Live data from Hacker News

The FBI Identified a Tor User

vice.com

181–190 of 367 posts

Re: The FBI Identified a Tor User

#181
post #177

Earlier quoted context omitted.

Probably. If you use a laptop once, on a public Wi-Fi hundreds of miles from where you live, while not being caught on surveillance, while using a stripped down privacy based OS, and then route yourself through Tor, you might be okay.

Not if you brought your cellphone on the trip. Or used a car that has a built-in SIM card and cellular modem. Or you bought that laptop from a supplier that registers all MAC addresses of sold devices. Or that laptop had Computrace or some other firmware-based anti-theft mechanism.

Okay so in addition to the above, use a burner and change your MAC address. “Lojacks” on laptops is still mostly pretty unheard of.

Re: The FBI Identified a Tor User

#182

Earlier quoted context omitted.

Is your intention in repeating that to keep Tor usage below the critical threshold where that remains true?

No offense but TOR is just too sluggish to be really useful unless you're a gay pirate assassin (or one of those three components)[0]. It has basically all the drawbacks a VPN has (most sites will distrust you on recaptcha, speed bumps, sometimes a connection gets timed out or dropped) whilst having a shitton of latency on top of that because y'know, it's free. There's always been more people willing to use TOR than…

Have you used Tor recently? I don't find it to be very slow. It's obviously not Gigabit but for just reading web pages it is more than enough. See https://metrics.torproject.org/torperf.png?start=2012-01-01&... - and that recent spike in latency only exists because of some DDos attack (I think).

Re: The FBI Identified a Tor User

#183

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

[dead]

Re: The FBI Identified a Tor User

#184
post #147

Earlier quoted context omitted.

Lol if you don't want to be fucked with by the government, just don't break the law! Unfortunately that doesn't work. Sometimes legal activities are best kept under wraps. I have a signed and executed federal search warrant in my drawer. I was tossed in a cell. I was dragged to a hospital. I was sent the bill for the "search" and am currently being hounded by debt collectors. Nothing was found and I did nothing wrong…

Aren't you mixing up two different things? There's your problem, being harassed for something you say you didn't do. And there is the criminal's problem, being found out for something they did do. For the latter problem, not doing the illegal thing sounds like a solid strategy.

What's the purpose of this distinction, if the actor (law enforcement) does not effectively make this distinction?

Re: The FBI Identified a Tor User

#185

Earlier quoted context omitted.

yep, this, I ran a tor webserver for discussing geopolitics with friends on a pi for a few months before finding it had been compromised. that was shortly after intel exchange had been taken down. Tor services just arent secure in any sense imho. especially not from the people who wrote them. sigh.

>I ran a tor webserver for discussing geopolitics with friends on a pi for a few months before finding it had been compromised. Not the fault of Tor. HSDir nodes could snoop on announced v1 .onion adresses. This isn't the case anymore for Onion v2 addresses. But even if an attacker has the onion address of your webserver, he needs a way to compromise it. Either through a vuln in your website or your webserver.

> This isn't the case anymore for Onion v2 addresses

You're right, except you meant v3.

Re: The FBI Identified a Tor User

#186

Earlier quoted context omitted.

Mullvad, please. nordvpn has been acquired by some private equity that's acquiring all the vpns.

do you agree based on your understand that if this TOR user had used Mullvad VPN services (or equivalent) he would've been fine/not detected by the FBI?

If FBI really has compromised Tor, there's no reason to believe they would be helpless against a VPN service.

Re: The FBI Identified a Tor User

#187

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

> it would require them revealing zero days they have on Tor I always figured this was the case for a lot of common things like full-disk encryption schemes, AES, root certs, etc. If there's a break, they wouldn't use it in court unless it's taking down a very, very big target.

Indeed. Very big targets are taken by 0 days, and like Op above mentioned, low hanging fruits are taken by parallel construction. Looks like there is a sweet spot in the middle, where they can’t be bothered.

Re: The FBI Identified a Tor User

#189

Earlier quoted context omitted.

> three people could only keep a secret if 2 are dead Exactly. Which is why, not to start a JFK war, I think the Mafia killed JFK. If it were the CIA, or LBJ, someone would have talked. Anyone who knew what happened got whacked.

But doesn’t that mean there was someone coordinating the whacking of those in the know? If so, wouldn’t THAT person know the truth?

Yeah, but those Mafia bosses don't get where they are by being blabbermouths.

And note that Jimmy Hoffa got disappeared, albeit 13 years later.

Re: The FBI Identified a Tor User

#190

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

I figured unless working for an intelligence agency or some ideological reasons there is no reason to go against the US government.

I don't think there is enough protection against such actor unless you are working directly for another state actor. And even that you won't keep anonymity. Check the North Korean gov cracker case. DoJ managed to figure out his name and photo despite that he works for a state actor.

That guy probably won't want to go abroad to most of the countries. Even countries competing with US such as China or Russia might send him to Uncle Sam for some exchange of interest. I actually think the Chinese probably provided some information to DoJ as he worked in the DaLian branch of a NK expo company for some years.

Post reply on HN