Slashdot Mirror


FBI Seizes Server Providing Anonymous Remailer Service

sunbird writes "At 16:00 ET on April 18, federal agents seized a server located in a New York colocation facility shared by May First / People Link and Riseup.net. The server was operated by the European Counter Network ("ECN"), the oldest independent internet service provider in Europe. The server was seized as a part of the investigation into bomb threats sent via the Mixmaster anonymous remailer received by the University of Pittsburgh that were previously discussed on Slashdot. As a result of the seizure, hundreds of unrelated people and organizations have been disrupted."

355 comments

  1. What does this help? by Anonymous Coward · · Score: 5, Interesting

    Unless the server was keeping logs, and I presume that it wasn't, how could seizing it possibly help the investigation?

    1. Re:What does this help? by Reasonable+Facsimile · · Score: 4, Funny

      Unless the server was keeping logs, and I presume that it wasn't, how could seizing it possibly help the investigation?

      The files are in the computer.

    2. Re:What does this help? by Wowsers · · Score: 5, Insightful

      It's a clear signal to people that if you run a business and your server is in the US, the US can kill your business stone dead in a raid which may have nothing to do with you other than being co-hosted at a server farm. And people wonder why less business is going to the US.

      --
      Take Nobody's Word For It.
    3. Re:What does this help? by Anonymous Coward · · Score: 1, Informative

      If your entire business depends on a single server you have more pressing problems to deal with. Gremlins are more likely to ruin you than jack-booted thugs. In fact, a Gremlin will on average take down your server once every two years. The odds of the FBI doing that are probably once in a thousand years, all things considered.

    4. Re:What does this help? by cyachallenge · · Score: 5, Funny

      If you remember in some of the pirate bay litigation they actually seized the computer RAM. :) The RAM contained case relevant material (at least when it had voltage going through it. Law and technical computer topics rarely mix well.

    5. Re:What does this help? by Anonymous Coward · · Score: 1

      I'm sure the FBI would be happy to take all of them.

    6. Re:What does this help? by 0123456 · · Score: 0

      You must buy crappy servers.

      We did have to reboot one of ours last year, but that was only because the internal hardware monitoring system was claiming the air temperature was 255 degrees.

    7. Re:What does this help? by Guppy06 · · Score: 2

      and I presume that it wasn't

      Don't presume, verify.

    8. Re:What does this help? by Reasonable+Facsimile · · Score: 1

      If you remember in some of the pirate bay litigation they actually seized the computer RAM. :) The RAM contained case relevant material (at least when it had voltage going through it. Law and technical computer topics rarely mix well.

      Holy crap.

    9. Re:What does this help? by Anonymous Coward · · Score: 0

      Unless the server was keeping logs, and I presume that it wasn't, how could seizing it possibly help the investigation?

      The real surprise is that the FBI wasn't already logging everything that went through it themselves. Maybe we're not being spied on as much as we think.

      Or maybe the NSA just doesn't share with the FBI.

    10. Re:What does this help? by Anonymous Coward · · Score: 1, Interesting

      Citation please (not tryging to be a troll, I'm genuinely interested).

      Either they made a copy of the content of the ram (smart), they tryed a cold boot attack (in which case this is the first time I hear of law enforcement doing this) or they are technically illiterate.

    11. Re:What does this help? by NoSleepDemon · · Score: 1

      Well that's a nice round number, it's when it hits 256 that you really should start to get worried =)

    12. Re:What does this help? by Anonymous Coward · · Score: 1

      There are lots of small businesses like mine that don't have the resources to maintain multiple servers. We only recently got to a point where spending a few hundred dollars on multiple servers might be considered worth while given the costs. Right now we spend $60 or so a month as it is on hosting (VPS) and lots more on phone, Internet, and other services. Small businesses that haven't gotten off the ground can't afford these luxuries. That is not to say there aren't solutions to this problem. But saying all businesses should simply setup multiple servers without regard for circumstances is wrong. My solution was to literally setup our server to compress, split, and email backups of our entire database and web site on a nightly bases to a free GMail account (yes- it is encrypted with GPG first). I started this company with little more than $10 and a roof over my head (parents basement, ok, not really the basement, but still, one room in a residential area). We broke even just this past summer although are doing phenomenal now and future sales are anticipated in the millions of dollars. I'm expecting to see the million dollar mark in the coming months. We have agreements in place that should see our profits rise 100x fold.

      And for anybody who thinks that free software (think freedom, not open source) isn't profitable you are a moron. It can be done and chances are you just don't have any business sense. I'm 27 and founded this company almost straight out of college (I took several months off). I'll admit we are succeeding by leaps and bounds where everybody else has failed.

    13. Re:What does this help? by KiloByte · · Score: 4, Insightful

      or they are technically illiterate.

      From a technical point of view, their action is completely pointless. But from the social point of view, it works. They're sending a loud and clear message: if you try to stand up to your rights, you WILL be trampled.

      --
      The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
    14. Re:What does this help? by evil_aaronm · · Score: 1

      Or some PHB thought it would be a good idea and, at the very least, he could say he tried it. "Leave no stone unturned," you know.

    15. Re:What does this help? by TheCarp · · Score: 2

      You know, we took an outage in our dev lab yesterday when a PDU blew, and took out some fiber that was running next to it. Shit happens...maybe not often, but it does. Any individual server can go, for any number of reasons, some of which are totally outside the server.

      If we are talking about unimportant services, sure... leave it up to a single server. If your business depends on it though? Well then I guess if your business isn't worth keeping up in an outage...then enjoy but... I would consider that important enough to have a couple, in different places.... hopefully in an active/active config but, even a warm spare means being back up reasonably fast.

      Its not about how likely it is...given enough time unlikely events happen. Its a question of how fast you can recover WHEN it happens.

      --
      "I opened my eyes, and everything went dark again"
    16. Re:What does this help? by Nefarious+Wheel · · Score: 1

      As a long-time follower of Groklaw.net, I've read of this happening before. Lawyers trying to seize the wind by asking for a machine's RAM. Not the contents, the RAM itself. Little green sticks. Lovely, no?

      --
      Do not mock my vision of impractical footwear
    17. Re:What does this help? by fustakrakich · · Score: 1

      Say what? The Gremlins lost the war over 65 years ago..

      --
      “He’s not deformed, he’s just drunk!”
    18. Re:What does this help? by mcavic · · Score: 1

      I read that too, but don't have a link. I guess the easiest thing to do would be to dump the RAM from inside the running OS, but you'd need admin access. You might also try warm-booting into a specialized OS, but I don't know if that would preserve the RAM or not.

    19. Re:What does this help? by Anonymous Coward · · Score: 0

      Again, worse than you think it is.
      http://reason.com/blog/2012/02/23/the-great-gibson-guitar-raid-months-late

      Gibson guitar was raided by the feds, they seized half a million in wood, shut down production, and have yet to charge Gibson with anything. They claimed Gibson used illegally imported wood, the same wood used by Fender as well. The difference? Fender guitars gives heavily to the DNC.

      No, it has become you either donate heavily to the DNC or if you are too big you will be shut down. Same circumstances behind Solendra getting $500 million and the Keystone pipeline being denied.

    20. Re:What does this help? by Anonymous Coward · · Score: 0

      You are assuming that a) are competent enough to know what logs a mixmaster keeps and b) really where after the logs and didnt want do disable the service or send a clear message (no pun intended) to everyone who operates a similar service.

    21. Re:What does this help? by Jeremiah+Cornelius · · Score: 3, Insightful

      The legal and forensic arguments from which this action stem are a part of American policy which can, in fact apply to any jurisdiction. Taken pretty strictly as it is defined, the policy can be expressed: "Look, We're the FBI. That means your fucked, no matter what you do."

      --
      "Flyin' in just a sweet place,
      Never been known to fail..."
    22. Re:What does this help? by Anonymous Coward · · Score: 0

      So, basically, you never did rely on a single server. You used your skills and free services to make sure you had contingencies in place. 'nuff said.

    23. Re:What does this help? by 0123456 · · Score: 3, Interesting

      You know, we took an outage in our dev lab yesterday when a PDU blew, and took out some fiber that was running next to it. Shit happens...maybe not often, but it does.

      Dual PSUs fed from two independent PDUs fed by two independent power sources. We would just shrug and replace the PDU if that happened.

      Its a question of how fast you can recover WHEN it happens.

      Much faster from a blown PDU than from having your server confiscated by the Feds because some other user may have broken the law.

    24. Re:What does this help? by 0123456 · · Score: 1

      Yeah, I'm sure some hardware register was stuck with all bits set; power cycling fixed it.

    25. Re:What does this help? by JazzLad · · Score: 2
      --
      "If you have nothing to hide, you have nothing to fear." - Every fascist, ever
    26. Re:What does this help? by MrQuacker · · Score: 1

      Maybe instead of solving the crime, it simply stops more threats from being mailed out. Until a new anon-service is found. And in the meantime the person might mess up and reveal themselves.

    27. Re:What does this help? by philip.paradis · · Score: 1

      Especially if the RAM is cooled sufficiently, cold boot attacks can be effective for information retrieval from "volatile" memory.

      --
      Write failed: Broken pipe
    28. Re:What does this help? by Anonymous Coward · · Score: 1

      You can do live forensics using a special device. I believe firewire ports allow for it via direct DMA. There is not contamination with this method as the contents in ram are not modified nor is anything loaded into ram (such as would happen from running a program from a flash drive/cd). Sadly courts / government are now saying it is legal to do things like install keyloggers and then use the evidence. Despite the fact these keyloggers have been in cases ruled illegal it was based on the wrong reasons and another keyloger trojan could be written to fix the problem. Basically the problem the court found was that the software could load modules which did something other than permitted by the courts. I believe there was actually evidence that the kelogger software isn't being used as permitted too which is a problem. Long story short while live forensics may have some merit I think as a general rule it shouldn't be allowed even if using firewire / DMA methods which don't contaminate. The reason being the software is extremely complicated and expert witnesses don't understand the issues sufficiently as to why random contents / strings in memory are not reliable. Essentially the prosecutors are using 'experts' to testify that words like 'how to kill' were found and thus there is evidence of premeditation when in reality the contents found in cache was only part of a string and/or corrupted. There may or may not be evidence of said corruption and nobody (including the author himself) is likely to know for sure what the case is. Particularly depending on the circumstances. Memory is a shared resource and the contents can be something other than expected. For instance if you write a program to do some arithmetic or create a file of a certain size using particular functions you may end up reading in unexpected data if things are not initialised properly. This may not be true on GNU/Linux although I did see this in Microsoft Windows. I found it quite disturbing.

    29. Re:What does this help? by hairyfeet · · Score: 2

      Or even more likely they are like the vast majority of computer users out there and don't know the difference between RAM, CPU and HDD. I don't know how many times i've dealt with extremely smart people, people that hold very complex jobs, that simply don't understand the difference between memory and hard drive or CPU and GPU.

      Sadly to many the PC is a "black box" that they know enough about to operate but don't even know the tiniest bit when it comes to what its made of or what it actually does. I've actually talked to cops that thought you should be able to "hack" a machine by simply being told the physical address of the person or that you should be able to push some button and magically have every password that has ever been used by a person simply by having their system. Too much CSI I guess but at least they didn't tell me to trace down an IP address using VB.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    30. Re:What does this help? by mug+funky · · Score: 1

      FTS:

      "May First / People Link and Riseup.net"
      "As a result of the seizure, hundreds of unrelated people and organizations have been disrupted."

      harassment... intentional collateral damage... who knows?

      it still amuses me that they up and take the server and walk out with it. why not put that police tape around the server room, and let the FBI techie do his/her thing in a new place?

      of course, yanking the connections will have the same effect, but it would be much easier for the techie to just say "hey, this thing doesn't keep logs" and let the collateral damage get on with their business.

    31. Re:What does this help? by mug+funky · · Score: 1

      then it would suddenly read 0 degrees?

    32. Re:What does this help? by Anonymous Coward · · Score: 0

      Dual PSUs fed from two independent PDUs fed by two independent power sources. We would just shrug and replace the PDU if that happened.

      Same where I work and we aren't even a big tech company. Just a mid sized law firm.

    33. Re:What does this help? by Anthony+Mouse · · Score: 1

      They're sending a loud and clear message: if you try to stand up to your rights, you WILL be trampled.

      I tend to take it as an invitation to claim to be Spartacus. Because, you know, if they think they can get away with this then there need to be more people doing the thing they're trying to prevent.

    34. Re:What does this help? by the+eric+conspiracy · · Score: 1

      Lots of things can take down a server. Memory going bad, drive controller karking up, cap on a motherboard going bad, cpu fan dying etc.

      Seems to me that it has to be a pretty half-ass ISP that can't bring a replacement mail server up an hour or so after losing one.

    35. Re:What does this help? by Zemran · · Score: 2, Interesting

      My hosting is up for renewal next month and I am already looking to move out of the US for security even though I do not think that I am doing anything of interest to them, I do not know what else is being done at my provider. It is not just bad guys that get taken down, everyone using that service suffered. I do not want to suffer when the jackboots arrive. I want somewhere safe and stable like Switzerland. I am sure that someone will post a reply quoting a bad incident in Switzerland but we could fill several pages with bad incidents in the US.

      --
      I love stacking my barbecues in the shed at the end of summer - you can't beat a bit of grill on grill action.
    36. Re:What does this help? by Anonymous Coward · · Score: 0

      Somewhat similar to the game warden seizing the truck you towed your boat in with to catch that short fish...

      Because you're bad, they know it, and they're going to make you pay.

    37. Re:What does this help? by KingMotley · · Score: 0, Troll

      I don't know how many times i've dealt with extremely smart people, people that hold very complex jobs, that simply don't understand the difference between memory and hard drive or CPU and GPU

      Unfortunately, you obviously aren't one of them, because the hard drive IS memory. Perhaps you meant RAM and hard drive memories?

    38. Re:What does this help? by Anonymous Coward · · Score: 0

      If you want to be a pedantic asshole then sure, but in common usage "memory" is "RAM" and a hard drive is a hard drive.

    39. Re:What does this help? by Anonymous Coward · · Score: 0

      It either

      1) presses the owners into buying new equipment

      2) forces the operators to establish service on another server, possibly in another co-lo, possibly in another country

      3) forces the operators to improve their software so as to be harder to trace by authorities,

      4) In reality, all of the above.

    40. Re:What does this help? by AHuxley · · Score: 1

      Its chilling to other firms, .coms. IT people, admins, owners, isp's. lawyers, accountants- everybody screams out -
      Log everything, makes sure its easy to get the data, keep everything, if we cooperate we might get our hardware back sooner, did we do due diligence on users?
      The ex NSA, GCHQ, DIA, CIA, cyber command - could do this in a nice way as contractors.
      Feel that push for CISPA to get real telco immunity? The company is protected from users and the feds get CALEA++++ like access.
      Until then its "Alright sir, I just need to check inside your sever."
      Yes, you're a smart admin, aren't you sir?

      --
      Domestic spying is now "Benign Information Gathering"
    41. Re:What does this help? by Anonymous Coward · · Score: 0

      It would not be surprising if this whole ordeal was constructed as a means of seizing the riseup server... after all, the FBI have a history of trying to impede social activists

    42. Re:What does this help? by CBravo · · Score: 1

      You also have double fibers?

      --
      nosig today
    43. Re:What does this help? by Anonymous Coward · · Score: 0

      You are such a tool.

    44. Re:What does this help? by Anonymous Coward · · Score: 0

      harassment... intentional collateral damage.

      This. Government agencies now by now that there is no legal point in seizing anonymisation servers. They do it to intimidate and deter those who provide them because they are an annoyance and threat to their power over the people.

    45. Re:What does this help? by Yvanhoe · · Score: 2

      It is not likely at all. We are in 2012 and during several years, various companies have shamelessly sold the "cyber-war" concept. There has been billions (really) of dollars made in training and countermeasure tools for federal organizations.

      You are not in the 90s anymore where a scriptkiddy could brute-force FBI passwords without being noticed. You now should assume competence in the people charged with these affairs.

      --
      The Wise adapts himself to the world. The Fool adapts the world to himself. Therefore, all progress depends on the Fool.
    46. Re:What does this help? by Anonymous Coward · · Score: 0

      Dual PSUs fed from two independent PDUs fed by two independent power sources. We would just shrug and replace the PDU if that happened.

      And you have some magic solution for photons-over-air? That was the cause of the outage, damage to the fibre runs.

    47. Re:What does this help? by FlyveHest · · Score: 1

      So, to do business online you absolutely must have at least 2 colocated servers?

      I sure hope that its possible for a startup to run their first version(s) on a single server, hosted at one provider.

    48. Re:What does this help? by Anonymous Coward · · Score: 0

      The CPU has memory (cache).
      GPU's have memory, both in their graphics processor. Discrete GPU cards (generally) have their own memory.
      Network card buffers are a form of memory.
      Every electronic part of a computer has something that could be described as memory.
      That said, memory is commonly used to refer to RAM.

    49. Re:What does this help? by hairyfeet · · Score: 2

      And you are assuming the same government that spent $600 on a toilet seat didn't piss a large amount of that money away on kickbacks and buying worthless training videos created by insiders who got no bid contracts. By your logic that would mean those retarded TSA goons would have the same level and skill as a secret service agent, because after all we have supposedly spent millions and millions on their training right? yet we have people walking through that forgot to take a fricking handgun out of their bag and not get caught while they yank diapers off little old ladies.

      If ever "Never ascribe to malice that which is adequately explained by incompetence" fit it would have to be the US government friend. All too many of them only care about is getting elected or looking like they are "doing something" that will get them a bigger budget. And look up the whole "taking the RAM" incident, we aren't talking some rare thing that would actually stop anybody but instead they believed according to their brief that "the RAM contained evidence" which I wouldn't be surprised if they got from some CSI where they magicked the contents of the memory and found the killer...using technobabble "science" of course.

      --
      ACs don't waste your time replying, your posts are never seen by me.
    50. Re:What does this help? by CuriousGeorge113 · · Score: 1

      Intimidation.

      Anyone running even a small data center knows that the US government can just walk in the front door and seize whatever they want. Yes, there is the formality of a warrant, but most judges will sign off on anything related to terrorism. (No judge wants to be 'that guy' who didn't help the police catch the Pitt bomber before he kills a bunch of people, etc etc.)

      This gives them the ability to intimidate other ISP's & data centers. "Oh, you don't want to cooperate? OK, we'll be back with a warrant. How much are each of those servers to replace? What about that nice SAN over there? Those 10GB switches? Yes, you'll get everything back when we're done. Might be a few years though...."

      Yes, it's a game. Yes, its nefarious. But, it works.
      Is it ethical? Probably not. Is calling in 100 bomb threats ethical? No.

      Do two lefts make a right? No, but three do.

      --
      No man is an island, But if you take a bunch of dead guys and tie them together, they make a pretty good raft.
    51. Re:What does this help? by CuriousGeorge113 · · Score: 1

      Megaupload had two primary centers, one in Virginia and the other in the Netherlands. I've heard they had a few other smaller colo's as well.

      Megaupload, as a corporation, wasn't even based in the US. The US government successfully shut them down.

      --
      No man is an island, But if you take a bunch of dead guys and tie them together, they make a pretty good raft.
    52. Re:What does this help? by lipanitech · · Score: 1

      They probobly want to get it off the air to analize but I agree I doubt anything on there will be of any use.

    53. Re:What does this help? by helix2301 · · Score: 1

      I agree these guys are not amateurs they are not going to leave info that could burn them on a server accessible to the FBI. But some amateur hackers have been doing things in Anonymous's name. Maybe that's who the FBI is after.

    54. Re:What does this help? by swalve · · Score: 1

      No, the hard drive is storage. It's pretty basic computing 101. If you need an analogy, consider an office desk. The surface of the desk is a computer's memory, the drawers are the storage.

    55. Re:What does this help? by CastrTroy · · Score: 1

      Actually, the hard drive is most frequently referred to as "storage" so that it isn't confused with "memory". When talking about computers, memory always means RAM. I've never heard a competent person in the IT field refer to a hard drive as memory.

      --

      Anthropic principle: We see the universe the way it is because if it were different we would not be here to see it.
    56. Re:What does this help? by Anonymous Coward · · Score: 0

      If they had a record of the traffic entering and exiting the machine,
          I wonder if there are any security keys in the server that might help figure out what was in the traffic.

    57. Re:What does this help? by Steauengeglase · · Score: 1

      They were raided by Fish and Wildlife, not the FBI. From there the details get very murky (everyone has their own spin).

      Beyond losing some wood, it only made Gibson more money as folks ran out to buy their products at (IMHO) already inflated prices.

    58. Re:What does this help? by DrProton · · Score: 1

      how could seizing it possibly help the investigation?

      Perhaps they want to run the machine and observe its operation.

      --
      "Mit der Dummheit kaempfen Goetter selbst vergebens." - Schiller
    59. Re:What does this help? by lokiTM · · Score: 1

      Unless the FBI was able to catch the messages on the fly, it is incredibly unlikely that anything would be left on the disk or in RAM. Even if there was something, it would just point back to a previous Mixmaster node. Because Mixmaster is high latency / store and forward, it has much better security characteristics than a real time / low latency system like TOR. I spent a lot of time on the design to protect against this kind of thing.

    60. Re:What does this help? by TheCarp · · Score: 1

      yes but, they were after megaupload. Of course you would make a coordinated takedown of a multi-homed system. Of course.... warm spares may be invisible until its time to turn them on... but thats besides the point.

      Remember, we are talking about a customer who was on the same box. So... in theory, sharing a box/rack/whatever with someone who may be their target...it is unlikely that secondary boxes would be shared with the same other customer.... especially if at another DC.

      --
      "I opened my eyes, and everything went dark again"
    61. Re:What does this help? by KingMotley · · Score: 1

      No. Hard drives are secondary memory. But you are correct, this is basic computing 101; You need to go back to class.

    62. Re:What does this help? by KingMotley · · Score: 1

      You should/would/will be taught this in your first year in college, but here's a reference (Yes, I know, wikipedia and all that, but I'm too lazy to look up references from my computer books from 20 years ago): http://en.wikipedia.org/wiki/Computer_memory

      And if you are too lazy to go look it up, here's the first two paragraphs:

      In computing, memory refers to the physical devices used to store programs (sequences of instructions) or data (e.g. program state information) on a temporary or permanent basis for use in a computer or other digital electronic device. The term primary memory is used for the information in physical systems which are fast (i.e. RAM), as a distinction from secondary memory, which are physical devices for program and data storage which are slow to access but offer higher memory capacity. Primary memory stored on secondary memory is called "virtual memory".

      The term "storage" is often (but not always) used in separate computers of traditional secondary memory such as tape, magnetic disks and optical discs (CD-ROM and DVD-ROM). The term "memory" is often (but not always) associated with addressable semiconductor memory, i.e. integrated circuits consisting of silicon-based transistors, used for example as primary memory but also other purposes in computers and other digital electronic devices.

    63. Re:What does this help? by Caratted · · Score: 1

      something something semantics something blahblahblah.

      How about you assume he does know what he's talking about, since rarely does anybody say "probably needs a new secondary memory controller and platter due to [insert hdd problem]." Not to mention I can now quote you as saying "hard drive memories."

      Or you can just go about being an a-hole, I don't particularly care. I'm just informing you that nobody else does, either.

    64. Re:What does this help? by KingMotley · · Score: 1

      Feel free to quote me as saying "RAM and hard drive memories" if you wish, as I mentioned two types of memory.

      Let's assume I know what I am talking about, but since you don't, here:
      http://en.wikipedia.org/wiki/Computer_memory [wikipedia.org]

      And if you are too lazy to go look it up, here's the first two paragraphs:

      In computing, memory refers to the physical devices used to store programs (sequences of instructions) or data (e.g. program state information) on a temporary or permanent basis for use in a computer or other digital electronic device. The term primary memory is used for the information in physical systems which are fast (i.e. RAM), as a distinction from secondary memory, which are physical devices for program and data storage which are slow to access but offer higher memory capacity. Primary memory stored on secondary memory is called "virtual memory".

      The term "storage" is often (but not always) used in separate computers of traditional secondary memory such as tape, magnetic disks and optical discs (CD-ROM and DVD-ROM). The term "memory" is often (but not always) associated with addressable semiconductor memory, i.e. integrated circuits consisting of silicon-based transistors, used for example as primary memory but also other purposes in computers and other digital electronic devices.

      You can complain all you want, but when someone goes on a rant about how someone doesn't know the difference between memory and hard drives, when he himself obviously doesn't is quite silly. Even sillier for you calling me out on pointing it out to him.

      Feel free to PM me if you wish, I can get you more references that point very specifically that hard drives are a type of memory in well published books if you want to continue being ignorant.

    65. Re:What does this help? by Anonymous Coward · · Score: 0

      Just for the record, it's current that flows, not voltage (which drives the current).

    66. Re:What does this help? by Lord+Chaos+EOG · · Score: 1

      Our business is small and most of it dependent on a single server. Outages are rare and easy to fix with minimum downtime...Having the FBI confiscate the server would be a bigger and more dangerous threat.

    67. Re:What does this help? by Anonymous Coward · · Score: 0

      This clearly says "if you run your business on US territory ...We will F*** with you." This does not only impact IT services It's about almost every business type or business service being provided on American jurisdiction or to American citizens. Some European companies (Banks, Insurances) are starting to shed their American clients...just too much trouble having them.

    68. Re:What does this help? by gweihir · · Score: 1

      Indeed. Unfortunately, it seems possible that the FBI did catch all messages in-flight for a time. In that case they are possibly hoping to get first-hop messages that they can somehow correlate (time, size, number sent) with the final messages. Note that even if they end up with a number of possibles, they are probably not above searching a few hundred people. Remember, the users of Mixmaster are "anonymity-terrorists" anyways. If the attacker was careful and used different chains for the messages, that will not help tough.

      But criminals do make mistakes and the authorities like to intimidate everybody that defies their authority, like Mixmaster users. I consider it possible that the node was on some list for some time and the authorities were just waiting for a reason to harass it.

      So, if the FBI finds the attacker with this, then we do know the following:
      1) The attacker was not careful
      2) The FBI has has access to all/most traffic of at least this Mixmaster node and possibly additional ones

      I do consider it far more likely though that this is just a fishing expedition (prompted by technological incompetence), or a pure pre-planned exercise in harassment.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    69. Re:What does this help? by Maxmin · · Score: 1

      how could seizing it possibly help the investigation?

      I can't believe you really think that law enforcement investigations are only about gathering evidence and impartially serving justice?

      Clearly, the point of the seizure was to interfere with the remailer, shut them down (albeit temporarily, likely), and maybe discover some forensic evidence that might be used to ensnare others.

      Pre- and ex-judicial property seizures are always about fucking with the innocent-until-proven-guilty.

      --
      O lord, bless this thy holy hand grenade, that with it thou mayest blow thine enemies to tiny bits, in thy mercy.
    70. Re:What does this help? by philip.paradis · · Score: 1

      Netcraft confirms it: you're a pedantic asshole, and your subsequent attempts to defend your pedantry only serve to make you look more pathetic. Listen, I've been doing this computing/programming/networking thing since about 1989. My history includes stuff like Timex Sinclair boxes with tape decks (Hey, look! It's technically memory, but commonly referred to as persistent storage), 8086 boxes such as the venerable AT&T PC-6300 with a badass 360K floppy drive (holy crap, memory once again, but most commonly referred to as removable diskette storage) and a whopping 10 MB hard drive (chrissake, look at that shit, it's memory again but most commonly referred to as a goldanged hard drive), various CP/M boxes, a couple of SCO boxes, some early SGI hardware, a slew of 386/486/586 (I still hate Cyrix) boxes, RS/6000 boxes running AIX at first and Debian once I "fixed" them (fun with null modem cables), what you might call "modern" servers spanning multiple datacenters and numbering in the thousands, etc.

      Over the years, when somebody who knows what the hell he's talking about says something like "gosh, I need more memory," nobody with half a clue assumed he was referring to hard drive space. Conversely, when somebody said something like "golly gee whiz, I sure am seeing high utilization on my filesystems," it was safe to assume he wasn't talking about fucking ramdisks. Attempting to cloud the issue in a pathetic attempt (via another reply of yours) to reference swap space (virtual memory, whatever makes you feel good) as memory in a vain attempt to prop up your prior pedantry honestly only serves one purpose: it further reinforces your status as pedantic asshole.

      In short, you can quote all the technical references you want. Hell, it's not unlikely that I've personally written or substantially contributed to a lot of documentation that you've read. What really matters here is the simple fact that you're being called out for what you are. Stop screwing with people and go do something useful, Junior.

      --
      Write failed: Broken pipe
    71. Re:What does this help? by KingMotley · · Score: 0

      That's nice. I haven't been called Junior in a very long time. Let's see, 1989. I remember when being able to load your entire program into RAM was an absurd idea, no one had that much RAM memory. We had to swap portions out or load different phases of it at time. By 1989, I had already mastered most of the popular programming languages (6502, 8088, IBM 360 Assember, C, a multitude of basics, pascal, rpg, forth, pilot, a few others that didn't make it very far), twice earned two honors in state wide programming contests as being the best programmer in the state, started my own consulting business, did consulting work with Robert Bosch, US Robotics, and Motorola. I'd written widely distributed and widely used software for the Atari 800 line and the Atari ST line, created multiuser software for the Apple 8-bit series, had grown up through 75,110,300,1200,2400,9600,19200bps modems, had built and modified by own computer systems, written my own fully multitasking operating system for the IBM PC, created disk defraggers, terminal software, wrote the most popular BBS software in the state on the Atari 8-bit line, ran the largest BBS system in the midwest for any computer system that I am/was aware of, remember when the first disk drives first started to show up for home use -- the 90K drives, then 180K, then 360K drives, had 4 computers of my own, played with the very first "portable" computers (if you consider a 20 pound box "portable"), had been accepted to MIT without having to take a single additional test based on my prior demonstrated experience, had been repairing computers for extra cash (Atari ST/800/Amiga/PCs), had my work published in numerous magazines, had software I had written available in computer stores, etc etc. I saw Windows 1.0 come and go, play with the first multitasking (not preemptive yet) that didn't come from me, played with OS/2. Worked with some of the early telecomminication systems like tel-net (No, not the protocol), talked to and consulted with some of the very biggest names in cutting edge software at the time, like Michtron. I had submitted patches to numerous software houses... Worked with the very first harddrives (A 5MB ST-506), lived through the whole is it MFM or RLL encoding controllers debacle. Saw and praised the first IDE connectors and controllers finally standardize things. Hell by 1989 I already had computers on the internet.

      After 1989 you can include everything you had listed, and add working on mini's like the AS/400, mainframes like the PDP series from DEC, and the System/360 series, built datacenters, designed and built probably a couple hundred PC's, setup and configured a half dozen networks ranging from Banyan Vines, Netware 286, Netware 386, Windows for Workgroups (YUCK! But it was awesome at the time), Windows NT, yadda yadda... Written FTP servers and clients, wrote remote control software (like PC Anywhere) for DOS. I saw Microsoft basically rip my off my multitasking OS code and use it as their new task scheduler in the Windows 3+ kernel. I could continue this list, but I think I've already made my point.

      I didn't start this. It started with someone said they hated people "who didn't know the difference between memory and hard drive". I just pointed out that technically a hard drive is a type of memory. You can continue to try and argue the opposite in the face of fact, if you wish, but you are just making yourself look silly.

      In short, I'm sure some people out there might be able to get away with calling me Junior, but it definitely isn't you. Now get off my lawn.

  2. Did they at least manage to figure out what server by Qzukk · · Score: 5, Interesting

    Or did they just kick over all the racks and rip everything out like they seem to do on a regular basis?

    --
    If I have been able to see further than others, it is because I bought a pair of binoculars.
  3. Correction by busyqth · · Score: 5, Funny

    FBI seizes terrorist server run by commies.
    Grateful American people throw candy and flowers at heroic agents.

    1. Re:Correction by Anonymous Coward · · Score: 0, Insightful

      At least with the communists we knew that what made us better than them was our freedom. I think that probably served to keep us freer, longer.

      Yeah, there's that lip service to how the terrorists "hate our freedom", but we don't have the old USSR to compare ourselves against. "What is this, Soviet Russia?" was often all it took to get people to shut up about their fascist bullshit. "What is this, Sharia Law?" doesn't seem to be in use since we have no real enemy, just "terrorists" and "terrorism."

      And that's not to say that we *don't* have real terrorist enemies. We do. But people's attitudes towards fighting terrorists are much different than their attitudes were towards fighting the Soviets. Finding the terrorists is all about destroying every last one of them. Fighting the communists was just about being better than they were (and also killing them in third party countries, but I digress).

    2. Re:Correction by fustakrakich · · Score: 1

      Finding the terrorists is all about destroying every last one of them.

      That would make the planet a very lonely place.

      --
      “He’s not deformed, he’s just drunk!”
    3. Re:Correction by cavreader · · Score: 1

      The Soviets were good reliable opponents. Both they and the US had limitations on their aggressiveness towards each country other because they both had 1000's of nukes aimed at one another. Blowing up airplanes and office buildings would have led to WW3 which would have lasted about an hour from start to finish. Today's terrorist organizations are unpredictable and under no such constraints and take the chance to kill as many people as possible with each attack.

    4. Re:Correction by ColdWetDog · · Score: 2

      So we should give the terrorists lots of nukes and a command and control system?

      Sounds perfectly reasonable.

      --
      Faster! Faster! Faster would be better!
    5. Re:Correction by cavreader · · Score: 2

      All the major nuclear states have proven they are responsible in the handling of nuclear weapons. They also have high levels of security to prevent these weapons from being compromised and provided to 3rd parties. The current Iranian issue is not really about them actually using a nuke if they had one. This is about them being able to provide the weapons to one of the 3rd party organizations they support. That's their standard method of projecting military power while being able to maintain plausible deniability. If a terrorist was able to get a nuke and use it Iran is counting on not being definitively identified as the supplier thus avoiding any immediate retaliatory strike. However, the source of the weapon would eventually be identified but it might take a few months in which time the initial outrage would have dissipated. Would the world approve of a retaliatory attack 6 months after the weapon has been used?

    6. Re:Correction by WeeBit · · Score: 1

      FBI seizes terrorist server run by commies.

      Grateful American people throw candy and flowers at heroic agents.</quote>

      And some Americans even kissed their ass! /s

    7. Re:Correction by Anonymous Coward · · Score: 0

      In soviet Russia, heroic agents throw candy and flowers at you!

  4. What did you expect? by OverlordQ · · Score: 1

    When their reply was basically "If we dont let them send bomb threats, we're undermining free speech and the Internet"

    --
    Your hair look like poop, Bob! - Wanker.
    1. Re:What did you expect? by v1 · · Score: 5, Insightful

      If we dont let them send bomb threats, we're undermining free speech and the Internet"

      To which I reply "They need to find a different way to discourage or stop them from sending bomb threats. Inflicting me with collateral damage in the quest for better law enforcement is unacceptable, and so is removing my ability to speak with anonymity."

      Given the choice, I think I'd rather deal with the occasional bomb threat than not be able to speak anonymously.

      --
      I work for the Department of Redundancy Department.
    2. Re:What did you expect? by houghi · · Score: 4, Interesting

      Given the choice, I think I'd rather deal with the occasional bomb threat than not be able to speak anonymously.

      Give me liberty or give me death.
      There: Translated that for you.
      Also: I rather die on my feet then live on my knees.

      --
      Don't fight for your country, if your country does not fight for you.
    3. Re:What did you expect? by Em+Adespoton · · Score: 4, Insightful

      If we dont let them send bomb threats, we're undermining free speech and the Internet"

      To which I reply "They need to find a different way to discourage or stop them from sending bomb threats. Inflicting me with collateral damage in the quest for better law enforcement is unacceptable, and so is removing my ability to speak with anonymity."

      Given the choice, I think I'd rather deal with the occasional bomb threat than not be able to speak anonymously.

      Or, to totally mangle a famous quote:

      "First they came for the anonymous, but I was not anonymous, so I did nothing." That's probably true to life for most people actually....

    4. Re:What did you expect? by v1 · · Score: 1

      Also: I rather die on my feet then live on my knees.

      [grammarnazi] I don't think you can do those two things in that order....[/grammarnazi]

      --
      I work for the Department of Redundancy Department.
    5. Re:What did you expect? by Anonymous Coward · · Score: 0

      He who has no knees bows to no man! - Dan Halen

    6. Re:What did you expect? by Guppy06 · · Score: 1

      Your inconvenience in having to find yourself another anonymous remailer is outweighed by someone else's jeopardy to life and limb.

    7. Re:What did you expect? by DdJ · · Score: 5, Interesting

      FYI, we're not dealing with "the occasional bomb threat" here.

      The University of Pittsburgh (which is down the street from where I work) has gotten multiple bomb threats per day every day for weeks now.

      Many students have been driven out of their dorms, to live off campus, because the evacuations were too disruptive. The campus police are no doubt way over budget. Classes are disrupted to the point where folks on academic probation were told this semester "doesn't count".

      At this moment, as I type this, two buildings have evacuation notices. Earlier today, eleven buildings had to be evacuated.

      And today was not exceptional.

      If you want to follow this yourselves, evacuation notices go out over the @PittTweet twitter account.

      Now, I'm not trying to say "knocking every anonymous remailer off the internet is justified". Please don't assume I think that. I'm just pointing out that this very much isn't a case of "the occasional bomb threat". It's basically a full-on ongoing multi-day denial-of-service attack on the Pitt police, Pittsburgh police, and a bunch of the university, happening in meatspace.

    8. Re:What did you expect? by nurb432 · · Score: 1

      Only a terrorist or child molester needs anonymity. What are you hiding?

      --
      ---- Booth was a patriot ----
    9. Re:What did you expect? by jpapon · · Score: 1

      You don't know, he could be a vampire or some other mythical creature which dies every day... then the statement would be grammatically correct. As long as dying isn't a hypothetical, it makes sense.

      --
      -- Let us endeavor so to live that when we pass even the undertaker shall be sorry. -- M. Twain
    10. Re:What did you expect? by Bucky24 · · Score: 1

      I absolutely agree with you on that. But that's not the reason I don't approve of this action. It's a form of government oversight that I don't particularly want to have.

      --
      All the world's a CPU, and all the men and women merely AI agents
    11. Re:What did you expect? by Anonymous Coward · · Score: 0

      Wow, nice. You've just justified collective punishment (ban cars because some people might misuse them).

    12. Re:What did you expect? by NeverSuchBefore · · Score: 1

      The inconvenience you suffer by not being able to ride on planes without getting molested by the TSA is outweighed by someone else's jeopardy to life and limb.

    13. Re:What did you expect? by Sipper · · Score: 2

      "Stand back... I'm going to try LOGIC..."

      FYI, we're not dealing with "the occasional bomb threat" here.

      The University of Pittsburgh (which is down the street from where I work) has gotten multiple bomb threats per day every day for weeks now.

      Many students have been driven out of their dorms, to live off campus, because the evacuations were too disruptive.

      ...

      I agree that this situation stinks, and that obviously constantly evacuating buildings is very disruptive. However at the same time, can't the University of Pittsburgh and the Pittsburg police stop doing that and ignore the bomb threats, knowing that their leg is being pulled? I realize that there may be some legal precident why they can't... but at some point logic and common sense, along with the knowlege of "The boy who cried wolf" should also come into play. :-/

    14. Re:What did you expect? by Anonymous Coward · · Score: 0

      That I know you're a terrorist child molester, of course.

    15. Re:What did you expect? by misexistentialist · · Score: 1

      More like a crazy immune response than a denial of service attack. I mean what happens when someone mails them a letter saying that are going to bomb "one or more university buildings within the next 20 years" ? If they are able to ignore indeterminate threats like that they can ignore unsubstantiated clusters of threats.

    16. Re:What did you expect? by Guppy06 · · Score: 1

      You're comparing potential threats to actual (and continuing) threats.

    17. Re:What did you expect? by j00r0m4nc3r · · Score: 1

      I don't understand why they need to disrupt a whole array of services that people are paying for in order to catch one guy emailing bomb threats. Are the computer security and forensics guys in the FBI such morons that they can't do any detective work without pulling out their big black boots and seizing the server(s)? Seriously, any 12-year-old Chinese hacker would probably do a better job.

    18. Re:What did you expect? by Guppy06 · · Score: 1

      The servers weren't seized because they "might" be misused, but because they were being misused.

    19. Re:What did you expect? by Obfuscant · · Score: 4, Insightful

      However at the same time, can't the University of Pittsburgh and the Pittsburg police stop doing that and ignore the bomb threats, knowing that their leg is being pulled?

      No. The next time it might not be a joke.

      Universities are being sued for not doing enough to stop violence on campus when it happens, as rare as it is, and as much as they do. It's never enough for the lawyers and "grieving heirs".

      It's a large "corporation" to start with, and state schools have the combined pockets of the taxpayer to pick. You can't sue a school for being too careful, only if something happens and you can convince a judge that they might not have done enough. Why make it a slam-dunk victory for millions by ignoring the last, valid threat?

      This is the same reason that cops have to go check out 911 hangup calls. Most likely, it was someone who dialed by accident and then said "oh shit" and hung up. If they try to dodge the problem by turning their cell phone off, or not answering, the cops will show up to see if everything is ok. If the cops just ignored the call, they'd be sued by everyone involved when it turns out that the caller was forced to hang up, or the wire was ripped out of the wall, by her violent husband or vice versa, and someone wound up dead.

    20. Re:What did you expect? by Anonymous Coward · · Score: 0

      exactly.. the boy who cried wolf. Everyone just ended up ignoring him when a real wolf came and the sheep were eaten.

      If they stop taking every threat as real, and stop evacuating... and then there really *IS* a bomb, a lot of people will be injured or killed and there will be massive lawsuits.

    21. Re:What did you expect? by roystgnr · · Score: 1

      The additional facts and context are much appreciated. However:

      Now, I'm not trying to say "knocking every anonymous remailer off the internet is justified". Please don't assume I think that.

      Do you instead think that "allowing unlimited anonymous communication is justified", even if it means that false bomb threats become as common as litter? Although I'm sure we'd all agree that ethically there's a middle ground between these two points, that may be a moot point if technically no such middle ground exists. And I don't see a technical middle ground, do you? Either truly anonymous speech is possible or it isn't. The mixmaster software can't distinguish between good and evil messages passing through.

    22. Re:What did you expect? by maccodemonkey · · Score: 1

      If it's anonymous, they don't even know if the next bomb threat is coming from the same person. Might mess with how serious you take a bomb threat compared to the previous ones. You don't want the one coming from a copycat who's actually planting a bomb to be the one you ignore.

    23. Re:What did you expect? by Anonymous Coward · · Score: 0

      Under which law is a public university permitted to be sued by a private citizen? Remember that government entities have a privilege called sovereign immunity.

      There was also a SCOTUS case a while ago that basically said that the police are under no obligation to protect you. I'd reasonable assume that applies to campus police.

    24. Re:What did you expect? by Anonymous Coward · · Score: 0

      The server was used to kill or maim someone?

      Last I checked, a threat of violence is not actual violence, it's just a threat (often empty).

    25. Re:What did you expect? by the+eric+conspiracy · · Score: 1

      You cannot do a detailed forensic analysis of a computer without taking it out of service. So you might as well seize it.

      And WTF kind of ISP doesn't have backup hardware? There should be NO disruption of services when a server is taken out of production.

    26. Re:What did you expect? by NeverSuchBefore · · Score: 1

      No, these are potential threats as well. There is no guarantee a bombing will happen.

      But, to begin with, the logic is the same: hurting everyone to stop X is okay because people could get hurt by X.

    27. Re:What did you expect? by qubezz · · Score: 1

      Except if this wolf comes, it has no relationship to a boy crying at all.

      I would find it highly likely that research will show the vast majority of bombings come with no threat, and the vast majority of threats come with no bombing. You can completely disarm the threat as an act of terrorism by simply ignoring it or at least by giving the impression the threat was completely ignored. You must digitally sign your threatening email and not hide behind a remailer before we will take it seriously.

      The most infuriating thing about this story is that by doing absolutely nothing illegal, you can have your property stolen by armed FBI thugs.

    28. Re:What did you expect? by Guppy06 · · Score: 1

      You're comparing "someone, somewhere, something bad might happen involving an airplane" to "a bomb will explode in ABC building on XYZ date."

      You're also comparing "everyone" to "the users of this particular service provider."

    29. Re:What did you expect? by Guppy06 · · Score: 1

      Last I checked, a threat of violence is not actual violence

      Then you need to re-read the legal definition of assault.

    30. Re:What did you expect? by Anonymous Coward · · Score: 0

      I'm not...

    31. Re:What did you expect? by rtb61 · · Score: 1

      Let's just say you wanted to knock every anonymous internet remailer off the internet, how would you go about it?

      If you wanted to scan through them and possibly leave some corrupted hardware in those servers to monitor them, how would you go about it?

      If you wanted to launch a big fishing expedition on those servers, how would you go about it?

      All a little to convenient, simpler to host your servers in another country than put up with junk like this.

      --
      Chaos - everything, everywhere, everywhen
    32. Re:What did you expect? by Anonymous Coward · · Score: 0

      However at the same time, can't the University of Pittsburgh and the Pittsburg police stop doing that and ignore the bomb threats, knowing that their leg is being pulled?

      No. The next time it might not be a joke.

      Constant bomb sniffer dog patrols, continual random searches of people and places, checkpoints.

      There are solutions to a constant stream of bomb threats that don't require you to evacuate the entire building for the 50th time.

    33. Re:What did you expect? by Anonymous Coward · · Score: 0

      Yet you are clearly alive, hypocrite.

    34. Re:What did you expect? by Anonymous Coward · · Score: 0

      You can't sue the cops for failure to respond to a crime, they have sovereign immunity per the SCOTUS.

    35. Re:What did you expect? by NeverSuchBefore · · Score: 1

      You're comparing "someone, somewhere, something bad might happen involving an airplane" to "a bomb will explode in ABC building on XYZ date."

      It's just a threat. "A bomb might explode." "A terrorist might attack."

      Sorry, but I don't believe in collective punishment at all. Word games or not, the logic is almost exactly the same.

      You're also comparing "everyone" to "the users of this particular service provider."

      All of the users of this particular service. You knew what I meant. It makes no difference, as everyone is being punished.

    36. Re:What did you expect? by NeverSuchBefore · · Score: 1

      legal definition

      The law is not always right. What he said was correct. A threat is not the exact same thing as actual violence. Punching someone in the face is very clearly different than threatening to do so. In only one of those scenarios someone actually got punched in the face.

    37. Re:What did you expect? by NeverSuchBefore · · Score: 2

      continual random searches of people and places

      That sounds about as awful of a solution as the TSA. If the solution violates people's privacy, I don't want it. I'd rather them evacuate the building for the 50th time.

    38. Re:What did you expect? by Guppy06 · · Score: 1

      A threat is not the exact same thing as actual violence.

      By your definition, pointing a gun at someone's face (a/k/a "assault with a deadly weapon") isn't violence unless and until you pull the trigger?

      Your libertarian fantasy would have every mob enforcer walk free.

      In only one of those scenarios someone actually got punched in the face.

      Congratulations, you've just found the difference between assault and battery. But in both scenarios (provided the victim saw it coming), the victim was...

      No, if I'm going to copypasta anything, it will be what I just wrote:

      Then you need to re-read the legal definition of assault.

    39. Re:What did you expect? by Guppy06 · · Score: 1

      It's just a threat. "A bomb might explode."

      No. "A bomb will explode, at $location and $time." In each instance, a clear and specific threat was made, by someone claiming to be the perpetrator.

      All of the users of this particular service.

      No. The "service provider." Users of other anonymous mailers are unaffected, and these other anonymous mailers are still available to the affected parties.

    40. Re:What did you expect? by Nyder · · Score: 1

      This is the same reason that cops have to go check out 911 hangup calls. Most likely, it was someone who dialed by accident and then said "oh shit" and hung up. If they try to dodge the problem by turning their cell phone off, or not answering, the cops will show up to see if everything is ok. If the cops just ignored the call, they'd be sued by everyone involved when it turns out that the caller was forced to hang up, or the wire was ripped out of the wall, by her violent husband or vice versa, and someone wound up dead.

      actually, the 911 people call back to make sure it's not an accidental call before they send a police to check.

      --
      Be seeing you...
    41. Re:What did you expect? by NeverSuchBefore · · Score: 1

      No. "A bomb will explode, at $location and $time." In each instance, a clear and specific threat was made, by someone claiming to be the perpetrator.

      They do not know that a bomb will actually explode. I thought it would be plainly obvious what I was trying to say, but I guess not.

      No. The "service provider."

      Oh, okay. My stance on collective punishment remains the same, though.

    42. Re:What did you expect? by NeverSuchBefore · · Score: 1

      By your definition, pointing a gun at someone's face (a/k/a "assault with a deadly weapon") isn't violence unless and until you pull the trigger?

      Indeed it's not. But I also never said that pointing a gun at someone's face should be legal.

      Congratulations, you've just found the difference between assault and battery.

      He didn't mention anything about assault or battery. He just mentioned that threats are not the same as actual violence. Which I maintain is true. You brought up legal definitions, but they're irrelevant to what he said.

    43. Re:What did you expect? by Anonymous Coward · · Score: 0

      Simple, turn of the internet and mobile traffic for the University of Pittsburgh and no more bomb threats in thy mail! It might be costly (no more online games or facebook), but you would get rid of all the threats without knocking down other peoples mail servers.

    44. Re:What did you expect? by Anonymous Coward · · Score: 0

      I agree that this perhaps isn't the best solution, or really a solution at all, but it's more than the "occasional" bomb threat at this point. I'm a student at the University of Pittsburgh, and we've gotten something like 130 bomb threats this semester, and they've been coming more and more frequently. We've had 20 or so in the past day. Several dorms were evacuated a few minutes ago, at 2:30am, the week before finals. A good many students have just given up and gone home, because so many of their classes are cancelled that it just isn't worth it. Some professors gave up a few weeks ago and cancelled finals and the rest of their lectures. There needs to be some kind of a solution here. Thousands of peoples' lives are being continually disrupted and millions of dollars of taxpayer and University money are being spent on this.

    45. Re:What did you expect? by Anonymous Coward · · Score: 0

      "No. The next time it might not be a joke."

      And you might be hit crossing a road, shot in a robbery while out to lunch, or abducted by aliens. So what?

      Using hypotheticals to justify any proposition permits one to just as easily contradict the proposition with a counter hypothetical. We could just as easily suppose that a genuine bomb threat could have been unheard due to the disruption caused by the raid, and that could have caused people to miss the threat, and thus get blown up because they failed to evacuate. There is a name for this fallacy that has roots in the utility of believing in gods to avoid the risk of damnation, called pascals wager. Its answer, the infinite gods rebuttal, is fairly similar to my argument about picking any hypothetical in response.

      This is why words like 'might' must be carefully considered. Conditional probability, expected outcome, and all the rest don't get waved aside just because something might happen. That ignores the very point of having a sane response to this problem, which is to understand that this is just an annoying and disruptive prank.

    46. Re:What did you expect? by Culture20 · · Score: 1

      legal definition

      The law is not always right. What he said was correct. A threat is not the exact same thing as actual violence. Punching someone in the face is very clearly different than threatening to do so. In only one of those scenarios someone actually got punched in the face.

      But in both of those cases, someone is hurt. Threats and menace are crimes because the fear of danger imposed upon the victim is psychological damage. Menace especially can lead to escalation of violence (in self defense) due to proximity.

    47. Re:What did you expect? by NeverSuchBefore · · Score: 1

      But in both of those cases, someone is hurt.

      It doesn't matter. That isn't what I (or I suspect he) was talking about. The harm caused by punching someone and threatening to punch them are fundamentally different (well, one might be mental harm, while the other might be mental and physical harm).

      I wasn't saying threats shouldn't be against the law.

    48. Re:What did you expect? by Culture20 · · Score: 4, Insightful

      can't the University of Pittsburgh and the Pittsburg police stop doing that and ignore the bomb threats, knowing that their leg is being pulled? [...] "The boy who cried wolf" should also come into play

      There are two morals to the story of "The boy who cried wolf":
      Don't consistently lie or you'll get eaten (the moral for children)
      Sometimes, children's lies end up being the truth, so pay attention every time or they'll get eaten (the moral for adults)
      If you want to discourage lying, punish the liars when they're caught, but don't ignore what seems like a lie because it might be the truth.

    49. Re:What did you expect? by NeverSuchBefore · · Score: 1

      Maybe the problem is their constant evacuations? That's not to say that the person sending the threats has nothing to do with it... they do, quite a bit. But you can't react to every threat when it's this costly and there's a low probability that they will act (which, based on how many empty threats there have been, this seems to be true). But at the same time, I don't blame the university. We live in a lawsuit-happy society. It's a shame that people would sue others because they didn't react to something that was highly unlikely to begin with and win (and the person being sued didn't even do the damage to begin with).

    50. Re:What did you expect? by Anonymous Coward · · Score: 0

      Carnegie Mellon University has also gotten bomb threats (I work there, and my building was evacuated).

    51. Re:What did you expect? by Anonymous Coward · · Score: 0

      It's not "the occasional bomb threat":
      http://www.pittenshistory.info/

      The buildings threatened (and presumably evacuated and searched) at 2:30 AM today are primarily dormitories. These people have been living like this for more than two months now. At least the semester is almost over.

    52. Re:What did you expect? by Anonymous Coward · · Score: 0

      However, a subpoena for the remailer logs, if there were any, would have effectively given the FBI the information they needed without the collateral damage. Taking out an entire remailer for a bomb threat is akin to taking out an entire AT&T central office for one that was called in.

    53. Re:What did you expect? by Sipper · · Score: 1

      can't the University of Pittsburgh and the Pittsburg police stop doing that and ignore the bomb threats, knowing that their leg is being pulled? [...] "The boy who cried wolf" should also come into play

      There are two morals to the story of "The boy who cried wolf":

      Don't consistently lie or you'll get eaten (the moral for children)

      Sometimes, children's lies end up being the truth, so pay attention every time or they'll get eaten (the moral for adults)

      If you want to discourage lying, punish the liars when they're caught, but don't ignore what seems like a lie because it might be the truth.

      Point taken. [Several others have essentially said the same thing, but I believe the above is the most succinct/eloquent statement of it.]

    54. Re:What did you expect? by Anonymous Coward · · Score: 0

      This is the same reason that cops have to go check out 911 hangup calls. Most likely, it was someone who dialed by accident and then said "oh shit" and hung up. If they try to dodge the problem by turning their cell phone off, or not answering, the cops will show up to see if everything is ok. If the cops just ignored the call, they'd be sued by everyone involved when it turns out that the caller was forced to hang up, or the wire was ripped out of the wall, by her violent husband or vice versa, and someone wound up dead.

      actually, the 911 people call back to make sure it's not an accidental call before they send a police to check.

      "If they try to dodge the problem by turning their cell phone off, or not answering, the cops will show up to see if everything is ok." Reading skills FTW!

    55. Re:What did you expect? by Anonymous Coward · · Score: 0

      In that case though- would not removing the anonymous mail server (allowing anonymous reporting of bomb threats) remove the option to anonymously report a bomb threat, and therefore the threat will never come in, and the bomb will just go off and kill people without a report having been made?

      The circular logic on this is insane:
      1. We can't ignore bomb threats, one of them might be real.
      2. We get so many fake bomb threats via anonymous means.
      3. We will remove the anonymous means, so that no more bomb threats arrive.
      4. see 1.

    56. Re:What did you expect? by Anonymous Coward · · Score: 0

      This is the same reason that cops have to go check out 911 hangup calls.

      I don't know where you live, but the police in my town have much, MUCH better things to do than go check on everyone who calls 911 and hangs up. And that's fine by me. The government, and by extension the police, are not here to protect me. That is my responsibility. If someone blows me up, then I guess I was just in the wrong fucking place at the wrong fucking time.

      Shit Happens(tm).

      I really have no idea where any of this "Gubbmint needs ta keep me safe from evathing all da time" shit comes from. Get yourself a pistol, hope you don't ever have to use it, and just live every day to the fullest. No fear, no bellyaching, no bullshit.

      You'd be amazed how refreshing it really is to know you are in control of your own destiny.

    57. Re:What did you expect? by LanMan04 · · Score: 1

      The University of Pittsburgh (which is down the street from where I work) has gotten multiple bomb threats per day every day for weeks now.

      So just fucking ignore them.

      How many false positives do you need before you realize this is a scam/prank/whatever?

      --
      With the first link, the chain is forged.
    58. Re:What did you expect? by DdJ · · Score: 1

      If they were a private business, they could.

      As a university, they cannot, especialy after Virginia Tech. Go read what Schneier recently wrote on the topic.

    59. Re:What did you expect? by Obfuscant · · Score: 1

      actually, the 911 people call back to make sure it's not an accidental call before they send a police to check.

      I know. That's why I talked about the caller trying to dodge the problem by turning his cell phone off or not answering the phone. If he turns his phone off or doesn't answer, the dispatcher can't deal with the call without sending an officer.

    60. Re:What did you expect? by Thing+1 · · Score: 1

      You can't sue a school for being too careful [...]

      Perhaps we should start. A spanner in the gears; "vote gridlock".

      --
      I feel fantastic, and I'm still alive.
    61. Re:What did you expect? by Anonymous Coward · · Score: 0

      That isn't being a grammer nazi. That's being demeaning to someone whose first language may well not be English byt who nevertheless manages to communicate their ideas effectively. Can you say the same? Pratt.

    62. Re:What did you expect? by Em+Adespoton · · Score: 1

      That's just so original.... I bet you're living the life of Brian.

    63. Re:What did you expect? by Anonymous Coward · · Score: 0

      The third moral to the story. If they keep crying wolf, ignore it and they will either get bored or eaten. Problem solved. If you are going to blow up a building, you would not call ahead.

    64. Re:What did you expect? by gweihir · · Score: 1

      FYI, we're not dealing with "the occasional bomb threat" here.

      The University of Pittsburgh (which is down the street from where I work) has gotten multiple bomb threats per day every day for weeks now.

      Well, if it was that many, correlation attacks on Mixmaster might just become possible and give them a clue were the messages came from. If they have a lot of traffic data for the Mixmaster net. Given the amount of snooping the US government does against its citizen, this just seems plausible.

      I wonder however what they want with a single Mixmaster node. For that they would have to have a pattern of messages sent to the node as first hop that somehow matches the arriving messages at the target. Maybe the attackers are stupid and have some timestamps in there and the FBI found the message traffic to austria matching those.

      The other option is that austria was an exit-node for some of the messages and they are now tracing it back. This would imply more compromised nodes in the near future.

      It could also just be an attempt to stop the threats by intimidation or a plain, pre-planned harassment action that is only loosely connected to the bomb threats.

      Time will tell. While not having read it, I am sure the Mixmaster docu warns that the message content of what you send can still be used to trace the messages to you.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    65. Re:What did you expect? by Goat+of+Death · · Score: 1

      Actually, there is case law that went all the way to the Supreme Court that decided the cops indeed have absolutely no obligation to help you and cannot be sued for not showing up.

      Two women heard a sexual assault going on in their building. They called the cops. No cops showed. The women heard the assault stop. They waited and figured the guy had left. They went downstairs to help the assaulted woman if they could. Turns out the guy had not left and proceeded to rape the would be saviors.

      The good samaritan women sued the police force for not responding to the call. Several years and appeals later it reached the Supreme Court where it was affirmed that the cops are under no specific obligation to respond to any given call. Cops can freely ignore 911 calls if they so choose with no legal repercussions unless local statues are in place that say otherwise.

  5. let's hope ECN doesn't keep logs... by Anonymous Coward · · Score: 0

    ...because organisations believed to provide anonymity have an annoying habit of keeping substantial logs which turn up when their servers are seized / information is demanded. See also moot / 4chan.

  6. nonsense by Tom · · Score: 5, Interesting

    More importantly: Unless the server operator was a total dofus, this brings them exactly zero steps towards resolving their problem, because this is exactly the kind of attack that Mixmasters was designed to withstand.

    Idiots. Is nobody teaching these fools basics about the stuff they encounter?

    --
    Assorted stuff I do sometimes: Lemuria.org
    1. Re:nonsense by Anonymous Coward · · Score: 2, Insightful

      More importantly: Unless the server operator was a total dofus, this brings them exactly zero steps towards resolving their problem, because this is exactly the kind of attack that Mixmasters was designed to withstand.

      Idiots. Is nobody teaching these fools basics about the stuff they encounter?

      I hate to defend them, but look at it from the FBI's point of view. Maybe the server operator was a total - or even a partial - doofus. The Feds would be even bigger doofuses (as in, negligent in their) to assume otherwise and not investigate the server. That's their job.

    2. Re:nonsense by tibit · · Score: 5, Insightful

      So, they really need a whole big stinkin' server? If you're a professional, you'd switch the server to single user mode, dump the drive contents to a portable drive, reboot the server, and be on your merry way. If they have proper forensic data analysis tools, they should be able to deal with all popular raid arrays out there, so given those you shut the server down, use a portable disk imager to copy the drives, you then replace the drives, power the server back up, and are on your merry way. I just don't get what they need the server itself for. They are after the data, not the hardware.

      --
      A successful API design takes a mixture of software design and pedagogy.
    3. Re:nonsense by Anonymous Coward · · Score: 0

      If you're a professional, you'd switch the server to single user mode

      ...it detects that you're not the usual sysadmin and silently wipes all logs.

      Security 101: don't trust a server you don't have full control of.

    4. Re:nonsense by Anonymous Coward · · Score: 0

      To parrot another response, there's also data on RAM that could have valuable info if they didn't shut down the machines.

    5. Re:nonsense by Em+Adespoton · · Score: 5, Interesting

      Have you ever done data forensics? The first thing you learn is that it's not the same data if it's not on the original storage medium.

      Of course, what they SHOULD be able to do is shut the server down, clone the drive, pull the drive that has the warrant, and drop in the cloned drive. Of course, this requires cooperation with the victim, which obviously wasn't available in this case.

      To put it another way: they weren't after the hardware OR the data, they were after the incriminating evidence. Data by itself is hearsay (no way to prove beyond a shadow of a doubt that it was preserved in the same state and context).

    6. Re:nonsense by Anonymous Coward · · Score: 0

      Its most likely the fbi trying to look like they are doing something. They know they are grasping at straws. It was just a pr move and they're hoping to get lucky.

    7. Re:nonsense by Burning1 · · Score: 2

      I suspect they wanted the drives themselves for analysis - makes it possible to look for deleted or over-written information that might not exist on a duplicated disk.

    8. Re:nonsense by cpu6502 · · Score: 2

      >>>I just don't get what they need the server itself for. They are after the data, not the hardware.

      Likewise the Russian government doesn't need to grab servers in order to investigate claims of "illegally-copied software", but they do it anyway in order to shut down groups that are critical of government. The FBI is simply employing the same tactic to silence human rights groups (many of which are critical of the Congress) under the cover of an "investigation". Two birds killed with one warrant.

      --
      My AC stalker: " I personally agree with your posts most of the time, but that won't keep me from modding you troll"
    9. Re:nonsense by Guppy06 · · Score: 1

      If you're a professional, you'd switch the server to single user mode, dump the drive contents to a portable drive, reboot the server, and be on your merry way.

      If you're a professional, you don't assume that the system isn't rigged to destroy evidence in the event of an attempted seizure.

      "On site" and "controlled environment" are mutually exclusive.

    10. Re:nonsense by Anonymous Coward · · Score: 0

      TPM + Encryption = Whoops we need the whole server and the downtime has alerted the owner and they've ordered the TPM chip to reset.

    11. Re:nonsense by mysidia · · Score: 1

      To parrot another response, there's also data on RAM that could have valuable info if they didn't shut down the machines.

      Perhaps if they ever come to prosecute someone, the defense can show how the investigative agents willfully destroyed evidence required for the defense by powering off the server and left it powered off for hours, resulting in data being permanently lost from RAM.

    12. Re:nonsense by Anonymous Coward · · Score: 0

      I think what you fail to realize is:
      1) Warrants are issued for hard drives containing data. Not just the data that may be on them.
      2) Data destruction techniques can easily be deployed if a certain piece of known field equipment is always used. Versus, a lab tech looking for a data booby trap using varying techniques prior to extracting the data. If a trap is found, the FBI have equipment that can clone disks without needing to even apply power to the drive.
      3) Confiscating an entire computer grantees all hard drives that are contained in the case are collected and sent to the lab.
      4) Copying Terabytes of data, sometimes hundreds of terabytes of data to a portable device could take several hours if not days.
      5) The original items in the warrant need to be presented as evidence if charges brought (see 1).

      If anything, this should be a lesson in centralizing servers and data centers with an internet based business. One disaster and say goodbye to your customer access. In this case, the disaster was collateral damage from an FBI investigation into other clients who used the same server service.

    13. Re:nonsense by mysidia · · Score: 1

      If you're a professional, you don't assume that the system isn't rigged to destroy evidence in the event of an attempted seizure.

      That can happen at a physical layer too. The chassis can be altered so that if an entry procedure is not followed, a data-destruct occurs if there is a chassis intrusion or if the chassis is moved.

      This can be done by installing an interposer circuit in between disk drives and the drive controller with an independent power supply.

      If a "destruct" event occurs; the independent battery powers up the disk drives, locks in ATA Secure Erase Mode, and detonates an explosive charge of just sufficient strength to shatter the glass plates in the hard drives.

      Anyways... if the volume decryption key is rendered unusuable by 1 second of ATA Secure erase, there is no opportunity at all to interrupt the process.

    14. Re:nonsense by evil_aaronm · · Score: 1

      "Wasn't available in this case." Oh, I'm sure it was available. The FBI is just carrying on its proud tradition of not giving a fuck. It's more "bad ass" that way. In fact, I can see agents rehearsing in the mirror: "That's right, mofo, I'm takin' it. Whatcha gonna do about it... Punk?"

    15. Re:nonsense by Anonymous Coward · · Score: 1

      How do you know they powered it down?

      It is possible to switch the power supply to something portable and move it while still powered on.

    16. Re:nonsense by BronsCon · · Score: 4, Funny

      the FBI have equipment that can clone disks without needing to even apply power to the drive.

      Then they're in the wrong business. They need to start producing and selling these ultra-efficient disks that don't require power for read operations. Imagine the battery life on your laptop running one of THOSE!

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    17. Re:nonsense by RollingThunder · · Score: 1

      Agreed. A number of forensic power supplies exist, ranging from full-PC units to ones that just manage the hard drive, and can be engaged without interrupting power.

    18. Re:nonsense by dondelelcaro · · Score: 1

      If you're a professional, you'd switch the server to single user mode, dump the drive contents to a portable drive, reboot the server, and be on your merry way.

      And if you were really a professional, you'd get a search warrant for a complete wiretap on the server, and track all packets coming in and out. You might also compromise the machine so you could obtain all of the unecrypted traffic entering and exiting the machine. But the FBI apparently isn't that smart.

      --
      http://www.donarmstrong.com
    19. Re:nonsense by bmo · · Score: 4, Informative

      makes it possible to look for deleted or over-written information that might not exist on a duplicated disk.

      Deleted stuff is never erased, just marked as "free space" by the OS.

      Overwritten data, these days, is unrecoverable, even if only overwritten once. There has not been a single criminal case that I can remember where data was overwritten and then recovered on modern drives. The standard of multiple overwrites for true erasure is from the days when disks were physically huge, and the recorded area was huge, and head alignment wasn't always the greatest thing in the world.

      Go read the epilogue to Peter Gutmann's paper

      http://www.cs.auckland.ac.nz/~pgut001/pubs/secure_del.html

      A simple dd of the original drives would have given investigators all the information that was available, including deleted files.

      --
      BMO

    20. Re:nonsense by Anonymous Coward · · Score: 0

      And you're trusting the HDD vendor to get that right? They'll happly store the key on platter...

    21. Re:nonsense by tibit · · Score: 1

      Yeah, but the AC above does have a point:

      ...it detects that you're not the usual sysadmin and silently wipes all logs.

      You need to choose a level of paranoia. If you really think that there's so much going on that there's anything useful in the RAM of the server, then it's not a long shot to assume that if said server detects that both gigabit links on the back are down, it may as well wipe stuff.

      IOW: there's no ideal, realistic solution. If you assume that the sysadmin was paranoid to the point of encrypting all the data and the keys being only in RAM, then it's fair deal to assume that the data is lost as soon as you start tweaking things, even moving the server while powered up.

      If you assume, like on every normal server out there, that RAM contents are of no importance, then probably it's safe to assume that single-user mode operates as designed, and it can be used to get the data off the drives in spite of not having a proper tool to directly read the drives that are a part of hardware RAID (like they'd likely to be). If you don't know the passwords, then of course single user mode is out anyway, and you have to reboot to your recovery medium of choice and use that to dump the drives; most RAID out there would be handled by any recent linux recovery disk so you'd get access to drive contents.

      Alas, professionals would have forensic data recovery software available, so there's no point in not pressing the power button, waiting for the shutdown (or even forcibly cutting power), then imaging the drives and dealing with reconstructing it once you're back in the office.

      --
      A successful API design takes a mixture of software design and pedagogy.
    22. Re:nonsense by tibit · · Score: 1

      The first thing you learn is that it's not the same data if it's not on the original storage medium.

      Since, obviously, the data cares very much what medium it's on, and bits may start looking all worried at you if you copy them. You get the original drive, use a disk imager to obtain the digital signature of original contents (the private key and the signing engine is in a tamperproof chip inside the imager), make an image, get the signature on the image, sign the affidavits, and be good and done.

      --
      A successful API design takes a mixture of software design and pedagogy.
    23. Re:nonsense by tibit · · Score: 2

      There is no such thing and hasn't been for more than a decade. It's a legend that was once true: in times of MFM and RLL drives, and early PRML drives. Nobody offers such analysis, feel free to prove me wrong by providing someone who would quote it for any hard drive that was shipped in the last decade. The quote would be for data recovery after the drive was overwritten precisely once with zeroes.

      --
      A successful API design takes a mixture of software design and pedagogy.
    24. Re:nonsense by Obfuscant · · Score: 1

      Since, obviously, the data cares very much what medium it's on, and bits may start looking all worried at you if you copy them.

      Stop being deliberately silly.

      You get the original drive,

      Which you will have to preserve in its original state as closely as possible, to the point that you might not even bother with a "clean shutdown" because the shutdown code could be rigged to wipe evidence. Yes, you perform the analysis on a signed copy, but you still need to keep the original to provide to the defense experts who will do their own imaging/signing/analysis.

      If the prosecution cannot prove to the court that their analysis was on the actual data, it will be thrown out. So, yes, in very real terms, it's not the same data if it isn't on the original medium.

    25. Re:nonsense by Obfuscant · · Score: 1

      This can be done by installing an interposer circuit in between disk drives and the drive controller with an independent power supply.

      This requires a bit more work than simply putting code in one file in /etc/init.d under the "stop" function, called by one of the K-files in rc3.d, that deletes any incriminating files. Shutdown code is a lot less dangerous than having to deal with explosive charges. And if triggered by accident, doesn't leave a slag heap or shrapnel.

      When explosive charges in confiscated servers becomes a significant issue, cops will start treating every confiscated server like it has explosive charges. "Modify disk on shutdown" is so easy to do that they have to assume it will be, and thus treat the server like it will do that. Pull the plug instead of clean shutdown, e.g..

    26. Re:nonsense by the+eric+conspiracy · · Score: 1

      Wrong.

      "Mark Johnson, a digital forensics contractor for ManTech International who works for the Armyâ(TM)s Computer Crime Investigative Unit, examined an image of Manningâ(TM)s personal MacBook Pro and said he found 14 to 15 pages of chats in unallocated space on the hard drive that were discussions of unspecified government info between Manning and a person believed to be Assange, which specifically made a reference to re-sending info."

      "Johnson testified that he found two attempts to delete data on Manningâ(TM)s laptop. Sometime in January 2010, the computerâ(TM)s OS was re-installed, deleting information prior to that time. Then, on or around Jan. 31, someone attempted to erase the drive by doing whatâ(TM)s called a âoezerofillâ â" a process of overwriting data with zeroes. Whoever initiated the process chose an option for overwriting the data 35 times â" a high-security option that results in thorough deletion â" but that operation was canceled. Later, the operation was initiated again, but the person chose the option to overwrite the information only once â" a much less secure and less thorough option.

      All the data that Johnson was able to retrieve from un-allocated space came after that overwrite, he said.

      http://www.wired.com/threatlevel/2011/12/manning-assange-laptop/

    27. Re:nonsense by the+eric+conspiracy · · Score: 2

      Forensic investigation of a computer includes a capture of the machine's memory, not just the drive contents.

    28. Re:nonsense by Anonymous Coward · · Score: 0

      Data by itself is hearsay (no way to prove beyond a shadow of a doubt that it was preserved in the same state and context).

      Is there a way to prove beyond a shadow of a doubt that the original storage medium is the original storage medium?

    29. Re:nonsense by eggstasy · · Score: 1

      Do you even read what you write? The data came after the overwrite, meaning, it was written there again after the multiple zerofills.
      On top of what the parent posters said about sector size etc. we have the fact that bits are perpendicular to the platter nowadays.

    30. Re:nonsense by the+eric+conspiracy · · Score: 1

      So why are they saying a single overwrite is less secure?

    31. Re:nonsense by qubezz · · Score: 1

      Another fucking idiot. Can't we IP ban stupidity? You put the key for hardware encryption on the drive so that you can erase 4096 bits and render the whole drive completely unreadable forever.

    32. Re:nonsense by tibit · · Score: 3, Informative

      You misunderstood what the cited article was saying. First of all, the article was essentially hearsay - a story of what Johnson said, retold by someone who didn't have much clue. Yet, obviously, nowhere did they say that they used magnetic force microscopy to recover data from the platters, as that would be the only technology that would have a chance (except, these days, it doesn't). All they did was a regular read from the drive and found some sectors that the zero-fill didn't overwrite. What happened, most likely, was that the zero-fill was only attempted on areas declared unallocated by the filesystem. Such areas are necessarily declared conservatively -- you should never trust a free-space erase on a mounted filesystem, and that's what seems to have happened here.

      Nowhere does the article disagree with what I'm saying, because, again, the legend of recovering the data from a zeroed-out hard drive is at this time nothing more. If you're lucky as in winning the lotto jackpot, and you're looking for very small amounts of data (say cryptographic keys), you may be able to recover useful error-correctable data from sectors that got reallocated because they started to fail. This doesn't require opening up the drive, merely gaining access to it via the factory/manufacturer mechanisms (there are software tools for that), so that you can read any sector, whether mapped into the space accessible via regular ATA data access calls or not. That's a slim chance, but if you're after a key or other short blurb, it's a low-hanging fruit -- and yes, in that case you need original drive, not an image.

      The deal with the drive you cite was as follows: it never got fully overwritten with zeroes. Was that the case, you'd never read about any large (more than dozens or hundreds randomly scattered sectors worth) data coming off of it, because, again, it's not possible anymore. If you want to overwrite a drive, you boot a DBAN CD/dongle and do it. One set of zeroes is enough. If you really worry about the few tens of nanometers worth of possibly relevant domains left over "between" the tracks, you can always overwrite it a couple times; I'd think thrice with random data plus once with zeroes is enough. You don't muck around with free-space overwriting, OS reinstallation, or anything of that sort.

      I think I posted something about it once somewhere where I argued that "obviously it's possible duh duh" -- I used to believe it until I looked at a honest-to-goodness drive platters with a magnetic force microscope. Even at a highest magnification, where a single pixel is a few nanometers across, you can't see anything but random hash "between" the tracks. At such magnification, the individual bits are huge, and any remnants would be quite obvious. They were very obvious in times of early PRML drives and before that. That time is long gone. Thus, an obvious tip: don't store sensitive data on old hard drives (say early IDE drives).

      --
      A successful API design takes a mixture of software design and pedagogy.
    33. Re:nonsense by Beryllium+Sphere(tm) · · Score: 1

      If that were correct then backups would not be admissible evidence. They are.

    34. Re:nonsense by MiG82au · · Score: 1

      I love it when I learn something obscure from Slashdot comments. Thanks.

    35. Re:nonsense by Anonymous Coward · · Score: 0

      But doesn't the FBI understand how pointless this exercise is?

      So, they seize this server. So what? Its a reach, but _maybe_ they get a lead on the douche posting the bomb threats. All that happens is the next jerk who wants to send threats uses another anonymous service, this time in a different country. The FBI could seize 1000 servers, hell, all of the servers in the US, and still fall victim to an anonymous bomb threat emailed from a box outside the USA.

      This seems like an exercise in futility.

       

    36. Re:nonsense by Leebert · · Score: 1

      No. That's why the standard for conviction is "reasonable doubt".

    37. Re:nonsense by lightknight · · Score: 1

      Magnetic domains. The data forensic's kids have this idea (it may or may not be true) that when bits are flipped, some random atoms that make up that bit do not flip. I.e. the majority will flip, but some may not. As such, it is possible to extract previously written data by reading the 'minority report' of the data on the disk (I assume they extract all possible minority reports per bit, then try to match the file checksum; if / when it matches, there is a fair chance they've recovered the original file).

      Supposedly, using a SSD prevents them from doing this. But who knows: the data forensics field is, from what I can tell, filled with spooks, con-men, and scammers of every color. As such, it's hard to tell when someone actually 'found' something that 1.) wasn't placed there by a crooked member of the recovery team (no one is above corruption), and 2.) it's not the interrogator bluffing for more than he's worth (99% of all cases, I imagine).

      Still, it would explain the CIA's paranoid approach to hard drive disposal (grind it, melt it, etc.).

      --
      I am John Hurt.
    38. Re:nonsense by bmo · · Score: 2

      Forensic investigation of a computer includes a capture of the machine's memory,

      But that doesn't mean you need to walk away with the whole machine. Unplugging it and carrying it out the door does nothing for preservation of data in DRAM, which needs power to refresh memory. You can yank the RAM out and put it in dry ice to keep things from discharging too quickly, but you are under a pretty strict clock to get the RAM unplugged and into the analysis machine on the crash cart. If you physically unplug the entire server and cart it out the door, you've lost whatever data that was in RAM by the time you reach the truck door.

      Taking the entire server or rack of machines is nothing but intimidation.

      --
      BMO

    39. Re:nonsense by lightknight · · Score: 1

      Forget to answer your question -> multiple overwrites, greater chance of getting those bit stragglers that refused to flip the previous times.

      I prefer the paranoid approach: just don't store anything supremely dangerous on a computer. Take the CIA's approach -> anything important is stored in people's heads only. And by people, I mean your head, and your head alone. And don't tell anyone about it. Sadly, it's the only safe thing you can do, as the Supreme Court has repeatedly failed to uphold your hypothetical right to privacy (and people looking for stuff won't care about that either -> they work on the mentality that it's only illegal if they get caught).

      --
      I am John Hurt.
    40. Re:nonsense by Leebert · · Score: 2

      If that were correct then backups would not be admissible evidence. They are.

      Welcome to Criminal Justice 101.

      Your first homework assignment is to read this:

      http://en.wikipedia.org/wiki/Best_evidence_rule

      Spoiler alert: Doing it is possible, but only in certain circumstances and it raises questions that you'd rather avoid as a prosecution. So they don't do it if they don't have to.

      (If it sounds snarky, I didn't mean to be. Trying to be funny but also informative...)

    41. Re:nonsense by mysidia · · Score: 1

      This requires a bit more work than simply putting code in one file in /etc/init.d under the "stop" function, called by one of the K-files in rc3.d, that deletes any incriminating files. Shutdown code is a lot less dangerous than having to deal with explosive charges.

      It's rather unlikely. Servers get rebooted all the time. There is a much simpler method: utilize full-drive encryption. When power is pulled, or a reboot occurs, the secured media becomes unreadable until actions are taken to decrypt and load encryption keys back into RAM and remount the secured volume -- then "pull the plug" as you suggest is destruction of evidence. The owner of the server may have a secret USB stick somewhere that is required to boot the server. Upon hearing that their server's are being seized, they go to their covert secure location, grab the USB stick and the backup stick, toss it them both a microwave, give it a good nuke, and then throw it in a dumpster somewhere. The servers' data is now impossible to recover.

      When explosive charges in confiscated servers becomes a significant issue, cops will start treating every confiscated server like it has explosive charges.

      The point is there are millions of possible methods of a server containing a data "self-destruct" mechanism, whether mechanical or logical; whether overt action is required by some mechanism, or the failure for some action to occur results in data becoming inaccessible. The practice that protects against one method ensures destruction of the data if a different method was used.

      If the server has unknown secured mechanisms for destroying the data, such as carefully attuned exploding charges/break the drive, or douse the disks in destructive acid, or logical methods, there's very little that can be done about that.

    42. Re:nonsense by Anonymous Coward · · Score: 0

      Deleted stuff is never erased, just marked as "free space" by the OS.

      Overwritten data, these days, is unrecoverable, even if only overwritten once [...]

      Exactly. When I delete logs to prevent outsiders getting hold of them, I don't use 'rm' which only marks the file deleted but doesn't touch the data. I use 'shred' instead. It overwrites the file multiple times if necessary before optionally deleting it. As far as I know, shred is part of standard Linux so you should have it too.

    43. Re:nonsense by Anonymous Coward · · Score: 0

      Of course not. We can't go around *educating* people, not even federal agents, because education is for socialist commies. It's a slippery slope - if we start educating our federal agents, then we'll have to educate more and more people, even those filthy poors and blacks and liberals.

    44. Re:nonsense by bmo · · Score: 2

      It overwrites the file multiple times if necessary before optionally deleting it. As far as I know, shred is part of standard Linux so you should have it too.

      There is another tool you might like, and that's bcwipe.

      It does shred, but it also wipes free space on currently mounted drives.

      Jetico's bcwipe is open source and cost-free for *nix if you compile it yourself (it's *not* GPL or Free/Libre).

      I like it. I use it often.

      --
      BMO

    45. Re:nonsense by Cabriel · · Score: 1

      Intended side effect: The server operator may be more more willing in the future to censor who uses his remailer for what purposes. Hey, if it becomes obvious that some dickweed is going to cause your remailing business* to be impeded, you might be willing to do something about it.

      "What?" you say. "Do something responsible? Perish the thought."

      *I don't know if the operator of the remailer was making any money from it. If he wasn't, then he was operating it for some reason, and that reason could be impeded by his server being raided in meatspace.

    46. Re:nonsense by Anonymous Coward · · Score: 0

      Mixmasters was designed

      That's a naive, technological point of view. Remember the XKCD comic with the wrench? http://xkcd.com/538/

      They just have to cause enough people who provide these services financial, legal and psychological hardship to deter them from even running such servers. Look at Germany for example: around here our glorious jackbooted thugs have regularly raided homes and seized all kinds of personal property of people who merely ran a Tor node on some server that wasn't even in their home. Unless you are willing to have your home raided and are ready to spend a lot of money on legal defense and explain to your friends and family why you were raided for terrorism/copyright infringement/illegal porn/random-crap-du-jour, running a Tor node isn't something you should do.

      Law enforcement merely has to make running those servers a liability to your safety.

    47. Re:nonsense by Anonymous Coward · · Score: 0

      Yeah, a forensics pro would put write blockers on the drives and image them immediately. The equipment itself was useless. They wanted the data...

    48. Re:nonsense by Tom · · Score: 1

      The server operator may be more more willing in the future to censor who uses his remailer for what purposes.

      Except that he can't. It's an anonymous remailer, even to the operator. That's kind of the whole point.

      Am I getting old when I look back and remember that there were times when people on /. generally knew what the heck they were talking about?

      *I don't know if the operator of the remailer was making any money from it.

      You could know if you'd know anything about remailing. The operator didn't make any money from it, because there is no way that you can. Since it is (I'm repeating myself here) an anonymous remailer, you simply wouldn't know where to send the bills. And since the mails are encrypted, you can't add any advertisement into them, either.

      --
      Assorted stuff I do sometimes: Lemuria.org
    49. Re:nonsense by Tom · · Score: 1

      All that happens is the next jerk who wants to send threats uses another anonymous service, this time in a different country.

      Not even that. He'll simply use a different chain of remailers. If he selected the chain randomly (which is recommended anyways), he won't even notice.

      --
      Assorted stuff I do sometimes: Lemuria.org
    50. Re:nonsense by Tom · · Score: 1

      That can happen at a physical layer too.

      But not in a shared server provided by the hosting company. ;-)

      --
      Assorted stuff I do sometimes: Lemuria.org
    51. Re:nonsense by Tom · · Score: 1

      They just have to cause enough people who provide these services financial, legal and psychological hardship to deter them from even running such servers.

      True, but then you forget that these are freedom-loving communist hippies. Chances are that you've just caused half a dozen people who were on the edge to start running a remailer.

      Not like it hasn't happened before...

      --
      Assorted stuff I do sometimes: Lemuria.org
    52. Re:nonsense by Anonymous Coward · · Score: 0

      > There has not been a single criminal case that I can remember where data was overwritten and then recovered on modern drives.

      Because such cases never reach the court, or at least not the open and public courts. Those cases are CIA / NSA / FISA at best.

      By the way, Ku:rt of Hungary will recover anything bitish from anything IT if you have the money - burning, hammering, grinding, magnetizing are no obstacle.

    53. Re:nonsense by Anonymous Coward · · Score: 0

      Johnson testified that he found two attempts to delete data on Manning’s laptop. Sometime in January 2010, the computer’s OS was re-installed, deleting information prior to that time. Then, on or around Jan. 31, someone attempted to erase the drive by doing what’s called a “zerofill” — a process of overwriting data with zeroes. Whoever initiated the process chose an option for overwriting the data 35 times — a high-security option that results in thorough deletion — but that operation was canceled. Later, the operation was initiated again, but the person chose the option to overwrite the information only once — a much less secure and less thorough option.

      All the data that Johnson was able to retrieve from un-allocated space came after that overwrite, he said.

    54. Re:nonsense by mrogers · · Score: 1

      Unless the server operator was a total dofus, this brings them exactly zero steps towards resolving their problem, because this is exactly the kind of attack that Mixmasters was designed to withstand.

      I'm not sure you're right about that. Unlike the more recent Mixminion design, Mixmaster doesn't provide forward secrecy. Each mix uses a long-term public/private key pair. To send a message anonymously, you encrypt it with the public key of each mix you want it to pass through, and each mix uses its own private key to remove a layer of encryption. The last mix in the chain removes the last layer of encryption and delivers the message to its destination. The mixes carry on using the same key pairs indefinitely.

      Now imagine you have the wiretapping and server-seizing powers of the FBI and you want to trace a message. You wiretap all the mixes and record the encrypted messages passing between them. When an unencrypted bomb threat pops out of one of the mixes, you seize that mix and use its private key to decrypt all the messages you recorded arriving at that mix. One of them decrypts to the bomb threat. You seize whichever mix that message came from and repeat.

      This attack has been known about ten years, which is why Mixminion changes its key pair periodically and uses TLS on the connections between mixes. But remailers don't get much attention these days, so it seems people are still using Mixmaster.

      TL;DR: You can trace messages by seizing Mixmaster servers. Expect more servers to be seized in the coming days.

    55. Re:nonsense by allo · · Score: 1

      and its quite useless, if you're using a journaled filesystem.

    56. Re:nonsense by allo · · Score: 1

      so you say, when i write a file (if you want to, with all zeros, but this shouldn't matter for that issue), i can not assume its on the disk like it wrote it?

      okay, disk manufacturers say there is a 1e-10 chance or something of a bit not being written correctly, but this is low enough ... ... to provide that all my files are written the way they should be ... one single erase is enough. when one or two bits are left, they cannot contain anything like an evidence, as every evidence clearly needs more than two bit of information.

    57. Re:nonsense by lightknight · · Score: 1

      Each bit, on a hard disk, is made up of a number of atoms. When the majority of them are magnetically oriented one way they read as a 1, and when they are oriented another, they read as a 0. When you write something, the majority of atoms, for that bit, flip. If you read in a series of those bits with a standard program, they will read back exactly what you wrote.

      Now, assume someone has your hard drive in a clean room. They take off the lid, and use a very sensitive head to read all the atoms that make up each bit. The majority of them will say whatever you last wrote there, but a small handful will still say what they were from the write previous to that one. Digital is implemented on top of analog devices. Perhaps the drive head was a little closer to the spindle on the previous write, perhaps a little further out. At which point, 90% of the track will have the most recent file, and 10% of the track will have the second most recent file. Got it? Due to the way things work, the past several recent files may be recovered.

      It's not one or two bits. It's several atoms per bit. And when you factor in file checksums (every operating system implements something that could work here, as well as the hardware level checksums), you have a more than fair chance at recovering some data. Hypothetically, anyway.

         

      --
      I am John Hurt.
    58. Re:nonsense by Anonymous Coward · · Score: 0

      Deleted stuff is never erased, just marked as "free space" by the OS.

      Unless it's an SSD.

    59. Re:nonsense by fafaforza · · Score: 1

      So do you honestly want the FBI to tell the people they are investigating that they will be coming in one hour to seize their system? Hope you have enough time to remove anything you might not want us to see? The amount of anti FBI venom on here is really grating, simply because it has to do with a computer.

    60. Re:nonsense by bky1701 · · Score: 1

      "Deleted stuff is never erased, just marked as "free space" by the OS."

      On some filesystems, that is enough to make the data unrecoverable. Just not the more common ones like NTFS and EXTn.

    61. Re:nonsense by evil_aaronm · · Score: 1

      No, the proposition was that the FBI simply could not avoid taking the entire machine with them. That's baloney. And they didn't need to provide any further warning for the raid, either. It's simple: Walk in unannounced, seize the machine, dupe the drive, put the new one in, take the original, machine is back in business. This is not exceptionally onerous for the FBI. We in the real world do it all the time. They just don't care about the people they raid, or collateral damage. I'm gonna say that's because there's practically no accountability. What is a sys-admin to do when the FBI shows up and takes the entire machine? Exactly: stand there and watch, and hope they don't shoot you, taze you, or arrest you for resisting arrest.

      And it's nothing to do with taking the computer that rubs some of us the wrong way: it's the total authoritarian attitude and behavior from the FBI. S'pose anyone could call up and ask for that machine back, or any further information about the investigation? Good luck with that. America fought against that shit when it came from King George. Why should we tolerate it any better when it's internal? It's still wrong.

    62. Re:nonsense by Anonymous Coward · · Score: 0

      I have done data forensics. That's not the first thing I learned.

      It's the same data if it matches the hash of the data on the original storage medium. If the original storage medium is not captured, the first copy, with a verified matching hash, is the best evidence and become the gold standard for comparing hashes if additional copies are made or need to be verified for the trying court.

      At some point, the judge/jury needs to trust the prosecution's evidence chain. Hashing the data moves that point as close to collection as possible. If all you were relying on is the presence of the physical media, and no hash, you're depending on the judge/jury trusting that the holder of that device did not modify the contents at any point between collection and trial. Once there's a hash, then any alteration can be detected and would need to be explained to the court.

      Want another monkey wrench for your statement? two words: Virtual Drives. When the host is virtualized, it's even easier to capture the drive contents. Create a snapshot, and clone the drive. In fact, that often gets you a snapshot of the volatile memory too, which can be even more useful.

      In such a case, the worst thing a law enforcement agency can do would be to kick the rack over and start pulling drives. They'd lose important artifacts and give themselves much more work to do sifting through everything trying to find the drive contents that were already there sitting in a nice, neat file for them if they only knew.

      That's an issue of education, and a reason why high-tech crime fighters need knowledgeable assistance when entering a datacenter.

    63. Re:nonsense by tibit · · Score: 1

      You're welcome. I have learned a bunch of stuff here as well. As far as non recoverability of zeroed-out data goes, nothing really beats a modern hard drive. Personally I think drive-level encryption in the drive can't be trusted for non-recoverability because I'm sure they can store the key somewhere where the informed governments can read it, it's not hard to hide it well enough. So, basically, there's no way to audit an encrypted hard drive to ensure there's no backdoor to the cryptographic key, so it can't be trusted for non-recoverability. Heck, there are many drives that store the plaintext password to the key, and there are even free tools that can recover that for some drive families! Then there are non-free tools that run a couple $k that recover that for most any drive out there, so it makes a bit of a joke of the whole on-drive-encryption thing.

      --
      A successful API design takes a mixture of software design and pedagogy.
    64. Re:nonsense by Anonymous Coward · · Score: 0

      Defense Attorney: Agent Smith, it says here your compromised the defendant's server in an attempt to obtain access to the data on the machine without the defendant's knowledge, is that correct:

      Agent: Yes.

      Defense Attorney: So you made modifications to the security and trustworthiness of the defendant's computer?

      Agent: Yes.

      Defense Attorney: Therefore you cannot prove you were the only person with access to the data you are using to implicate my client, correct?

      Agent: ...But...but...but...terrorists...and marijuana...and copyrights...and...

      Judge: Case dismissed, learn about security and documenting who has control over what, thanks for playing.

    65. Re:nonsense by LanMan04 · · Score: 1

      Have you ever done data forensics? The first thing you learn is that it's not the same data if it's not on the original storage medium.

      As a matter of fact, yes I have. The the first thing you do is clone the drive to as close to an identical drive as you have and then work on THAT, using a write-blocker.

      What, do you sit around combing through the ORIGINAL drive with EnCase using a write-blocker all day? What happens when the original drive goes tits up due to you banging on it all day? It should be sitting in an evidence locker.

      This discussion excluded SSDs, which do all kinds of wonky shit in the background that not even a write-blocker can protect you from...

      --
      With the first link, the chain is forged.
    66. Re:nonsense by EdwinFreed · · Score: 1

      This approach only works if the messages continue to be sent using the same mix. Which given all the publicity this has gotten and how these sorts of crazies tend to monitor every reference they get in the media, seems very unlikely.

      More specifically, they've seized one server, presumably after monitoring it for some time and capturing all the incoming messages. Now they use the private key to re-encrypt the message and look for a match among the incoming traffic. Assuming that traffic wasn't sent using a TLS mechanism with perfect forward secrecy, they now have the IP address of the next to last server in the mix. But what they don't have is any recordings of the traffic getting to that server. And unless the person sending these messages sends some more using the same mix, they will never be able to catch any.

      I supppose it's possible that after monitoring the traffic, they also started monitoring traffic coming in to every host that ever sent this system mail. But I'm dubious of the practicality of that, both in the legal and technical sense.

      What they should have done is use one of those handy-dandy national security letters or whatever they are called to gain access to the server in secret. They could have pried the private key loose that way, then initiated monitoring on the next server up the chain, another letter, and so on.

      Of course this also falls apart if one of the servers is some place that doesn't like the US and won't honor requests from US law enforcement.

    67. Re:nonsense by Obfuscant · · Score: 1

      It's rather unlikely. Servers get rebooted all the time. There is a much simpler method: utilize full-drive encryption.

      Adding a step to the shutdown process is simple, it's trivial to install, and it's trivial to turn off if you need to reboot. You can install something like that remotely -- you don't even have to have physical access to the system, and you can do it to a virtual machine without causing any harm to any other user of the physical hardware. You can't be forced to turn over a key to an encrypted file or disk if there is no file to decrypt, and there is no incriminating encrypted data to make the cops curious.

      The point is there are millions of possible methods of a server containing a data "self-destruct" mechanism,

      Yes, there are, but just like everday life where there are millions of possible things you could have for lunch, there is a much more limited number of highly likely possibilities. It is extremely unlikely that anyone will install a system in a datacenter that contains explosive devices to turn the system into shrapnel if a network cable is disconnected. The triviality of a shutdown-based 'shred' command makes it much more likely.

      If the server has unknown secured mechanisms for destroying the data, such as carefully attuned exploding charges/break the drive, or douse the disks in destructive acid, or logical methods, there's very little that can be done about that.

      Oh, well then. Since it is very hard to defeat an explosive self-destruct, lets not bother doing anything to try to keep any other means of deleting data from happening. We might as well do a clean shutdown and let what happens happen. Or we might as well just ask the owner to pretty please make us a backup copy of all his files so we can look at them, right?

    68. Re:nonsense by bmo · · Score: 1

      By the way, Ku:rt of Hungary will recover anything bitish from anything IT if you have the money - burning, hammering, grinding, magnetizing are no obstacle.

      Really? They defeat the laws of physics when you have heated the platters above the Curie point they can get the data back?

      If I grind the oxide off, they can put the oxide back on?

      They can reconstruct the platters after I've shattered them with a .45ACP?

      How come the entire world doesn't know this?

      --
      BMO

    69. Re:nonsense by Anonymous Coward · · Score: 0

      its too bad they cant grind down the be-as-much-of-an-asshole-as-possible-when-unaccountable component of your online persona.

      I'm going to call it right now. this douche gets "internet time" from his mom.

    70. Re:nonsense by mrogers · · Score: 1
      This case is unusual in that there's been a long series of bomb threats - they could easily have started monitoring all known remailers a week ago. But I wouldn't be surprised if they had all known remailers under surveillance all the time - especially since they know that's necessary if they want to trace a message at any time in the future.

      What they should have done is use one of those handy-dandy national security letters or whatever they are called to gain access to the server in secret. They could have pried the private key loose that way, then initiated monitoring on the next server up the chain, another letter, and so on.

      Interesting point - I wonder if they though the Riseup admins would blow the whistle and go to jail.

      Of course this also falls apart if one of the servers is some place that doesn't like the US and won't honor requests from US law enforcement.

      True. Watching this unfold could be an interesting lesson in the international reach (or not) of wiretap and seizure orders.

    71. Re:nonsense by bmo · · Score: 1

      He came out and basically said that company can perform magic. It was bullshit.

      >me being an asshole

      *holds up mirror*

      I have said before, get an account here, set your foe settings to -6 and foe me. It's one of the better Slashdot tools. You get the benefit of not ever seeing one of my posts ever again.

      But that is apparently too complicated for you.

      --
      BMO

    72. Re:nonsense by allo · · Score: 1

      show me someone, who says he can do this.

    73. Re:nonsense by mysidia · · Score: 1

      Adding a step to the shutdown process is simple, it's trivial to install, and it's trivial to turn off if you need to reboot.

      You don't necessarily control all reboots. Reboots sometimes are a result of application or OS failure, for example the INIT process receives a SIGINT signal. Under certain circumstances system management applications will issue reboot as an automatic response to a problem.

      It is extremely unlikely that anyone will install a system in a datacenter that contains explosive devices to turn the system into shrapnel if a network cable is disconnected.

      It's neither necessary nor likely that someone stuffs a server with a charge sufficient to turn the server into shrapnel; they only need the disk drive coated with enough material to destroy the drive inside the chassis, and extra shielding around the disk drive cage. If there was a risk of the server becoming shrapnel, this could endanger the server operator, and create unwanted risks, loss, and liability, should it accidentally be engaged.
      A mechanism to destroy the hard drives should effect the hard drives but no other system components.

      Also, there are self-destroying drives on the market.

    74. Re:nonsense by holdenweb · · Score: 1

      The point of the action wasn't necessarily to gain intelligence from a forensic analysis, but to inconvenience a perceived "enemy of the state" and serve as a warning to others who are contemplating similar activities.

    75. Re:nonsense by holdenweb · · Score: 1

      You do realize, I suppose, that by "switching the server to single-user mode" you destroy valuable forensic data? The correct procedure in such forensic investigations is to first capture all the non-volatile data (primarily RAM-based), then to REMOVE POWER (pull the plug from a server, remove the battery from a laptop). Only that way can you avoid shut-down procedures deleting further valuable information from the disk. Then you image the disk, take the original drive as evidence and (assuming you give a shit about the continued operation of the system, which the FBI clearly don't) leave the system with the copy. This assumes, of course, that you have the legal right to sieze property. This should require a warrant, which is supposed to allow judicial supervision. Sadly the judiciary are closely aligned with law-enforcement and extremely badly informed about IT, so a warrant isn't difficult to obtain.

    76. Re:nonsense by Em+Adespoton · · Score: 1

      Indeed. My point was talking about the evidence, not talking about corrupting the original drive by poking around in it unnecessarily. You don't just image the drive and let the GP keep on using it, like the GP was suggesting (this story is about confiscating the drives having residual effects).

    77. Re:nonsense by gweihir · · Score: 1

      Depends on the amount of traffic data they have for the Mixmaster network. Apparently a lot of bomb threats are sent by these people. That could make correlation attacks on the Mixmaster network possible. In this case, this raid would have been about gathering evidence.

      However, if that is the case, I am wondering why they did not compromise a lot more Mixmaster nodes. A single node seem not very useful, unless they found a pattern that looks like it was first-in-chain. Even then, going after the sender directly would have been better, because they are now alerted. Maybe somebody with some kind of semi-knowledge of how Mixmaster works made that decision.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    78. Re:nonsense by gweihir · · Score: 1

      The server operator may be more more willing in the future to censor who uses his remailer for what purposes.

      Except that he can't. It's an anonymous remailer, even to the operator. That's kind of the whole point.

      Am I getting old when I look back and remember that there were times when people on /. generally knew what the heck they were talking about?

      Seems to be getting worse lately (last few years). My impression is that CS studies have been massively dumbed down over the last two decades. Maybe CS is getting to hard to understand with the CS education younger people are getting at universities.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    79. Re:nonsense by gweihir · · Score: 1

      Oops, cut a quotation mark too many. Up to "generally knew what the heck they were talking about?" it is supposed to be quoted.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    80. Re:nonsense by hendrikboom · · Score: 1

      then it's possible to recover previously written data even after it's been overwritten, because erasure isn't complete, the heads weren't perfectly aligned so only most of the signal for each bit was overwritten, There's still a trace of the original magnetism slightly biasing the new, etc.m all of which will not be present in the copy. Serious forensics can tease out this stiff. There's a reason why security erasure is a bigger deal than just reusing space.

    81. Re:nonsense by hendrikboom · · Score: 1

      Sorry. Other posts make it clear that that's no longer practical on modern, state-of-the-art drives. I stand corrected.

  7. Damn you George Bush! by Vinegar+Joe · · Score: 3, Funny

    I can't wait for the elections to come!

    --
    "The average reporter we talk to is 27 years old......They literally know nothing." - Ben Rhodes
    1. Re:Damn you George Bush! by Anonymous Coward · · Score: 0

      I can't wait for the elections to come!

      George Bush? Obama is the current president. Blame him.

    2. Re:Damn you George Bush! by Anonymous Coward · · Score: 1

      Whoosh.

    3. Re:Damn you George Bush! by Anonymous Coward · · Score: 0

      Racist!

    4. Re:Damn you George Bush! by darthdavid · · Score: 1

      The whoosh you heard was the joke going over your head.

    5. Re:Damn you George Bush! by Anonymous Coward · · Score: 0

      Nope. President George Bush started this mess and President Obama would like to fix it but for some reason he can't. But it's not his fault!

    6. Re:Damn you George Bush! by Threni · · Score: 1

      To be fair, it wasn't remotely funny; it was more a sort of a flaccid, farting sound.

    7. Re:Damn you George Bush! by cpu6502 · · Score: 1

      Damn you Mitt Romney!
      (I come from the future.)

      --
      My AC stalker: " I personally agree with your posts most of the time, but that won't keep me from modding you troll"
    8. Re:Damn you George Bush! by darthdavid · · Score: 1

      So more of a thppt than a woosh?

    9. Re:Damn you George Bush! by man_of_mr_e · · Score: 0

      The president's only real power is to sign into law what congress passes (or veto it). If the president wants to pass a piece of legislation, he must get congress to first pass it, so he can sign it.

      Guess what congress is NOT doing? Giving the president ANY legislation he wants to sign.

    10. Re:Damn you George Bush! by PRMan · · Score: 4, Funny

      I simply don't get this comment....If Obama was the god of freedom that Leftists claim, he would have overturned the over-extending post-911 policies of the Bush Administration such as the Patriot Act instead of reveling in them and expanding them like many non-liberals warned that he would.

      And you said you didn't get the joke...

      --
      Peter predicted that you would "deliberately forget" creation 2000 years ago...
    11. Re:Damn you George Bush! by Anonymous Coward · · Score: 0

      So more of a thppt than a woosh?

      That really depends on how strong your sphincter muscle is.

    12. Re:Damn you George Bush! by Anonymous Coward · · Score: 0

      I think you mean: Damn you Ron Paul!

    13. Re:Damn you George Bush! by TapeCutter · · Score: 1

      C'mon, who are you trying to kid, we all know the POTUS is emporer of planet Earth.

      --
      And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
    14. Re:Damn you George Bush! by evil_aaronm · · Score: 1

      If you don't totally support our efforts to make China and North Korea look like bastions of freedom in comparison, then you must be a terrorist! There is no in between, citizen! Why do you hate America?

      /snark

    15. Re:Damn you George Bush! by evil_aaronm · · Score: 3, Interesting

      Who needs legislation when the Pres has Executive Orders and legal council that will parse those orders 10 ways cubed to justify, if not make it look like the very definition of the "American Ideal" when, in fact, he's shitting on the Constitution? Remember "water boarding"? Was there any legislation for that? How about "extraordinary rendition"? "Free speech zones"?

    16. Re:Damn you George Bush! by bmo · · Score: 1

      10 ways cubed

      That's only a thousand.

      --
      BMO

    17. Re:Damn you George Bush! by Anonymous Coward · · Score: 0

      "Hey everyone! Let's go vote for Obama because of his skin color --- in order to show the world that America doesn't pay attention to petty things like skin color!"

  8. Not New by jimmerz28 · · Score: 2

    Whenever they take servers "down" it's like a ogre killing a spider with a tree trunk. They smash the table, furniture, and destroy the house along with the poor spider.

    1. Re:Not New by Anonymous Coward · · Score: 3, Insightful

      don't worry the spider will not be harmed it will walk out between the debris and find a new place to hide...

    2. Re:Not New by JonySuede · · Score: 1

      But the disgusting spider is dead !
      Most of the time it's all that they need to know.

      --
      Jehovah be praised, Oracle was not selected
    3. Re:Not New by Kjella · · Score: 3, Insightful

      You're assuming the message was for the spider and not for everyone who has a spider in their house. And the message is that if you carry a service we don't like, we'll make sure to inflict as much damage as possible when we come for it. You get a pretty good self-censoring effect out of it. Same reason TOR doesn't scale very well, you'd have to be mildly insane to run an exit node as a private person.

      --
      Live today, because you never know what tomorrow brings
    4. Re:Not New by Anonymous Coward · · Score: 0

      Can someone start hosting this stuff on Amazon, please? I'd just love to see the FBI wander in and empty racks upon racks trying to grab all the servers where someone's image had been running.

      The FBI must really be clutching at straws on this one though - the chances of there being any useful logs on those servers is really, really small. One might assume that if there are no logs to be found that the servers will be returned in a short time. However, we know that the purpose of this sort of action isn't really to gain evidence, it's about creating inconvenience, so I wouldn't expect those servers to materialise any time this decade. I just hope the ECN has been following all the best advice about "one click installs" and continuous delivery so they can get fresh servers up before the weekend's over.

    5. Re:Not New by gweihir · · Score: 1

      They did not take the server down, just made a forensic copy. Basically that means a sector-image.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    6. Re:Not New by jimmerz28 · · Score: 1

      Hence the quotations around '"down"'.

  9. Mass disruption by Anonymous Coward · · Score: 1

    This is the stage in CISPA legislation where they try to win over people by pointing out, "Look, everyone got disrupted so we could find one user. If the service would just share information with the Government..." These disruptions aren't necessary. If the government wants to scrounge through logs they can do so while the servers are running. Who are the judges approving all these stupid warrants?

    1. Re:Mass disruption by evil_aaronm · · Score: 2

      Well, hell, in that case, let's nuke NYC, LA, DC, Detroit, etc. There's gotta be more than a few criminals in those towns. Sucks for the collateral damage, but, you know, gotta weed out those bad guys. They probably hate America, too, so all the more reason.

  10. Haven't they done this several times now? by Anonymous Coward · · Score: 0

    This is absolutely pathetic levels of basic networking knowledge.

    How does an agency even exist so thick as that when it comes to actually policing the internet?
    Get a grip already FBI, you are embarrassing.

    Hope they get sued for disruptions.
    Oh, wait, suing FBI is like pissing in the cornflakes of the leader of a country.
    Good luck winning.

  11. Ineffective by Anonymous Coward · · Score: 0

    If the intent is to stop bomb threats at University of Pittsburgh, it much easier and simplier to stop all internet and mobile traffic at the University of Pittsburgh. Stopping a mail server that do not store any logs will do nothing beside give the police some newspaper headlines.

  12. So someone sends some bomb threats .. by n5vb · · Score: 4, Interesting

    ..and the FBI seizes the server they used?

    Anyone else think this is more believable as a denial of service attack, or as a pretext for taking down a troublesome server they couldn't legally seize by any other means, than as an actual threat?

    Unless the person sending them was stupid enough to think that a remailer would protect them from ever being caught, and didn't care that it was going to mean taking down the whole service for everyone else using it..

    1. Re:So someone sends some bomb threats .. by Guppy06 · · Score: 1

      Unless the person sending them was stupid enough to think that a remailer would protect them from ever being caught, and didn't care that it was going to mean taking down the whole service for everyone else using it..

      And you've just answered your own question! Don't worry, though, as I'm sure that this remailer was only the first of his Seven Proxies.

      New to the internet much? People are stupid.

      Besides, you're assuming that the perpetrator is both smart enough to be using this as a sideways method of getting the servers taken down and yet stupid enough to do it by way of a major felony that will practically land your ass in Gitmo if it goes wrong.

    2. Re:So someone sends some bomb threats .. by Zorque · · Score: 1

      Whoever it was didn't care that they were disrupting people's lives by having their classes cancelled over and over (and over, and over, and over. It was a continuous and practically psychotic series of threats), so of course they didn't care about getting a remailer taken down. I've spoken with people who live on campus there and the person sending the threats is clearly unstable at best.

    3. Re:So someone sends some bomb threats .. by the+eric+conspiracy · · Score: 1

      Any decent ISP will have a backup and have the service up and running again forthwith.

      If the customers are truly disrupted by this they would also be by any number of possible issues including something as basic as a drive going bad.

    4. Re:So someone sends some bomb threats .. by WrecklessSandwich · · Score: 1

      See this comment for some clarification on the situation. It's not "some" bomb threats, it's over one hundred bomb threats against specific buildings at a university with 28,000 students. They threaten academic buildings during class hours. They send in threats for dorm buildings in the middle of the night so that everyone has to be woken up and evacuated. They even sent a bomb threat to the hospital on campus, causing all of the patients to have to be evacuated. This is absolutely not some kind of convoluted plot to get a server shut down.

  13. Can You Say False Flag Opp? by msaroff · · Score: 5, Interesting

    Someone bosts a gazillion bomb threats, and computers associated with OWS and other protests get seized.

    Awfully convenient.

    Any guess as to whether the bomb threats can be traced back th Langley or Ft. Meade?

    1. Re:Can You Say False Flag Opp? by evil_aaronm · · Score: 0

      Ya know, there was something funny about all those planes flying into buildings and what-not on 9/11. Kind of makes you wonder how all of that could've happened right under the noses of our ever-vigilant authorities. Unless it was an inside job... Nah - couldn't be...

    2. Re:Can You Say False Flag Opp? by WrecklessSandwich · · Score: 2

      Someone bosts a gazillion bomb threats, and computers associated with OWS and other protests get seized.

      Awfully convenient.

      Any guess as to whether the bomb threats can be traced back th Langley or Ft. Meade?

      Put down your tinfoil hat. This person has more or less paralyzed a major university campus for an entire semester and the FBI barely has anything to go on. They already subpoenaed/questioned/arrested everyone they can find that's had a major quarrel with the school in recent memory (and one nutjob from the 80s). They're grasping at straws with the remailer services they know were used because they don't have any other leads and finals week is coming up.

      While we're at it, TFA is pretty vague on the facts. Riseup calls the seizure "an attack against us", when the seized server was owned and operated by ECN. At the same time, the top of the page says "Riseup had a server seized by the US Federal Authorities". Either these groups are more closely related than their press release makes clear, or they're being deliberately misleading. It also doesn't help their credibility that they clearly state that the FBI had a warrant (which, being a warrant, is signed by a judge), and then they turn around and call it an "extra-judicial punishment". It's unfortunate that they've been inconvenienced by the situation, but they're acting like the server is gone forever. Playing the victim when 28,000 people are having their (already paid for) education compromised and the FBI didn't break any rules is not a good way to garner sympathy.

    3. Re:Can You Say False Flag Opp? by DdJ · · Score: 1

      If you're a conspiracy-minded crackpot who uses "follow the money" reasoning, then another obvious possibility is Verizon or AT&T.

      Why?

      Every time one of these bomb-threat incidents happens -- and they've been happening multiple times a day every day for quite a while now -- Pitt uses their emergency notification infrastructure to coordinate communication about them. And that means text messages to thousands of students.

      (Because of the whole "in loco parentis" thing Universities have to deal with, and because of the aftermath of Virginia Tech, and for all sorts of other reasons some of which Bruce Schneier recently articulated talking about this very topic, Pitt does not have the realistic option of scaling back their response. The minute they react less seriously, they're potentially open to massive lawsuits -- and that's if nothing happens. If the jackasses are waiting for a weaker response before doing something real, well, Pitt might not survive the aftermath.)

      Reports indicate that multiple students who didn't previously have unlimited texting plans have now been forced to upgrade to unlimited plans. Follow the money...

      Of course, that theory for what's going on is absurd to the point of being laughable. Can't be disproven, no, but come on...

      It's almost certainly the case that some drunk undergrad asshat thought it would be funny to make a bomb threat anonymously, figured out how to push the buttons on the anonymous remailer while sitting in a public library, and did it. (Well, once the "scrawled on the walls of a men's room" vector had been shut down, which is how it all actually started.)

      Let it spread to the level of a minor in-joke meme among even a small number of such folks, and you'd observe something an awful lot like what we're actually seeing now. Much more likely than government conspiracy, anti-occupy conspiracy, or mobile operator conspiracy (though of course we can't disprove any of those).

      Until the masses of American citizens, especially and particularly the "helicopter parents" of current undergrads, are willing to accept a security environment that involves cost/benefit analysis and the acceptance of some actual threat, what can be done? And it doesn't look like they're ready to accept that any time soon. "Think of the children!"

    4. Re:Can You Say False Flag Opp? by WrecklessSandwich · · Score: 1

      Well, if you want to follow the money, it costs the school/state/FBI (not really sure who foots the bill initially, but paying it back will likely be part of the sentence in the end) a few thousand dollars to do a bomb sweep. I sadly don't have a link I can cite, but I heard that sweeping the Cathedral of Learning costs them $30,000 per bomb threat there due to the size of the building. I'm not even sure how to make a conspiracy theory out of that, but I'm sure someone here will find a way.

    5. Re:Can You Say False Flag Opp? by Anonymous Coward · · Score: 0

      No because that idea is idiotic.

      Plus if you dont want to sound like a wild eyed jackass, at least spell a two letter abbreviation properly.

    6. Re:Can You Say False Flag Opp? by Anonymous Coward · · Score: 0

      Well, they don't really need to be the source of the threats, now do they?
      They can just tell a judge that the threats were traced to this server and they need to confiscate it for further examination.

  14. What other reason for anonymous remailers.. by Anonymous Coward · · Score: 0

    Than to be used for dastardly and nefarious things.

    1. Re:What other reason for anonymous remailers.. by Anonymous Coward · · Score: 0

      What dastardly and nefarious things are you up to Anonymous Coward?

    2. Re:What other reason for anonymous remailers.. by evil_aaronm · · Score: 1

      Well, duh. Anyone using them must be a terrorist. People who don't hate America don't hide their communications. It makes it hard for the authorities to keep track of what everyone is doing. There's no good reason to want that, unless you hate America! /geezIhopenoonetakesthisseriously...

  15. Waiting for FBI to "take down" ATT and Verizon by Anonymous Coward · · Score: 0

    I am sure more than one bomb threat has been sent via their networks.

    Better haul all their equipment into the base to make sure we get the evidence we need.

    Stupid cop, no donut.

  16. pre-emptive visibility by Onymous+Coward · · Score: 1

    Could you develop a service for allowing anonymous communication that you gave the FBI pre-emptive visibility into without compromising the anonymity of the system?

    Allow the FBI to snapshot the whole hard drive and peruse it at their leisure any time they requested.

    Perhaps the FBI wouldn't trust you and your fancy transparency, but maybe you could make it plausibly accurate enough such that a server confiscation would be equal to an unwarranted attack from a legal standpoint.

    1. Re:pre-emptive visibility by Anonymous Coward · · Score: 0

      Um... no? Why bother with anonymity if as soon as someone with power decides to check into it, you're found out? This makes no sense from an anonymity standpoint, and from a non-anonymous standpoint it's just wasted effort. If you're trying to hide your communications from nearby drug-dealers, there are much safer and more useful methods than not-really-anonymous mail.

    2. Re:pre-emptive visibility by Anonymous Coward · · Score: 0

      I think I just answered my own question.

    3. Re:pre-emptive visibility by Onymous+Coward · · Score: 1

      Sorry, I didn't make myself clear.

      The idea is that your system keeps no logs, as is typical for these anonymity-providing services, so the anonymity is preserved. And it makes this anonymity clear to the authorities by providing complete visibility into the hard drive contents at the FBI's requests. Voilà, law enforcement has no reason to take your server down. They're not going to get any additional information.

      The sticking points I see:

      • thermal freezing of RAM for memory recovery may make physical confiscation still desirable
      • the attackers may not believe the accuracy of your hard drive content reports
      • (ad hoc) hard drive reports may leak information and undermine anonymity
      • exact software state (which programs and versions being used and their configurations) may increase vulnerability to intrusion

      My intuition says it may be possible to overcome each of these.

  17. Anonymous vs anonymous by milbournosphere · · Score: 2

    From what I can tell, the service was providing anonymous re-mailer services, not re-mailer services to Anonymous. This being the case, they're not going after a service used by the hacker group; they're going after a service offering anonymous communications to your average citizen. Not cool, gov'mint, not cool.

  18. They had a warrant. by cpu6502 · · Score: 5, Interesting

    They followed proper constitutional procedure (for a change). So blame the judge not the fbi.

    --
    My AC stalker: " I personally agree with your posts most of the time, but that won't keep me from modding you troll"
    1. Re:They had a warrant. by lbft · · Score: 1

      I blame the FBI for seeking a moronic warrant in the first place.

    2. Re:They had a warrant. by Chazerizer · · Score: 2

      And, in addition, the company who provided the service had agreed to cooperate with the investigation: http://www.post-gazette.com/stories/local/neighborhoods-city/internet-service-to-help-in-probe-of-pitt-threats-631734/ God that title is really misleading.

    3. Re:They had a warrant. by Anonymous Coward · · Score: 0

      Why is it always an either/or situation? Blame both. The judge obviously is not qualified to vet a warrant partaining to computers. The FBI are idiots and/or malicious and don't care who else they stomp on while parading around in their windbreakers and flashing their badges. Their policies state "grab the server before something happens to it" and they grab anything and everything they can get away with.

    4. Re:They had a warrant. by evil_aaronm · · Score: 2

      As little as I appreciate the FBI, you can't fault their approach. Always ask for more than you need: you might not get it - but then again, you just might.

    5. Re:They had a warrant. by Anonymous Coward · · Score: 0

      And is why any officer of the court needs to get their ass handed to them when they ask for too much.

  19. Why seize a server for more than clone time? by PeterM+from+Berkeley · · Score: 1

    Why should a server EVER be seized as "evidence"?

    Why not just have an FBI team come in, temporarily shut down the server, clone all the data, and then leave, and the server comes back up?

    --PM

    1. Re:Why seize a server for more than clone time? by Anonymous Coward · · Score: 0

      Why not just have an FBI team come in, temporarily shut down the server, clone all the data, and then leave, and the server comes back up?

      And you, as the defendant, would trust the FBI not to tamper with the cloned evidence? (Because the FBI would be just as stupid to trust that you wouldn't alter it as soon as you got the servers back.)

      Your scenario:

      Judge: So, what did you find?
      FBI: Lotsa incriminating stuff! Look at this 0xFF byte! Drive was fulla ones when we mirrored it!
      Defendant: Bullshit! That's not even my hard drive! My hard drive reads 0x00! It's fulla zeroes!
      FBI: Bullshit! Our copy is correct, you just erased yours!
      Defendant: Bullshit! Your copy's the bogus ones, you put all those ones there to incriminate me, or maybe you forgot to erase your spare drive before you imaged mine, or... Judge: One of you is lying to me. Problem is, I can't tell which.

      Why they pretty much have to seize the server, even when they're working in good faith and not trying to send a message to other innocent customers of the datacenter:

      Judge: So, what did you find?
      FBI: Lotsa incriminating stuff! Look at this 0xFF byte! Drive was fulla ones when we mirrored it! Don't beleive us? We've got the drive, still sealed in a little baggie. It's got his fingerprints all over it from when he installed it in the cabinet.
      Defendant: Bullshit! That's not what's on my hard drive! 0x00! It was fulla zeroes!
      Judge: OK, Mr. Defendant, if you think the FBI's lying to me, why don't the three of us find someone with a disk imager, open the baggie and re-image the drive.

    2. Re:Why seize a server for more than clone time? by TapeCutter · · Score: 1

      Even if goons knew how to clone the data onsite, the act of copying will open a huge can of worms in any subsequent court case, moreso if you allow the owner of the server to do it. It's nothing new really, they did the same thing with filing cabinets long before server rooms existed. However there must be a better way to do it, courts routinely demand 'records' be handed over without sending in the goons in to empty your server room.

      --
      And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
    3. Re:Why seize a server for more than clone time? by Anonymous Coward · · Score: 1

      It's not an evidence thing. You can't show magnetized domains to a juror. That means _anything_ you put in front of them will be a copy. All that matters, then, is chain of custody of the "information"--that is, who copied what to where.

      They take the servers out of convenience. It's just plain easier to do forensics work in a lab.

    4. Re:Why seize a server for more than clone time? by Anonymous Coward · · Score: 0

      There are legal requirements that mandate they use the original and not a replica as evidence.

    5. Re:Why seize a server for more than clone time? by gweihir · · Score: 1

      From the message of the server operator, just the HDD was imaged and the server is up again with changed keys. Also, he wrote "the police", the term "FBI" is never mentioned in his messages.

      Seriously, people, maybe inform yourself about what is known before starting to complain?

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  20. Collateral damage by nurb432 · · Score: 1

    Hey, we are in a war with something or other.. a little collateral damage is expected.

    Suck it up or get put on a dissident watched-list.

    --
    ---- Booth was a patriot ----
  21. Re:Did they at least manage to figure out what ser by evil_aaronm · · Score: 4, Funny

    Man, you would not believe the rush you get from going all commando on racks of servers. "Blink those lights funny at me, beeyotch, and I'll bust a cap right between your USB ports!"

  22. Hmmmm..... by Anonymous Coward · · Score: 0

    What else could be expected? We have almost unlimited power of a "law enforcement agency" mixed with technical ignorance and a high dose of arrogance

  23. Re:Captain America: The First Bully by TapeCutter · · Score: 1

    The first may have been Goliath or God, definitely not Captain America.

    --
    And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
  24. Re:Did they at least manage to figure out what ser by Anonymous Coward · · Score: 0

    Aaron, Aaron, Aaron.... calm the fuck down man.

  25. Anonymous communication, a right? by jpapon · · Score: 1
    Is anonymous communication really a right? It's a relatively new thing in human interaction, is it really necessary, or beneficial?

    I'm not stating an opinion one way or the other, I'm honestly asking, what do we really gain from truly anonymous communication? The things we lose (i.e. accountability for things you say) are clear, so I'm just asking, what are the benefits to society?

    Isn't free speech enough? If we truly had the right to free speech, why would anonymity even be necessary?

    --
    -- Let us endeavor so to live that when we pass even the undertaker shall be sorry. -- M. Twain
    1. Re:Anonymous communication, a right? by Anonymous Coward · · Score: 0

      Been around as long as bathrooms have had walls and stalls at least, so it's not really that new.

    2. Re:Anonymous communication, a right? by evil_aaronm · · Score: 1

      I would argue that anonymous == private. If you don't know who's saying it, it doesn't really matter what's being said or who hears it: my ability to communicate with whomever is safe. To a point, of course. Giving up obvious tactical information, for example - "The Harlequin will attend the meeting at 10:00, dammit, on time!" - kind of defeats the purpose, if you're the Harlequin trying to evade capture. And, yes, I know he showed up early in that instance.

      In the Pitt case, one person is broadcasting to all and sundry and he's not hiding anything in the message. And his message is clearly unlawful and unsupportable. However, it doesn't have to be that way. It could be a message that's understood only by two people - "The monkeys are restless and my dog has fleas." - even if it is in the clear.

      I don't think I need to argue that private communication is an absolute must. Consider how well the American revolution, for example, would have progressed if every citizen was prohibited from communicating privately.

    3. Re:Anonymous communication, a right? by BitterOak · · Score: 1

      Is anonymous communication really a right? It's a relatively new thing in human interaction, is it really necessary, or beneficial?

      I guess that depends on what you mean by "relatively new thing", as Common Sense, the pamphlet distributed anonymously by Thomas Paine, who has been called the father of the American Revolution is more than 200 years old. As to whether or not such speech is beneficial or not, I suppose it depends, at least in part, on whether or not you think the American Revolution was a good idea.

      --
      If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    4. Re:Anonymous communication, a right? by currently_awake · · Score: 1

      If your government is doing something horrible and illegal and you tell (and they know it was you) they will punish you. If you can do this without them knowing who told everyone then they won't punish you. If you want to live in a free country you must have anonymity.

    5. Re:Anonymous communication, a right? by betterunixthanunix · · Score: 1

      Is anonymous communication really a right?

      It is in America, since it is vital to free speech. Unpopular minorities may be unable to exercise their right to free speech if they are forced to attach their real name to that speech. This country was founded by men who published documents anonymously.

      --
      Palm trees and 8
    6. Re:Anonymous communication, a right? by NeverSuchBefore · · Score: 1

      I'm honestly asking, what do we really gain from truly anonymous communication?

      Honest opinions. Privacy. Protection from those who would abuse us (including government, random criminals, and corporations, assuming you're even trying to be anonymous). The value of privacy should already be clear.

      The things we lose

      Losing things is okay if it's in the name of freedom.

    7. Re:Anonymous communication, a right? by robsku · · Score: 1

      Is anonymous communication really a right? It's a relatively new thing in human interaction, is it really necessary, or beneficial?

      I believe that anonymous communication is a right as long as someone can provide service to do that... And it's really not that new - consider how easy it has been for long time to achieve relatively high anonymous communication via plain mail system... Sure it's not perfect, but a letter written using computer or electronic typewriter sent using different mailbox (not post office) for each letter provides quite a bit of anonymity, even though it can be easier to track the person than one tech savvy poster using anonymous proxies / tor, etc. and anon re-mailer.

      I'm not stating an opinion one way or the other, I'm honestly asking, what do we really gain from truly anonymous communication? The things we lose (i.e. accountability for things you say) are clear, so I'm just asking, what are the benefits to society?

      Isn't free speech enough? If we truly had the right to free speech, why would anonymity even be necessary?

      I think anonymous communication has a load of huge benefits... One pretty obvious example being activists in oppressive countries criticizing the system anonymously to avoid disapearing after men in black paying a visit. Yes, I believe anonymous communication should be a protected right.

      --
      In capitalist USA corporations control the government.
  26. Bullshit, but with an extreme reason by Anonymous Coward · · Score: 0

    I get the FBI just destroys everything. I am not defending them. It seems a fact was left out of this-

    One of my direct relatives works for the University in question, and has personally kept me up to date on now over 100 separate
    individual bomb threats at totally random times over the last month. They come for certain schools within the University, and sometimes
    at 4 am for dorms, removing all the students. They are specific. It is a major University, and driving them insane.

    Who ever this worthless fucker is, I hope they throw them in jail, but I agree, heavy handed, idiotic removal of anonymous servers does
    nothing at all technically speaking. It's amazing how inept the FBI is. It would be the equivalent of a 12 yr. old not knowing they shouldn't
    shit their own pants when they have to go to the bathroom.

    Doesn't anyone train these tools? Is basic IT knowledge unknown to them? How can they be just that stupid and do the job they do?

    1. Re:Bullshit, but with an extreme reason by MrShaggy · · Score: 1

      The entire usa can be summed up like this.

      WMD's.

      Weapons of Missing Destruction.

      --
      I have mod points and I am not afraid to use them.
    2. Re:Bullshit, but with an extreme reason by Skapare · · Score: 1

      Maybe the university should shut down getting emails from whatever IP addresses these threats are coming from? Seems that would be basically the equivalent of taking out the remailer server, except that it doesn't have the collateral effects, and doesn't have the risks of the remailer being replaced.

      I'm assuming the IP addresses are not random. If they were, taking out ONE remailer would not stop the threats.

      --
      now we need to go OSS in diesel cars
  27. FBI = DOS? by wjcofkc · · Score: 1

    I wonder if it has occurred to the FBI that by yanking a server with other individuals and business' stuff on it, that they are conducting a DOS much like anonymous. It seems they played right into their hands even if it wasn't their intention to offer said hand. To the FBI: smooth move ex-lax.

    --
    Brought to you by Carl's Junior.
    1. Re:FBI = DOS? by the+eric+conspiracy · · Score: 1

      Crikey it's just an email forwarder. Replacement = installation of a new one in an hour or so.

    2. Re:FBI = DOS? by Skapare · · Score: 2

      And not only that, it is one that other mail servers have every right to refuse data or connections from if they want only communications which are fully traceable. Think about what objective exists by the FBI seizing a computer that was used (let's assume for sake of argument that this really was used in that way) to transmit these threats, but has no record of what was sent or where it came from. All it's doing is interrupting the ability to send anonymous mail. But specifically it interrupts the ability of the person making these threats from doing so. Is that a good idea? If it is, then why not configure the UofP computers to refuse connections from this or any other anonymous remailer. That should be just as effective. Why not just ignore the threats? These are all basically the same effect in that the threat maker is deprived of the communications.

      What are the implications of ignoring a threat? The threat might represent a real danger. Maybe there is a real bomb ... this time. Then ANY form of interrupting the communication represents the equivalent of ignoring the threat.

      I don't know what the best solution is. But we are currently acting irrationally out of insane public policy. On the one hand by not communicating we risk danger. On the other hand by communicating we real idle threats. We are our own problem and we need to find a solution to that.

      --
      now we need to go OSS in diesel cars
    3. Re:FBI = DOS? by Skapare · · Score: 1

      bad edits ... "real idle" should be "risk idle".

      --
      now we need to go OSS in diesel cars
  28. Can we get a little streisand effect? by mrmeval · · Score: 2

    Take your hacked router, your raspberry pi, your beagle board and fire up a remailer service off of some public wifi or other, run it off solar, coil leech, thermal gradient sucker, piezo traffic leech or whatever power you can get.

    Didn't someone do a patch to mixmaster so it could do hold and forward like fidonet?

    --
    I'd go on a Vegan diet but the delivery time from Vega is too long. --brownkitty
  29. Who will FBI the FBI ? by Taco+Cowboy · · Score: 5, Insightful

    "Look, We're the FBI. That means your fucked, no matter what you do."

    The question that is begging to be asked is ---

    Who will FBI the FBI ?

    --
    Muchas Gracias, Señor Edward Snowden !
    1. Re:Who will FBI the FBI ? by Anonymous Coward · · Score: 0

      The Secret Service have shown a flair for Female Body Investigation....

    2. Re:Who will FBI the FBI ? by Svartormr · · Score: 3, Funny

      "Look, We're the FBI. That means your fucked, no matter what you do."

      The question that is begging to be asked is ---

      Who will FBI the FBI ?

      The FBFBII ?

    3. Re:Who will FBI the FBI ? by Anonymous Coward · · Score: 1

      The question that is begging to be asked is ---

      Who will FBI the FBI ?

      We the people. Right after American Idol.

    4. Re:Who will FBI the FBI ? by Anonymous Coward · · Score: 0

      a 16 year old kid in his basement.

    5. Re:Who will FBI the FBI ? by Genda · · Score: 1

      Who will FBI the FBI ?

      That would be the CIA, but don't ask, its not part of their charter. If you want all the information on everybody, go to the NSA, of course then they have to shoot you, I'm sure you understand.

  30. There could still be evidence by elucido · · Score: 1

    Depending on how the machines are setup there could be evidence on them if they aren't properly configured.

  31. May First vs. University of Pittsburgh by Anonymous Coward · · Score: 0

    Interesting comments about this server by and the Pittsburgh community here:

    https://support.mayfirst.org/ticket/5583

  32. Re:Offtopic^2 by qubezz · · Score: 2, Informative

    This is not a Rush Limbaugh forum, and your retarded post has nothing to do with the topic. If you watch the BBC documentary Madagascar, Lemurs and Spies, you'll see that Gibson looks guilty as hell. A researcher working with an endangered group of Lemurs sees illegal logging in protected wilderness, and they get a hidden camera lawyer posing as an American wood buyer to go deep inside the logging operation, documenting the mass harvesting and lumber mills there producing pallets of fingerboard blanks with the Gibson front company name all over. The sawmill owner even brags on camera about what they are doing.

    By your logic, you would shut up and go away if the justice department put people at Gibson in jail. More likely, you would be here bitching about how another American company was shut down by the feds.

  33. Who the hell is relying on a single shared server? by Anonymous Coward · · Score: 0

    Who is cohosting on a single server now a days?

  34. Innocent bussiness by MrShaggy · · Score: 1

    Could the business that are not the warrent sue the Feds for the disuption of their bussinesses?

    Since in a sense that they were not part the names on the warrent.

    --
    I have mod points and I am not afraid to use them.
  35. Re:Did they at least manage to figure out what ser by Anonymous Coward · · Score: 0

    You had me at "USB ports". No way these guys would know how to pronounce that.

  36. How remailers work by betterunixthanunix · · Score: 1

    There are twenty or so remailers that are active at any time. Typically people chain the remailers, so that no single system knows both the sender and receiver of a message. One remailer going down is not an uncommon event; a different remailer will be used to send the messages, and nobody will bat an eye.

    Maybe the FBI wants that to happen, so they can take down the entire network, one node at a time, with legal justification.

    --
    Palm trees and 8
  37. Re:Who the hell is relying on a single shared serv by Ash-Fox · · Score: 1

    They tell you in the summary.

    --
    Change is certain; progress is not obligatory.
  38. If You're Going To Host Stuff Like This... by Anonymous Coward · · Score: 1

    ...then make sure you ALSO host the servers for important things.

    Like the servers for the local sewage treatment plant, for example. I can see the conversation now...

    FBI: "Alright, we're taking this server. It's hosting a criminal "x" and we're going to confiscate it as evidence."
    Network Admin: "I don't think you wanna do that?"
    FBI: "Why not?"
    NA: "It would cause a shit-storm."
    FBI: "Hah! You're funny!"
    NA: *grins* "Yeah, ain't I a stinker?"

  39. a good reason to limit anon networks to P2P by Burz · · Score: 1

    ...bc they don't normally connect to regular Internet services.

    Its probably a forgone conclusion that Mixmaster and even Tor will be attacked by authorities (yes, even by 'free and democratic' regimes) because someone will use it to make meatspace threats.

    With a P2P only anonymizer like I2P, connections/proxies to the regular Internet are rare so the anon network as a whole is less likely to come under attack due to threats made by some hothead or provocateur. And threats made within the anon space are far less worrisome because the threat recipient is also protected by a significant degree of anonymity.

  40. Don't host in the U.S. by efalk · · Score: 1

    When are people going to learn? If your site is at all controversial, don't register it or host it in the U.S.

    1. Re:Don't host in the U.S. by Skapare · · Score: 1

      Host it where? North Korea?

      --
      now we need to go OSS in diesel cars
    2. Re:Don't host in the U.S. by Pope · · Score: 1

      I remember using anon.penet.fi back in the 90s for posting to Usenet, since my university at the time didn't allow posting for non-CS majors. http://en.wikipedia.org/wiki/Penet_remailer

      Lesson: don't mess with Scientologists or retarded newspaper editors.

      --
      It doesn't mean much now, it's built for the future.
  41. Re:Who the hell is relying on a single shared serv by Skapare · · Score: 1

    One server can do quite a lot, especially if you ditch Windows and put BSD on there.

    --
    now we need to go OSS in diesel cars
  42. A comment from Riseup by Anonymous Coward · · Score: 1

    The server that was seized does not have any Riseup data on it. The machine was operated by the European Counter Network (?ECN?), an Italian technology collective. To repeat: no Riseup service or user data is on this machine. No Riseup keys or certificates are on the machine. Furthermore, the root filesystem of this machine is encrypted.

    Full press release: https://riseup.net/seizure-2012-april

  43. but but but... by Anonymous Coward · · Score: 0

    At least they are doing *something*.

    (In reference to better to be doing something [wrong] than nothing at all)

  44. Lesson to learn by aaaaaaargh! · · Score: 1

    People might point out that with a search warrant this could have happened anywhere, but this is not entirely true. It seems that in the US servers are more and more often seized as a sort of harassment in cases like this, where it is clear that there is no useful evidence can be obtained.

    Sorry if this offends a few alleged 'patriots', but the lesson to learn from this story is once more:

    Do not host your software or potentially controversial content on US servers or servers run by US companies!

    1. Re:Lesson to learn by RockDoctor · · Score: 1

      Sorry if this offends a few alleged 'patriots', but the lesson to learn from this story is once more:
      Do not host your software or potentially controversial content on US servers or servers run by US companies!

      Why on earth would that upset approximately 96% of patriots?
      Patriotic Albanian ? No problem.
      Patriotic Algerian ? No problem.
      Patriotic American ? Possible problem, though for the life of me, I can't see how pointing out that some part of the government is acting reprehensibly is necessarily going to be upsetting to a patriot. Unless that patriot also accepts the argument that their government's behaviour constitutes the country's only grounds for self-esteem. To quote a more realistic Zimbabwean colleague, "our government are murdering bastards, but I miss the beauty of the veldt".
      Patriotic Belgian? Pas de probleme.

      ...
      Patriotic Zimbabwean ? No problem.

      Now, whether American patriots find it embarrassing that their government is acting to suppress free speech and privacy while theoretically supporting those freedoms ... is a problem for them to worry about. To me, the concept of governments behaving hypocritically is reprehensible, but is so absolutely normal that it is the exceptions which surprise me.

      Personally, I prefer to not spend any money in America - let them starve ! - but even if that were insufficient reason, then distrust of American spying would be another completely sufficient reason to not consider using any American service or business.

      None of which invalidates your general message that content or services likely to be embarrassing or controversial to Government X (and/or their associates and paymasters) should not be hosted in Territory X or with companies susceptible to pressure from Government X.

      --
      Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"
  45. Wikileaks case by Anonymous Coward · · Score: 0

    There has not been a single criminal case that I can remember where data was overwritten and then recovered on modern drives

    I think this might be the case you are looking for: http://www.wired.com/threatlevel/2011/12/manning-assange-laptop/

    Johnson testified that he found two attempts to delete data on Manning’s laptop. Sometime in January 2010, the computer’s OS was re-installed, deleting information prior to that time. Then, on or around Jan. 31, someone attempted to erase the drive by doing what’s called a “zerofill” — a process of overwriting data with zeroes. Whoever initiated the process chose an option for overwriting the data 35 times — a high-security option that results in thorough deletion — but that operation was canceled. Later, the operation was initiated again, but the person chose the option to overwrite the information only once — a much less secure and less thorough option.

    All the data that Johnson was able to retrieve from un-allocated space came after that overwrite, he said.

    -- ab1

    1. Re:Wikileaks case by bmo · · Score: 1

      This is edited to show my thinking while I was writing this.

      All the data that Johnson was able to retrieve from un-allocated space came after that overwrite, he said.

      Not even enough information in this quote to tell if he got the data from the overwritten part or a part that failed to be overwritten or even if the zero wipe even finished.

      It is likely that whoever tried the wipe did it wrong both times. A "Gutmann wipe"? That just screams stupid.

      ******revisit the above quote and think about it more *******
      Wait...what?

      said he found 14 to 15 pages of chats in unallocated space on the hard drive

      unallocated This is used more than once in the article. It's not a mistake.

      Unallocated? That's a specific term in reference to partitioning. That means an "empty" space that's not available as a partition to read from or write to. It's unavailable to normal OS processes. He reformatted and reinstalled the OS. If he repartitioned too, it is likely he didn't set up the partitioning exactly the same way and wound up with a dead spot that was unallocated to any partitions. A zero wipe of free space is going to only write to the end of the partition and no further.

      It's easy to have unallocated space. I've got some on this laptop because of partition boundaries not landing in neat areas.

      You can run whatever regular wipe tool you want. If you tell it to wipe /dev/sda1, it's only going to wipe /dev/sda1. Whatever is on either side of that as unallocated space, doesn't get touched.

      --
      BMO

  46. Survival of the fittest or.... by 3seas · · Score: 1

    .... lowest common denominator rules the world?

  47. FBI == DoS by Anonymous Coward · · Score: 0

    And so the FBI becomes a proxy DoS attack.
    Anybody at the Bureau lookup 'irony' in a dictionary lately?

  48. so obvious... by Anonymous Coward · · Score: 0

    ..given how the us gov is screwing its people nowadays.
    Send a fake bomb mail to give a legal context to seizing the servers.
    d'oh!

    1. Re:so obvious... by Anonymous Coward · · Score: 0

      I don't think they would bother with that. It's their job to go after bomb threats, they have no real way of knowing which is fake and which isn't.

      I also note that *proper* procedure was followed, in that they requested international assistance. This means they must have provided enough evidence (or enough blackmail - depends on what you're willing to believe) to ensure *local* authorities acted.

      Having said that, it's getting silly. It appears the guiding assumption is that all terrorists are dumb. Granted, there are good examples that seem to confirm this, but I'm worried that the signals of the real dangerous ones get buried under all this rubbish..

  49. Re: Aww, how precious! by Anonymous Coward · · Score: 0

    You leftys are so cute. #Occupy whatever you think you have a right to do and ruin a business or park, but the second one of your servers are impounded you whine like stuck pigs.

  50. This reminds me of... by Anonymous Coward · · Score: 0

    America Fuck Yeah!

  51. It happened ON THE INTERNET by Anonymous Coward · · Score: 0

    The University of Pittsburgh is definitely dealing with an ongoing disruptive problem. However, the message delivery system is not the issue. What if the threats were delivered via snail mail? Surely all the post offices the mail passed through, around the country or world, would not be seized.

  52. Re:Did they at least manage to figure out what ser by Anonymous Coward · · Score: 0

    Why do you have it in for capacitors?