How to be UNTRACEABLE and anonymous online - spoiler alert, it’s basi...
Original video: https://vm.tiktok.com/ZGd9shV7d/
Fact checked on: August 6, 2026
Fact Check Analysis
Summary
The text is broadly right that online anonymity is difficult and depends on many possible identifiers. However, several claims are overstated, technically imprecise, or presented as certain when they are only possible in particular circumstances.
Checked claims
-
“It’s basically impossible to be untraceable on the internet.” — Partly true. Perfect anonymity is difficult to guarantee, especially against well-resourced investigators, but privacy tools and careful operational security can substantially reduce traceability.
-
Buying a phone with cash does not make the purchase anonymous. — True. Retail records, inventory data, timestamps, loyalty-program information, payment details, and surveillance footage may link a device to its purchaser. The availability and usefulness of those records vary by retailer and jurisdiction.
-
A phone’s serial number is recorded in store inventory records. — Partly true. Retailers often track device identifiers such as IMEI, serial number, or SKU, particularly for expensive electronics. However, not every store records the identifier of every prepaid phone in a way that can be easily searched.
-
A cash-register timestamp can be used to find corresponding surveillance footage. — Partly true. Transaction times can help investigators locate relevant footage, but footage retention, camera coverage, image quality, and access policies determine whether this is actually possible.
-
A random buyer or disguise would solve the purchase-identification problem. — False or misleading. Those measures might reduce one link in the chain but do not guarantee anonymity. Other evidence could include location data, communications records, device identifiers, account activity, or later surveillance.
-
Phones can provide precise GPS location. — True, with qualification. Smartphones can determine location using GPS, Wi‑Fi positioning, cell towers, and other sensors. The accuracy depends on the environment, hardware, permissions, and which services are active.
-
Turning off location services only stops apps from receiving GPS data. — Partly true. Disabling location permissions can prevent or limit ordinary app access, but it does not necessarily disable all location-related signals. Cellular networks can estimate a device’s location, and operating-system, carrier, emergency, or security functions may operate under separate rules.
-
A phone continues to communicate with cell towers after location services are disabled. — True. A cellular phone generally must communicate with networks to register, make calls, send messages, or use mobile data. Towers can infer an approximate location from this communication.
-
Phones can infer location from nearby Wi‑Fi and Bluetooth signals. — True. Nearby networks and Bluetooth devices can contribute to location estimation. Whether data is collected or transmitted depends on the operating system, apps, permissions, and network configuration.
-
Any Wi‑Fi connection necessarily identifies the user. — False. A Wi‑Fi network can associate a connection with a location, router, account, or subscriber, but that does not automatically establish who was physically using the device. Public networks, shared access, changing identifiers, and other factors complicate attribution.
-
Nearby Wi‑Fi networks form a reliable identifying “habitat.” — Partly true. A repeated pattern of nearby networks can contribute to device fingerprinting or location inference. It is not necessarily unique or stable enough to identify a person by itself.
-
Surveillance footage can always link a device on Wi‑Fi to a person on camera. — False. Such correlation may be possible if dates, locations, camera coverage, network logs, and image quality all align. “Always” is unjustified.
-
A VPN routes traffic through the VPN provider and can conceal the user’s IP address from websites. — True. In the usual VPN model, the website sees the VPN server’s address rather than the user’s public IP address. The VPN provider can still observe or potentially infer connection metadata, depending on its technology and logging.
-
A VPN merely shifts trust from the internet provider to the VPN company. — Partly true. A VPN changes which party can observe particular traffic and metadata. It does not eliminate trust, and it does not necessarily provide anonymity from websites, accounts, browser fingerprints, cookies, or endpoint compromise.
-
VPN providers may retain logs or disclose information. — True. Providers differ substantially in logging practices, legal obligations, technical design, and transparency. “No-logs” claims are not automatically proof that no useful data exists.
-
Logging into a normal personal account can reveal the user’s identity. — True. Authentication directly links activity to that account, regardless of whether a VPN is used.
-
A person must never log into any account previously used elsewhere if they want privacy. — Overstated. Reusing an account clearly links activity, but privacy goals differ. Separate accounts, privacy-preserving browser configurations, and other measures can reduce linkability; they cannot guarantee separation.
-
Writing style, repeated typos, and typing patterns can identify users. — Partly true. Stylometry and behavioral biometrics can sometimes link authors or sessions, especially with sufficient data. Their reliability varies by sample size, language, device, context, and the number of possible users.
-
Typing intervals measured to the microsecond can identify people in ordinary web use. — Mostly false or misleading. Keystroke dynamics research can use timing features, but browser and operating-system timing limitations, network effects, varied keyboards, and sparse data make the claim of routine microsecond-level identification far too strong.
-
Websites collect behavioral and fingerprinting data for marketing or tracking. — True. Cookies, device and browser characteristics, identifiers, analytics, and behavioral data are widely used for advertising, fraud prevention, personalization, and security. Not every site collects or uses all of these techniques.
-
One login or one Wi‑Fi visit can definitively expose someone. — Partly true. Such events can create a strong link under the right circumstances, but they do not automatically prove identity. Attribution normally depends on corroborating evidence.
- “Everything you do is traced.” — False as an absolute statement. Many activities generate records, but collection is incomplete, retention varies, and some data is inaccessible, anonymized, encrypted, or never generated.
Context & nuance
Anonymity is not a single condition. It can mean hiding an IP address from a website, preventing an internet provider from seeing content, avoiding account-based identification, resisting commercial tracking, or remaining anonymous from a capable investigator. A method may help with one goal while failing at another.
The text also conflates several different entities: the mobile carrier, Wi‑Fi operator, VPN provider, website, app developer, retailer, advertising network, and government investigator. Each may see different data, and none necessarily has a complete record. Correlating those records can be powerful, but it requires access, time, compatible timestamps, and sufficient data.
A phone does not inherently “emit” a complete identity. It exposes identifiers and signals that may become identifying when combined with subscriber records, account logins, location history, browser characteristics, surveillance, or other evidence. Some identifiers are persistent, while others can be randomized or rotated.
VPNs are also not designed to make a user universally anonymous. They mainly alter network routing and the parties that can see traffic metadata. Encryption protocols, browser configuration, account separation, tracker blocking, device security, and minimizing unnecessary data collection may all matter, depending on the threat model.
Finally, the strongest claims use words such as “always,” “never,” and “basically impossible.” Those formulations make the passage rhetorically effective but factually weaker. Privacy is better understood as risk reduction rather than a binary state: careful practices can make identification substantially harder without making it impossible.
Takeaway
The passage correctly warns that anonymity can fail through purchase records, network metadata, account logins, tracking, and behavioral patterns. Its main weakness is treating possible correlations as inevitable and describing several technical mechanisms with more certainty and precision than the evidence supports.