Live data from Hacker News

The FBI Identified a Tor User

vice.com

11–20 of 367 posts

Re: The FBI Identified a Tor User

#11

I wonder if this is going to be confirmation that a large fraction of Tor nodes are in fact run by the FBI.

> The FBI also found what specific pages Al-Azhari visited, including a section on donating Bitcoin; another focused on military operations conducted by ISIS fighters in Iraq, Syria, and Nigeria; and another page that provided links to material from ISIS’s media arm Based on what little I know of SSL, this suggests the server was compromised too? Or does tor do a bad job of certificate pinning? Edit: Or the clients a…

Unless I'm missing some info, I don't see anything that points at them finding all this info through Tor or the server. They identified the user AND 'also found what specific pages Al-Azhari visited'. That could've happened from his PC after they arrested him. Language like this is always ambiguous in order to give out as little information as possible while still providing some.

Re: The FBI Identified a Tor User

#13
post #6

Earlier quoted context omitted.

So what if they were? Only exit node see the message (encrypted or not). And it doesn't know where it originated. I speculate this is most likely case of a ISIS server run by FBI.

If you control both exit and entrance nodes, you can corralate connections with a timing analysis.

I don't think that is how timing analisis works. User can say to "entrance node" that it is also a node and that is how it can deny that it is originator. "Entrance node" doesn't know its position in a chain. Only Exit node knows its position.

Re: The FBI Identified a Tor User

#14
post #11

Earlier quoted context omitted.

> The FBI also found what specific pages Al-Azhari visited, including a section on donating Bitcoin; another focused on military operations conducted by ISIS fighters in Iraq, Syria, and Nigeria; and another page that provided links to material from ISIS’s media arm Based on what little I know of SSL, this suggests the server was compromised too? Or does tor do a bad job of certificate pinning? Edit: Or the clients a…

Unless I'm missing some info, I don't see anything that points at them finding all this info through Tor or the server. They identified the user AND 'also found what specific pages Al-Azhari visited'. That could've happened from his PC after they arrested him. Language like this is always ambiguous in order to give out as little information as possible while still providing some.

> That could've happened from his PC after they arrested him.

Tor client wouldn’t save any of that.

Re: The FBI Identified a Tor User

#16
post #11

Earlier quoted context omitted.

Unless I'm missing some info, I don't see anything that points at them finding all this info through Tor or the server. They identified the user AND 'also found what specific pages Al-Azhari visited'. That could've happened from his PC after they arrested him. Language like this is always ambiguous in order to give out as little information as possible while still providing some.

> That could've happened from his PC after they arrested him. Tor client wouldn’t save any of that.

[deleted]

Re: The FBI Identified a Tor User

#18
post #11

Earlier quoted context omitted.

Unless I'm missing some info, I don't see anything that points at them finding all this info through Tor or the server. They identified the user AND 'also found what specific pages Al-Azhari visited'. That could've happened from his PC after they arrested him. Language like this is always ambiguous in order to give out as little information as possible while still providing some.

> That could've happened from his PC after they arrested him. Tor client wouldn’t save any of that.

he may not have been using the tor browser

Re: The FBI Identified a Tor User

#19
post #13

Earlier quoted context omitted.

If you control both exit and entrance nodes, you can corralate connections with a timing analysis.

I don't think that is how timing analisis works. User can say to "entrance node" that it is also a node and that is how it can deny that it is originator. "Entrance node" doesn't know its position in a chain. Only Exit node knows its position.

I don't think that's totally true. At least, it's maybe superficially true but not in a real world sense. The entry node can see your IP by virtue of the incoming TCP connection and it's not hard to figure out if an IP is a Tor relay or not. The list of known relays is a list that you can just go and get. If it's not a relay, then it's a client, and you're the entry node.

Re: The FBI Identified a Tor User

#20
post #9
post #7

More troubling - is it a crime to visit a website which begs donations for an illegal cause?

No, it isn't. That's not what he was charged for, it's just one piece of evidence in the case: > “From Mr. Al-Azhari’s attempt to acquire firearms through unlawful channels to his desire to provide material support to a designated foreign terrorist organization, it was clear Mr. Al-Azhari’s intention was to carry out an act of violence,” > According to the complaint, Al-Azhari was an ISIS supporter who planned and at…

I’m interested what the case law is for arresting someone for intent to perform a heinous act. I’ve heard a lot from stalking victims and the like that often times police will refuse to do anything until the stalker has assaulted or murdered the victim in question, despite clear indications the stalker is actively planning to do harm.
Post reply on HN