Even if you bought a laptop from someone in another state on Craigslist with cash and connected to public Wi-Fi (without a cellphone on your person, of course)... I still would not feel confident that NSA couldn't track you down if you gave them a good reason to.
For the lulz
Do you think there is a database that connects an identifying factor of all computers to their owners?
A computer vendor could maybe keep a list of device serial numbers/MAC addresses, along with non-cash payment methods, but how could law enforcement legally acquire such data, if not authorized in a specific case?
And if there is a specific case, what is the likelihood that an investigator could determine a device's serial number/MAC from over the internet(how is that even possible?) and then locate the original vendor then locate the original purchaser?
The crux of this seems to be somehow uniquely identifying a device over the internet. A vendor having a database of items sold + payment method seems more plausible.
Isn't an IP address the only identifying factor of a machine transmitted over the internet? And IP addresses aren't permanently tied to machines. Even if theoretically an IP address could somehow be used to acquire the connected MAC addresses, doesn't TOR prevent that?
I'm not an expert on this, if something is wrong here, or I'm missing something, I'd be happy to learn.
I expect the manufacturer to have a database correlating MAC address, serial number, date the device left the factory, and where (i.e. which retail store) it was shipped to.
I expect the retail store's inventory tracking system to know when the device with that serial number was sold, by which cashier, at which register.
If it doesn't know the (tokenized) credit card number and name on card directly, I expect the store to be able to find its copy of the receipts from that register at that time, which would contain the last 4 digits and name on card.
If the purchase was relatively recent, I expect video of the register at that time.
If the purchase was in cash but the video is still around, I'd also expect video of the purchaser walking out to his car, and (maybe separately) a shot of that car with good enough resolution to pick out the license plate.
I don't think Joe Credit Card Fraudster gets this kind of attention, but someone who is believed to be a credible national security threat... absolutely.
In reality, I would expect that one or more of those elements in the chain to be broken. Retailer lost their backups. Changed systems, threw out the old one. Doesn't keep records that far back. Etc.
I agree there is a possibility they could track all these steps, but it would require everything working perfectly (from the authorities' POV)
As an added level of security, a month after buying it make a post on craigslist to sell it as broken/not working. send an email to yourself from an internet cafe offering to buy it. Via email arrange a trade at a location without any CCTV. Plausible deniability if the police do ever show up at your door.
What can be done with those logins by someone NOT employed by the government to harm ME?
This is the kind of thing that needs to be brought up in arguments when politicians pine for safety and surveillance. The history shows us over and over that the information cannot be controlled.
Treason against the United States, shall consist only
in levying War against them, or in adhering to their
Enemies, giving them Aid and Comfort. No Person shall
be convicted of Treason unless on the Testimony of two
Witnesses to the same overt Act, or on Confession in
open Court.
It wouldn't surprise me to see the government try to claim "cyber warfare" meets the bill for "levying War against them", but I can't imagine the supreme court letting that stick.edit: If you provided hacked information to a foreign power I could see that being considered giving aid to an enemy. My original question was more focused on the actual hacking itself than what you do with the information.
It could be considered "light treason" however...
In truth it'd be likely to fall under federal statutes governing systems access, and probably I'd guess the 1917 Espionage Act.