Raided For Running a Tor Exit Node
An anonymous reader writes "A Tor Exit node owner is being prosecuted in Austria. As part of the prosecution, all of his electronics have been held by the authorities, including over 20 computers, his cell phone and hard disks. 'During interview with police later on Wednesday, Weber said there was a "more friendly environment" once investigators understood the Polish server that transmitted the illegal images was used by Tor participants rather than by Weber himself. But he said he still faces the possibility of serious criminal penalties and the possibility of a precedent that Tor operators can be held liable if he's convicted.' This brings up the question: What backup plan, if any, should the average nerd have for something like this?"
Cloud storage, and make the exit node a leech off your neighbors wifi.
Lots of money.
Look at Kim Dotcom.
If you're running Tor, or FreeNet, or anything else with the possibility of pissing off the man - be prepared for the concequences. The authorities repsonse here is pretty standard across the board.
Any Freenet nodes get raided? That's a good test for how secure the system is.
..don't panic
If a TOR exit node can be prosecuted for traffic passing through it, should the ISP and backbone router owners not also be held responsible for traffic passing through their nodes? If the ISP and network operators are not held responsible then neither should the TOR node owner.
Run a dark net.
Give me Classic Slashdot or give me death!
"What backup plan, if any, should the average nerd have for something like this?"
Select a new exit node, duh.
I think not running TOR is about all you can do.
Of course if this is something they can prosecute you for, can they also prosecute your ISP as well?
You mean to tell me you guys don't have your cases rigged with thermite?
If you ship contraband via FedEx, is FedEx a criminal?
It's hard for the average nerd, you either have to be so small and invisible that you can take off at a moment's notice, or maintain shell corporations that own all the stuff that might get taken. If you own a house, or have a family that you care about, fugetaboutit.
All ideas^H^H^H^H^Hprocesses in this post are Patent Pending. (as well as the process of patenting all postings)
What average nerd runs a TOR exit node?
For your security, this post has been encrypted with ROT-13, twice.
I've wondered, from day one, why anyone would be crazy enough to run a TOR exit node. Why would you willing serve as the front man for someone else's unknown but likely illegal activity? It's just crazy.
Running an exit node is just begging to get arrested for child porn. I'm positively amazed that it doesn't happen a LOT more often.
They likely will not turn it off when they remove it. There are products just for that purpose.
Destruction of the USB stick would get you Obstruction of Justice charges.
They have a history of doing stuff like this in Austria (Germany also). I am now aware of this happening in the US, we have fairly clear laws on the subject. I have ran a 5 mb/sec exit node unmolested, without even one single abuse complaint for 10 years. Anyone who sees the obvious tor-exit hostname in their logs knows whats up, if they are still confused the exit node notice should clear things up. The EU has been trying to get some reasonable laws passed but their broken economy steels the show.
The problem is not the exit node, no information of any value contains there, and nothing that can incriminate you will be on the exit node.
The problem is the complete raid of everything of value you own and depend on that had no part in the exit node, no matter what is stored on the machines. Likely keeping them for months, even years depending on how far they want to go with the case.
c++;
What backup plan, if any, should the average nerd have for something like this?
1. Don't run an exit node
2. if 1 fails, fly to Belize and live blog my evasion of the local police
Traditional backup methods are good against media failure, or even natural disaster, but ineffective against seizure. The standard police procedure is 'if in doubt, take everything,' because it isn't practical to train frontline officers to work out what is and isn't potentially evidence. That's why they take cell phones and games consoles. That and, as the more cynical point out, the more miserable they can make the defendent the easier it is to force a plea bargin. So they'll take all your backups too.
You can forget about getting that back, too. Even if all charges are dropped. Law enforcement is well-known all around the world for their reluctance to return siezed evidence, espicially evidence that may one day go into police auction. Even if they are willing to return it, many areas have overwhelmed forensics staff and computers can sit in the locker for months before there is an expert available to poke around and declare them free of anything incriminating.
So if you do have reason to worry about being raided - eg, you run an open wireless hotspot or exit node - then a sensible precaution is to keep backups of critical data somewhere out of reach, like a cloud store hosted overseas, or drives left with trusted friends for safekeeping. Making sure, of course, that no-one else knows - you don't want them to get raided too!
Also beware of another police policy. It varies by country, and even by state and district, but many departments are loathe to let any accused off without charge or found not guilty - it makes them look incompetent, wrongly arresting someone. So they will likely resort to the 'throw the book' approach, going through the evidence looking for any other, unrelated crimes they can find. Sure, you may not have actually launched that attack or trafficked those illegal files they raided you for - but if, in the process of investigating, they discover you've been involved in piracy or find chat logs of you talking about your drunken vandalism or theft of office supplies, or something which would be otherwise borderline illegal, they will happily add more charges - insurance in case you were innocent of the original accusations, and to pile on more pressure for a plea bargin. Prosecutors love guilty pleas - much more reliable than actually having to prove something beyond reasonable doubt.
You can encrypt, of course. But that just makes you look even more suspicious, plus in most countries now it's either an explicit crime to withhold keys from police or considered a form of withholding evidence, either of which gets you jailed anyway. Even if you legally wriggle free from that, good luck getting a jury to see it as anything other than a sign you are trying to hide evidence of whatever terrible act you are accused of.
Simply tell the prosecution / judge - "I run a TOR exit node to help preserve freedoms on the internet, especially those of people oppressed in countries like Syria and other places. If you choose to prosecute me for running a TOR exit node which, by its stated purpose and nature, is encrypted and anonymous AND which I have no control of the data flowing through it then you must also prosecute EVERY internet service provider over which the same data flowed. I do not know now, nor have I ever known, exactly what data flows over the exit node. Just like ISPs do not know what data is flowing over their networks."
DO NOTHING ELSE. Even if it makes complete sense to you (keeping an encrypted backup of all your data and computer images off-site), the prosecution will do what they can to skew that to "Why did you keep encrypted backups off-site? What are you hiding?" Fuck 'em. Don't give them any ammunition in their fear-mongering quest to rule your life. Come away clean and then lawyer up and sue the police departments, all government levels* involved, and even the prosecutor. Your aim with the lawsuits is not to get paid, it is to get all your electronics back in a timely manner if they refuse to give them back once you are cleared. Of course, if they're being dicks about it then the object is to get your equipment back and get VERY large settlements.
*Not sure how the government levels are in Austria, but here in the United States we have city government, county government, then state, then federal. Depending on who is doing the prosecution, I would start my lawsuits with that level of government and work my way down. Same with the police forces involved.
Dream as if you'll live forever.
Live as if you'll die tomorrow.
~Anonymous~
bury yourself in your yard with a cardboard box above your head for air when the police come to question you because you know you're innocent!
http://betabeat.com/2012/11/murder-suspect-and-bath-salts-enthusiast-john-mcafee-claims-hes-innocent/
My God can beat up your God. Just kidding...don't take offense. I know there's no God.
Give it a while and you're back at his plan.
Quite seriously, unless you've been under a rock lately, you should have noticed that sooner or later laws have gotten to the point where the only legal thing you can do online anymore is buying crap.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
You might want to think about that plausible deniability. First off, if the **AA sues you, the standard of proof in a lawsuit is "preponderance of the evidence", not "proof beyond a reasonable doubt". Second, much law is written on the basis of what a hypothetical 'reasonable person' would do or understand. It's quite easy to argue that a reasonable person with your level of technical skill would understand that their open wifi and tor exit node would likely be used by people engaging in criminal activity. Going from there to persuading a jury that you were knowingly aiding and abetting criminal activity likely would not be hard - especially if they know that the secret service has spoken to you in the past and advised you to stop it.
No, in both cases the pawn shop owner (or Tor node operator in this case) wasn't explicitly aware that their business (or Tor node) was being used to steal goods (or illegal online activity). The pawn shop owner (or Tor node operator) is likely aware that running a pawn shop (or Tor node) carries the risk that illegal goods (or illegal online activity) will be filtered through, though predictive knowledge itself is not a crime. Rather than seeking the assistance of the business owner (or Tor node operator) in tracking down the perpetrator, the authorities chose to instead implicate the business owner (or Tor node operator) directly for the illegal activities of the perpetrator who utilized the business owner's (or Tor node operator's) property to carry out those illegal activities.
See how that analogy works there? If they arrested all pawn shop owners who had facilitated the stealing of stolen goods without explicit knowledge then likely all pawn shop owners would be arrested.
Set it up so that if a certain encrypted file isn't updated manually at certain intervals, the entire system self-immolates.
Realistically, though, I've been thinking about building inconspicuous, low-power Tor exit servers that I can dead-drop in places with open wifi. That way, exits can be operated with a minimal threat of legal ramifications for anyone (plausible deniability on the part of the wifi provider).
To that end - anybody know where I can bulk order small form factor, inexpensive low-power computers that are battery pack/solar power friendly?
An enigma, wrapped in a riddle, shrouded in bacon and cheese
20 computers isn't that much. WIth my family of 5, we have 3 home theater PCs, a server, 3 laptops, and 3 tablets that just have easily could have been additional laptops. That's 10 "computers" right there and I don't consider myself particularly nerdy anymore.
From one of the links the guys says that those 20 computers were mainly "barebone PCs, HP storage microservers, and thin clients". And it doesn't state if those were even functional computers. Over the years I've collected and scavenged from many old PCs that were going to be thrown out or were no longer wanted.