I'm seeking feedback on my April Fool's prank, which may ruffle some feathers, so I need to be well-prepared
against doxxing. My plan is to create a fake persona that doesn't share my interests, someone who embodies the
character of a cocky, self-proclaimed dumb hacker with a penchant for leetspeak and Discord raids. People will
likely assume this individual is real, but in reality, I'll be controlling their online presence.
My top priority ideas are:
1. Utilize an Android virtual machine with spoofed GPS to create fake locations on social media platforms like
Facebook, Twitter, Instagram, and Tinder. This is my most valuable resource. Additionally, generate fake Google
Maps reviews of places I've never been to.
2. Rewrite all chat messages through ChatGPT in Tor to conceal my writing style. If that's not possible, I'll use
NeuralDaredevil-8B-abliterated locally on my PC.
Other ideas, listed from most useful to least:
* Upload photos or documents with fake metadata on 4chan and use Exiftool to edit them, ensuring the same serial
number across multiple images.
* Generate a bio using ElfQrin (elfqrin.com/fakeid.php) and Fakenamegenerator (fakenamegenerator.com).
* Censor my photo's face using AI-generated or other methods, storing the unedited version in metadata.
* Create a public Google Drive document as if I'm sharing it with someone but was too lazy to limit access to
their email alone.
* Provide private details on smaller networks, such as board readers and Craigslist forums. Less obscure sites
include Discord, Reddit, Hacker News, TikTok, dating platforms, and more.
* Delete or alter content after the Wayback Machine caches it to create suspicion.
* Block individuals who find information about my character on social media.
* Maintain unique misspellings, grammatical errors, phrases, or bios across multiple platforms.
Additional tactics:
* Share a single link with tracking parameters across various fake personal accounts, saying "Look, I made
Twitter/YouTube/Reddit/more mad." To make it more believable, post screenshots from my Android VM, as many apps
force tracking parameters. Note that Twitter's tracking parameter contains an encoded user ID.
* Obtain fake photos of my home from real estate listings or purchased property images.
* Rush comments with intentional misspellings using Gofbid to appear intimidated or angry when "my cover" is
blown.
* Claim I use VPNs and privacy software recommended by YouTubers and that I learned OPSEC in Discord.
* Make it seem like my haters found my fake personal email or phone number (public VoIP) through account recovery
or contact exploitation. Which sites allow using a phone number without confirmation?
Questions for further investigation:
* Can I obtain an abandoned account from an old data breach for my sock puppet?
* Are there alternative photo sources, such as Fiver or Vidi?
Regarding my OPSEC, it's largely based on OSINT Techniques 10th edition by Mike Bazzell:
* I'll create accounts at a public WiFi spot in my country or another to avoid VPN-blocking and use DOH if
necessary. Then, I'll access those accounts from home using the same Mullvad server.[Expand Post] * Use a high-entropy, randomly generated password for each account via KeepassXC.
* All activities will be conducted within an Ubuntu and Android virtual machine with no personal information or
activity.
* Employ TOR with JavaScript disabled whenever possible; if not, use LibreWolf without extensions.