IP address errors lead to wrongful arrests
nakedsecurity.sophos.com
nakedsecurity.sophos.com
As outlined in the article:
* most residential IP addresses are dynamic
* more and more carriers are using cgNAT as they exhaust IPv4 addresses
I'd like to add a third case that I feel is often overlooked:
* most consumer or ISP provided routers never have their firmware updated (unless the ISP pushes the update themselves) and are probably vulnerable to mirai, KRACK, and many others.
Taking a these into account, even if LEO is able to get the correct information for an IP address, there's a non-zero chance that the people had/have a compromised device.
No average consumer is going to be able to prove to LEO or a judge that their device was compromised, and I somehow doubt doing forensic analysis of the person's network is top of LEO's list of evidence to gather. Additionally, many compromises can be ephemeral so by the time the deed is done and the police show up, the router has been rebooted and evidence of the compromise is gone. There is zero chance that LEO is dumping RAM of the router before seizing it as evidence.
Combine this with the fact that people may have an encrypted device and may legitimately forget the password before being requested to decrypt the device. I'm sure this can happen, as being arrested and going to trial can be quite stressful.
The US government is already indefinitely detaining people for not decrypting their devices. [1] I'm not saying the suspect in this case is innocent or guilty, but consider what precedent is being set there.
I don't see heading anywhere good...
[1] https://nakedsecurity.sophos.com/2016/04/28/suspect-who-wont...
Here in Germany, authorities treat IP addresses as very weak forms of circumstantial evidence due to the issues you mentioned (CGNAT, compromised devices). Nobody is going to be convicted purely based on an IP address.
(Disclaimer: I'm not a lawyer, exceptions apply)
Making a statement just to avoid an edge case is what we hackers like to call "boilerplate". We don't find it useful, and generally prefer to avoid it, both for the writer and the reader.
"This person seems really knowledgeable on law" which leads to
"Must be some sort of a lawyer"
They then go on to assume they have gained valid legal knowledge.
I have heard that even starting torrent program will get you fine to your inbox.
How do they trace it?
However, there's bunch of companies monitoring popular torrent trackers and since it's all peer-to-peer, they can easily figure out your IP address as soon as you start downloading a torrent they're monitoring (they usually work for a particular distribution company and have a list of files they're interested in). Popcorn Time and similar apps are a common and obvious target.
Once they know your IP address, ISPs are required to disclose your personal data (§ 101 UrhG) and they'll send you a nice letter requesting a payment (Abmahnung). If you do not pay, they might sue you (but probably won't).
If they do sue you, it's on them to prove that it was indeed you who used the IP address at the time, which is - in most cases - an impossible feat.
So, yes, you're highly likely to get in trouble if you torrent in Germany, but you'd probably win of you fight it.
You ban it, and they'll switch to something else, and you'll have done nothing but make things slightly less convenient but with relatively large cost to enforce. Why not just do the job properly and ban general purpose computers, limited to government approved and locked down hardware, os and apps?
One IP per person really doesn't hold.
Edit: this is incorrect apparently.
I don't have AT&T so I didn't pay much attention to the details. One possible approach: https://github.com/jaysoffian/eap_proxy
It has the same affect on you as your neighbor does.
Bandwidth would be unaffected. Or more exactly, on WiFi (but not Ethernet): as affected as if your close neighbor used that amount (since WiFi itself has limited bandwidth). The connection from the router to the cable modem has lots of headroom, so that would be unaffected, as would wired connections.
IANAL, but wouldn't a presumption of innocence require the prosecution prove that their evidence is not mistaken?
In theory perhaps, but in practical terms your mileage may vary widely. I'm not sure about the rest of the USA, but in the Chicago area Comcast appears to have pretty much abandoned rotating dynamically-allocated IPs, and I suspect many other carriers have something similar. On the other hand, experience last year with attempting to whitelist a remote user living in Germany showed that at least one ISP there appears to rotate home IPs every few days.
A quip. But also, I think, how things like this work.
You can ask the ISP. They are supposed to store metadata.
What you say is true, but prosecutors/investigators have little incentive to jump through another hoop. If they are willing to prosecute someone with just circumstantial evidence of an IP address, they aren't really looking to find the perpetrator, only a fall guy.
Similarly, if I torrent pirated media in a Starbucks, should the store be charged?
In my state, that was specifically to cover "well, if you deny driving the vehicle..." situations, where people would say "Oh, it wasn't me, I lent my car to someone/my kids drove/whatever", and law enforcement replying "Who?" "Oh, I don't know. Sorry."
Now it's to increase the burden of proof. It's reasonable to assume that if you own a vehicle, you were driving it. It's furthermore reasonable to assume that you should be able to identify who was driving the vehicle, from the face, even if you do have multiple people driving.
If you then refuse to identify the person, or "I don't know", then it's tantamount (in the law's eyes) to saying you weren't taking due regard to the care of operation of your vehicle (after all, if you don't even know their name, how do you know they're licensed?).
Computer crimes are the same way. It may be possible to prove what equipment it's implicated in a crime, but that's rarely sufficient to make any individual responsible without other evidence. People give WiFi passwords to their guests, equipment is hacked, etc. Establishing that an owner of a router or computer is responsible for anything it is used for unless proven otherwise opens a massive attack surface for blackmail, extortion, etc.
> Cars are stolen with significant frequency, for example.
Presumably you'd report your car stolen, no?
> People also drive them without permission (e.g. a spouse gives the keys to a visiting in-law).
Then you'll be able to identify the person via a picture of their face, most likely, no?
> Establishing that an owner of a router or computer is responsible for anything it is used for unless proven otherwise
I'm not trying to say any different, in fact I'm saying that it is a "reasonable" assumption, and as with any reasonable assumption there are notable exceptions, by which showing the driver's face is a reasonable method by which saying "No, Your Honor, the person driving my vehicle is not me". In some states you may not even be obliged to identify the driver, only show that it "is not you".
https://technet.microsoft.com/en-us/library/hh278941.aspx
"When you attach your computer / computing device to the Internet it's no longer yours."
and from that:
"There is no such thing as nonrepudiation on any computing device which is not actively monitored by an outside, independent, air-gapped system under the strictest of operational control."
Which takes us here:
"No credible forensics expert can tie user interaction to any specific event or file on a computing device with any certainty as no forensics expert can be aware of all attack surfaces and vectors over time available through the platform they are reviewing. Nor can they be aware of attack motivations and the capabilities of an attacker to obfuscate said attack."
Since the 1990s I have been very bothered by the practice law enforcement follows of using IP addresses as evidence against people. I can't imagine how many fathers have had their lives ruined because their young teen son went searching for something they shouldn't have, or because someone used their open wifi connection, or routed through them via malware, or spoofed that IP address, etc. There are multitudes of ways in which it might not point to the right person.
And it is very important to remember that when you act on information that points at an innocent person - you are protecting the actual offender. You are shielding them from prosecution. You are guaranteeing that they remain available to continue to commit the crime you are investigating. I would think, just generally, police would be motivated to not be providing that sort of shielding... but getting those headlines seems to just be so damned tempting...
The stakes are low. Nobody in law enforcement (or government in general) stands to lost their job or have their career ruined if the organization they run ruins someone else's life in error. It's no surprise that they play fast and loose when it comes to anyone who isn't part of their in-group.
What percentage of the victims of this kind of error are also getting their hard-drives tampered with fake evidence like child porn. There is an incentive on the police department to not back down if they arrest someone - they can get sued - a hard drive full of that would have that lawsuit thrown out very quickly and likely without anyone wanting to pay for an external investigation.
Those of us who do understand don't have an appealing alternative, because the entire thing is nonsense.
We have the same problem with DRM and software patents.
For example, a post office box is a real address, but what goes in can be put there by anybody with access to the box, whether it's with the key from the customer side, or from the open back from the post office side. Similarly, what goes out can be removed by anyone with access to the open back of the box, or from the front with a key. No one checks to ensure that the holder of a key is the owner of the box.
Of course this is a very blunt metaphor, but with it one can see the light go on....
It's the public, the yokels on the jury, that you need to correct the perceptions of. When most of them get their CS understanding from daytime television crime procedurals, you have a lot of work ahead of you.
An educated person such as yourself might be able to influence the other jurors (or at least hang it), and we can't have that. It's much easier if everybody simply accepted the prosecutor's explanation of how IP addressing works.
You can either go online and claim to be a turbosexual 15 year old whose parents are out of town and bust anyone who shows interest and net 5 busts in an evening.... or you can investigate the most profoundly disturbing case of your career of parents abusing their own children for months and then get 1 bust. The police make the easy choice, and the kid getting abused by their parents (the absolute most common case by a country mile) gets no help. Child advocacy groups do not waver in their mantra: Education and empowerment. They are the only things that actually STOP child abuse. But they're not as flashy and quick and easy, and society generally doesn't want to educate or empower kids, so everyone just does what makes them feel good without thinking too much about whether it actually helps real children.
It plagues our judicial system from the most trivial crimes (speeding), to the most awful (sexual abuse and murder).
Still I understand the prosecution. Pedophiles and other assorted scum know OPSEC and society wants criminals off the street. So just letting people walk because they were clever enough to encrypt their HDD is not an option.