Live data from Hacker News

FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

justice.gov

61–70 of 73 posts

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#61

Earlier quoted context omitted.

Why would you expect to sympathize with him? Is it usual (i.e more likely than not) that cases of cyberharassment are overblown, or based on faulty knowledge, or outright false? It's strange to me that someone would immediately be so skeptical, unless the rate of false accusations is higher than the rate of true accusations (at least insofar as determined by the imperfect legal system). Is that the case? I'd like to…

I don't know what the rate of false or overblown allegations is. I wrote above about my intuition and not my judgment after a considered study of the issues and evidence. It's just what I expected. As for why my intuition went that way, I suspect it's because, from the title, I felt like Lin was wronged by the VPN company which misled him, I generally distrust the FBI, deanonymizing VPN traffic seems troubling to me,…

I don't think "cyberharassment" sounds like being mean online at all, I think it's what most would consider harassment but conducted through the Internet to the extent that it is possible to do so, and it may even be more pernicious, since it is very easy to stalk people and submit anonymous comments via the Internet. In the same way, I'd also assume you personally more likely to be falsely accused of rape than you are to be victimized by it - simply because you're probably not a rapist. It does not have much to do with the fact that most rape allegations are true, at least to the extent we determine in legal courts.

Maybe we should think about how we act online if we feel that there is a significant risk of being accused of cyberharassment, even if such conduct should not be illegal (and I suspect we also disagree on where the line ought to be drawn here).

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#62
post #11

They all log, and they all turn those logs over to police agencies when they get court orders to do so. These services are only intended to prevent ISP snooping on legal activities that may be personal or embarrassing, but not illegal. That's it. If you do something illegal on a VPN connection and think the VPN providers have no logs/evidence, you'll be very surprised when the cops show up.

Exactly. Even my personal VPN (Streisand) running on a cloud-hosted VPS is not safe if I decide to become a criminal. All LE would have to do is subpoena my hosting company and monitor incoming connections.

A VPN may slow a nation-state down a little, but it will certainly not stop them.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#64

Earlier quoted context omitted.

I don't know what the rate of false or overblown allegations is. I wrote above about my intuition and not my judgment after a considered study of the issues and evidence. It's just what I expected. As for why my intuition went that way, I suspect it's because, from the title, I felt like Lin was wronged by the VPN company which misled him, I generally distrust the FBI, deanonymizing VPN traffic seems troubling to me,…

I don't think "cyberharassment" sounds like being mean online at all, I think it's what most would consider harassment but conducted through the Internet to the extent that it is possible to do so, and it may even be more pernicious, since it is very easy to stalk people and submit anonymous comments via the Internet. In the same way, I'd also assume you personally more likely to be falsely accused of rape than you a…

"Harassment" can refer to a variety of behaviors. I feel "harassed" by telemarketers insisting I apply for a loan or buy whatever they're selling. If someone were to repeatedly bother me at the mall trying to sell me something, I'd think of that as them "harassing" me to buy something etc. Harassing seems to me like repeatedly being a nuisance.

In the context of criminal behavior I'd expect harassment to be a campaign of intentionally bothering someone and invading their space. I'd assume someone like Lin might be guilty of criminal harassment if he waited outside this girl's house and lewdly propositioned her every day, bothered her at work, etc.

I think we should have a higher bar for what constitutes cyberharassment because it's so much less invasive and threatening than physical harassment and so much easier to ignore. It's also possible that it's easier to inadvertently participate in cyberharassment when you can't see how the other person is reacting to you or feel how inappropriate the behavior is.

What Lin did in this case is far beyond any of what I described above. I think of his behavior as transcending what I'd describe as cyberharassment - in my earlier comment I called it psychological torture and I think that's far more apt than cyberharassment which seems too milquetoast a phrase for what happened here.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#65
post #14

Earlier quoted context omitted.

Ahhh. They aren't keeping the logs, they're merely forwarding the logs to another "non-associated entity" (giving them legal cover), and storing the logs there. Makes sense. They can advertise "we don't keep logs" ( we meaning the corporate entity itself) so they have legal cover, and they make the three letter agencies happy (and thus are allowed to continue to operate)

Indeed. And those tools to do such an analysis already exist. Its the formerly NSA tool called "Apache NiFi". It even has a syslog server plugin specifically for this purpose (it's built in already; drag, drop, configure, done): https://nifi.apache.org/docs/nifi-docs/components/org.apache... Link/proof asserting Apache NiFi is one of the NSA data analytics tools: https://www.forbes.com/sites/adrianbridgwater/2015/07/…

Proof also can be found here: https://code.nsa.gov

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#66
post #36

This guy is a monster. Read the whole thing if you have the time. For some reason this bit stuck out at me out of all the crimes: He hacked into her "Rover" account (Uber for dog walking) and messaged all her clients that she had a panic attack and murdered their dogs, and will deliver the dog to them in a ziploc bag. Total psychopath.

Yeah, this primarily inspires the thought of whether we should be providing services that enable this kind of behavior.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#67
post #13

If you use PureVPN, you're a sucker, plain and simple. You failed to do basic research into your VPN provider, or failed to consult with someone who actually knows what they're talking about. Let's do a very quick experiment where we evaluate a few popular VPN services at a glance, and critique them using non-technical insights which can generally be applied to any business trying to sell you a product. In other word…

> "Protect your privacy online and access media content with no regional restrictions. Strong encryption and no-log policy with 5000+ servers in 60+ countries..."

I don't see how this is deceptive whatsoever? It states known facts about the VPN while also giving a basic outline on their policies. I'm inclined to believe that Nord doesn't keep logs (as of Nov. 1 of 2018) due to their audit by an external company. The report is available: https://ucp.nordvpn.com/audit-report/

I'm not saying that Nord is 100% safe, as others mentioned in this thread, it is completely possible that any "no-logs" VPN provider may store logs somewhere else or an organization may store their data. It allows a provider to claim they keep no logs, which also technically being truthful. I'm intrigued by Nord's stance to this (as their audit has no mention of it at a quick glance) and I will email their support about this.

Not only that, regional restrictions may apply to services such as Netflix, which have been battling VPNs for years now. Most VPN providers don't work with many of these services, and due to the fact Nord does, I'd claim that as a good advertising standpoint. Never tried "Mullvad", but I doubt they can bypass restrictions of these same sites.

Now onto Mullvad... The reason they can't claim to be the best, in any field for that matter, is because they aren't. Isn't keeping your data private "a GIVEN for any decent service" (to quote your own words...)? I'm also worried about that price, are the potential legal fees Mullvad may pay to keep your privacy safe worth the 5 pounds a month you pay? Same with any VPN for that matter - the cheaper it is, the less likely it is safe.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#69
post #67
post #13

If you use PureVPN, you're a sucker, plain and simple. You failed to do basic research into your VPN provider, or failed to consult with someone who actually knows what they're talking about. Let's do a very quick experiment where we evaluate a few popular VPN services at a glance, and critique them using non-technical insights which can generally be applied to any business trying to sell you a product. In other word…

> "Protect your privacy online and access media content with no regional restrictions. Strong encryption and no-log policy with 5000+ servers in 60+ countries..." I don't see how this is deceptive whatsoever? It states known facts about the VPN while also giving a basic outline on their policies. I'm inclined to believe that Nord doesn't keep logs (as of Nov. 1 of 2018) due to their audit by an external company. The…

Regarding #2, I flubbed and meant to say "More noise", not "More deception". I didn't realize my mistake till later.

And I was briefly dissecting the Google summaries of these services, but I have read much, much more than that for every major VPN provider before settling with Mullvad.

I recommend Mullvad and if you took more than a cursory glance at their blog and documentation then you would get an understanding of what kind of service they want to be. They strive for top-notch security and service.

Nord also seems like a decent choice, even if they are not for me. For me, a company's ethos is extremely important and comes first. However, Nord still has the standard scummy sales tactics employed by so many companies, as you can see from their summary.

Re: FBI affidavit against Ryan S. Lin in cyberstalking case (2017)

#70
post #9

Earlier quoted context omitted.

Bandwidth counting can be accomplished without keeping "logs" per se, and with WireGuard, I think there would be very little reason to attempt to limit connections.

WireGuard is very hard to run without logging. It simply wasn’t designed for that and the maintainer was paid once to write “a rootkit-like” piece of code for a VPN provider which hired him to help them fix that. It’s still an open question afaik edit: I've worded this weird. I was typing on my phone at lunch stuff I'd just learned this morning[0] which referenced this[1] article saying running a log-less Wireguard m…

>WireGuard is very hard to run without logging. It simply wasn’t designed for that and the maintainer was paid once to write “a rootkit-like” piece of code for a VPN provider which hired him to help them fix that.

This is a really bizarre misunderstanding of the events.

Wireguard does not generate any log entries by default.

zx2c4 wrote a rootkit which makes it more difficult to retrieve connected users IPs from a running wireguard instance.

Post reply on HN