Live data from Hacker News

The FBI Identified a Tor User

vice.com

331–340 of 367 posts

Re: The FBI Identified a Tor User

#331

Earlier quoted context omitted.

>I ran a tor webserver for discussing geopolitics with friends on a pi for a few months before finding it had been compromised. Not the fault of Tor. HSDir nodes could snoop on announced v1 .onion adresses. This isn't the case anymore for Onion v2 addresses. But even if an attacker has the onion address of your webserver, he needs a way to compromise it. Either through a vuln in your website or your webserver.

A vuln in the webserver is the usual way, I used to collect and scan .onion domains for misconfiguration issues a few years ago. You would be amazed how many admins leave shit like PHPMyAdmin wide open.

I've found the clearnet IP of some darknet markets by typing their into the text input at search.censys.io. That's such poor opsec that I have to assume I identified a phishing proxy to the market rather than the actual origin server of the market itself.

Re: The FBI Identified a Tor User

#332

Earlier quoted context omitted.

> - ordering the most boring coffee The fatal flaw in the plan: Barista talking to news after person is arrested by FBI: "As soon as they ordered the brewed coffee with no customizations after standing in line for 10 minutes, I knew something was suspicious. Who comes to Starbucks, stands in line for 10 minutes, and then orders boring coffee?"

Good point! Let's make it a caramel macchiato with two pumps vanilla and sugar free creamer! Oh god I am leaking information!

That sounds like the most boring coffee. Why would someone wait in line 10 minutes for that?

Re: The FBI Identified a Tor User

#333
post #221

Earlier quoted context omitted.

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

One of my favorite HN comments of all time [0] suggested that MMO's provide plentiful means of covertly communicating: >MMO's are packed with possible communication channels in addition to chat. Ever wonder if that annoying gnome in the auction hall is jumping in morse code? Could signals be sent with bids? Could a character's inventory contents be arranged to leave a message to someone else who shares the login info…

Thanks to Snowden we know that the NSA is monitoring MMOs. I wouldn't doubt if the FBI wasn't watching over online games too especially the ones targeting kids like fortnite and roblox

Re: The FBI Identified a Tor User

#334

Earlier quoted context omitted.

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

If I were hiding from a state actor I'd use a high-bandwidth communications medium like video. In another life I worked for a large live streaming service, the infrastructure required to process terabits of video is mind-boggling in size, extremely technically challenging, and usually involves custom built ASICs and hardware that's expensive and in short supply. Even with the NSA's budget and infrastructure, I don't…

> Even with the NSA's budget and infrastructure, I don't think it's technologically feasible for them to decrypt and then semantically process or store that much content.

I have little doubt that they can store terabits of video content. They let us know about their utah data center (https://en.wikipedia.org/wiki/Utah_Data_Center) which was estimated to have as much as 12 exabytes in 2013 and who knows what data centers they have they aren't mentioning. Back in 2003 they had no problems capturing every bit of data that moved over AT&Ts network. Storage is dirt cheap and they can just hang onto everything until they see a reason to dig into it. No need to process everything right away.

You'd think your video would be blending in with all the other video on the internet, but it really wouldn't. Streaming video put out by netflix is going to look very different than streaming video served via youtube vs streaming video over P2P etc.

Re: The FBI Identified a Tor User

#335

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

> it would require them revealing zero days they have on Tor I always figured this was the case for a lot of common things like full-disk encryption schemes, AES, root certs, etc. If there's a break, they wouldn't use it in court unless it's taking down a very, very big target.

[deleted]

Re: The FBI Identified a Tor User

#336

I think a lot of this has been covered elsewhere before: - when using tor you should disable javascript because a malicious or compromised site can use javascript to do non-tor stuff that potentially compromises your location. (can be a big pill to swallow, web without javacript is very 90s) - Run torbrowser within a secure VM or separate device using Tails to minimize your activity footprint - Use a VPN when connect…

> Use a VPN when connecting to TOR You should not do this. It is at best useless, at worst strictly negative. A VPN tunnels all your traffic through their own servers, so they are a single point of failure roughly equivalent to your ISP. Anyone with access to the VPN servers could spy on all of your traffic, completely bypassing Tor. If you pay for the VPN with a credit card, you can be easily identified.

It's not a good idea, but not for the reason stated here.

The TOR client will establish a tunnel OVER the VPN to the entry node, so the VPN provider will only see this encrypted traffic. The VPN server cannot spy on you.

When you connect to TOR it carefully selects your circuit for diversity over the Internet between each hop (for example avoiding your entry and exit nodes not being on the same service provider). By using a VPN your opening the possibility for something to go wrong here.

Re: The FBI Identified a Tor User

#337

Earlier quoted context omitted.

The most paranoid plan i have come up with: - tor + cubesOS set up by somebody you deeply trust (person A) - on a USB bought by a different person (person B) - with a network card bought by a different person (person C) - many miles away, wearing generic clothes in a cafe where people go to work - different hairstyle and facial hair - mask - without having a phone (obv) - navigating there by changing multiple cars wi…

What you're describing is likely overkill. Just buy a used laptop on Craigslist. Drive about 50 mi away. Park at a motel and take a yellow cab to a moderately busy Starbucks. Hack away, and then leave via yellow cab. Leave your phone in your car. Pay for everything in cash. Throw away the laptop. There's a chance that you'll get caught on camera at Starbucks. But the cameras there, if any, aren't set up to provide fu…

When they trace the activity back to that starbucks I imagine the fact that you happened to be in the area that day, 50 miles away from your home, stopping at a hotel that requested a cab to that same starbucks would stand out rather quickly.

If you leave your cell phone at home that would help, but you still risk being tracked by your car or being caught on any number of cameras and identified via facial recognition.

Re: The FBI Identified a Tor User

#338

Earlier quoted context omitted.

The most paranoid plan i have come up with: - tor + cubesOS set up by somebody you deeply trust (person A) - on a USB bought by a different person (person B) - with a network card bought by a different person (person C) - many miles away, wearing generic clothes in a cafe where people go to work - different hairstyle and facial hair - mask - without having a phone (obv) - navigating there by changing multiple cars wi…

Walking and driving without a mobile device on your person is sufficiently unusual that it's a form of metadata in itself. Look at the Kohberger case - they're using the fact he turned his phone off as evidence. In fact, this kind of pattern was even used by the Obama administration while targeting humans in the Middle East for extrajudicial killings. It's even more precise when coupled with traffic analysis: if ever…

> Want to turn off location services? Make sure you turn off WiFi too, because a list of nearby access points and SSIDs is enough to pinpoint you down to a few meters.

Not just wifi, bluetooth is used for location tracking as well.

Re: The FBI Identified a Tor User

#339

Earlier quoted context omitted.

In USA I wonder how they forced you to enter contract with medical provider. A letter to debt collector to 'validate alleged debt and show me the signed contract' could be interesting.

I did that exact thing and they sent back a rejection of the dispute along with shitty screenshot of me listed as "guarantor" of ICE's health service corps lol. Obviously I refused to sign anything. I have no idea how the collectors even found me as I had no valid contact information as the feds put their own address as mine.

FDCPA has provisions for a letter with specific words to make them stop contacting you. They will likely ignore that, so consider if you would then sue for damages.

Most States have a 'declaratory judgment' law in which an issue is brought to court and decided. You could force them to prove a contract in a court. They will probably not show up. Or they could show up and you could get corrupt judge and lose.

https://www.law.cornell.edu/wex/fair_debt_collection_practic...

Re: The FBI Identified a Tor User

#340

I think a lot of this has been covered elsewhere before: - when using tor you should disable javascript because a malicious or compromised site can use javascript to do non-tor stuff that potentially compromises your location. (can be a big pill to swallow, web without javacript is very 90s) - Run torbrowser within a secure VM or separate device using Tails to minimize your activity footprint - Use a VPN when connect…

> Use a VPN when connecting to TOR You should not do this. It is at best useless, at worst strictly negative. A VPN tunnels all your traffic through their own servers, so they are a single point of failure roughly equivalent to your ISP. Anyone with access to the VPN servers could spy on all of your traffic, completely bypassing Tor. If you pay for the VPN with a credit card, you can be easily identified.

> You should not do this. It is at best useless, at worst strictly negative.

Whenever people write this comment I get the same vibe as when people say that all the recipes in The Anarchist Cookbook are rigged to fail - however I’m in a much better position to judge the technology then the chemistry.

Adding in the VPN (which you should already have and use regularly) before the first Tor guard or bridge node has several benefits - it obscures your usage of the Tor network by a causal observer at the origin (the FBI said they could tell Dread Pirate Roberts was using Tor from the ip addresses, just not what he was using it for - though they did note he was active on Tor during periods Dread Pirate Roberts was active although that alone wasn’t enough for a warrant), it obscures your origin ip to the causal observer at the guard or bridge, your activity is mixed with all other vpn users using the same vpn server(s) - some VPNs add a layer of indirection by routing your traffic through two servers, and it increases the total number of nodes your traffic flows through by at least 1 - unless you do a compile time change to increase the length of the route.

The risk of a party having control of both your vpn and all the tor servers in your path is not zero but at that point the universe pretty much wants you to be found. Should have gone to those Wednesday pot-lucks and put a little more into the building fund. ;)

The person in the article did not use a vpn and they traced the traffic to his mom’s house - amendment to the Ten Commandments of Selling Crack, “Don’t sell crack where your moms at”.

Paying for a vpn with a credit card doesn’t make you identifiable, the list of suspects is everyone who uses the vpn, or knows someone who has a password, or works for a company that maintains a pool of corporate accounts. Most VPNs don’t link outgoing connections to back to users, just so they don’t have to deal with people asking those sorts of questions.

Post reply on HN