
Kwame Asante
Attribution comes with a confidence level attached, and the level is nearly always lower than the writer would like. A hostname resolves to an address, an address belongs to a network, and a network belongs to an organisation. None of those steps identifies a person. The first hop is the autonomous system. Every address sits in a numbered block announced by an autonomous system, and the registry record for that number names the organisation that registered it. It is a strong signal about infrastructure and a weak one about a human, because hosting providers, clouds and agencies all front for the person you want. The registration trail is where redaction bites. A domain record can name a registrar, a privacy service or a company, and each tells you something different. A dated change of nameservers can date an infrastructure move to within days, which is often more useful than the ownership record itself. Passive DNS shows what a name resolved to in the past, and that history survives a migration. It also records addresses that no longer belong to the target, so it needs reading with the dates attached. Certificate transparency logs are the best free source going. They publish the names a certificate authority has issued for, with timestamps, and they frequently reveal internal hostnames that were never meant to be public. Location from an address is the claim I push back on hardest. It is derived from a database of network registrations, it is often several hundred kilometres out, and it describes the network rather than the person. I show the number and then say plainly what it means.
About ToolSura
ToolSura offers 80+ free, privacy-first online tools that run 100% in your browser — no uploads, no logins. Learn more about our mission →