惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MongoDB | Blog
MongoDB | Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
小众软件
小众软件
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - Franky
博客园 - 聂微东
V
Visual Studio Blog
I
InfoQ
罗磊的独立博客
Security Latest
Security Latest
G
Google Developers Blog
博客园_首页
P
Proofpoint News Feed
T
Threat Research - Cisco Blogs
D
DataBreaches.Net
PCI Perspectives
PCI Perspectives
Forbes - Security
Forbes - Security
P
Proofpoint News Feed
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Know Your Adversary
Know Your Adversary
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Recent Commits to openclaw:main
Recent Commits to openclaw:main
The Cloudflare Blog
AWS News Blog
AWS News Blog
Latest news
Latest news
T
Tailwind CSS Blog
P
Palo Alto Networks Blog
Hugging Face - Blog
Hugging Face - Blog
云风的 BLOG
云风的 BLOG
Cyberwarzone
Cyberwarzone
T
The Exploit Database - CXSecurity.com
WordPress大学
WordPress大学
Recorded Future
Recorded Future
A
Arctic Wolf
V
Vulnerabilities – Threatpost
Security Archives - TechRepublic
Security Archives - TechRepublic
宝玉的分享
宝玉的分享
人人都是产品经理
人人都是产品经理
月光博客
月光博客
有赞技术团队
有赞技术团队
P
Privacy & Cybersecurity Law Blog
Scott Helme
Scott Helme
美团技术团队
Hacker News - Newest:
Hacker News - Newest: "LLM"
Jina AI
Jina AI
N
News and Events Feed by Topic
Attack and Defense Labs
Attack and Defense Labs

Hacker News

Introducing Claude Opus 4.7 Qwen Studio The Future of Everything is Lies, I Guess: Where Do We Go From Here? GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis Bonsai 1-bit WebGPU - a Hugging Face Space by webml-community Moving a large-scale metrics pipeline from StatsD to OpenTelemetry / Prometheus GitHub - Nightmare-Eclipse/RedSun: The Red Sun vulnerability repository GitHub - SethPyle376/hiraeth: Local AWS emulator focused on fast integration testing, with SQS support, SQLite-backed state, and a debug-friendly web UI. GitHub - macOS26/Agent: Any AI, replaces Claude Code, Cursor, OpenClaw. Over 18 LLM providers (Claude, OpenAI, Gemini, Ollama, Zai, HF, Qwen) wired into a native Mac app that writes code, builds Xcode projects, bumps versions, manages git, automates Safari, use AppleScript, JS or Accessibility, extend Agent! w/ MCP Servers, run tasks from your iPhone via Messages. YouTube now lets you turn off Shorts I Made a Terminal Pager Burgers | マクドナルド公式 Commands — HackerNews CLI documentation ChatGPT for Excel PiCore - Raspberry Pi Port of Tiny Core Linux Live Nation illegally monopolized ticketing market, jury finds Google Broke Its Promise to Me. Now ICE Has My Data. Founding Engineer at Adaptional | Y Combinator CRISPR takes important step toward silencing Down syndrome’s extra chromosome GitHub - saffron-health/libretto: The AI toolkit for building reliable browser automations US v. Heppner (S.D.N.Y. 2026) no attorney-client privilege for AI chats [pdf] Retrofitting JIT Compilers into C Interpreters IPv6 – Google The Accursèd Alphabetical Clock Cybersecurity Looks Like Proof of Work Now Fragments: April 14 Cal.com Goes Closed Source: Why AI Security Is Forcing Our Decision | Cal.com - Scheduling Software for Online Bookings Laravel raised money and now injects ads directly into your agent When moving fast, talking is the first thing to break Too much Discussion of the XOR swap trick – Heather Cafe Introduction to Spherical Harmonics for Graphics Programmers The Grand Line Building a Z-Machine in the worst possible language High-Level Rust: Getting 80% of the Benefits with 20% of the Pain GitHub - duguyue100/midnight-captain: Inspired by Midnight Commander, tailored to my taste. How to build a `git diff` driver · Jamie Tanna | Software Engineer Center for Responsible, Decentralized Intelligence at Berkeley The Local Universe’s Expansion Rate Is Clearer Than Ever, but Still Doesn’t Add Up - A new synthesis of astronomical measurements confirms a persistent mismatch that could point to physics beyond current models The air throughout our homes is infused with microplastics. But there are things you can do to breathe less of them The disturbing white paper Red Hat is trying to erase from the internet – OSnews The Future of Everything is Lies, I Guess: Annoyances ‘Abhorrent’: the inside story of the Polymarket gamblers betting millions on war Productive procrastination — Max van IJsselmuiden maps, territory and LMs 447 Terabytes per Square Centimetre at Zero Retention Energy: Non-Volatile Memory at the Atomic Scale on Fluorographane Show HN: Pardonned.com – A searchable database of US Pardons 20 Years on AWS and Never Not My Job The Seasons are Wrong Artemis II crew splashes down near San Diego after historic moon mission We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs How a dancer with ALS used brainwaves to perform live On filing the corners off my MacBooks Installing every* Firefox extension OpenClaw’s memory is unreliable, and you don’t know when it will break Steve Blank Nowhere Is Safe Chimpanzees in Uganda locked in vicious 'civil war', say researchers watgo - a WebAssembly Toolkit for Go linux/Documentation/process/coding-assistants.rst at master · torvalds/linux GitHub - callumlocke/json-formatter: Makes JSON easy to read. Founding Product Engineer at Bild AI | Y Combinator A compelling title that is cryptic enough to get you to take action on it GitHub - Keychron/Keychron-Keyboards-Hardware-Design: Industrial design files for Keychron keyboards and mice. 100+ models with CAD assets in STEP, DXF, DWG, and PDF. Source-available, with commercial use allowed for original compatible accessories within the license terms. [ANNOUNCE] WireGuardNT v0.11 and WireGuard for Windows v0.6 Released 1D-Chess Helium Is Hard to Replace Cooperative Vectors Introduction | Evolve Keeping a Postgres queue healthy — PlanetScale Our response to the Axios developer tool compromise Do Americans read print books, e-books or audiobooks more? The Zettelkasten Method in Obsidian: A Practical Setup Guide Artemis II Is Competency Porn and We Are Starving For It WeakC4 Flight Viz — Cockpit View A Mexican surveillance giant you’ve never heard of is now watching the U.S. border Surelock: Deadlock-Free Mutexes for Rust RISC-V 101 – what is it and what does it mean for Canonical? | Ubuntu The Problem That Built an Industry How Much Linear Memory Access Is Enough? | Solidean Investigating Split Locks on x86-64 Simplest hash functions Sybilproof reputation mechanisms (2005) [pdf] What is a property? How Complex is my Code? Static code analysis in Kotlin — tools overview Toffoli gates are all you need PGLite evangelism dcmake: a new CMake debugger UI Clojure on Fennel part one: Persistent Data Structures Fragments: April 2 Python Release Python install manager 26.1 The Life and Death of the Book Review - Liberties Introducing Database Traffic Control — PlanetScale Bitcoin miners are losing $19,000 on every BTC produced as difficulty drops 7.8% God sleeps in the minerals Building slogbox Apple Silicon and Virtual Machines: Beating the 2 VM Limit Who was “Not Even Wrong” first? Pokemon Evolution Vs Darwinian Evolution The APL Programming Language Source Code
Should you leave red herrings about yourself online?
2026-05-11 · via Hacker News

Short answer: for most people, no. Planting fake jobs, cities, and life details all over the web is a weak default. It rarely wins against systems that ingest public records, commercial data, and whatever you already leaked. It can confuse you on recovery questions, create collateral hassle, and still leave the real trail intact.

The idea is easy to sympathize with. Privacy guides and OSINT-minded writers sometimes suggest muddying the water so data brokers and search aggregators end up with a mess instead of a clean dossier. Michael Bazzell’s Extreme Privacy line of thinking is one place that mindset shows up. The instinct is not silly. The execution usually is, unless your threat model is narrow and you treat deception as a small, controlled tactic.

To decide what is worth doing, it helps to separate three things people blur together:

  1. Pseudonyms and compartments (different name or handle, different email, keep those worlds from touching).
  2. Broad fake personal facts (invented employers, cities, birthdays sprinkled across profiles and forums).
  3. Targeted decoys (honeytokens and canaries that fire when someone touches something they should not).

(1) and (3) often make sense. (2) is what this article argues against as a default lifestyle.

What “red herrings” usually means here

People mean: leave enough false trails that an automated profile or an amateur OSINT sweep picks up noise instead of signal. Maybe a fake hometown on an old forum, a junk LinkedIn-adjacent crumb, or made-up “about me” text somewhere indexable.

The imagined adversary is often a people-search site, a marketer’s graph, or a stranger with Google and patience.

The appeal

Real dossiers are built from scraps. The Federal Trade Commission explains that people-search companies compile reports from other brokers, public social posts, and government public records. Starting from something small (a name or phone), a buyer can get a report with age, past addresses, associates, and more.

If the machine is correlation-hungry, maybe garbage in means garbage out. That hope is the whole pitch.

Where the tactic usually breaks

Strong sources beat weak fiction. Brokers do not only scrape your Substack and your forum signature. They buy and merge feeds. The FTC notes public-record inputs can include property, voter files where applicable, licenses, and court filings. A fake bio on a hobby site does not delete your deed history or un-ring data you already sold with consent by signing up for services.

You are outgunned on scale. You might plant ten lies. The ecosystem has automated refresh, many secondary sites, and years of accumulated transactional data. Opting out can push your file down; it does not turn the internet into a clean slate. The FTC also warns that after opt-out, information can reappear when public records change, and it may still show up through relatives or neighbors.

The data is already dirty. Commercial profiles often mix fact and error without asking you. In one Brennan Center piece on broker data, the author described LexisNexis Accurint stating it does not verify data and that changing incorrect data is not possible in the way consumers might expect, and Thomson Reuters data showing odd inaccuracies. If the baseline is noisy, adding more noise is not clearly an upgrade. It can even help a sloppy system “confirm” a wrong story because another negligent source repeated it.

Serious adversaries do not stop at Page 1. Nation-states, litigation, dedicated harassers, and well-funded investigators use records, legal process, financial footprints, and interpersonal graph data. Hobby disinformation does not harden you against that tier. It mostly changes what low-effort search aggregations say, sometimes.

Costs you might not budget for

Account recovery and identity checks. Security questions, “verify your previous address” flows, and support tickets are built for consistency. The EFF notes recovery answers can be mined from social details and suggests false answers stored in a password manager. That is a controlled lie with a system behind it. Random old fibs scattered online are not the same. They are debt you forget until you are locked out.

Self-doxxing through inconsistency. If you reuse patterns, links, photos, or usernames across supposed compartments, the fake story and the real one collapse into one graph anyway. EFF guidance stresses keeping profiles separate: separate email, avoiding phone numbers where possible, and not reusing photos that tie accounts together.

Forms, banks, and fine print. A joke city on a forum is not the same as a false line on a government form or a loan application. The practical line is: harmless theater stops where a statement gets treated as a formal declaration.

Harm to bystanders is rare but real. Invented addresses or phone blocks can land on real people. Invented employers can point at real small businesses. If your red herring is another person’s nuisance, you traded their time for your comfort.

What tends to work better

Start with threat modeling in plain terms: what you protect, from whom, how bad failure is, how much hassle you will accept. Without that, dramatic tactics jump ahead of basics.

Then prefer:

  • Less submission, not more performance. Every signup is a data event. The Privacy Rights Clearinghouse notes how many everyday actions can end up in broker-derived listings because records and surveys proliferate.

  • Opt-out hygiene where it matters. The FTC describes DIY and paid approaches and warns that removal from people-search sites does not erase government public records. Repeat checks matter because data can return.

  • Pseudonyms where the platform and your life allow it. A pseudonym is a chosen public name that is not wired to your everyday identity. That is different from maintaining a contradictory trail of alleged facts under your real name.

  • Compartments: distinct email, distinct payment method when feasible, distinct browser profile or device for sensitive work, and discipline about not cross-posting links that stitch worlds together.

  • Security questions: use random answers stored in a password manager, per EFF, not a second fake life you will forget.

When targeted deception does make sense

Canarytokens and similar decoys are for detection, not for cosplaying a second life. Canarytokens are tripwires: things nobody legitimate should touch, so an interaction is a signal. Use small planted artifacts with a defined purpose and an alert path.

Limited operational cover also belongs here: a throwaway email for one project, a press alias that colleagues know is a mailbox, a PO box that is a real mailbox but not your bedroom. These are bounded, documented, and consistent inside their scope.

Bottom line

If you want privacy from data brokers and casual searchers, subtract data, segment identity, and repeat opt-outs more often than you add convincing lies.

If you want anonymity in a specific corner of the internet, a pseudonym plus real compartmentalization beats a litter of implausible facts tied to your legal name.

If you want warning shots that someone accessed something they should not, use decoys meant for alerting, not a fictional resume you half-maintain for a decade.

Red herrings read clever in a book. For most readers here, the sharper move is dull: fewer accounts, harder linking, tools sized to the adversary you actually have.