Live data from Hacker News

U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

antilop.cc

31–40 of 73 posts

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#31
post #5

Well, fuck. Regardless of the rest, if the government's story changed in a factual way before vs. after the government acquired the Silk Road server ... well, further confirmation that parallel construction is in use and the "foreign tools" are being used in domestic cases. "the account by former Special Agent Tarbell in his Declaration differs in important respects from the government’s June 12, 2013, letter to Icel…

Agreed regarding the usage of parallel construction-- I am sure that somewhere in the government's internal guidelines on when to use parallel construction there is a catchall clause providing exemption for "exigent circumstances" which allows it to be abused domestically for any purpose. This case now reeks of heavy NSA involvement merely passed to the FBI for the actual enforcement side of things. I'm not sure if t…

Why would they incur a massive scandal for one guy they can surveil forever?

If enough doubt is cast, they'll drop this.

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#32

From a legal perspective, why does it matter how the FBI got access to the server or determined it was a Silk Road server? I assume they got a warrant for the server itself, and therefore the evidence found on the server is a candidate for inclusion in the trial.

If they hacked the servers, they've tainted the evidence.

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#33
post #27

Earlier quoted context omitted.

No more than NoScript forks the web.

So if I hack a website what's stopping me from serving javascript with no signature or my own signature?

Ah, key management, the bane of any asymmetric crypto system!

My draft specified TOFU; if a site was previously signed and no signature is attached, don't allow any JS. If the signature doesn't match the key cached in the browser, go full noscript.

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#34

It was pretty obvious that the FBI was lying (or misrepresenting or whatever weasel word you want to use) in their original claims. The real question in my mind, which still remains unanswered, is why? The most optimistic explanation is that they just botched the investigation and then spectacularly confused the prosecution as they were preparing their claims. I'd rather not think too hard about the most pessimistic…

I find it plausible that the NSA, DHS may have assisted. During the same time of the rise of Silkroad we have the NSA in full cowboy mode. A reading of the xkeyscorerules100.txt[1] leak shows this, among other things. Looking to Tor as a potential tool for terrorism, if not now than in the future, they would turn to Silkroad as the only interesting target for them to train their teeth on. I just know that if I were in the shoes of a NSA "hacker" dealing with Tor I wouldn't be satisfied with playing war games against internal teams. Hackers are addicts that get their kick best when its public. I would certainly have argued for "better cooperation" with the FBI and DHS for that reason alone.

Anything the NSA does is "secret" so the holes in the FBI arguments, in this scenario, would make sense. An interesting result in this case would be if at any point evidence is not permitted for publication. I wonder if the defence could construct a canary for this possible circumstance.

1: http://daserste.ndr.de/panorama/xkeyscorerules100.txt (note how certain civil liberties are dictated by Geo IP location alone -- that is what I mean by "cowboy mode")

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#35
A tarball is not a disk image and - in my view - is seriously shaky as evidence in a criminal trial.

I had always imagined - apparently incorrectly - that evidence-gathering requirements in this area would have been more along the lines of imaging the disk bit-for-bit in a controlled, well documented procedure onto another disk which is immediately made read-only in hardware before being placed in the chain of custody. Copies provided in legal proceedings should be verifiably identical.

EDIT: Also not only is it insane that they didn't save the sniffed packets but for a one-shot, unreproducible event like the one the FBI describes they really should have preserved the local environment too. Any number of unknown browser/extension/proxy/system behaviours could have caused that captcha to appear on the screen once. Hell, if they only saw it in the viewport and not, say, the DOM source, it could even be a bug in the system graphics renderer - massively unlikely, yes, but I've seen weirder.

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#36

From a legal perspective, why does it matter how the FBI got access to the server or determined it was a Silk Road server? I assume they got a warrant for the server itself, and therefore the evidence found on the server is a candidate for inclusion in the trial.

Yes, there was a warrant, but that warrant must be obtained based on legally obtained information, or else the warrant is invalid as is all information gathered through the execution of that warrant.

Here's an example: Suppose you have drugs in your house, and no one knows that but you. The police may suspect that that's the case, but they need some kind of information that provides probable cause in order to obtain a warrant to search your house.

There are two general categories of ways they could then obtain a warrant: either 1.) they happen to see you carrying drugs or someone else does and reports it or 2.) they break into your house, find drugs, and then request a warrant after the fact to do so.

Now typically option 2 isn't so blatant. More likely is that they break in, find drugs, and then make up some other way that they determined you had drugs. This made up story is called "parallel construction", and it's generally a way to lie and cover up the act of illegally obtained evidence.

If the FBI found the Silk Road IP through an example of scenario 1, then everything's legal. But the FBI's story provides fairly strong indication that scenario 2 is far more likely. If that is the case, then the contents of the server are not admissible in court, nor is anything obtained further down the line from that information.

The result: if scenario 2 is indeed what happened, it doesn't really matter the legality of the actions committed by the defendant were under US law as the authorities have no legal knowledge of said activities. Therefore there is no case, and the defendant must be acquitted.

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#37
post #5

Well, fuck. Regardless of the rest, if the government's story changed in a factual way before vs. after the government acquired the Silk Road server ... well, further confirmation that parallel construction is in use and the "foreign tools" are being used in domestic cases. "the account by former Special Agent Tarbell in his Declaration differs in important respects from the government’s June 12, 2013, letter to Icel…

Agreed regarding the usage of parallel construction-- I am sure that somewhere in the government's internal guidelines on when to use parallel construction there is a catchall clause providing exemption for "exigent circumstances" which allows it to be abused domestically for any purpose. This case now reeks of heavy NSA involvement merely passed to the FBI for the actual enforcement side of things. I'm not sure if t…

> I'm not sure if there's actually an angle here, but it would be extremely interesting if the defendants were able to impeach the FBI's evidence to such a degree so as to force an admittance of parallel construction. It's a no brainer that something fishy happened here.

Tbh, I think that is basically their defense if you read between the lines. This defense reads as basically:

"The FBI's explanation isn't technically possible for how they found the IP address therefore this case should be thrown out as they are lying."

The FBI will never admit to parallel construction. They get enough leeway in their testimony, etc. that they can just say "We agree to disagree on what happened" and no one would question them seriously, from a justice system perspective.

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#38

Earlier quoted context omitted.

I also have an idea to stop the FBI from gaining any meaningful information via Javascript exploits: PGP or Ed25519 sign all .js files and have a browser that only executes signed code. Not only do you need to obtain access to the server, you also need the private key of its operator. (Which should be kept offline for signing.) If they don't surrender the key, then you cannot compromise their visitors. This can also…

That's a cool idea, but it comes with a lot of overhead. Javascript files are one of the most heavily-cached on the web, and by signing them with PGP, you cripple your caching ability. Or am I missing something?

Signing just prevents you from altering the files so you can cache them just fine.

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#39
post #27

Earlier quoted context omitted.

So if I hack a website what's stopping me from serving javascript with no signature or my own signature?

Ah, key management, the bane of any asymmetric crypto system! My draft specified TOFU; if a site was previously signed and no signature is attached, don't allow any JS. If the signature doesn't match the key cached in the browser, go full noscript.

Wouldn't I typically want my Tor Browser to not record any details about sites I have previously visited? Seems like a lot of work for modestly more security.

Re: U.S. v. Ross Ulbricht: Declaration of Joshua J. Horowitz [pdf]

#40

A tarball is not a disk image and - in my view - is seriously shaky as evidence in a criminal trial. I had always imagined - apparently incorrectly - that evidence-gathering requirements in this area would have been more along the lines of imaging the disk bit-for-bit in a controlled, well documented procedure onto another disk which is immediately made read-only in hardware before being placed in the chain of custod…

That was my concern as well. First thing I learned early on was that when you suspect that a server is compromised, or you you just deleted something super critical, is to dd it to an image and then mount it ro for forensics.
Post reply on HN