Live data from Hacker News

How to exploit home routers for anonymity

danmcinerney.org

41–50 of 80 posts

Re: How to exploit home routers for anonymity

#41

It feels like we need to include anonymity in the Internet Bill of Rights: 1. I have a right to read or write public information in an anonymous way. 2. I have a right to prevent you from reading or writing MY private information in an anonymous way, even if the intent is to obtain the right to exercise #1 in the process. 3. Using someone else's infrastructure/compute/power to enable #1 without breaking #2 requires y…

With the advent of cryptocurrencies, we're finally in a place someone can pay me to use a portion of my infrastructure for enabling their anonymity. I'm willing to contribute to the cause as long as it's worth my while. Your infrastructure will immediately be used to download or upload child pornography. If you're exceptionally unlucky, the FBI will come knocking and, if you're unable to provide them with a useful ho…

"I invite the community to toss around ideas about how to protect against this. I hypothesize that it's an unsolvable problem"

I'm not sure if you would count this as a solution, but, conceivably you could "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud ?

This is fast enough for speech. It is not fast enough for any kind of multimedia that would be acceptable in 2014 and beyond. It might be a barrier that would cause all bad guys to use other networks, but still allow the kind of "freedom" that we're all convinced twitter gives us (and so on).

Re: How to exploit home routers for anonymity

#42

Earlier quoted context omitted.

This is, incidentally, the reason why government-resistant anonymity services need to be legal. If you don't care about stealing credit card numbers or hurting people then you don't care about breaking into some poor sucker's router. But if you're blowing the whistle on some organizational malfeasance, you won't, so you need the likes of Tor.

I think that oversimplifies an important point. Criminals may not CARE about breaking into someone's computer or router, but that doesn't mean they're capable of doing so. Tor significantly lowers the bar for anonymity online, and there is no question in my mind that it enables criminals who wouldn't have the means to mask their identities otherwise. This is not necessarily an argument against tools like Tor, but it'…

Criminals are humans. They will use and abuse whatever infrastructure any other person has access to for their own purposes, much like (you guessed it) any other person.

Your argument is about as lazy as it is old. The only possible solutions are to make all criminals go extinct (good luck), or to take away tons of important tools away from the public, because get this, criminals might use them! How terrible.

Re: How to exploit home routers for anonymity

#43

Earlier quoted context omitted.

> unable to prove your innocence Here's the issue. Return presumption of innocence back and problem's solved. Obviously, that's impossible in a real world. > credentials for the anonymous party to use That wouldn't be anonymous anymore. And there's no way to realistically force a single human to have only one credential - if one's banned they'll just generate a new one.

It could be possible to enable someone you trust to use your infrustracture. You don't have to know who this person is. For example, this devconsole HN account that I'm using now is an anonymous HN account, meaning as long as Tor is secure, and I don't reveal myself through e.g. text analysis or timing correlations, it should be hard to figure out who I am. If I were to come to you and ask to use your infrastructure…

> It could be possible to enable someone you trust to use your infrustracture. You don't have to know who this person is.

Am I the only one to whom this sounds absolutely crazy? How can I trust you if I don't know who you are? (I mean the general you, not you personally, devconsole.)

Your comments could have been deliberately sanitized -- perhaps you have trolling accounts elsewhere that you are exceptionally good at keeping separate from this one, and spend time making this one look good. One could be posing as a mild-mannered Python developer here on HN, but be spending one's evenings being Super-Mallory the Malicious, trolling and trading illegal information.

I really want to be able to support things like mesh networks and Tor, but the very risk the GP noted (people will use your resources for Bad Things, and good luck defending from the feds) prevents me from being willing to do so. There's no way I would trust you or someone else that I don't personally know enough to use my resources, unless I were somehow able to keep meticulous logs which exonerate me from any activity they do. (And, I don't trust that such logs would even do that...)

Saying that you should be able to trust a stranger is like saying that you should be able to run a courier service for strangers where you have no idea whether they are transporting drugs or counterfeit money.

Re: How to exploit home routers for anonymity

#45

It feels like we need to include anonymity in the Internet Bill of Rights: 1. I have a right to read or write public information in an anonymous way. 2. I have a right to prevent you from reading or writing MY private information in an anonymous way, even if the intent is to obtain the right to exercise #1 in the process. 3. Using someone else's infrastructure/compute/power to enable #1 without breaking #2 requires y…

With the advent of cryptocurrencies, we're finally in a place someone can pay me to use a portion of my infrastructure for enabling their anonymity. I'm willing to contribute to the cause as long as it's worth my while. Your infrastructure will immediately be used to download or upload child pornography. If you're exceptionally unlucky, the FBI will come knocking and, if you're unable to provide them with a useful ho…

I think our ability to communicate privately as a society at large is more important than the issues of child pornography or terrorism, both of which have policing avenues besides pervasive monitoring and tracking of all associations and messages through communication networks.

But yes, we should think of the children, 9/11, etc.

Re: How to exploit home routers for anonymity

#46
post #41

Earlier quoted context omitted.

With the advent of cryptocurrencies, we're finally in a place someone can pay me to use a portion of my infrastructure for enabling their anonymity. I'm willing to contribute to the cause as long as it's worth my while. Your infrastructure will immediately be used to download or upload child pornography. If you're exceptionally unlucky, the FBI will come knocking and, if you're unable to provide them with a useful ho…

"I invite the community to toss around ideas about how to protect against this. I hypothesize that it's an unsolvable problem" I'm not sure if you would count this as a solution, but, conceivably you could "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud ? This is fast enough for speech. It is not fast enough for any kind of multimedia that would be acceptable in 2014 and beyond. It mi…

Could you "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud?

What a fantastic idea. This seems worth pursuing. It should be possible to configure a modern browser to work with low bandwidth: HTML/CSS/JS would load, but images and other media wouldn't. Is there any reason why HN, Reddit, Twitter, webmail, and other services like IRC wouldn't be usable under those conditions?

It seems like people might be much more willing to rent out their infrastructure to anonymous parties strictly for those purposes.

Re: How to exploit home routers for anonymity

#47
post #15

Earlier quoted context omitted.

> What can be done? Are we reduced to just securing our friends' and families' infrastructure, all the while standing by idly while others outside of our direct sphere of influence suffer the consequences of naïvety? No. We can write articles similar to this one which, instead of clearly explaining step-by-step procedures for exploiting weaknesses, clearly explain step-by-step procedures for REPAIRING weaknesses.

I think you give way too much credit to the average person. It's easy to lose sight of how scary technical things are to normal people when you're in it day in and day out, but to ask the average person to change something in their router is kind of like asking me to replace a cylinder in my car. There's a reason things like the Geek Squad are around and can charge as much as they do...

I agree with Oxdeadbeefbabe; you are complementing your own 'technical' (computer-related) ability, and overstating the task of configuring a router. Also, not to be pedantic, 'to replace a cylinder' hardly describes a task that can be undertaken on a motor.

The variance in technical ability of the 'average person' nowadays is pretty wide. There are still pop-up clicking grandmothers on IE7 out there, but there are also plenty of baby-boomers with the ability to set the clock on their VCR's, which is a much more fair analogy to the task of router configuration.

I think the important thing is getting the message out that such configuration is much more important than having the clock on your VCR right, which is probably how important the average person thinks router configuration is. As you said in another comment, routers are effectively shipping to average people broken. I think if this were more commonly known, people would take the time to learn and configure their networks. Not ALL people, but more average people than do today. The real problem is not that people are not technically capable of doing the task, but they do not know that it is a task that is really necessary; it's not common knowledge that a brand new router is a security risk.

Re: How to exploit home routers for anonymity

#48

Probably worth pointing out that one should remain aware of their local laws when carrying out such activities as the ones outlined in this HOW TO. Because you're blindly hitting hosts and attempting logins, you don't know whose infrastructure you're probing. If you accidentally knock on the wrong door, the simple act of attempting a log in can cause issues for you (legal and otherwise). I'm trying to avoid sounding…

Of course you can ignore all that if you are attacking from Nigeria. Laws are exciting and important (especially good ones like Newton's laws of motion), but laws could improve too: If someone gets caught doing this they probably ought to do community service working on some bug bounty program instead of going to jail.

I love this impression that if you're connecting from , laws don't apply. I'd wager nobody that's ever actually lived anywhere in 3rd world bandies it about.

True, you're less likely to actually be convicted, but the months/years waiting for trail is guaranteed to be worse than your actual sentence elsewhere, if not fatal.

Re: How to exploit home routers for anonymity

#49
post #41

Earlier quoted context omitted.

"I invite the community to toss around ideas about how to protect against this. I hypothesize that it's an unsolvable problem" I'm not sure if you would count this as a solution, but, conceivably you could "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud ? This is fast enough for speech. It is not fast enough for any kind of multimedia that would be acceptable in 2014 and beyond. It mi…

Could you "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud? What a fantastic idea. This seems worth pursuing. It should be possible to configure a modern browser to work with low bandwidth: HTML/CSS/JS would load, but images and other media wouldn't. Is there any reason why HN, Reddit, Twitter, webmail, and other services like IRC wouldn't be usable under those conditions? It seems lik…

I would love to see someone try to use HN at 9600 bps. That's bits per second, so 9600 / 8 = 1200 characters per second, roughly.

Re: How to exploit home routers for anonymity

#50

Earlier quoted context omitted.

Of course you can ignore all that if you are attacking from Nigeria. Laws are exciting and important (especially good ones like Newton's laws of motion), but laws could improve too: If someone gets caught doing this they probably ought to do community service working on some bug bounty program instead of going to jail.

I love this impression that if you're connecting from , laws don't apply. I'd wager nobody that's ever actually lived anywhere in 3rd world bandies it about. True, you're less likely to actually be convicted , but the months/years waiting for trail is guaranteed to be worse than your actual sentence elsewhere, if not fatal.

The parent specifically mentioned Nigeria. Africa is not a country, and his comment may not apply to say, South Africa or Morocco. You're the one generalizing about 3rd world countries, not him.

If you think LLE or even the FBI is going to open the diplomatic channels necessary to pursue someone in Nigeria over access to a consumer-grade router, you're kidding yourself. For all practical purposes, these laws do not in fact apply there.

Post reply on HN