Live data from Hacker News

Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

thestranger.com

221–230 of 236 posts

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#221
post #70

Earlier quoted context omitted.

Context will do that for you in 99% of the cases, the other 1% is people who are confused for about 15 seconds.

Literally the comment just above you had to specify they meant "Golang" in parentheses. It's a very poor choice of name. I remember when the AlphaGo thing came out on HN and there were some people who clicked because they thought it was about the language.

Yeah that's my comment, I was driving my point home that Golang is dumb.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#222

Earlier quoted context omitted.

I know you're being facetious but seriously... what a way to easily ruin someone's life. This system needs reform.

This is 100% true for anyone in IT could ruin anyone they want to. I am shocked the number of people caught doing this is so low but few people realize the power an IT person has.

I can't even think of how someone could prevent this type of thing. Even if you kept your own access logs it's doubtful a judge would allow you to use it as evidence.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#223
post #55

I never understood the value of a judge authorization requirements for surveillance. Has there ever been a recorded case where the request was denied, except maybe for even more shady reasons? I just don't see any incentive the judge could have to actually make an informed decision instead of just issuing rubber-stamp approval. Even in the unlikely worst case scenario of a scandal of rampant spouse-spying, a simple "…

> Has there ever been a recorded case where the request was denied, except maybe for even more shady reasons? Yes. And most are never reported, since law enforcement will either fix what was wrong with their application, pursue a different line of investigation, or drop the investigation. Perhaps you are thinking of FISA court surveillance requests in the national security arena. Those have been revealed to have an e…

As you correctly guessed, I was arguing about surveillance warrants and not physical searches. So I am to blame not only for being off-topic but also for causing confusion by not even being clear about if.

For physical searches, I agree with all your points. Searches are visible and can be questioned if invalid, so there is incentive for good (or at least acceptable) work on both sides of the warrant application. Besides, physical searches are inherently bottlenecked by manpower, so an artificial quota would not improve anything over unlimited warrantless searches, whereas a warrant requirement certainly does.

In the immaterial world of modern electronic surveillance, important things change (invisibility, no natural upper bound, it having so much more utility for illegitimate use than detectable physical intrusion). I do believe that there, unbounded rubberstamping approval could easily reach a level where a blind artificial quota would be the lesser evil.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#224
post #55

I never understood the value of a judge authorization requirements for surveillance. Has there ever been a recorded case where the request was denied, except maybe for even more shady reasons? I just don't see any incentive the judge could have to actually make an informed decision instead of just issuing rubber-stamp approval. Even in the unlikely worst case scenario of a scandal of rampant spouse-spying, a simple "…

I just don't see any incentive the judge could have to actually make an informed decision Some people pride themselves on doing their jobs as well as they know how.

> Some people pride themselves on doing their jobs as well as they know how.

And others might become good at never crossing paths with those. Subtleties like wether this is possible or not make or break a desirable outcome.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#225
post #70

Earlier quoted context omitted.

Context will do that for you in 99% of the cases, the other 1% is people who are confused for about 15 seconds.

For me, the larger issue is searching! E.g., compare the search results for "Go sequel" and "golang sequel". Golang is far more searchable than the ultra-vague "go". Even if humans can figure out the context, a search engine indexing it cannot.

I would beg to differ, maybe because I have never heard of someone searching 'sequel' instead of 'sql' but I have never had a problem with google or bing or duck duck go giving me what I was looking for by just using 'go'

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#226

Here's what I don't understand: You go to a judge for a warrant and the only piece of evidence you have an IP address . How is an IP address even remotely considered "evidence" enough to search someone's home? An IP address is not an identity. It is not a location. It is not even permanent in most cases! I cannot fathom that police are granted warrants to search and seize people's homes and property based solely on,…

Seriously? They didn't just have an IP address. Police had an IP address and timestamp of a video of child-rape, as provided by 4-chan, said IP address belonging to an ISP as provided by MaxMind, and said ISP confirming its ownership of the IP and providing a subscriber name and address for that IP and timestamp, indicating that the posting originated from a cable modem at a residential location. If you don't find ch…

Solution: rent an empty room and place TOR exit node equipment there. When the police comes, it's just a computer room with no logs or files cached locally. They can do all the searches they want.

Also, TOR should have a blacklist of CP sites to filter out as much of the bad traffic as possible. It doesn't do anyone any good to allow CP on exit nodes. Even if the sites are using https, the exit node could sample a few pages to pass the data into a CP classifier and whitelist/reject the site. This classification work could be aggregated over many exit nodes to maintain an up-to date filter. In the end, if we can assure TOR node hosts that their IPs will not be used for CP, it would ensure more people are willing to offer their resources to the network.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#227

Earlier quoted context omitted.

> If your mail server is an open relay and sends a lot of spam, you might expect it to get blocked at a minimum, and possibly to see some legal problems. But it isn't an open relay. It's just a normal mail server. It's cash with the typical trace amount of drugs on it. That's the whole point -- just because a lot of X is bad and you did X that doesn't mean that you did something bad. It's even possible, as is the cas…

> But it isn't an open relay. It's just a normal mail server. It's cash with the typical trace amount of drugs on it. That's the whole point See, I think the "typical" usage would be your own usage. I don't think the typical person happens to have a certain small percentage of traffic that happens to by child pornography pass through their connection, even if the internet as a whole does. Once you run a Tor exit node…

> See, I think the "typical" usage would be your own usage.

It's your own usage only if you're the only user, which is an invalid assumption even before Tor. People aren't shy about sharing wifi with house guests. Tor takes it from "could be any of 25 people" to "could be any of 7 billion people."

But even regardless of that, why should the expected result of offering a service to the general public put you under suspicion? If you sell sandwiches you're going to end up with cash that has traces of drugs on it, even if you don't use drugs, because some of your customers or some people they transact with do. Everyone who sells sandwiches for cash will end up with population-typical cash in their possession. Which is exactly why having such cash isn't at all suspicious. It's the thing you would expect from an honest person in that situation which means it provides no utility in distinguishing honest people from criminals.

> That doesn't mean every time, but I'm not going to immediately condemn them for looking into a crime.

By what criteria do you propose that they distinguish the times they do from the times they don't, which would reasonably put the case in question in the "do the raid" category?

> I also think how the police handle it has to do with the entity they are interacting with. If it's a multi-person business in good standing, I would expect a subpoena. If it's an individual, it might be a raid, because I think the chance and capability of an individual to destroy evidence is higher.

A large super-majority of individuals work for a business in good standing. Why would they be less likely to destroy evidence at work than at home?

Actually implementing such a rule would also seem to give undue comfort to criminal conspiracies.

Would it not make more sense to issue a warrant only if the crime can be tied to the suspect with something more than an IP address known to be shared by multiple people?

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#229

Earlier quoted context omitted.

> But it isn't an open relay. It's just a normal mail server. It's cash with the typical trace amount of drugs on it. That's the whole point See, I think the "typical" usage would be your own usage. I don't think the typical person happens to have a certain small percentage of traffic that happens to by child pornography pass through their connection, even if the internet as a whole does. Once you run a Tor exit node…

> See, I think the "typical" usage would be your own usage. It's your own usage only if you're the only user, which is an invalid assumption even before Tor. People aren't shy about sharing wifi with house guests. Tor takes it from "could be any of 25 people" to "could be any of 7 billion people." But even regardless of that, why should the expected result of offering a service to the general public put you under sus…

> It's your own usage only if you're the only user, which is an invalid assumption even before Tor. People aren't shy about sharing wifi with house guests. Tor takes it from "could be any of 25 people" to "could be any of 7 billion people."

> But even regardless of that, why should the expected result of offering a service to the general public put you under suspicion?

Because the police have an obligation to investigate. By mixing personal usage with the Tor traffic, you've muddied the source of the offending traffic, and given them something they can investigate, even if just to remove a suspect. Another way to look at this is should I be able to run a Tor exit node and then expect any criminal traffic seen from that connection, even if from me, should not be investigated? Is the mere presence of a Tor exit node enough to deter the investigation? If so, everyone even considering doing anything illegal should run one.

> If you sell sandwiches you're going to end up with cash that has traces of drugs on it, even if you don't use drugs, because some of your customers or some people they transact with do.

I don't think trace drugs is an equitable substitution. We aren't talking about portscans, we are talking about a higher classification of crime, siuch as child pornography (and I would think crime network tracking, murder evidence, etc). If you're selling sandwhiches out of your house, and spending the cash directly (little or none is going to the bank), and a murder is traced back to you from the cash, yeah, the police might raid you, depending on circumstance. You have a good explanation, but that doesn't prevent you from all suspicion.

> By what criteria do you propose that they distinguish the times they do from the times they don't, which would reasonably put the case in question in the "do the raid" category?

First by police discretion (by whether they try to obtain a warrant), and then by the judge involved. If something needs to change, then it's at this level. If that means the vast majority of the times, the person is not investigated, that's probably not only fine, but right. But I don't think a Tor exit node operator is immediately excluded from all suspicion. For example, investigation of an active terror threat. The reward is so high for active seizure of someone involved, and the possible risk so great for not breaking up the network, that a raid on the exit node operator might be worth it even if the likelihood of them being complicit is very small. Whether other crimes meet that criteria is up for debate, but that's why we have judges to mediate that desire with the rights of the people.

> A large super-majority of individuals work for a business in good standing. Why would they be less likely to destroy evidence at work than at home?

There are more people around, it's harder to hide a crime when other people may have witnessed a part of it, even if they didn't know it at the time. The leaders of the business likely would want to help the police and not the criminal (for many reasons, both selfish and altruistic). If you believed the entire business and all employees were complicit in the crime, or that people with little oversight such as the owner were complicit, then a raid might be warranted in that case as well. A single person working as a business would be equivalent to the entire business being complicit, for the purposes of deciding risk of evidence tampering.

> Would it not make more sense to issue a warrant only if the crime can be tied to the suspect with something more than an IP address known to be shared by multiple people?

Preferably, but I'm more arguing that it should not be a reason they can't. There are simple things people can do to prevent this, such as clearly distinguishing your personal traffic from Tor (such as not running it from your home connection). Providing for ambiguity in the source of criminal behavior will lead to ambiguity in the application of resources to investigate that behavior.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#230

Earlier quoted context omitted.

> See, I think the "typical" usage would be your own usage. It's your own usage only if you're the only user, which is an invalid assumption even before Tor. People aren't shy about sharing wifi with house guests. Tor takes it from "could be any of 25 people" to "could be any of 7 billion people." But even regardless of that, why should the expected result of offering a service to the general public put you under sus…

> It's your own usage only if you're the only user, which is an invalid assumption even before Tor. People aren't shy about sharing wifi with house guests. Tor takes it from "could be any of 25 people" to "could be any of 7 billion people." > But even regardless of that, why should the expected result of offering a service to the general public put you under suspicion? Because the police have an obligation to investi…

> Because the police have an obligation to investigate. By mixing personal usage with the Tor traffic, you've muddied the source of the offending traffic, and given them something they can investigate, even if just to remove a suspect.

The whole issue is that it doesn't give them someone they can investigate. There is no more reason to suspect the exit node operator any more than anyone else. Investigating people effectively at random is nothing more than a fishing expedition and a waste of police resources.

> Is the mere presence of a Tor exit node enough to deter the investigation? If so, everyone even considering doing anything illegal should run one.

I'm not sure why this is supposed to be such an unreasonable result. It's the same result you get as a Tor client rather than an exit node and the same result you get when using public wifi at a coffee house or anywhere else. There are a hundred ways to get an IP address that isn't tied to you, why is this one special?

> First by police discretion (by whether they try to obtain a warrant), and then by the judge involved.

That isn't how, that's who. By what criteria are the police or the courts supposed to make the decision?

> For example, investigation of an active terror threat. The reward is so high for active seizure of someone involved, and the possible risk so great for not breaking up the network, that a raid on the exit node operator might be worth it even if the likelihood of them being complicit is very small.

I'm not convinced that the severity of a crime should change the standard for probable cause, but even accepting that premise, the problem is still that the existence of a Tor exit node takes the probability that the traffic originated at any particular place to 1/(population size). Any justification to raid the location of the exit node would apply equally to any other place that could have used the exit node. You're trying to justify the search with an argument that could equally be used to justify a general warrant.

> There are more people around, it's harder to hide a crime when other people may have witnessed a part of it, even if they didn't know it at the time.

This doesn't really apply to almost anything that could be done via the internet. You can see your coworkers carting off toxic waste to be dumped in the river or conducting in person meetings with the victim of a scam. If you see them sitting in their office typing things into a computer, what is that supposed to provide evidence of?

> The leaders of the business likely would want to help the police and not the criminal (for many reasons, both selfish and altruistic).

Which obviously doesn't apply when the leaders could be the ones engaged in the criminal activity, and how are you supposed to know? Even regardless, what are the leaders supposed to do? One of their employees or customers signed into the company guest network with a personal laptop and did some illegal thing. The company has no way to know who it was and no authority to search all their employees' and customers' personal devices, and the device may not even be on company property anymore.

The inability to determine the source of network traffic is clearly a problem for investigators, but it isn't a problem you can reasonably solve by issuing warrants against scads of innocent people. It's a problem you solve by tying the crime to the perpetrator in some way that doesn't apply equally to innocent people.

> Providing for ambiguity in the source of criminal behavior will lead to ambiguity in the application of resources to investigate that behavior.

I don't understand why you think this mixing together of traffic is supposed to change anything. If you pay for both cable internet and DSL and use one for your own activities and the other to operate an exit node then there is a clean separation between your traffic and the traffic of the exit node, but how is that supposed to make any difference? You still control the IP address of the exit node and therefore could still have used it for criminal activity, as could anyone else.

Post reply on HN