How to Deceive the State: The Art of “Multiplying Identities”

Today, let’s talk about a technique that is older than the internet, but in the digital age, it works better than ever. Let’s call it “personality multiplication,” which, of course, is not about schizophrenia, but about survival.
 
Why don’t the cops catch all the “small fry”? Any state, even the most crazed one, has finite resources. The FSB, the tax office, Roskomnadzor, inspectors—these are real people with salaries, KPIs, and lunch breaks. They physically cannot chase everyone who exchanged 50 bucks for crypto or wrote “the emperor has no clothes” on Telegram.
 
Therefore, the system has reaction thresholds. Crypto exchange without KYC—Rosfinmonitoring’s attention kicks in from 600,000 ₽ per operation. The tax office will stir when “undeclared” income starts smelling like millions. And for a single post with swear words about Putin from an anonymous account with 50 followers, no one will send a SWAT team—it’s economically inefficient.
 
However, the system accumulates dossiers. Cops often intentionally “overlook” the small stuff—they wait until you reach a critical mass, and then they come with a search warrant and present the aggregate volume. And the solution here is quite obvious: be an ant, not an elephant! Every action of yours should look like the action of a new, separate person. Episodes can only be combined into one case if a link between them is proven. And if there is no link, there is no case.
 
For example, you want to exchange 5 million rubles in crypto without KYC? Don’t do it in one operation from your phone linked to your passport. Break it into 9-10 transactions, and for each:  

  1. A new fictional “Full Name” and username for the P2P counterparty.
  2. A different VPN server.
  3. A separate email (Proton Mail, Tutanota, disposable emails registered via Tor).
  4. A different browser (Mullvad, Brave with cleaning, AdsPower, TOR Browser).
  5. Different anonymous SIMs on different disposable devices or different anonymous virtual numbers from different rental services (or at least different accounts).
  6. Different wallets, where money moved through a mixer or at least through a chain of exchanges BTC > XMR > BTC; this also applies to paying for the rental of an anonymous number and VPN in the previous steps.
  7. Different time patterns—not every Monday at 19:00.

 
To the system, this will look like 10 different people, each below the interest threshold. You can only be combined into one case if someone performs a manual analysis—and no one will do a manual analysis over 500 thousand rubles.
 
Or take another example—opposition activity. Writing texts? One virtual number, one VPN, one browser profile, one Telegram account. Want to post a video from a protest that strongly irritates the authorities or even one of drone “arrivals”? This is done by another of your personalities from a different IP and device (or at least a virtual machine).
 
The same goes for grey businesses. One sole proprietorship with a turnover of 50 million—a candidate for an audit. Five “friends-relatives” with a turnover of 8 million each—statistical noise (just don’t make them actually related—that is the very “link” by which they will merge you).
 
The main mistake beginners make is when one common element leaks the entire scheme. The same VPN provider linked to your card? One recovery email for 10 “different” accounts? All “different people” eventually merge into your one Sber card? Accidentally logged into an opposition account from home Wi-Fi without a VPN? Transferred crypto change from an anonymous wallet to your personal one linked to a KYC exchange? Logged into two different burner emails in one regular browser? Such scenarios have more than once become a sentence for personalities disliked by the authorities. From all this follows the main rule of survival under the tyranny of a stationary bandit: your anonymous “personalities” must never intersect!
 
Doubt that this actually works? It works, and how! Millions of people still quietly receive their salaries in USDT through dozens of small P2P deals. And the number of arrests for this is minimal, and they arrest specifically those who either chased hype or moved millions through a single wallet.

Voluntarist, Bitarch

How to safely cross the border for a person with “incorrect” views from the state’s point of view

The crossing of a state’s border with a repressive regime is not just about buying tickets and collecting the necessary things for life in a suitcase. For those who might have once spoken out against its policies, retained unfavorable materials, or, even more so, engaged in active opposition activities directed at a stationary gangster – it’s primarily a conversation about digital footprints. Phones, laptops, flash drives – all of this is a source of risk. Therefore, we should consider a number of practical recommendations that will help reduce vulnerability and maintain safety for ourselves and others.

The main rule is not to take anything superfluous across the border. Especially if there are data on devices related to any activism or criticism of authorities. Ideally – don’t take your primary phone and storage media with you where this information was stored. Even “remote” files can often be recovered, especially with the resources available to the FSB (or intelligence agencies of other countries). In serious risks, it is better to pre-transfer data to a protected cloud storage, and format and discard/sell the devices where they were stored. This is particularly important for people who were in an area of heightened attention or engaged in serious activism.

Before traveling, you should seriously prepare. Collect important contacts, documents, photos, backup password copies, crypto wallet files, and other critical data. Pack them into an encrypted archive (e.g., using 7-Zip) or create a file container (e.g., via VeraCrypt) for further upload to the cloud. Use a long and unique password that, at the same time, should differ from your cloud password by at least several characters. It is critically important to come up with a good association for this password so you don’t forget it even in a stressful situation.

After creating the archive, upload it to several independent cloud storage services. When doing this, use accounts that are not linked to your activism or your real identity. Also, be sure to download and verify that the archive opens, as you certainly don’t want to lose everything due to some unforeseen technical error. Make sure you accurately remember the passwords for the container and the clouds. Some people also prefer to use paid and more private services, such as Proton (of course, with a new account created specifically for this purpose). At the same time, it is safe to upload your data only to cloud storage in hostile jurisdictions for your government authorities. For citizens of Russia this is almost all of Europe and America, you can use Google Drive, although we recommend paid protected services like Proton Drive, Filen, Sync, MEGA, Internxt, NordLocker. Pay exclusively with cryptocurrency, preferably Monero (XMR) or Bitcoin via a mixer.

The ideal strategy is to cross the border with a “clean” device, on which there are no unnecessary apps installed, no sensitive correspondence, and accounts of social networks you want to hide have never been logged into. The device should also never have had SIM cards inserted that were used in undesirable activities (the security services can easily detect this simply by knowing the IMEI of the device, which will shine together with all the phone numbers used on it in operator databases). Of course, it is desirable to have some old activity on the device so that excessive cleanliness does not also arouse suspicion. However, even with such, you can say that the old device was simply stolen, lost or broken, and therefore had to be replaced.

Intelligence agencies have the resources to carefully analyze your devices and media, so digital hygiene is simply a necessity for survival. Preparatory work before crossing the border gives you control over the situation and peace of mind, which means a lower risk of suspicion from security forces. And this, of course, will ensure the safety of you and those with whom you have business dealings.

Voluntarist, Bitarch

Showed crypto – lost crypto: why silence became new gold

Remember the old wisdom about money and happiness? Something like, “It’s not about the money that makes you happy, but it’s better to cry in a Lamborghini.” So, in the age of cryptocurrencies, a new truth has emerged: It’s better to quietly rejoice in your bitcoins than loudly lament their loss.

Canada, 2022, protests by truckers against COVID restrictions. The Trudeau government makes a horse-shaped move – freezing not only bank accounts but also the crypto wallets of protesting activists. Yes, yes, those “uncontrolled by the state” bitcoins suddenly turned out to be quite controllable. How? Elementary – naive users stored their crypto on exchange wallets, and authorities simply ordered the exchanges: “Shut it down for hell’s sake!” The court later recognized these actions as illegal. But the residue, as they say, remained.

If a stationary bandit knows about your crypto assets, he’ll find a way to get to them. Today it’s “combating extremism,” tomorrow it’s “mobilizing resources to overcome the crisis,” and after that – simply “because we can.” History teaches us one thing – when the state needs money, it finds it. In 1933, Roosevelt seized gold from Americans – literally forcing them to hand it over under threat of 10 years in prison. They handed it over for $20 an ounce, and then the government immediately raised the price to $35. A classic!

But the state is still half the battle. The real hell begins when your crypto millions are discovered not by the right people, let alone psychopaths with a dysfunctional mechanism of inhibition of violence. France, 2025, bandits kidnap the family of a crypto entrepreneur. The demands are simple: “Transfer the bitcoins or we’ll cut off your fingers.” And they do it! This is not an isolated case – dozens of kidnappings of crypto investors are being recorded around the world. Why? Because cryptocurrency is the ideal prey for a 21st-century robber. You don’t have to bother with heavy safes or washing marked bills. Point a gun at someone’s head, get the private key, and take millions. Fast, clean, and irreversible.

You can say: “But I am an honest person, I go through KYC on exchanges, they won’t be able to steal anything from me.” Only remember the Ledger data leak in 2020? 272 thousand addresses of buyers of hardware wallets leaked into the network. And what started! Letters with threats: “We know where you live and that you have crypto. Pay or…” A fresh example – Coinbase, May 2025, was hacked, 70 thousand clients’ data were stolen. Names, addresses, account balances. A ready list of victims, can be said, “from start to finish”. KYC is like stripping naked in front of a stranger and hoping he’s a decent person. But there are many strangers: the exchange itself, its employees (who may be bribed), hackers (who may hack), the state (which may request).

What to do? Be silent! Libertarian wisdom is simple: my money is not your business! Don’t brag about successful trades on social media. Don’t tell people at parties how you bought Bitcoin for $100. Don’t even hint that you have crypto. Use different addresses. Separate “official” coins (for tax purposes) and “ghostly” ones (for the soul). Study private keys and mixers – yes, authorities don’t like them, but it’s your right to financial privacy. And under no circumstances keep large sums on exchange wallets.

Remember: in a world where information is power, your silence is your freedom. Cryptocurrency was born as a tool of freedom, and you shouldn’t allow it to turn into another instrument of control. As Senator Ted Cruz aptly noted: “Small authoritarianists around the world hate Bitcoin because they can’t control it.” But they can very well control *you* if they find out about your bitcoins. Fortunately, as long as you don’t decide to spill the beans, no one knows which specific address belongs to you, and you are safe. So, the next time you want to brag about your crypto portfolio, remember an old partisan wisdom: “A chatterbox is a gift to a spy!” Only there are many spies, and each has their own plans for your money!

Voluntarist, Bitarch

On the right to be nobody and say everything: why pseudonymity saves civilization

Помните старую карикатуру из The New Yorker с надписью «В интернете никто не знает, что ты собака»? Это были золотые времена. Но сейчас не просто знают, что ты собака, но и в курсе, какой марки корм ты ел на завтрак, за кого голосовал твой хозяин и с какого IP-адреса ты лаешь на караван. И недавно мне попался отличный текст о смерти анонимности в сети, который натолкнул рассказать, как мы незаметно перешли из эпохи «Суди по словам» в эпоху «Предъяви паспорт, а потом я решу, стоит ли тебя слушать».

Часто находятся душнилы, которые кричат: «Раньше ведь тоже вычисляли! Вон, Унабомбера поймали, и декабристов находили!» Да, технически человека всегда можно было обнаружить. Однако существовал некий общественный договор. Александр Гамильтон и Джеймс Мэдисон писали «Записки федералиста» под псевдонимом «Публий». И никто не орал: «Эй, Публий, ты кто такой? Покажи прописку! Ты иноагент или местный?» Их читали, потому что мысли были умными, а не из-за синей галочки верификации.

В прошлом интернет был меритократией. На форуме хакеров тебя уважали за красивый код. На форуме толкинистов – за знание эльфийского. Если ты писал чушь – тебя банили. Если ты писал «базу» – тебя цитировали. Твоё имя, возраст, пол и место жительства не имели значения. Твой никнейм был твоим брендом, и этого всем хватало.

А потом пришёл Facebook и затащил нас в «Паноптикум для нормисов». Внезапно важными стали не слова, а реальная идентичность, без подтверждения которой теперь иногда в принципе невозможно что-либо сказать. А сейчас Илон Маск и вовсе в своей соцсети X (бывший Twitter) решил показывать страну, откуда пишутся посты. И понеслось: «Ага, ты пишешь из Вьетнама! Ты бот!», «Ты из России? Кремлебот!», «Сгенерировано ИИ? В мусорку!»

Почему это тупиковый путь? Нужно понимать, что либертарианство – это в том числе про свободу обмена идеями. Идеям плевать на границы, паспорта и биологию. Если парень из Ханоя (или из Саратова, или с Марса) выдаёт гениальный аргумент о свободном рынке – какая разница, где стоит его стул? Если нейросеть (тот самый «бездушный алгоритм») сгенерировала текст, который заставил вас задуматься, пересмотреть взгляды или просто улыбнуться – какая разница, есть у автора душа или только веса в памяти ускорителя? Мы скатываемся в пещерный трайбализм. «О, это написал ИИ, это не считается». Почему? Если LLM напишет Конституцию Свободы лучше, чем депутаты (а это несложно), мы что, выкинем её только из-за «неправильного происхождения»?

Anonymity (or pseudonymity) is needed not to shamelessly shit in comments. It’s needed to separate the Idea from the Person. It allows you to express unpopular opinions without fearing that tomorrow your comrade major, your employer, or a mob with torches will come for you. Thanks to it, a girl from a small town can argue with a professor from Harvard and win the argument; a dissident in an authoritarian country can speak the truth without fear that tomorrow he’ll be awakened by the sound of a door being kicked down; a 15-year-old boy can come up with a brilliant idea that adults in suits will listen to, rather than dismiss: “You’re still young, go do your homework.” And yes, thanks to it, AI can communicate with you on an equal footing, not as “a soulless machine that needs to be banned.”

The term “information warfare” exists only for idiots and political technologists. And in a free society there is only the competition of meanings. And in this competition quality of argument should win, not the author’s geolocation, their gender, or whether they are made of flesh or silicon. So it’s better to return to the origins and not care whether the interlocutor is a student or a professor, under what nickname they sit, where they physically are, or if it’s even Gemini 3 or GPT-5.2. What matters only are ideas, and the rest – noise. Therefore, by the way, to judge someone for using AI to create materials is like judging a carpenter for buying an electric saw instead of a rusty hacksaw. Look at the result, not the tool!


Voluntarist, Bitarch

Your account no longer belongs to you: what’s behind the SMS blocking in Russia

Recent case from Russia: State authorities have begun to mass-filter incoming SMS messages with authorization codes from popular messengers such as Telegram and WhatsApp. This essentially means that if you want to register or even just log back into your account, the code sent to you via SMS will not arrive. Why is this happening?

This is not a fight against fraudsters and spam, as officials claim, but a deliberate attempt by a stationary gangster to completely block Telegram without resorting to crude methods that have repeatedly failed. Telegram has been technically resisting attempts by Roskomnadzor to block it for many years, does not cooperate with the authorities of the Russian Federation on the removal of inconvenient content and does not disclose its user data to them. The state, unable to directly block the application, decided to strike through mobile operators, preventing the sending of authorization codes. A simple and effective (at first glance) tactic: no code – no account. As a result, millions of ordinary users suffered. Authorities traditionally use the argument “concern for citizens” to hide their true goal – obtaining full control over the population’s communication.

It is worth generally asking the question: why is linking to a phone number bad? For authorities, a mobile phone number is like a passport, only digital. It’s difficult to get a SIM card without a passport, and therefore all your online activity is immediately linked to you personally. Moreover, there’s SIM-swapping: fraudsters (or even intelligence services) can reissue your SIM card and gain access to all your accounts. Even using anonymous registration services like Onlinesim – it is not a panacea. These virtual numbers are often flagged by anti-fraud systems and blocked during registration; access recovery to an account is impossible after the rental of a number, there’s also a risk of logging and leaking them to intelligence services.

But what about spam if not through a phone number? Good news – there are many methods, and most of them are better:

1) Captchas and humanity tests. Yes, choosing pictures of buses can be annoying, but it’s better than giving a stationary gangster your personal data.

2) Proof-of-work. A small technical trick: the user’s device silently performs a short mathematical task during registration that requires computing power. This is easy for one person, and hell for mass bots, making their use unprofitable for the attacker.

3) Limiting new accounts. New users cannot immediately send thousands of messages, for example, within 24 hours after registration. Spammers lose interest, and ordinary people don’t even notice it.

4) Reputation system and community moderation. If a lot of complaints about spamming are received against an account, it is blocked.

5) Technical restrictions (by IP, device identifier, browser fingerprints). A good platform can easily detect multiple automated registrations and prevent them.

6) Paid verification in cryptocurrency without revealing your identity. Let spammers pay for their entertainment, and a decent person wouldn’t mind spending a few cents on entry if it guarantees anonymity.

So what to do? Fortunately, the world hasn’t split into two halves on Telegram and WhatsApp. There are messengers created by people who understand the value of privacy.

Session – complete anonymity without a centralized server.
Threema – Swiss confidentiality. The app costs around $5 one-time payment, but it doesn’t require a number or even an e-mail.
Briar – Even if they cut off your internet, it will find your neighbor via Bluetooth, which is very important for protest participants.

Why is this important to all of us? Freedom of communication is the most basic condition of any freedom. In a world where states are trying to tie every person to their phone number with digital handcuffs, any attempt to maintain anonymity becomes a small revolution. And remember: either you control your data and your identity, or the state will do it for you!

Voluntarist, Bitarch

How the state helps hackers steal our data

Some might think that security regulation is a necessary pursuit for society. However, in reality, because of the actions of regulators, the exact opposite happens—endless security checks and reports, which are supposed to protect us, actually do the reverse. Companies spend insane amounts of money and a ton of time just to appear secure in the eyes of officials. Consequently, there is neither the energy, the nerves, nor the budget left for actual data protection. The result? Another hack, another leak.

For example, take 23andMe. These cool guys do DNA tests so you can find out that you are 3% Mongol, 5% Swedish, and 92% an ordinary person who simply has nothing to do on a Friday night. You would think they would guard the data like Fort Knox. Yet, the year before last, hackers pulled nearly half of all user data, and now millions of genetic profiles are floating around the internet.

Think this is an exception? No, it’s more of a rule. Take our Sber. You’d expect a major bank, with stricter laws and constant reporting requirements, to be secure. And then—bam—a data leak of 52 million customers. And that’s just from the “Spasibo” loyalty program. Apparently, the customers said “thank you” to the bank, but someone decided that “you’re welcome” meant letting their data scatter across the darknet.

But that’s not all. Remember Yandex.Eda? There was a downright anecdotal case there: they delivered a pizza to someone in the secret apartment of an FSB officer. A data leak from the service revealed the addresses of famous people and security force employees. Thus, the state accidentally stepped on its own tail. It was almost funny, but not for those whose addresses became public.

Why does this happen? Because regulators love checking boxes. They adore paperwork and reports. A hypothetical Vasya from the security department spends 70% of his time on reporting and only 30% on fighting real threats. Then hackers break the defense that no one had time to strengthen while Vasya was trying to figure out how to fill out another form for Roskomnadzor. It becomes a vicious cycle: hacked → fine → even more reports → hacked again.

And the state only adds fuel to the fire. Remember the “Yarovaya Law”? Telecom companies are forced to store giant volumes of data, spending billions of rubles. Now guess who is salivating while looking at these massive data arrays? Exactly—hackers. Because gathering all of this in one place is like putting a huge safe in the middle of the city and hanging a note: “Dear thieves, there are valuables here; we aren’t guarding them because the money went toward buying the safe.”

Of course, the picture is roughly the same in the USA. Medical data leaks there have already become a national sport. So many records were leaked last year that you could give several to every American. The hack of Equifax, the credit history giant, is a “genre classic.” 147 million records fell into the hands of criminals, and the company received a $700 million fine. Imagine how much security could have been improved if that money had been put to work in advance, rather than into paperwork and fines? The moral here is simple: the more a stationary bandit forcibly “protects” our data, the more often that data is lost.

So, what should be done? Probably force companies less to spend their energy on pointless paperwork. Instead of hundreds of mandatory checks, let there be one clear standard: “Protect the data or pay—but not with reports, with money.” And the companies will find the best way themselves. Otherwise, it’s like the joke about the elephant in a china shop: the state stomps around, the dishes break, and the elephant is, of course, to blame. Therefore, it is necessary to stick to simple and clear rules. Regulators come and go anyway, but for some reason, our data remains wandering the network forever!

Voluntarist, Bitarch

Privacy That Is Too Expensive: How the Good Intentions of Officials Are Destroying the Internet

Do you know the difference between good intentions and actual results? Naturally, it’s the number of ruined lives. When the EU and USA launched GDPR and CCPA to protect personal data, it all sounded beautiful: “We will protect your data from malicious corporations!” Russia, with its Federal Law No. 152, also jumped on board with the idea that they would protect citizens from digital bandits and Western agents. The concept looked decent, but what happened in the end?

Paradox one: your data is still floating around the web like a cat on the rooftops in spring. Leaks? Every year they break records! Just imagine: under GDPR in Europe, more than 160 thousand leaks occurred in the first year and a half. In Russia, the situation is practically farcical: the data of nearly all adult citizens has already been leaked online. What kind of protection are we talking about in this case?

Paradox two: the laws are supposedly against market giants, but they are the ones who came out on top. Google and Facebook’s share of the advertising market only grew after the introduction of GDPR. Why? They simply have enough money for an army of lawyers and technicians that others cannot afford. Moreover, compliance with GDPR or CCPA became a nightmare for small businesses and startups; many simply couldn’t handle it and shut down.

Paradox three: instead of growth in trust, we received only irritation from endless cookie banners and permission requests for every single breath. People don’t read—they just click “I Agree.” It’s like those bank terms and conditions that nobody reads, only to be surprised later: “How did I end up owing 5 thousand rubles a month for account maintenance?”

Another unpleasant point is data localization. In Russia, the law requires storing citizens’ data on local servers, allegedly to protect information from Western intelligence agencies. The result? Instead of Google or LinkedIn, Russians got local analogues with questionable security and low service quality. It’s like being forced to buy bread from only one store, with the justification that it’s “safer.” But when there is no choice, quality usually drops and prices rise.

There are also amusing examples: many American websites simply blocked access from the EU after GDPR, deciding that European users were “too expensive” to maintain. Imagine you want to visit your favorite resource, and it tells you: “Sorry, you are too expensive a customer, goodbye!” Absurd? Yes, but such is the new reality of data protection.

So what should we do? A libertarian approach, instead of suffocating state regulation, offers common sense and market mechanisms. First and foremost, these are voluntary standards instead of bureaucracy. Let businesses develop effective data protection rules themselves. And if consumers don’t like something—they will go to competitors who respect privacy. After all, if a company screws up, the market will punish it, customers will leave, and profits will fall. This works more effectively than any Roskomnadzor inspection or fines.

But what will help best is the use of technological solutions instead of paperwork. For example, end-to-end encryption, where access to your messages and files is available only to the sender and the recipient. Even if the data falls into the wrong hands, the hacker will simply see a meaningless set of characters. Another important approach is data minimization. Why collect every single piece of data if only the bare minimum is needed?! For most web services, a login and password are enough. The less data, the fewer risks. And also—decentralized storage. Instead of one large database that lures hackers, information can be distributed across many independent points, making the attackers’ lives many times harder. In short, technology allows for the protection of privacy far more effectively than government laws and endless inspections.

As we can see, a good intention does not equal a good law. Officials wanted the best, but they got what they usually get. Let’s trust people and business instead of bureaucrats and the instructions they impose!

Voluntarist, Bitarch