Tor exit node operator gets raided by police
npr.org
npr.org
> "Knowing that, moving in, it doesn't automatically preclude the idea that the people running Tor are not also involved in child porn," Whitcomb says. "It does offer a plausible alibi, but it's still something that we need to check out."
> Whitcomb also says Seattle police were "artful" in the way they did the search. Instead of impounding all of Robinson's computers, which the warrant would have allowed, they offered to search them on the premises as long as he consented to turning over his passwords. He did, and they let him keep his machines after they scanned them.
This is the important part. They didn't shut down the exit node. They didn't even take away the computer. This sounds bad, but in all honesty, it could have gone at lot worse.
they raided his house because of child pornography.
that he had a Tor node and that fact got him off the hook is the part that needs more analysis. How do we know he doesn't operate the node for the very purpose of watching kiddy porn go by? Shouldn't everybody interested in child pornography operate their own exit node just for this purpose? Keep the kiddy porn collection in RAM for viewing whenever, then give the police the in-RAM-kiddy-porn-deleter password...
I understand that ghkbrew (and MANY other people here, not picking on you) subscribe to the idea that there should be untraceable currency, perfect privacy delivery mechanisms, etc.
But there are other people who live in the same democratic country that like the idea that somebody who bombthreats can be found.
I understand the issues on both sides, and I don't mind there is a spectrum of beliefs and a discussion. But it's so annoying when people write posts slanted like yours that they don't acknowledge the obvious "other side".
I read/heard something that David Mamet said, that he learned from the study of Jewish law (but it would apply everywhere) that in order for you to have the basis to discuss an argument with the other side, you need to be able to state the other side's argument in a way that the other side would not disagree with, then you get to make your point.
I thought that was a nice idea.
I particularly like a version of this termed the "Ideological Turing Test". The idea is to anonymously write both your position and an opposing position, and to see if an audience consisting of people from both sides (and, potentially, those who are neutral or are on some other side) can identify which side you actually support. If you can state both arguments convincingly enough that it's difficult to determine which one you really believe, then (according to adherents of this concept) you've earned the right to be critical. If, on the other hand, one side easily identifies you as an outsider, then you require further listening/study before you'll be capable of criticizing that side on a reasonable level.
While I think the process is more cumbersome than necessary, I agree with the underlying concept -- if you can't state someone else's argument in a way that they think is fair, then you either don't understand it well enough, or you understand but you're being intentionally disrespectful by choosing unfair characterizations.
This is brilliant, I love it.
You only need to be able to understand a valid argument. The problem is that everyone will evaluate "valid" by their own beliefs and worldview.
But there are some it doesn't catch. This is a valid argument:
All animals live on Mars.
All humans are animals.
Therefore, all humans live on Mars.This is what you meant to say:
Suppose all animals live on mars.
Suppose all humans are animals.
Therefore, if all animals live on mars, then all humans live on mars.
This argument passes the type-checking test, and is indeed valid.> That is not a valid argument, because all animals do not live on mars
It would be more accurate to say that it is not a sound argument because all animals do not live on mars. Validity relates to whether the conclusions follow from the premises, not whether the premises are true. (There are more constraints than that, but that's the basic version.)
Our strict types are Fact, Hypothetical, and Implication. It is only valid to use possibly unsound premises if you admit their type as Hypothetical and not Fact. If our argument includes premises of type Hypothetical then it is only valid to make conclusions of type Implication, which have the form "If <Hypotheticals are True> then <Fact>."
Disguising Hypothetical-type premises as Fact-type, and using that to draw conclusions of type Fact instead of type Implication is how people create strawman arguments in bad faith, and can be prevented at the validity-checking phase by enforcing strict typing.
That meant it either proceeded elsewhere on the TOR network or stayed on his machine, and they had no external way of knowing without checking his hard drives.
If they knew he was running an exit node it smells a bit like a fishing trip, but since they didn't send the SWAT team in through the windows and hold his computers for 4 years out of spite (the Steve Jackson treatment) I have trouble faulting the cops too badly.
They did know. Martin Kaste of National Public Radio [reported](http://www.npr.org/sections/alltechconsidered/2016/04/04/472...), "Seattle police spokesman Sean Whitcomb says the department understands how Tor relays work, and they knew Robinson was a Tor host."
To support a warrant, the question has to be the other way around. As with any activity the could be in proximity to illegal activity, it's not, by itself, evidence of anything.
Alternatively they could have just been bunch of dicks out to intimidate someone.
Why would anyone do that? If he knows how to install Tor, why wouldn't he download it through somebody IP instead of his own? I can't see any technical advantage to downloading it using your own IP when you could use somebody elses...
Download from somebody elses IP = Probably not at all associated with himself.
Download from his own IP = Definitely associated with himself.
Again. What would be the advantage of doing this? There isn't one...
This a great way of phrasing what I'd been thinking about as "arguing from someone else's shoes".
>I thought that was a nice idea.
Its a truly terrible idea, and not surprising that it stems from someone who found religion worth studying. There is no need to delve into the depths of minutia to dismiss baseless arguments. If you argue that Spiderman is real, and he lives at the Justice League, I don't need to study canon of Marvel comics in order to deal with your argument.
> someone who found religion worth studying
Like it or not, religion has been a cornerstone of history and civilization for about as long as there has been history or civilization. Secularism is a relatively recent invention, and secularism's influence has only been really felt in the last 50 years or so.
Religion is history, and history is definitely worthwhile to study.
Related: you want to face the other person's central viewpoint in its strongest form ("strongest" in the sense of being the best or most compelling variant, not necessarily the variant which has the most supporters or the most vocal supporters.) This is in both sides' best interest, provided both are honest in their motivations.
If someone believes something that's not true, but you only "take down" a misrepresentation of their false belief, you haven't actually helped them, because they know you didn't answer their actual position. It may even strengthen their false belief, because they now have the experience of someone claiming to be able to criticize their position but failing to do so, which they may generalize to "critics of this position have no real argument".
And if someone believes something that is true, but you are able to show a misrepresentation or a weaker formulation of it is false, you haven't done yourself any good. You've missed an opportunity to learn something true, by distracting yourself with a superficially similar position that you can dismiss.
That's a dangerous statement to make. Yes, religion has been hugely influential across societies. But religion has been equally succesful in rewriting history to suit its narrative.
I suspect religion has destroyed as much history as it has informed.
Running a Tor exit node in itself isn't a problem. The problem arises when the exit node operator knowingly is giving up control over the traffic going through his connection.
If you run a tor exit node you need to accept the fact there is a chance something illegal is passing through and that when it happens (as it did here) you are going to get investigated.
It would be irresponsible and neglectful for law enforcement not to raid this man's home.
I have no issue with the intent, and such things are - in a restricted manner - allowed for, see prostitution stings.
But the fact that they -do- distribute CP is verifiable fact.
I'm not even concerned that they hold it. Sometimes it's evidence. Sometimes it can be used to identify and rescue victims. Sometimes it just goes in a database and isn't ever accessed again. Meh.
The continued distribution is concerning, though I understand its purpose, and I presume there are reasonable safeguards in place such that the value in catching new suspects is higher than the harm done to the victims.
At that, one has to assume that they "planted" the image in question because they've proven their willingness to play dirty.
Given his early morning wake-up call last week and the fact that he may now have to get rid of his computers because he can't be sure what the police did to them while he was being questioned outside his apartment, Robinson says he may have to reassess whether it's practical for him to stand on that principle.
Not much, admittedly, but it's something.
It's more like raiding the return address even if it says "I was just forwarding this, this is not the actual return address".
And this return-address analogy needs to include the fact that a Tor node operator is cryptographically prevented from tracing backward toward the sender.
Well, not quite, but eh I can't make it perfect, it's a throwaway analogy.
If you're going to run a TOR exit node, which you are absolutely free to do, you have to expect this to happen from time to time and be prepared to explain why you are not responsible for the traffic you appear to have originated.
Cost of doing business. If standing on principle was free, it would be unremarkable.
Who's going to run a tor exit node if that's the legal precedent?
It's also pointless. While it's possible for a CP collector or distributor to run an exit node as cover, why would they when they can just use tor for real for all their CP dealings?
Think of the ultimate consequences. Such a legal precedent would have CP and other criminal activity causing more collateral damage rather than less. If all it takes to get most tor exit node operators to shut them down is engaging in illegal activities that will draw the attention of the authorities, then I can imagine a lot of countries' intelligence and military services would have an interest in engaging in criminal activities using U.S. tor exit nodes to reduce the available pool of tor exit nodes.
The IP address presumably actually belongs to the exit node operator's ISP. By this logic they should be raiding them instead.
> There's no way for law enforcement to know he didn't make those connections until they investigate
There's no way for law enforcement to know that you didn't make those connections until they investigate. That shouldn't be justification for raiding you, should it?
> If you're going to run a TOR exit node, which you are absolutely free to do, you have to expect this to happen from time to time and be prepared to explain why you are not responsible for the traffic you appear to have originated.
They already knew it was an exit node.
> If standing on principle was free, it would be unremarkable.
That is a very poor justification for unnecessarily making it more expensive.
Running a Tor exit node shouldn't give you some blanket against police investigations.
A warrant based on an IP address should be specific to the computing device associated with that IP address at the time it was logged. The cops should never be able to threaten someone with additional seizures--beyond what is specified on the warrant--to coerce cooperation.
Just the NAT router? Computer(s) behind the NAT router? Phones which have wi-fi and may or may not have been on it at the time? Computers on the other end of the site-site VPN which routes traffic out that NAT router to get around Geo IP restrictions? Any computer in the world which has TOR installed and therefore may have been "behind" that NAT router?
The Internet is really complicated, how specifically would you write that warrant without details of the network design?
Many conflate reasonable doubt with "any doubt whatsoever", and think that any excuse that can be concocted which is technically feasible is an alibi. "But Your Honor, it is possible that someone snuck into his house, spoofed his MAC address to get on his Wifi, used that to download this and that, and then left undetected!"
So there's a standard of reasonability, and there should be corroborating evidence.
Should, at least. In theory.
But if it is not reasonable to believe that an IP address is connected with a person, it is not justifiable to search or seize anything else that person may own or possess, beyond the particular device identified by the IP. I don't think an IP address alone is sufficient to even meet the probable cause standard.
It is also possible that someone with authorized access to his computer used an unsecured browser to view a compromised advertisement on an ordinary website, which recruited the machine into a botnet, which used infected machines as a distributed filesystem.
It is also possible that a wardriver with a cantenna brute-forced his Wi-Fi WPS PIN and extracted the WPA password, obtaining easy access to the network.
It is also possible that the ISP regularly refreshes its IP leases, and gave the cops identifying information for the customer who had the IP at the time the request was made, rather than the customer that had the IP at the time the suspicious traffic was logged.
None of those scenarios are necessarily exculpatory alibis, but they may cast doubt on any hypothesis that purports to connect an IP to a particular person.
In practice, warrant-signing judges seem to believe that an IP address is analogous to a postal address, possibly because it also contains the word "address", which may be conceptually ingrained into their minds as a permanent physical location.
You've discovered the fundamental problem. You can't. An exit node IP address is completely useless for that purpose because it tells you nothing about where the ultimate endpoint is. The person who actually did it could be in Brazil or Korea or on the International Space Station. You have no actual information on which to base a search.
There is at least a reasonable argument to make that for most residential IP addresses the devices that use the IP address are in the same building as the NAT router. And then you have an obvious solution: You look at the NAT router and then you look at the devices it has given a DHCP lease to, as in most cases there will only be a small number of them which will be in the same building.
But that isn't always the case. The NAT router or one of the devices behind it could be routing traffic for a very large number of machines, e.g. an entire corporation or all of a small ISP's customers or a coffee shop's public wifi. And in those cases the number of different machines controlled by different people is large enough that the IP address no longer identifies anything with enough particularity to justify searching all of the possibilities.
Tor and other open proxies are the extreme far end of that spectrum. It could literally be anyone in the whole world. The IP address tells you nothing at all. And if you know it tells you nothing at all, it provides no justification to search anything in particular.
B. As others have said 6:00 AM is among the most likely time that most working professionals will be home.
C. I'm not sure what his status as an exit node operator has to do with the hour at which a search is executed?
I can watch videos of people getting killed on reddit. I can watch rape videos. I can even watch videos of horrific crimes....
But how dare I watch someone under 18 get naked through a computer. Even if that someone is myself. The worst part is that, while in most other crimes, account for intentionality is considered. (Something falling in my cart while I walk out the store isn't shoplifting, yet shoving something in my pocket is.) Instead this "crime" frankly shouldn't be. It is proof a crime took place however. Its too easy to have a potential dangerous image... even from hosting a Tor gateway
Edit: at absolute minimum, there should be a mens rea requirement where possession or transmission of child pornography took place.
In honestly though, you're not wrong. Richard Stallman has his controversial stance on child porn as well and I tend to agree with him. It is really really bizarre that modern western society doesn't seem to have a problem with video of soldiers shooting up little kids in Baghdad, yet a picture of a teenager showing her breasts to her boyfriend via text is instant grounds for being locked up (in Australia there is a zero tolerance police and teenagers have gone to jail and are on sex offender registries for just that; although their sex offender databases are confidential and not as fucked up as America's).
However, sexual assault on children is a heinous crime. It's sad and destroys the lives of kids who parents hope to keep from getting tainted by the world as long as possible. It's not unjustified to hate this crime to the degree which it is, but it's also kinda bizarre we don't treat videos of kids getting shot the same way. People get off on that stuff too; sexually.
What's even more interesting about this case is that the police knew CP was downloaded from his IP address. That might because the United States has mandatory ISP reporting, or potentially his IP was found on a raided website:
I'm more interested in how that information was obtained, and whether that process involved violating the rights of individuals of people not associated at all with any crimes.
I'm not surprised. Considering I work with Tor extensively, along with cryptocurrencies and other 'interesting stuff', I guess I fit right in with the tech crowd on there.
I'm all for just punishment, from which I think pedophilia is most certainly a crime. It gets... fuzzy around a lot of areas though, especially after puberty up to 17. The law, frankly, is just a total mess. Sex- OK, sext- CP, fake license- pedophilia.... on and on.
Homosexuality was viewed as psychiatric disorder not too long ago as well. Although some people still think it is - are you one of them?
Whether that is a mental health asylum, prison, or somewhere/somehow else, so be it.
I don't think they should be abused either, as it's a popular trend in the penal system to use rape as an informal deterrent for criminals.
Or do you believe that e.g. audiophiles hump their speakers, and bibliophiles use the library for public orgies?
Well, yes. But only because it's really easy to imagine after browsing their forums.
I'm curious what the laws / regulations would be for general social media, image hosts, and other businesses that host user content. It's pretty much a given that at some point, there will probably be some illegal content uploaded onto it (including potentially child pornography). In some ways, a Tor exit node sort of falls under that same boat: you are indirectly passing information generated / requested by users.
Now, Twitter or Facebook doesn't going to get raided / computers confiscated every time an illegal image passes through their network. But I'm sure the police may ask questions during investigations (and I'm sure the companies comply as best they can). So I honestly think what happened here is fine. (I'd think differently if the police automatically confiscated computers and trashed houses of Tor exit nodes for no reason.)
I'm sure I'm sitting nice and pretty on several lists.
It seems to me that it would be patently unreasonable to raid the FedEx employee's home, but it would be perfectly reasonable to hold FedEx the company responsible for not delivering such things. If it happened once, sure, raiding them is excessive. But if the government knew that FedEx, by design, actively did not care what they were delivering and made it hard for themselves to figure that out until it's loaded onto a truck for local delivery, and they had evidence that some drugs or weapons were being delivered, then sure, raiding the local FedEx distribution center and searching it seems within the realm of reasonable actions. Seizing all packages at that distribution center would be unreasonable, but the analog (seizing the computers) didn't happen.
You're saying that should justify the FBI going to all the FedEx hubs and opening all the packages to check for various illegal stuff?
Unlike UPS and FedEx, Tor makes this straightforward, and also tries to avoid knowing the identities of people who are sending things via their service. So the police don't have that option.
(Note that the above is simply a description of what Tor is currently doing, as I understand it, and not an attempt to make a moral judgment one way or the other as to what Tor should be doing.)
I suspect that package services are used with high frequency by criminals without these constraints, e.g. the ones committing mail fraud. The police deal with this not by searching the contents of random packages but by arresting the actual perpetrators regardless of what they use for a delivery service.
There seems to be a common impression that if the police can't find you using one specific investigative method then they have to give up and go home. There are hundreds of different ways to catch criminals. Most of the ones people complain about the police losing are ones they never traditionally had to begin with.
Tor is more like you operating as a volunteer delivery guy who is willing to pick up a locked box anywhere in the city for free and drop it off anywhere else that is requested. You have no idea what's in the box nor who you are picking it up from or dropping it off to.
This doesn't stop police from raiding them.
They don't need to have SWAT no-knock the place. They don't need to seize and confiscate everything and make it very hard to recover. They don't need to handcuff anyone. They don't need to act like smug assholes. Etc.
Or do you mean they install their own "special" tor exit node on his machine?
There have been various public and leaked catalogues of law enforcement tools put online now, these abilities are commoditized and packaged in a user friendly manner. This is pretty old news at this point.
Do you think that they came up with this in their emergency war room, as they planned out the sneak attack on the Tor node, or was this a more general policy developed over the previous months and years and this was just one of the first times they got to practice it?
Most famously, because they were recently hacked themselves, the Milan based company Hacking Team. The intercept has a good breakdown of their software manual here: https://theintercept.com/2014/10/30/hacking-team/#manuals
There are many others out there, this cell phone related catalogue is really interesting: https://theintercept.com/2015/12/17/a-secret-catalogue-of-go...
Any company considered a "defense contractor" will probably offer tools along these lines. They are in high demand.
Of course the FBI, Homeland security and the NSA have their own tools as well. And they share with local law enforcement (probably not the latest and greatest ones).
> Do you think that they came up with this in their emergency war room, as they planned out the sneak attack on the Tor node,
I don't really have any idea what the Seattle PD methods or procedures would be, but they knew what TOR was and tracked the traffic to his exit node. I doubt it was the same cops who did that part ... so how likely was it that this briefing didn't include anything like "Just plug the CriminalBuster(tm) box into the computer until the light turns green, then coordinate with Bob to get access to the information you want later. You can get things like X, Y and Z from the CriminalBuster. To requisition a unit fill out form TPS-01 and give it to John."
The entire reason to commoditize these things is to make it easy to use within an inefficient bureaucracy that doesn't have a lot of tech training or a "war room". Just like they have done with phone taps or gps car trackers for years.
> this was just one of the first times they got to practice it?
Why assume this was the first time? It's standard practice for all sorts of infosec workers, journalists, etc to assume this was done to their laptop if it was out of their hands. You can literally download one of these and put it on a usb stick yourself (for your own personal use of course, anything else would be very illegal).
Can someone show me the Seattle PD budget that has in it those kinds of purchases?
Can you show me where they'd at least hide it in the budget somehow? This isn't DOD black ops slush funds, after all.
Maybe these defense contractors do it for free, out of the goodness of their hearts?
I don't make the mistake of thinking that the government or its agencies are the good guys who would never do anything underhanded. But I feel pretty safe believing that they're A) incompetent and B) piss-poor strategists and C) not interested in anything but the current investigation.
The idea that they've Jason Bourned his computer is absurd paranoid blather.
I think you have a miss-calibrated idea of how hard/technical/uncommon/expensive this is. This is the IT equivalent of collecting DNA, not Jason Bourne stuff.
Funnily enough the annual National Technical Investigators Association conference is in Seattle this year.
Tacoma PD has at least one Stingray. Tacoma. That's a few orders of magnitude more expensive and complex than a little usb drive.
Want to see the FinFisher price list? https://wikileaks.org/spyfiles/docs/DREAMLAB_2011_FinFPric_e... I wonder what the "1x Auto-Exec USB Dongle" or "10x Activated FinUSB Dongles" lines refer to? Why wonder, you can read the catalog.
They have identified a number of western LEO's on that customer list, no American ones yet but FinFisher is just one company and there are FinFisher command and control servers in the US.
Anyway, I'm responding just because I am interested in the subject and not because I think a dialogue is going to happen here and that's not the best use of my time.
I think you have little experience with cops. It's surprising they can figure out shoe laces.
What they (Seattle Police Department) claim to have was a tip, from 4chan, filtered through a national clearinghouse, that about seven weeks prior someone had allegedly transferred to 4chan a video of an unidentified woman abusing an unidentified child in an unknown location at an unknown time, allegedly from an IP address that they discovered was assigned by an ISP to David and that they learned prior to the search was the exit point from an anonymizing proxy network.
SPD staff involved were familiar with Tor and thus knew that there was no more reason to suspect David--an outspoken critic of their public surveillance programs and other privacy-invading programs--of uploading the evidence of some woman's crime to 4chan than to suspect any of the many thousands of users of the Tor network of such. This was pure harassment.
Would they raid a Starbucks if someone used Starbucks wifi to distribute CP? No, they would need more evidence that someone at that Starbucks was doing it and not just someone who bought a cup of coffee there that day.
Tor is open wifi, the IP of the exit node doesn't provide evidence that the person running the exit node has anything to do with the traffic.
That's why they raided his house.
> Would they raid a Starbucks if someone used Starbucks wifi to distribute CP?
Of course they would. Obviously aiming to try and catch the perpetrator in the act, but also at least to get a good look at the network configuration.
"CP came from this IP endpoint" means crime is being committed using this network. It's perfectly reasonable for them to go and investigate. And as others point out, them knowing how Tor works makes no difference - otherwise people making/distributing CP would host their own exit nodes with the sole purpose of being able to point them out to police and tell that CP it's not their traffic.
They didn't jailed him, they checked if he is in fact involved - and finding no additional evidence, left him in peace.
If you take anything but a ridiculously short term view, the expectations of how police will treat people today are far higher than they have been in the history of the US.
We still have to recognize and confront the remaining problems, but national media attention and prosecution of police who commit murders is a step up from police committing murders with no consequences.
Not exactly a best case.
Basically a small tool that runs hidden and allows remote keylogging, upload and download of files, screen capture, etc.
https://en.wikipedia.org/wiki/DarkComet is a good example of a free one.
Although my view won't be popular, running an exit mode and having to deal with this is not a smart thing to do. What is the upside vs. having to deal with this type of raid and perhaps police who are not so accommodating at some point? Why draw attention to yourself in this way? Also assumes that some rogue cop won't plant something on your device if it does get hauled away. Seems dangerous the way I see it.
IANAL but I sincerely hope one would not be compelled to unlock their device only in the presence of a police officer and prohibited from having a camera, lawyer, witness, judge, internal affairs officer, etc. present.
All things considered, this dude dodged a bullet. I don't know if he was acting under the advice of counsel, but he came out relatively unscathed. This time.
This might be a shot across the bow designed to frighten those without the deep pockets of Apple. Just a reminder that The Man still has teeth when it comes to the 99%.
"We can seize all this money and put you in jail, or you can decide to talk to use without a lawyer and we'll let it all stay."
Coercing rights away is never a good situation to allow. Not that he was wrong in accepting it, but that the police were wrong in being able to offer the option.
I guess in truth it might be "do your backups actually work", but if that's false then you're already in trouble.
I can afford another machine right now, but will that put a monetary strain on other areas of my life that are important to me?
I can afford another machine, and I have backups, but the restoration of the backups is painful enough that I would prefer to avoid it.
I would prefer this episode be over with as quickly as possible as I'm not guilty, so should I comply to speed this process along? (note that I think this isn't necessarily guaranteed to be a good strategy).
Depending on what the police believe about the situation may greatly affect what is the path of least resistance and problems, but you unfortunately have very little insight into exactly what that is. In some cases, talking to and cooperating with the police is the easiest way to extricate yourself from the situation, and in other cases it's the easiest way that they can twist the situation to implicate you in some way. The safest way is to always have a lawyer present and never voluntarily give up information, but not everyone is in a situation that makes the safest choice easy to take.
When the police interviewed him and admitted they _knew_ what a Tor exit node was, and that he was unlikely to be responsible for the traffic. But they did want him to know that running a Tor exit node makes their life harder, and would land him in this sort of trouble.
(I can't remember the exact words he reported, but it was outright intimidation).
It'd probably be safer still setup a nonprofit group to own and run the exit node(s).
Allowing any random person to forward mail through your address may not end up well for you either, but I think people are more willing to accept that they've opened themselves up to the liability in that case.
I have seen no reporting--not even in Detective Daljit Gill's affidavit in support of her application for search warrant (which I've read)--that police observed any violation of law related to the search. They claim to have received a tip, from 4chan, filtered through a national clearinghouse, that about seven weeks prior someone had allegedly transferred to 4chan a video of an unidentified woman abusing an unidentified child in an unknown location at an unknown time, allegedly from an IP address that they discovered was assigned by an ISP to David and that they learned prior to the search was the exit point from an anonymizing proxy network.
The point is not whether he was responsible for the child porn traffic, but whether they have an obligation to investigate, and I think they do. In this case, that means a raid, since it's an individual and not a business (a business would likely have people that would speak out, and individual mean that if he's guilty, there's no reason for him to incriminate himself). Even so, raids on businesses happen as well, when there is a belief a evidence might be destroyed.
That is, I'll amend my earlier statement. If the police have been notified about a law being broken, it's within acceptable behavior to follow up on that tip.
In this case, while inmy eyes the existence of a TOR exit node might reduce the likelihood that the person running it was responsible for the traffic, it also raises the likelihood that the traffic existed in the first place in my opinion. That puts the police in an interesting position, in that depending on how they weight those items, they may decide to investigate further.
In any case, I think my point stands, which is that when you make yourself responsible for delivering other people's traffic without oversight, you are increasing the chance that something problematic may result. Thinking it should have no effect on you is unrealistic.
Sure, the package could have been injected by somebody at the FedEx depot, but there is no evidence of such, and thus no cause for search.
A business with multiple employees is not the same as an individual when investigating a crime, depending on whether you think it's likely that they are colluding.
The traffic of the suspect and TOR was mingled, therefor it is not possible to say whether the offending traffic was from TOR or the suspect. If it was from the suspect, there could have been traces on his systems.
A low probability is not the same as no possibility, and there was a possibility he was trading in child pornography. Your threshold for how high that probability should be compared to the investigating officers, or their superiors, may differ. At this point, it's subjective, which is what I was getting at in my prior comment.
In any case, this is irrelevant to my original point, which I already clarified in my prior comment. But to address what may have been your intent, yes, I believe that a package forwarding service may have some problems with the police from time to time. It may not be to the level you describe, but my point clearly does not require that.
To put it plainly, if you in any way enable illegal activity, even unknowingly, it's not entirely unexpected that at times you may face increased scrutiny, or legal misunderstandings. For the suspect in this case to say he "shouldn't have to" is not realistic. That would allow a de-facto smokescreen for real criminals to hide behind.
Yes, of course, they may. Police act in unethical or even unlawful manners from time to time. At question is not whether judges may warrant searches by police that they should not warrant, it is whether those searches should be warranted.
A fourth-party tip relayed through a third party about someone allegedly transferring via a computer network that provides locational privacy a file that apparently contains evidence of crime committed by an unidentified person in an unknown place at an unknown time is not any indication that the operator of the machine from which the file exited the anonymizing network onto the open Internet is party to any crime, whether that operator performs the service for fee, for free, at a commercial property, or at a residential property, as an individual, or as part of a group.
No they don't. They didn't investigate the ISP, or the ISP's ISP, did they?
Wouldn't it be more effective to simply use Tor as intended with somebody else hosting the exit node?
But that's just my guess. Perhaps somebody should ask @snowden.
(IANAL!)
You never corporate with the police. It doesn't matter if you're innocent. It doesn't matter if you're guilty. The police are not your friends. They are not there to help you. They don't give a shit about you. Never comply with police. Never consent to a search. They had a warrant in this case so it wouldn't have mattered, but he still shouldn't have consented. He should have never given them his passwords. He should have waited for a lawyer. He made so many mistakes that I'm surprised he isn't in jail for incompetence.
I really want to encourage you to read the following: https://www.eff.org/issues/know-your-rights
At the time, we couldn't find anyone who had even heard of Tor (not to say there weren't lots of people who were familiar, just that we didn't find any of them), let alone thought through the implications of someone running an exit node so I find it interesting that they didn't just seize all of his equipment. Based on my experience, I would not have predicted such an "artful" search, to use words from the article, even just a couple years ago.
https://blog.torproject.org/running-exit-node
Also, how risky would it be to host an exit node that is HTTPS only?
That might not be much in the way of concrete evidence, but if your exit node is hitting carder forums all day long it might be enough for them to still knock on your door.
0: https://theintercept.com/2016/03/30/fbi-honeypot-ensnares-mi...
1: http://www.techworm.net/2016/01/fbi-child-porn-sexually-expl...
They need to keep doing what they have been doing with the recent FBI case and bringing these things out into the public's view. There is far too many things happening to subvert our privacy that we know nothing about...
I'd rather not deal with the police at all, in any capacity.
In fact, I should probably build a "invalidate every credential I have on all my computers and accounts" checklist. That and a tested backup strategy.
Tor exit nodes in the PNW are a very bad idea.
Would they bring around cocaine or a gun from another scene? I'm assuming the police officer is exempt from distributing child porn as long as he's accusing of something before showing it.
Then they would probably want to compare the image itself if it was detected on the harddrive, instead of relying purely on the file hash.
That was not the case. They were authorized by warrant to search for the following, which I transcribed from a copy of the affidavit in support of application for warrant:
A. Personal computer hardware to include, the computer system case with internal components, motherboard, CPU, memory, etc., internal and peripheral storage devices (such as fixed disks, external hard disks, floppy disk drives and diskettes, tape drives and tapes, zip drives, optical storage devices, transistor-like binary devices, video cameras, digital cameras, cell phones, and any other memory storage devices); peripheral input/output devices (such as keyboards, mouse/track ball/pad, video display monitor); and all related cables, power cords and connections, RAM or ROM units or CD ROM; as well as any devices, mechanisms, or parts that cat be used to restrict access to computer hardware (such as physical keys and locks).
B. Computer software applications used by the computer system and any related components.
C. Computer-related documentation that explains or illustrates how to configure or use the computer hardware, software, or other related items/devices. The documentation consists of written, recorded, printed, or electronically stored material.
D. Computer-related passwords and other data security devices designed to restrict access or hide computer software, documentation, or data.
E. Digital data that may be kept on any computer related storage device listed in 'A' above. The specific data will be (or will contain or incorporate) digital video and/or image files depicting minors engaged in sexually explicit conduct, any digital data related to the trading or exchange of depictions of minors engaged in sexually explicit conduct, and any digital "user attribution" evidence to include, but not limited to, registry information, configuration files, user profiles, e-mail, e-mail address books, "chat," instant messaging logs, photographs, and correspondence (and the data associated with the foregoing, such as file creation and last accessed dates) that may be evidence of who used or controlled hte computer or storage medium at a relevant time.
F. Photographs of the interior and exterior of the listed residence.
G. Papers showing dominion and control.
H. Any other evidence of the crimes of RCW 9.68A.070, to include but not limited to videotapes, books, magazines, catalogs, photographs, film, diaries, or other documents pertaining to the possession or dealing of child pornography, to include printed material documenting any communication with other persons regarding the trading or exchange of depictions of minors engaged in sexually explicit conduct.
This guy gave up the password & now doesn't trust what they did to his systems. He has to get rid of them now? This is no different if they took his computers away without knowing his passwords.
What if this guys was working with the police all along. Now some guy decides to give away his password to the police so they can check his computer? Sounds fucking suspicious to me. I guess they are testing the waters to see if other TOR node exit maintainers are going to do the same.
Listen up! Never give your password out. Encrypt your systems & keep them separated if you are running a TOR node. Let them take your systems, because you will have to trash them anyway if you grant them access.
How many bytes do I need? In the countries that have laws against cartoons, can I make an illegal favicon? Can I design a neural network which generates illegal favicons?
More seriously, criminalizing data is a terrible, terrible idea, simply because it provides a backdoor into the justice system.
I can't tell if the detective is a moron or just really hoping to induce a pedophile
If I ever get the balls to host an exit node myself, I'd likely only allow port 22. Even allowing 443 seems a bit risky after reading this.
In any case, you are always in danger of being identified by honeypot servers.
You could certainly, for example, redirect HTTP traffic through the Internet Watch Foundations child-porn filters, if you had the connections.
Running an exit node as an individual is going to be a dicey proposition.