Live data from Hacker News

Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

thestranger.com

211–220 of 236 posts

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#211
post #64

Earlier quoted context omitted.

Right. This is somewhat the point of the oppositional trial system; we can't expect a biased party to bring up all facts relevant to the case, so we bring in someone else with the opposite bias to give the judge the rest of the facts. In these expedited judicial-request hearings, there isn't an explicit defendant, so there's no oppositional counsel to bring in. Maybe we need to bring back the concept of a "devil's ad…

prosecutors have a duty to 'justice' not simply to deliver the strongest result against the defendant. This is why they have to disclose information that suggests innocence.

Brady violations are taken very seriously:

http://www.nytimes.com/2014/01/05/opinion/sunday/rampant-pro...

http://www.prosecutorintegrity.org/wp-content/uploads/Epidem...

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#212
post #207
post #197

Earlier quoted context omitted.

So that they don't need to obtain a copy of the image in the first place? Also a much lesser crime if they get caught.

Bob is found with a file of pseudo random data that matches a hash on the database. There's no evidence of other images of child sexual abuse on his machine; there's no history of sites that distribute images of child sexual abuse; there's no history of the file being opened by Bob; Bob claims that he didn't know the file was there and he doesn't know what it is. How does that benefit an attacker? How does that benef…

I don't know the laws in the US; is the police obligated to respond if someone warns them of this event? (Bob has a file matching a "bad hash".) How seriously - will there be a polite guy knocking on the door, or a SWAT team at 3 am? If nothing is found, and another such event occurs next month, will they have to check again?

People can come up with crazy scenarios for anything :)

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#213

Earlier quoted context omitted.

Apparently, the National Center for Missing and Exploited Children provides ISPs with a hash database of known illegal images [1]. ISPs are then required by statute to notify the government when images with matching hashes cross their network [2]. [1] https://www.law.cornell.edu/uscode/text/18/2258C [2] https://www.law.cornell.edu/uscode/text/18/2258A

I always assumed antivirus venders were given a copy of the list as well. It's a way to scan millions of computers without the owners of those computers knowing they are even being checked. It's perfect. It also begs the question can you get around detection by re-encoding the files so the hashes don't match?

No they are not like md5 hashes. They are likely https://en.m.wikipedia.org/wiki/PhotoDNA hashes.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#214
post #207

Earlier quoted context omitted.

Bob is found with a file of pseudo random data that matches a hash on the database. There's no evidence of other images of child sexual abuse on his machine; there's no history of sites that distribute images of child sexual abuse; there's no history of the file being opened by Bob; Bob claims that he didn't know the file was there and he doesn't know what it is. How does that benefit an attacker? How does that benef…

I don't know the laws in the US; is the police obligated to respond if someone warns them of this event? (Bob has a file matching a "bad hash".) How seriously - will there be a polite guy knocking on the door, or a SWAT team at 3 am? If nothing is found, and another such event occurs next month, will they have to check again? People can come up with crazy scenarios for anything :)

In the USA police are not obligated to do anything really. See https://en.m.wikipedia.org/wiki/Warren_v._District_of_Columb...

>"[t]he duty to provide public services is owed to the public at large, and, absent a special relationship between the police and an individual, no specific legal duty exists."

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#215
post #2

This is probably what I find most worrying about the TOR concept. By running an exit node, you open yourself up to all sorts of legal actions. But if you can't run a TOR exit node as an average citizen, won't all exit nodes end up being run by NSA, GCHQ, and their ilk?

By running an exit node, you open yourself up to all sorts of legal actions

This is not going to be popular here, but IMO this is actually reasonable: you ought to be aware that running an exit node is enabling all kinds of terrible behaviour. You can't just handwash your responsibility away from this.

(No, this is not the same thing as providing encryption software, or general public chat forums etc)

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#216
post #207

Earlier quoted context omitted.

Bob is found with a file of pseudo random data that matches a hash on the database. There's no evidence of other images of child sexual abuse on his machine; there's no history of sites that distribute images of child sexual abuse; there's no history of the file being opened by Bob; Bob claims that he didn't know the file was there and he doesn't know what it is. How does that benefit an attacker? How does that benef…

I don't know the laws in the US; is the police obligated to respond if someone warns them of this event? (Bob has a file matching a "bad hash".) How seriously - will there be a polite guy knocking on the door, or a SWAT team at 3 am? If nothing is found, and another such event occurs next month, will they have to check again? People can come up with crazy scenarios for anything :)

That's not how this works. When a service provider detects a match, they send the file when they report the match. They don't just say "hey, some file matched this hash" and then SWAT kicks down the door, because that would be stupid. They send the file, NCMEC looks at it, and then forwards it to law enforcement who also looks at it. If it's a random file that happens to collide, NCMEC won't send it to law enforcement, and if they did, law enforcement wouldn't act on it.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#217

The warrant is ridiculous even without the tor part. Read pages #6 and #7. http://www.thestranger.com/images/blogimages/2016/04/08/1460... ISPs maintain hash values of known child porn files? Show me a single ISP in the Seattle area that runs any of its residential customer http traffic through a caching proxy that examines and hashes each file, I'll eat my shoe.

Apparently, the National Center for Missing and Exploited Children provides ISPs with a hash database of known illegal images [1]. ISPs are then required by statute to notify the government when images with matching hashes cross their network [2]. [1] https://www.law.cornell.edu/uscode/text/18/2258C [2] https://www.law.cornell.edu/uscode/text/18/2258A

"a poor mans XKeyscore", more or less

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#218
post #216

Earlier quoted context omitted.

I don't know the laws in the US; is the police obligated to respond if someone warns them of this event? (Bob has a file matching a "bad hash".) How seriously - will there be a polite guy knocking on the door, or a SWAT team at 3 am? If nothing is found, and another such event occurs next month, will they have to check again? People can come up with crazy scenarios for anything :)

That's not how this works. When a service provider detects a match, they send the file when they report the match. They don't just say "hey, some file matched this hash" and then SWAT kicks down the door, because that would be stupid. They send the file, NCMEC looks at it, and then forwards it to law enforcement who also looks at it. If it's a random file that happens to collide, NCMEC won't send it to law enforcemen…

Ok, so it's not as open to attack as I thought. Thanks for explaining.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#219
post #23

PSA: "Tor", not "TOR". https://www.torproject.org/docs/faq.html.en#WhyCalledTor "Note: even though it originally came from an acronym, Tor is not spelled “TOR”. Only the first letter is capitalized. In fact, we can usually spot people who haven't read any of our website (and have instead learned everything they know about Tor from news articles) by the fact that they spell it wrong."

That note seems so childish. "We rebranded and if you don't know about it you are just uneducated mongrel on the mercy of media"

If someone speaks as an authority about Tor but never even visited the official site to read the FAQ, they deserve some criticism...

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#220

Earlier quoted context omitted.

An ip address is not good enough to locate someone. If they have evidence beyond an ip address sure raid the house, but if they have no identity evidence beyond an ip address then they need to understand they have no identifying evidence. Per this article yesterday, MaxMind(a geolocation ip service) lists a farm in Kansas (selected because it is roughly the midpoint of the US) as it's unknown location as a result it…

I agree that's a larger issue. However, IP addresses being enough evidence for a search seems somewhat out of scope of the article.

[deleted]
Post reply on HN