In ‘Anonymous’ Raids, Feds Work From List of Top 1,000 Protesters
wired.com
wired.com
The "crime" here is not sending packets to DDOS PayPal but criticizing the goverment. The goverment is in turn showing they're not afraid to destroy lives of those who do.
DDOS attacks are pretty much an epidemic on the internet. I'm pretty sure every major company like Google or Microsoft or Amazon has to deal them on a regular basis (http://mashable.com/2009/12/24/ddos-attack-amazon/ for just one example of an attack that was actually successful and well publicized).
Huge botnets make it relatively easy to launch an attack.
This is not some new fact - existence of bots, DDOS attacks on many hosts, that's been known for years and yet this is one of the few times where feds lifted a finger to combat it and certainly the first time where it's done on such a scale and based on such a flimsy evidence and small transgressions like an individual running a DDOS tool (which, by itself, is not nearly enough to bring a website down, it only works if many people are doing it at the same time).
This is not a coincidence and not really that surprising - you fight the goverment, the goverment will fight you.
> Then it sounds like the Feds already had all their
> stuff in place to collect the data while the attacks
> were happening.
[citation needed]My read says that PayPal had some sort of network monitoring system in place which allowed them to capture data during the attack. They then handed this information over to the Feds.
So they're going to arrest a kid for sending an average on one packet every two seconds, over the period of two-and-a-half hours?
It really raises question as to whether you can trust something as flimsy as an IP header given the technical sophistication of Anonymous. These people could well be innocent and in fact victims of anonymous directing attention away from itself and towards these innocent victims. When Anonymous can gain control of HB Gary and FBI/CIA assets imagine what they could do to an off the shelf system that hasn't been through the rigorous security protocols that HB Gary, the FBI and CIA follow.
Given the mutability of data on a USB stick I'd also be very interested to see the chain of custody on that data and how it might have been modified. Also, the defense should request access to the source code for the IDS system in question so that it can be examined for bugs and problems that may affect its ability to generate reliable evidence.
This is wishful thinking, but there is a sense in which it is true. People running LOIC are typically if not exclusively clueless mooks duped into doing so by people who know better.
For all the mythos around Anonymous "having no leaders", I doubt very strongly that you'll find many examples of people who spontaneously downloaded LOIC and started flinging packets at PayPal. Instead what you'll find is people who say they got the idea from an image posted on 4chan (or elsewhere) or from "some guy" on IRC.
All you have to do is convince someone to willingly join a botnet (or anything else) is that 1) this is a way to relieve their angst and 2) other people are doing it. The affidavit even includes examples of the kind of image instructions that accomplish exactly this. The "orders" spread as would memes, and the originators of those orders put themselves at almost no risk to distribute them, while "innocent" members of the herd get caught.
Indeed: "When..." But AFAICR, Anonymous didn't gain control of either FBI or CIA assets. Hacking a self-described FBI "affiliate" and DDOSing cia.gov are hardly the same thing.
Also, holding up HB Gary Federal as an example of an organisation with "rigorous security protocols" is an amusing claim with no real evidence.
On balance I think the idea that DDoS is "ok" and should be tolerated is not a good road to travel down.
Regardless, it's questionable whether a DDoS and a sit-in are comparable. For one, DDoS does not require the presence of the individual, this makes it more difficult to form a connection with their cause and the activity. For another, a sit-in doesn't typically totally shut down a business, let alone at a national scale. With a DDoS a very tiny minority of people are able to disrupt the business activities of millions. This is not the sort of thing that we want to become accepted a legitimate form of protest. You may think it's all well and good when people who are "fighting" for causes you believe in are "sticking it to the man" but if it becomes the norm then everyone with a grudge will use it. And then it won't be the "good guys" wielding the power it'll be the people most fanatical in its use who will get what they want.
If you want to find a form of protest that mimics a sit-in, fine, go ahead, by find something other than DDoS, because that isn't it.
Furthermore, sit ins are by definition denial of service attacks. Assertions about differences of scale are 1) irrelevant, 2) questionable (most DDoS fail miserably).
This has nothing at all to do with my approval or disapproval of the politics.
As far as sit-ins vs. DDoS, it's patently ridiculous to say that scale is irrelevant. If I steal a single penny that is a much different crime than if I were to steal a penny from everyone in America. And if I stage a sit-in at a place of business and deny one or a handful of customers the opportunity to do business that's incomparable to if I deny a thousand or a million people.
One of the core reasons why sit-ins are a respected form of civil disobedience is because it preserves an important aspect of scale. One person one seat. The more popular a cause is and the more people are dedicated to fighting for it the more effective the sit-in can be. But unpopular causes will find it tough to use a sit-in to advance their agenda. The public will ignore their cause and turn a deaf ear to their arrests. And no one will take their place at the sit-in once they're gone. That sense of scale is important. In contrast, a DoS becomes very much more akin to a bomb threat or breaking windows. Because a far smaller and less popular group can effectively disrupt the business activities of a very large number of people. That is not in any way a good thing.
But I think the analogy to a bomb threat or breaking windows is a bad one, primarily because it's likely to be misunderstood. I'll agree that those are more similar in the sense of scale, but that's about the only similarity. Bombs and stones damage both property and individual human lives in ways that are likely to be traumatic and irrevocable. A DDoS is peaceful, causing only a temporary financial effect on a business.
He had the functional impact of a single person at a sit in. No, realistically even less.
I suggest you read this article, since I am beginning to suspect you are operating under a very very distorted definition of the term: http://en.wikipedia.org/wiki/Sit-in
They're going after these people to make an example of them, not because they did anything actually harmful.
One person taking a book means others can not see the same book. Acceptable DoS because the owner thinks you may purchase it.
One person taking several books means others can not see the same books. Questionable DoS because the owner thinks you're screwing around.
Many people doing taking several books out in the store leaves the owner to suspect a DDoS attack because there's not usually that many people and none seem to want to buy. It's especially malicious if there's intent.
Ugly thing about DDoS is that since there's unexceptionally large amount of people and no books to check out, loyal and new customers will be put off and may not return causing future loss.
Probably a crime, but a pretty minor one.
Any real protest in front of a real store is in turn also kind of DoS - thinking about that i wonder whether real protests can be more successfully prosecuted on such a grounds, especially that stretching DoS to an "act of domestic terrorism" is very acceptable today.
As a general principle, if it is illegal for one person to perpetrate an act against a victim, I don't see how it should not be illegal for a large group of people to perpetrate the same act, even though the individual contribution of each member of the large group might be small enough that if he were alone it would not rise to the level of a crime.
To do it any other way would open up a hell of a big loophole, it seems to me.
And why are people complaining about the FBI going after people anyway? It's their job to catch (probable) criminals, so they can't really start deciding which ones to pursue. It's the judges and jurys (and lawmakers) who make that decision.
How to launch a worse attack than these people did:
1) Browse to website. 2) Place heavy object on F5 key.
Seriously.
Man, they executed a federal raid with FBI agents over something that amounted to a few thousand "slowlaris"ed GET requests over a few hours?
How much does something like that cost? What, 2-4 agents, 4-8 hours, seizure, paperwork, court filings, etc. Tens of thousands of dollars, right?
I want a tax refund.
"what is the digital equivalent of civil disobedience and protest?"
Put another way (and translated into meatspace), environmental protesters don't win when they chain themselves to a tree to stop it from being cut down. They win when they are confronted by the authorities, hauled off to jail, and covered by the media, making people aware of their protest. Simply blocking access to the site and hoping there will be no repercussions is basically pointless.
Not necessarily. Some civil disobedience is symbolic, as you describe, some is direct action. Some acts of civil disobedience have succeeded even though there have been media blackouts, mostly because the cost of continually arresting protestors who refuse to back down exceeds the downsides to negotiation.
I didn't see Anonymous turn themselves in, did you?
That's not, actually, a requirement of civil disobedience, and never has been, historically. For instance, millions broke the salt laws of India, but only 80,000 were arrested, and I can guarantee that the remainder did not voluntarily turn themselves in.
http://torrentfreak.com/ip-address-not-a-person-bittorrent-c...
Good thing that's not what the FBI is doing.
can we really say for sure who caused any transmission from a PC?
If a computer is seized from a teenager's bedroom and it has LOIC installed and it isn't malware-infested...
Are you not bothered by the notion of a warrant being issued for search of your home and seizure of your computers based on nothing but an IP address?
I'm extremely bothered by that, personally, because I know enough about networks to know how very shaky that "evidence" of identity is.
Given that having your computers and data seized is already punishment for a lot of people, possibly significant and life-altering punishment, I think courts should be damned careful about allowing police to take that action. I've known people who's businesses have been destroyed by computer seizure. And I've known people who have only gotten their computers back years later (which effectively is the same as "never", because computers have a relatively short shelf life), despite no charges ever being brought against them. My business probably wouldn't currently be destroyed by the loss of all of my personal computers, but it would certainly be a very serious hardship, far beyond what I feel would be just punishment without a trial. And, seizure of all of my servers (including the ones where the backups are stored) probably would very nearly destroy my business and cost me tens or hundreds of thousands of dollars in lost sales and data.
A search is one thing, effective theft of my means of putting food on my table is something altogether different, and I think police ought to have to have a pretty damned good reason for taking away my livelihood for an indeterminate period of time.
>The standard for a search warrant is lower than the quantum of proof required for a later conviction. The rationale is that the evidence that can be collected without a search warrant may not be sufficient to convict, but may be sufficient to suggest that enough evidence to convict could be found using the warrant.
http://en.wikipedia.org/wiki/Search_warrant#United_States_of...
I'm simply uncomfortable with the level of the bar on probable cause with regard to IP addresses, given how little information an IP address actually provides, even when government has cooperation of the ISP to identify users of that IP during the actions in question.
I'm also uncomfortable with the history of how computer seizures have been handled, and how little respect is shown in such cases. Given that seizing computers is not the same as searching a home; once a search of your home is over, it's over. With alleged computer crimes someone's business could be destroyed by the time the computers and data are returned. And, historically, it has occasionally required a lawsuit to get the computers and data returned (and the data may have been tampered with or destroyed).
I'm comfortable with using IP addresses to issue warrants -- I don't think it's a stretch to say that a reasonable percentage of the time it'll turn out to be accurate.
The way computer seizures are handled is fucked up, though, totally with you on that.
On the one side, they offer quality articles and have quality resources. They seem to favor the hackers.
On the other side, this article was written by Kevin Poulsen, who had a part in turning over a whistleblower and journalist source to the authorities. Kevin Poulson has made himself too related to anonymous and WikiLeaks to be regarded as objective on these matters.
I know that isn't reason to judge any article of his, but the extra care I'm forced to take when Poulson is involved (consider his sources, morals and agenda), leaves me with a sour taste in my mouth and an inability to enjoy reading this article.
Why?
The FEDs targets would be the financial, administration of the botnets used in the DDOs attacks..
The arrests are to put pressure on the alleged criminals to turn in the others..
The FEDs are after who is controlling the botnets in the DDOS attacks in the long term..
And you will not see the arrests of those for awhile as far as what appears in the press a the FBI can lock that down for 90 days as far as anybody knowing that you are being investigated..