Live data from Hacker News

Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

thestranger.com

231–236 of 236 posts

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#231

Earlier quoted context omitted.

> It's your own usage only if you're the only user, which is an invalid assumption even before Tor. People aren't shy about sharing wifi with house guests. Tor takes it from "could be any of 25 people" to "could be any of 7 billion people." > But even regardless of that, why should the expected result of offering a service to the general public put you under suspicion? Because the police have an obligation to investi…

> Because the police have an obligation to investigate. By mixing personal usage with the Tor traffic, you've muddied the source of the offending traffic, and given them something they can investigate, even if just to remove a suspect. The whole issue is that it doesn't give them someone they can investigate. There is no more reason to suspect the exit node operator any more than anyone else. Investigating people eff…

> There is no more reason to suspect the exit node operator any more than anyone else.

It's not that they are suspected more, it's that they are a lead that can be followed on. If everyone that used that Tor exit node where known, the Police would be faced with a different problem, too many leads to follow up on, too little manpower to do so, and not enough info to differentiate one suspect from another. In this case there is enough info to differentiate one suspect from another in that one suspect is known.

> It's the same result you get as a Tor client rather than an exit node and the same result you get when using public wifi at a coffee house or anywhere else.

No, it's the same as someone running a wifi at their home. The scale is larger, but one thing we can assume with a fairly high degree use correctness is that the connection is also used by the people that live there, which is not something we can assume about a business, as nobody lives there.

To be clear, I think running an open WiFi or a Tor exit node is adequate defense against prosecution (barring further evidence), but not against investigation, and that investigation may warrant a raid, depending on circumstances. I would like to see those circumstances tightened significantly with corroborating evidence (such as repeated logging of activity and during times the suspect is known to be on premises, etc), but I don't believe discounting the information that the traffic went through the suspect's connection just because they allow public use is ultimately beneficial.

> I'm not convinced that the severity of a crime should change the standard for probable cause

I'm not saying it should affect the standard beyond not removing it as a factor. That the suspect is linked (not necessarily in culpability) in some small way to the crime through this information should not be ignored simply because of probability if it's the only evidence you have. It should be weighed appropriately though, and in almost all cases that will be that it's a red-herring.

> Any justification to raid the location of the exit node would apply equally to any other place that could have used the exit node.

Except that "any other place" may not have a concrete link to the crime, while this one does, even if it ends up only being as a conduit. Should someone previously convicted of child molestation that's a Tor exit node operator and happens to have the IP address associated with some child pornography not be looked at simple because of the Tor exit node? My assertion is that they should be given the extra scrutiny that the traffic has warranted; that we shouldn't stop a cursory investigation due to finding early on that they allow public access to their network. It's entirely possible that the evidence will end up being coincidental and the person is not related to the crime in any way, but should these leads be ignored entirely? I don't think so.

> This doesn't really apply to almost anything that could be done via the internet.

Sure it does. Plenty of businesses log all sorts of information. For example, was that email being investigated sent through the company mail server originally received from your workstation, someone else's, or some external IP? Would someone else notice and report some weird data loss on the mail server if they noticed it and were asked?

> Which obviously doesn't apply when the leaders could be the ones engaged in the criminal activity,

Which I specifically noted.

> and how are you supposed to know?

You make a call based on the situation and try to justify it to a judge? Is someone scamming someone else for $5k likely to be the CEO of a milti-million dollar company? Is a murder linked to the company but only really likely for a small subset of the employee base that doesn't include management likely to have management cover for them? Alternatively, if it has to do with bonuses, profits, mergers, stock, etc, maybe it is likely it may go to the top, so you take appropriate steps.

> I don't understand why you think this mixing together of traffic is supposed to change anything.

It provides a lead to an individual where none existed previously. As a single piece of evidence it's not obviously anything more than coincidental, but combined with further information may yield compelling enough evidence to investigate further, whether the person is ultimately responsible for the crime or not. I think the cases where the evidence is compelling based on further information are likely more often to yield useful investigation that otherwise, if done responsibly.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#232
post #150

Earlier quoted context omitted.

In practice some individuals do have immunity. If this case led the detectives to a local coffee shop do you really think they would have raided the owner's house at 6am and ransacked his home and business searching for something that they knew they were unlikely to find? It's not really that different from running a Tor exit node. The police knew that the traffic was likely coming from another source and that the mo…

The coffee shop owner probably wouldn't be prosecuted, but he would likely still be investigated.

Yes, up until it comes to light that there is very little reason to believe that the owner is guilty. More importantly though they wouldn't handcuff him and trash his business when there's clearly no probable cause to do so.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#233

Earlier quoted context omitted.

> Because the police have an obligation to investigate. By mixing personal usage with the Tor traffic, you've muddied the source of the offending traffic, and given them something they can investigate, even if just to remove a suspect. The whole issue is that it doesn't give them someone they can investigate. There is no more reason to suspect the exit node operator any more than anyone else. Investigating people eff…

> There is no more reason to suspect the exit node operator any more than anyone else. It's not that they are suspected more, it's that they are a lead that can be followed on. If everyone that used that Tor exit node where known, the Police would be faced with a different problem, too many leads to follow up on, too little manpower to do so, and not enough info to differentiate one suspect from another. In this case…

> It's not that they are suspected more, it's that they are a lead that can be followed on.

If they're not suspected more then it isn't a lead.

> If everyone that used that Tor exit node where known, the Police would be faced with a different problem, too many leads to follow up on, too little manpower to do so, and not enough info to differentiate one suspect from another.

Which is exactly the same problem they have when most of the users are unknown. The probability that it was any given person depends on how many other people there are, not how many of the other people you know the names of. When the way you got the one name provides no additional reason for suspicion over any of the others, investigating that one person is the same waste of resources as having the full list of thousands of users and then choosing one to investigate at random.

> In this case there is enough info to differentiate one suspect from another in that one suspect is known.

Being known doesn't differentiate a suspect from the others in terms of suspicion. It's like knowing somehow what town the suspect is in and then, because the investigating officer already knows the name of someone in that town, deciding to raid that person. Waste of police resources and undue harassment of someone who is with 99.995% probability not the offender.

> No, it's the same as someone running a wifi at their home.

That's not what I mean.

Your objection to not raiding the exit node operator is that otherwise someone who doesn't want the police to associate their internet activity with their IP address could put up an exit node. But people can already achieve the same effect by using somebody else's exit node or by using the wifi at a coffee house or a VPN service or any of a hundred other ways. There is no additional criminal advantage to be had by running an exit node.

> The scale is larger, but one thing we can assume with a fairly high degree use correctness is that the connection is also used by the people that live there, which is not something we can assume about a business, as nobody lives there.

So the internet connection in a business can be used by the people who work there instead of the people who live there, because people work in businesses and live in homes. What conclusion is that supposed to reach?

Also, many people have a work VPN account that causes their home internet traffic to go through their work internet connection, so the premise is incorrect.

> I would like to see those circumstances tightened significantly with corroborating evidence (such as repeated logging of activity and during times the suspect is known to be on premises, etc), but I don't believe discounting the information that the traffic went through the suspect's connection just because they allow public use is ultimately beneficial.

It's not a matter of discounting it, it's a matter of accurately calculating its evidentiary value. For the IP address of an exit node that value is very close to zero. The probability that some malicious traffic seen from that IP address came from the exit node rather than the occupants is not 100.0000% but is well in excess of 99%.

So yes, if you have a large pile of other evidence that the occupants are the perpetrators, knowing that it was their IP address will add another thousandth of a percent or so to the probability that it was them. But it isn't anything more than that. And it specifically shouldn't be enough to justify a warrant when it's the only thing you have.

> Should someone previously convicted of child molestation that's a Tor exit node operator and happens to have the IP address associated with some child pornography not be looked at simple because of the Tor exit node?

You're asking the question backwards. Knowing that it was the IP address of an exit node tells you nearly nothing. You don't then discount the operators, you just don't count them any more than you would have otherwise. Investigate as if you didn't know the IP address (because with extremely high probability you don't). If the same exit node operators were actually the perpetrators then the evidence will lead back to them regardless and operating an exit node would only explain the IP address but not any of the rest of it.

> That the suspect is linked (not necessarily in culpability) in some small way to the crime through this information should not be ignored simply because of probability if it's the only evidence you have.

Probability is exactly why it should be ignored. You're just advocating the law enforcement edition of "something must be done, this is something, therefore we must do this."

Doing nothing is better than doing something harmful, wasteful and unproductive.

> Sure it does. Plenty of businesses log all sorts of information.

Your original argument was that people at work would see you doing bad things. Now it's that there will be computer logs. But now the set of people who can "get away with it" expands to include the IT staff. And what logs are you expected to have tying a perpetrator to a personal device on a public guest network?

> Which I specifically noted.

But didn't really address. Granted there are some crimes that are less likely to be committed by corporate executives, but what about all the others? I'm not aware of any reason why executives would be any differently predisposed to child pornography than the population at large. Are you saying the police should raid AT&T every time they're investigating child pornography?

> As a single piece of evidence it's not obviously anything more than coincidental, but combined with further information may yield compelling enough evidence to investigate further, whether the person is ultimately responsible for the crime or not.

The point is that having the IP address of an exit node plus further information has approximately the same value as the further information. You don't ignore further evidence against the same party, you just don't credit the IP address with more than the almost-nothing which it is actually worth.

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#234

Earlier quoted context omitted.

> There is no more reason to suspect the exit node operator any more than anyone else. It's not that they are suspected more, it's that they are a lead that can be followed on. If everyone that used that Tor exit node where known, the Police would be faced with a different problem, too many leads to follow up on, too little manpower to do so, and not enough info to differentiate one suspect from another. In this case…

> It's not that they are suspected more, it's that they are a lead that can be followed on. If they're not suspected more then it isn't a lead. > If everyone that used that Tor exit node where known, the Police would be faced with a different problem, too many leads to follow up on, too little manpower to do so, and not enough info to differentiate one suspect from another. Which is exactly the same problem they have…

> If they're not suspected more then it isn't a lead.

Sure it is. "The thief was a member in the AA meeting held on the 28th, but we don't know which one. We do know one person in that group's name though, so let's follow up on what we can." A lead is anything that can be followed up on. If it can't be followed up on, it's not a lead.

This is getting pretty far into the weeds, so I'm going to try to summarize my position more concisely, and from a different direction. I'm interested in if our stances on this are actually all that different.

My stance: The running of a Tor exit node should not be used to exclude a suspect from an initial look just because the traffic has a statistically much smaller chance of having originated with the suspect (based on percentage of traffic, not number of users). That is, it should not be a "fruit of a poisoned tree" type scenario, where the running of the exit node somehow provides protection, as I think none is warranted.

By running the Tor exit node through your home connection (or in any way that easily tracks back to you), you are associating your identity to that traffic. Not necessarily as the originator, but you are associated. If that association happens to bring attention to you that makes you look like a viable suspect (hopefully from more than just that association!), then that should be followed up on, even if it happens to end up not yielding the correct suspect (you can't know ahead of time). To me, this isn't about Tor, or an open WiFi, but about associating your name in any way in criminal activity, no matter how small, no matter how removed. There is increased risk there purely because you've made yourself more present in the minds of the investigators, and they may see something there to your detriment.

I don't think it's any different than if I walked around handing my business card to every person I saw on the street. If one ends up murdered or arrested, the police may see that and decide to take a look at me. Should I be arrested or raided purely on that criteria? No. But if I'ma lawyer, and there was a lawyer associated with the crime in some way, I might start looking like an interesting suspect. It is very clear to me that I have increased my risk by being very undiscerning of who I hand my cards out to.

My position on this comes from a prior article on the same event, discussed at HN[1], where the raided party said:

Robinson admits it might be safer, legally, to host the Tor relay on rented space from a commercial Internet service to avoid mingling his personal traffic with Tor, but he says he shouldn't have to.

"Why should I be spending extra money?" he asks. "There need to be more Tor exit nodes, more Tor nodes generally, and you don't need to be discouraging people from doing it by intimidating them with bogus criminal complaints," he says.

He doesn't have to, but he also doesn't get to act like his actions are completely removed from reality, and don't have any consequences whatsoever. Clearly they do, and they did, and I think it's unrealistic to think they won't or shouldn't, as that's not how people's minds (and thus investigations) work.

1: http://www.npr.org/sections/alltechconsidered/2016/04/04/472...

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#235
post #219

Earlier quoted context omitted.

That note seems so childish. "We rebranded and if you don't know about it you are just uneducated mongrel on the mercy of media"

If someone speaks as an authority about Tor but never even visited the official site to read the FAQ, they deserve some criticism...

To me "tOr" will always mean "The Onion Router" because that's what it is. No matter how the "toR" people want me to spell their programs name

Re: Judge Who Authorized Police Search of Privacy Activists Wasn't Told About Tor

#236

Earlier quoted context omitted.

I always assumed antivirus venders were given a copy of the list as well. It's a way to scan millions of computers without the owners of those computers knowing they are even being checked. It's perfect. It also begs the question can you get around detection by re-encoding the files so the hashes don't match?

They are. From experience, testing the updates for work. Didn't try mutating the test vector.

In response to OOB questions:

No, it was a short string, not an image. If it was an image, I would have tried various mutations.

Because of this, I assumed at the time, and still do, that it's a simple digest instead of a context aware image description.

And it phoned "home" instead of alerting the user - even the institutional user.

Post reply on HN