Live data from Hacker News

The FBI Identified a Tor User

vice.com

171–180 of 367 posts

Re: The FBI Identified a Tor User

#171

From Bruce of all people, this is a wildly provocative, unsubstantiated claim about routine takedown behavior from the feds. I mean, nobody hates the gov side of the cryptography wars more than me, but this type of article is well below table-stakes for discussion. Especially by legendary professionals of repute like Bruce. It's very disappointing to me. The price of clicks truly deconstructs the modern man's integri…

> unsubstantiated claim

There's a court document from a defender specifically referring to the evidence the FBI is presenting. Lawyers can be severely sanctioned if they lie in a briefing, so the lawyer drafting that has certainly seen a court document by the FBI stating that they got the IP of this user despite Tor. Bruce never claims more than that.

Re: The FBI Identified a Tor User

#172

From Bruce of all people, this is a wildly provocative, unsubstantiated claim about routine takedown behavior from the feds. I mean, nobody hates the gov side of the cryptography wars more than me, but this type of article is well below table-stakes for discussion. Especially by legendary professionals of repute like Bruce. It's very disappointing to me. The price of clicks truly deconstructs the modern man's integri…

My take on it: He's sending out a reminder that Gov retains ability to extract people it wants from encrypted comms. He may have noticed a downturn in similar news stories. That we don't know the methods used here, this seems to emphasize the old reasons to live in caution.

Yeah, that thought crossed my mind, and I'm sure now that you mention it, it must have crossed his too.

Still, couldn't he just have written that?

Re: The FBI Identified a Tor User

#173
post #9

Earlier quoted context omitted.

No, it isn't. That's not what he was charged for, it's just one piece of evidence in the case: > “From Mr. Al-Azhari’s attempt to acquire firearms through unlawful channels to his desire to provide material support to a designated foreign terrorist organization, it was clear Mr. Al-Azhari’s intention was to carry out an act of violence,” > According to the complaint, Al-Azhari was an ISIS supporter who planned and at…

I’m interested what the case law is for arresting someone for intent to perform a heinous act. I’ve heard a lot from stalking victims and the like that often times police will refuse to do anything until the stalker has assaulted or murdered the victim in question, despite clear indications the stalker is actively planning to do harm.

Staking and terrorism are not the same. The FBI gets a boost to their career if they get a terrorism conviction, but there's no such incentive for more normal crime.

Re: The FBI Identified a Tor User

#174

can you not use nordvpn first, then tor?

Mullvad, please. nordvpn has been acquired by some private equity that's acquiring all the vpns.

do you agree based on your understand that if this TOR user had used Mullvad VPN services (or equivalent) he would've been fine/not detected by the FBI?

Re: The FBI Identified a Tor User

#175

Earlier quoted context omitted.

Well, not all the exit nodes by now. But many of them. Most people are probably leery of running an exit node, because its traffic is in the clear (modulo ssh) and often connects to disparate and shady servers.

This is what I've never understood about Tor. What possible incentive does anyone have to run an exit node? Seems like nothing but a liability for some extremely awful stuff.

There is no incentive to run any node other than feeling good about it or using it for intelligence purposes. It's a volunteer thing. But to run exits you just need a host who won't kick you for every single abuse notice.

Re: The FBI Identified a Tor User

#176

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

> it would require them revealing zero days they have on Tor

I always figured this was the case for a lot of common things like full-disk encryption schemes, AES, root certs, etc. If there's a break, they wouldn't use it in court unless it's taking down a very, very big target.

Re: The FBI Identified a Tor User

#177

Earlier quoted context omitted.

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

Probably. If you use a laptop once, on a public Wi-Fi hundreds of miles from where you live, while not being caught on surveillance, while using a stripped down privacy based OS, and then route yourself through Tor, you might be okay.

Not if you brought your cellphone on the trip. Or used a car that has a built-in SIM card and cellular modem. Or you bought that laptop from a supplier that registers all MAC addresses of sold devices. Or that laptop had Computrace or some other firmware-based anti-theft mechanism.

Re: The FBI Identified a Tor User

#179

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

Hole in the ground far away? Not on the internet presumably. In any case any would be terrorists should take note: don't use grannies computer.
Post reply on HN