Hacker Newsnew | past | comments | ask | show | jobs | submit | devconsole's commentslogin

Growth hacking is hard. We had to learn a few tricks to grow our Hacker News alternative (https://laarc.io)

Suppose you were to start a site similar to HN. How would you get the word out?

The most reliable way to grow is to have an audience (or access to one). But they have to be interested in what you're showing, else you're little better than a spammer.

Looking over the traffic for the last month (https://imgur.com/a/O1wtzav) the spikes were from comments posted to lobse.rs:

https://lobste.rs/s/jqkqwb/what_are_you_doing_this_weekend#c...

https://lobste.rs/s/kx4ojt/what_are_you_doing_this_weekend#c...

This won't keep working, but it might have been enough. The site seems to be spreading through word of mouth now, and about 400 people show up each day.

Communities are also a strange thing to grow. Grow too fast, and you'll spoil it. Ditto if you grow from the wrong source of people.

Fundamentally, you have to have a product that users love so much that they spontaneously tell their friends about it. But press coverage – or at least social media coverage – seems to matter a lot. You probably need both.

We've been using https://playbook.samaltman.com/ as a mantra, and it's been effective so far. But it's only been a month. We'd like to try Michael's advice next: http://www.michaelseibel.com/blog/getting-press-for-your-sta...


It seems that there are two conditions necessary for a better product to take over, which is what you are trying to acompish.

First and most obviously, the new product needs to be objectively better in key ways that people care about, preferably multiple key ways.

Second, the audience must be above some threshold of dissatisfaction with the current product. There must be a sufficient pain point for a sufficient part of the audience. It cannot be merely a "geez it might be nice if X", but an actual "damn, this is annoying...". And, obviously, your new product must address it.

If there is no significant pain point, you have no chance of gaining any traction. Even if the switching cost is essentially zero, you have no real chance.

Trying for a better HN? Maybe I'm missing something, but I haven't seen any big issues, nor anybody complaining about issues. So, I wish you luck, but it seems you may have put a lot of effort into something no one really wants; might be best to consider taking the huge amount you've just learned and pivot to a new target...


Why use the alternative when here we are on the perfectly fine original?

Maybe it can't grow because it's an unnecessary and inferior substitute. I don't mean to sound harsh but if it's difficult to gain traction there's likely a reason.

Which gets to the main point of the original article: you can't 'growth hack' a product that has no market from which to grow from.

Build something people find valuable and it will grow is the only "hack" that truly works.


I agree with you, but would add one caveat. You may have built something valuable, but have yet to find the proper distribution channel. In which case, you experiment selling through different channels until you either grow, die, or pivot.


Nice try here! But still not visiting the site ;)


> But they have to be interested in what you're showing, else you're little better than a spammer.

Just got one of those spam emails from you guys. Not cool. And the website just looks like a clone of HN. Why should I go to a clone when I have the original right here?


The same response posted twice by different accounts. Seems legitimate.

And within the post they reply with: "...else you're little better than a spammer"

Hilarious.


There are some interesting theories being tossed around. I'd like to add one more.

The common thread across all darknet websites is the fact that they generally run from datacenters. Most people don't host websites from their residence.

Further, most people don't colocate servers anymore. I would be surprised if any of the 414 websites operated on boxes that had been colocated. However I won't rule out that colocating is also compromised.

I'd like to posit the following law of nature: You can't run a darknet website from a datacenter and think you've hidden the location of the server, regardless of whether it's using Tor or other anonymity software.

Why not? Because the datacenter has the ability to image servers, along with the ability to notice that you're generating large amounts of outgoing Tor traffic (or other anonymity software).

Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website.

Remember, the point of Tor is to hide the final IP address of a web request or web service. It does not hide the total volume of traffic that must be delivered. And it can't. If you operate a darknet marketplace, you're probably serving a large volume of traffic. Guess who notices? ISPs and datacenters. Guess which datacenters can be trusted not to divulge an image of your server to authorities? None of them.

What do I think the future of darknet opsec will look like? Well, if you're reading this, and you're an individual or group interested in pursuing your ideology through a darknet website, you will need to run your website from a datacenter and not rent your server in your name. In fact, your opsec needs to be so good that there's no way to trace the account back to you. This sounds hard, and it is, but it's possible. Secondly, you must assume at all times that the server you're using is compromised. Assume that aurhorities can access the contents of the server, can manipulate it, and can subvert anything you put on it.

This is a grim situation, to be sure. The above assumption is that you are never safe from authorities gaining a copy of the contents of your datacenter-hosted darknet website (including any databases), and from a takedown of the service whenever authorities deem to do so.

Here's the ray of hope: Just because they takedown your website doesn't mean they take you down. This is where opsec comes into play, and it's our last hope. Every other link in the chain of trust for darknet websites has been broken. The one and only chance is that you can figure out a way to create accounts at datacenters without authorities being able to trace them back to you.

Authorities takedown your service? Okay, start it again at some other datacenter. Authorities get a copy of what's on your server? Okay, no problem: you were assuming it was compromised anyway, right? Authorities install a program to make your software malfunction? That's unfortunate, and will shake the trust in your website, but it's possible to recover from this.

Do your best, and do not get caught. The rest follows from this.

At a minimum, you need to research opsec. Read history of how groups have evaded detection. Do your research using Tor, because associating such Google searches with your home account is a terrible mistake.

One of your biggest problems is going to be anonymous money. No, bitcoin won't help you. You can't rent a server from a datacenter using bitcoin. But you can anonymize your money and then use that money to rent your server.

It's a long shot, but it's all we've got left. Be perfect. There's no room for error. Or realize the truth: If you can't be perfect, you will get caught. And you may get caught anyway. Being perfect sounds impossible, but human history has shown that there are situations in which no or few mistakes are made. I would recommend you research those situations and how to minimize the total number of mistakes you make. Use software to help you do this, while realizing that clever software alone won't be enough. For example, if you're configuring an individual piece of software on your personal computer to connect to your darknet website, even through Tor, you're doing it wrong. You need to isolate yourself from this equation at all times. Sound hard? Oh, it's hard. It will slowly dawn on you how hard this method of operating is. Convenience? No. You don't get to enjoy the benefits of convenience. Convenience is the opposite of security.

Oh, and if you do happen to somehow make a lot of money, you should keep it as bitcoin for the forseeable future. What good is it? Maybe converting small amounts won't be noticed. On the other hand, converting large amounts of bitcoin to dollars will be noticed, and it's extraordinarily dangerous to your opsec.

I'll be around to answer questions if you have them. If you'd like to ask a question anonymously using Tor, create a new HN account and post your question. I'll see it, but it will show up as dead on HN, so I won't be able to reply to it directly. So I'll reply to my own comment with a copy of your question, along with a response. Then you can reply to that, and I'll repeat the process.

HN is one of the few websites that we can even have these kinds of conversations on using Tor. Everything on Reddit is autokilled. 4chan doesn't let you use Tor. Maybe we should work on this problem first: How to make the equivalent of unlisted Tor exit nodes so that Tor isn't so trivially blocked?

There are a lot of ideas in my comment, and some of them are better than others. I hope that the bad ideas can be discarded and the good ones refined until we have someting workable.


> Here's how the attack may have happened: Step one, collect data about which computers are sending and receiving large amounts of Tor bandwidth. Step two, if the server resides in a datacenter, request an image of the server. Step three, you now know whether the server is a darknet website.

This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic and all of them could be hosting hidden services as well. The total traffic in itself doesn't necessarily show that a server hosts hidden services. It could also me masked by generating fake traffic to/from the server.

Knowing that Tor traffic comes and goes through a server isn't enough. Most data centers would not just hand over disk images just because a server is running Tor and a hidden service. You would need good evidence that the particular hidden service you seek is hosted at that particular data center.

You still need detective work to pinpoint the location of the datacenter. This could come from timing attacks or an unrevealed weakness in the Tor protocol itself, but it's more likely that they noticed suspicious activity in real life (large purchases, people already known to be involved in drugs), infiltrated some markets, managed to get some people to talk, ... Once you suspect a particular person and they are under surveillance, you can catch them paying for servers with their CC, connect to their server directly, or watch their BTC transactions.

They would certainly need the cooperation of the involved data centers at some point, but neither Europol nor the FBI can just walk into any data center and request images of any server that handles Tor traffic without a warrant, which would require some tangible evidence to support its release, lest it becomes inadmissible in court.


>This in itself is not sufficient: there are thousand of Tor bridges, relays and exit points. All of them carry lots of traffic and all of them could be hosting hidden services as well. The total traffic in itself doesn't necessarily show that a server hosts hidden services. It could also me masked by generating fake traffic to/from the server.

Relays (exit and non-exit relays) are listed in the consensus, so you can easily rule them out, or just watch the hidden service and the relay and correlate downtime.

Bridges are not listed in the consensus, but they also don't survive very long, and don't carry very much traffic, since they tend to be used by a small number of individuals. So bridges will naturally churn out of your target set.

>neither Europol nor the FBI can just walk into any data center and request images of any server that handles Tor traffic without a warrant,

This seems optimistic at best. They could certainly ask to install a wiretap, or just threaten their way into installing a wiretap (i.e., install this wiretap or my buddy at the EPA is going to be allllll over you for how bad your parking lot is drained, etc). They could just ask and say they suspect the computer is involved in child pornography, which will probably override most people's objections.

But beyond that, people tend to cooperate with authorities. It's either a natural state of humans to be subservient, or we've been indoctrinated through eons of hierarchy, but now, the only thing necessary to get someone to kill someone else is a stern command. If you don't believe me, look up the Milgram experiments.


> but now, the only thing necessary to get someone to kill someone else is a stern command. If you don't believe me, look up the Milgram experiments

I think you're being a bit hyperbolic here.


Look up the Milgram experiments and tell me I'm being hyperbolic.


Etheteum web3.0 + TOR


Knowing that Tor traffic comes and goes through a server isn't enough. Most data centers would not just hand over disk images just because a server is running Tor and a hidden service. You would need good evidence that the particular hidden service you seek is hosted at that particular data center.

They can just enumerate every hidden service, figure out which ones are doing something obviously illegal, then once they locate a datacenter that is likely to be hosting hidden services e.g. accepts payment in Bitcoin, get netflow data and pump traffic at each hidden service in turn. When a synchronised block of encrypted traffic turns up at a host, there's your probable cause to go image the server: it's practically bulletproof evidence that the hidden service corresponding to some black market is running on that machine.

The only bottleneck to this approach is finding the datacenters, but there aren't that many which accept Bitcoin for payment, and I bet intelligence agencies can easily provide a list of every colocation facility that is running long term connections to the Tor network. Heck they can probably identify the precise machines by doing traffic correlation automatically - it's the sort of task they'd be good at, and they have the infrastructure.


> there aren't that many which yet accept Bitcoin for payment

FTFY


neither Europol nor the FBI can just walk into any data center and request images of any server that handles Tor traffic without a warrant, which would require some tangible evidence to support its release

What about with a data request by a judge in Italy, raising a sealed subpoena through a Texas court to get the FBI to physically remove a server from a datacenter in London belonging to a UK organisation, without informing them, the UK government or the UK police, all while keeping the original reasons for this under seal, and then suddenly returning the hardware just as mysteriously as it was first taken, without thinking you should have to explain a single thing?

That happened to Indymedia years ago. - https://www.eff.org/cases/indymedia-server-takedown


As long as everyone has someone else to point to who is responsible, these things will continue to happen. It's the same pretty much everywhere in the world.


Agreed, but the sheer scope of this operation forces us to consider whether the authorities are playing by all of the rules. Since we don't know which rules are still reliable, the best defense is simply to assume your server is compromised from the start. And, incidentally, your support staff.

By the way, I'd also like to thank everyone for the thoughtful responses. It's great that people are thinking about this problem.


To be honest, I don't think it is possible to evade the authorities and run a profitable business on BTC.

I think that is really where these markets are running into trouble. They need to spend the BTC they earn to cover their costs and lifestyle, at which point it becomes pretty obvious given I doubt there are many people converting BTC to cash in 6 figure quantities per year. Given the blockchain isn't anonymous, every 3rd party you move your BTC through can receive a warrant until they find the name you withdrew the cash under. They all want your bank account information which means you'd need a fake bank account.

Once you hit the "I need a fake second identity for financial information, etc." you are going to throw up all kinds of red flags.

Yes the banks break the rules [e.g. HSBC]:

http://www.reuters.com/article/2013/07/02/us-hsbc-settlement...

But they do eventually get caught.

I think Tor and the Darknet is great when you need to start a revolution or other non-profit-activity. The moment you try to make money you can live off of and cover your costs is the moment you accept you will get caught eventually.

> How to make the equivalent of unlisted Tor exit nodes so that Tor isn't so trivially blocked?

Run a VPN connection through TOR via a service that lets you pay anonymously. [e.g. gift cards you can buy with cash]

Of course, then the VPN can snoop all your traffic but given you are using TOR...you should be expecting that anyway. TOR guarantees technical anonymity, not privacy. You screw up your OpSec and you are screwed anyway. ~


The whole idea of a centralized market, with someone syphoning off large amounts of money and being the major legal target, sets it up for failing. Once it becomes a distributed marketplace with all services replicated it becomes much more secure.


So like the distributed tracker system in bittorrent I guess: http://en.wikipedia.org/wiki/BitTorrent#Distributed_trackers Some background research on a distributed key/value system that this could serve as a basis for a peer-to-peer distributed marketplace: http://www.cs.rice.edu/Conferences/IPTPS02/109.pdf


DHTs are susceptible to Sybil attacks. A key/value store based on a cryptocurrency would be a better approach if you're looking for a decentralized key/value store that guarantees that the data is available.


Requesting an image of a paranoid person's server isn't necessarily that great. When I worked for a run-of-the-mill cybersecurity firm, our simulator products were protected with full disk encryption using run-of-the-mill open-source software + light patches and keys bound to specific hardware, software, and configuration states via the TPM. This is for fully automated boot up. If you can accept the risk of needing to be physically close to a machine, you can generate random bytes and store those into your TPM and require both the hardware/software/configuration to be correct as well as knowing your key. This would incidentally also prevent you from being able to give law enforcement the key to an image of your computer (this is actually impossible, you don't know the key).

If you're doing this under a warrant, you could just request that the server's operator unlock the machine. Whether you comply is a legal situation that varies from jurisdiction to jurisdiction (in the US, it seems that you might be held indefinitely in jail if you refuse to divulge your key). The thing is, you should be able to make an extremely strong case (possibly with the EFF's help) that any warrant is false. Anonymous traffic itself should not be enough to compel you to divulge your secrets without other evidence pointing to your machines (standard IANAL, but this seems consistent from everything I've read).


It's an interesting idea. I think physically shipping a server to a datacenter is precarious. Remember, it is known that your server is hosting a darknet website. You can't really hide this fact. Timing correlations make it possible to figure out which server is doing what. The reason that Tor users are generally safe from this is because they're not constantly connected, and an adversary generally can't cause a client to issue a web request on demand. But a webservice is constantly connected, and any adversary can cause it to issue responses since it's a webservice. Whether it's a timing correlation from a global passive adversary, or it's simply noticing that "silk road is extremely popular and this webserver in this datacenter seems to be hosting a huge amount of Tor traffic," you have to assume that it's known that the location of your server is compromised.

And if you assume that, then it suddenly becomes very, very bad if you've personally shipped a computer to the datacenter, colocation-style. First, clever hardware won't protect you if it's a running box. But beyond that, you can be traced simply by the components that you've assembled. You have to order those components from somewhere. You have to assume the worst: that authorities will take your box using a power adapter that lets them physically remove the computer from the datacenter without turning it off (such things exist), dump an image of your server while it's running (so that encryption keys won't help you), and then dismantle your server and trace the origin of the components. Congratulations: you're caught.

I think the model of "rent a bunch of servers using opsec" is also precarious, but less precarious than relying on hardware protections to save you.


How about hosting your website on a botnet? Using infected machines to handle requests and sending the compressed order info over TOR to suppliers?


Not a bad idea, assuming you don't care about taking other people's property and using it in ways they don't expect for personal gain. But it's difficult. Once you no longer control the underlying hardware guarantees, availability chief among them, it's hard to design a reliable webservice. There has been some research in this area, though I'm not intimately familiar with it. Find it and read up on it. In general, the problem is how to organize some kind of store of data across multiple unreliable machines. That sounds like a solved problem (bigtable et al) until you realize it also needs to be secure, and you're running on an unsecure network of infected computers. At some point, some computer needs to access the secure info. If you're letting infected computers do that, then that means its operator can also do that. Though, in fairness, maybe you don't need to care about that threat. A bigger threat is that the operator would also have write access: they could corrupt your data or forge transactions in your system.


> You have to assume the worst: that authorities will take your box using a power adapter that lets them physically remove the computer from the datacenter without turning it off (such things exist), dump an image of your server while it's running (so that encryption keys won't help you)...

I believe they can keep my server powered on whilst they remove it from the DC (dual PSUs in enterprise servers would make this _extremely_ easy) but how exactly are they supposed to be "dumping an image of the server whilst it's running"?


I'm not sure this part is true.

You can buy servers and server parts anonymously via places like Craigslist with cash. At which point, you just need a fake ID to trick the Colo and pre-pay them for 12 months in cash w/o being recorded. Its possible given I've run into colos that were run by college kids with just a single cage. I'm pretty sure they wouldn't turn the offer down and just say you were "too busy" to set it up yourself due to work.


Then the authorities trace the server component to the person who sold it on Craigslist. And if your opsec isn't perfect, you're busted right there: Did you forget to set up a new email account for all of your craigslist transactions? Did you forget to set them up and connect to them only through Tor?

Did the person you met with write down your license plate number? Seem unlikely? Think again. Cameras write down your license plate number as you drive. Constantly. So the authorities will simply look up where the person drove to meet you (parking lot, etc) and any cars that drove to the area at the time. You'll probably be on a highway at some point, which is a highway of data collection. There weren't that many people who drove a long distance to go to the meetup area. Now the authorities know which of 1,000 people you are. The more times you do this, the fewer the number of suspects there are, until they're down to a number that they can just investigate one by one. Then you're caught.

Or did you take your cell phone with you, and did the person who sold you components take their cell phone? Yes, you're caught. The operation in the previous paragraph, which assumes that you're just driving to meet someone and both parties are leaving their cell phones at home, is already busted. So if you've taken your cell phone on top of it, then it's even easier. Anything involving correlating cell phone movements is trivial for authorities. And if you don't take your cell phone, how are you going to let them know you've arrived? What if they're late? Or you're late? Now you have two problems: Set up a burner phone in an anonymous way (hello, in-store security cameras) and then never, ever use this cell phone in the same place as your main cell phone. Not a good position to be in.

I've ignored the whole "fake ID" aspect, because if you're in a position where someone is putting their face onto a forged legal document, that person is going to be persuaded by authorities to betray you. And if that person is you, then obviously you're caught at this point. Your face is probably on Facebook, and facial recognition software is getting pretty good nowadays.

In general, physical ops are the most dangerous of all ops, and should be avoided until every other avenue has been explored. Better to anonymize your cash (which is also a physical op) and then use that cash to rent a single remote server.


you are probably going to be one of the few people to meet up and do a cash drop for the server. Which is automatically going to make you standout to the hosting guys. Thus, MUCH more identifiable.


'course. But how else are you going to pay? Stolen credit card?


> Then the authorities trace the server component to the person who sold it on Craigslist. And if your opsec isn't perfect, you're busted right there: Did you forget to set up a new email account for all of your craigslist transactions? Did you forget to set them up and connect to them only through Tor?

If your opsec isn't perfect you are busted anyway. You already said that in the OP. ;)

> Did the person you met with write down your license plate number? Seem unlikely? Think again. Cameras write down your license plate number as you drive. Constantly. So the authorities will simply look up where the person drove to meet you (parking lot, etc) and any cars that drove to the area at the time. You'll probably be on a highway at some point, which is a highway of data collection. There weren't that many people who drove a long distance to go to the meetup area. Now the authorities know which of 1,000 people you are. The more times you do this, the fewer the number of suspects there are, until they're down to a number that they can just investigate one by one. Then you're caught.

We are assuming a criminal here. You use a fake license plate that you change regularly. You also move regularly and pay cash. Once again, your OpSec needs to be perfect but it is the only real obstacle. If they know which cluster of 1,000 people you are, your license plate gets changed, and you leave at the end of the month forever...they'd have to investigate all 1,000 people to maybe-possibly-id-you then try to figure out who and where you changed your license plate. But you are assuming they can trace the hardware of an anonymous cash transaction on craigslist again. I highly doubt that.

> Or did you take your cell phone with you, and did the person who sold you components take their cell phone? Yes, you're caught. The operation in the previous paragraph, which assumes that you're just driving to meet someone and both parties are leaving their cell phones at home, is already busted. So if you've taken your cell phone on top of it, then it's even easier. Anything involving correlating cell phone movements is trivial for authorities. And if you don't take your cell phone, how are you going to let them know you've arrived? What if they're late? Or you're late? Now you have two problems: Set up a burner phone in an anonymous way (hello, in-store security cameras) and then never, ever use this cell phone in the same place as your main cell phone. Not a good position to be in.

The last time I bought one, I met them at their house and rung the door bell. No phone required. You can also pay a bum to go in and buy the burners for you. Admittedly, I was just buying something to experiment with on the cheap so I didn't really care about anonymity.

However, you are making the assumption these components are easily traced in after market cash sales. I doubt strongly that they are that easy. And given you are trying to be anonymous, you don't care if either party is late since you'd wait a reasonable amount of time and if that failed, setup a new transaction elsewhere.

> I've ignored the whole "fake ID" aspect, because if you're in a position where someone is putting their face onto a forged legal document, that person is going to be persuaded by authorities to betray you. And if that person is you, then obviously you're caught at this point. Your face is probably on Facebook, and facial recognition software is getting pretty good nowadays. In general, physical ops are the most dangerous of all ops, and should be avoided until every other avenue has been explored. Better to anonymize your cash (which is also a physical op) and then use that cash to rent a single remote server.

You can't anonymize your cash for digital transactions given sufficient effort being expended to find you. If you don't do physical ops, you aren't paying cash. If you aren't paying cash, they will find you because the banks [which are intentionally letting things slide to increase business] can't hide it from the regulators forever. They've proven that repeatedly with billion+ dollar fines.

Honestly, it doesn't matter tho. I have no real interest in hiding to that degree. Everything I do is legal. :P Its just a fun mental exercise to me.


This is a perfect illustration of how to get busted. For example, the whole idea of "How can I acquire a burner phone?" is misguided, because as soon as you speak into a burner phone, your voiceprint alone is enough to identify you.

Various assumptions like "I doubt it's that easy" are also the road to getting busted.

Trying to forge or steal legal documents, let alone a license plate that you drive around with and which officers can notice at any time, is also how to get busted.


I'll have to take your word for it. I'm pretty sure you are overthinking this tho.

What you are describing is basically:

1) They find the server [this likely takes months based on their performance so far].

2) They get a copy of the paperwork & server [fake id, so useless information on it and a fake picture. That is assuming they keep a copy at all, they might not.]. Server is commodity and basically untraceable. They trace you via license plate readers to a residential neighborhood with 1,000 people.

3) They see you leave a month later via license plate reader on a major freeway and somewhere along the way you disappear because the entire country isn't monitored, especially rural highways where there aren't traffic cams. You change your license plate in the middle of nowhere.

4) They somehow detect the license plate change and track you from there to your new destination.

I mean its possible, I just don't see it as being likely given how hard they've worked to find people who made publicly visible glaring errors. :P


>They find the server...

I doubt you could host a large scale operation on a single server. Given the volume that SR1 && SR2 received, you would need more servers at some point. At that point you either need to hit up craigslist again or host via cloud providers. (of course all of this is assuming that the first guy you met on craigslist was not an undercover agent).


> I doubt you could host a large scale operation on a single server. Given the volume that SR1 && SR2 received, you would need more servers at some point. At that point you either need to hit up craigslist again or host via cloud providers. (of course all of this is assuming that the first guy you met on craigslist was not an undercover agent).

Given I've bought servers for cash on craigslist, I doubt this is really an issue.

You are making a large number of assumptions that in real world situations aren't likely.

They'd need to:

A) Locate you. Assuming good opsec, you'd move and so forth if they imaged/seized your servers and you were aware of it. B) Seed craigslist across a large enough area to catch you.

Hell, you could just move to Canada on "vacation" and pay cash to rent a room up there as well as buy servers in Vancouver or something.


I'm probably naive, but any computer a crack-head customer can find, can not be rocket science for the FBI to find. Right?


It's an open question whether Tor has been compromised to the point that it's now trivial for authorities to locate where darknet websites are hosted. I'm simply making the observation that if your opsec is good enough, you shouldn't need Tor's hidden webservice capability to protect you. You could simply run your website as a standard .com website, except for the fact that authorities can take the .com domain from you.

Or, put another way, if you're relying on Tor's hidden webservice capability as your sole defense, then you're in a bad position.


Learn about Tor. A key distinction is that the "crackhead" Alice is only communicating with the "pusher" Bob, but the location of Alice and Bob is a secret.

http://en.m.wikipedia.org/wiki/Tor_(anonymity_network)


One potential long term outcome of these highly publicized fed / darknet busts is that future operators will learn from the opsec mistakes of Dread Pirate Roberts, Blake Benthall, Sanu, Lulzsec, Anonsec, etc. Theoretically after enough people cock up, the 'playbook' on how to run a dark service / h4x0r group should be sufficiently fleshed out and there will be fewer and fewer busts.


I don't think they will.

Remember, the FBI's story about a leaky captcha only came out very recently. SR2 had been running for a long time by then. And there's currently no info about how they found the servers for 414 different onion sites: seems most likely they have beaten hidden service security and can now find most or all of the ones they want. No opsec gonna save you from that.


>No opsec gonna save you from that.

Unless you anonymously rent the server and it contains no information on it that could trace back to you.


>You can't rent a server from a datacenter using bitcoin

Why not? A google search for this reveals several companies who offer this.


It looks like I was wrong about this. Will multiple datacenters allow you to continue setting up new accounts using nothing but bitcoin? If you don't need to provide identification, then this might be an interesting avenue to explore. Thank you for fact checking me.

There's the chance that datacenters will be more inclined to image your server for authorities if you've set up a server using bitcoin and are hosting large amounts of Tor traffic, but at this point we must assume authorities will image your server anyway, so there's no reason not to go this route if it's as good as you say.

You may need anonymous money for other things, but server rental was the primary case I had in mind.


>Will multiple datacenters allow you to continue setting up new accounts using nothing but bitcoin?

I don't see how they could stop you. None of the btc hosting sites I've seen ask for real ID (passport, drivers license, etc..) They also allow you to rent by the year, though I suspect you would have to scale up fairly often. Overall though, I think anonymous hosting wouldn't be a problem (tor + ssh + tumbled btc).

The server imaging is a tough problem, however, as long as you ensure that you never upload any info that could point back to you, you should be anonymous.

Hopefully a truly decentralized marketplace will emerge before the next bust...


perhaps the darkmarket fork https://openbazaar.org/


>> [TOR] does not hide the total volume of traffic that must be delivered. And it can't.

But what about I2P [0]? To my knowledge, it can hide much more than TOR does, including the amount of traffic going through your server. You get a large amount of traffic even if you do not host anything, because you become a relay node.

[0] https://geti2p.net/en/


What kinds of discussions, exactly, get autokilled on Reddit?


I just tested it. It looks like I was incorrect. People told me that Reddit shadowbans you if you create a new account using Tor. Maybe that was the case for awhile, or maybe it's true for a certain subreddit, but it doesn't seem to be true anymore. Thank you for fact checking me.


Hi dang. Someone downvote bombed a conversation I was having with some fellow HN users: https://news.ycombinator.com/item?id=7726544

All the comments below that link had a downvote except one of mine. I tried to correct it, but I use Tor. I noticed when I tried to upvote the comments that upvotes from Tor users don't actually register. This makes sense, because allowing access from Tor will make it too easy to create sockpuppet accounts that game the system. But I was wondering if I might be able to be granted an exception based on good behavior? If it's not possible at the software level then don't worry about it, I understand. It's an unfortunate fact that Tor citizens won't be able to fully partake in HN, but it seems like that's the price of anonymity (and it seems like a reasonable one too!)

I was also wanting to check with you: has Tor caused the mod team many problems? I'm hoping that by setting a good example, I can convince others that it's possible to allow strong anonymity to good effect in a community. So I'm crossing my fingers that Tor will continue to be allowed on HN. (Thank you from the bottom of my heart for resisting the urge to ban it from the start.)


Happy to look into it, but please send support requests to hn@ycombinator.com, so as not to dilute the threads.


A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge those by hand." https://news.ycombinator.com/item?id=7609780

In fact, it turns out the future is probably headed in that direction. All mobile phones are already compromised; every phone has a proprietary baseband chip with full remote DMA access that no amount of open software running on your phone can stop. And as laptops become more and more mobile, it's going to seem strange that we've spent so long trying to tether our mobile phones to our laptops. Perhaps future laptops are going to have 3G access embedded right into them which consumers can subscribe to for some low monthly fee. Consumers would probably love it, because it's very enticing: you get internet access in most of the world without having to find a public hotspot or tether your phone. No more dealing with hotel wifi; no more dealing with logging in to someone else's.

The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. Desktop computers aren't ever going to go away, but hardware design seems to be trending towards having built-in theft prevention. One feature of theft prevention is having the ability to locate the computer, or send it remote kill signals. If trends like that do catch on with consumers, it's "gg no re," because once our hardware is compromised to the point of third parties being able to remotely access it on demand, we've all lost something precious, and there won't be any opportunity to fix it. The more I think about it, the more it seems like it's just a matter of time until this happens, precisely because once it's here, it's never going away.

More and more network adapters seem to have DMA access to your computer. It would be interesting if the protections afforded by open source software were defeated at the hardware level without most people noticing. There doesn't seem to be any way to defend against it, because open source hardware simply can't survive: no money is necessary to develop open source software, whereas large investment would be necessary for development of open source hardware down to the chip level.


> The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to.

If your adversary is a well funded government you need to have:

Secure software

Secure firmware

Secure hardware

Secure staff who follow procedure

Secure location

Armed guards

Etc

Most people can not do all of this and this have been vulnerable to governments for a long time.

Suggesting that your mobile communications data was ever secure when it was available to your telecoms provider seems odd to me.


> The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to.

This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion.

> More and more network adapters seem to have DMA access to your computer.

With an IOMMU (VT-d or equivalent on other platforms), it should be possible to protect against malicious DMA from any source.

Also, not all phones have basebands with DMA access to main memory. I think iPhones do not, though I am not sure, and some older iPhones have been attacked by turning on "auto answer", demonstrating direct access to the microphone.


Unfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted.

This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion.

Today you can use OS's such as Tails to prevent most exploits from embedding themselves into your computer. This is what Snowden used, for example. But if hardware becomes compromised, Tails will offer much less protection.

Here's an interesting section of the article:

The department must describe the computer it wants to target with as much detail as possible. For example, an investigator may be covertly communicating with a suspected child molester and know an IP address, and then obtain a warrant to use malware to find the actual location. In the case of botnets, malware might be used to try to free the compromised computers from a criminal’s control.

Imagine if child molestors begin using Tails. The government response may be to try to set up some kind of "Tails dragnet" via compromised network interfaces. It should be possible for a network adapter to detect that Tails is running. At that point, since it has DMA access, and since few people use Tails at any given time, it should be possible to instuct a network adapter to search through a computer's memory for evidence of activities that the government doesn't like. Since Tails offers strong anonymity protection, there's no way to describe a computer "as specifically as possible" other than to say "it's running Tails while watching child porn."

The unfortunate conclusion is that in the future, someone like Snowden might immediately be caught. "If someone is using a strong anonymity tool and GPG to hide their conversation, we should probably configure their network card to monitor their activity."

Once hardware begins to turn against you, there seems to be nothing anyone can do to protect themselves. Encryption doesn't work against an adversary that has access to your computer's memory.


"strong anonymity tool and GPG"

just thinking, the problem, it seems, is that end-to-end encryption is not really end-to-end. the user is the endpoint, not the computer.

from a ux point of view, a dongle between screen / keyboard and computer for an encryption overlay could be a way to unambiguously protect information - so information never exists decrypted in a machine.. just the screen.

user input-output accessories are much more technologically static than software / hardware, so an open-source hardware solution may be possible?


>The unfortunate conclusion is that in the future, someone like Snowden might immediately be caught.

I think that is too naive. Snowden types don't assume they won't be caught, they probably assume that it is only a matter of time until they are caught, and play the cards they have in such a way that you make it really hard to send your garden variety cia/dia/spec ops/defense contractors out on a pick up operation not only only from a feasibility standpoint, but from a geopolitical stand point (e.g. What will Beijing's/Moscow's/D.C.'s response be if we run such an operation in their front yard? What precedents might we be setting?).

Also to note that offensive/defensive technical capabilities aren't as asymmetric as they appear for all possible targets of nation states, some yes, but probably not as much to those with the technical knowledge who can create/use such and derivative systems which might very well be other nation states (or appearing to originate from such).


Also to note that offensive/defensive technical capabilities aren't as asymmetric as they appear for all possible targets of nation states, some yes, but probably not as much to those with the technical knowledge who can create/use such and derivative systems.

If you concede that your computer has a chip with DMA access which can be used by the government, then you must concede that the same chip can monitor you for activity that triggers active surveillance. For example, I think Tails is going to force governemnts into monitoring at least which operating system you're using. There's no way to target a specific Tails user, so the only recourse is for the government to do dragnet surveillance of everyone using Tails, or ignore the activities of those using Tails. Since the latter seems politically untenable, the former is becoming more likely with time. When the government can passively check whether your activity is fitting the pattern of some kind of criminal activity, the situation is about as asymmetric as I can imagine. Is there really any technical knowledge that could protect you?


>If you concede that your computer has a chip with DMA access which can be used by the government, then you must concede that the same chip can monitor you for activity that triggers active surveillance.

Whats DMA access? Direct Memory Access access?

That aside, I'm not willing to concede that across every computer than has been/can be built and be exploited by a government out of the box remotely [because dragnet] (most of them, I will concede probably can though, and conversely anyone technical enough can probably exploit many systems in the same way for their own means[don't trust your spouse/freinds/employees?, bug them with remote backups of data to analyze in real-time, hell, companies do such things now as-a-Service]). But continuing on with your conclusion of a dragnet (which is more or less present today), access isn't really the problem, but you have a signal and a noise problem, wherein you will have false positives and false negatives. Text book example of the mal-possibilities is the NSA providing data which led to the targeting phones in the ME, which drone strikes we're initiated and hit innocent civilians[0]. Just wait when we're at the point when this is happening within a countries national borders by domestic agencies, one day, someone is going to be taken out that wasn't meant to be taken out. Can't ignore the false neg/positives forever, though governments seem to try very hard to do so. I think corporations are more forthright about the extent the data they collect is able to be used because if you knowingly contract/ utilize bogus data for certain applications, someone else will eat your lunch eventually.

>activity is fitting the pattern of some kind of criminal activity

From a predatory-prey/evolutionary standpoint, criminal activity is always evolving (typically every living being and the systems they rely on are). Not to mention the time sensitive nature of these systems that do the analysis so if $criminal_activity is always changing and over a defined period of time, you risk that you will get no signal for those who conduct such $criminal_activity in less than the defined period of time or that by the time the analysis has been done, or any signals collected from such device will be moot (i.e. computer was destroyed, thrown away or even worse: passed along to/associated to someone else which also means any point there after associated with such systems is akin to going after a ghost within the machine).

>Is there really any technical knowledge that could protect you?

Well since the focus is on tails [but mostly on the dragnet], one can clone the sc[1] and go through it for what could possibly define one as a Tails user, replace that with something else, build their own image and voila, you just avoided being in the dragnet. The thing about dragnets is that they can only really capture the lowest common denominator, deviate only slightly from that, and the adversary will have to expand resources going for an targeted operation (any adversary, not just nation states is technically possible of doing these things and by definition not a dragnet). This is what happens today. Not in some far off distant dystopian future meant (intended or not) to invoke fear in the ignorant/lazy. Yes if one wants to avoid being in a dragnet with some of the tools they use, then one will take the steps necessary to keep such information obfuscated/opaque from the dragnet.

[0]: http://www.policymic.com/articles/16949/predator-drone-strik...

[1]: https://tails.boum.org/contribute/build/


Whats DMA access? Direct Memory Access access?

This is what happens today. Not in some far off distant distopioan future meant to invoke fear in the ignorant/lazy.

Why not talk with me without the snark? This topic seems like it interests you a lot, so it seems like we have some shared ground.

one can clone the sc[1] and go through the source code for what could possibly define one as a Tails user, replace that with something else, build their own image and voila, you just avoided being in the dragnet.

This won't work because it's extremely difficult to analyze your network card and discover its behavior, and without this knowledge you'd be changing things blindly. There are far too many ways to detect an OS to change them all. Tweak-and-recompile would work if they use a naive and brittle heuristic like "look for the first 64 bytes of whatever is loaded into memory when Tails is booting up," but they wouldn't employ such a brittle heuristic in the first place because every time a new version of Tails is released, they'd need to update their entire infrastructure to look for a new pattern. Something like monitoring the network traffic for a unique "Tails signature" is more likely in this scenario; for example, how many computers start Tor immediately after a network card is connected? Detecting that condition would be a decent starting point for detecting Tails, and they'd want to combine it with some other hard-to-evade condition to cut down on false positives without introducing false negatives.

One interesting way to detect that someone is using Tails would be to notice that their system clock is set to UTC time. Most of the computers connected to the internet aren't using UTC, so UTC time plus Tor usage on startup is pretty commonly associated with anonymity OS's. That said, it seems like it might be difficult for the network card to detect whether the system clock is UTC time, but it's just an example of how difficult it is to fully conceal your usage of an anonymity tool. It's not just a matter of tweaking the source code.

This seems to prove the seriousness of this threat, though. Once you agree that it might be possible for your network card to be your adversary, there are endless ways that it can be used to defeat you. Hardware manufacturers have evidently been thinking along these lines, so why shouldn't we try to think of ways to prevent this from happening? As the BIOS exploits have shown, that dystopianic future may be closer than anyone's comfortable admitting.

EDIT: Someone went through and downvote bombed our whole converastion on both sides... I tried to correct it, but it looks like upvotes from Tor users under a certain karma threshold aren't registering, so I wasn't able to help fix it.


>Why not talk with me without the snark? This topic seems like it interests you a lot, so it seems like we have some shared ground.

>One interesting way to detect that someone is using Tails would be to notice that their system clock is set to UTC time. Most of the computers connected to the internet aren't using UTC, so something like that is pretty commonly associated with Tails. That said, it seems like it might be difficult for the network card to detect whether the system clock is UTC time, but it's just an example of how difficult it is to fully conceal your usage of an anonymity tool. It's not just a matter of tweaking the source code.

It's not out of snark (I apologize for if it sounds like it, not intentionally seeking to offend anyone), but mainly out frustration about the conversation on how everything seems to be so difficult. Difficulty to whom? Someone who cannot modify sc to a significant extent? Someone who just downloads the program and expects it to just work? Not just some random tweak, I mean going through looking at what the functions actually do, which remote connections do they rely on to connect to at various stages, how data is generated and allocated in memory, what system calls are made, etc and change it according to ones threat model so that the program one complies has the same functionality but is not recognized as the same program. Maybe that involves changing the the system time. Again, trying to target someone doing such is trying to target someone actively adapting, probably faster than it takes for the dragnet to adapt since like I said, dragnets mainly hinge on effectively going after the common denominator that of which is usually of the mind set of someone who downloads/uses a program system and expects it to just work and address all of their concerns without doing anything themselves. In the end, anyone can try all they want to cut down on the false negatives and positives, but they will still exist and that's where the "real" danger comes from for groups/orgs/gov's that go to such extents.

>Once you agree that it might be possible for your network card to be your adversary, there are endless ways that it can be used to defeat you.

If this is really in one's threat model, one is probably throwing away or using shared computers before this point… maybe from within a virtual machine on a large banks network from an exploit one used (remote, or local).

>so why shouldn't we try to think of ways to prevent this from happening?

Few people do this today for themselves, most others do not. People today seem to have come to expect that someone else needs to protect them which must have fmr cyhperpuks laughing. As far as I'm concerned, we are already living in the dystopian future, and the few who take the steps to mitigate based on their threat model do. These issues have been around for a while, and those who cared all along took steps they felt were necessary to protect themselves and still do. Maybe that involves not taking advantage of the latest skinner box of the day, again tradeoffs and threat models to consider. And those now made aware have to learn a lot to put themselves in the same shoes, if they even care enough to learn what they need to start protecting themselves and to continue to adapt to do so. Again, its not like BIOS exploits suddenly became possible because snowden profiteers told us and because all of this I don't think it really is a serious threat (any more than it already was) because your adversaries are opening themselves up at the same time. This has always been an evolving landscape. Such is the world we live in and have always had.

Edit: No worries, as I've learned over time, down-voting isn't really effective for silencing ideas/discussion since it just attracts more interest to those who want to seek such information.


> projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted

That iPhones used to completely trust physically connected devices without any verification was obvious to anyone paying attention even before it was verified at Black Hat USA 2013 [1]. This was fixed in iOS 7. The evidence we have of DROPOUTJEEP says it is installed via "close access methods" [2]. I wouldn't be surprised if remote vulnerabilities exist that could be used to install it remotely, but I am aware of no public evidence that they are being exploited now.

1. http://www.zdnet.com/researchers-reveal-how-to-hack-an-iphon...

2. http://www.zerohedge.com/news/2013-12-30/how-nsa-hacks-your-...


> Once hardware begins to turn against you, there seems to be nothing anyone can do to protect themselves. Encryption doesn't work against an adversary that has access to your computer's memory.

In the future (or today, depending on your setup), IOMMU. In the present, there is no evidence that baseband backdoors of this type actually exist (as opposed to hacks). When the adversary adds backdoors deeper in the hardware? ...well, we'll see if that is discovered someday.

To editorialize a bit, I guess it can't hurt to worry about and try to head off anticipated future threats - it's not like anticipating different threats is mutually exclusive - but still, I somehow can't shake the feeling that people's emphasis on secret backdoors unduly weights threats that are easier to romanticize over more pragmatic but more dangerous ones.


The reason it's good to proactively think of future threats is because so many past concerns have proven to be true. Several months ago, no one on Hacker News really believed that BIOS backdoors were much of a threat. But today it's a well-established fact, for example.

The tools of law enforcement probably aren't going to be revealed, and they're hard to discover. Nobody knew about the zero-day exploit employed against Tor browser, for example, and there are almost certainly many more tricks like that up their sleeve. They already take steps to conceal them; parallel construction is an unfortunate reality. And since there's not much justification for a whistleblower to reveal the techniques, it's unlikely someone will come out and talk about them. We'll probably need to think along the lines of "What's technologically possible, and how is it useful to law enforcement?" It's not a good idea to wait until a weapon is used before thinking about how to react to it.

The history of communications technology and how governments have reacted to the technology is actually quite fascinating. Wiretaps used to be extremely commonplace, and since there's not too much legal protection from the government rifling through your digital life at will (at least compared to getting permission for wiretapping your phone), it seems like it's better to err on the side of caution.

It's also important to realize that even though some governments follow due process, several powerful ones don't. Also, there are other global other considerations. The US has made it pretty clear that their legal restrictions are designed to apply to US citizens, not any foreign person. You may be forced into a situation of choosing which governments you'll trust, especially when cross-nation collaboration becomes even more pervasive. Assuming that other countries adopt a similar attitude of "Our citizens are protected; other citizens are examined," then the US may simply outsource their databases of information to be examined by some other government, like any other member of the Five Eyes.

I understand your concern and skepticism though. It was a question I've often wrestled with myself.


  Nobody knew about the zero-day exploit employed against Tor browser,
  for example, and there are almost certainly many more tricks like that
  up their sleeve.
I had actually been patched already upstream, so it was not really a zero-day. I'm not sure if it a patched Tor Browser Bundle had been released and people just hadn't upgraded, or if the patch hadn't made its way to the bundle yet.


> This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion.

Bingo. Even if you go all-out with security and only browse the web with a pure text web browser through Tor running on a VM that you purge after every use, use full-disk encryption with plausible deniability, fully shut down your computer and wait until the RAM is cool before leaving, inspect your computer for NSA/other implants every time before boot, tape your webcam and mic, never use your real name, and whatever else you can think of, you're just going to go nuts from all the paranoia, as well as from realizing all the myriad ways your security could still be broken (don't forget to check the keyboard for a built-in logger and look inside your case for PCI cards you don't recognize, and hope they don't have any implants that look convincingly like something you'd recognize as yours). Never mind that this isn't a very viable way to do most things most people actually use their computers for, like personal email, online banking, social networking, and so on.


The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to.

The government has always had access to everything if they a) really wanted to and b) had just cause. That's why search warrants, tailing suspects, court-approved phone taps, bank account freezes, etc etc etc exist.

The notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent.


The notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent.

I didn't intend to argue that. I'm saying that strong anonymity OS's like Tails will force governments to do dragnet surveillance using compromised hardware in order to track suspects down. There is no way to tailor surveillance to an individual using Tails, because it's set up to hide your IP address at the OS level (assuming Tails is implemented correctly).

Assume child molestors begin using Tails or whatever environment that prevents FBI browser exploits from working. What then? There's one recourse: the government can set up your network card to monitor when you're using Tails for unlawful activity. And since it's very difficult to come up with a "footprint" of an individual Tails user, i.e. some way to monitor or attack one specific individual, this is likely to force the government into monitoring all activity. This can be done via compromised hardware, like a network card, which can be remotely configured to monitor memory for specific trigger conditions like "user is running Tails, and main memory contains specific terms for underage children."

Sure, it sounds unlikely right now. But this is the general direction that technology has been headed in. How much ground should we concede in this debate? Is it ethical for a government to be able to subvert someone using strong anonymity tools if it forces them to broadly target everyone using such a tool?

More broadly, what mechanism should we approve of the government using to inject your computer with code? If the government has DMA access to everyone's computer, then that hardware could be configured to monitor which operating system you're using, and only triggered into actively targetting you specifically when certain conditions arise, such as using a strong anonymity tool, or a certain specialized browser that child pornographers also happen to use. Should the government be allowed to be proactive in its hunt for offenders? Are we comfortable with a hardware device watching which OS we're running? There are a lot of issues that seem worth thinking carefully about.


Yeah, it is a damn tough question. Criminals have more tools than ever for operating under the radar, so restricting agents to traditional rules for investigation & surveillance seems like a mistake. But on the other hand, how do you grant increased surveillance capabilities to counter increased covert capabilities, without ruining privacy? Basically, it's like privacy is caught in the crossfire.


Criminals have always had lots of tools available to them; by definition, they aren't restricted by law, which opens up many possibilities not available to the rest of society. Nobody ever said police work is (or should be) easy.

Despite that, the answer to how you grant increased surveillance capabilities is easy: you get a warrant.

It isn't a terribly difficult bar to reach - judges will hand out warrants quite easily. We - the citizens - just ask that those asking for such capabilities ask for them (each time...), and at least show they have some minimal sort of reason to want such easily-abused capabilities.

Requiring the warrant therefor shouldn't slow down legitimate investigations more than a trivial amount. If enforced, on the other hand, it does act as a "limiter" to sweeping abuses.


> Perhaps future laptops are going to have 3G access embedded right into them which consumers can subscribe to for some low monthly fee.

The future is now.

http://www.dell.com/learn/us/en/19/campaigns/4g-3g-mobile-br... http://www.amazon.com/Samsung-XE303C12-H01US-Chromebook-3G-1... http://www.bestbuy.com/site/mobile-phones/mobile-broadband-c...


> Perhaps future laptops are going to have 3G access embedded right into them which consumers can subscribe to for some low monthly fee.

We're getting bit off topic here, but my colleague has a 2-year old Sony Vaio laptop that has this. He also has a SIM card for it that came for free with his €50,- internet/tv subscription (incl more monthly GBs than he needs).


No software running on your x86 chip can stop System Management Mode.

http://en.wikipedia.org/wiki/System_Management_Mode


I don't know what "gg no re" means.


Not really. They don't have a way to change their laws. It's Putin's Russia.



If that were strictly true, then SOPA would have passed.


How is the temporary shelving of SOPA proof that on over 1700 policy issues US citizens have essentially zero chance of affecting the outcome of the legislation?

As for SOPA - say hello to SOPA 2.0 http://www.uspto.gov/news/publications/copyrightgreenpaper.p...


How is that SOPA 2.0?


Try reading it. Or at least searching for the report which is commonly referred to as SOPA 2.0 by various opposition groups.

In essence however, SOPA in some form will pass and this document represents a new approach.

As someone posted before - it does not matter if it is SOPA 14.0 or SOPA 22.0 - it just needs to pass once. Very few examples of legislative repeal exist outside of social equality.


The report didn't claim the great Corporation of the Elites are omniscient and omnipotent; just that 'they' owned all Intellectual Property rights, and that We, the People, must offer remittance for air.


Agreed. It is actually a really bleak and depressing read; I am certain the UK is not much different at all.

Future dystopian writers can certainly draw upon it as a non-fiction source.


How would you verify on demand that the BIOS isn't compromised?


I don't know about "on demand" but PCEngines will give the source for the BIOS and has an older version posted to the site. http://pcengines.ch/tinybios.htm


What I mean is, how would we verify the BIOS firmware matches what that source code should produce? If it's possible for us to make our own builds (i.e. there's no cryptographic signing for the BIOS binaries) then an adversary can insert a backdoor into the source code, make their own build, and then remotely flash your hardware with it. Or does flashing the hardware require some kind of manual operation, like holding down a button for 30 seconds?


Could be the processors as well, better to forge the chips by hand to be sure.


With the advent of cryptocurrencies, we're finally in a place someone can pay me to use a portion of my infrastructure for enabling their anonymity. I'm willing to contribute to the cause as long as it's worth my while.

Your infrastructure will immediately be used to download or upload child pornography. If you're exceptionally unlucky, the FBI will come knocking and, if you're unable to provide them with a useful honeypot, you may risk legal consequences. If you're unable to prove your innocence (the request for the CP did come from your IP address, after all) then you may be very screwed.

I invite the community to toss around ideas about how to protect against this. I hypothesize that it's an unsolvable problem: if you enable strong anonymity, that anonymity will immediately be used for child porn.

One way to combat this would be to have some kind of credentialing, where you are able to generate credentials for the anonymous party to use. Assuming your infrastructure is set up as a Tor hidden service, then it's possible for them to use your infrastructure anonymously, and then you can revoke the credentials for individual violators.

However, under that scheme, your IP address(es) are shared by every user. 4chan will immediately ban all of them as soon as it becomes clear you're a proxy, for example.

It may still be worth exploring, but it needs some thought. Tor itself still doesn't have "endpoint bridges," that is, endpoints which aren't publicly listed. Meaning it's very easy to ban all of Tor, as far as I know.


"I invite the community to toss around ideas about how to protect against this. I hypothesize that it's an unsolvable problem"

I'm not sure if you would count this as a solution, but, conceivably you could "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud ?

This is fast enough for speech. It is not fast enough for any kind of multimedia that would be acceptable in 2014 and beyond. It might be a barrier that would cause all bad guys to use other networks, but still allow the kind of "freedom" that we're all convinced twitter gives us (and so on).


Could you "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud?

What a fantastic idea. This seems worth pursuing. It should be possible to configure a modern browser to work with low bandwidth: HTML/CSS/JS would load, but images and other media wouldn't. Is there any reason why HN, Reddit, Twitter, webmail, and other services like IRC wouldn't be usable under those conditions?

It seems like people might be much more willing to rent out their infrastructure to anonymous parties strictly for those purposes.


I would love to see someone try to use HN at 9600 bps. That's bits per second, so 9600 / 8 = 1200 characters per second, roughly.


I used all of those things - irc, the web (gopher), etc., at 9600 baud for years. Wasn't a problem.

Also, you don't really need to configure a browser - just use lynx, which will ignore most of the bandwidth hungry aspects of a site.


When we used the Internet at slow speeds or in batch mode we had people being cautious with bandwidth. Usenet had the informal McQ limit for signatures, which led to newsgroups like alt.fan.warlord to mock people with big or ugly sigs.

The text on the current top story (the Wright Brothers article) is about 11kbytes. That doesn't include any html or css or anything else. That would make a page load at over ten seconds just for the text.

The point isn't that it can not be done, but that people would not tolerate it unless they had a real need.


I regularly use links (as opposed to lynx) to access text heavy sites; nice, clean, distraction-free reading.


I stuck with ~30K bps a lot longer than was reasonable (it's still been years...). HN would be fine, a few seconds waiting for a few minutes reading. Megabyte js monstrosities were the problem, they would time out.


> unable to prove your innocence

Here's the issue. Return presumption of innocence back and problem's solved.

Obviously, that's impossible in a real world.

> credentials for the anonymous party to use

That wouldn't be anonymous anymore. And there's no way to realistically force a single human to have only one credential - if one's banned they'll just generate a new one.


It could be possible to enable someone you trust to use your infrustracture. You don't have to know who this person is. For example, this devconsole HN account that I'm using now is an anonymous HN account, meaning as long as Tor is secure, and I don't reveal myself through e.g. text analysis or timing correlations, it should be hard to figure out who I am. If I were to come to you and ask to use your infrastructure to help me maintain my anonymity, you may read my comment history and decide that you trust me not to do illegal things. Providing such a service would be extremely valuable, because if Tor is indeed not completely impervious, your extra layer of anonymity may be all that preserves one's privacy.

If an authority were to come to you and demand you cooperate in determining my identity, then there would be no way for you to oblige, except by providing them with a log of the VPN activity, or allowing them to set up a pen trap to log the VPN activity. At that point, the privacy is still as strong as the Tor network, so both Tor and this extra layer would have to fall in order to be unmasked.

(In practice, it's more complicated than that: your infrastructure would be a fixed endpoint, meaning that if it's compromised then an adversary would gain a log of your activity. That would provide an overall picture of what you're up to on the internet. Tor rotates endpoints, making it hard to piece together that info. So in practice a user should want your service to be something like a middleman between two different anonymity services. But that's outside the scope of this comment for now.)

This becomes a pretty attractive idea, because it's not necessarily a great idea to assume that Tor should be the world's one realistic defense. Since Snowden used Tor, you can be absolutely certain that various powers are going to take a keen interest in penetrating Tor. They may use dirty tricks to do it, such as joining the Tor project as an apparently-trustworthy developer.

Extra layers of defense such as the one outlined above may be worth pursuing.


> It could be possible to enable someone you trust to use your infrustracture. You don't have to know who this person is.

Am I the only one to whom this sounds absolutely crazy? How can I trust you if I don't know who you are? (I mean the general you, not you personally, devconsole.)

Your comments could have been deliberately sanitized -- perhaps you have trolling accounts elsewhere that you are exceptionally good at keeping separate from this one, and spend time making this one look good. One could be posing as a mild-mannered Python developer here on HN, but be spending one's evenings being Super-Mallory the Malicious, trolling and trading illegal information.

I really want to be able to support things like mesh networks and Tor, but the very risk the GP noted (people will use your resources for Bad Things, and good luck defending from the feds) prevents me from being willing to do so. There's no way I would trust you or someone else that I don't personally know enough to use my resources, unless I were somehow able to keep meticulous logs which exonerate me from any activity they do. (And, I don't trust that such logs would even do that...)

Saying that you should be able to trust a stranger is like saying that you should be able to run a courier service for strangers where you have no idea whether they are transporting drugs or counterfeit money.


> Am I the only one to whom this sounds absolutely crazy? How can I trust you if I don't know who you are?

Well, cryptographers had invented a fancy thing called "ring signatures" that allows one to check whenever a signature belongs to someone in a group, but don't allow to determine who exactly that was. So, technically, it's well possible to remail anonymous (as far as belonging to a group does not break your anonymity) and be trusted at the same time.

But, unfortunately, I don't think F2F mesh networks would prosper anytime soon.


While I don't disagree with you, at least in the UK, possession in a cache and in some circumstances, transmission of child abuse images is a strict liability offence, meaning intent doesn't come into it - I suspect it's the same in many jurisdictions. It's a ridiculous position, but it's still the reality for many.


Are there any actual cases where someone was found guilty just for operating a computer/router/whatever that relayed information?

What is a piece of legislation says and what is actually "law" is often not the same, as the courts can interpret it however they want.


There are a couple that stick in the back of my head, but I can't remember the names - I'll try and dig them out when I get home next week!


I think our ability to communicate privately as a society at large is more important than the issues of child pornography or terrorism, both of which have policing avenues besides pervasive monitoring and tracking of all associations and messages through communication networks.

But yes, we should think of the children, 9/11, etc.


It's worth noting that Tails doesn't make you impervious. Tails uses Tor, and Tor is vulnerable to NSA and GCHQ attacks. Specifically, they have the capability of deanonymizing individual targets. I hypothesize that this capability works by monitoring Tor traffic worldwide, then performing a timing correlation between an origin and an endpoint.

Here's an example: Let's say (for the sake of example please) that the NSA can passively monitor Google searches in realtime. Let's say you search for a phrase that sets off their monitor: something like "a Tor user has Googled for Snowden." They'd like to know who you are. How would they do that?

One way is to record the fact that from your home computer originated some Tor traffic at almost the same time the Google search took place.

It's unclear exactly how they deanonymize Tor users, but one piece of info that may corroborate my hypothesis is that in a Snowden screenshot, you can see the NSA has a tab called "Tor Events" in one of their tools.

The need for websites to load quickly is Tor's Achilles heel, because it enables timing correlation. The fact that few people use Tor exacerbates the problem.


I think you mean to say that users of Tor are potentially vulnerable to NSA and GCHQ attacks. Specifically, they lack the capability to deanonymize individual targets upon request and according to the slides leaked by Snowden they are only able to deanonymize a very small fraction of the traffic and usually have to rely on attacking surrounding software, such as the Firefox browser bundled with Tor.

http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack...


https://tails.boum.org/doc/about/warning/index.en.html#index...

"Tor doesn't protect you from a global adversary

A global passive adversary would be a person or an entity able to monitor at the same time the traffic between all the computers in a network. By studying, for example, the timing and volume patterns of the different communications across the network, it would be statistically possible to identify Tor circuits and thus matching Tor users and destination servers.

It is part of Tor's initial trade-off not to address such a threat in order to create a low-latency communication service usable for web browsing, Internet chat or SSH connections.

For more expert information see Tor Project: The Second-Generation Onion Router, part 3. Design goals and assumptions. [https://svn.torproject.org/svn/projects/design-paper/tor-des...


> One way is to record the fact that from your home computer originated some Tor traffic at almost the same time the Google search took place.

This either implies someone already suspects you and are monitoring you or that you are the only person searching on Google using Tor at that particular moment. I find the latter hard to believe. Even if it is true, it can be mitigated by more people using tor at the same time.


You might want to run a non-exit node at your home. That way you have a lot of Tor traffic all the time, and the one time you really do need anonymity, it doesn't show up as anything unusual.


I don't quite know how this works, so forgive me if this is a stupid question, but couldn't someone just take the difference between your inbound and outbound tor traffic to find how much traffic originates from your computer?


If the in/out rate of your bridge was both constant And lower than the max in/out rate of your connection, but it seems a bit of a stretch.

(And of course they wouldn't know that it was your traffic to whatever site they're surveilling, they'd just have evidence that was not inconsistent with you actively using Tor to do Something Or Other at that time.)


They might know how much, but they wouldn't know which traffic was yours.


The same is still true even if you do not run a tor node.


They can see all of the packets in both directions. Which mean they could tell when more was coming out than being relayed in.


Yes, because nothing will make you less interesting to law enforcement than running a Tor node.


Google searching no, but an IRC room or being logged into something would be good for metadata. Especially a forum or chat room where you reveal timezone or other geolocation info. "It's snowing here"

Would not take long to grep ISP logs and find the known Tor bridges, Obfsproxy bridges, relays and who might have used them.

If you tunneled Tor traffic through a VPN exiting Russia then your local ISP has no Tor timing metadata to give, unless you're Snowden and your adversary is global. Running an internal relay would help obfuscate your own traffic too if you can connect to it on a local network it would be a lot harder to prove you logged into IRC channel #blowuptheembassy on the Al Qaeda IRC freenode server.


> Tails doesn't make you impervious

For all X, X does not make you impervious. All it can do is increase the cost to an attacker.


Has anyone looked into thwarting timing attacks by using Selenium to run web tasks at random times?


Perhaps the scariest thing is their plan to collect and store all data on all of your activities, then retroactively mine it. That is, from the moment you use the internet for the first time as a 9 year old until the day you die as an 89 year old, every text message you send, every email you write, every website you visit, and (if you're thinking of becoming a politician) every nude picture you send can potentially be used against you.

The reason this is scary isn't just because of the present social climate. The current social climate is actually pretty decent. The reason it's scary is because social climates can change quickly. A couple decades from now, what you did legally today may be illegal. If you're pursued and prosecuted, it's possible someone may dig through this vast trove of collected data and use it against you.

Clapper (the head of the NSA) has taken the stance that it's okay to collect everything, and that a "search" hasn't taken place until some human actually tries to look through that data. He frequently uses the analogy of a library: it's okay for the NSA to have all the books (everyone's data, everywhere) because a search hasn't taken place until they take one of the books off the shelf and look through it.

The temptation to use that library for purposes other than curbing terrorism must be pretty strong.

I'm going to speculate for the sake of example. It was often cited that one of the reasons for the 9/11 attacks was that the agencies weren't cooperating. As such, there has been a lot of pressure for the agencies to work together since then. I'm going to guess that if the FBI hadn't eventually tracked down DPR on their own, they may have tried to turn to the NSA for help. While it's not clear that the NSA has those kinds of capabilities, they're certainly more capable than the FBI at breaching the Tor network. There are slides out there which say something along the lines of "... we're able to deanonymize individual targets, not everybody at once."

That example is a little bit unrelated to "collecting all data about everybody and then mining it," but remember that if the agencies begin cooperating in that fashion, sharing that trove of data may be the next logical step.

I apologize for speculating, and my speculation should be treated as such. But please realize that just because they're not doing that to Americans yet doesn't mean they're not doing it to citizens of other countries with impunity today.

Here's another ancillary point. It should be no surprise that the NSA could probably find out the identity of Satoshi Nakamoto pretty easily. But my point in bringing that up is this: if Satoshi himself cannot stay anonymous, then what hope do any of us have? Anonymity may be dead at this point. It's pretty clear that humans will continue to live even if that's the case, but a world without privacy is going to be a very strange one.

By the way, I should also mention that the GCHQ may be even more capable than the NSA. There are signs that the NSA are better at pulling off attacks (Stuxnet, Tailored Access Operations) but that GCHQ are better at collecting data (bypassed Google's encryption). It has also been hinted that whenever the NSA runs into roadblocks against investigating Americans, they enlist the help of the GCHQ since it's legal for them to do so (and vice-versa). So even if the NSA is reformed, there is still this spectre of this worldwide data collection and governmental collaboration hovering over society.


Perhaps the scariest thing is their plan to collect and store all data on all of your activities, then retroactively mine it

This is the biggest grey area/ major issue. The issue is not just 4th amendment stuff (reasonable expectations of privacy), but selective disclosure and prosecution (ie, equal protection). The use of this for blackmail would be come ~irresistable to those seeking to cling to power. And this kind of stuff is why the bill of rights exists.


The problem is that the selective disclosure and prosecution are very easy to abuse without violating the text of the constitution; especially when the average American commits three imprison-able offences per day, because of the number of criminal laws, and their breadth.[1]

[1] http://online.wsj.com/news/articles/SB1000142405274870447150...


| the stance that it's okay to collect everything, and that a "search" hasn't taken place

Anytime this argument is made, it must be held in contempt, and along with its wanton disregard for logic, be not allowed to stand.

Scenario 1: If Alice sends a letter to Bob unintercepted and Bob reads the letter then burns it, his privacy has not been violated and he has not been searched.

Scenario 2: If Alice sends Bob a letter and before delivery the postman opens the letter, photographs the contents in such a way as to not see the contents of the letter at the time, then sticks the photo in his pocket for a rainy day, then delivers the letter, Bob has been searched.

For any of a number of definitions for searched.

One of which being Bob no longer has control over his personal effects(information), cannot choose the manner in which they are presented to others, or if they are presented at all.

If your option of not being searched has been taken away, you've been searched.

In Scenario 2 Bob's option of not being searched has been taken away, so therefore he has been searched.

It's pretty obvious these bulk collection practices are 'seizure' as well as 'search,' though I've not heard anyone with the audacity to argue that it is somehow not seizure.


> and that a "search" hasn't taken place until some human actually tries to look through that data.

It's actually scarier than that; the term used was 'acquisition' rather than 'search'.

So they collect all the raw data, but don't 'acquire' intelligence until they search for specific information.

Since the legislation pertains to acquisition they are not, by their interpretation, bound by that legislation during collection.


> Perhaps the scariest thing is their plan to collect and store all data on all of your activities, then retroactively mine it

I would even go to say that the NSA already has files on all major politicians in the US and therefore can threaten anyone (including the president) to release something the public would not like (extra-marital affairs, pretty common among politicians, but could be many other things too) and therefore easily coerce the politicians to avoid any significant reform of their mandate.


>what you did legally today may be illegal

In the United States, the Congress is prohibited from passing ex post facto laws by clause 3 of Article I, Section 9 of the United States Constitution.


  *In the United States, the Congress is prohibited from passing ex post facto laws by clause 3 of Article I, Section 9 of the United States Constitution.*
I don't know if you've noticed, but folks in Washington don't give a fuck about the Constitution any longer.


But if that hypothetical law were passed by Congress, people sued under that law would argue that the law was unconstitutional, and any competent court would agree, acquit the person, and strike down the law.


The problem is that laws and clauses of the constitution only provide protection if there is political will to allow it to do so.

The second that the people in power have no actual political will to follow them, the fact that laws exist provides no protection.


Even if there were no political will, the judiciary could enforce the protection, for eg by striking down unconstitutional laws.


Highlights from the slides:

Your CPU chipset is also standalone webserver. Most vPro chipsets (MCHs) have:

- An Independent CPU (not IA32!)

- Access to dedicated DRAM memory

- Special interface to the Network Card (NIC)

- Execution environment called Management Engine (ME)

Your chipset is a little computer. It can execute programs in parallel and independently from the main CPU!

How might we design some malware that embeds itself into the chipset? Such malware would be able to survive reboots, brick the hardware on demand, reboot on demand, act as a MITM for all network traffic, inject vulnerabilities into the host OS during bootup, etc.

Step 1: Search for an attack vector in any version of the Intel BIOS. If you can find any attack vector in any version of the BIOS, you've won. For example, if the latest Intel BIOS is v3.9.2, but you found an exploit in BIOS v2.3.1, you've still won. Because...

Step 2: ... as the attacker, you can downgrade the victim's BIOS to any previous version without any user consent! Any old version of the BIOS is of course signed by Intel; all versions are. The chipset firmware allows any valid signed BIOS to replace the current BIOS regardless of whether it's older or newer than the current.

It was pretty shocking that the BIOS can be downgraded without any user consent. Downgrading requires a reboot, but that's probably not a huge problem in practice.

This article is from 2009, so at this point it's just an interesting piece of history. But I wonder whether any of these issues still persist today, such as the ability for userspace programs to downgrade/upgrade the BIOS at will?


Once you find a bug in certain critical paths, you can write to flash at will, no signatures required. AFAICS some Samsung and Lenovo users ran into one of those when installing Linux.

As for the management engine (the CPU that drives the vPro stuff), it exists in _all_ Intel chipsets since Series 5, vPro is just a certain configuration of its firmware. It also has full access to RAM, some access to USB, network and graphics.



> such as the ability for userspace programs to downgrade/upgrade the BIOS at will?

I assume some amount of privileges would be required to reflash. By "at will", do you mean that once those privileges are acquired, there is no notification or confirmation to the user? (Or perhaps it is easier than I think to reflash.)

Apparently they've added some downgrade protection[1]:

> The recent patch mentioned above solves this problem by displaying a prompt during reflash boot, if reflashing to an older version of BIOS. So now it requires user intervention (a physical presence). This "downgrade protection" works, however, only if we have administrator password enabled in BIOS.

[1]: http://theinvisiblethings.blogspot.com/2009/08/vegas-toys-pa...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: