BitTorrent study finds most file-sharers are monitored
bbc.co.uk
bbc.co.uk
To summarize for others indicators were:
"""
1. The proportion of a subnet that has been seen in BitTorrent swarms. Monitoring agencies may use a large proportion of their subnet for monitoring.
2. The length of time a peer spends in a swarm. Monitors may spend more time in the swarm than regular file-sharers.
3. The number of different (IP, port, infohash) combinations per IP address. Monitoring agencies may operate many clients from a single IP address.
4. Whether a peer reported by a tracker accepts incoming connections. Monitors may block all incoming connection attempts. (((This was discarded as an unreliable indicator)))
5. The number of swarms in which IP addresses from a particular subnet appear. Monitoring agencies may monitor many torrents from their subnet.
6. The number of times the same (IP, port) pair is observed concurrently in different swarms.
... we found 1,139 IP addresses that were in the top first percentile for all four features (((1,2,3 and 5))) IP addresses assigned to a company named Checktor [3], which offers commercial BitTorrent monitoring services, and 16 addresses assigned to a medium-sized computer security consultancy company that does not publicly acknowledge monitoring BitTorrent. Another subnet, which we saw in over 500 swarms, belongs to a company that advertises itself as providing “intellectual property advice” ... We also found two subnets assigned to hosting companies ... We speculate that copyright enforcement companies are using these hosting companies as a front to disguise their identities. We also identified a number of IP addresses allocated to large ISPs, such as Vodafone, Etisalat and SingNet. ... This feature (((6))) found IP addresses assigned to Peer Media Technologies [16] (a well-known copyright enforcement agency) monitoring seven Harry Potter ebook and movie torrents, and the INRIA research institution [10], which had been overlooked by features 1–5 because so few torrents were being monitored, and because a very small proportion of INRIA’s subnet was being used for monitoring """
I didn't read too much further into their methodology for detecting "direct monitoring" other than to see a pretty graphic showing peer lying about their download completion.
You can find the lead researcher's other papers here: http://www.cs.bham.ac.uk/~tpc/home.html
(A previous paper: Analysis of BitTorrent Peers' Behavior and Monitoring Trends http://www.kaspersky.com/images/camilo_andr%D1%83s_gonzalez_... which was based on the Snark Project, updated)
Link to 18-page scientific article by University of Birmingham. This is the actual meat behind the BBC article.
Not an alarmist paper, just boring work with Bittorrent download progress bitmap monitoring.
Some juicy bits on their usage of Tor, from the paper:
"we created our own indirect monitoring client that gathers newly-published torrent files from the Top 100 in each category on The Pirate Bay, and continually contacts each of the trackers and stores (IP address, port number, infohash, time) tuples from the peer lists that are returned; it then attempts to establish a TCP connection with each host and sends a handshake message to ensure that the host is in fact a BitTorrent peer. [..] We collected data from July 21–28, 2009, routing our traffic through the Tor anonymity network."
"The Unbearable Lightness of Monitoring: Direct Monitoring in BitTorrent"
http://www.edri.org/edrigram/number8.18/collecting-ip-addres...
MAFIAA and others don't care about downloaders (as yet I don't believe a single user who downloads only, has been sued successfully), but they DO care about those sharing their material. The fines levied so far are not for downloading tracks, but for sharing them.
The article title is misleading. They logged only popular, public torrent content. I'm certain that many, many other file sharers were not even seen by their study. It's all just scare tactics.
They could simply send out a few million or so letters, maybe costing a million £ or so. Offer everyone a settlement of a few hundred £ to cover all past transgressions with the threat of suing for a much greater sum if there is a repeat offence or if they do not comply.
If you work on the basis that about 50% just pay up straight away that's quite a lot of money. This money can be used to subsidize going thermonuclear on at least a few thousand of those who don't.
Besides, they don't need to sue everyone to make people scared enough to avoid pirate sites.
Looking at activity on torrents gives you a really good idea of relative interest in something, and in addition, on membership torrent sites, it could be cross referenced with the other interests of the downloader simply by using their history to give you some idea of demographic and to guide marketing strategies.
It might be interesting to know if your show is unpopular because nobody wants to watch it or if everyone who wants to watch it prefers bittorrent.
On the other hand , I don't know what you would do with this information unless you had a strategy for monetising bittorrent.
Even more interesting to me are the surprising highly trafficked music and movies that are long out of print. Might be a good indicator of when to bring them back, and what fora to announce that in.
And all of this data is stored for once the Gov decides to "crack-down" on illegal file downloads, they will have massive amounts of evidence.
My router has various features to block P2P traffic, as an experiment I tried enabling these features and then downloading torrents (Linux distro ISOs). Every time I enabled these the data rate on the torrent client would start to drop, but then within minutes it would be right back to full power again. At the end of the day you can just make a bunch of connections to port 443 on a remote host, start an SSL session and you are now indistinguishable from HTTPS traffic.
The only way I could effectively block it was to disable NAT and force everything to go through an HTTP proxy.
My personal choice is privateinternetaccess.com: $40/year, unlimited bandwidth (cloak and many others limit bandwidth), multiple platforms (Windows/MAC/*nix/iOS/Android), multiple protocols (PPTP, OpenVPN and IPSEC/L2TP), multiple gateways (US/UK/Switzerland), and most importantly, NO user activity logs.
Also, per http://news.ycombinator.com/item?id=4474529 you could use any vpn that routes through Switzerland.
This also only covers Bittorrent, not "most file-sharers".
And I doubt that if I download some rare indie music stuff, that anyone would care to monitor this torrent.
> Average time before monitors connect. 40% of the monitors that communicated with our clients made their initial connection within 3 hours of the client joining the swarm; the slowest monitor took 33 hours to make its first connection. The average time decreases for torrents appearing higher in the Top 100, implying that enforcement agencies allocate resources according to the popularity of the content they monitor.
[1] http://torrentfreak.com/judge-an-ip-address-doesnt-identify-...
Is a person responsible if someone has been using his or her router for file-sharing because they were able to crack its WEP-encryption, while the accused in question hardly knows what a router is?
Of course there are other ways someone may have broken into your network.
Open-source tool: http://code.google.com/p/reaver-wps/
Again , ISPs seem to be ahead of this. Looking in my local area most of the APs have names like "BThub543897534895" and I assume that the passwords are randomly generated.
You're right about ISPs being on the safe side with their SSIDs and passwords, but I think you're underestimating the users here. For the sake of it I've spent an hour and a half driving around town a year ago, logging locations of access points. I never did anything with the data except for looking at how access points are distributed across my town. Most of the AP names where common words or a combination of such. Concerning passwords, I've used wifi at friends and coworkers places quite a few times and most of them had weak passwords.
An attacker might just go and do some wardriving and randomly attack access points and I believe he'll find one weak enough without much of a hassle.
Bottom line it's the same as always: In the real world security isn't as depended on technology as it is on how much the user is concerned with it. How that works out in a lawsuit is a different question though.
If someone steals your car, are you responsible if they use it as the getaway car for a bank robbery?
There don't seem to be many wireless LANs using WEP anymore anyway because of the obvious security flaws. Perhaps some grandma with an old router could get away with claiming ignorance as a defence but the average HN reader probably couldn't.
As for the car analogy perhaps this would be similar to leaving your car unlocked knowing full well that it was likely to be stolen by criminals.
I'm also not sure how far ignorance goes as an excuse although this could well depend on whether we are talking about civil or criminal law. For example in pretty much any country there are literally thousands of laws that you are expected not to break. I doubt even veteran lawyers know all of these down to the letter , yet if I am charged with one of them that I have no knowledge of I cannot get away with saying that I didn't know it existed. In theory I guess it could be argued that you should never do anything without first consulting a legal professional.
Possibly a lawyer could say to grandma "If you didn't know anything about routers or Java updates, why didn't you hire an IT expert to configure your computer for you?"
Which ISP configures wifi routers? And I always see unsecured connections from default routers. Don't tell me you're never connected to the unsecured "Linksys" network..
Usually what happens is that they send a box with a router + modem + filters etc and instructions as to how to plug it all together.
They also give you a piece of paper telling you the SSID and key with strict instructions not to tell it to anybody.
I imagine the router also calls home at a regular interval and downloads updates automatically, so if there is a security issue it should be rectified relatively quickly.
As far as I can tell in my googling none of these negligence claims so far have been successful but there has been no clear judgement on this matter to be sure one way or another what might happen in future cases. Also bare in mind that these judgements might differ between jurisdictions.
I simply think that saying "open up your wifi, now you're no longer liable for anything that happens on your internet connection!" is very dangerous advice to be spreading.
Default settings. Many wifi routers work just by plugging in ethernet.
> I simply think that saying "open up your wifi
I'm not suggesting anything besides grandma isn't her IP. I don't see why that's confusing.
Then again, it's just an analogy, which holds little sway in a court of law.
HN often fails to realize what 'normal' users are like. The world is still very unsecured.
Suppose I invited a friend over to my house, and while I was asleep, they taped TV movies onto my VCR. Am I the one at fault because I didn't lock up my VCR? Is there any other place in the law where I am considered at fault when somebody else breaks a law? I'm not talking about "the getaway car", but more like "the guy who parked across the street from the bank and had his car taken by the robbers".
AFAIK in a civil case there would be more onus on you to prove that you didn't know what other people were doing with your stuff.
Also this would be affected by your circumstances, so if you work in tech/IT you might have a job arguing that you didn't know that running an unsecured wireless AP was a bad idea.
At home, is there any requirement, legal or otherwise, for me to secure my data if I don't have a desire to?
Pointing to a renowned security expert saying he does the same might help, though:
http://www.schneier.com/blog/archives/2008/01/my_open_wirele...
Good luck making an insurance claim.
I've personally seen this used to crack a WPA2 network in < 2 hours. However this isn't a problem with WPA, and disabling WPS renders this attack vector useless. Thou as noted in the white-paper some routers are intelligent enough to slow the attack down.
WPA: http://www.tomshardware.com/reviews/wireless-security-hack,2...
yes the 4-way handshake needs to be captured, and can be compared to a rainbow table (fast) however (and if i understand correctly) if it is not in the table you can then throw computing power at it to bruteforce it (slowly)
http://www.youtube.com/watch?v=RXwteto3nNg
Yes its really slow, and would take practically forever for any reasonably long/secure passkey, but it is possible and only going to get easier as time goes on. I think it gives anyone with a wireless network an 'out' by being able to say they must have been hacked, either because they left WPS on or used a simple short passkey.
However i really have no idea if that would actually hold up in court.
It was my local ISP the one who installed the WiFi with WEP and they don't provide the option to manage the router and disable it, even if I requested WAP2 explicitly.
Car analogies are flawed because car security is waay ahead of IT security for vast majority of people.
For example , someone with enough brute force is always going to be able to break into your house and someone with enough patience and sneakyness is always going to be able to find an opportunity to steal your car keys.
You can always improve you physical security, but after a while the costs and inconvenience start to become unrealistic. You probably can't afford to fit your home out with bulletproof glass and bank vault style doors for example.
With computer security you can make the brute force (for example deriving an RSA private key from the public key) entry nearasdammnit impossible without spending really any money at all (just implement openSSL).
Of course the downside is that sidechannel type attack can render this security effectively useless. Even a crappy lock or a glass window provides some protection against thieves especially in the sense that they might be spotted when trying to bypass it.
On the other hand, having an information security system that uses strong encryption provides 0 protection against somebody who can use metasploit if the software itself is full of exploitable and publically known bugs.
You can but what if you don't? Verizon for a while was setting their FIOS routers with WEP with a password derived directly from SSID!
> "It is questionable whether the monitors observed would actually have evidence of file-sharing that would stand up in court."
However, it’s not really that much more work to verify if that peer is sharing the file in question. Just request/offer few random blocks. There’s no mechanism in place to assign peers in BT network varying degree of trust.
A side fact: Data retention hasn't proven to be very successful yet.