Live data from Hacker News

Man jailed for parole violations after refusing to decrypt his Tor node

reddit.com

291–300 of 397 posts

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#291
post #252
post #222

Earlier quoted context omitted.

Breaking in in a system, whether or not the password was easy to guess, sounds like a crime to me.

It is a crime! But CFAA charges should, and this is the issue a lot of people have with them afaict, have a sliding scale for premeditation though. If I knock on a door, it swings open, and I walk inside and steal something, then imho there should be a lesser maximum charge for possessing burglary tools than if I show up with a lock gun, crowbar, and concrete saw. A lot of the CFAA excesses are maximum penalties from…

>If I knock on a door, it swings open, and I walk inside and steal something, then imho there should be a lesser maximum charge for possessing burglary tools than if I show up with a lock gun, crowbar, and concrete saw.

Why? (I'm not a lawyer...) - shouldn't intent and harm (i.e. the value of the stolen item) be the only relevant details? Now of course its much easier to demonstrate intent if there's a crowbar involved, but once that's already established, it seems irrelevant.

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#292
post #151

Earlier quoted context omitted.

That shouldn't require a pact, that should be part of the standard check list for ending employment. (The list is longer for those who have root, but it should still be a list.)

For sure, and I’m often the one who makes the list, and one with root. But the big thing is to do it quickly, like within the hour, and diligently. Don’t say, oh, I’ll give him a chance to access his email and download stuff, or whatever. No! Like, cut me off completely right now. Then, if something breaks down the road, there’s no temptation for them to wonder if I had anything to do with that weird failure. (And ob…

I agree with the overall point. (And WTH would you ever have things you need to download in your work email?) But there's not an employer I have ever left that I couldn't have done extensive damage to without any permissions at all. Not that I would ever add a felony charge to even the most bitter firing, but I could.

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#293

Earlier quoted context omitted.

> You can't refuse to submit evidence to court, including things like encryption keys or things only stored in your head - or face penalties including unlimited jail time. This is a bit more complex in the US. We have the fifth amendment to our Constitution which says "nor shall [a person] be compelled in any criminal case to be a witness against himself." So, we can't be made to testify against ourselves. This has s…

Why would breaking the privacy of Tor users be self -incriminating? If anything, surely it's the evidence of innocence - whatever unsavoury websites were visited via the Tor node were Tor users, not this guy.

> surely it's the evidence of innocence

The obligation to provide evidence of self- innocence is equivalent to the obligation to provide evidence of self- guilt. Doesn't one follow logically from the other?

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#294

Earlier quoted context omitted.

Here's what the wife says about that[1], for the record: > The Origins of a Retaliatory Prosecution (Texas, 2019-2022) > Early 2019: Conrad Rockenhaus, a supporter of free speech, runs Tor exit nodes used by journalists and activists. Federal agents demand he assist them in decrypting traffic; he repeatedly refuses, asserting his constitutional rights. > The Coerced Confession: The case against him began when he was…

All that is as may be, but the CFAA charge here isn't pretextual; what he's alleged to have done is pretty serious by any standard. I have no trouble believing that the prosecution was motivated by Tor drama, but all that tells me is that the DOJ had real cards to play, and they played them. My guess is that things would have gone substantially worse for this person had he taken that case to trial.

Having seen the system up close, I hesitate to draw conclusions from cases that don't go to trial. Doesn't really sound like they have the means to afford trial, or at least a chance at a fair one.

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#295
post #222

Earlier quoted context omitted.

Breaking in in a system, whether or not the password was easy to guess, sounds like a crime to me.

It does sound like a crime to me too. But was it a password or other credential that was guessed, or was it just some sequential primary key? The latter is not an authorization system, and I do not believe it a crime to do that unless you have specific knowledge that it is likely to cause damage and/or the intent to cause that damage. As far as I am concerned, I am allowed to send any traffic I wish to public-facing…

You are not allowed unauthorized access regardless of how the key works.

> I am allowed to send any traffic I wish to public-facing hosts

No you're not. Denial of service is a federal crime.

> I have no responsibility to refrain

Yes you do, and this is just beyond silly. The nuance of how you obtained it will be decided in a court. Stop making everything so reductionist and lazy.

> The only traffic I am not permitted to send are credentials I am not authorized to use

Absolutely not. Use of a vulnerability to cause a data breach is OBVIOUSLY a federal crime.

This is beyond absurd.

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#296
post #151

Earlier quoted context omitted.

That shouldn't require a pact, that should be part of the standard check list for ending employment. (The list is longer for those who have root, but it should still be a list.)

For sure, and I’m often the one who makes the list, and one with root. But the big thing is to do it quickly, like within the hour, and diligently. Don’t say, oh, I’ll give him a chance to access his email and download stuff, or whatever. No! Like, cut me off completely right now. Then, if something breaks down the road, there’s no temptation for them to wonder if I had anything to do with that weird failure. (And ob…

Yeah, I usually stress to employers and clients that I want to be cut off quickly, and usually remind them of what they need to lock me out of when I leave.

Even then, I've had clients for whom things have broken come to me in despair hoping I'd kept access. The day one of them for whatever reason decides to suspect that I was the one to break things, I will be very happy to be able to point to consistently having done what I can to ensure I get locked out.

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#297
post #188

Earlier quoted context omitted.

It doesn't matter if you brute forced their crappy login with commonly-used credentials. You think it's OK for someone to rummage around in your garage just because they correctly guessed your keycode was 12345? Of course not.

You think walking through an unlocked door should result in federal charges?

So now the door is unlocked?? Where are the goal posts?

Don't mess with people's stuff if they don't want you to. This seems very simple to me. But I'm aware that you're trying to find some fringy gray area where you think it will be OK to mess with people's stuff even though they don't want you to.

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#298

Earlier quoted context omitted.

Doesn't this posture also criminalize white-hat hackers, whose disclosures would protect you from the people who actually want to do damage?

> Doesn't this posture also criminalize white-hat hackers, whose disclosures would protect you from the people who actually want to do damage? There is no law for "white-hat hackers". You don't get to break into a system because the color of your hat. "White-hat hackers" have contracts, or very specific rules of engagement. Having run many a bug bounty, if someone was malicious, we would absolutely work to prosecute.…

This isn't true: there is, jurisdictionally dependent and I think also dependent on DOJ norms, a broad exception for good-faith white hat vulnerability research that would otherwise violate CFAA. Like I said, CFAA is very complicated in practice.

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#299
post #188

Earlier quoted context omitted.

It doesn't matter if you brute forced their crappy login with commonly-used credentials. You think it's OK for someone to rummage around in your garage just because they correctly guessed your keycode was 12345? Of course not.

You think walking through an unlocked door should result in federal charges?

So what about using rakes or bump keys? Very low tech, very easy. Can defeat some poor quality locks.

Re: Man jailed for parole violations after refusing to decrypt his Tor node

#300

Earlier quoted context omitted.

All that is as may be, but the CFAA charge here isn't pretextual; what he's alleged to have done is pretty serious by any standard. I have no trouble believing that the prosecution was motivated by Tor drama, but all that tells me is that the DOJ had real cards to play, and they played them. My guess is that things would have gone substantially worse for this person had he taken that case to trial.

Having seen the system up close, I hesitate to draw conclusions from cases that don't go to trial. Doesn't really sound like they have the means to afford trial, or at least a chance at a fair one.

That's a pretty good reason not to break into your former employer's data center to unplug a bunch of servers because you're mad they terminated your contract. That would not have been a difficult case to prove up.
Post reply on HN