Live data from Hacker News

The FBI Identified a Tor User

vice.com

91–100 of 367 posts

Re: The FBI Identified a Tor User

#91
post #52

Earlier quoted context omitted.

Out of curiosity, will we get more detail? Presumably the FBI would need to reveal to somebody how they obtained this information in order for it to be admissible as evidence ("he did this, trust us" probably won't fly in court), but is there a legal means by which they could do that without revealing their exact methods to the general public? (I don't actually know what the law says on this subject.)

Parallel construction. They use their real methods to identify the user, then once they know the user, specifically target them with simpler known methods to build evidence for the case. In the court filing, they present evidence that they've gained through known methods which don't work all that well unless you already have a suspect, but they actually caught the suspect using methods that are not public (and won't…

Is there proof of anything like this or is it just a conspiracy theory you’re peddling?

Re: The FBI Identified a Tor User

#93

Earlier quoted context omitted.

I’m interested what the case law is for arresting someone for intent to perform a heinous act. I’ve heard a lot from stalking victims and the like that often times police will refuse to do anything until the stalker has assaulted or murdered the victim in question, despite clear indications the stalker is actively planning to do harm.

There are plenty of laws about, say, attempted murder. Also, it’s possible for somebody to be convicted of shoplifting even if they’re nabbed before they leave the store if it’s clear that they were in the process of stealing items ( https://en.wikipedia.org/wiki/Attempt ). And when there isn’t a specific law, there is a general “conspiracy to commit” law ( https://en.wikipedia.org/wiki/Criminal_conspiracy ), which i…

I guess my confusion here is why stalkers aren’t arrested for intent to commit assault or murder in a similar way, I mean, this guy intended to help terrorists but he was largely doing this through otherwise legal channels like purchasing weaponry? What if a stalker buys a weapon, repeatedly tells a victim of planned murder plots, etc?

Re: The FBI Identified a Tor User

#94

Earlier quoted context omitted.

Parallel construction. They use their real methods to identify the user, then once they know the user, specifically target them with simpler known methods to build evidence for the case. In the court filing, they present evidence that they've gained through known methods which don't work all that well unless you already have a suspect, but they actually caught the suspect using methods that are not public (and won't…

Is there proof of anything like this or is it just a conspiracy theory you’re peddling?

Parallel construction is very real and common

Re: The FBI Identified a Tor User

#95
I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases.

The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content.

If your adversary is a state actor, particularly the U.S., tor alone is not sufficient for anonymity. It's fairly safe to assume they have the ability to deanonymize you. Your only safety net, it seems, is the value of other targets relative to you when it comes to them burning their "golden ticket" zero day. And even then, you're at risk of parallel construction.

If you're sitting in front of a computer that you're using for something the U.S. government has significant interest in prosecuting, that device should be considered compromised and adversarial - you should act accordingly.

https://www.wired.com/2017/03/feds-rather-drop-child-porn-ca...

Edit, pulling up from the threads below:

Tor is just a layer. You still have to take measures to separate your identity from the device, the behavior, and the location.

When tor falls, the next question is "what do they see?" You have control over that.

Re: The FBI Identified a Tor User

#96

Earlier quoted context omitted.

Parallel construction. They use their real methods to identify the user, then once they know the user, specifically target them with simpler known methods to build evidence for the case. In the court filing, they present evidence that they've gained through known methods which don't work all that well unless you already have a suspect, but they actually caught the suspect using methods that are not public (and won't…

Is there proof of anything like this or is it just a conspiracy theory you’re peddling?

I think it's commonly known, maybe not proven, but also it's a case of can they? yes. Would they? yes. As long as you agree with those two premises it's pretty likely

Re: The FBI Identified a Tor User

#97

Earlier quoted context omitted.

> The FBI also found what specific pages Al-Azhari visited, including a section on donating Bitcoin; another focused on military operations conducted by ISIS fighters in Iraq, Syria, and Nigeria; and another page that provided links to material from ISIS’s media arm Based on what little I know of SSL, this suggests the server was compromised too? Or does tor do a bad job of certificate pinning? Edit: Or the clients a…

> Based on what little I know of SSL, this suggests the server was compromised too? Not necessarily. If a passive snooper knows I used Tor Browser to make an SSL request to en.wikipedia.org and received 987,654 bytes then immediately made a SSL request to upload.wikimedia.org and received 1,234,567 bytes that might be enough information to work out I visited https://en.wikipedia.org/wiki/National_Security_Agency .

That size-inference side channel leak has been patched for years, random padding is added between hops to mitigate this.

It is large files / DDoS going over the network that is still hard to obfuscate.

Which is why TOR is intentionally slow, especially when requesting larger files. If it wasn't, you could watch the lump of data traverse across the pipe.

source: n/a

Re: The FBI Identified a Tor User

#98
post #42

Earlier quoted context omitted.

So you did illegal things illegally. And who owned the public AP? Someone not as smart as you? You sure?

So you did illegal things illegally. Yep. I said I don't understand people who do illegal things over their own connection, i.e., stupidly. And who owned the public AP? McDonald's.

McDonald's has video cameras pointing at every inch of their property 24/7. All they need is a timestamp from the AP and they'll go find your license plate in the parking lot on the surveillance tapes.

Re: The FBI Identified a Tor User

#99

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

Is there really any way to hide from a motivated state actor?

Asking about it on HN is definitely not one.

Relevant xkcd: 538 [1]

[1] https://xkcd.com/538/

Re: The FBI Identified a Tor User

#100

Earlier quoted context omitted.

Seems like this is a case of the government saying "trust us". They noted two ways that the feds could have gotten the IP address but how about a third, they targeted the guy and got the IP address from the ISP and said "look!, we found our guy" -occams razor.

Wouldn't they need to know who he is before they could target him and acquire his IP? Unless your suggesting parallel construction?

I read the doc and it seems like the case is built on information gathered by the government but they won't say how. They don't want to say how because it's supposed to be a national security issue, which is understandable but not how our legal system works (or should work). They are saying that they got his IP via tor and that that IP address went to ISIS websites, but again they won't say how they have this information they are just saying "trust us". I'm saying that if they had targeted this individual, the feds thought he was up to something but had no real evidence, it would be really easy to find this guys IP address and then say he went to X website and he needs to go to jail -but we can't tell you how we found this out. Do you see where the problem is? We still have due process in this country or at least we're supposed to.
Post reply on HN