LulzSec indictment published
scribd.com
scribd.com
Here's a site with these indictments as downloadable PDFs and without the annoying shaking ad: http://publicintelligence.net/lulzsec-indictments/
Despite all that, their "correlation attack" was distinctly low-tech. They watched the traffic leaving his residence and confirmed with a confidential informant logged into the chat server that he was online. It just shows that despite all the paranoia of the crypto-nerd crowd, even the second most sophisticated government agency in the world (perhaps after the NSA), pursuing a high value target, still can't or doesn't want to perform those kinds of attacks (maybe because they aren't reliable enough to hold up in a court of law).
And the CCC was claiming that they could fingerprint encrypted connections with 40% reliability. That's so far from being an effective real-world attack by even the most sophisticated organizations, that you'd be wasting your time ever worrying about it.
I think Hollywood and perhaps even our own fascination with technology misleads us, blinding our eyes to what has been proven to be simple and effective time and time again.
Also, the surveillance you disclose in explanation of finding him, and the surveillance you do for the sake of having some surveillance to disclose.
Not secure against end-to-end attacks: Tor does not claim to completely solve end-to-end timing or intersection attacks. Some approaches, such as having users run their own onion routers, may help; see Section 9 for more discussion.
They are repeating it several times in their documentation, too.
It's not really a bug - there is little that can be done here, IMO.
However, depending on how high the garbage stream must be set to ensure that there is never a spike of real communications higher than that, it could easily be too costly for most people.
So if it saturates your connection for an hour for 6 hours randomly spaced throughout a day, it's not immediately apparent if that's because you're using it, or it's a decoy stream. Varying the amount used (and always adding at least a little extra when in use) would also make it harder to detect.
At least, that's how it seems to me. There may be some sort of cunning statistical attacks depending on the implementation, especially if the attackers have the endpoint under physical surveillance (and notice that your presence always matches traffic increases of some level)
They might have other teams using it for intelligence rather than case-building. If they sequestered those from the teams building evidence that usage might not be discoverable.
Reading through the indictment it becomes clear that he outed himself through many statements that narrowed down his identity. Not too smart.
"While sup_g may indeed have been a "credible threat," he was in the end no match for the overwhelming federal resources of the FBI agents hunting him down. Over the last month, federal agents staked out his home in Chicago constantly, dug up old police surveillance records, tapped his Intern'et connection, used directional wireless finders to locate and identify his wireless router, and relied on Sabu back in his New York City apartment to let them know when sup_g went on or offline."
This is the one thing hackers will never get. You get the FBI on you and guess what? You're one person. They can assign hundreds of people to the case, bring down a wealth of resources to get you, and they go 24/7 until they build an airtight case on you. Not much you can do at that point but play their game.
Are we supposed to assume this guy wasn't encrypting his wifi? I'll grant that it's possible, but it strikes me as unlikely given his activities.
Alternatively, if the wifi router were encrypted, are they suggesting that it is "public" because it's wireless, penetrates walls, and can be "seen" from outside?
In order to inspect MAC addresses, the WPA encryption would need to be cracked using that SSID pre-computed attack. However, executing such an attack certainly couldn't be considered the collection of public information.
Theoretically, you could encrypt a MAC address, but all it would mean is that your packet would go nowhere as your own computer wouldn't even know where to send it. Even when using WEP/WPA/WPA2 the MAC addresses between the devices must be clear text. There is simply no way around that. It does mean that the idea that they just intercepted public signals is entirely accurate if all they did was determine MAC addresses as they are transmitted in the clear with no active attack needed. Heck, every time I open my wifi manager I see the MAC addresses for all neighbours within 500m.
My big question is why is someone's MAC important? I can't see it being a very useful piece of evidence. It isn't end-to-end like IP addresses so I can't see anyway it could be used to track him down. His own ISP probably doesn't even know it since they'll just see the MAC address of the modem he connects through. They are also notoriously easy to change at a seconds notice.
For more information on how the laws relating to phone tapping are interpreted for the internet, see: https://en.wikipedia.org/wiki/Pen_register
Guess they did not want to provide too much info on that - otherwise they would have had to acknowledge that they are actually screening all traffic with deep inspection.
The deeper meaning of this is that all I-Net traffic can / is inspected through special interfaces at the ISPs (that could of course also be on the edge of the networks) and all (larger) ISPs have to make those available 24/7 without knowing who's accessing them. Generally speaking I guess it might be better to say that all traffic taking certain routes (I certainly don't want to explain this) or using / showing certain patterns will automatically be inspected.
From a logical point of view you will have to look into everything if you do not know what you're searching for and identify the unusual or some "patterns" you already know...
The general approaches used here are similar to IDS solutions and generally HW based / speed enhanced solutions are used for that (magnitudes faster than software only).
Keywords on that - if you want to find out more - are Deep Packet Inspection, lawful inspection and interception, network neutrality, PCRF etc.
There is a whole industry providing these services / solutions (to the TelComs and government agencies) and their biggest players are all based in the U.S.
This is what the congressional hearings with AT&T reg. Bush Mark 2 interceptions were all about - now its all legal so no press on that anymore.
And I guess you know that what can be done will be done.
No conspiracy, standard practice - 15 years ago everybody involved into such practices would have been called a terrorist, enemy no 1 to our democratic systems now seemingly its the other way around.
Why?
Performance of the typist? Security concerns?
Well, I guess they're still using computers as if they were just typewriters...
It also seems they have a policy of using Courier, which is probably a carry-over from the days of paper records. It isn't the most readable font ever, but it is surely one of the most legible- a good thing for documents meant for preservation.
I suppose, just another reason not to trust Godaddy?
somebody needs to sit down and work out the timeline here and figure out what happen.
6 lines of chat, 2 paragraphs of summary. Ah, bureaucracy.