Harvard Bomb Hoax Perpetrator Caught Despite Tor Use
Meshach writes "The FBI has caught the student who called in a bomb threat at Harvard University on December 16. The student used a temporary anonymous email account routed through Tor, but the FBI was able to trace it (PDF) because it originated from the Harvard wireless network. He could face as long as five years in prison, three years of supervised release and a $250,000 fine if convicted. He made the threat to get out of an exam."
Whenever you peel back the layers of an onion, someone is bound to cry.
Science advances one funeral at a time- Max Planck
We can either live in a future where little jackwagons can effect a denial-of-service attack on society, or
we can spank the crap out of the idiots so that this kind of noise is minimized. Same goes for rape/hate crime hoaxes.
Get thee glass eyes, and, like a scurvy politician, seem to see things thou dost not.--King Lear
And therefore they'll put him in rehab rather than prison.
Unless he's not affluent enough for his affluenza to be strong enough to cover this crime, after all, he called in a bomb threat, rather than killed four people in a drunk-driving incident.
Not neccessarily. His access to Tor via the campus wifi matched the timing of the emails enough to get him in a room, and then he confessed. Without the confession there'd be a lot less certainty of conviction, as the presumption of innocence would probably compel a jury, in the absence of any other compelling evidence, to find him not guilty.
Moral of the story: Don't talk to cops.
(also, don't make false bomb threats. They're stupid)
...but because he was the only one on the whole campus wifi that used Tor that day.
Lesson to learn: Keep your endpoint traffic able to be lost in the noise, or ya' stick out like a sunflower in a coal mine.
I.E. SSH somewhere *THEN* Tor.
In our next lesson we will learn delayed email deliver functionality. Stay tuned!
Love many, trust a few, do harm to none.
also, don't make false bomb threats. They're stupid
Don't make real ones either. They're even stupider.
... to use TOR, but then gave a full confession during an "interview", throwing his right to remain silent (and to have a lawyer present during questioning) out the window?
He made the threat to get out of an exam.
he won't have to worry about that any more
The wonderful thing about shows like CSI is that it convinces criminals to implement absurd technical defences when their crimes will almost certainly be dealt with by old-fashioned police work.
No kidding!!! What do you say at this point?
The best Harvard students learn that you have no need to conceal your crimes if you can commit them from a position of enough influence to simply make them legal. That's where kiddo slipped up.
Was the guy ever catched ? Nope.
Did this happen during an English class?
Depends on who the "you" is. The list of entry nodes is public knowledge. Telecoms/Government agencies probably keep historic lists of entry nodes. So it should be trivial to show a connection to the Tor network. The PDF implied (to me) that the FBI just crossreferenced Harvard's log with their list of entry nodes.
To technically answer your question: Tor packets don't have a unique signature, but they all are of a known size.
This is one of the best-known ways to deanonymize people using Tor: timestamping entering traffic and exiting traffic. Tor itself explains they have no theoretical way to fix that issue and still maintain a system that is low-latency (there may have been a third feature as well, where they got to pick-2-of-3).
Your ad here. Ask me how!
Precisely this. Harvard keeps flow type logs, they found someone using tor. Pigs barfed on him, he cracked and confessed. The kid's a fucking retard, mostly for cranking people.
Please, don't use Tor to harass and be an asshole.
Real freedom fighters need Tor, not you and your lulz.
See who else really needs Tor: https://www.torproject.org/
And quit being assholes.
Remember the days when this story wouldn't even have made the local paper? Seriously, 25 years ago your average school saw one of these every few years. It headlined the school paper, the local cops investigated, but the FBI? National news? Heck no.
Who needs terrorists when we now pay large corporations and government agencies to spread panic? Quit terrorizing the nation to protect your job security and let me know when something actually blows up.
If he'd just called it in from a pay phone, they'd never have found him.
In Luxembourg, a couple of students at the European School did exactly that a few years ago. They were caught pretty quickly, because, you know, payphones have cameras... ("officially" to catch vandalism, but these cams sure did come in handy in this case as well). So, cops just walked with the pix from classroom to classroom until they found the perps.
Just study, it's easier.
Except he didn't actually send the bomb threat! He only confessed to that lesser crime because what he was REALLY doing was seeding a pirated release of Gravity, and he knew if the police continued their investigation they might find out and he'd end up in jail for 10 years and have to pay $3 million in fines.