. Ранее мы подробно писали, почему бывает опасно связывать аккаунты и как этого избежать .
Вам не удастся гарантированно достичь полной сетевой анонимности. Тем не менее с помощью селф-доксинга можно обнаружить и прекратить утечки данных, изъять некоторые данные из Сети (это может остановить злоумышленников с невысокой подготовкой и мотивацией) и сделать себе пометку на будущее: не стоит рассказывать все о себе на каждом углу. Просто ради безопасности.
Автор благодарит руководителя хостинг-компании «Комтет» Михаила Ивановского за помощь в работе над статьей.