Harvard Bomb Hoax Perpetrator Caught Despite Tor Use
Meshach writes "The FBI has caught the student who called in a bomb threat at Harvard University on December 16. The student used a temporary anonymous email account routed through Tor, but the FBI was able to trace it (PDF) because it originated from the Harvard wireless network. He could face as long as five years in prison, three years of supervised release and a $250,000 fine if convicted. He made the threat to get out of an exam."
...but because he was the only one on the whole campus wifi that used Tor that day.
Lesson to learn: Keep your endpoint traffic able to be lost in the noise, or ya' stick out like a sunflower in a coal mine.
I.E. SSH somewhere *THEN* Tor.
If he'd just called it in from a pay phone, they'd never have found him.
In Luxembourg, a couple of students at the European School did exactly that a few years ago. They were caught pretty quickly, because, you know, payphones have cameras... ("officially" to catch vandalism, but these cams sure did come in handy in this case as well). So, cops just walked with the pix from classroom to classroom until they found the perps.