Access Now and EFF Condemn the Arrest of Tor Node Operator Dmitry Bogatov
eff.org
eff.org
In Russia? You sure about that? I wouldn't be, if I lived in Russia, and I'd be much less so today than yesterday. It wouldn't surprise me if this prosecution were intended to make a point, in the characteristically subtle style of the modern Russian government, that regardless of what any potentially relevant legislation might say, running an exit node, and by extension acting in ways that help conceal communications potentially of interest to the state, isn't a very good idea if you cherish whatever stability and comfort your daily life affords.
The modern US government, on the other hand, has tended to be rather less blunt about making such points, and to choose different such points to make.
I reckon this was their point rather than a rebuttal. They seem to believe it is legal as well as a right and they're going to at least try.
Would I do run a tor node? Not in Russia and prob not in the US where I live. I am glad a global network of people are braver than I am.
I value privacy and support VPN use, but for some reason this seems different to me. Maybe something to do with a VPN being a company using servers to create an obvious layer of identity protection that police can generally subpoena when of importance.
By running a Tor exit node, this individual was consciously allowing his IP address to be used for potentially malicious purposes. Why can't it easily be compared to someone making a cover for or assisting a criminal they don't know the identify of, which would be a crime if committed in person? Investigations lead back to him because he put himself in that position.
analogy: VPNs seem like concealing your ID from everyone, however police can sometimes work to see it if a court deems it justifiable and necessary. Individuals running Tor exit nodes seem like being given someone else's ID instead, with no trace otherwise.
Untraceable VPNs (ones unaffected by subpoenas) are somewhere in the middle, but the primary issue I see with this is the Tor system's use of someone else's ID rather than hiding your own (investigators are aware when they find a VPN service's IP).
Wifi seems different in that it's somewhat traceable when necessary, and the person or institution would likely help with that in cases of serious issues, unlike willingly putting your personal identity at the end of an anonymized network you can't control the actions of.
I support privacy in almost every case, but this even prevents actual subpoenas of serious magnitude or importance, and makes that individual the final point of contact, you know?
IP addresses of what is connected to can be hidden by proxies or anonymizing networks, or even just TLS. MAC addresses are spoofed routinely. It's wireless so fat chance it's reachable from places not under your surveillance, if you have any of that in the first place.
I also don't agree that an IP address is your personal identity, I think that's a very harmful idea. I am not a computer and I just barely control part of what my machines do.
Do you believe in the possibility of a risk-less society?
I agree with you that an IP shouldn't, in every case, be your personal identity and that legal situations should take context into account. Everyone from advertisers to the government uses your IP address as a personal identity for you, though. It unarguably leads investigators to your person, and that's our only real method of dealing with cybercrime. Leading investigators to an incorrect individual seems different than to an obvious wall, such as a VPN, that would require a lot of effort and justification on the investigator's part to break through.
Risk-less society in what way, if you could rephrase?
That's a very debatable claim, from both a legal and technical viewpoint
I highly doubt that an individual who commits a serious crime over the internet without masking their IP won't be investigated.
Wifi routers are insecure and often can't be flashed with more transparant/secure software, so in practice anyone within 100m with a directional antenna can connect to your wifi.
People let guests on wifi, and students tend to share internet connections.
Some devices randomize their MAC address by default (Apple stuff I think) and MAC addresses are trivially spoofed.
If I'm on your wifi router I can probably spoof the MAC addresses of any and all of your devices, and I definitely can if you've ever connected to an AP managed by me.
Lastly, ISP's can spoof everything and fabricate logs with ease.
So no, technically there is no proveable link between IP address and person or device. Perhaps legally but that has no bearing on the technical reality.
EFF agrees with you: https://www.eff.org/wp/unreliable-informants-ip-addresses-di...
Is providing a public service a "good enough" reason?
If you provide free classes on bomb-making, should you bear any responsibility for how your students use the knowledge? Just because you're offering a public good/service doesn't absolve you of responsibility.
If my land had a trail through it that I knew was being used for human trafficking but also for natural resources preservation, I'd still have a problem with that "road".
And, yes, it doesn't really matter what setting the bomb-making class is held in the teacher arguably should bear some accountability.
For example, you assume the police are legitimate and not the tools of an oppressive government.
For example, you are completely ignoring non-"malicious" purposes for disguising origin, say whistleblowing.
Finally, you are equating providing a legitimate service that may be used for a crime with actual facilitation of crime. We should lock up telephone company execs on this theory.
Complaint: Individuals as tor exit nodes presents a fake identity as opposed to a lack of an identity. Fake identity seems problematic.
- Internet freedom around the world declined in 2016 for the sixth consecutive year.
- Two-thirds of all internet users — 67 percent — live in countries where criticism of the government, military, or ruling family are subject to censorship.
- Social media users face unprecedented penalties, as authorities in 38 countries made arrests based on social media posts over the past year. Globally, 27 percent of all internet users live in countries where people have been arrested for publishing, sharing, or merely “liking” content on Facebook.
[1] https://freedomhouse.org/report/freedom-net/freedom-net-2016
Does the existence of the latter negate the former?
To claim that is an answered question is myopic to me.
Would uber be if one of it's self driving cars is used in a crime and they cant provide the real identity of the user ?
If anything, he's a victim. Someone used a public service he offers in a way contrary to its (implied) TOS.
If you want to run exit nodes use a hosted server. It separates it from your normal traffic and makes it clear that it has a specific purpose.
Notably, BrightCloud (Webroot) is such an ill-informed provider, and Dan's DNS blocklist offers both exit and relay lists (the latter is an attractive nuisance). Care2 is a consumer that blocks intermediate relays, although only on their http: traffic, not https:. (I'm guessing their SSL termination proxy messes up their IP detection!)
The odd thing is that the Tor Project provides an easy to parse, up-to-date list of exits (https://check.torproject.org/exit-addresses) but these providers go to a lot of trouble to harvest bad data themselves.
No amount of condemnation on part of the EFF and declarations that "running an exit node is not a crime" is going to help Bogatov, where the Russian government has decided it will do what it takes to prove a point. This is how chilling effects work: when it endangers your own freedom and livelihood, you are forced to suddenly re-evaluate your priorities between big abstract issues like freedom of speech and whistleblower protection, vs. holding your head down and hoping you don't get caught up in something much bigger than yourself.
It also proves that these anonymizing networks only function in a free society, and break down in the exact situations where they would be most needed.
i2p doesn't. It is a parallel dark-net.
Am I missing something or could thing whole problem be put to rest, at the same time the rest of the net is transitioning to https only.
Maybe it would help if site took pains to not keep logs, but sometimes even that is difficult.