Live data from Hacker News

LulzSec indictment published

scribd.com

11–20 of 70 posts

Re: LulzSec indictment published

#11
This is why privacy is such a Hard problem: damn near everything you do leaks information. If I post anonymously somewhere, my choice of words would narrow down who I am. If I mention that I live in San Francisco, that immediately excludes all the people who live somewhere else and aren't lying. As I browse through web sites, I leave a trail across a bunch of sites' access logs that could all be pieced together and linked to my IP address. (I've got my browser set to block those social tracking buttons, but still information leaks out.) The same thing applies to the physical world (e.g. every printer has its own distinguishing quirks if you inspect the printed output); the only difference is that the internet makes it a lot easier to snoop on people in bulk.

Re: LulzSec indictment published

#13
post #6

Wait... This is 2012 and they wrote this document on a typewriter ? Why? Performance of the typist? Security concerns?

It's Courier, not an actual typewriter.

Haha, I got fooled by the by fact it's a scanned document + the ascii art in the corner.

Well, I guess they're still using computers as if they were just typewriters...

Re: LulzSec indictment published

#14

I think this is actually a pretty strong endorsement of TOR, just based on what I briefly read here. They had a wiretap running, and all they got out of it was "he's definitely using TOR." That's pretty awesome, if you ask me.

the case was mainly built by correlating internet activity timing...WITH an informant on the other end.

Re: LulzSec indictment published

#15
post #11

This is why privacy is such a Hard problem: damn near everything you do leaks information. If I post anonymously somewhere, my choice of words would narrow down who I am. If I mention that I live in San Francisco, that immediately excludes all the people who live somewhere else and aren't lying. As I browse through web sites, I leave a trail across a bunch of sites' access logs that could all be pieced together and l…

yeah and if like nobody uses TOR and you do...then you're even more identifiable

Re: LulzSec indictment published

#16
post #3
post #2

see page 31: "...An FBI TOR network expert analyzed the data from the Pen/Trap and was able to determine that a significant portion of the traffic from the CHICAGO RESIDENCE to the Internet was TOR-related traffic..." Guess they did not want to provide too much info on that - otherwise they would have had to acknowledge that they are actually screening all traffic with deep inspection.

I don't know what you mean by "all traffic"; on the previous page it says the FBI installed some kind of device to capture the suspect's traffic, which is hardly a controversial practice.

Well, this is now called lawful inspection.

The deeper meaning of this is that all I-Net traffic can / is inspected through special interfaces at the ISPs (that could of course also be on the edge of the networks) and all (larger) ISPs have to make those available 24/7 without knowing who's accessing them. Generally speaking I guess it might be better to say that all traffic taking certain routes (I certainly don't want to explain this) or using / showing certain patterns will automatically be inspected.

From a logical point of view you will have to look into everything if you do not know what you're searching for and identify the unusual or some "patterns" you already know...

The general approaches used here are similar to IDS solutions and generally HW based / speed enhanced solutions are used for that (magnitudes faster than software only).

Keywords on that - if you want to find out more - are Deep Packet Inspection, lawful inspection and interception, network neutrality, PCRF etc.

There is a whole industry providing these services / solutions (to the TelComs and government agencies) and their biggest players are all based in the U.S.

Re: LulzSec indictment published

#17
post #16
post #3

Earlier quoted context omitted.

I don't know what you mean by "all traffic"; on the previous page it says the FBI installed some kind of device to capture the suspect's traffic, which is hardly a controversial practice.

Well, this is now called lawful inspection. The deeper meaning of this is that all I-Net traffic can / is inspected through special interfaces at the ISPs (that could of course also be on the edge of the networks) and all (larger) ISPs have to make those available 24/7 without knowing who's accessing them. Generally speaking I guess it might be better to say that all traffic taking certain routes (I certainly don't w…

Yeah, we know about CALEA and ECHELON, but there's no evidence that they were used in this case so I don't know why you're bringing it up. It sounds like conspiracy-mongering.

Re: LulzSec indictment published

#18
post #11

This is why privacy is such a Hard problem: damn near everything you do leaks information. If I post anonymously somewhere, my choice of words would narrow down who I am. If I mention that I live in San Francisco, that immediately excludes all the people who live somewhere else and aren't lying. As I browse through web sites, I leave a trail across a bunch of sites' access logs that could all be pieced together and l…

To mask your diction somewhat, you could use a translation service to go from English to, e.g., Chinese, and then back, fixing gross semantic errors as necessary.

Re: LulzSec indictment published

#19

I think this is actually a pretty strong endorsement of TOR, just based on what I briefly read here. They had a wiretap running, and all they got out of it was "he's definitely using TOR." That's pretty awesome, if you ask me.

Did you read the indictment? They got it specifically by matching TOR traffic to his online-activity patterns. Obviously they matched perfectly. IMHO this was a weak proof, but still is totally unacceptable for a secure network not to hide traffic patterns.

Re: LulzSec indictment published

#20

This was all detailed by Ars Technica a couple of days ago: http://arstechnica.com/tech-policy/news/2012/03/stakeout-how...

Compare the photo of him from Ars Technica to this one from 2007: http://www.chicagomag.com/Chicago-Magazine/July-2007/The-Hac...

Reading through the indictment it becomes clear that he outed himself through many statements that narrowed down his identity. Not too smart.

Post reply on HN