The Pirate Bay in the cloud
thepiratebay.se
thepiratebay.se
It's pretty much what you'd expect, though: The web site is now running on VMs on two unnamed cloud providers, accessed through a load balancer. All traffic is still routed through servers they control. The cloud providers apparently don't know that they're hosting the pirate bay, or pirate cloud as it were. If a cloud provider goes away, they can move to the VMs to another one. If their own transit routers go down, no data is lost and it's easy to get back and running.
If you know the physical and network location of their routing boxes and you keep polling some (e.g. static) resource on their servers you can eliminate all cloud providers that are further away than the response time as being the hidden backend.
Let's say you narrow it down to 10 candidates and 5 of them experience some sort of network issue that gets reflected in the response times of TPB, you've now narrowed it to 5.
I wonder what they're doing to mitigate these sort of timing attacks meant to discover their hidden backend.
I wouldn't bother just taking the load balancers down. I'd go upstream of them to see where the traffic is going, and then take down those hosts at the same time as the load balancers.
... only for The Pirate Bay to spin up more instances elsewhere and point a domain or two at it.
Imagine trying to detect copyrighted songs from Youtube if users could upload code bundled with the videos and load balance requests.
I will assume fingerprints of detected instances will travel between cloud provides, and that pirate bay will then add code to prevent that.
The Pirate Cloud
So, first we ditched the trackers.
Then we got rid of the torrents.
Now? Now we've gotten rid of the servers. Slowly and steadily we are getting rid of our earthly form and ascending into the next stage, the cloud.
The cloud, or Brahman as the hindus call it, is the All, surrounding everything. It is everywhere; immaterial, yet very real.
If there is data, there is The Pirate Bay.
Our data flows around in thousands of clouds, in deeply encrypted forms, ready to be used when necessary. Earth bound nodes that transform the data are as deeply encrypted and reboot into a deadlock if not used for 8 hours.
All attempts to attack The Pirate Bay from now on is an attack on everything and nothing. The site that you're at will still be here, for as long as we want it to. Only in a higher form of being. A reality to us. A ghost to those who wish to harm us.
Adapt or be forever forgotten beneath the veils of maya.
https://tpb.pirateparty.org.uk/
And there is a Tor hidden service for it as well, which can not be taken down unless Tor it's self is taken down:
http://jntlesnev5o7zysa.onion/
And for those who want to use Tor hidden services, but don't have Tor installed:
https://blog.torproject.org/blog/bittorrent-over-tor-isnt-go...
If you're using a Linux box, you can use iptables to force all TCP traffic through Tor, dropping everything else. Then make sure the box doesn't know it's "public" IP address, only it's NAT'ed one. Even if it does a call out to something like http://whatismyip.com/ in order to determine it's external IP address, it wont get the real one because that traffic will have been forced out through Tor.
See: https://trac.torproject.org/projects/tor/wiki/doc/Transparen...
Speed wise, Tor appears to be slow, but that is just latency. For throughput it's fine. Especially if you're connecting to lots of different hosts over lots of different Tor circuits, as happens with Bittorrent.
But yes, the Tor Project doesn't want you to be using Bittorrent over Tor.
It's like TPB has achieved Nirvana. It no longer has a physical presence...
In effect, they are replacing their current legal protections with a game of cat and mouse as they switch between clouds.
Thinking back to Napster... you mean it hasn't already?
The transit and load balancer servers are another story. It will become a game of cat and mouse with colocation providers, the same game that spam purveyors played in the days before botnets. They will get raided and have to set up a new server at some provider elsewhere. Eventually they will run out of decent providers and have to move somewhere on the fringes of the hosting industry and performance will suffer.
A better approach, in my opinion, is to take the whole thing into the cloud and to come up with some sort of P2P protocol that is capable of determining where the transit server(s) live entirely without the aid of centralized DNS.
Cloud is mainstream now, why did it take TPB so long to catch up?
//Sorry if it sounds like trolling
I don't know how many cloud hosing providers there are - to judge from the way people talk here there's only EC2 and maybe Linode. You'd need a lot of providers if you need a new one every 3 days!
[1] http://www.readwriteweb.com/cloud/2010/12/amazon-drops-wikil...
I think eventually, something has to give tho, but hopefully, it will be a while before that happens.
TPB's case is slightly different from most cloud setups, in that their primary need is mobility not scalability. So, where most cloud backends will try to be as tight as availability and pricing allows, TPB wants and needs to spread across (or be ready to move to) as many different providers, datacenters and countries as possible.
Sure nothing they're doing is particularly novel, but if you're the sort of person who wants to host in the cloud, but needs to keep a website responding even when cloud hoster goes down (or decides to ban you), you should find something interesting about their setup.
> the cloud image encrypts itself and becomes useless
Sounds more like they are using full disk encryption, and the system just shuts down, requiring a password to boot up again.basically seems like they've got a virtual setup now that lets them essentially deploy "the pirate bay" on anything that runs virtual machines.
Now if they had distributed user run VMs running this private server VPN they might have something to talk about, but is basically just a hosting change. Makes it easier for them to move around as hosting get wise and shuts them off (as it will inevitably do).
The real question is, are they doing something sneaky like having VMs running on known clouds using encrypted vpn traffic to hide the fact that those machines are pirate bay VMs, and relays to feed info in and out. ;) Just speculating...
1. Border router handling inbound traffic, connecting via encrypted VPN to their load balancer in a different country.
2. Load balancer which is a disk-less server with all configuration in RAM that connects via encrypted VPN to two separate sets of VMs at two separate cloud providers in two different countries.
3. Said VMs using encrypted disk images, and set up to automatically shut down if they are out of contact with the load balancer for more than 8 hours, at which point a keyphrase would need to be entered to unlock the disk images.
I would assume they probably has more routers and load balancers in other locations ready in case they need to switch over.
They can keep this shell game up forever as long as the people operating it are able to get online - adding more layers if necessary.
To reduce cost this "border router" is probably also running an in-memory cache such as memcached or varnish. So they simply re-created what SuprNova.org did in 2003.
9 years ago this was really novel. SuprNova was the first to introduce a load balancer for both HTML and .torrent hosting.
Aside from that, it doesn't sound like SuprNova's setup was quite as intricate as this. I think that the post above was suggesting that the "caching border router + encrypted VPN" setup was what SuprNova used, but that's not everything that ThePirateBay seems to be using. Also, ThePirateBay only has to host magnet links, which didn't exist (IIRC) back when SuprNova was active. SuprNova had to host all of the .torrent files.
It's simple: the exist node in both Tor and Piratebay has all the legal exposure. That server/caching router/proxy could become impossible to host anywhere. Move it to USA? Expect 1 hour of uptime:-) Russia? Expect 10seconds page load times.
Any experience hosting people out there? Are Sweden and The Netherlands the only few-questions-asked options on town?
This will cut short most of the users who do not remeber IP by heart.
Step 2 - go after static IP and shut it down through ISP.
This will cut the remaining users who remeber old IP by heart.
If executed simultaneously...
Hopefully, TLD's like .se will stand fast and refuse to use the DNS system for censoring.
Nobody uses the old domains, but there are many mirrors, and people still use TPB, maybe even more than before. A lot of people just know the IP by heart, too.
That is the single point of failure, even in a move to the cloud.
If authorities are able to figure out the topology of the network, they could coordinate this.
Sounds like a bug to me!