FBI operated 23 Tor-hidden child porn sites, deployed malware from them
arstechnica.com
arstechnica.com
First, let's not rely too heavily the analogies with drugs or prostitution. The differences between CP and drugs / prostitution are too large to ignore anyway.
CP consumers are often producers as well. That's a fact—you want CP, so you make some yourself and swap it with others to get more. This isn't universal but it's common enough that you should know about it. So the visitors to the CP web site are not all just consumers of CP but many of them are producers as well. This is relevant because you have to weigh the damage of distributing CP against the benefit of catching people who produce CP. People have stated that distribution revictimizes the children, but I would weigh that against the ability to catch people who were either producing their own or at least supporting other producers of CP.
So the FBI discovers this server, operates it for less than 30 days with a Tor exploit, and catches 200 people using the site. Yes, the FBI was complicit in the distribution of CP, but rephrased as a trolley car problem, this is basically like not pulling the lever, allowing the distribution to continue for a short time, and using that to catch 200 consumers—and how many of them are producers? You can pull the lever now and stop the distribution of CP, or you can let the trolley barrel down the tracks for a short time and save all these people somewhere else.
(People are saying that the exploit may have done damage to other police investigations from other countries—I don't see any evidence that the exploit damaged the computer, merely that it leaked information about the computer.)
I only skimmed, but at least 1 of the Websites required users to upload their own CP, to be approved by the admins, before they could download any.
They surely would have all the easiest CP to find already.
If not everyone would upload the same content pretty much.
So again, uploading does not imply production capability, at least the way I see it.
Additionally with how laws are structured in many places selling CP is a worse offense than possession, hence the trading scene is an easy way to legally cover your ass to get a reduced sentence or no sentence at all. But this also means that there is either direct production or contracting for this material from developing nations since otherwise everyone would be trading the same thing, about 9-10 years ago I've volunteered with the police and we were tracking sharing and downloading back then over P2P.
Once there was sufficient evidence they would flag the person and check their travel history, quite a few of them had traveled back then often (2-3 times a year or more) to either the Balkans/Central Europe and Asia and they were going there to effectively purchase or produce it for self consumption and trade.
Sadly there are way to many places where you can have sex with a child for money, and not for a lot of it, child prostitution in Mexico even in border towns it cheaper than normal street prostitution in the US not to mention higher end call girls.
Get a laptop or a camera and for a few 100$ you can produce quite a bit of content.
Financially you can always donate to international NGOs and local organizations that battle and assist the victims of CP but overall I don't think they have much actual impact other than the feel good factor, I doubt they have the reach for it, maybe Mexico, but Thailand et. al highly unlikely.
These days it seems that anti-CP operations are pretty much centralized on TOR and a few other networks, P2P and Usenet used to be the spot for that but over the past 10 years everything moved to either private internet sites that domain hop frequently or TOR and similar networks.
Encryption, VPN's and other privacy tools make the job of tracking people down en mass without any exploits nearly impossible, even 10 years ago besides the usual rehashed crap that one could find with a few search terms on P2P file sharing apps everything was already encrypted.
CP users were pretty much encrypting everything way before anyone else, on P2P/Usenet they were running PGP rings and they would exchange keys via side channels and share their content encrypted so only people that were in the ring could decrypt it (this was in effect running your own private site over P2P or a specific newsgroup).
Back then the best LEOs could do is try to get into the PGP rings and lure some of their members to meet in person or reveal their identity (no one even thought of using malware to track them down, that tradecraft wasn't there, nor would it have been admissible most likely) via other means.
Today this type of well effectively state level intelligence agency operations is pretty much the only way of combating CP at any reasonable scale, and even this scale is likely quite underwhelming when compared to the amount of content produced and traded each year. But AFIAK probably the only LEO worldwide that does this is the FBI, local police departments don't have the resources, Interpol and Europol are mostly a joke, and most countries have considerable constraints on active network exploitation by law enforcement.
Do you have a source for your information regarding the prevalence of production?
You can imagine all you like, but this hasn't radically changed just because we have the internet.
Eastern Europe and Russia also used to be a hot spot for these productions but they cracked pretty hard on that.
He is correct that most CP these days is traded, large scale productions are too risky since even 3rd world countries have been stepping up Anti-CP enforcement.
If you are a middle aged men traveling to Thailand a lot for no apparent reason don't be surprised if they flag you at the airport and search you.
It's hard to acquire guns for abuse in the west maybe, but they can always go to the Middle East and get it there.
You do realize that every child in a CP movie is being raped right? This isn't regular porn, these aren't consenting adults who are compensated for their participation.
These communities would have a lot more producers in them than your run-of-the-mill CP imageboards, as they have to fulfill a barrier to entry that only a seasoned CP consumer or producer would be able to meet.
So, once the FBI have control of the site, they can sort out all the lurkers who are consuming but not actively participating (probably uncommon, given that these sites also require you to remain active to keep your membership) and get damning information about people who are mass-distributing/selling and/or producing child pornography.
I think the entire debate relies on the re-victimization aspect. If we accept it, and they do, then it's decidely not a trolley car lever conundrum.
Your argument really hinges on this point. So, what's the answer? Out of the 200, how many are proven producers?
EDIT: Not to mention; the logic behind possession of CP being illegal is completely defeated by this enforcement strategy. (That's not to say I'll actually defend possession of CP, but I think it's very troubling that law enforcement and the judiciary are this out of sync.)
We can all look at this and assume the FBI made a good choice here, even if they broke the law in the process.
But.. what about those of us who use Tor to browse perfectly legal content in order to simply attain added privacy from the prying eyes of our local ISPs? Or to host SSH via a hidden service? Etc.
You may not know it yet, but you need tor or you will need it sooner or later. Or you will need something else like it.
> On August 4, all the sites hosted by Freedom Hosting — some with no connection to child porn — began serving an error message with hidden code embedded in the page. Security researchers dissected the code and found it exploited a security hole in Firefox to identify users of the Tor Browser Bundle [https://www.wired.com/2013/09/freedom-hosting-fbi/]
However, as far as we know, unlike the more recent Playpen thing, in the Freedom hosting case the FBI did not actually serve child pornography, they just displayed an error message. I don't see anything in this article that suggests otherwise.
Motherboard passed on this story but it appears it was too sensationalist for Ars to resist. See thread here for more info: https://twitter.com/josephfcox/status/797070958205038592
1. The crime that utterly dwarfs all others is involving children in the making of child porn.
2. After that, the crimes that dwarf all the rest are those that provide financial or practical support to child porn makers. Consuming child porn is generally regarded as one of those, and I'm fine with that categorization.
3. I'm sorry, but violating a victim's theoretical privacy by distributing the images a little further doesn't seem to be nearly as big a deal as helping to prevent the next live video of child porn from being made.
I'm usually regarded as being pro-privacy, but privacy is not something to be a rabid extremist about. Preventing physical sexual abuse of children, on the other hand, is a fine area for extremism.
You then claim that preventing child abuse is a fine area for extremism. That's an appeal to emotion and also a fallacy.
Perhaps we could debate whether extremism is justified but let's do it without all the nonsense you wrap around your argument to cloud the real question. You say that extremism is justified but all of the reasons your posit as justification are fallacies.
Making the assumption* that some decent fraction of those who consume such media would be sated if they could get it and not move on to actually hurting children. Then couldn't a preventative measure be to take all the existing child porn and make it available to them?
Though I guess that risks normalizing the condition and could lead to it being more commonplace (certainly it would appear so as those who successfully suppress it would hide it less) and if it's more commonplace than the fraction that does still act harmfully upon the impulse could, in absolute numbers, exceed those that do today. Figuring out how things fall would first require a good understanding of the numbers.
*I don't know if this is true or false and would be interested to know if there is existing general consensus on the evolution of seeking out fantasy fulfillment over time in general and how it's affected by free access v. restricted access to related material.
Of course, in some countries, that too is illegal, for some reason.
Making of child porn with real children is one of the most horrific crimes in the world. Fighting that by criminalizing other steps in the creation/consumption chain makes sense.
On the other hard, child porn in which no real children were involved is a free speech issue, and I'm on the side that favors permitting it.
There's also a third group of issues -- child porn is used as an excuse for general internet surveillance, which then is used to also benefit anti-terrorism, law enforcement, and anti-piracy. That's why copyright lobbyists refer to (concern about) child porn as being a godsend for their industry.
What about the victims' right not to have their privacy and dignity violated by the continuing consumption of the material?
That's weak evidence, but at least it doesn't contradict the hypothesis.
Someone should try giving some pedophiles access to a generous supply of computer-generated CP and seeing what happens.
To give some example numbers, say that 5% of those who view the material ever directly harm a child. And say that 100% of those who harm a child view the material. Now, say that 50% of those who harm a child get busted, but only 1% of those who don't get busted for viewing the material. The end result would be that of those caught about 5 of every 7 who viewed material harmed a child directly.
Now, the numbers are made up, but there are many values that lead to a false conclusion if people only look at those caught.
I know, it sounds disgusting. But if it turns out to actually work, I think we have to set our disgust aside. If not, well, back to the drawing board.
Isn't it that the whole family bathes together? The way you put it makes it sound like it's just the two of them, which doesn't fit the impression I have, though I don't really know.
It is definitely good that this happened and that the people using the sites for CP were identified and caught.
It is scary for the FBI, an agency that upholds the law, to break the law, even if it is for good reason.
From a moral point of view, Child pornography is de-ontologically wrong. Nothing can justify its existence. Even if such a sting managed to shut down the entire industry, it would be moot to attempt to argue for its moral goodness in consequentialist terms.
The FBI could have used other means to establish criminal intent in the visitors to the websites along with the fact that they had used Tor to search out and visit those websites in the first place. They could have made prospective viewers engage in a series of incriminating acts such as requiring them follow a series of links with the promise of finding the material, or making them refresh the page. There was no need to provide the actual offensive material in order to make a solid case.
I find this part very interesting: is this well established, that is, is it clear before the law which acts are surely incriminating? Is clicking on a link enough to establish intent?
Legally no it's not, that's a very weak binding and they know it. That's why any type of sting - whether cp or other - will attempt to get the user to sign-up, view content, or otherwise willfully provide personal information (eg a credit card).
It would have to be established that the accused was fully intent on the end goal and was of the belief that the steps taken would facilitate achieving that end goal. It seems intuitive that each successive deliberate step would compound, and even double the certainty of guilt. More steps, more certainty.
In this context, the first three steps would already have been taken. Firstly to acquire the Tor browser in order to hide one's identity, secondly, to learn how to search the darknet, thirdly, to have searched out and visited such sites. At this stage, the FBI apparently short circuited the process by providing the actual material, the viewing of which is a crime in itself.
Further steps could consist of following clearly labeled links, clicking on thumbnail images whose import was clear, even if they were blurred. This would show knowledge, and to a lesser degree, intent. Intent could be established by sending the perpetrator on a fool's errand of repeatedly following links and thumbnails without ever achieving their goal.
From your point of view. You can't make an argument by just rejecting an entire perspective in moral philosophy. Otherwise I'd be equally right in flat out rejecting deontology.
For instance, although Kant held that lying is wrong from a de-ontological perspective, telling a lie would certainly be the right thing to do to protect someone from being murdered. Consequentialist reasoning prevails here.
The moral question here is whether the FBI did the right thing in allowing the compromised websites to continue in operation. There has been some interesting discussion on this point. I think that they shouldn't have, and furthermore, that they did not even need to do so in order to achieve a conviction.
For instance, it is clearly moral to lie to a psychopathic killer in order to prevent a murder.
Child abuse is the least defensible crime that could exist. As such, CP rings tend to be understandably paranoid and risk-averse. If anything appears to give the impression that they are being monitored, you can say goodbye to the arrest of another monster lurking in the shadows. That's why it's necessary to sting as many people at a time when the authorities get their chance, because once the window closes, anyone who gets away can either go off the grid or distribute in another ring, perpetuating their crime and thereby increasing demand for CP.
It's pretty ugly to think about a federal agency knowingly distributing child pornography. I often wonder what kinds of psychological effects it has on the Bureau's agents. But child abuse is a horrible thing, and it is difficult to consider anything but the swift and absolute elimination (arrest and elimination from the network, not execution) of producers, distributors, and the abusers themselves.
The idea was |Stealth VM| --> |Tor router VM| --> |Virtual Box NAT|
The Tor router VM was running redsocks[0] to route all TCP traffic through tor's socks proxy interface. The stealth VM also used tor's DNS service.
That way, even if the stealth VM is compromised, it can't access the internet directly.
Thanks. Didn't know about it.
I'm not sure whether this is OK or not.
The FBI discovers a child prostitution ring and infiltrates it, but keeps running it and forces the children to have sex for a month to ensnare more customers.
If one accepts the idea of re-victimization, then I'm not sure how what the FBI did here can be considered acceptable, or any different than the analogy above.
From all I have heard and read on the subject of sex crimes, the research and the government policy has nothing to do with each other. Worse, some feminist movements have successfully lobbied to prevent research on criminal sexual behavior, on the principle that deeming such behavior as abnormal will result in lower jail sentence for criminals.
Instead we have this abnormal-but-not-abnormal behavior happening "randomly" by totally "healthy" individuals, and there is very little to explain why it happens or how we can reduce it.
More research I think would go a long way.
"Operation Pacifier is reminiscent of reverse drug stings in which cops pose as dealers to catch retail buyers, except that in this case the FBI actually disseminated contraband. It did not merely pose as a distributor of child pornography; it was a distributor of child pornography. During the two weeks the FBI was running The Playpen, about 100,000 people visited the site, accessing at least 48,000 photos, 200 videos, and 13,000 links. In fact, the FBI seems to have made The Playpen a lot more popular by making it faster and more accessible."
http://reason.com/blog/2016/08/31/the-fbi-distributes-child-...
It's not out of place at all. I just wanted to add some context to make things clear, that your Reason link doesn't contradict the claim that in the Freedom Hosting case they only displayed an error message.
Here's a better one: Fighting sex trafficking by abducting and selling children, but training them to rat on their captors first. I think that better captures the disaster that this is.
Not that it matters at this point. The new administration is going to give these folks a medal.
So, is getting someone arrested as easy as spoofing their network information and visiting those sites? I can already imagine trolls using this to have people swatted.
Forensic analysis of the hard drive would exonerate you though.
No. Anything an analyst could feasibly look at can be spoofed with root access. The only thing that could potentially approximate the actual age of a hard drive write is thermal annealing of the storage medium, but this isn't really true anymore with SSDs (and was never practical even for HDDs).
I'm not saying it's impossible, but it sounds pretty difficult to me. Maybe I'm wrong though.
We're talking about a very large sting operation, just browse a few of those, I guess?
So they seized an onion hosting provider that had 23 cp sites, they ran those sites for a few weeks, then shut them down.
Keep in mind, you can't just pause the site and expect your targets not to notice, they had to actively maintain the site (and consider what that means) to keep their targets coming back. It's disgusting and disturbing. And if it's what we know about it, it's also just the tip of the iceberg.
At least with Fast & Furious I think it was real criminals running the guns and just a failure to intervene. I think a failure to intervene here would be seen as unacceptable as well. But here we have way more than failure to intervene, they effectively provided the guns and helped run them across the border.
Actually providing the sting targets with illegal material seems a lot shadier.
The general pattern for drug and prostitution stings is that the police will commit those secondary crimes, but intervene before allowing the primary crime to happen. In this case, they pretty much committed the primary crime at length before acting.
In a way [0], the US does preemptively ban chemicals, regardless of whether that chemical has even been synthesized or used recreationally yet.
We don't criminalize baking soda, we're just trying a Minority Report sort of approach to things that are likely to be used rather than playing catch-up with known-psychoactive analogues. Certainly the metaphor bit still applies - selling and importing these things are only banned because of their abuse potential, not because the chemical is seen as intrinsically bad.
But I stand by the point of the metaphor, which is that we criminalize distribution because of use. If you couldn't use it, it wouldn't be illegal. So even when flipping users, the intent is to run stings without letting the primary 'event' of drug use happen. That seems like the key difference between drug stings and this sting.
That seems like the police would have enough to arrest people and do a full investigation of their computer storage. Then should corroborating evidence be found they could charge the people; publishing details of convictions later.
It seems that by continuing to run the site that police enabled crimes which otherwise might not have been possible.
Now that's a headline I can get behind
edit: second thought: I don't think it matters if something is done illegally, unless there is some penalty attached to it, no?
You can be found guilty of crime and not punished via a number of mechanisms ... that doesn't negate the existence of the crime.
The problem is that if government is not punished, then why on earth to think they will stop committing crime?
For me this sort of hinges on whether actual child pornography was distributed (and then, i imagine, consumed and re-distributed by pedophiles) in the name of making a bust.
Time to charge the FBI with aiding and abetting. Period. Equal treatment under the law. Period.
source?
That's quite the exploit.
Federal jurisdiction is implicated if the child pornography offense occurred in interstate or foreign commerce. This includes, for example, using the U.S. Mails or common carriers to transport child pornography across state or international borders. Additionally, federal jurisdiction almost always applies when the Internet is used to commit a child pornography violation. Even if the child pornography image itself did not traveled across state or international borders, federal law may be implicated if the materials, such as the computer used to download the image or the CD Rom used to store the image, originated or previously traveled in interstate or foreign commerce.
https://www.justice.gov/criminal-ceos/citizens-guide-us-fede...
Theoretically, would a general citizen be exempt from the ban if he manufactured his own CD-ROMs, and his own CPUs in-state?
It might be illegal for them to operate the sites for extended periods of time. It doesn't seem illegal for them to deploy malware as part of an investigation. I'm looking at (f) here:
https://www.law.cornell.edu/uscode/text/18/1030
So the worst that could happen is that the evidence gets thrown out. If they weren't going to otherwise be able to nab the person, the worst that could happen is they lose the case.
"Where necessary to make a regulation of interstate commerce effective, Congress may regulate even those intrastate activities that do not themselves substantially affect interstate commerce" [emphasis mine]
-- Justice Antonin Scalia, in the majority opinion for Gonzales v. Raich, using his vaunted legal genius to find a reason, any reason at all, to stop people from doing things that he didn't like.
One of the most influential hypocrites of the new millenium, if not the whole history of the republic.
I would be seriously impressed if you could manufacture your own computer capable of accessing the Internet and displaying an image from a single US state. Semiconductor manufacturing, networking software, electronics manufacturing, and so on are thoroughly global industries.
But even if you could, in the end, they're using this clause from the constitution:
> To regulate Commerce with foreign Nations, and among the several States, and with the Indian Tribes.
to give them jurisdiction in cases of Internet child pornography.
The entity determining whether or not this jurisdiction is valid is not like a computer program that will look at a homebrew computer, check where all the parts came from, look at the text of the law, and say "Whoops, nothing in this case crossed state lines, we don't have jurisdiction, you're free to go."
I see this attitude on HN way too often.
Instead, remember that it's a bunch of humans who considered the problem of child pornography, chose to fight it, and only then looked for a source of jurisdiction. That source does not actually need to be valid (not that I actually dispute that the FBI should have jurisdiction when US citizens commit crimes using the Internet), but it's important to realize that it only needs to be strong enough to stand up to the political will to oppose it. And there are no prosecutors with a will or the political power to oppose the FBI for going after sexual predators.
This state of affairs probably results in some overreach. But even considering the potential problems with this approach taken to the extreme, I find it extremely hard to align myself against the FBI. What if the FBI operated honeypot sites with zero-day exploits inserted for them by Microsoft, Apple, and Google, hacking modems and demanding ISPs snoop on their users, opposing HTTPS rollout, and generally causing great harm to law-abiding users of the internet? But these actions protected kids? How much harm would it take to shift my allegiance into opposing the FBI? Scary stuff.
It's not my country but this is the thing that grates most with me, the "act first and try and find legal justification afterwards". Officers of the law should really be seeking to act legally in the first place.
What you propose, companies creating a system of open reporting is fine by me, but doing it covertly is not. Enact laws allowing it and tell the public it's happening. That's the democratic way.
Sorry if I was unclear, I wasn't actually proposing that. I am saying that I think they'd be likely to get away with it if they did.
Given that 95% of people in the world are not from US, how many visitors were police officers from other countries, conducting their own investigation?
Quite recently, I ended up on an image board [whose name suggested to me it's got to do with topics such as freedom of speech] I hadn't heard of before, with sections whose short names meant nothing to me. So out of curiosity, I opened the first one.
Well, that board is no more.
That reads to me like yes, they were running the fully operational CP sites and allowing it to continue to serve up CP.
The ends do not justify the means.
ANd nobody has raised the question of how this can actually be done legally - under current law is there a way to make the serving up of CP content a sufficiently grey area that it's permissible to do with only judicial approval?
If not, seems to me the individuals managing the site for the window of federal operations have the potential to be in a whole mess of trouble.
If so, that seems a thing that should be fixed.
And in the process of answering that question we should probably ask, "is it working?"
Like seriously? Do you really think the absolute lowest hanging fruit is valuable, fair, or effective for justice to focus on?
And since the analogy was dealing with illegal drugs I was wondering whether these tactics are in fact more effective than just prosecuting at the level of "selling loose cigarettes".
http://disinfo.com/2016/01/why-did-the-fbi-operate-a-child-p...
In context, it sounds even harder to justify.
And they didn't operate the servers because they wanted to give platform to child porn users, but because they wanted to catch the users.
If you use a cp site of your own free will without encouragement from law enforcement, then it's not entrapment just because the site was operated by law enforcement.
Like leaving open bottles of spirits in alcoholic's rooms if there were prohibition.
When you exempt certain agencies from the law, they will inevitably abuse that power. In these conditions it was acceptable. However, setting up a CP server as a honeypot crosses the line and blurs the line between stopping and supporting it.
It wouldn't have been so easy to get information on 200 real cyber criminals.
Do you have a citation that a pedo has less IQ than the average member of society?
I think by using Tor that puts them in the top 1% of internet user knowledge, which is against your statement.
Whether that means they have a lower IQ than the average member of society though, that is a whole other thing.
There used to be an image on 4chan that was posted quite often. On the image you would see a link to download the Tor browser and then onion urls to the main child porn websites.
Those people are not crypto experts. They are idiots that followed an "how to child porn" infographic.
Two Virtual Machines, the one you actually use for browsing and stuff only connects through the gateway virtual machine.
If an exploit breaks out the firefox skin, it is just in the host VM, if it somehow breaks out of the host VM it is in the gateway VM.
We could keep going down possibilities, but we are far removed from attack vectors that actually exist.