I Know What You Download on BitTorrent
iknowwhatyoudownload.com
iknowwhatyoudownload.com
Sort of "IKnowWhoKnowsWhatIDownload".
I wonder if they share their data with law enforcement, because there appears to be al lot of valuable data to be mined in the DHT swarms. This service reminds me of the crux in the most recent south park season.
* SPOILER *
Wherein world-order is threatened by the 'troll-trace' program that will expose the on-line behaviour of everyone.
* END
Of course law enforcement don't operate on guaranties and even weak evidence can help if a already suspected person is involved in an investigation, but its important that we distinguish between weak evidence vs strong evidence. The GetPeer reply is about as good as an anonymous tip arriving by email.
It mentioned that I downloaded the following on Dec 11th:
1. Office 2016 Pro
2. Assassin's Creed Unity
3. Watchdogs
Not only is it completely inaccurate, no one used my internet on Dec 11th (which meant my IP was probably shuffled by my ISP to someone else).
This is one of the reasons why you should probably take all those DMCA notices with a pinch of salt...it's almost impossible to argue that you pirated in the first place.
Wouldn't the ISP be able to prove you were assigned that IP at that time of day?
You can't really take DMCA notices with a "grain of salt". Many ISPs will just cut you as a customer after you get enough of them, as DMCA notices require effort on their part and the amount of effort their IT and legal staff spend dealing with other IT and legal staff looking for you quickly exceeds how much you are paying a month. So unless your area has an overabundance of ways to get internet to your home (in which case you must not live in America), you probably can't afford to have your ISP ban you from using their service.
After you do that, they basically forget all the notices (although the copyright holder can still sue you).
Most copyright protection services, generally just grab thousands of IP addresses and send notices (without knowing who you really are). If you do respond, they'll then sue you if you refuse their exorbitant fine (along with countless others who did the same - as it's generally too expensive to sue just one person).
An IP address is not grounds for proof anymore. It's like saying every citizen is assigned their own IPV4 address, which is likely wrong, as more often than not an IPV4 address is shared by a pool of users.
Carrier-grade NAT (CGN), also known as large-scale NAT (LSN),
is an approach to IPv4 network design in which end sites,
in particular residential networks,
are configured with private network addresses that are translated
to public IPv4 addresses by middlebox network address translator
devices embedded in the network operator's network,
permitting the sharing of small pools of public addresses among many end sites.
This shifts the NAT function and configuration thereof from the customer premises to the Internet service provider network.IPv6 all the things.
I'd bet they're pulling popular torrent files from big sites and then pulling peer lists from the DHT. This will work OK for 'hot' content, but they could probably get much better lists if they actually connected to swarms and did peer exchange (PEX) which clients effectively have no control over - it's up to their peers if they are going to reveal addresses through PEX.
Also note that of course none of this will work for private torrents (which almost all clients respect) as they disable all methods of peer/metadata acquisition other than from the trackers directly.
For example:
https://iknowwhatyoudownload.com/en/torrent/?infohash=81ac3d... -> magnet:?xt=urn:btih:81ac3df677afb84211d59443fbb65f5f584cfa1a
Paste into torrent client and download. You might want to doublehash that to avoid a potential legal threat.
[1] https://torrentfreak.com/i-know-what-you-downloaded-on-bitto...
IPv6 is unsupported temporary
Odd though, if you don't support searching via IPV6, why have a website that accepts IPV6 connections?
Edit: Likely because they are using Cloudflare, which bridges IPV6 to IPV4. They should probably turn that off until they support IPV6 searches...it's under the network settings in cloudflare's control panel.
Our system collects torrent files in two ways: parsing torrent sites and listening DHT network. We have more than 500.000 torrents which where classified and which are using now for collecting peer sharing facts (up to 700.000.000 daily). We don't guarantee we can show ALL peer sharing facts:
Single IP address could be assigned to multiple users. It depends on user's ISP. For example mobile operators often used this schema.
- IP address could be dynamic. In such case it changes every
- time user connects to the Internet or periodically.
- User could donwload torrent which we don't have
This makes sense if you think about the kinds of traffic you'd expect from the most common uses. There's a pretty limited set of categories that most Internet traffic can be grouped into, and they all will have pretty distinct and identifiable patterns - commercial streaming will be slow and steady, downloads will be bursty, VoIP will be small streams, etc.
For sophisticated enough systems or determined investigators with enough raw material to examine, they may even be able to get a decent guess at what sites you're using (even via a VPN) if you're only doing one activity at a time. If they can identify that almost every video view on YouTube starts with a particular traffic pattern of sets of blocks of data of roughly identifiable sizes and that video views on Netflix, Vimeo, Hulu, YouPorn, or whereever all have different patterns, they can approximate which sites you're visiting - particularly given enough data over time.
[NSFW - adult links] https://iknowwhatyoudownload.com/en/peer/?ip=173.254.222.162
https://iknowwhatyoudownload.com/ru/contacts/
Screenshot: http://imgur.com/a/PTiDT (under the title "Сотрудничество", which means "Cooperation").
Here is my crude translation:
...
Cooperation
============
We are ready to share data on an automated basis, in a different cross-sections and formats. Besides we do have the technical means for "catching" users, who do participate in the torrent-file seeding. By means of connecting to the user's device and subsequent downloading of one tiny piece from the torrent-file, it is possible to collect a TCP-dump of the data exchanged for that piece. There is a unique fingerprint associated with both those data exchanged and the torrent-file itself [0]. That allows to prove the fact that torrent distribution had been taken place from the particular IP address [1]. Everything mentioned above will be potentially actual/useful in Russia [2]. If interested in cooperation, you could let us know: <cooperation-email-address>
P.S. We also have means/possibilities to build recommendation systems, to de-anonymize torrent-trackers users and much, much more.
...
[0] I guess, they speak about "piece" from the "info" array: https://en.wikipedia.org/wiki/Torrent_file#File_structure
[1] They have downloaded it from you, so the fact of the distribution, am I missing something?
[2] http://hitech.newsru.com/article/03oct2016/piratefine || https://translate.google.com/translate?sl=ru&tl=en&js=y&prev...
"The company informed us that the site helps to showcase their abilities to the various outfits they work with, including copyright holders.
“We’ve set up the site for promotional purposes and as a demonstration of our capabilities,” Marketing director Andrey Rogov says.
“We are engaged in the distribution of information relating to torrent downloading activity to rightsholders, advertising platforms, law-enforcement and international organizations.”
The company offers API access to its data for interested parties and can also provide TCP dumps as extra proof that downloaded content is linked to a certain IP-address."
https://torrentfreak.com/i-know-what-you-downloaded-on-bitto...
We are ready to share our data, providing automated API to raw data or aggregated reports. We also have technical means to catch users who share torrent downloads. By connecting to user's computer and downloading a small piece of torrent, we can get a TCP-log of communication with the user. Data in this log have a unique "print" - crypto hash, which matches hash from the torrent. This allows to indisputably prove the fact of distribution of content from a given IP address. It will be important in Russia soon. [...] P.S.: We also can build recommendation systems, deanonymize users of torrent sites and many other things.
I don't think so.
I'll never forget my first ip address.
Checked the last dozen or so IP addresses I used. I don't see a single valid result. I torrent lots from the most popular torrents on the biggest site. You'd think it could get that right.
> IPv6 is unsupported temporary.
This is creepy.
Bittorrent peers are fundamentally public by design, unless the torrent is marked private, so this is just curating and presenting that information.