Harvard Student Charged In Bomb Hoax
boston.cbslocal.com
boston.cbslocal.com
It sounds like they determined from the email provider that the message came from a Tor exit node, then from there they looked for who had made a connection on Harvard campus to known Tor relays. He had, so they interviewed him and he confessed to everything. I don't see any strong indication of a weakness in Tor from this, but it's a bit concerning that you could be interviewed for having used Tor at the same time as something like this. I run a relay full-time, I don't know if this is better or worse for me.
He could have easily avoided detection (not to say that would have been a good thing) by using something like SkypeMorph (https://crysp.uwaterloo.ca/software/CodeTalkerTunnel.html)
Actual interrogations are far more cunning and complex, involving psychological tricks and play against weaknesses in the human mind. Perpetuating this "they'll hit you until you confess" bullshit stops people from learning actually useful information about how to resist interrogations.
Pedantism and comics do not go well together. The format is not meant for conveying exactingly precise information. Interpretation is required.
This sort of interrogation typically starts with "we know you did it, so why don't you make things easy for yourself...", not "break his finger so he knows we're serious".
The XKCD 538 fallacy is the delusional belief that torture and threats of violence are how people are coerced into confession during an interrogation. That is not the case. Perpetuating that fallacy actually helps interrogators, since the fear of "confess or else you'll get the wrench" is implanted in people's minds. Since that is not how things actually work, it is counter productive. It does not help anyone except the authorities. This is why I say stop perpetuating the fallacy. Seriously.
Seriously, you are not telling anybody here anything they did not already know.
There are many creative ways to circumvent encryption, and one of those ways could be something sinister like a wrench-torture, but it could also be through social engineering or psychological craft. The wrench is just an extreme example, maybe even a metaphor.
I don't know if he used the Tor Browser Bundle, and if that is even all that clean from a forensic standpoint, but I certainly wouldn't trust it to conceal what I did.
Maaaybe he'd have a chance if he used a LiveCD that they could not find evidence of him ever having. That is a very strong "maybe".
I'm assuming at this point that thousands of Syrian, Egyptian, Iranian, Chinese, etc. dissidents are dead from misplaced trust in Tor and other crypto magic, and no one's the wiser.
If all they had to go on was what's in the article -- that "the person who used Guerilla Mail used Tor to access it" and "[Kim] used Tor around the same time the e-mails were sent" -- that's not enough to charge him with a crime.
It's enough to go and talk to him about it, but if he had wanted to, he could have protected his identity (but possibly prolonged the investigation, depending on what other resources the agent had) by simply denying that he had anything to do with it.
Nobody but a fool thinks that Tor (or any other piece of technology) is a silver bullet. It is just a tool, and like any tool, has intended uses and numerous shortcomings when you use it without knowing what it is for.
Trying to use Tor to protect you against interrogators who are convinced of your guilt and willing to torture you to death is like trying to toast your bread with a hammer. Completely nonsensical, though that does not mean a hammer is a bizarrely useless contraption invented and touted by fools. Asking what the point of Tor is if it cannot protect you from that is like asking what the point of body armor is if stepping on a landmine still blows your leg off.
Had he not used Tor, he would never have sent an email: he wouldn't have felt secure.
"Trying to use Tor to protect you against interrogators who are convinced of your guilt and willing to torture you to death is like trying to toast your bread with a hammer."
It's Tor [traffic analysis] that led integrators to him in the first place.
Also, Tor is frequently advertised for use against repressive governments.
That is unknowable, certainly not certain. Plenty of people called in bomb threats before Tor was invented. Hell, he may have just pulled the fire alarm instead.
> "It's Tor [traffic analysis] that led integrators to him in the first place."
Tor is not safe from traffic analysis; it is pretty trivial to figure out if someone is using Tor. This is a well known limitation of Tor that must be understood by anybody using it, particularly if they are living under a repressive government.
If you are using Tor with the expectation that nobody will be able to tell that you are using Tor, then you are trying to hammer bread into toast. That is simply not what the tool is for.
It is certainly possible that the Tor project needs to work harder at making sure people understand this.
Edit for clarity: I don't think that following up obvious leads is evidence of government hostility. After all, if Harvard called up law enforcement to advise of a bomb threat and were told not to bother unless an explosion had taken place, most people would consider that pretty remiss (especially given Harvard's proximity to Boston).
I'm guessing you don't even believe this to be a laudable goal, and that's precisely why we need anonymity tools.
First off, don't put words in the anigbrowl's mouth.
Second off, it's not government hostility to investigate a bomb hoax that costs a lot of people money and inconveniences a ton of people. This guy wasn't engaging in civil disobedience.
Third off, the dude could have just walked to any of the dozen coffee shops in harvard square with free wifi and done this all in the clear, and been fine. Tor cannot and will never prevent traffic analysis if you're dumb enough to plug into the organization you're hoaxing's network. Tor created reasonable doubt, that's all it could do in this case, as a matter of physical limitations.
As I had said, it's a "hostile government" in the context of security analysis. Sorry, there just isn't a technical distinction between this kid and a dissident. To take a principled stand of saying dissidents should have the means to communicate freely, you also have to assert that you'd like for this kid to not get caught. Understandably this is a hard thing to do, given the chaos it would cause (is causing) in the short term.
On a technical level.. I don't see how Tor could have performed better here. It's physically impossible for them to mask the fact that this guy connected, through the harvard network, to the tor network. The rest of it is between the police and the guy. If they had gotten proof that it was his specific machine that sent the emails through some weakness in Tor, then I'd lay some blame with Tor.
I disagree that I have to root for this kid not to get caught. Tor didn't fall down, and I'm not rooting for Tor to fall down. He could have stonewalled the cops, or he could have taken the most basic precaution on earth of not doing it from his frickin dorm room, Tor or no
EDIT: Actually, maybe they'd be able to correlate his mac address if they subpoena'd whatever coffee shop the email came from. That's a much bigger fishing expedition for "any coffee shop that connected to a tor node that day", though. But anyways, my point is that Tor can't be held responsible for things it will physically never be able to mask.
Back to the technical, isn't this the point of Tor "bridges" ? Of course these don't work out of the box - they require finding out the address of one out-of-band and manually configuring it. Wider casual adoption of Tor would have also fixed the problem in this case (if the resulting Tor user list was too long to question everybody).
The whole point is that ending up on a shortlist means you are essentially caught. This kid may have gotten off by playing it cool. But translated into the dissident scenario, it's still a loss.
Given the proliferation of surveillance cameras, the coffee shop scenario becomes much harder. Assuming after-the-fact facial recognition is standard these days, it would only work if there were enough other Harvard students also on tape. Low latency is the mortal enemy of mix networks.
With time, I've come to the conclusion that the ability to (re*-create such tools is more important than any individual instance of such a tool.
I want to live in a world where the routine use is anonymous, with nyms only connected voluntarily. Of course people have to be smart enough to not post 'my name is XXX' in-band, but they shouldn't have to go to a distant coffee shop. If privacy takes work, that means it's only accessible to the few willing to put in that work, and will be viewed as an aberration by everyone else. It's only by making it easily accessible to everyone that it can become societally accepted.
To take a principled stand of saying dissidents should have the means to communicate freely, you also have to assert that you'd like for this kid to not get caught.
Realistically he would have been better off to call it in using a payphone (to the extent that he considered a hoax bomb threat a matter of necessity). I don't think you can automate away a complete disregard for security.
And yes, by the time you're on a short "of interest" list, you're fucked. (with the only real solution to the traffic fingerprinting being to get peer-talking encryption software in widespread use for everyday tasks).
No matter the nature of your activity, if you're trying to obfuscate your identity using systems like TOR and GuerillaMail, you probably shouldn't do it on the network of the people you're attempting to hide your identity from...
I wonder if there is any sort of correlation between the prestige of a school and how often someone calls in a threat or pulls a fire alarm. I had a fire alarm go off while I was taking a final twice when I was in university. Seems like it is probably a semi-frequent occurrence.