Copyright Trolls Order Wordpress To Hand Over Critics’ IP Addresses
torrentfreak.com
torrentfreak.com
...and a solved problem. We have numerous technologies for this.
It's good that the legal framework allowing anonymity is already in place in some countries (like Germany and... Even the EU seems to be going in this direction) but technically it's complicated.
I don't expect regular people to know how to connect to free public WiFi hotspots and then to use Tor and browser(s) able to dodge Panopticlick-like detection anytime soon.
This may come at one point but we're not there yet and we probably won't be there anywhere soon seen that there are big governments out there determined to crush for fun and profit the very notion of anonimity.
Using Tor has now become fairly straightforward with the Browser Bundle and I expect similar packages to be available for mobile devices soon.
With that one crucial link between you and the hosting provider severed, i.e. who's paying for it, what's left to link the server to your identity?
Of course it depends on who is trying to get the data about you. If it's the hoster then yea, he wont get it. But if it's the authorities/government then they'll get it. Plus theres a chance of you by accident exposing all your payments with your name...
- Mine bitcoins.
- Steal bitcoins (i.e. hack an exchange)
- Pay cash for bitcoins[1]
- Pay for bitcoins with stolen credit card info.
- Pay for bitcoins with anonymous pre-paid credit cards[2]
Of course, that just gets you a bitcoin wallet that isn't necessarily tied to you. Now you have to figure out a way to spend them without leaking personal information.
[1] The person that you pay could identify you, but if you give false information, and aren't picked up on surveillance (CCTV, etc), then it becomes a difficult to track down link.
[2] Same issue as [1]. Your weak link is the point-of-sale for the pre-paid credit card.
You could set up a bitcoin gambling website, sell some sort of SaaS for bitcoins or, perhaps the most popular and profitable route right now, sell some drugs for bitcoins. Hypothetically, depending on your state/country, you could acquire weed legally and then (illegally) send the weed through the post in exchange for bitcoins.
Basically if you're providing a service to someone, then there is a possibility of said service revealing who you are. E.g. if you're sending drugs to people, then maybe the packages are traced to a source.
Since you can generate unlimited wallets, lets say I have two, A and B.
Wallet A is known to belong to me. Coins I buy off of Mt. Gox end up in this wallet.
I create wallet B, and then send coins to it.
Using wallet B, I then send coins to a hosting company's wallet for for a server.
The fact that I sent coins from Wallet A to Wallet B is public information. The fact that I own wallet B is not public information.
If I was a government type trying to trace someone down, how would I prove who owns wallet B?
Let's assume I generate a new wallet every time I pay for hosting when the bill comes due. The path is even murkier.
If I was really paranoid, I could create wallet B, hop on Tor, make a post on a bitcoin board somewhere selling some kind of non existent goods, posting my Wallet B address for payment, regenerate my Tor circuit, post as another account on the same board indicating interest in these goods and post my wallet A address.
How does this look to any observer like anything but some guy sending coins to some other guy who ends up using those coins to buy hosting, or any other good or service?
This can be defeated, either manually or via a tumbling service to make the link chain so huge as to be useless for evidence purposes.
Again, it's easy to link me to wallet A assuming I just buy from a service with links into the traditional financial system. It's significantly harder to prove I own any of the wallets I send money to.
>If they look back a few links in the chain and the find bitcoin exchange where you initially got the money, they now know that you exchanged just the right amount of money to make the illegal purchase.
This could be defeated by sending more than the amount required when you fund the second wallet.
Again, nobody knows that I own wallet B. Given a sufficiently plausible public exhibition on a trading site, it may look entirely like it's owned by another person outright, and if your goal is to avoid legal scrutiny, so much the better.
Bitcoin can be anonymous because you can create wallets and transact between them without any proof of ownership of the wallets.
Put another way, yes, they can see that one coin that you originally owned eventually made it to a specific party, but they can't prove that you were the parties in between.
tldr; Don't make assertions about stuff you don't understand.
Example: you have 10 BTC, spread it to 3 addresses (A: 2 BTC, B: 5 BTC, C: 3 BTC) and want to make a payment over 6 BTC. Now you will have to either create a new address which gets money from B + (A || C), then transfers it to the seller or transfer from said combination directly to the seller. Since one can see B and one other address working together, one could assume they both belong to the same owner.
This is just one example of how you can still track address owners with varying chances of success. One can with great care probably make Bitcoin anonymous but the average user wont.
Yes, that pretty much covers your comment. It's not like they won't just investigate all wallets intermediate to major exchanges/merchants as leads. It's not like FinCEN doesn't have decades of experience tracking mass flows. It's not like they won't invoke guilt by association for any of the four horsemen.
Please, take a look at the properties of Brands's blinded signatures for an example of an actually anonymous currency (it has other problems though).
Bitcoin is definitely anonymous. Consider: a wallet has no PII attached to it, beyond what you give it via transactions. Contrast this with a credit card, which typically has PII as an integral part of the way it operates.
[The exception here being mining. I don't believe that you release PII as a miner, yet you bring in bitcoins.]
To your point at [1], I am not aware of any way which mining can compromise PII.
This makes it anonymous.
We have never had the amount of anonymity we do today. Being able to communicate to large numbers of people while remaining anonymous was something that was just not that practical before the internet. Society functioned just fine then. So why is it so important now?
Not that I support what this troll is doing of course. But I fail to see why a start of affairs that basically only existed for a small group of people from 1970-2000 is so crucial to civilization now that the internet is just an extension of real life and not a playground for the technological elite.
Perhaps it is that experience that has rendered the status quo unable to satiate. "The needs of society" can kindly go stuff itself, I need anonymity.
With modern technology, all that is slipping away, or already gone.
I grew up in a small town and my Dad knew everybody in the county and the next one, whether they were in town or in the countryside. And likely a couple of generations back. Several families moved to California, and the social network reached there.
A cousin of mine had a brother that fled home. He eventually tracked him down using old shoe leather techniques.
My experience and that of my family does not match this theory of "loss of anonymity."
Now, modern suburbs are more likely to be anonymous, and perhaps that is where this theory comes from, but it does not come from small towns.
A historical comparison is irrelevant and fallacious - we didn't have modern surgery hundreds of years ago and despite people dying society ticked on. If all you see is the forest you can pretend the pain of the trees doesn't matter.
And the internet is just a playground for the technological elite too (you need a computing device after all) so I suppose you see no need for it either.
The internet is not a playground for the technological elite, not any more. It's a place where my mother in law trades baby pictures with my mother.
As internet use becomes ubiquitous in the real world, and the boundaries between "meat space" and internet space evaporate, the anarcho-idealism of the technological elite that got onto the internet early is evaporating too.
This is to an extent lamentable, but you can't expect the "wild west" to continue to exist after the land stops being the frontier. That isn't to say that anonymity isn't important, it is, but it's just one concern to be balanced against many.
The internet has never been the wild west. Twenty years ago it was a bunch of middle class scientists and mathematicians discussing philosophy and writing code. It's about as far away from any kind of real danger as you can possibly imagine.
The result of the "wild west" metaphor is to imply that we need to have some cowboys come in with blankets and other "gifts" for all those wild Indians who once occupied it so that they can hurry up and die out and make room for Walmart and Cable TV and upstanding members of the Chamber of Commerce.
But the internet isn't a dangerous place. It isn't even a place. It's just a thing that lets computers and users all over the world communicate with one another. About the worst thing that the average person is even capable of doing with it is to lie to someone else or infringe copyright, or maybe (if we're the sort of people with an interest in keeping our comrades compliant members of The Party) they could distribute or gain access to some "subversive propaganda" from the likes of Jane Fonda or Adam Smith or whoever we don't like this year in this part of the world.
The internet isn't the dangerous thing, it's the rest of the world -- the dangerous thing is an internet without anonymity. Because if people know who you are then saying the wrong thing or reading the wrong thing can get you killed (or fired or harassed or wrongfully imprisoned). And all not knowing who said something really does is the same thing as the First Amendment: It requires you to respond to speech with speech instead of with punishment.
Come on now. That's only because for the average person being able to communicate to large numbers of people at all was something that was just not that practical before the internet. And to the extent you could communicate, it wasn't that hard to do it anonymously: Sit down in a public phone booth to make your phone calls. Write a letter to the editor under a pseudonym or write letters to as many people as you like and drop them into a public mailbox. Post a message on a bulletin board at the local library while nobody is watching. Provide a recording for broadcast to a journalist with a reputation for protecting sources.
The novelty is being able to trace the source of a communication through the corporate intermediary that carries it and back to the actual speaker. And even that is a lot of hand wavy hocus pocus that makes poor assumptions about the relationship between paying for an internet connection and being the one responsible for what gets sent through it.
Worse, it could be done on a massive automated scale. Before if an agency wanted to find a potential criminal, they'd have to expend time and manpower looking things up. In the coming years a computer could data-mine your online activity going back a decade, including email, to decide if you were a threat or not. Perhaps it's not possible today, but someday, it will be--and this stuff is being recorded now.
Laws and societies change. The hard information on your history kept in easily-processable racks in vast data centers doesn't. That's the big worry for me.
Just the other day, I was googling for something in the library. I can't see so well, so I crank up the text size. It's quite readable to others sitting a few feet behind me.
On a whim, a stranger walks up behind me, addresses me by name, and tries to strike up a conversation. He wanted to know where the bathroom was or whatever, but he addressed me by name. I never saw him before.
"Wait wait wait. How'd you know my name?" I ask. "Who are you?"
"Oh, don't you see? It's right there in the corner of your browser window."
I looked, and sure enough, if you're signed in to Google Plus, Google will grace all of its web pages -- all of them, including gmail, search results, etc -- with your first and last name, as decided by your profile's display name. It's right there in the corner.
Since then, I learned my lesson: stay signed out of Google + when I'm browsing in pulbic places unless I want strangers to walk up to me and know who I am.
Sometimes I prefer to remain anonymous. Sometimes I feel like the increasing pressure to always use real names for services isn't a good thing, especially when those companies turn around and expose that valuable information in odd ways like Google is doing.
The option to exercise anonymity is one of the best defenses I have against these kinds of events.
That or I can simply stay signed out all the time...which is equivalent to not using the service.
This is by far the most surreal, almost TwilightZone-like, behavior of any legal entity I've ever seen. I'm tempted to almost take it as a desperate attempt to self-destruct in some spectactular way as to deflect any sort of punishment for the abuse of the justice system. But that would assume they actually knew what they were doing.
They have no standing to demand this information as visitors haven't conducted any sort of copyright infringement (we're not talking Viacom-YouTube stuff here) and second, among the visitors were journalists and (surely) representatives from the government. Someone had to research the trolls.
"The TL;DR is that there is going to be an unprecedented showdown in a Los Angeles court on Monday that could lead to someone associated with Prenda going to prison."
Uh, make that everyone, if there's any justice left. Except maybe that Cooper fellow who had his identity usurped as CEO.
http://www.popehat.com/2013/03/06/what-prenda-law-is-facing-...
Do not taunt super happy fun federal judge.
Judge Wright's moves in this big game of chess are especially good. He really wants to get to the truth.
Here's a starting point: http://www.popehat.com/2013/03/06/deposition-reveals-prenda-...
This is a rare instance in which Torrentfreak may be covering a story accurately, although don't race to pat them on the back for that because this does seem to be a case in which copyrights are being prosecuted by parodically conceived comic book supervillains.
As Popehat reports it, what seems to have happened is this:
* A small law firm in Chicago, through a series of shell transactions, acquired the rights to some porn properties.
* The firm began running a variant of the movie studio lawsuit playbook on people it determined had shared those files over the Internet.
* The firm did not disclose to the court that it had a direct interest in the media properties, instead representing that it was counsel for 3rd party firms that owned the properties (this is technically true, but wait...).
* Another attorney, Morgan Prietz, began inquiries into these suits, smelled a rat, and started collecting evidence.
* Among the evidence discovered: one of the shell owners of the porn videos was an "Alan Cooper", who is evidently a former acquaintance of one of the Prenda attorneys with no actual relationship to the business and who has in effect had his identity stolen as a figurehead for the lawsuits.
* Prenda manages to bring a case in the court of Judge Otis Wright. Prietz reaches out to Judge Wright, filing a document that more or less directly accuses Prenda of fraud. Prenda replies to the filing by addressing ancillary issues in it without rebutting the core allegation. Judge Wright notices, and brings down the righteous legal hammer of a vengeful god down on Prenda, ordering them to his courtroom next week in person to either cough up a real Alan Cooper and a very compelling explanation of what they're up to or potentially face immediate incarceration.
I'm leaving out all sorts of fun details here, which is all the more reason you should be reading Popehat. For starters, you really need to dig into Popehat to see how one of Prenda's outside counsels explained the business relationship between the porn-video shell companies and Prenda itself.
[PS]
A big problem with Popehat vis a vis HN is that the blog titles are never congenial to this site, and the ethos on HN is now "don't mess with the titles". So it never seems productive to submit their articles. That's a shame, because Popehat legal coverage is everything Torrentfreak's and Techdirt's isn't: thoughtful, careful, technical, accessible, well-written.
Porn trolling mastermind is the world’s most evasive witness Prenda-linked lawyer testifies for seven hours, gives no useful information.
http://arstechnica.com/tech-policy/2013/03/leading-porn-trol...
Anyhow, I get the feeling that these guys are being too clever by half and that the judge is about to make them answer for it. Thankfully, Ars has promised a reporter on the scene. Personally, I'm betting that they come up with some lame excuse for a no show, but we'll see.
It seems like they originally did have proper contracts to sue on behalf of porn studios, with the porn studios getting a cut of the settlements. Then that well dried up, due to a combination of factors like very slow moving cases and a few nasty countersuits against the porn studio owners that had to be settled for cash going the wrong way.
It's only at that point where they decided they could just buy the copyrights to films directly, and get rid of the pesky clients.
HN needs subheads! They could be slightly more tolerant of pulling out salient details or interpretation, and even wiki-rewritable by users over a certain karma, with a version history. They'd make the 'original title' policy more tolerable, and be a massive timesaver for readers, when they provide the necessary counterbalance (in details or qualifications) for whatever sensational or dry choice was made in the title. (Popehat writeups could win with a good subhed; 'trick' titles would lose when the subhed offers the necessary clarification.)
It looks like they domesticated it to California, so they (wordpress) would need to file a motion to quash.
...really swinging for the fences with this one.
It makes this a very high stakes game, since even if the court throws out the result of the subpoena for use in the libel case, Prenda gets what they want. You could argue that is why they filed three separate actions in three different courts, just to up the odds that one of them would get the desired information.
They've done very similar things before, where they filed a lawsuit against the same list of IP addresses / John Does in a dozen different venues, because they only needed one judge to allow the discovery request to go through to get what they wanted.
Just give us the facts! </rant>
>Please provide this information in an Excel spreadsheet.
Easy. Give them an Excel 97-2003 spreadsheet with the first 65,535 and tell them the format can't support any more.
* sigh * ... the desired word is not "complimented", it's "complemented".
http://blog.oxforddictionaries.com/2011/04/compliment-or-com...
"'Television' is one of the most recent offspring of linguistic miscegenation." -- Leslie A. White, The Science of Culture, 1949