Live data from Hacker News

Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

thestranger.com

181–190 of 236 posts

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#181
post #177
post #165

Earlier quoted context omitted.

"This hash is computed such that it is resistant to alterations in the image, including resizing and minor color alterations." ( https://en.wikipedia.org/wiki/PhotoDNA )

which makes collision with the incrimination intent described above much easier.

Deep Neural Nets might solve the problem better than hashes

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#182

Earlier quoted context omitted.

Apparently, the National Center for Missing and Exploited Children provides ISPs with a hash database of known illegal images [1]. ISPs are then required by statute to notify the government when images with matching hashes cross their network [2]. [1] https://www.law.cornell.edu/uscode/text/18/2258C [2] https://www.law.cornell.edu/uscode/text/18/2258A

I always assumed antivirus venders were given a copy of the list as well. It's a way to scan millions of computers without the owners of those computers knowing they are even being checked. It's perfect. It also begs the question can you get around detection by re-encoding the files so the hashes don't match?

[deleted]

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#184
post #177
post #165

Earlier quoted context omitted.

"This hash is computed such that it is resistant to alterations in the image, including resizing and minor color alterations." ( https://en.wikipedia.org/wiki/PhotoDNA )

which makes collision with the incrimination intent described above much easier.

Ugh, this is not how you do crypto. Crypto algorithms have to be understood with regards to what guarantees they provide and in what context. Your approach here is basically ZOMG COLLISIONS ARE BAD when in fact collision-resistance was never a property of this hash function and a collision doesn't provide an attacker with any power they didn't already have.

If an attacker has the power to create a non-CP file that has the same hash as a CP file and plant it without detection, they have the power to plant a CP file without detection. Why would they go to the effort to create a collision with a non-CP file? It's wasted effort.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#185

Earlier quoted context omitted.

Suppose I'm AT&T and one of my customers is running a Tor exit node. Do I now have "immunity from investigation, for illegal activities originating from any IP address associated with them"? I can certainly use a router spoof my customer's IP address for any connections I want to use for illegal activity. Then the IP address will trace back to that customer, which is a Tor exit node, and the police can't investigate…

>Suppose I'm AT&T ISPs have a specific set of statutes that grant them immunity as long as they comply with certain requirements [1]. Individual users do not. [1] https://www.law.cornell.edu/uscode/text/18/2258B

How is it that Tor node operator is not "an electronic communication service provider [or] a remote computing service provider"?

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#186
post #150

Earlier quoted context omitted.

In practice some individuals do have immunity. If this case led the detectives to a local coffee shop do you really think they would have raided the owner's house at 6am and ransacked his home and business searching for something that they knew they were unlikely to find? It's not really that different from running a Tor exit node. The police knew that the traffic was likely coming from another source and that the mo…

The coffee shop owner probably wouldn't be prosecuted, but he would likely still be investigated.

Then why shouldn't AT&T be investigated?

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#187

Here's what I don't understand: You go to a judge for a warrant and the only piece of evidence you have an IP address . How is an IP address even remotely considered "evidence" enough to search someone's home? An IP address is not an identity. It is not a location. It is not even permanent in most cases! I cannot fathom that police are granted warrants to search and seize people's homes and property based solely on,…

> How is an IP address even remotely considered "evidence" enough to search someone's home?

Because it localises a particular network request to a piece of hardware, e.g. a modem, located within that home. In my opinion, in the absence of evidence that someone was running a Tor exit node, or that their wireless network was unprotected, there is a high probability that the network request was originally sent by a device within that home, or by a network user known to the owner.

Regular people aren't like technical people: a lot of them have no idea that their nefarious behaviour can and will be tracked back to their home. I would guess that most warrants granted solely on an IP address actually turn up incriminating evidence.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#188

I'm all for privacy technologies like Tor, but this is one of the risks you assume when you operate an exit node. The alternative would be to give all Tor exit node operators not only legal immunity, but immunity from investigation, for illegal activities originating from any IP address associated with them. Even if the judge and the police were aware of the exit node, it wouldn't have changed the way this was invest…

Suppose I'm AT&T and one of my customers is running a Tor exit node. Do I now have "immunity from investigation, for illegal activities originating from any IP address associated with them"? I can certainly use a router spoof my customer's IP address for any connections I want to use for illegal activity. Then the IP address will trace back to that customer, which is a Tor exit node, and the police can't investigate…

> You're still going to jail when you buy something with a stolen credit card and have it shipped to your house

Imagine me as the friendly neighbourhood trickster living on the same floor as you.

I buy an illegal firearm with a credit card bought over a DNM using Tor and have it mailed to your house.

Enjoy your preordained jailtime.

(you are not your address, IP or postal)

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#189

Earlier quoted context omitted.

Then those facts become part of the investigation. Having your computer searched doesn't mean you at guilty or even that you will be charged. It just means your machine is implicated in a crime.

The unfortunate reality is that if you become a suspect that is good enough to burn you at the stake for much of the population. The same with rape really. Once you've been a suspect or, even worse, accused you are basically screwed.

Those are problems that should be solved directly.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#190

Earlier quoted context omitted.

Most email is spam. Most cash contains traces of drugs. Most BitTorrent content infringes copyright. Is that supposed to justify a raid of anyone who runs a mail server or pays in cash or torrents a Debian ISO? For that matter, given the whole Three Felonies a Day thing, most postal mail is in fact sent by criminals too. There is a reason we have a law against theft and not a law against crowbars.

I don't think those are very good examples. > Most email is spam. ... runs a mail server If your mail server is an open relay and sends a lot of spam, you might expect it to get blocked at a minimum, and possibly to see some legal problems. > Most cash contains traces of drugs. ... pays in cash If you run an ATM and the money you put out has a higher proportion of drugs on it than the average currency, you might expe…

> If your mail server is an open relay and sends a lot of spam, you might expect it to get blocked at a minimum, and possibly to see some legal problems.

But it isn't an open relay. It's just a normal mail server. It's cash with the typical trace amount of drugs on it. That's the whole point -- just because a lot of X is bad and you did X that doesn't mean that you did something bad. It's even possible, as is the case for Tor, that percent-of-thing and percent-of-people-who-do-thing have completely different numbers, because it's possible for a small number of bad actors to generate a disproportionately large amount of traffic.

> This isn't even hard to disambiguate like the others. Is the torrent being downloaded/served infringing in some manner? If it's not, you're fine, if it is, you might have a problem. BitTorrent isn't a single system, it's bunch of loose networks.

That's the point. "Is using BitTorrent" is not a useful metric for badness because the false positive rate is extremely high. If you sit on my internet connection and see me download encrypted data via BitTorrent, you don't know if it's a legal copy of Debian Testing or a pirated copy of Windows 7. Which means you should have to do more work before you can send a fracking SWAT team to my house.

Post reply on HN