Creating Sock Puppet (Fake) Social Media Accounts
Creating Sock Puppets - Introduction
I signed up for the Trace Labs Global Missing Person CTF V. Here is my experience/tips with sock puppet accounts!
Virtual Machine
Don't use your usual browsers. If your logged into Gmail, that will track everything and reveal your sock puppet identities. I use an OSINT VM I made myself using Michael Bazzell's OSINT book.
Burner Phone
Remember "Wear Hat, Pay Cash". These days you can "Wear Hat, Use Mask, Pay Cash". I got my burner phone at Walmart. StraightTalk has cheap $30 dollar flip-phones that have a working mobile browser. You can use the browser to register for Facebook and Instagram. StraightTalk (when registering online) doesn't ask for personally identifiable information. The most they requested was for a Zip Code. You can lie.Gmail
Surprisingly, Gmail let me register on a VPN without email or phone number verification.Instagram - #2 Pain
Instagram hates VPNs. It flagged me. I resorted to using my burner phone to register. After you can login using a VPN.
Facebook - #1 Pain in the Ass
Facebook hates ProtonMail. I got a Facebook account using my burner flip-phone browser. I tried using ProtonMail + VPN. Failed. I tried the Library Wifi + Protonmail account. Failed. Maybe using a Gmail + Public Wifi will work? With a flip-phone browser you can forgo the email situation.
I also think my use of Firefox containerization + lack of bot tracking history flagged me too. How will Facebook make money/advertise off me? I just seem too secure and privacy oriented... maybe?
I heard you have to constantly upkeep the FB account. I'll let you know how long I last. Hopefully I can keep it alive until the CTF is over.
TikTok
So far I can see TikTok videos without registering. I will forgo a TikTok Account.
Any Tips?
Tip down below or DM me in TraceLabs Slack channel (username is Q).
Comments
Post a Comment