Live data from Hacker News

LulzSec indictment published

scribd.com

41–50 of 70 posts

Re: LulzSec indictment published

#41
post #28

Ugh. Not downloadable (unless you want to download each page individually by saving it as an image), and it keeps giving me one of those shaking "Congratulations! You have WON!" banners. Here's a site with these indictments as downloadable PDFs and without the annoying shaking ad: http://publicintelligence.net/lulzsec-indictments/

no ads, change doc to fullscreen in the url: http://www.scribd.com/fullscreen/84156085/

Re: LulzSec indictment published

#42
post #41
post #28

Ugh. Not downloadable (unless you want to download each page individually by saving it as an image), and it keeps giving me one of those shaking "Congratulations! You have WON!" banners. Here's a site with these indictments as downloadable PDFs and without the annoying shaking ad: http://publicintelligence.net/lulzsec-indictments/

no ads, change doc to fullscreen in the url: http://www.scribd.com/fullscreen/84156085/

and here's link to pdf http://www.mediafire.com/?9264mdslw3sm630

Re: LulzSec indictment published

#43
post #9

They didn't get him via TOR. If you start reading on page 26, it states that Jeremy hammond revealed personal info to the confidential witness (CW-1). It was this personal info he shared that was used to identify Hammond as the suspect.

It's interesting because the FBI was in a perfect position to perform the most well-known attack on Tor: a correlation / timing attack. "If your adversary can watch both ends of the connection, you lose." They could watch his end and probably knew where the chat server was located. If it was located in the US, it would have been pretty straightforward to send an agent / install a device at the data center and watch the traffic on both ends. Even if the server was in another country, it would be slightly more complicated to set up, but I'm sure local law enforcement would cooperate.

Despite all that, their "correlation attack" was distinctly low-tech. They watched the traffic leaving his residence and confirmed with a confidential informant logged into the chat server that he was online. It just shows that despite all the paranoia of the crypto-nerd crowd, even the second most sophisticated government agency in the world (perhaps after the NSA), pursuing a high value target, still can't or doesn't want to perform those kinds of attacks (maybe because they aren't reliable enough to hold up in a court of law).

And the CCC was claiming that they could fingerprint encrypted connections with 40% reliability. That's so far from being an effective real-world attack by even the most sophisticated organizations, that you'd be wasting your time ever worrying about it.

Re: LulzSec indictment published

#44
post #43
post #9

They didn't get him via TOR. If you start reading on page 26, it states that Jeremy hammond revealed personal info to the confidential witness (CW-1). It was this personal info he shared that was used to identify Hammond as the suspect.

It's interesting because the FBI was in a perfect position to perform the most well-known attack on Tor: a correlation / timing attack. "If your adversary can watch both ends of the connection, you lose." They could watch his end and probably knew where the chat server was located. If it was located in the US, it would have been pretty straightforward to send an agent / install a device at the data center and watch t…

[deleted]

Re: LulzSec indictment published

#45
post #43
post #9

They didn't get him via TOR. If you start reading on page 26, it states that Jeremy hammond revealed personal info to the confidential witness (CW-1). It was this personal info he shared that was used to identify Hammond as the suspect.

It's interesting because the FBI was in a perfect position to perform the most well-known attack on Tor: a correlation / timing attack. "If your adversary can watch both ends of the connection, you lose." They could watch his end and probably knew where the chat server was located. If it was located in the US, it would have been pretty straightforward to send an agent / install a device at the data center and watch t…

I'm not sure what's wrong with the low-tech solution. Why is a sniffer preferable to an informant? Don't go with the high-tech option just because it's high-tech.

I think Hollywood and perhaps even our own fascination with technology misleads us, blinding our eyes to what has been proven to be simple and effective time and time again.

Re: LulzSec indictment published

#46
post #43
post #9

They didn't get him via TOR. If you start reading on page 26, it states that Jeremy hammond revealed personal info to the confidential witness (CW-1). It was this personal info he shared that was used to identify Hammond as the suspect.

It's interesting because the FBI was in a perfect position to perform the most well-known attack on Tor: a correlation / timing attack. "If your adversary can watch both ends of the connection, you lose." They could watch his end and probably knew where the chat server was located. If it was located in the US, it would have been pretty straightforward to send an agent / install a device at the data center and watch t…

http://xkcd.com/538/

Re: LulzSec indictment published

#47
post #2

see page 31: "...An FBI TOR network expert analyzed the data from the Pen/Trap and was able to determine that a significant portion of the traffic from the CHICAGO RESIDENCE to the Internet was TOR-related traffic..." Guess they did not want to provide too much info on that - otherwise they would have had to acknowledge that they are actually screening all traffic with deep inspection.

The FBI has TOR network experts? Hmm. I wonder if they use it themselves?

What's so surprising in that? FBI can probably hire an expert in any existing technology. I'm sure they have very smart people working for them, and if they need they can always use outside consultants. I'd be pretty surprised and disappointed if they didn't have some experts with knowledge in everything that pertains to internet security, cracking, etc. There's a whole industry about that, for years now, so why not?

Re: LulzSec indictment published

#48
post #20

This was all detailed by Ars Technica a couple of days ago: http://arstechnica.com/tech-policy/news/2012/03/stakeout-how...

Compare the photo of him from Ars Technica to this one from 2007: http://www.chicagomag.com/Chicago-Magazine/July-2007/The-Hac... Reading through the indictment it becomes clear that he outed himself through many statements that narrowed down his identity. Not too smart.

As Reiser case showed, some very smart people think that they are so smart as to get away with anything, but in practice they're just humans like everybody else, and will eventually make a mistake that takes them down.

Re: LulzSec indictment published

#49
post #47

Earlier quoted context omitted.

The FBI has TOR network experts? Hmm. I wonder if they use it themselves?

What's so surprising in that? FBI can probably hire an expert in any existing technology. I'm sure they have very smart people working for them, and if they need they can always use outside consultants. I'd be pretty surprised and disappointed if they didn't have some experts with knowledge in everything that pertains to internet security, cracking, etc. There's a whole industry about that, for years now, so why not?

I guess what I'm saying is, it makes it sound like they have a guy on staff (not contracted) whose whole job is to be the TOR expert. I just wasn't expecting TOR would be that important.

Re: LulzSec indictment published

#50
post #37
post #33

Earlier quoted context omitted.

If you're monitoring the encrypted wireless traffic of a wifi router without busting the encryption, then what good are IP addresses? Do you even see IP addresses if the traffic is encrypted. Wouldn't you just see MAC addresses? And even if you did "see" IP addresses, wouldn't you just see the wireless client and the router's IP addresses?

correct, you would not see IP header, if you were snooping encrypted wireless traffic. But thats not really what was described.. They describe a "wireless router monitoring device"...however I don't think think they mean "wireless router", but wireless "router". My guess, this is a physical 'wired' device, attached to, or installed in a router, that transmits data to nearby monitoring (FBI)agent 'wirelessly'. This is…

Right. If you're the FBI and you have a warrant, you have access to the cable or wire coming out of the house and also to the ISP. There's no reason why you'd need to bother decrypting the transmissions between the user's computer and his wireless router. Although I've also read about the possibility that WPA wireless encryption can be cracked.
Post reply on HN