Live data from Hacker News

Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

insidehighered.com

61–70 of 80 posts

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#61

Earlier quoted context omitted.

They call it "A study into toxicity" . I call it gonzo research.

I think I wooshed some people with this comment. Gonzo journalism is when the journalist participates in the story. Gonzo research then is when the researcher participates in what they're studying. In this case, the researchers ostensibly researching toxicity are doxing people, which is toxic behavior. This makes them gonzo researchers.

Intent matters. Both the police and kidnappers restrain people and lock them in rooms. Are they both criminals?

Revealing people for their toxic behavior is in no way the same as toxic people doxxing others purely for what those other people believe.

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#62
post #61

Earlier quoted context omitted.

I think I wooshed some people with this comment. Gonzo journalism is when the journalist participates in the story. Gonzo research then is when the researcher participates in what they're studying. In this case, the researchers ostensibly researching toxicity are doxing people, which is toxic behavior. This makes them gonzo researchers.

Intent matters. Both the police and kidnappers restrain people and lock them in rooms. Are they both criminals? Revealing people for their toxic behavior is in no way the same as toxic people doxxing others purely for what those other people believe.

Basically everybody who doxes thinks they have some ends that justify the means. That kind of mentality is toxic because every dirtbag uses it.

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#63
post #30

Earlier quoted context omitted.

I remember a short time when posting "hacked materials" was a thing people were up in arms about, but that ship seems to have sailed.

What are the hacked materials in this case?

The IP address post link that required a lot of CPU to brute force.

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#64
post #41

Earlier quoted context omitted.

The whole point is they aren't security researchers - they were doing research on the nature of posts on this forum. They worked out that they could do that, and so did - for the paper they wanted to publish having that information was the goal, and the way they did that was essentially in the methods section. Certainly the attack itself is not worth publishing: it's not in any way novel or interesting, the "anonymiz…

> They worked out that they could do that, and so did - for the paper they wanted to publish having that information was the goal My claim is that they shouldn't have. >Which is why it is necessary to publish this information - if this paper did not detail how terrible ejmr's "anonymization" was, it's pretty clear ejmr would not have told its users I agree it's necessary to disclose the vulnerability to the victims (…

> My claim is that they shouldn't have.

Studying the disposition and demographics of forum posters is not new, nor is this a unique example. The only issue here is the forum posters believe, based on incorrect claims from the forum, that they were anonymous. But their posts were not, and this is the first time it came up publicly, because this is the first time someone looked at this particular forum, in the context of "I want to publish a paper about the demographics of this forum".

The forum users have the right to feel angry that their posts were not anonymous, but that anger should be directed at ejmr, not the academic that made it clear their posts were not.

The posts on ejmr were not fully anonymous, and nothing can change that - there are more than 10 years of posts, all of which are public, none of which are [fully] anonymous. It does not matter whether this academic collected any of the information, because in a hypothetical world where they don't and simply disclosed that none of the last decade+ forum posts are anonymous, anyone else could do exactly the same thing. This is assuming of course no one has done this in the past.

> I agree it's necessary to disclose the vulnerability to the victims (especially if ejmr wouldn't have), but it wasn't necessary collect as much data as possible themselves and write a paper about it for their own gain.

What harm do you think writing a paper on forum demographics did? I am genuinely curious, because this seems like you're still just trying to find ways to blame the gross negligence of the ejmr folk on the authors of this paper.

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#65
post #19

Because people keep on acting like these researchers have retroactively removed the anonymity of this forum, or somehow everything was anonymous before this published, lets go over the facts: 1. ejmr made a system that includes hashes that could be trivially linked to ip addresses 2. ejmr claimed posts were anonymous 3. this researcher realized that the hashes could be trivially linked to ip addresses 4. the research…

> ejmr made a system that includes hashes that could trivially be linked to ip addresses "trivially be linked" = searching 3 quadrillion possibilities? Suppose that in the near future that a quantum computer enables the "trivial" piercing of current anonymity assumptions, should those individuals also be fair game for doxxing: "they were never anonymous"? Your casual appropriation of "triviality" to dismiss moral con…

> "trivially be linked" = searching 3 quadrillion possibilities?

Which is trivial. Doing the same thing many times is literally what computers were invented for. Whether it's 3 times or 3 quadrillion times, it does not matter.

> Suppose that in the near future that a quantum computer enables the "trivial" piercing of current anonymity assumptions, should those individuals also be fair game for doxxing: "they were never anonymous"?

There are myriad ways to have provable anonymity, quantum computers are not magic. More over the best known algorithm for some kind of deanonymization under QC is still Grover's search which is a sqrt improvement, rather than anything catastrophic like Shor's. But that's also irrelevant.

ejmr's "anonymization" was not anonymous under the standard cryptographic assumptions of 20 years ago, let alone 12 years ago when the software originated.

To be clear, when ejmr was first started:

* SHA1 was mostly cryptographically broken (that is it was considered a sufficiently determined adversary with unlimited money could break it), hence any new use of SHA-1 is definitionally wrong.

* SHA is the wrong family anyway, SHA hashes are authentication codes and are therefore intentionally extremely fast to compute. It was well established in the _90s_ that authentication hashes are not appropriate for anything other than authentication, alongside numerous demonstrations of breaking password hashes which is what ejmr was essentially doing.

* ejmr was not salting anything, and literally anyone with actual experience in any actual field using hashes knows that salting hashes is mandatory.

This isn't "this was anonymous until computers got faster", this was not anonymous at the time it was first written, under standard cryptographic assumptions. Let's say it cost $10k for this PI to compute those hashes, then 12 years ago, assuming Moore's law, it would cost $5million to break (under simple assumptions, so I doubled to be conservative).

That. is. broken.

> Your casual appropriation of "triviality" to dismiss moral concerns over this paper and the authors' possible motives rings hollow in me.

No. My claims are purely related to the claims that the authors of this paper are responsible for deanonymizing people that on ejmr, when ejmr catastrophically failed and misled its users.

Your immediate response to my statement about triviality was to repeat "it's a big number" which belies a gross misunderstanding of the field. Anything involving hashing or cryptography is filled with giant numbers. A non-trivial attack is one that involves doing something clever to reduce the search space to make the attack possible. This attack was _literally_ "we just tried every option as fast as possible". That attack on misuse of hashing operations was identified in the 90s when people demonstrated breaking of password hashes.

This attack is not clever. It does not - afaict - do anything that in anyway reduces the complexity from "try every option", it is a dumb solution to the incompetent "anonymization" performed by ejmr. That "try every option" was an option speaks to how poor the ejmr code was, and how trivial this was.

As for the "morality" of the paper: there are endless "studies" of forum culture and demographics that haven't caused problems.

The only problem I see is that ejmr is refusing to acknowledge that they rolled their own crypto, and predictably got it wrong. That and people like you who seem to believe this mediocre research paper is somehow responsible.

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#66
post #43

Earlier quoted context omitted.

No. Black vs white hat is "did you break this and then use it to . The responsible vs. irresponsible disclosure question is "do you tell the responsible party ahead of time and give them time to repair it". From articles it certainly appears that ejmr learned how broken their code was prior to this paper being published. But responsible vs irresponsible disclosure is not a question of "should this be disclosed at all…

> Black vs white hat is "did you break this and then use it to . That is a very narrow interpretation of "black hat". I think mainstream take is that black hat includes many legal but ethically dubious actions. Maybe you would call it "grey hat", I don't know. But publishing vulnerability without a responsible disclosure can be considered unethical. > But responsible vs irresponsible disclosure is not a question of "…

> But publishing vulnerability without a responsible disclosure can be considered unethical.

Yes, there is debate on that, and there are arguments on either side. But given ejmr went 12 years without changing their "anonymization" scheme, and then changed it a short time prior to an article being published that demonstrated the scheme was broken, I think it's reasonable to presume ejmr was notified prior to publication, and had time to correct the flaw, which is the canonical example of responsible disclosure.

That ejmr did not tell its users is an example of the behavior that the anti-responsible disclosure folk point to. Organizations that say "you should tell us about vulnerabilities in our products, but you cannot tell our users, and neither will we" are a large part of the reason some people oppose responsible disclosure.

> No. If they were informed about this issue, after changing the schema EJMR could take down all preexisting posts made with the old schema and request public archives to remove them (and reindex new ones).

There are multiple existing libraries online to support scraping ejmr specifically, as well as who knows how many archives and search engines we don't know about.

Every person who posted need to be made aware that their posts could be tracked at least to the IP (though at any institution you're behind a NAT so generally IP != person, and the idea of ISPs having per hour IPuser logs from a decade ago seems suspect).

Also we know that ejmr found out about the gaping hole somehow - we don't know exactly, we just know they addressed the incompetence, though I assume they're still doing it wrong - and they didn't even pull and re-index their own archive let alone ask anyone else to do so.

> It's not foolproof because many posts may happen to be archived independently but it would be something.

Either you're anonymous or you're not, so you can't just say "we doubt there are any other archives so you're safe". The user IPs are not secret, as they were never secret.

We also have no way to know if anyone else had already done this, and we likely never will.

> And of course notify users.

Which they also did not do.

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#67
post #14

Earlier quoted context omitted.

> this is rly awful "research". ederer prob got bullied on there and got mad, cause he has a reputation as a bitch. No. Also name calling, while commenting on something you clearly don't understand is not a good look. EJMR claimed to be anonymous. It was not, and what they were doing skipped the most absolutely trivial of steps for actual anonymization. The only difference between this week and last week, is that now…

>Blaming the person who found out how terrible EJMR's "anonymization" was, is classic shooting the messenger. Found out! They had an enemy: a small forum that they did not control. They looked for ways to screw it. This isn't some good-natured happenstance, they targeted someone they didn't like so they could screw them. The result, the point, wasn't, "Hey, security is important, kids, let me highlight your errors" i…

Dude, you're hiding behind an explicitly anonymous account throwing random personal attacks at people.

I literally had not heard about ejmr until this week.

Direct your anger at ejmr, they're the people who made bogus claims about anonymity while using tools they lack the most basic understanding of.

It also does not matter if it was some kind of personal "I hate this forum" or "I hate the creator". ejmr's anonymization was incompetently written, and screwed up the most basic usage of the most basic cryptographic primitives, and was using the wrong primitives in the first place.

The fact that we're hearing about this in a paper by a person you have declared to be on a vendetta is irrelevant - given that person is explicitly not a cryptographic specialist and was able to find that the ejmr posts were not anonymous means that the idea that no one else could have done so without publishing an academic paper is implausible.

As I have said elsewhere, ejmr's "anonymization" was so broken that even the attack itself was trivial (the article's author is an academic and would have absolutely made a separate publication on the deanonymization process if they could have).

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#68

So what's next? Get these people fired from their jobs for having unapproved ideas? Also, who decides what is or is not toxic?

You make it sound like it's a matter of academic freedom. It is not. Do you or do you not think that it should be acceptable to use language like "d4mn j3ws" in an academic forum?

Sticks and Stones [1]?

[1]: https://en.wikipedia.org/wiki/Sticks_and_Stones

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#69
post #57
post #26

Earlier quoted context omitted.

> Do you or do you not think that it should be acceptable to use language like "d4mn j3ws" in an academic forum? Of course it's not acceptable. It's not acceptable for any academic to disagree with me period. All those posters need to be rooted out, fired, and blacklisted.

Sorry if this sounds harsh, but you need to have a little more empathy for those aren't part of your "white boys club." Don't you think women and minorities need to know if their colleagues are posting their horribly sexist and racist thoughts online? Read the examples in the paper and then tell me that the colleagues of these people don't have a right to know.

Well, if you don't mind being harsh, I'll tell you this: In your woke-scolding, you are assuming the both the gender and race of the person who you are replying to; probably based on a single comment.

Re: Researchers Say They Found IP Addresses for ‘Anonymous’ Econ Forum Posts

#70
post #63

Earlier quoted context omitted.

What are the hacked materials in this case?

The IP address post link that required a lot of CPU to brute force.

You mean the publicly posted IP address post link? That's not hacking.
Post reply on HN