We recently alerted our members to a datamining attack against our board, which we successfully shut down by locking registration and banning suspicious users. Our response was so effective that the attackers deleted the threads about raiding our site.
However, we cannot keep registration disabled forever. We will re-enable registration on August 29th, and future attacks are inevitable.
We have made changes to forum permissions that make it much more cumbersome to datamine our members. In particular, those who are not Senior Members will be unable to view user profiles or search the board.
This remains a primarily public board, however, and public posts can still be viewed by anyone or scraped by tools. Therefore, you should read this quick guide on beating datamining attacks.
First of all, don't use the same username on sites linked to your real identity, for obvious reasons. Do not even use the same e-mail address to register for MAP and non-MAP sites or accounts. Tools exist that allow attackers to search for data leaks by e-mail address. This attack has been attempted against me, but it failed because I maintained 100% separation.
You should also drop lots of unimportant misleading information. If you're 44 years old, write in your signature that you're 47. And if you were born in the summer, update your age in the winter. If you are half-Latino, let slip that you're fully Caucasian. If your favorite food is pizza, casually refer to it being steak. If you live on the east coast of the USA, drop hints that you're on the west coast. If you're skinny, make a reference to trying to lose weight. Why bother? Because datamining works best when lots of details add up, and it fails spectacularly when many little details are wrong.
Attackers have been analyzing my posts as far back as 20 years ago, and they have been unable to identify me. Likewise, an attempt at doxxing a BoyChat member is failing because some details the poster 'dropped' over the past 25 years were probably misleading. This comment demonstrates everything; the attacker had posted a very detailed summary of all the major and minor details he thought he had on the target, and was unable to locate a match.
Finally, don't communicate via messengers. A likely attacker recently e-mailed me and shared his Telegram ID. Nope!
Staying safe on Mu's MAP Forum
- BLueRibbon
- Posts: 1617
- Joined: Sat Jun 29, 2024 12:03 pm
Online
-
Theendoftheline
- Posts: 220
- Joined: Fri Apr 03, 2026 8:38 pm
Re: Staying safe on Mu's MAP Forum
What did said attackers say in their post? Do we have screenshots? I'm curious!
