This paper has comprehensively demonstrated why you don't roll your own anonymization (unless extremely qualified). It's pretty epic:
https://www.insidehighered.com/sites/default/files/2023-07/ejmr_paper_nber(1).pdf
... It also demonstrates that a bunch of
economists will say a lot of hateful things (sexist, racist, homophobic, and antisemetic) if they think they're anonymous. So many people are trying to get this replaced by a moderated alternative.
Paper is worth a read to drop your jaw at the terribleness of either angle. Or both.
@leak This paper is a wild ride. Daaaaaamn.
@evacide I wish we had room for them at PEPR this year, everyone would love it, but the program is *packed* with great stuff already.
@leak Page 7: "be neigh impossible"
@leak that's an incredibly good read
@leak Stunning. Jaw-dropping. This stuff needs to be rooted out, stem and branch.
The crypto mistakes are quite basic. Whoever came up with the scheme was clearly "self-educated" on the matter. A salt or hmac would've prevented the analysis from just public data.
As it stands, I'd be pooping bricks as the administration of any of these formerly-respected institutions.
@binaryphile @leak The topic ID is the salt. It should not have been public or predictable though.
@leak Far from the most important part of this paper, but did the authors claim the $1m prize for guessing the IP address of fddf2 offered in the quote on p. 3?
@riastradh @leak that thought crossed my mind, too.
@riastradh I suspect that: 1) this is their attempt 2) they strongly doubt it's going to happen or if the person in question even has that money.
@leak hardly surprising on either accounts. Anonymization is hard, and Econ is largely an attempt to make right wing politics technocratic and acceptable to the masses.
@leak The (relatively progressive) YouTube Channel Unlearning Economics did a video about this a few years back, with a whole section on EJMR! Highly recommended to get more info on the background/toxicity issues within the field, it was really eye-opening at least to me https://www.youtube.com/watch?v=AeMcVo3WFOY
@leak The salt was null! Priceless.
@leak Thanks so much for all your excellent discussion and comments on our paper. If you have more, please don't hesitate to send them our way.
@florianederer Thank you for the paper! It's great to see such a mix of interesting technical aspects and interesting human implications. It was a great read and I've been passing it around liberally.
@leak so you're saying they should have hashed it instead?
@djm They *did*!