Live data from Hacker News

The FBI Identified a Tor User

vice.com

191–200 of 367 posts

Re: The FBI Identified a Tor User

#191

Earlier quoted context omitted.

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

Probably. If you use a laptop once, on a public Wi-Fi hundreds of miles from where you live, while not being caught on surveillance, while using a stripped down privacy based OS, and then route yourself through Tor, you might be okay.

The most paranoid plan i have come up with:

- tor + cubesOS set up by somebody you deeply trust (person A)

- on a USB bought by a different person (person B)

- with a network card bought by a different person (person C)

- many miles away, wearing generic clothes in a cafe where people go to work

- different hairstyle and facial hair

- mask

- without having a phone (obv)

- navigating there by changing multiple cars with minimal electronics

- ordering the most boring coffee

- persons A, B, C don't know each other. You don't know personally B, C, but a person(s) D, (and E) can vouch for them.

My gut tells me that the more people you involve, the easier it is to trace you because you will be at the intersection of those people's radii.

Re: The FBI Identified a Tor User

#192
post #177

Earlier quoted context omitted.

Not if you brought your cellphone on the trip. Or used a car that has a built-in SIM card and cellular modem. Or you bought that laptop from a supplier that registers all MAC addresses of sold devices. Or that laptop had Computrace or some other firmware-based anti-theft mechanism.

Okay so in addition to the above, use a burner and change your MAC address. “Lojacks” on laptops is still mostly pretty unheard of.

> mostly pretty unheard of

Yeah, but if there is an exception to that, it'd be the scenario we're talking about.

Re: The FBI Identified a Tor User

#193

From Bruce of all people, this is a wildly provocative, unsubstantiated claim about routine takedown behavior from the feds. I mean, nobody hates the gov side of the cryptography wars more than me, but this type of article is well below table-stakes for discussion. Especially by legendary professionals of repute like Bruce. It's very disappointing to me. The price of clicks truly deconstructs the modern man's integri…

Bruce has also been hardcore anti-cryptocurrency. From a pure cryptography perspective the innovations around zero knowledge proofs are very intriguing and it’s highly unlikely they would have happened as quickly without the monetary benefit of cryptocurrency pushing such research forwards. However Bruce is an extreme statist, and if he had his way I’m sure all cryptography would be backdoored.

Really? Bruce is pro-backdoor?

Where's that pro-backdoor advocacy in this essay from 2013 on evading NSA surveillance and warning about the risk of backdoored cryptography? https://www.schneier.com/essays/archives/2013/09/nsa_surveil...

Or this essay from 2016 arguing that backdoors sabotage security? https://www.schneier.com/essays/archives/2016/04/the_value_o...

Or this essay from 2019 decrying yet another effort to backdoor encryption? https://www.schneier.com/blog/archives/2019/12/scaring_peopl...

Re: The FBI Identified a Tor User

#194

can you not use nordvpn first, then tor?

Mullvad, please. nordvpn has been acquired by some private equity that's acquiring all the vpns.

I know that Nord Security the company that own nordvpn has acquired AtlasVPN and I also know that the VPN market is quite concentrated, 7 companies owns dozens of brands. I would like information on those acquisitions... have I missed some important news?

I would like to know because NordVPN, while not as hardcore on privacy as mullvad, is still providing a useful service for protection against an untrusted wifi and geofence jumping.

Re: The FBI Identified a Tor User

#195

Earlier quoted context omitted.

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

it depends on what you're doing (as far as I understand as a criminal news nerd) the police-justice system is usually broke for commoners. So yeah, if you're not doing a serious offense, they will never catch you. Where I live, you can buy weed. Even if the government says they're motivated to stop it, they don't have the resources to plant police everywhere. If your home was 'visited' by burglars, they would just ta…

[dead]

Re: The FBI Identified a Tor User

#196

I have a Glinet[0] router that has Tor functionality and 'torifies' your connection, so even if there's some JS 0day that executes trying to decloak me, the adversary just gets a Tor IP instead of my home connection IP. Note: I connect to Tor from my torified Glinet router which is doing Tor-over-Tor which is considered 'dangerous'[1] but I do it anyway. This might be overkill for most, and I'm not doing anything ill…

Out of curiosity, what is the benefit of using Tor just to browse legal clearnet sites?

Re: The FBI Identified a Tor User

#197

Earlier quoted context omitted.

Even leaving aside the question of whether the FBI actually compromised Tor, or just did something way more mundane like infect the defendant's PC with malware, the linked court document is really interesting. Not only does the FBI decline to say how they determined what IP address the defendant used to access the Tor hidden service, but they're also trying to hide the fact that the defendant asked to see that inform…

If becomes widely known that the government can de-cloak Tor users, that will change the behaviour of their targets and so hurt their surveillance, so it's fairly common that the government wants to hide this fact. (same with stingrays, for example). But just wanting to keep it secret is not enough. So they will claim that this has national security implications, saying some targets are terrorists. And courts defer v…

>If becomes widely known that the government can de-cloak Tor users, that will change the behaviour of their targets and so hurt their surveillance, so it's fairly common that the government wants to hide this fact. (same with stingrays, for example).

As was discussed verbally at Defcon, a huge chunk of the exit nodes are either in the US or EU. Same for guards.

(The whole GCHQ vs several EU countries trying to do intel in parallel without a shared intelligence agency thing is perpetually amusing.)

Re: The FBI Identified a Tor User

#198

Earlier quoted context omitted.

Probably. If you use a laptop once, on a public Wi-Fi hundreds of miles from where you live, while not being caught on surveillance, while using a stripped down privacy based OS, and then route yourself through Tor, you might be okay.

The most paranoid plan i have come up with: - tor + cubesOS set up by somebody you deeply trust (person A) - on a USB bought by a different person (person B) - with a network card bought by a different person (person C) - many miles away, wearing generic clothes in a cafe where people go to work - different hairstyle and facial hair - mask - without having a phone (obv) - navigating there by changing multiple cars wi…

> - ordering the most boring coffee

The fatal flaw in the plan:

Barista talking to news after person is arrested by FBI: "As soon as they ordered the brewed coffee with no customizations after standing in line for 10 minutes, I knew something was suspicious. Who comes to Starbucks, stands in line for 10 minutes, and then orders boring coffee?"

Re: The FBI Identified a Tor User

#199
post #42

Earlier quoted context omitted.

So you did illegal things illegally. And who owned the public AP? Someone not as smart as you? You sure?

So you did illegal things illegally. Yep. I said I don't understand people who do illegal things over their own connection, i.e., stupidly. And who owned the public AP? McDonald's.

I was more taking issue with your misplaced confidence about using a public AP than your doing illegal things.

Re: The FBI Identified a Tor User

#200

Earlier quoted context omitted.

Parallel construction. They use their real methods to identify the user, then once they know the user, specifically target them with simpler known methods to build evidence for the case. In the court filing, they present evidence that they've gained through known methods which don't work all that well unless you already have a suspect, but they actually caught the suspect using methods that are not public (and won't…

Is there proof of anything like this or is it just a conspiracy theory you’re peddling?

Exclusive: U.S. directs agents to cover up program used to investigate Americans [2013]

https://www.reuters.com/article/us-dea-sod-idUSBRE97409R2013...

Post reply on HN