In fact I think that's why they withheld the fact that he runs a TOR node from the judge.
Not a rhetorical question^
Another analogy may be running a Hertz in Saudi Arabia and renting to women without male guardians present.
The computer is not rented, they were in control of a device that may have been used to distribute child pornography. They themselves claim to know and understand this but feel that the risk of enabling criminal behavior is outweighed by the benefits to society of the "good" crime. Such as expression of dissent against regimes they disagree with.
I'm not convinced this search was unreasonable from a legal perspective. I do not know enough about the legal precedent around running a Tor node but I could understand if they are on the hook for what happens with their node. I respect what they are doing and I don't think what they are doing is wrong morally but they are taking on a risk which they believe is outweighed by the benefit.
How did you establish intent there?
I know as a fact that by depositing money in the bank, some of that money will be lent out by the bank. I also know that some people who lend money from banks will be criminals. I thus know that by depositing money in the bank, criminal behavior will be enabled.
I do not know however if my money specifically will be use for criminal behavior, nor do I know whom the criminals are or what the crime will be. In order to "knowingly" participate in a crime, the will, whom, and what is kind of important.
From the article:
"Bultmann and Robinson had publicly advertised that they operated a Tor exit relay node—a node in the global Tor network, whose purpose is to give users the ability to browse the web anonymously. They said they operated the node as a service to dissidents in repressive countries, knowing full well that criminals might use it as well, much like any other communication tool."
So yes, they didn't know which drug dealer they were renting to or which packets were from drug dealers (or child pornographers) but they did know it was possible. And with Tor I think it would even be considered likely.
There seems to be a difference between say running a Tor exit node and running a commercial VoIP service. With VoIP the operator is required by law to record and make available certain information to LEO. Tor by design prevents the operators from having that information. I'm not sure what the legal consequences are but it seems to me that in any other "communication tool" situation the operator is expected to at least make an attempt to prevent illegal use. With Tor that isn't possible so I don't think it's really "like any other communication tool"
Bultmann and Robinson knew they might be enabling criminal behavior with their own personal equipment in their home. I think it's easy to at least see the perspective of law enforcement in this case or how the legal system could find them at least partially responsible.
I'm not saying this is what should happen but I don't think we have a clearly defined right to run an open proxy as a get out of jail free card.
[1] https://www.schneier.com/blog/archives/2016/02/survey_of_the...
> most of the content
Easily refuted: the authors had a spider crawl hidden services, which is laughably stupid. They claimed that there where 5,205 hidden services, of which 1,547 hosted illegal content. Another study [1], one which actually took advantage of network statistics, found the number of hidden services closer to 30,000. Also, well over 90% of Tor traffic is unrelated to any hidden services.
So not most. As far as the analogy is concerned, hidden services would be more like the personal thoughts of the mailman - not the mail he is routing.
[0] http://www.tandfonline.com/doi/abs/10.1080/00396338.2016.114... [1] https://research.torproject.org/techreports/extrapolating-hi...
Is that supposed to justify a raid of anyone who runs a mail server or pays in cash or torrents a Debian ISO?
For that matter, given the whole Three Felonies a Day thing, most postal mail is in fact sent by criminals too.
There is a reason we have a law against theft and not a law against crowbars.
> Most email is spam. ... runs a mail server
If your mail server is an open relay and sends a lot of spam, you might expect it to get blocked at a minimum, and possibly to see some legal problems.
> Most cash contains traces of drugs. ... pays in cash
If you run an ATM and the money you put out has a higher proportion of drugs on it than the average currency, you might expect some inquiries.
> Most BitTorrent content infringes copyright. ... torrents a Debian ISO
This isn't even hard to disambiguate like the others. Is the torrent being downloaded/served infringing in some manner? If it's not, you're fine, if it is, you might have a problem. BitTorrent isn't a single system, it's bunch of loose networks.
There's a useful discussion to be had over whether someone running a Tor exit node should expect some increased risk of inconvenience and/or exposure to mistaken legal action, but I don't think these really advance that conversation at all.
But it isn't an open relay. It's just a normal mail server. It's cash with the typical trace amount of drugs on it. That's the whole point -- just because a lot of X is bad and you did X that doesn't mean that you did something bad. It's even possible, as is the case for Tor, that percent-of-thing and percent-of-people-who-do-thing have completely different numbers, because it's possible for a small number of bad actors to generate a disproportionately large amount of traffic.
> This isn't even hard to disambiguate like the others. Is the torrent being downloaded/served infringing in some manner? If it's not, you're fine, if it is, you might have a problem. BitTorrent isn't a single system, it's bunch of loose networks.
That's the point. "Is using BitTorrent" is not a useful metric for badness because the false positive rate is extremely high. If you sit on my internet connection and see me download encrypted data via BitTorrent, you don't know if it's a legal copy of Debian Testing or a pirated copy of Windows 7. Which means you should have to do more work before you can send a fracking SWAT team to my house.
See, I think the "typical" usage would be your own usage. I don't think the typical person happens to have a certain small percentage of traffic that happens to by child pornography pass through their connection, even if the internet as a whole does. Once you run a Tor exit node and you are proxying something closer to the statistical average of types of internet traffic (even though there's probably more illegal traffic on average on Tor than on the Internet, whether it's 1% more or significantly more), and you are doing it from home and mixing your own traffic with it, I think it's not out of the question for the Police to investigate. That doesn't mean every time, but I'm not going to immediately condemn them for looking into a crime.
I also think how the police handle it has to do with the entity they are interacting with. If it's a multi-person business in good standing, I would expect a subpoena. If it's an individual, it might be a raid, because I think the chance and capability of an individual to destroy evidence is higher.
I equate this to tracking the source of a gun that was used in a crime. If the last known source is a business, a subpoena may or may not suffice. If it's a guy selling out of his house (legally), a raid may be warranted.
Now, all that said, the police should be doing their part and providing the relevant info to the judge. The judge should be making this call, not you or I, and only when he has all the relevant info, which includes whether the suspect is running a Tor exit node (and as others have stated, it's up to the judges to either consult an expert or learn the facts themselves to deal with this information). Given our current laws and my understanding of them (probably poor), this is how I think it should currently function legally. Whether I think that's how they should function given changes, I'm not sure I would opt for the current system.
It's your own usage only if you're the only user, which is an invalid assumption even before Tor. People aren't shy about sharing wifi with house guests. Tor takes it from "could be any of 25 people" to "could be any of 7 billion people."
But even regardless of that, why should the expected result of offering a service to the general public put you under suspicion? If you sell sandwiches you're going to end up with cash that has traces of drugs on it, even if you don't use drugs, because some of your customers or some people they transact with do. Everyone who sells sandwiches for cash will end up with population-typical cash in their possession. Which is exactly why having such cash isn't at all suspicious. It's the thing you would expect from an honest person in that situation which means it provides no utility in distinguishing honest people from criminals.
> That doesn't mean every time, but I'm not going to immediately condemn them for looking into a crime.
By what criteria do you propose that they distinguish the times they do from the times they don't, which would reasonably put the case in question in the "do the raid" category?
> I also think how the police handle it has to do with the entity they are interacting with. If it's a multi-person business in good standing, I would expect a subpoena. If it's an individual, it might be a raid, because I think the chance and capability of an individual to destroy evidence is higher.
A large super-majority of individuals work for a business in good standing. Why would they be less likely to destroy evidence at work than at home?
Actually implementing such a rule would also seem to give undue comfort to criminal conspiracies.
Would it not make more sense to issue a warrant only if the crime can be tied to the suspect with something more than an IP address known to be shared by multiple people?
> But even regardless of that, why should the expected result of offering a service to the general public put you under suspicion?
Because the police have an obligation to investigate. By mixing personal usage with the Tor traffic, you've muddied the source of the offending traffic, and given them something they can investigate, even if just to remove a suspect. Another way to look at this is should I be able to run a Tor exit node and then expect any criminal traffic seen from that connection, even if from me, should not be investigated? Is the mere presence of a Tor exit node enough to deter the investigation? If so, everyone even considering doing anything illegal should run one.
> If you sell sandwiches you're going to end up with cash that has traces of drugs on it, even if you don't use drugs, because some of your customers or some people they transact with do.
I don't think trace drugs is an equitable substitution. We aren't talking about portscans, we are talking about a higher classification of crime, siuch as child pornography (and I would think crime network tracking, murder evidence, etc). If you're selling sandwhiches out of your house, and spending the cash directly (little or none is going to the bank), and a murder is traced back to you from the cash, yeah, the police might raid you, depending on circumstance. You have a good explanation, but that doesn't prevent you from all suspicion.
> By what criteria do you propose that they distinguish the times they do from the times they don't, which would reasonably put the case in question in the "do the raid" category?
First by police discretion (by whether they try to obtain a warrant), and then by the judge involved. If something needs to change, then it's at this level. If that means the vast majority of the times, the person is not investigated, that's probably not only fine, but right. But I don't think a Tor exit node operator is immediately excluded from all suspicion. For example, investigation of an active terror threat. The reward is so high for active seizure of someone involved, and the possible risk so great for not breaking up the network, that a raid on the exit node operator might be worth it even if the likelihood of them being complicit is very small. Whether other crimes meet that criteria is up for debate, but that's why we have judges to mediate that desire with the rights of the people.
> A large super-majority of individuals work for a business in good standing. Why would they be less likely to destroy evidence at work than at home?
There are more people around, it's harder to hide a crime when other people may have witnessed a part of it, even if they didn't know it at the time. The leaders of the business likely would want to help the police and not the criminal (for many reasons, both selfish and altruistic). If you believed the entire business and all employees were complicit in the crime, or that people with little oversight such as the owner were complicit, then a raid might be warranted in that case as well. A single person working as a business would be equivalent to the entire business being complicit, for the purposes of deciding risk of evidence tampering.
> Would it not make more sense to issue a warrant only if the crime can be tied to the suspect with something more than an IP address known to be shared by multiple people?
Preferably, but I'm more arguing that it should not be a reason they can't. There are simple things people can do to prevent this, such as clearly distinguishing your personal traffic from Tor (such as not running it from your home connection). Providing for ambiguity in the source of criminal behavior will lead to ambiguity in the application of resources to investigate that behavior.
The whole issue is that it doesn't give them someone they can investigate. There is no more reason to suspect the exit node operator any more than anyone else. Investigating people effectively at random is nothing more than a fishing expedition and a waste of police resources.
> Is the mere presence of a Tor exit node enough to deter the investigation? If so, everyone even considering doing anything illegal should run one.
I'm not sure why this is supposed to be such an unreasonable result. It's the same result you get as a Tor client rather than an exit node and the same result you get when using public wifi at a coffee house or anywhere else. There are a hundred ways to get an IP address that isn't tied to you, why is this one special?
> First by police discretion (by whether they try to obtain a warrant), and then by the judge involved.
That isn't how, that's who. By what criteria are the police or the courts supposed to make the decision?
> For example, investigation of an active terror threat. The reward is so high for active seizure of someone involved, and the possible risk so great for not breaking up the network, that a raid on the exit node operator might be worth it even if the likelihood of them being complicit is very small.
I'm not convinced that the severity of a crime should change the standard for probable cause, but even accepting that premise, the problem is still that the existence of a Tor exit node takes the probability that the traffic originated at any particular place to 1/(population size). Any justification to raid the location of the exit node would apply equally to any other place that could have used the exit node. You're trying to justify the search with an argument that could equally be used to justify a general warrant.
> There are more people around, it's harder to hide a crime when other people may have witnessed a part of it, even if they didn't know it at the time.
This doesn't really apply to almost anything that could be done via the internet. You can see your coworkers carting off toxic waste to be dumped in the river or conducting in person meetings with the victim of a scam. If you see them sitting in their office typing things into a computer, what is that supposed to provide evidence of?
> The leaders of the business likely would want to help the police and not the criminal (for many reasons, both selfish and altruistic).
Which obviously doesn't apply when the leaders could be the ones engaged in the criminal activity, and how are you supposed to know? Even regardless, what are the leaders supposed to do? One of their employees or customers signed into the company guest network with a personal laptop and did some illegal thing. The company has no way to know who it was and no authority to search all their employees' and customers' personal devices, and the device may not even be on company property anymore.
The inability to determine the source of network traffic is clearly a problem for investigators, but it isn't a problem you can reasonably solve by issuing warrants against scads of innocent people. It's a problem you solve by tying the crime to the perpetrator in some way that doesn't apply equally to innocent people.
> Providing for ambiguity in the source of criminal behavior will lead to ambiguity in the application of resources to investigate that behavior.
I don't understand why you think this mixing together of traffic is supposed to change anything. If you pay for both cable internet and DSL and use one for your own activities and the other to operate an exit node then there is a clean separation between your traffic and the traffic of the exit node, but how is that supposed to make any difference? You still control the IP address of the exit node and therefore could still have used it for criminal activity, as could anyone else.
It's not that they are suspected more, it's that they are a lead that can be followed on. If everyone that used that Tor exit node where known, the Police would be faced with a different problem, too many leads to follow up on, too little manpower to do so, and not enough info to differentiate one suspect from another. In this case there is enough info to differentiate one suspect from another in that one suspect is known.
> It's the same result you get as a Tor client rather than an exit node and the same result you get when using public wifi at a coffee house or anywhere else.
No, it's the same as someone running a wifi at their home. The scale is larger, but one thing we can assume with a fairly high degree use correctness is that the connection is also used by the people that live there, which is not something we can assume about a business, as nobody lives there.
To be clear, I think running an open WiFi or a Tor exit node is adequate defense against prosecution (barring further evidence), but not against investigation, and that investigation may warrant a raid, depending on circumstances. I would like to see those circumstances tightened significantly with corroborating evidence (such as repeated logging of activity and during times the suspect is known to be on premises, etc), but I don't believe discounting the information that the traffic went through the suspect's connection just because they allow public use is ultimately beneficial.
> I'm not convinced that the severity of a crime should change the standard for probable cause
I'm not saying it should affect the standard beyond not removing it as a factor. That the suspect is linked (not necessarily in culpability) in some small way to the crime through this information should not be ignored simply because of probability if it's the only evidence you have. It should be weighed appropriately though, and in almost all cases that will be that it's a red-herring.
> Any justification to raid the location of the exit node would apply equally to any other place that could have used the exit node.
Except that "any other place" may not have a concrete link to the crime, while this one does, even if it ends up only being as a conduit. Should someone previously convicted of child molestation that's a Tor exit node operator and happens to have the IP address associated with some child pornography not be looked at simple because of the Tor exit node? My assertion is that they should be given the extra scrutiny that the traffic has warranted; that we shouldn't stop a cursory investigation due to finding early on that they allow public access to their network. It's entirely possible that the evidence will end up being coincidental and the person is not related to the crime in any way, but should these leads be ignored entirely? I don't think so.
> This doesn't really apply to almost anything that could be done via the internet.
Sure it does. Plenty of businesses log all sorts of information. For example, was that email being investigated sent through the company mail server originally received from your workstation, someone else's, or some external IP? Would someone else notice and report some weird data loss on the mail server if they noticed it and were asked?
> Which obviously doesn't apply when the leaders could be the ones engaged in the criminal activity,
Which I specifically noted.
> and how are you supposed to know?
You make a call based on the situation and try to justify it to a judge? Is someone scamming someone else for $5k likely to be the CEO of a milti-million dollar company? Is a murder linked to the company but only really likely for a small subset of the employee base that doesn't include management likely to have management cover for them? Alternatively, if it has to do with bonuses, profits, mergers, stock, etc, maybe it is likely it may go to the top, so you take appropriate steps.
> I don't understand why you think this mixing together of traffic is supposed to change anything.
It provides a lead to an individual where none existed previously. As a single piece of evidence it's not obviously anything more than coincidental, but combined with further information may yield compelling enough evidence to investigate further, whether the person is ultimately responsible for the crime or not. I think the cases where the evidence is compelling based on further information are likely more often to yield useful investigation that otherwise, if done responsibly.
If they're not suspected more then it isn't a lead.
> If everyone that used that Tor exit node where known, the Police would be faced with a different problem, too many leads to follow up on, too little manpower to do so, and not enough info to differentiate one suspect from another.
Which is exactly the same problem they have when most of the users are unknown. The probability that it was any given person depends on how many other people there are, not how many of the other people you know the names of. When the way you got the one name provides no additional reason for suspicion over any of the others, investigating that one person is the same waste of resources as having the full list of thousands of users and then choosing one to investigate at random.
> In this case there is enough info to differentiate one suspect from another in that one suspect is known.
Being known doesn't differentiate a suspect from the others in terms of suspicion. It's like knowing somehow what town the suspect is in and then, because the investigating officer already knows the name of someone in that town, deciding to raid that person. Waste of police resources and undue harassment of someone who is with 99.995% probability not the offender.
> No, it's the same as someone running a wifi at their home.
That's not what I mean.
Your objection to not raiding the exit node operator is that otherwise someone who doesn't want the police to associate their internet activity with their IP address could put up an exit node. But people can already achieve the same effect by using somebody else's exit node or by using the wifi at a coffee house or a VPN service or any of a hundred other ways. There is no additional criminal advantage to be had by running an exit node.
> The scale is larger, but one thing we can assume with a fairly high degree use correctness is that the connection is also used by the people that live there, which is not something we can assume about a business, as nobody lives there.
So the internet connection in a business can be used by the people who work there instead of the people who live there, because people work in businesses and live in homes. What conclusion is that supposed to reach?
Also, many people have a work VPN account that causes their home internet traffic to go through their work internet connection, so the premise is incorrect.
> I would like to see those circumstances tightened significantly with corroborating evidence (such as repeated logging of activity and during times the suspect is known to be on premises, etc), but I don't believe discounting the information that the traffic went through the suspect's connection just because they allow public use is ultimately beneficial.
It's not a matter of discounting it, it's a matter of accurately calculating its evidentiary value. For the IP address of an exit node that value is very close to zero. The probability that some malicious traffic seen from that IP address came from the exit node rather than the occupants is not 100.0000% but is well in excess of 99%.
So yes, if you have a large pile of other evidence that the occupants are the perpetrators, knowing that it was their IP address will add another thousandth of a percent or so to the probability that it was them. But it isn't anything more than that. And it specifically shouldn't be enough to justify a warrant when it's the only thing you have.
> Should someone previously convicted of child molestation that's a Tor exit node operator and happens to have the IP address associated with some child pornography not be looked at simple because of the Tor exit node?
You're asking the question backwards. Knowing that it was the IP address of an exit node tells you nearly nothing. You don't then discount the operators, you just don't count them any more than you would have otherwise. Investigate as if you didn't know the IP address (because with extremely high probability you don't). If the same exit node operators were actually the perpetrators then the evidence will lead back to them regardless and operating an exit node would only explain the IP address but not any of the rest of it.
> That the suspect is linked (not necessarily in culpability) in some small way to the crime through this information should not be ignored simply because of probability if it's the only evidence you have.
Probability is exactly why it should be ignored. You're just advocating the law enforcement edition of "something must be done, this is something, therefore we must do this."
Doing nothing is better than doing something harmful, wasteful and unproductive.
> Sure it does. Plenty of businesses log all sorts of information.
Your original argument was that people at work would see you doing bad things. Now it's that there will be computer logs. But now the set of people who can "get away with it" expands to include the IT staff. And what logs are you expected to have tying a perpetrator to a personal device on a public guest network?
> Which I specifically noted.
But didn't really address. Granted there are some crimes that are less likely to be committed by corporate executives, but what about all the others? I'm not aware of any reason why executives would be any differently predisposed to child pornography than the population at large. Are you saying the police should raid AT&T every time they're investigating child pornography?
> As a single piece of evidence it's not obviously anything more than coincidental, but combined with further information may yield compelling enough evidence to investigate further, whether the person is ultimately responsible for the crime or not.
The point is that having the IP address of an exit node plus further information has approximately the same value as the further information. You don't ignore further evidence against the same party, you just don't credit the IP address with more than the almost-nothing which it is actually worth.
Sure it is. "The thief was a member in the AA meeting held on the 28th, but we don't know which one. We do know one person in that group's name though, so let's follow up on what we can." A lead is anything that can be followed up on. If it can't be followed up on, it's not a lead.
This is getting pretty far into the weeds, so I'm going to try to summarize my position more concisely, and from a different direction. I'm interested in if our stances on this are actually all that different.
My stance: The running of a Tor exit node should not be used to exclude a suspect from an initial look just because the traffic has a statistically much smaller chance of having originated with the suspect (based on percentage of traffic, not number of users). That is, it should not be a "fruit of a poisoned tree" type scenario, where the running of the exit node somehow provides protection, as I think none is warranted.
By running the Tor exit node through your home connection (or in any way that easily tracks back to you), you are associating your identity to that traffic. Not necessarily as the originator, but you are associated. If that association happens to bring attention to you that makes you look like a viable suspect (hopefully from more than just that association!), then that should be followed up on, even if it happens to end up not yielding the correct suspect (you can't know ahead of time). To me, this isn't about Tor, or an open WiFi, but about associating your name in any way in criminal activity, no matter how small, no matter how removed. There is increased risk there purely because you've made yourself more present in the minds of the investigators, and they may see something there to your detriment.
I don't think it's any different than if I walked around handing my business card to every person I saw on the street. If one ends up murdered or arrested, the police may see that and decide to take a look at me. Should I be arrested or raided purely on that criteria? No. But if I'ma lawyer, and there was a lawyer associated with the crime in some way, I might start looking like an interesting suspect. It is very clear to me that I have increased my risk by being very undiscerning of who I hand my cards out to.
My position on this comes from a prior article on the same event, discussed at HN[1], where the raided party said:
Robinson admits it might be safer, legally, to host the Tor relay on rented space from a commercial Internet service to avoid mingling his personal traffic with Tor, but he says he shouldn't have to.
"Why should I be spending extra money?" he asks. "There need to be more Tor exit nodes, more Tor nodes generally, and you don't need to be discouraging people from doing it by intimidating them with bogus criminal complaints," he says.
He doesn't have to, but he also doesn't get to act like his actions are completely removed from reality, and don't have any consequences whatsoever. Clearly they do, and they did, and I think it's unrealistic to think they won't or shouldn't, as that's not how people's minds (and thus investigations) work.
1: http://www.npr.org/sections/alltechconsidered/2016/04/04/472...
Imagine a hypothetical world where the government could search anyone's house at any time without a warrant. And some service came up that, through a strange legal technicality involving registering as a religious institution, could prevent your home from being searched. The first users of such a service, would of course be actual criminals. Most people wouldn't bother because they have nothing to hide.
Imagine you want to create a website that allows users to create forums with minimal moderation. Of course your first users will be interested in hate speech, because who else needs a forum that doesn't have moderation?
Or if you create a service that lets people distribute files peer to peer. Of course your first users will be copyright infringers, because they've been blocked from everywhere else. Or an anonymous currency will first be used for drugs and online gambling, etc.
There was another article, either here or slahdot or somewhere, talking about how there have been several of these TOR node raids. I doubt they even had any evidence of illegal material being downloaded. I think the FBI got all these local police departments to do this intentionally to scare people.
The guy should have never turned over his passwords either. He would have lost his machine, but IIRC, the Seattle privacy group he's with decided to scrap those machines anyway since they couldn't be sure the PD didn't tamper with the tor server.
If the police have probable cause to search a server at a datacenter, then they would likely also have probable cause to search the computers of the owner's of those servers. In which case, we're back to 6am raids (probably done at the same time as the datacenter raid to prevent evidence tampering)
Find one that accepts Bitcoin. Use a pseudonym, and a throwaway email address. Find a plausible meatspace address and telephone number online. Maybe a hostel, business hotel, restaurant that just closed, etc.
This is not going to be popular here, but IMO this is actually reasonable: you ought to be aware that running an exit node is enabling all kinds of terrible behaviour. You can't just handwash your responsibility away from this.
(No, this is not the same thing as providing encryption software, or general public chat forums etc)