Live data from Hacker News

FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

justice.gov

1–10 of 73 posts

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#2
The relevant bit is on Page 22.

>Further, records from Pure VPN show that the same email accounts Lin's gmail account and the teleportfx gmail account-were accessed from the same WANSecurity IP address. Significantly, Pure VPN was able to determine that their service was accessed by the same customer from two originating IP addresses: the RCN IP address from the home Lin was living in at the time, and the software company where Lin was employed at the time.

Also, it seems Lin knew or suspected this at least, seeing as he doesn't believe in a VPN service that doesn't keep logs:

>For example, on June 15, 2017, Lin ... re-tweeted a tweet from "IPVanish," that read: "Your privacy is our priority. That's why we have a strict zero log policy." Lin criticized the tweet, saying, "There is no such thing as VPN that doesn't keep logs. If they can limit your connections or track bandwidth usage, they keep logs."

This will be a useful .pdf to keep on hand because I also don't believe in VPN's that don't keep logs. At a minimum they'll keep 30 days worth and in many countries may actually be required by law to keep them longer than that even (60-90 days usually).

As an aside, it's good to see another example that the FBI does actually investigate cases of cyberharrasment and takes doxing seriously, contrary to popular opinion.

E: A few typo fixes and the last 4 words.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#4
post #2

The relevant bit is on Page 22. >Further, records from Pure VPN show that the same email accounts Lin's gmail account and the teleportfx gmail account-were accessed from the same WANSecurity IP address. Significantly, Pure VPN was able to determine that their service was accessed by the same customer from two originating IP addresses: the RCN IP address from the home Lin was living in at the time, and the software co…

Bandwidth counting can be accomplished without keeping "logs" per se, and with WireGuard, I think there would be very little reason to attempt to limit connections.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#5
I'm always curious at how these VPN providers aren't being hit with false advertising. They claim to keep basically no data about you.

"You are Invisible – Even We Cannot See What You Do Online We DO NOT keep any record of your browsing activities, connection logs, records of the VPN IPs assigned to you, your original IPs, your connection time, the history of your browsing, the sites you visited, your outgoing traffic, the content or data you accessed, or the DNS queries generated by you." [0]

[0] https://www.purevpn.com/privacy-policy.php

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#6
post #5

I'm always curious at how these VPN providers aren't being hit with false advertising. They claim to keep basically no data about you. "You are Invisible – Even We Cannot See What You Do Online We DO NOT keep any record of your browsing activities, connection logs, records of the VPN IPs assigned to you, your original IPs, your connection time, the history of your browsing, the sites you visited, your outgoing traffi…

Them not keeping a record may be true...

But the rsyslog was delivering the logs to *.fbi.gov

And not retaining logs would still be correct. They said nothing about transporting them to the relevant feds.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#7
post #2

The relevant bit is on Page 22. >Further, records from Pure VPN show that the same email accounts Lin's gmail account and the teleportfx gmail account-were accessed from the same WANSecurity IP address. Significantly, Pure VPN was able to determine that their service was accessed by the same customer from two originating IP addresses: the RCN IP address from the home Lin was living in at the time, and the software co…

Again, its easier to buy a cheap VPS in a country that is at odds with the one you're in. Then, any intelligence the other country gets will likely not be sent to the country of residence.

Ally countries usually have extradition treaties, and have a greater chance of sharing intel.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#8
post #2

The relevant bit is on Page 22. >Further, records from Pure VPN show that the same email accounts Lin's gmail account and the teleportfx gmail account-were accessed from the same WANSecurity IP address. Significantly, Pure VPN was able to determine that their service was accessed by the same customer from two originating IP addresses: the RCN IP address from the home Lin was living in at the time, and the software co…

In Brazil law requires services to keep logs for a year. This made me very wary of services like ProtonVPN that put some servers there. A lot of people trust them, but I for some reason don't...

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#9
post #2

The relevant bit is on Page 22. >Further, records from Pure VPN show that the same email accounts Lin's gmail account and the teleportfx gmail account-were accessed from the same WANSecurity IP address. Significantly, Pure VPN was able to determine that their service was accessed by the same customer from two originating IP addresses: the RCN IP address from the home Lin was living in at the time, and the software co…

Bandwidth counting can be accomplished without keeping "logs" per se, and with WireGuard, I think there would be very little reason to attempt to limit connections.

WireGuard is very hard to run without logging. It simply wasn’t designed for that and the maintainer was paid once to write “a rootkit-like” piece of code for a VPN provider which hired him to help them fix that.

It’s still an open question afaik

edit: I've worded this weird. I was typing on my phone at lunch stuff I'd just learned this morning[0] which referenced this[1] article saying running a log-less Wireguard might not be possible.

AirVPN in [0]:

> "Wireguard, in its current state, not only is dangerous because it lacks basic features and is an experimental software, but it also weakens dangerously the anonymity layer."

and Perfect Privacy:

> "WireGuard has no dynamic address management, the client addresses are fixed. That means we would have to register every active device of our customers and assign the static IP addresses on each of our VPN servers. [...]"

Things may have changed, but it appears that running a log-less vpn provider is actually more complicated with Wireguard than at first glance. Namely the issues around DynamicIPs.

[0]: https://restoreprivacy.com/wireguard/ [1]: https://www.perfect-privacy.com/blog/2018/10/10/wireguard-vp...

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#10
Although much of the data seems to have been recovered from his work computer after he lost a job.

This article is two years old. Current status, from US Bureau of Prisons Inmate Locator:

    RYAN S LIN
    Register Number: 00578-138
    Age:  	26
    Race: 	Asian
    Sex: 	Male
    Located at: Brooklyn MDC
    Release Date: 01/02/2033
Post reply on HN