Live data from Hacker News

Harvard Student Charged In Bomb Hoax

boston.cbslocal.com

51–55 of 55 posts

Re: Harvard Student Charged In Bomb Hoax

#51
post #31

Earlier quoted context omitted.

he wouldn't have gotten nabbed in a court of law -- all you need is a motive.

I doubt that the "finals list/tor usage" combination would have been enough to convict him, but I suspect it would have been enough to get a search warrant for his computer. I don't know if he used the Tor Browser Bundle, and if that is even all that clean from a forensic standpoint, but I certainly wouldn't trust it to conceal what I did. Maaaybe he'd have a chance if he used a LiveCD that they could not find eviden…

Here's what the young lad should have done, had he had really thought about this: Use a LiveCD to boot with Tor on it, and also tether his cell phone to his computer, so he wouldn't have to go through the campuses wifi. Then the only way they'd have know he used a Tor would be if they checked every student's phone usage -- which would take too long -- and therefore they'd never have found him. Or if they did, they couldn't prove he did it because he used a LiveCD and tor had no trace on his machine.

Re: Harvard Student Charged In Bomb Hoax

#52
post #44

Earlier quoted context omitted.

Oh, for god's sake. First off, don't put words in the anigbrowl's mouth. Second off, it's not government hostility to investigate a bomb hoax that costs a lot of people money and inconveniences a ton of people. This guy wasn't engaging in civil disobedience. Third off, the dude could have just walked to any of the dozen coffee shops in harvard square with free wifi and done this all in the clear, and been fine. Tor c…

What specific words did I put in his figurative mouth? anigbrowl took a technical point about anonymity opsec and responded to it as if it were a political plea about the police, and you're doing the same. So I'm guessing that both you and him don't consider this a failure of Tor because you consider the "right thing" to have happened in the larger situation. As I had said, it's a "hostile government" in the context…

Look, not that many people use Tor in the overall scheme of things. If you find a bomb threat that seems to have originated from a Tor node, and you find that a few people on the campus network were using Tor around the same time, that's the obvious clue to follow. ISTM that you wish Tor were so good at anonymity as to spoof its origins to the webmail program from where the threat were issued, but that seems an unrealistic thing to ask. It's just a protocol, things like time-shifting or IP obfuscation are surely up to the person using it.

To take a principled stand of saying dissidents should have the means to communicate freely, you also have to assert that you'd like for this kid to not get caught.

Realistically he would have been better off to call it in using a payphone (to the extent that he considered a hoax bomb threat a matter of necessity). I don't think you can automate away a complete disregard for security.

Re: Harvard Student Charged In Bomb Hoax

#53
post #47

Earlier quoted context omitted.

Well, sorry, I read it like you were the one injecting politics about 'government hostility' into it, regardless of Tor or SSL, ssh keys or whatever methods are involved. You seemed to be attributing motives to the previous poster with comments about "maybe you prefer it that way" which seem to place him on the side of surveilling fascists, and I thought that was unjustified but maybe I misread it. If you're not gett…

I'd just gotten done typing why it's impossible to convince most people this stuff matters, and was responding to a comment that seems to be written with the assumption that man-made laws are the ultimate authority. So I'll admit to being a bit presumptuous, but I really do believe it to be a fact that most people will never see the need for technically-granted anonymity, and that these opinions simply aren't relevan…

I do appreciate the arguments about why anonymity matters. You might find it interesting to consider the similarities fo debates about services like the penet remailer (http://www.textfiles.com/hacking/INTERNET/na.txt and http://en.wikipedia.org/wiki/Penet_remailer).

With time, I've come to the conclusion that the ability to (re*-create such tools is more important than any individual instance of such a tool.

Re: Harvard Student Charged In Bomb Hoax

#54
post #31

Earlier quoted context omitted.

I doubt that the "finals list/tor usage" combination would have been enough to convict him, but I suspect it would have been enough to get a search warrant for his computer. I don't know if he used the Tor Browser Bundle, and if that is even all that clean from a forensic standpoint, but I certainly wouldn't trust it to conceal what I did. Maaaybe he'd have a chance if he used a LiveCD that they could not find eviden…

Here's what the young lad should have done, had he had really thought about this: Use a LiveCD to boot with Tor on it, and also tether his cell phone to his computer, so he wouldn't have to go through the campuses wifi. Then the only way they'd have know he used a Tor would be if they checked every student's phone usage -- which would take too long -- and therefore they'd never have found him. Or if they did, they co…

Or he could have just not emailed a bomb threat.

Re: Harvard Student Charged In Bomb Hoax

#55

Earlier quoted context omitted.

I'd just gotten done typing why it's impossible to convince most people this stuff matters, and was responding to a comment that seems to be written with the assumption that man-made laws are the ultimate authority. So I'll admit to being a bit presumptuous, but I really do believe it to be a fact that most people will never see the need for technically-granted anonymity, and that these opinions simply aren't relevan…

I do appreciate the arguments about why anonymity matters. You might find it interesting to consider the similarities fo debates about services like the penet remailer ( http://www.textfiles.com/hacking/INTERNET/na.txt and http://en.wikipedia.org/wiki/Penet_remailer ). With time, I've come to the conclusion that the ability to (re*-create such tools is more important than any individual instance of such a tool.

I've come to the opposite conclusion. Adopted systems in continual use are what is important. I could setup any number of service 'anonymizers' within a day, but if an individual operator can even be short-term trusted, they certainly can't be relied on. Only by getting an overwhelming number of not-heavily-invested node operators can one bootstrap reliable trust.

I want to live in a world where the routine use is anonymous, with nyms only connected voluntarily. Of course people have to be smart enough to not post 'my name is XXX' in-band, but they shouldn't have to go to a distant coffee shop. If privacy takes work, that means it's only accessible to the few willing to put in that work, and will be viewed as an aberration by everyone else. It's only by making it easily accessible to everyone that it can become societally accepted.

Post reply on HN