Someone posted a thread earlier about how hard it is to keep forum users' PGP keys straight with identities elsewhere. I thought I'd share a little of the other side of that coin. Many of the older posters here remember Pine's post from the old forum about how the keyid of a PGP key can tell you a lot. I just wanted to make a brief Public Service Announcement about something even more obvious than that:
When you create a PGP Key, and stick a real personal email address in there, then post that key on your profile on a fucking darknet forum, that personal email address is visible to everyone who sees your key.So after SRFv1 went away, I decided to do my own archiving of forums that I like, because I'm sick of shit disappearing. Around the time the whole "DPR account may be compromised" thing unfolded, I grabbed another full copy of the forum and the user profiles.
I decided to take a quick crunch through the PGP keys in the user profiles here, extracting the email addresses from the PGP key metadata. The data I'm pasting below represents the most common legitimate domains (the part after the '@') for email addresses in PGP keys posted here, with counts of how many times they're used. My source data is a couple weeks old.
While many of the GMail/Hotmail/Yahoo/etc addresses are obviously bullshit or burners (somebody just sticking '@gmail.com' at the end to fill up space), some quick Internet stalkery told me that more than you'd figure are actually people's real personal email addresses. That match Facebook/etc accounts. With pictures. None of the ones I found turned out to be beautiful blonde women, by the way.
36% of the PGP keys posted to user profiles here (as of a week or two ago, whenever I scraped it) have email addresses in the domains listed below.
There were plenty of 'nickname@silkroad.onion' addresses. That's a perfectly good approach. Just don't use anything that actually ties to your real identity.
When you're creating a key, and it asks for an email address, give it a fake one, please.536 safe-mail.net
325 gmail.com
86 hotmail.com
77 hushmail.com
58 yahoo.com
34 riseup.net
28 countermail.com
24 live.com
23 lelantos.org
20 aol.com
18 outlook.com