If you had visited any of my exit nodes via port 80 or 443, I had a lander on them stating that it was a Tor exit node and to please contact me if you wanted your IP to be blacklisted from it. I also stated that there was no useful information contained on this server (by design) that would be helpful for any evidence gathering or investigations. Seriously, all they had to do was plug my IP into a browser or do a simple scan of it but I suppose that's asking too much from LE lol.
Additionally, Tor exit nodes are public and all they had to do was look into my IP more than 5 seconds after finding it in logs somewhere and firing off a warrant or subpoena for it. The first two were straight up vague templated fishing expeditions. The 3rd subpoena actually came straight from the DOJ and was a lot more detailed and serious.
They should know what Tor is and know that any Tor server contains ZERO info that would be able to assist them in whatever they are attempting to investigate.
Sure, I do think such situations require follow-up but as soon as they are informed it's a Tor ip, they should know to drop any pursuit of getting evidence from it. They do not, they continue to go after you via legal means. Even though I had the EFFs help, this entire process still took months.
It's pretty stressful to be in a situation where its lil ole me VS the entire United States government who has unlimited resources, time, and money to go after you.
I am extremely blessed to have had the EFF lawyers at my defense and will forever be a life long supporter and donor to them. They really do fight for our digital rights and can help defend you in a digital equivalent of a David versus Goliath situation.
I mean, yes, I'm pretty sure "just take my word for it" is asking too much of LE.
We can always say "Come back with a warrant" but then sometimes they'll come back with a warrant.
> They should know what Tor is and know that any Tor server contains ZERO info
Unless, of course, one has misconfigured it... Which could be the case. Definitely the kind of thing LEO can figure out on the other side of a seize-and-strip of the hardware. Unfortunately, I think the only way to not be a part of the story here is to not be a part of the story here... Don't proxy anonymous traffic if you don't want law enforcement asking after the anonymous traffic you proxied. Otherwise, expect the responsibility imposed upon a service provider (since you're providing a service).
Other ISPs avoid this scrutiny by going out of their way to be helpful to law enforcement.
One day I will resume but in the future :)
It would in fact be negligent if the police did not properly investigate the server/computer/house of the device.
Like the OP says, it's harrassment to discourage continued operation.
To have some sort of automated process in place to deflect blame allows an exit node operator to ignore the real damage their work can do. They may still decide that the good that they're doing outweighs the bad, but forcing them to see the negative consequences of shielding anyone who wants a shield has value.
I'm not suggesting people shouldn't be able to run a Tor exit node. I'm suggesting that people who run Tor exit nodes should occasionally have to a deal with a subpoena that says "your exit node was used by a criminal to hurt people in ${these ways} and we require any information you have to help apprehend the attacker."
I don't want to deprive anyone of the right to make a moral decision, but I do want them to feel the weight of the full import of that decision.
Of course there is. If I am deciding whether to dedicate resources, money and time to running a service which -
a) Helps dissidents in authoritarian regimes communicate freely
and
b) Enables bad actors to send threats and/or move CSAM around
Then that is absolutely a moral choice I need to make. It's not outside your control, you get to decide whether or not to provide the service.
Can you name a product or service for which this is not the case? Militaries use general purpose software to design weapons. Murderers use vehicles and transit systems. We don't expect the government to harass the makers of cutlery because they provided a product used in a mugging.
The distinction some people try to draw is when a higher proportion of a product's users are nefarious, but that doesn't really work either because who uses something can change over time.
If you have a society where nobody has window blinds or locks on their doors because it's a rural area and there is no one around to invade your privacy then locks will be disproportionately used by neerdowells "with something to hide", and then busybodies will claim that anyone with nothing to hide shouldn't be concealing their private spaces and anyone selling or using any privacy technology should be pressured to stop. Which sustains the status quo through external pressure even if someone does start invading everyone's privacy.
And that's what's been happening on the internet. Surveillance is the default, Cloudflare et al block Tor users as a matter of course and that drives normal people from Tor and similar technologies even though they would otherwise benefit from its use. People are told that it's the dark web where there are criminals and they shouldn't use it -- it being Tor Browser, the thing that keeps ad networks from tracking them across the internet.
Then after dispersing the normal users who would otherwise benefit from using it, people say that it has a lot of nefarious users to justify the continued harassment of anyone who does. But that's just path dependence, and there are parties interested in leading us down the garden path to mass surveillance.
Right, I could kill a person with a spoon. Still we regulate guns and not spoons, why is that?
Cost versus benefit. Steel has massive, obvious benefits. That makes its costs worth it. On the other hand, several toxic compounds have no known benefits and are tighty regulated.
You're trying to argue Tor's costs are worth its benefits. But that requires being clear-eyed about both. You can't build buildings and spaceships out of Tor. But neither can you fashion it into a gun. Unless you're arguing for solely action-based regulation, never access-based, which is its own idiotic can of worms.
Everything could be used for nefarious purposes, and I do not think that is why we should "stop having nice things".
By their logic, we should get rid of encryption, too, completely.
I'm saying that too many people in this forum are too comfortable completely ignoring the harm that Tor causes, and in order to make a good judgement call about whether to run an exit node the harms need to be surfaced. Full stop.
Everything else that you and others in this thread read into my comment is on you, not me.
Case in point.
> If not, what are the differences between Tor and IM software with E2EE?
I would never run an IM software with e2e encryption either, for the same reason. I don't want to be paying to move data that is being used to hurt people, no matter how many people I'd be benefiting in the process.
If other people come to a different decision that's entirely reasonable as long as they're cognizant of the harms caused and not in denial.
Not trying to single out the person you're responding to, but I've seen this play out many times and engaged in it previously to no effect.
I won't be surprised if there were something in US criminal code with supreme court precedents that specifically dictate the government harass in timely manners the makers of cutlery used in a mugging. There _are_ always laws. _Everything_ is regulated. Most of those regulations are reasonable.
Camera feeds, ticket records... All of that is accessible via warrant. That's probably the most salient example in this context.
Yes, quite noble. But: How many of those are there using it, and how many criminals? It's mind-boggling how people so adamantly insist on seeing this only as black-and-white, and refuse to admit that there even exists something to weigh against each other.
If all you'd need to deter law enforcement is to put a website up on your server and say that you don't have anything to do with anything happening on that server and that they shouldn't bother because there's nothing to see anyhow, a lot more criminals would do that. I'm sure they'd even put an actual exit node on their machines if that protected them from law enforcement.
It's like raiding the home of the mail carrier because someone got drugs in the mail. Sure, it could technically be that the mail carrier is also a drug dealer. But when it comes to the USPS, the identity of who delivered the contraband package is not a useful data point for investigating the crime, and acting otherwise is willful ignorance.
It doesn't have to be the actual origin for it to be useful—unless the software is specifically designed to avoid traces (i.e., Tor), there are often logs that will lead you to another IP address, which might lead you to another, which might eventually lead you to the source. It would be foolhardy for police investigating a bomb threat to not at least ask, given how many people they do in fact catch this way.
> It's like raiding the home of the mail carrier because someone got drugs in the mail.
No, in the case of OP it's like subpoenaing the local post office and asking for everything they know about where that package came from. Which is, incidentally, quite common, except that in the US the post office is a government entity that doesn't need to be subpoenaed because it has its own law enforcement agency that should have jurisdiction over the case.
There could be logging bugs in Tor that you were unaware of, or the owner could be using Tor as a cover. It would be negligent _not_ to at least check the device logs for anything useful.
The truth is that police investigations normally are restrained based on the disruption that they cause the public. Police deviate from standard operating procedure when it comes to TOR exit node operators because they want to punish and intimidate them.
They want to punish operators because the authorities are frustrated by the effectiveness of these technologies in countering the pervasive surveillance environment which the authorities take for granted.
Implying that they don’t have the capability to do this already and/or alternative means to accomplish the same thing.
https://en.wikipedia.org/wiki/Room_641A
> Room 641A is a telecommunication interception facility operated by AT&T for the U.S. National Security Agency, as part of its warrantless surveillance program as authorized by the Patriot Act. The facility commenced operations in 2003 and its purpose was publicly revealed by AT&T technician Mark Klein in 2006.
You think they don't!?
So there's no need to seize their equipment.
Citation needed. ISPs have entire departments dedicated to cooperating with law enforcement. Comcast has a whole portal with its own subdomain specifically for handling requests from law enforcement [0]. Cox has a page detailing exactly how to send them a subpoena [1]. These guys are clearly dealing with subpoenas just like the ones OP is describing all the time.
It only seems out of the ordinary this time because it's a random person who decided to play middle-man instead of an enormous corporation with a massive legal department.
[0] https://lrc.comcast.com/lea
[1] https://www.cox.com/aboutus/policies/law-enforcement-and-sub...
That's my experience too from actually having my house raided. I had two kids in bed at the time, and the police didn't even know to expect kids in the house (both kids were over 11 years old, had birth certificates, had lived in that house all their lives and attend local schools and are darn fine students).
They didn't know. It's mind boggling to me that they could get a raid warrant without having done even the most basic (below even basic) investigation.
My opinion of police investigative competence took a 99% hit as a result.
It's a lesson my kids won't forget either.
The dirty people behind all this are in the way they run the investigations. And what way is that ? Well it’s the “organised crime investigations”. The Netherlands pushed the RIEC way of working here to Germany and Belgium. Look it up. Euriec.
The whole way of working is to do dirty tricks in an unaccountable way.
Is the burden undue?
A Tor exit node operator has made the ethical judgment call that they're doing more good than harm. That might be a reasonable position to take, but I don't think it's unreasonable for us to expect an operator to face up to exactly what it is that they are doing. I'm fully on board with any bomb threats (as just one example) leading to a subpoena on the exit node operator who shielded the threat actor, even if the answer is the same every time.
Making the decision that you're doing more good than harm requires you to fully understand the harm that you're justifying, and law enforcement subpoenaing you every single time is one way to make it very clear what it is that you're choosing.
It is fair that running an exit node might be inconvenient, maybe even to the point where consulting a lawyer is advisable, but I think we should draw a hard line at direct threats to an innocent person's liberty, livelihood, and physical safety. That kind of fear is definitely an "undue burden".
> it's clear all you're doing is running software. (Side note: I'm surprised how often attitudes on this site are at odds with the "hacker" part of "Hacker News".)
I do not view software as amoral. It's a tool, and like any tool it is an extension of myself. Software that I run is acting on my behalf, and what my software is designed to do is something that I should be held morally accountable for.
I'm not sure when the hacker ethos came to mean that "just running software" absolved you from having to account for the damage your software causes, but if that's what the hacker ethos is about then yes, you can count me out.
[0] https://techcrunch.com/2021/10/15/f12-isnt-hacking-missouri-...
Where is the presumption of guilt? A threat of violence was traced to their IP and they were served a subpoena to provide information that might lead to finding the threat actor before they actually hurt anyone. No one even accused OP of a crime, much less presumed their guilt.
Their lawyers warned them to prepare as though a raid would occur, but that's the lawyers' job: to prepare their clients for the worst just in case.
When computing became predominantly online, hackers inherited a moral dimension: the need to consider whether they are doing harm to others via what they do with the shared global network.
It's a different story when you're cobbling scraps together in your basement, and it's a different story when you're primarily phone phreaking "the man," as it were.
Yeah yeah “parents should know” but given the rash of shootings by young people, fuck that argument.
That's not what subpoenas are for, and it would be a really stupid waste of time and resources. If you really want to do that, just send them an email.
> a really stupid waste of time and resources
Subpoenas are used all the time in cases where they're not expected to be inherently useful for acquiring information. If law enforcement is going to take 10x as long to find the perp because you hid them, I don't see a problem with them sharing that burden with you a bit—there are externalities here that should be internalized.
Yes.
> A Tor exit node operator has made the ethical judgment call that they're doing more good than harm.
They are. Absolutely. It's not really a question.
> Making the decision that you're doing more good than harm requires you to fully understand the harm that you're justifying, and law enforcement subpoenaing you every single time is one way to make it very clear what it is that you're choosing.
No, that's just harassment.
The exit nodes have been known to be the weakest part of the tor design. It has been a logical theory for a while that all exit nodes are visible to the U.S. Govt.
This is just one way they can leave a system like Tor up for their uses and also make sure anything domestically is fully visible to them.
Surely that's worse than the exit nodes?
The way I see it, the right approach is some kind of continuous communication where messages end up in fixed slots, where if no message would have gone, there'd have been a randomly generated message.
That's very nice but until tor exit nodes are illegal, such police action is purely a harassment effort, right?
One thing that struck me, years ago, is that the people running these actions (recipient of a death threat or police) are far more concerned with the fact that "someone enabled this", rather than the fact that someone was angry enough at them to issue a death threat. They had no visible concern about that wannabe murderer, apparently spending no effort trying to identify THEM. They just wanted retribution against the exit node operator. It was totally doing something for the sake of doing something, zero concern about solving any root problem. They had seemingly zero concern that their safety was a risk (I mean, from eventual action stronger than a death threat.)
They also had zero awareness that anonymous email had allowed this ennemy to be revealed before any physical violence.