Earlier quoted context omitted.
> It's your own usage only if you're the only user, which is an invalid assumption even before Tor. People aren't shy about sharing wifi with house guests. Tor takes it from "could be any of 25 people" to "could be any of 7 billion people." > But even regardless of that, why should the expected result of offering a service to the general public put you under suspicion? Because the police have an obligation to investi…
> Because the police have an obligation to investigate. By mixing personal usage with the Tor traffic, you've muddied the source of the offending traffic, and given them something they can investigate, even if just to remove a suspect. The whole issue is that it doesn't give them someone they can investigate. There is no more reason to suspect the exit node operator any more than anyone else. Investigating people eff…
It's not that they are suspected more, it's that they are a lead that can be followed on. If everyone that used that Tor exit node where known, the Police would be faced with a different problem, too many leads to follow up on, too little manpower to do so, and not enough info to differentiate one suspect from another. In this case there is enough info to differentiate one suspect from another in that one suspect is known.
> It's the same result you get as a Tor client rather than an exit node and the same result you get when using public wifi at a coffee house or anywhere else.
No, it's the same as someone running a wifi at their home. The scale is larger, but one thing we can assume with a fairly high degree use correctness is that the connection is also used by the people that live there, which is not something we can assume about a business, as nobody lives there.
To be clear, I think running an open WiFi or a Tor exit node is adequate defense against prosecution (barring further evidence), but not against investigation, and that investigation may warrant a raid, depending on circumstances. I would like to see those circumstances tightened significantly with corroborating evidence (such as repeated logging of activity and during times the suspect is known to be on premises, etc), but I don't believe discounting the information that the traffic went through the suspect's connection just because they allow public use is ultimately beneficial.
> I'm not convinced that the severity of a crime should change the standard for probable cause
I'm not saying it should affect the standard beyond not removing it as a factor. That the suspect is linked (not necessarily in culpability) in some small way to the crime through this information should not be ignored simply because of probability if it's the only evidence you have. It should be weighed appropriately though, and in almost all cases that will be that it's a red-herring.
> Any justification to raid the location of the exit node would apply equally to any other place that could have used the exit node.
Except that "any other place" may not have a concrete link to the crime, while this one does, even if it ends up only being as a conduit. Should someone previously convicted of child molestation that's a Tor exit node operator and happens to have the IP address associated with some child pornography not be looked at simple because of the Tor exit node? My assertion is that they should be given the extra scrutiny that the traffic has warranted; that we shouldn't stop a cursory investigation due to finding early on that they allow public access to their network. It's entirely possible that the evidence will end up being coincidental and the person is not related to the crime in any way, but should these leads be ignored entirely? I don't think so.
> This doesn't really apply to almost anything that could be done via the internet.
Sure it does. Plenty of businesses log all sorts of information. For example, was that email being investigated sent through the company mail server originally received from your workstation, someone else's, or some external IP? Would someone else notice and report some weird data loss on the mail server if they noticed it and were asked?
> Which obviously doesn't apply when the leaders could be the ones engaged in the criminal activity,
Which I specifically noted.
> and how are you supposed to know?
You make a call based on the situation and try to justify it to a judge? Is someone scamming someone else for $5k likely to be the CEO of a milti-million dollar company? Is a murder linked to the company but only really likely for a small subset of the employee base that doesn't include management likely to have management cover for them? Alternatively, if it has to do with bonuses, profits, mergers, stock, etc, maybe it is likely it may go to the top, so you take appropriate steps.
> I don't understand why you think this mixing together of traffic is supposed to change anything.
It provides a lead to an individual where none existed previously. As a single piece of evidence it's not obviously anything more than coincidental, but combined with further information may yield compelling enough evidence to investigate further, whether the person is ultimately responsible for the crime or not. I think the cases where the evidence is compelling based on further information are likely more often to yield useful investigation that otherwise, if done responsibly.