The FBI Identified a Tor User
vice.com
vice.com
The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content.
If your adversary is a state actor, particularly the U.S., tor alone is not sufficient for anonymity. It's fairly safe to assume they have the ability to deanonymize you. Your only safety net, it seems, is the value of other targets relative to you when it comes to them burning their "golden ticket" zero day. And even then, you're at risk of parallel construction.
If you're sitting in front of a computer that you're using for something the U.S. government has significant interest in prosecuting, that device should be considered compromised and adversarial - you should act accordingly.
https://www.wired.com/2017/03/feds-rather-drop-child-porn-ca...
Edit, pulling up from the threads below:
Tor is just a layer. You still have to take measures to separate your identity from the device, the behavior, and the location.
When tor falls, the next question is "what do they see?" You have control over that.
Asking about it on HN is definitely not one.
Relevant xkcd: 538 [1]
Which is why Agora marketplace, digital lawyers, and a slew of others have simply said:
"we no longer operate under any assumption of privacy regardless of measures taken, and have simple refused to operate on the internet any longer."
Which is what the 3 letters want, a chilling-effect to reduce their Herculean-effort to just an Athenian one.
You can avoid being the "easy picking".
When tor falls, the next question is "what do they see?" You have control over that.
You can make things more and more difficult for your adversary (and usually for yourself too) but if they are dedicated enough they can basically outspend you.
Therefore you need to minimize the apparent cost of your actions and their duration. You can afford to be a passing pain in their butt but you can't afford to be the focus of their eye.
the police-justice system is usually broke for commoners. So yeah, if you're not doing a serious offense, they will never catch you. Where I live, you can buy weed. Even if the government says they're motivated to stop it, they don't have the resources to plant police everywhere. If your home was 'visited' by burglars, they would just take fingerprints. They wear gloves, and that's enough to avoid the state actor.
if you're doing a real serious crime, you can kind-ish avoid attention, if you know retention laws and stuff. if the (mostly digital) traces you generated are too old, they would have disappeared or would not be usable in court. if you appeared on mall CCTV months before you did the crime, have been browsing sites over a year before, ... these data should technically have been deleted.- Just don't create new data in the meantime.
In a similar fashion, some white collar criminals host data in their lawyers office. it is so hard to have a warrant for a lawyers office that you can be safe. A law teacher at our engineering college said it was convenient to hang out with a lawyer - just drop your phone in their purse if cops show up.
then, you can avoid some digital communications. Putin and friends are well known for being mostly offline, unlike some ministers at western governments, for example. Send letters, and you will have that perfect forward secrecy.
there has also been some stories about plausible deniability ( https://en.wikipedia.org/wiki/Plausible_deniability ), especially among rogue corporations and corrupt politicians. ie when you create data, you can do it in a way where it says what it says, but it's not meaningful in court.
don't drag attention on you. cops shows teach you how so many criminals are found out after a traffic stop, when they were speeding or ran a red light. The government can't check everyone, so they check those who stand out.
Lastly, I remember watching a youtuber who got out of prison, and who said that three people could only keep a secret if 2 are dead. it's a bit pessimistic and dark, but maybe don't just involve everyone in your crimes.
I would like to know if series like Breaking Bad are (or were) realistic. I know some criminals learned a lot from movies.
Edit : or just befriend politicians, you would be above any law in most places. Someone in France once stole 2.5 billions $ in one shot from the government. It what became known as the uramin scandal, and nobody was caught. So everything is possible.
Exactly. Which is why, not to start a JFK war, I think the Mafia killed JFK. If it were the CIA, or LBJ, someone would have talked. Anyone who knew what happened got whacked.
And note that Jimmy Hoffa got disappeared, albeit 13 years later.
I believe one of the theories about the proliferation of the current organization of political entities is that the only organization that can reliably compete with one nation-state is another nation-state.
Yeah, but if there is an exception to that, it'd be the scenario we're talking about.
Meanwhile, detectives scoured video footage from cameras in the area and picked out a white Hyundai Elantra driving past the house three times before stopping on the fourth pass shortly after 4am. The car left 16 minutes later “at a high rate of speed”, according to Payne
Meanwhile, FBI investigators trawled through Kohberger’s cellphone records and discovered that he turned it off shortly before the attack, perhaps thinking it would help him to avoid detection. The phone springs to life again at 4.48am on a road out of Moscow.
The records also showed that Kohberger was in the area near the house at least a dozen times in the months before the attack, usually in the early morning or late evenings. Investigators said they were examining whether he “conducted surveillance on the King Road residents and was in contact with any of the victim’s associates before or after the alleged offense”.
https://www.wired.com/2012/12/calgary-travel-time-informatio...
- tor + cubesOS set up by somebody you deeply trust (person A)
- on a USB bought by a different person (person B)
- with a network card bought by a different person (person C)
- many miles away, wearing generic clothes in a cafe where people go to work
- different hairstyle and facial hair
- mask
- without having a phone (obv)
- navigating there by changing multiple cars with minimal electronics
- ordering the most boring coffee
- persons A, B, C don't know each other. You don't know personally B, C, but a person(s) D, (and E) can vouch for them.
My gut tells me that the more people you involve, the easier it is to trace you because you will be at the intersection of those people's radii.
The fatal flaw in the plan:
Barista talking to news after person is arrested by FBI: "As soon as they ordered the brewed coffee with no customizations after standing in line for 10 minutes, I knew something was suspicious. Who comes to Starbucks, stands in line for 10 minutes, and then orders boring coffee?"
There's a chance that you'll get caught on camera at Starbucks. But the cameras there, if any, aren't set up to provide full coverage and are rotated every few days.
Don't involve any other people , don't wear a disguise. If you're going to alter your appearance in any way, do it when you meet the seller to pick up the laptop.
added: You might want a burner phone to call the cab. But normally a motel desk will do that if you ask nicely.
If you leave your cell phone at home that would help, but you still risk being tracked by your car or being caught on any number of cameras and identified via facial recognition.
This assumes they are already looking for YOU.
At a certain point, the world is full of so much metadata that you really can't control your own. Want to turn off location services? Make sure you turn off WiFi too, because a list of nearby access points and SSIDs is enough to pinpoint you down to a few meters. Want to spoof your location when using an app with network services permission? You'll need to spoof nearby access points and their transmission power to match them to somewhere in the real world. And you better make sure to do it inside a Faraday cage. Because no matter how careful you are, if someone else is walking by your clever hacking nest, and they do have location services enabled, then their phone will be able to pair their geolocation with your unique access point topology. Oh, and even with the Faraday cage, the fact your phone is seeing access points that no other phone has seen is a unique data point in itself.
Point is, you can be compromised without any action on your own part. Traffic analysis is hard to defeat, but you can mitigate against it by not committing crimes that motivate the government to spend resources on tracking you across disparate systems like mobile networks and traffic cameras. Or if you must commit those crimes, then you'll need to make sure everything you do is in the fattest part of the bell curve for every possible statistical test the government can use to analyze common behaviors.
Not just wifi, bluetooth is used for location tracking as well.
Before the internet and mobile phone age I can only imagine how much harder crimes like this were to solve.
>MMO's are packed with possible communication channels in addition to chat. Ever wonder if that annoying gnome in the auction hall is jumping in morse code? Could signals be sent with bids? Could a character's inventory contents be arranged to leave a message to someone else who shares the login info? Is that nonsense coming from what you presume to be a bot-controlled gold-farming crew really nonsense? When a game goes to great lengths to simulate a world, the possibilities for covert communication are nearly limitless!
This is a plot device in <http://enwp.org/Little_Brother_%28Doctorow_novel%29>.
It’s a comedy, I don’t think it aims to depress.
https://www.forbes.com/sites/insertcoin/2015/11/14/why-the-p...
>
The hunt for those responsible (eight terrorists were killed Saturday night, but accomplices may still be at large) led to a number of raids in nearby Brussels. Belgian federal home affairs minister Jan Jambon has said outright that the PS4 is used by ISIS agents to communicate, and was selected due to the fact that it’s notoriously hard to monitor. “PlayStation 4 is even more difficult to keep track of than WhatsApp,” he said.
Even with the NSA's budget and infrastructure, I don't think it's technologically feasible for them to decrypt and then semantically process or store that much content. Video is also the vast majority of traffic on the Internet so it would be trivial to hide in plain sight with some creativity (Using stenography to hide content in the video) With 4k you can pack a ridiculous amount of information into even a single frame, and that's one frame among hundreds of thousands, among billions of videos.
I have little doubt that they can store terabits of video content. They let us know about their utah data center (https://en.wikipedia.org/wiki/Utah_Data_Center) which was estimated to have as much as 12 exabytes in 2013 and who knows what data centers they have they aren't mentioning. Back in 2003 they had no problems capturing every bit of data that moved over AT&Ts network. Storage is dirt cheap and they can just hang onto everything until they see a reason to dig into it. No need to process everything right away.
You'd think your video would be blending in with all the other video on the internet, but it really wouldn't. Streaming video put out by netflix is going to look very different than streaming video served via youtube vs streaming video over P2P etc.
Ideally they wouldn't have to search everything when needed and could keep a running file on everyone (because lazily parsing data could be expensive and probably a waste on their existing current resources). That's not to say they can't do it, given that they probably have a huge budget, but it's also not a sure thing they can do it effectively for those who are trying to stay hidden.
Steganography is the word in this case. Stenography is different, it means short-hand writing.
Yep: stop breaking the law. The vast majority the US government has significant interest in prosecuting, the general public is OK with.
That's certainly one takeaway. I wouldn't say that's "the" takeaway.
I have a signed and executed federal search warrant in my drawer. I was tossed in a cell. I was dragged to a hospital. I was sent the bill for the "search" and am currently being hounded by debt collectors. Nothing was found and I did nothing wrong. Sadly just following the law didn't work.
I could have easily jumped the fence to the US, and as a citizen unless caught in the act it'd be nigh impossible to prove I did anything wrong. Instead I presented at a port of entry where an insane officer claimed there was drugs up my ass.
If you don't want to be treated like a criminal, the smart choice is not to commit crimes, even though there is small chance you'll be treated like a criminal anyway.
The question at hand is not whether to break the law, it's whether to protect yourself from intrusion by state authorities with demonstrably little public accountability.
Most States have a 'declaratory judgment' law in which an issue is brought to court and decided. You could force them to prove a contract in a court. They will probably not show up. Or they could show up and you could get corrupt judge and lose.
https://www.law.cornell.edu/wex/fair_debt_collection_practic...
The Spanish Inquisition charged procedural costs for their ... administrations. Usually on the subject's family, because of high mortality rate. Terry Gilliam has even said that this particular practice was one of the big drivers for doing Brazil in the first place.
Modern governments have learned from the history, and chosen to repeat it.
A woman (who they never even got a warrant for and nothing found) at the hospital I was at was forcefully penetrated in a pretty disgusting way and I'm unaware of any significant remedy for her despite a lawsuit [2]. The lawyer who took her case told me they'd given up on such cases when I spoke with them. I complained to the relevant medical state board and they basically said everything is kosher.
While in the hospital with officers, I had the opportunity to ask them about their history in regard to this behavior. They bragged to me of various nefarious activity, such as taking someone in because they had a trans female-to-male "appendage" so they accused it of being a drug smuggling apparatus apparently to fuck with them. It was clear to me in these discussions it is routine and common behavior, and they voiced to me it was profitable for them as they commonly were paid a very high overtime wage to sit in the hospital which is easy work compared to their normal job at the port of entry and allows them to buy expensive trucks.
2 (relevant details start bottom page 6) is a pretty brutal read.
[0] https://www.aclutx.org/sites/default/files/aclu_hospital_adv...
[1] https://www.aclu-nm.org/en/press-releases/cbp-settles-lawsui...
[2] https://storage.courtlistener.com/recap/gov.uscourts.azd.985...
Did you really just shoot down your own argument by acknowledging that there are some things the government has a significant interest in prosecuting, but which the general public doesn’t find objectionable?
Schneier himself predicted this in Applied Cryptography in the mid-90's.
I always figured this was the case for a lot of common things like full-disk encryption schemes, AES, root certs, etc. If there's a break, they wouldn't use it in court unless it's taking down a very, very big target.
Why do we tolerate government corruption at the highest levels of law enforcement?
Sure. But then first you have to prove it is a parallel construction.
The purpose of laws like the 4A is to prevent the police from harassing innocent people by going on fishing expeditions. The purpose of the poisoned tree doctrine is to prevent the police from committing crimes as part of their work.
But if a plains-clothes police officer sees you load a kilo of cocaine into your car every Tuesday, on the same street corner, there's nothing illegal or immoral about him telling a uniformed cop to show up next Tuesday, to observe you doing just that. I see no reason why the uniformed cop should be compelled to reveal his source.
Now, if the plains-clothes officer was doing warrant-less break and entry in order to observe you doing the crime, that would be an ethical problem.
This does create a bit of a connundrum - where you often can't tell if parallel construction was used to cover for legal, or for illegal behaviour. But I see no reason for why the first case I presented should be forbidden. If pressed on the stand as to why the officer chose that street corner to be on Tuesday, they can avoid prejury by declining to answer, or just say that they were tipped off. I find it doubtful that a judge would compel the officer to answer, or to elaborate - he's not the one that's on trial, after all.
It all hinges on whether or not they had a warrant to surveill the ISIS site.
If the police have a warrant to plant a hidden camera at a crackhouse, I don't see why they would have to reveal its existence, when they later stop and search a car full of drugs at a perfectly legal search at a border checkpoint. If they didn't have a warrant... That's an ethical problem, and it runs afoul of the fruit of the poisoned tree.
Likewise, if there's an informant or a mole at the crackhouse, do you think the police are obliged to notify the world of his identity, every time they arrest someone he tips them off to?
If the defense asks at trial, what legitimate reason is there not to answer?
It's not exculpatory evidence, there is no obligation for the prosecution to turn it over. There's no reason for the judge to allow a line of questioning into it unless the defendant can make an argument as to why its relevant.
In reality I know that its difficult and unlikely to be proven or prosecuted, but it seems like that would be perjury.
Honest question though and I'm curious if someone with more expertise can explain where I'm wrong.
I don't think there is enough protection against such actor unless you are working directly for another state actor. And even that you won't keep anonymity. Check the North Korean gov cracker case. DoJ managed to figure out his name and photo despite that he works for a state actor.
That guy probably won't want to go abroad to most of the countries. Even countries competing with US such as China or Russia might send him to Uncle Sam for some exchange of interest. I actually think the Chinese probably provided some information to DoJ as he worked in the DaLian branch of a NK expo company for some years.
Another area of exposure is payment networks (cryptocurrency or otherwise), so ideally you wouldn't purchase any infrastructure at all. But that's not always feasible.
And of course, to be absolutely safe you'd also need to limit your own physical location to countries that don't extradite to the US (and hope they don't sign an extradition treaty before the statute of limitations runs out).
I would say that if you are doing something the US government has a significant interest in prosecuting, you might want to reevaluate your life choices and think about whether it is something you ought to be doing in the first place.
I know this is not going to be a hugely popular sentiment on here; but if you are doing something such that the US is going to burn a zero day to get you, the appropriate prior is that you are doing something supremely heinous and evil. You may in fact be on right the side of justice, but you do not get the benefit of the doubt by default.
Generally speaking I can agree but more specifically cases like Julian Assange come to mind. Certainly there are at least some people who are at risk of this kind of persecution and otherwise not doing something that would so immediately be considered in such a negative light.
How about ransomware gangs bricking hospital IT infrastructure? Seems like that is a much more common occurrence than the types of examples you are referring to. Hence the appropriate prior - absent evidence to the contrary - is that someone is doing heinous shit.
Just drop “US” in that statement and then reevaluate it. Then ask yourself why the US should be special in regard to (not) protecting people’s privacy.
Similarly, the public performance of civil disobedience was an integral part what MLK was doing with his civil disobedience.
Again I am not saying that the US government is always right. Just the person who is using Tor to hide illegal activity should not receive the benefit of the doubt.
And the “US” part of my comment is key here. There is a big qualitative difference between the US government and the N Korea government.
Sounds like the people who ran the Underground Railroad would have had significant thinking to do, by your logic. They probably should have gone home and abided by the law of the land, like the fugitive slave acts and Dred Scott v. Sandford.
To say nothing people living in Iran and China today.
I think a much stronger / more contemporary argument for you would be something like facilitating access to abortion for people residing in states where it is now illegal.
But a few questions here. Is something like this an exception rather than the rule? Do you think the FBI would burn a zero day to prosecute someone for this?
Or, you are someone like Edward Snowden, or some activist who is directly working against the US government's interests overseas. The US has a history of even assassinating activists that get too powerful (usually indirectly, by hiring some local goons), so using a zero-day to compromise them is table stakes.
However, nation-states with enough backdoors to all the servers serving as tor jumpboxes could likely deanonymize the remote user (it's assumed they'd be watching all traffic going to and from the known endpoint, which in Snowden's case was a journalist's email server).
Snowden's method IIRC was to acquire a laptop or phone without leaving any identifying marks (ownership information), then drive around until he found an open wireless network which he could log onto, then he'd use that network over tor to connect to the journalists he was talking to. The device was used for no other purpose, never turned on and connected to his home network, etc.
There doesn't seem to be any way for two anonymous parties to find and connect with each other across tor in this manner however, without having some other side channel to coordinate time and place and exchange identifying information.
You can still hide the content of communication using PGP-style strong encryption, but even then, it's likely that keys could be compromised in some manner.
As for Snowden you just described a burner however he would still need to find or know that open WiFi hotspot.
Really?
What's stopping them from just lying?
Or claiming they had an anonymous tip?
And the relevant court document: https://www.documentcloud.org/documents/23569961-motion-to-r...
Yeah, it's been a problem for a while now. I do think you're referring to Parallel Construction, a.k.a. evidence laundering.
Not only does the FBI decline to say how they determined what IP address the defendant used to access the Tor hidden service, but they're also trying to hide the fact that the defendant asked to see that information by requesting the court label the defendant's court filing itself a "highly sensitive document"? And the court granted that request? Is that normal? It seems really bizarre to me, but I'm not a lawyer.
But just wanting to keep it secret is not enough. So they will claim that this has national security implications, saying some targets are terrorists. And courts defer very heavily to the government in this area, so the FBI might be successful.
Because just knowing that there is a break is enough to tip someone off, the FBI can and courts likely would classify a request for details as well as the details themselves.
As was discussed verbally at Defcon, a huge chunk of the exit nodes are either in the US or EU. Same for guards.
(The whole GCHQ vs several EU countries trying to do intel in parallel without a shared intelligence agency thing is perpetually amusing.)
- when using tor you should disable javascript because a malicious or compromised site can use javascript to do non-tor stuff that potentially compromises your location. (can be a big pill to swallow, web without javacript is very 90s)
- Run torbrowser within a secure VM or separate device using Tails to minimize your activity footprint
- Use a VPN when connecting to TOR (I also put my TOR services behind their own VPN so even if the entry point is known you can't get the origin IP from it)
- As an added protection I use firewall rules to ensure that only the tor client process can communicate out, any other attempt to send or receive traffic to the public internet gets dropped.
The whonix project has good info on the environment variables you will need to set to get the torbrowser to play nice with an external tor daemon, so you do not need to resort to tor over tor which will make your traffic stand out.
https://github.com/Whonix/anon-ws-disable-stacked-tor/blob/m...
IMO, torbrowser, on platforms that support it, should separate daemon and browser by default, with browser in a separate network namespace with no network interfaces.
But, if zero day in tordaemon, and your adversary is US gov't or other well resourced organization, it is probably still game over. Not to mention NSA scale traffic analysis that Schneier seems to be suggesting as a possibility here, which can only be defended against by only using Internet access that can never be tracked back to you. For downloading bookwares off libgen, the above mitigation is probably sufficient, though, if not a bit overkill.
Note, this part is incorrect, the tor control port works over a unix socket natively. I just spent some quality time with the torrc manpage and am in the process of fixing my setup.
Has this advice been studied? If everyone uses a VPN you could be reducing network diversity. A single compromised provider could make correlation attacks easier across the entire network.
I'm not saying that's certain, but I'm generally skeptical of "hone remedies" when it comes to Tor. There is so much potential for counterintuitive interaction.
Unless you’re completely certain it’s impossible for the VPN providers to coordinate, that sounds like a way to short circuit the entire tor infrastructure.
You should not do this. It is at best useless, at worst strictly negative.
A VPN tunnels all your traffic through their own servers, so they are a single point of failure roughly equivalent to your ISP. Anyone with access to the VPN servers could spy on all of your traffic, completely bypassing Tor. If you pay for the VPN with a credit card, you can be easily identified.
Hmm, can you explain how this could possibly be true? I think the VPN couldn't see any more than your ISP could have.
If you encrypt traffic on your host properly and send it off to a remote host, your ISP (node(s) in between) sees encrypted traffic.
If you create an encrypted VPN connection to a VPN providers server and then configure a second encrypted connection (e.g. through Tor) from that VPN providers server to a remote host, then your VPN provider is able to see exactly what happened on that VPN providers server; since that’s where the encryption (and decryption) happens.
The TOR client will establish a tunnel OVER the VPN to the entry node, so the VPN provider will only see this encrypted traffic. The VPN server cannot spy on you.
When you connect to TOR it carefully selects your circuit for diversity over the Internet between each hop (for example avoiding your entry and exit nodes not being on the same service provider). By using a VPN your opening the possibility for something to go wrong here.
Whenever people write this comment I get the same vibe as when people say that all the recipes in The Anarchist Cookbook are rigged to fail - however I’m in a much better position to judge the technology then the chemistry.
Adding in the VPN (which you should already have and use regularly) before the first Tor guard or bridge node has several benefits - it obscures your usage of the Tor network by a causal observer at the origin (the FBI said they could tell Dread Pirate Roberts was using Tor from the ip addresses, just not what he was using it for - though they did note he was active on Tor during periods Dread Pirate Roberts was active although that alone wasn’t enough for a warrant), it obscures your origin ip to the causal observer at the guard or bridge, your activity is mixed with all other vpn users using the same vpn server(s) - some VPNs add a layer of indirection by routing your traffic through two servers, and it increases the total number of nodes your traffic flows through by at least 1 - unless you do a compile time change to increase the length of the route.
The risk of a party having control of both your vpn and all the tor servers in your path is not zero but at that point the universe pretty much wants you to be found. Should have gone to those Wednesday pot-lucks and put a little more into the building fund. ;)
The person in the article did not use a vpn and they traced the traffic to his mom’s house - amendment to the Ten Commandments of Selling Crack, “Don’t sell crack where your moms at”.
Paying for a vpn with a credit card doesn’t make you identifiable, the list of suspects is everyone who uses the vpn, or knows someone who has a password, or works for a company that maintains a pool of corporate accounts. Most VPNs don’t link outgoing connections to back to users, just so they don’t have to deal with people asking those sorts of questions.
Note that "VPN provider" could refer to any entity who is next in the connection chain after your ISP. That could be some public VPN providers like Cloudflare or Apple Private Relay (which is run by Cloudflare and Akamai). Or, if you host your own VPN, it could be your VPS provider. If your goal is to blend in, you probably want to use the public VPN provider where exit IP addresses are (theoretically) shared between a (limited) number of users at any given time. Whereas a VPN on your own box will have an exit IP that is uniquely attributable to you, making you not only easier to trace, but also easier to hack, through any vulnerabilities you might have introduced when setting up the server.
I'm wondering if the classified document wasn't about tor, but about the 'implants' aka malware that were leaked in the same set of Snowden documents.
I think as much as tor being broken in some fixable way, they'd like it known even less that the FBI installs malware on the devices of persons of interest who haven't been convicted of anything.
If they truly can't break Tor and they deem the person of interest important enough for "national security" then I don't think anyone who has studied history, American or otherwise, believes that they are going to throw their hands up and say "welp, that's it."
Outside the US, I have no idea.
Genealogists use parallel construction to build out their families. Data from a large variety of sources gets used to indicate and corroborate individuals.
https://www.reuters.com/article/us-dea-sod-idUSBRE97409R2013...
The CIA did a great job getting that word out there. It's sad it's used to dismiss credible and logical conclusions so readily.
The latest PDF[2] states:
In discovery, the Government has declined to provide any information related
to its TOR operation. The Defense therefore researched and drafted a motion to
compel such discovery. In the course of this research, the Defense discovered an
exhibit filed on the public docket in at least two federal cases with similar issues
(“Exhibit 2”). The document is partially redacted, purports to be the work of a U.S.
government agency, and is marked “Top Secret.” Outside of these public docket
filings, Exhibit 2 is widely available on public internet sources. A Google search for
Exhibit 2’s title yields 102,000 results. All of the top results apparently provide the
document itself, and most of these date back to 2013.
That would likely be a reference to something leaked by Edward Snowden given the year mentioned.1. https://www.justice.gov/opa/press-release/file/1279441/downl...
2. https://www.documentcloud.org/documents/23569961-motion-to-r...
From a doc I found[0] he was under aerial surveillance (aka, the FBI Cesnas {related [1]}) since June 2018.
Also some of the facts in the case are...well this is from doc [0].
> Some of the surveillance footage is itself incriminating. (See Doc. 5, pp. 50-51) (asserting that Mr. Alazhari’s travel on certain days in May 2020 shows that he was “scouting targets fora potential mass shooting attack.”).
[0]: https://www.documentcloud.org/documents/21052490-motion-to-s...
> We configure NoScript to allow JavaScript by default in Tor Browser because many websites will not work with JavaScript disabled. Most users would give up on Tor entirely if we disabled JavaScript by default because it would cause so many problems for them.
[1] https://openresty.org/, https://github.com/openresty/lua-nginx-module
(Fuck you imgur)
The NoScript approach is dumb because it easily supports temporary and permanent white-listing of sites, which is agreeable to many (but still problematic depending on what your risk profile).
With NoScript’s current approach, you get ruined when your JavaScript-free-optimized starts sending you nasty JavaScript.
Tech-literate people use JavaScript.enabled=false in about:config.
Why? What's the hurdle for running a bunch of servers? How much does a server cost?
Why not both?
From my experience over the years doing datacenter/transit/fiber/etc. type of infrastructure - just assume a government agency of some sort either outright operates an exit node, or has a wiretap on it. You can be the most trustworthy person in the world operating in the name of freedom - outright working for a say a colo provider. Unless you are the CEO, legal team, or the individual engineer responsible for it - you will have no idea you are also operating an exit node under surveillance.
I'd put money on well over 50% of the world's exit nodes being packet captured 24x7.
The FBI running hundreds of servers is fairly likely, and could give enough data to suggest that all of their information is just grunt detective work.
If you had 10 years and the resources of the US Government, I am sure Tor has been broken many times over now...
Based on what little I know of SSL, this suggests the server was compromised too? Or does tor do a bad job of certificate pinning?
Edit: Or the clients are/were compromised. Or the suspect’s computer was compromised. Or they can somehow decrypt traffic between client and server.
Tor client wouldn’t save any of that.
Not necessarily.
If a passive snooper knows I used Tor Browser to make an SSL request to en.wikipedia.org and received 987,654 bytes then immediately made a SSL request to upload.wikimedia.org and received 1,234,567 bytes that might be enough information to work out I visited https://en.wikipedia.org/wiki/National_Security_Agency.
It is large files / DDoS going over the network that is still hard to obfuscate.
Which is why TOR is intentionally slow, especially when requesting larger files. If it wasn't, you could watch the lump of data traverse across the pipe.
source: n/a
There is also random padding added to cells, so that the cell content is unpredictable.
I speculate this is most likely case of a ISIS server run by FBI.
The real timing attack that is not fixed and will not be (it is not in threat model), is when your ISP works with police (that has warrant) and gives them data. And police also controls server or exit node.
https://www.bbc.com/news/technology-28573625
"The Tor Project suggests the perpetrator compromised the network via a "traffic confirmation attack".
This involves the attacker controlling both the first part of the circuit of nodes involved - known as the "entry relay" - as well as the exit relay.
By matching the volumes and timings of the data sent at one end of the circuit to those received at the other end, it becomes possible to reveal the Tor user's identity because the computer used as an entry relay will have logged their internet protocol (IP) address."
"Timing attack" that will not be fixed is when police has warrant for your ISP, and police has ISP logs and destination server logs. (so it can compare the two)
We already know that the FBI passes information to local law enforcement agencies and tell them to do parallel construction when the information was obtained illegally, so why not the NSA too? It's probably easy to deanonymize Tor traffic when you see everyone's Internet traffic (they don't even need to setup exit nodes).
But yeah, TOR is certainly a double edged sword, but I am led to believe that they assess that it's offensive capabilities to pierce against Anglo-Oligarchy enemies offsets the drawbacks it produces on how they themselves deal with homefront dissidents
My take is that, well, yeah, that's one of the benefits of having overwhelming power and capabilities, that they can afford to take one or two punches in the nose, if that means that they will beat the ever living shit out of their actual enemies
It is sharpest triple-edged sword in modern intelligence existence.
Discussion about these issues has been stifled since critics like Assange and Applebaum have been smeared (but not prosecuted) with sex charges and Greenwald is being depicted as a conspiracy theorist.
What makes things harder for them makes it harder for the enemy, and vice-versa.
If anything, maybe it will help intelligence services realize that gathering intelligence is only half of the job, keeping secrets is the other half. Well, maybe they already realized it and we are not aware of that (it means it worked). But at the time of Snowden's leaks they failed big time. While most people focused on the content of the leaks and arguing about whether Snowden is a hero or a traitor, what I mostly saw is a guy who managed to break the security of the NSA. If a single guy can do that, what about trained spies backed by world power gouvernements? I guess countries like Russia and China already knew everything there was to know about the NSA. I could go for some "master plan" conspiracy theory, but my guess is just that the NSA is incompetent, or at least it was at the time of Snowden. Maybe that "dagger to the heart" is more like a wake up call, I hope for them.
0 - https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted...
I have heard it somewhere but using Tor or end-to-end is like using armoured car to transport money between park bench and cardboard box. If someone wants you compromised, you will get compromised, it only matters how many resources they are willing to throw at you. And for average person, it's not a lot. So best way is to blend in. And using Tor, end-to-end, VPN(full of people with something to hide, it would be stupid not to infiltrate or honeypot) will make you stand out, you might even peek someone's curiosity. Not a very healthy way to operate on the Internet...
Wants who compromised? What are they going to do against people who use no pseudonym and never originate from the same machine or the same physical location?
To catch one specific guy doing one action one time that he might do hundreds of times without getting caught but he only needs to get caught once to get punished, if you only need to succeed 0.1% of the time you only need to own 0.1% of the nodes, as a simplification.
There's also the incredibly valuable chilling effect that he's being found guilty in public opinion of having read the wrong website once. If millions of people read the "wrong" website a dozen times a day for decades, you only need one bust in a couple billion accesses to generate massive propaganda that reading uncensored badthink is and should be punishable.
Quite a few people online wear multiple masks. You're that wonderful professional on linkedin with your full name on display, the ideal grandson on Facebook, but also a Twitter shitposter and toxic gamer under the disguise of anonymity.
Its worthwhile to consider the anonymous version of you. I'm imagining that it won't take long before a few dots can be connected. Not by the FBI, surely they already can, but as a public service. AI reverse engineering your clicks, writing style, whatever other input.
Meaning, if there's a "socially less accepted" version of you, do worry. It seems inevitable to me that they ultimately get linked back to your true identity.
And to be clear, this isn't just about a burner account to let off some steam. Anonymity is also used to freely criticize employers, political ideas, the establishment in authoritarian regimes, and it's an essential defense for people/groups that are often the target of harassment.
To illustrate how easily this can go wrong, recently a giant Twitter dump resurfaced. It turned out to be a cleaned up 2 year old file, but it did send a lot of people into a moral panic. Specifically, some made the mistake to link their real identifiable email address to their burner account.
The bottom line is that anonymity is fragile and unlikely to last.
Note: I connect to Tor from my torified Glinet router which is doing Tor-over-Tor which is considered 'dangerous'[1] but I do it anyway.
This might be overkill for most, and I'm not doing anything illegal (I mostly browse clearnet sites instead of hidden services anyways).
[1] https://tor.stackexchange.com/questions/427/is-running-tor-o...
My (updated) understanding is that running all things via Tor is slow without as much benefit as just a normal VPN and that if anything you use throw away VMs or Tor Browser sessions to avoid any way to correlate. Also note that a well known attack is simply knowing a connection is currently happening (preferably a long-running one) and cutting off the internet in suspected areas until the connection drops. So I guess either you need to avoid long running connections (I think you could do this in the local firewall?) or have redundant network connections like Dual ISP or ISP + LTE on something like Opnsense (cause wow, is it difficult to do this on Linux. I intend to blog about it someday soon).
[0]: https://www.theguardian.com/world/interactive/2013/oct/04/to...
Yep. I said I don't understand people who do illegal things over their own connection, i.e., stupidly.
And who owned the public AP?
McDonald's.
you can proudly use it to download torrents (because nobody cares and the feds won't triangulate a signal for torrents), but they can definitely do it for terrorism and intelligence matters. (check out all the stories of spies who had radios, from the 1914 to SOE to cold war)
As a bonus, you even post your story on HN, a site where analysts from all the governments and major companies of the planet meet to talk about tech...
this guy was probably more careful than you
I don't even drive a car when I'm selling shit on craigslist for fear they'll look up the plate and do dumb shit when they're mad the drill I sold them has normal battery life.
Also- the secret about torrents is that nobody really gives a shit. They're more worried about pedos and terrorists.
Hard disagree, unless you have some citations to back this up.
That’s not true in some places like Germany. Just a few seconds of uploading a somewhat popular movie or porn without a VPN will get you a C&D + fees letter.
I don't understand... how can this be illegal?
A 10dbi gain yagi boosts your transmitted and received signal equally.
> A 10dbi gain yagi boosts your transmitted and received signal equally
I don't see how this can be true, as long as you're not arguing semantics and actually want to use the wifi. Wouldn't you need two identical routers outfitted with high gain directional antennas pointing at each other? That's easy to do when you control both of them, but the subject under discussion is connecting to public wifi of a router you do not control.
Surely a big antenna pointing directly at a router with a tiny antenna will send signals with more clarity than it receives them. The tiny antenna is broadcasting a weak signal in all directions, and the big antenna is transmitting a strong signal in one direction.
I believe that the big antenna could "pick up" some parts of the radio waves from the router, but wouldn't most environments be too noisy for your receiver to find any useful signal? By the time the already weak radio wave gets to your antenna, it's dissipated so much that you couldn't possibly read enough of it to put a meaningful signal back together, right?
Just the fact you’re using it automatically makes you interesting and worthy of a closer look.
All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?
I recollect a case a few years ago, where they tracked a guy down on a campus through traffic analysis in a fairly quiet environment Torwise, and both endpoints were on the campus.
It has basically all the drawbacks a VPN has (most sites will distrust you on recaptcha, speed bumps, sometimes a connection gets timed out or dropped) whilst having a shitton of latency on top of that because y'know, it's free. There's always been more people willing to use TOR than the server space needed to prevent overburdening the network (in no small part because running the server space needed usually incurs significant legal risks since congrats, you've now become a target for law enforcement to bust your door down and ask why an IP you own a machine on is being used to upload CP to the clearnet - few people want to deal with this scenario for blatantly obvious reasons).
This isn't really something you can fix, it's just kind of an inherent issue with the protocol.
What this graph doesn't really unveil but is so crucially important is that webpages have gotten a lot heavier over the years. In the past, you could visit most websites at a half-decent speed with a regular landline connection. Nowadays you need to download several megabytes of content before you can even load a page in properly.
It only does if you set it up as an exit node.
I do believe that most people on HN qualify as "interesting" to these forces.
I mean, nobody hates the gov side of the cryptography wars more than me, but this type of article is well below table-stakes for discussion. Especially by legendary professionals of repute like Bruce.
It's very disappointing to me. The price of clicks truly deconstructs the modern man's integrity...
Where's that pro-backdoor advocacy in this essay from 2013 on evading NSA surveillance and warning about the risk of backdoored cryptography? https://www.schneier.com/essays/archives/2013/09/nsa_surveil...
Or this essay from 2016 arguing that backdoors sabotage security? https://www.schneier.com/essays/archives/2016/04/the_value_o...
Or this essay from 2019 decrying yet another effort to backdoor encryption? https://www.schneier.com/blog/archives/2019/12/scaring_peopl...
https://www.lawfareblog.com/tornado-cash-not-free-speech-its...
Schneier has gone off the deep end
That we don't know the methods used here, this seems to emphasize the old reasons to live in caution.
Still, couldn't he just have written that?
There's a court document from a defender specifically referring to the evidence the FBI is presenting. Lawyers can be severely sanctioned if they lie in a briefing, so the lawyer drafting that has certainly seen a court document by the FBI stating that they got the IP of this user despite Tor. Bruce never claims more than that.
Just like when you say "a BMW driver crashed into a mall", you mean that they did it with their BMW, not with the Subaru that they also own.
Or they run the site and it has some sort of browser exploit.
I'm guessing the first though. That they set up the site specifically to target him. The rest of the investigation involves them running eBay accounts to sell him weapons and such. Seems like the whole investigation was borderline entrapment to be able to arrest him on something.
> “From Mr. Al-Azhari’s attempt to acquire firearms through unlawful channels to his desire to provide material support to a designated foreign terrorist organization, it was clear Mr. Al-Azhari’s intention was to carry out an act of violence,”
> According to the complaint, Al-Azhari was an ISIS supporter who planned and attempted to carry out an attack on behalf of that terrorist organization. Al-Azhari, who has a criminal history that includes prior terrorism charges in Saudi Arabia, attempted to purchase multiple firearms over the course of the investigation, before acquiring a Glock pistol and a silencer. He also expressed admiration for Pulse nightclub shooter Omar Mateen and spoke of his desire to carry out a similar mass casualty shooting. Additionally, Al-Azhari researched and scouted potential targets in the Tampa area, including Honeymoon Island. He also rehearsed portions of an attack and the statements that he would make during or in connection with such an attack.
And when there isn’t a specific law, there is a general “conspiracy to commit” law ( https://en.wikipedia.org/wiki/Criminal_conspiracy ), which is what I’m sure is involved in this case.
“Conspiracy” makes it sound funny, but the basic idea is that when multiple people (and “multiple” means “at least two”) have conversations about committing a specific crime and one takes concrete steps toward committing that crime, then all people involved can be punished for conspiracy. Of course, the ones who were undercover agents don’t get punished. And the fact that the plan wouldn’t work doesn’t matter. If the FBI sells fake explosives to somebody and that person plants them outside a building and tries to set them off, the fact that they were fake doesn’t help them beat the rap.
The issue with stalking is that there isn’t a law against being in the same area as somebody else (unless there’s a restraining order). So, unfortunately, the police can’t make an arrest until a law is broken or the potential stalker at least tries to break the law.
They're probably still committing a crime. The thing with terrorism vs stalking though, is the budgets that are being spent on preventing them. It's also the level of Law Enforcement that does the investigation. Local PD is much less capable and has much less man power than the FBI.
Also, in case of 'tells a victim of planned murder plots' this often happens in person with no record existing. This happens about as often as fake victims saying someone is threatening them. So it's hard to judge whether any report of death threats from a stalker is real.
I've personally worked on stalking cases and until you've got actual irrefutable evidence of a stalker having made threats, it's always a gamble. Even letters and messages are being faked by pretend victims. Overreaction by local PD, without evidence, is how people get shot when they get swatted.
https://theintercept.com/2015/03/16/howthefbicreatedaterrori...
You might be interested in the "cannibal cop" case.
https://en.wikipedia.org/wiki/United_States_v._Valle
Where, exactly, is the line crossed between "this guy is talking shit" and "this guy is actively planning to do harm?"
(I don't know where I even stand on that case. The ramifications of every alternate outcome is equally unsettling.)
Most likely his Bitcoin donations gave him away, since Bitcoin is far from anonymous. He might also have left other clues such as an email address which he accessed from clearnet.
Anyway, it's pretty obvious LEA cannot identify Tor users en-masse. There have been several CP websites taken down which had hundreds of thousands of users, yet they only managed to arrest the website administrators. Only a handful of users were arrested, and mostly because of dumb mistakes.
Tor was broken a while back. Not sure why anyone would think it is a safe/private/secure.
Your ISP is always rattin you out.
The FBI has done this before - inject a browser exploit into a site they compromised to identify its users.
that was shortly after intel exchange had been taken down.
Tor services just arent secure in any sense imho. especially not from the people who wrote them.
sigh.
that's very suspicious
dont get the more juicy military stuff, but it's much less effort.
Not the fault of Tor. HSDir nodes could snoop on announced v1 .onion adresses. This isn't the case anymore for Onion v2 addresses. But even if an attacker has the onion address of your webserver, he needs a way to compromise it.
Either through a vuln in your website or your webserver.
You're right, except you meant v3.
You would be amazed how many admins leave shit like PHPMyAdmin wide open.
In both cases you could run a honeypot to catch 0-days.
The only reason I spotted it was because I was checking for compromise by comparing any file/process changes every few weeks.
It was a few years ago, my guess back then was tor is the honeypot, given what happened recently with encrochat I wouldnt be surprised if a few years down the line it turns out it was.
Or maybe I misconfigured the server, or maybe the binary I used for tor was compromised, it was as much a test for whether I could trust tor as anything else and it failed. delete, move on.
- Obtain the person's IP
- Decrypt the person's traffic to see what pages they visited
I honestly do not believe the second is possible so it makes me question the validity of the first. I have a feeling Tor itself wasn't the issue, but rather something else.
Everyone daydreams of activists and journalists but really they're only enabling child pornographers and methamphetamine dealers.
When the ambassador of some country purchases advertising space in a national newspaper in the country they are stationed in and uses that to publish a letter or pamphlet, then that is likely officially sanctioned propaganda (the Chinese ambassador did this in the Netherlands to present the official Chinese view on certain matters related to China debated in Dutch media some years ago). That particular instance literally came with the stamp of approval (or rather the ambassador's signature).
nordvpn has been acquired by some private equity that's acquiring all the vpns.
I would like to know because NordVPN, while not as hardcore on privacy as mullvad, is still providing a useful service for protection against an untrusted wifi and geofence jumping.
https://blog.torproject.org/transparency-openness-and-our-20...
Just because someone gives money to the Tor Project doesn't mean they get to tell them exactly what to do.
the US collective funds TOR so that they can exert control over the field of play, or even just keep it in sight. perhaps that control is relatively small and only used in extremely high-profile cases, but that's more useful than nothing at all
it's a parenting paradigm: it's safer for your kids to drink at home than out at a bar or in a park somewhere, because at least at home you can keep an eye on things
Tor was created by the feds for spies to use, then they made it public yo hide the traffic.
This is the official story that everyone has evidently forgotten.
Most people are probably leery of running an exit node, because its traffic is in the clear (modulo ssh) and often connects to disparate and shady servers.
If we go back further to the original concept of chained anonymous remailers as envisioned by Chaum 40 years ago, it gets even harder to claim something like this.