Live data from Hacker News

FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

justice.gov

21–30 of 73 posts

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#21
post #14

Earlier quoted context omitted.

Them not keeping a record may be true... But the rsyslog was delivering the logs to *.fbi.gov And not retaining logs would still be correct. They said nothing about transporting them to the relevant feds.

Ahhh. They aren't keeping the logs, they're merely forwarding the logs to another "non-associated entity" (giving them legal cover), and storing the logs there. Makes sense. They can advertise "we don't keep logs" ( we meaning the corporate entity itself) so they have legal cover, and they make the three letter agencies happy (and thus are allowed to continue to operate)

Indeed. And those tools to do such an analysis already exist. Its the formerly NSA tool called "Apache NiFi". It even has a syslog server plugin specifically for this purpose (it's built in already; drag, drop, configure, done):

https://nifi.apache.org/docs/nifi-docs/components/org.apache...

Link/proof asserting Apache NiFi is one of the NSA data analytics tools: https://www.forbes.com/sites/adrianbridgwater/2015/07/21/nsa...

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#22
post #9

Earlier quoted context omitted.

Bandwidth counting can be accomplished without keeping "logs" per se, and with WireGuard, I think there would be very little reason to attempt to limit connections.

WireGuard is very hard to run without logging. It simply wasn’t designed for that and the maintainer was paid once to write “a rootkit-like” piece of code for a VPN provider which hired him to help them fix that. It’s still an open question afaik edit: I've worded this weird. I was typing on my phone at lunch stuff I'd just learned this morning[0] which referenced this[1] article saying running a log-less Wireguard m…

Your statement is vacant without an explanation of what kind of logging Wireguard requires. Currently, all it does is attempt to scare the user with the word "rootkit".

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#23
Sometimes I feel the anonymity aspect of the Internet brings the worst out of people. If we didn't have anonymity to begin with, people would have not tried those kind of harassment. Or if they do, it'll be a routine case for the police as opposed to requiring substantial FBI involvement.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#24
> On April 14, 2017, at 14: 55: 52, the email address "rlincc@gmail.com" was accessed from IP address 199.38.233.169, an IP address owned by WANSecurity, a Kansas VPN service. As discussed above, this Gmail address is directly attributable to Ryan Lin and was used to communicate directly and openly with Smith and her roommates, including when he first responded to the Craigslist advertisement to be their roommate.

This type of information couldn't be provided by VPN logs due to gmail using TLS encryption. If they gained physic access to a device that he was currently logged into, they just needed to look at the gmail account activity. Anyone can look at all the IP addresses they have accessed their gmail account from. They could have also just got a warrant.

> On April 14, 2017, at 15:06:27, the email address teleportxf@gmail.com, provided by "Ashley Plano" to Rover, was accessed from the same exact WANSecurity IP address, 199.38.233.169

This is more interesting. It doesn't seem likely they caught him logged into this account, or that would be all the evidence they needed. I suspect they issued a warrant to Google for this account and got a list of IP addresses back. I can't imagine that the VPN provider allocated a unique IP addresses for each subscriber. This seems like a really weak correlation unless they are leaving out some important information.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#25

What the guy did was seriously disturbing. He looks like he is going to prison for 17 years and virtually ruined the victim’s lives: https://www.justice.gov/usao-ma/pr/newton-man-sentenced-over...

This dude is a horrible monster and has been one for years. 17 years seems like barely enough.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#26

Sometimes I feel the anonymity aspect of the Internet brings the worst out of people. If we didn't have anonymity to begin with, people would have not tried those kind of harassment. Or if they do, it'll be a routine case for the police as opposed to requiring substantial FBI involvement.

I generally file it under:

This Is Why We Can't Have Nice Things

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#27

Sometimes I feel the anonymity aspect of the Internet brings the worst out of people. If we didn't have anonymity to begin with, people would have not tried those kind of harassment. Or if they do, it'll be a routine case for the police as opposed to requiring substantial FBI involvement.

The other side of that coin is without anonymity only the strongest can truly speak their mind without fear of repercussions.

I’d say, overall, it’s been worth it so far.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#28
post #9

Earlier quoted context omitted.

Bandwidth counting can be accomplished without keeping "logs" per se, and with WireGuard, I think there would be very little reason to attempt to limit connections.

WireGuard is very hard to run without logging. It simply wasn’t designed for that and the maintainer was paid once to write “a rootkit-like” piece of code for a VPN provider which hired him to help them fix that. It’s still an open question afaik edit: I've worded this weird. I was typing on my phone at lunch stuff I'd just learned this morning[0] which referenced this[1] article saying running a log-less Wireguard m…

At least AzireVPN has some claims of not logging Wireguard:

https://www.azirevpn.com/docs/security#blind-operator-mode

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#29

Sometimes I feel the anonymity aspect of the Internet brings the worst out of people. If we didn't have anonymity to begin with, people would have not tried those kind of harassment. Or if they do, it'll be a routine case for the police as opposed to requiring substantial FBI involvement.

don't fool yourself, people have been harassing and exploiting others without issue long before the internet. the difference is that while the internet can extend their reach the very nature of brings such occurrences to light more often than before.

so while the internet broadens their reach it doesn't always give them more anonymity, if anything their trail is easier to follow by more people, especially law enforcement. people just don't understand the depth of a trail they leave when using the net

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#30
post #22
post #9

Earlier quoted context omitted.

WireGuard is very hard to run without logging. It simply wasn’t designed for that and the maintainer was paid once to write “a rootkit-like” piece of code for a VPN provider which hired him to help them fix that. It’s still an open question afaik edit: I've worded this weird. I was typing on my phone at lunch stuff I'd just learned this morning[0] which referenced this[1] article saying running a log-less Wireguard m…

Your statement is vacant without an explanation of what kind of logging Wireguard requires. Currently, all it does is attempt to scare the user with the word "rootkit".

FWIW Jason called it A Defensive Rootkit [0].

But the parent post is wrong, the defensive rootkit is not to prevent logging, it's to prevent extracting the configuration from the kernel. It effectively makes the WireGuard configuration write-only from the perspective of userspace. WireGuard does not do any access logging by default as far as I am aware.

[0]: https://lists.zx2c4.com/pipermail/wireguard/2017-November/00...

Post reply on HN