To keep Tor hack source code secret, DOJ dismisses child porn case
arstechnica.com
arstechnica.com
It's hard to point to anything in this story that resembles "How the world should be".
Wouldn't the right word be "principle"?
The details are sketchy, who prosecutes the police/prosecutors? But in principle I think it makes sense.
Alleged criminal. You realize you're innocent until proven guilty, right?
Not if the officer going to jail is being manipulated by their superiors or is otherwise arranged to take the fall for someone else.
https://slatestarcodex.com/2014/12/17/the-toxoplasma-of-rage...
"New Brunswick, N.J., police drive their patrol car into fleeing suspect. Officers: We parked in his path, and he rode his bike right into us. Third Circuit: Video inconclusive. No qualified immunity.
The reason we believe the exclusionary rule works so well is that it strikes directly at the incentive structure for the police. We don't have to convince evidence-gathering officers of their liability or assess liability up and down the chain of responsibilities on the prosecution's side; we just have to assess whether evidence was handled properly, and, if it wasn't, the prosecutors lose the evidence. The one simple rule neatly ensures that nobody --- in any role --- on the prosecution's side has any incentive to mishandle evidence (or coerce underlings or partner organizations to mishandle it).
But clearly the rule isn't a requirement. We don't generally believe, for instance, that Canada's criminal justice system is systemically corrupt, and they don't have a hard-and-fast exclusion rule.
That assumes that the police's incentive is simply to convict as many people as possible. Which, if true, raises other concerns.
If they were simply trying to maximize the total number of convictions, then this wouldn't necessarily help; the police would just make broaden the kind of cases they'd accuse
And ofc, it's the function of the police to maximize the misdemeanor to conviction ratio; it's the function of the court to judge the quality of misdemeanor.
It is the function of whatever social/moral arm of the government to minimize misdemeanors. A police officer minimizing the number of accusations should only be doing so for practical reasons; In the ideal world he shouldn't be trying to interpret the law itself, and if it should exist (because it should in general be explicit what is and is not legal, and in general, it is not the policeman's job to decide what is moral, it is to enforce the standing morals.)
But its not an ideal world, and nobody wants to spend time/effort/money on a trash case, so the general incentive is to successfully convict; not to simply try.
Um -- I think you meant that the other way around :-)
Strictly speaking it's not a very reasonable goal. The best way to achieve it would be to pick, say, the three easiest to prosecute cases every year and only prosecute those.
Maximize ratio and minimize unaccounted (unaccused?) crime
But if the numbers = tough on crime, then there is pressure to obtain evidence illegally. If it becomes pervasive, then investigating the misconduct will never be prioritized because it doesn't seem as impressive to the voting public, and furthermore the justice system very rarely goes after their own.
So it's good there's a consequence for not walking a fine line; it's the embarassament of having your work undone.
It also strikes directly at the incentive structure for defendants.
If you prove that the government wronged you but even then you still go to jail, you have little incentive to spend your resources proving that. And neither does anybody else, because prosecutors are not very interested in looking for prosecutorial misconduct.
But if proving government misconduct will keep you out of jail then you have every incentive to do it and the government won't be able to get away with it as much.
That's debatable. Parallel construction seems pretty common. The NSA shares information with the FBI, DEA etc, and then they exploit that information to collect clean evidence. So there's never any mention of NSA help.
Of course, that arguably involves perjury. But judges seem pretty OK with ignoring that. I do suspect that the Playpen cases involved parallel construction, and that they just screwed up on this one.
If a police officer sees a defendant that they wish to let off the crime, all they have to do is testify to some trivial mishandling of the evidence.
Quoting Bill Binney “Things won't change until we put these people in jail”
Secondly, when gathering evidence illigally, it may be that the evidence is purely out of context, shaped to make the person look guilty, or that the methods of doing so are not reliable. Courts still have a problem with reliability of evidence, even 'lie-detectors' are still seen as legitimate, but there is no evidence of their ability.
It's not possible for random people to successfully sue, say, the police for illegally gathering evidence if they have no proof that they were harmed and no proof that it happened.
The issue is that only people charged with a crime have the standing needed to bring this matter up in court. The (possible) crooks keep the police and justice department honest.
In general if a criminal goes free despite having evidence against him just because the evidence was not obtained legally ... it sounds rather wrong to me.
Just imagine undercover police walking into every home that left their door unlocked and having a snoop around. They could do that and get some convictions out of it.
When you gather evidence illegally, it's easier to fake it.
Judge: Did you obtain this evidence illegally? Prosecution: Yes we did, your honor. Judge: Okay, trial on that starts Monday.
No...you'll have to legally make it so the exclusionary rule is not a defense...i.e, the number of times that this is even brought up will inevitably diminish to 0. Admittedly, it does exist, but the legal system tries it damnest to remove gray areas. At the very least, you will need a legal test to prove that the evidence was not manufactured. You know of any?
It could also be the case that it's evidence that was collected by someone who didn't commit the crime, but would currently be excluded by the fruit of the poisoned tree doctrine.
These are _all_ based on someone's word, in a world of Photoshop, text editors, hex editors, scanners and printers, voice synthesis, etc.
Then you are terribly shortsighted. It is "innocent until proven" guilty" for many very good reasons. We have only the word of the government that this man is guilty.
The government has ALL the cards and power, the innocent need protection from it more than we need to punish the guilty.
The accused aren't geniuses; the fact that the government didn't build a solid case against him with physical evidence, wiretaps, keyloggers, etc. means he really wasn't that important. The fact that they have such a high profile suspect and can't make the case against him without a fishing expedition makes me VERY suspicious.
The fact that they are willing to drop the case makes me wonder how much of what they have is induced, entrapped, or outright fabricated.
I'm not talking about _this_ particular case. (I'm not sure that accessing a dubious website is in itself a crime; obviously the police accessed the site too).
Presumably the police _can_ prove it, but the court simply refuses to even _see_ the evidence.
Then you are required to assume that the police CANNOT prove it.
I have several system administrator friends who have actually dealt with CP on their systems. Every single time it was discovered to have been planted by the FBI attempting to fish for pervs.
So, yeah, I'm gonna give the accused a whopping benefit of the doubt. CP is such a hot button issue and so amazingly rare that I always assume that the government or its agents are up to something nefarious first and that someone is a despicable human being second.
Perhaps my Bayesian prior is wrong, but I kinda doubt it.
So does the investigation agency who broke the law.
Evidence gotten through illegal means also get a lot of doubt just by default. Imagine a police officer paying somebody to steal evidence for them. The person now how has an incentive to forge evidence.
An important detail of this system is that evidence brought to the table cannot be trusted without a transparent system. Defendants will almost always contest evidence, but this system makes that argument hold a lot less water.
(There's still the issue that police might not be interested in collecting evidence that goes against a prosecutor's case. Don't know how that's solved)
I wish there were some way to get a private but independent verification that X technique allowed IP addresses to be collected if they did action Y (e.g. logging onto playpen). Then the investigation could be questioned without the government disclosing their vulnerability, which seems like a standard we wouldn't hold most to. If someone were on trial for copyright infringement could they subponea for the full source of FairPlay as a coercion to get the case dropped?
Otherwise you could just create the data. With the above, you still can - it does however allow for inconsistencies to arise, and when they do a closer inspection can be conducted. (IANAL)
You do not get to convict someone based on evidence that can't be entered at trial. Some third party saying "oh yeah we totally verified it" is not enough.
EDIT: It appears that they did do more than just visit the site: https://news.ycombinator.com/item?id=13799213
You don't stumble on "kiddy stuff" on TOR accidentally. You actively seek it. 150.000 is a lot of pedos in the wild.
Banning production I understand fully. But viewing, under the argument it promotes it? The TOR developers have done far more to promote it than any single viewer, especially if we consider those who never paid any money and use ad blockers. Would we say the TOR developers should face some sort of punishment for not working with governments to develop a version that works to stop this (such as integrating something which causes it to drop off the TOR network as soon as it detects an illegal file, probably biases the algorithm against false positives)?
At the very least, I think they should be using all the resources to go after producers and those paying for it.
We're taking it as a given that this guy (and the others) actually committed the crime, but the prosecution cannot actually prove that without allowing us to verify that the evidence gathered actually comes from a place of fact.
So what might these NITs be doing? In the simplest case, they'd be dropping malware that reports ISP-assigned IP address, local IP address, network hardware MAC, and whatever to FBI servers. And it's probably Windows malware.
To protect against that, you isolate userland and the Tor process in separate machines, or at least VMs. So adversaries that compromise browsers etc can't discover ISP-assigned IP addresses, and can't reach the Internet except through Tor. Also, you don't use Windows or OSX. Whonix does this, and you can run it in Qubes.
It's possible that these NITs are exploiting a bug in Tor itself. Even if that were so, however, isolating the Tor process from userland would mitigate that risk.
Perhaps the FBI has access to substantial numbers of malicious Tor relays, operated by the NSA etc. To mitigate that risk, you can hit Tor through nested chains of VPN services. Even if they identify the final VPN exit in your chain, they will probably need to track back through the chain to identify you. And by including unfriendly jurisdictions in your chain, you can make that harder.
Finally, it's possible that the NSA has sufficient global intercepts and logs to deanonymize any network connection, no matter how complicated and indirect. It's impossible to say.
This applies as well to people who run Tor hidden services that are doorkicker bait (like drug cryptomarkets).
It should be impossible for a compromised browser or hidden service server or Tor process to know anything about your hardware or MAC address, your internal IP address (the RFC1918 one), or your globally routable IP address.
also yeah the Feeb loves to exploit browsers (especially firefox :^) and make them execute the NIT (which just sends, unencrypted/unauthenticated data of the MAC address, ethernet interface's IP addresses, username, and stuff like that, to a computer run by the FBI)
once one of their exploits got leaked, it was pretty fucking lulzy https://blog.mozilla.org/security/2016/11/30/fixing-an-svg-a... https://lists.torproject.org/pipermail/tor-talk/2016-Novembe...
Nobody knows exactly what the attack is...but if they're willing to drop cases to cover it up, its probably something that either: 1) completely breaks TOR permanently 2) is easy to bypass/block
Since TOR has withstood a lot of scrutiny I'm betting on option #2. They found a total break but it's really brittle. Either an exploit in software, or more likely, some protocol hiccup that allows them to de-anonymize users running certain popular software or OS.
Also if just the exit node is compromised, encrypted connections are still safe (TTBOMK).
Only that it would be incredibly cheap and valuable to do so.
Not the FBI per se, but it shows that someone is clearly attempting to compromise TOR users.
Also there's been whispers about it forever. Much like the "black rooms" at datacentres before all the NSA leaks.
The FBI has a long history of tracking down and compromising CC theft and CP rings, along with silk road and the hoards of clones. Most of these sites are primarily or only accessible over TOR.
Running compromised TOR nodes would be an extremely cheap way to monitor a large portion of illicit Internet traffic. The frequent busts are usually attributed to other reasons to shift attention away from TOR, but this is classic parallel construction.
The feds will nearly always get you on secondary evidence when the primary means is too sensitive... See stingrays. The sheer number of TOR based site busts however is telling.
Anyone relying on TOR for security is a fool. It's more heavily monitored than the regular net.
this is why we should encourage more tor traffic for regular, normal use. making the cost of deanonymization more costly.
Using multiple Tor instances with MPTCP, I've managed 50 Mbps between onion sites with gigabit uplinks.
If i recall, this case is one of the first times the term NIT was used and it could mean literally anything.
They may just want to keep from revealing the details as long as possible -- but could re-file the same charges years later, right before the Statute of Limitations.
* "We have an eyewitness! File the charges."
* "Our eyewitness recanted, dismiss."
* "We now have DNA evidence, refile the charges."
You actually think the trial should not be allowed to go forward?
You can't present the exact same case again after you filed to dismiss...
...unless a major change has happened, such as a massive amount of new incriminating evidence.
Actually, yes. If you filed a case on something so flimsy and it collapses, the case should get dismissed.
It would sure make prosecutors go the extra mile to make sure that there is concrete evidence before filing charges.
Simply filing charges can destroy someone's life. The prosecution should have to put something at risk when they do so.
Also, this is how it happens already if they go through the entire trial.
* "We have an eyewitness. File the charges!"
* "Jury finds the defendant not guilty because they didn't think the eyewitness' testimony was proof beyond a reasonable doubt."
* "We found DNA evidence and even a video that someone recorded but didn't admit to just now."
Double jeopardy means they can't go ahead, no matter what evidence they find. This is just extending that a little further, which I see as a good thing.
It sucks that the pervert in the case is going free (for now), but I would guess the experience scared him enough that he won't be doing it again any time soon.
Perhaps they did use a valuable exploit in this case, or they used something not legal (such as something not covered by their warrant or NSA surveillance).
I might be willing to grant that legitimate cases of national security warrant this, but routine criminal proceedings? Fuck no. That kind of exclusion of the accused is terrifying and delegitimizes the proceedings in my eyes. The state can't try you in secret just because they don't want to talk about the evidence, and we know the state routinely abuses secrecy laws to cover malfeasance.
There were no doubt other steps taken to limit the field of people to charge. Shared computers and shared IP addresses (vpns, school networks etc) seem to have been deselected. The man living on his own, with his name attached to a non-proxied internet connection, makes for an easy prosecution. They must have a far longer list of suspects ... who may now be on some sort of watch list. I suggest they think twice about boarding an international flight with a laptop. Expect to be randomly searched.
- is this only an issue for the prosecution because it happened before the changes to rule 41?
Producing it is of course another matter.
they jail innocent people all the time a give huge payouts or put people away in guantanamo and then also pay huge amounts of compensation.
how about the judge fines the law enforce and gives the fine to orphanages or to the victims.
If you are being serious, I'd like to direct you to the wikipedia page on the topic: https://en.wikipedia.org/wiki/Think_of_the_children
"In debate, however, as a plea for pity, used as an appeal to emotion, it is a logical fallacy"
And now we find that when it comes time to actually use these tools to protect the children, the secrecy of the tools is more important.
I believe I see what you mean, however in a case of child pornography do you not think that it's in a human's best interest to keep something from abuse of naivety?
>And now we find that when it comes time to actually use these tools to protect the children, the secrecy of the tools is more important.
I don't want to get into too shaky ground, but if you can de-emotionalize the issue, prosecuting the consumer of the material isn't directly protecting anybody. That picture was taken no matter how many people look at it. You wouldn't expect the government to prosecute everyone who looked at the stolen pictures of celebrities that came out a few years ago. The government is now using this to legitimize surveillance, actively attempt to circumvent security (which is illegal), and to hide the circumvention methods. That's bad for everybody. Child porn is horrible, and horrible things happen to children, but an authoritarian government with massive, legal surveillance power is worse. The road to hell was paved with good intentions.