Live data from Hacker News

The FBI Identified a Tor User

vice.com

351–360 of 367 posts

Re: The FBI Identified a Tor User

#351
post #260

Earlier quoted context omitted.

When you say "de-anonymize a Tor user", the implicit but unambiguous meaning is that you attacked Tor, not found the information from somewhere else. Just like when you say "a BMW driver crashed into a mall", you mean that they did it with their BMW, not with the Subaru that they also own.

The language in the blog post, "There are lots of ways to ..." is explicitly highlighting the ambiguity.

Yeah, maybe so. The linked slide does list "user error" as one of the angles.

Re: The FBI Identified a Tor User

#352
post #347

Earlier quoted context omitted.

When they trace the activity back to that starbucks I imagine the fact that you happened to be in the area that day, 50 miles away from your home, stopping at a hotel that requested a cab to that same starbucks would stand out rather quickly. If you leave your cell phone at home that would help, but you still risk being tracked by your car or being caught on any number of cameras and identified via facial recognition…

> When they trace the activity back to that starbucks I imagine the fact that you happened to be in the area that day This assumes they are already looking for YOU.

I assume they'd be looking at everyone who was in the area and isn't following their usual routine. That's what I'd do anyway. I'd look into the owners of each device logged that isn't normally around.

Re: The FBI Identified a Tor User

#353

Earlier quoted context omitted.

The most paranoid plan i have come up with: - tor + cubesOS set up by somebody you deeply trust (person A) - on a USB bought by a different person (person B) - with a network card bought by a different person (person C) - many miles away, wearing generic clothes in a cafe where people go to work - different hairstyle and facial hair - mask - without having a phone (obv) - navigating there by changing multiple cars wi…

Walking and driving without a mobile device on your person is sufficiently unusual that it's a form of metadata in itself. Look at the Kohberger case - they're using the fact he turned his phone off as evidence. In fact, this kind of pattern was even used by the Obama administration while targeting humans in the Middle East for extrajudicial killings. It's even more precise when coupled with traffic analysis: if ever…

Interesting post. Regarding Kohberger, you would think a PhD in criminology would have left his phone on and at his residence during and leading up to the crime. I read that he had a pattern of taking his phone with him on the same route for several months leading up to the murders... Along with the rest of the sloppiness, that seems to be fairly damning evidence and is low hanging fruit IMO.

Before the internet and mobile phone age I can only imagine how much harder crimes like this were to solve.

Re: The FBI Identified a Tor User

#354

Earlier quoted context omitted.

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

If I were hiding from a state actor I'd use a high-bandwidth communications medium like video. In another life I worked for a large live streaming service, the infrastructure required to process terabits of video is mind-boggling in size, extremely technically challenging, and usually involves custom built ASICs and hardware that's expensive and in short supply. Even with the NSA's budget and infrastructure, I don't…

> it would be trivial to hide in plain sight with some creativity (Using stenography to hide content in the video)

Steganography is the word in this case. Stenography is different, it means short-hand writing.

Re: The FBI Identified a Tor User

#355

Earlier quoted context omitted.

The long-range wifi antenna has always sounded like an opsec urban legend to me. You'll be able to transmit signals to the router, but can you really receive them with any sufficient fidelity if the router itself does not also have a long range antenna or unusually high transmission power?

Antennas are reciprocal. They are just as directional receiving as transmitting. A 10dbi gain yagi boosts your transmitted and received signal equally.

Disclaimer: I'm a total noob at anything radio or electronics (and would appreciate an education on this topic from someone who isn't!)

> A 10dbi gain yagi boosts your transmitted and received signal equally

I don't see how this can be true, as long as you're not arguing semantics and actually want to use the wifi. Wouldn't you need two identical routers outfitted with high gain directional antennas pointing at each other? That's easy to do when you control both of them, but the subject under discussion is connecting to public wifi of a router you do not control.

Surely a big antenna pointing directly at a router with a tiny antenna will send signals with more clarity than it receives them. The tiny antenna is broadcasting a weak signal in all directions, and the big antenna is transmitting a strong signal in one direction.

I believe that the big antenna could "pick up" some parts of the radio waves from the router, but wouldn't most environments be too noisy for your receiver to find any useful signal? By the time the already weak radio wave gets to your antenna, it's dissipated so much that you couldn't possibly read enough of it to put a meaningful signal back together, right?

Re: The FBI Identified a Tor User

#356
post #257

Earlier quoted context omitted.

Why would it be? The purpose of laws like the 4A is to prevent the police from harassing innocent people by going on fishing expeditions. The purpose of the poisoned tree doctrine is to prevent the police from committing crimes as part of their work. But if a plains-clothes police officer sees you load a kilo of cocaine into your car every Tuesday, on the same street corner, there's nothing illegal or immoral about h…

> I see no reason why the uniformed cop should be compelled to reveal his source. If the defense asks at trial, what legitimate reason is there not to answer?

The legitimate reason is that it's not pertinent to the case. The accused is on trial, versus evidence publicly presented against him. If the prosecution feels that the evidence they would like to reveal in the trial is sufficient for a conviction, they have no reason to throw in 'Oh, and we have an informant who's been snitching on you and your fellow conspirators.'

It's not exculpatory evidence, there is no obligation for the prosecution to turn it over. There's no reason for the judge to allow a line of questioning into it unless the defendant can make an argument as to why its relevant.

Re: The FBI Identified a Tor User

#357

Earlier quoted context omitted.

I don’t think this is true unless the original evidence was obtained in violation of the fourth amendment, which zero days are not necessarily. You’re right though using parallel construction to launder prohibited search is illegal.

Why wouldn't parallel construction be perjury, even if the real search was legal?

I'm not a lawyer but my thought process is that the "parallel construction" is going to include some chain of information/observation > probable cause > search > evidence and parallel construction is going to include dishonest testimony in the observation or probably cause area.

In reality I know that its difficult and unlikely to be proven or prosecuted, but it seems like that would be perjury.

Honest question though and I'm curious if someone with more expertise can explain where I'm wrong.

Re: The FBI Identified a Tor User

#358

I wouldn't get so excited about this. There have been tons of javascript exploits to leak IP addresses in the past, it's more likely that than the FBI running thousands of servers.

But then you'd need to entice Tor users to turn on Javascript since it's turned off by default.

This is not actually the case, at least not with the most recent versions of the browser

Re: The FBI Identified a Tor User

#359
post #38

Earlier quoted context omitted.

After reading Edward Snowden's autobiography (Permanent Record, great read), I feel like Tor, end-to-end encryption and similar solutions/products are basically a dagger through the heart of intelligence services. As such, I find it hard to believe that they knowingly gave the public such tools. And if they did, it sure as hell backfired on them.

If they run enough nodes to deanonymize users, it's a dagger through the heart of other intelligence services, but an absolute blessing for the NSA

For very obvious reasons you don't need to run any nodes, craft any malware, or scrutinize a target's layer 3+ OPSEC, in order to break Tor. You simply go to tier 1 ISPs and buy up IP datagram headers going to/from entry nodes and you win. The only solution is a constant rate of fake traffic to the guard node.

Re: The FBI Identified a Tor User

#360
post #233

Earlier quoted context omitted.

After reading Edward Snowden's autobiography (Permanent Record, great read), I feel like Tor, end-to-end encryption and similar solutions/products are basically a dagger through the heart of intelligence services. As such, I find it hard to believe that they knowingly gave the public such tools. And if they did, it sure as hell backfired on them.

> After reading Edward Snowden's autobiography (Permanent Record, great read), I feel like Tor, end-to-end encryption and similar solutions/products are basically a dagger through the heart of intelligence services. As such, I find it hard to believe that they knowingly gave the public such tools. And if they did, it sure as hell backfired on them. I have heard it somewhere but using Tor or end-to-end is like using a…

> If someone wants you compromised, you will get compromised, it only matters how many resources they are willing to throw at you.

Wants who compromised? What are they going to do against people who use no pseudonym and never originate from the same machine or the same physical location?

Post reply on HN