Live data from Hacker News

LulzSec indictment published

scribd.com

31–40 of 70 posts

Re: LulzSec indictment published

#31
post #25

The indictment says they used a pen/trap device to monitor the wirless traffic. Does that mean they busted the encryption? I'm not saying that's a shock, it would seem more likely that they would monitor the traffic from the ISP's end rather than monitoring the wireless traffic.

No, they wouldn't have looked at anything that was encrypted. A "pen/trap" means they didn't examine the contents of the traffic at all, only where it was sent to (IP address). The term dates back to the old days of telephony -- a pen register would record dots for every digit dialed on a rotary dial (e.g., 8 dots if you dialed "8"). This would only allow the police to determine what phone numbers you dialed. There is another type of warrant that allows you to actually eavesdrop on the conversation; that type of warrant was apparently not used in this case.

For more information on how the laws relating to phone tapping are interpreted for the internet, see: https://en.wikipedia.org/wiki/Pen_register

Re: LulzSec indictment published

#32
post #25

The indictment says they used a pen/trap device to monitor the wirless traffic. Does that mean they busted the encryption? I'm not saying that's a shock, it would seem more likely that they would monitor the traffic from the ISP's end rather than monitoring the wireless traffic.

[deleted]

Re: LulzSec indictment published

#33
post #25

The indictment says they used a pen/trap device to monitor the wirless traffic. Does that mean they busted the encryption? I'm not saying that's a shock, it would seem more likely that they would monitor the traffic from the ISP's end rather than monitoring the wireless traffic.

No, they wouldn't have looked at anything that was encrypted. A "pen/trap" means they didn't examine the contents of the traffic at all, only where it was sent to (IP address). The term dates back to the old days of telephony -- a pen register would record dots for every digit dialed on a rotary dial (e.g., 8 dots if you dialed "8"). This would only allow the police to determine what phone numbers you dialed. There i…

If you're monitoring the encrypted wireless traffic of a wifi router without busting the encryption, then what good are IP addresses? Do you even see IP addresses if the traffic is encrypted. Wouldn't you just see MAC addresses? And even if you did "see" IP addresses, wouldn't you just see the wireless client and the router's IP addresses?

Re: LulzSec indictment published

#34
post #32
post #25

The indictment says they used a pen/trap device to monitor the wirless traffic. Does that mean they busted the encryption? I'm not saying that's a shock, it would seem more likely that they would monitor the traffic from the ISP's end rather than monitoring the wireless traffic.

[deleted]

[deleted]

Re: LulzSec indictment published

#35
post #19

I think this is actually a pretty strong endorsement of TOR, just based on what I briefly read here. They had a wiretap running, and all they got out of it was "he's definitely using TOR." That's pretty awesome, if you ask me.

Did you read the indictment? They got it specifically by matching TOR traffic to his online-activity patterns. Obviously they matched perfectly. IMHO this was a weak proof, but still is totally unacceptable for a secure network not to hide traffic patterns.

I have some serious doubts about the validity of this claim. While the its possible in proofs of concept, I reserve judgement until they can prove it in a court of law.

Re: LulzSec indictment published

#36
post #19

I think this is actually a pretty strong endorsement of TOR, just based on what I briefly read here. They had a wiretap running, and all they got out of it was "he's definitely using TOR." That's pretty awesome, if you ask me.

Did you read the indictment? They got it specifically by matching TOR traffic to his online-activity patterns. Obviously they matched perfectly. IMHO this was a weak proof, but still is totally unacceptable for a secure network not to hide traffic patterns.

To cite the first Tor research paper: https://svn.torproject.org/svn/projects/design-paper/tor-des...

Not secure against end-to-end attacks: Tor does not claim to completely solve end-to-end timing or intersection attacks. Some approaches, such as having users run their own onion routers, may help; see Section 9 for more discussion.

They are repeating it several times in their documentation, too.

It's not really a bug - there is little that can be done here, IMO.

Re: LulzSec indictment published

#37
post #33

Earlier quoted context omitted.

No, they wouldn't have looked at anything that was encrypted. A "pen/trap" means they didn't examine the contents of the traffic at all, only where it was sent to (IP address). The term dates back to the old days of telephony -- a pen register would record dots for every digit dialed on a rotary dial (e.g., 8 dots if you dialed "8"). This would only allow the police to determine what phone numbers you dialed. There i…

If you're monitoring the encrypted wireless traffic of a wifi router without busting the encryption, then what good are IP addresses? Do you even see IP addresses if the traffic is encrypted. Wouldn't you just see MAC addresses? And even if you did "see" IP addresses, wouldn't you just see the wireless client and the router's IP addresses?

correct, you would not see IP header, if you were snooping encrypted wireless traffic. But thats not really what was described.. They describe a "wireless router monitoring device"...however I don't think think they mean "wireless router", but wireless "router". My guess, this is a physical 'wired' device, attached to, or installed in a router, that transmits data to nearby monitoring (FBI)agent 'wirelessly'. This is why they can see IP (wired, so no encryption), but can't see anything else (tor).

Re: LulzSec indictment published

#38
post #8

I think this is actually a pretty strong endorsement of TOR, just based on what I briefly read here. They had a wiretap running, and all they got out of it was "he's definitely using TOR." That's pretty awesome, if you ask me.

Actually the wiretap only permitted them to see IP addresses not packet contents.

Packet contents wouldn't have helped, due to multiple layers of encryption.

Re: LulzSec indictment published

#39
post #19

I think this is actually a pretty strong endorsement of TOR, just based on what I briefly read here. They had a wiretap running, and all they got out of it was "he's definitely using TOR." That's pretty awesome, if you ask me.

Did you read the indictment? They got it specifically by matching TOR traffic to his online-activity patterns. Obviously they matched perfectly. IMHO this was a weak proof, but still is totally unacceptable for a secure network not to hide traffic patterns.

Once the FBI has a surveillance van parked outside your house, I think you already lost. I don't think there's much you can realistically do.

Re: LulzSec indictment published

#40

Earlier quoted context omitted.

Haha, I got fooled by the by fact it's a scanned document + the ascii art in the corner. Well, I guess they're still using computers as if they were just typewriters...

They have a policy of printing & scanning documents for archival purposes. It also seems they have a policy of using Courier, which is probably a carry-over from the days of paper records. It isn't the most readable font ever, but it is surely one of the most legible- a good thing for documents meant for preservation.

Lots of courts have very specific rules about the format of documents. I think it's at least partly to keep lawyers from playing schoolboy-style shenanigans like making lengthy documents seem short or vice versa.
Post reply on HN