{"id":199754,"date":"2015-11-12T22:18:05","date_gmt":"2015-11-12T22:18:05","guid":{"rendered":"http:\/\/rinf.com\/alt-news\/?p=199754"},"modified":"2015-11-12T22:18:05","modified_gmt":"2015-11-12T22:18:05","slug":"tor-project-accuses-fbi-paying-university-deanonymize-users-without-warrant","status":"publish","type":"post","link":"http:\/\/rinf.com\/alt-news\/breaking-news\/tor-project-accuses-fbi-paying-university-deanonymize-users-without-warrant\/","title":{"rendered":"Tor Project accuses FBI of paying university to \u2018deanonymize\u2019 users without warrant"},"content":{"rendered":"<p>Tor Project, the world\u2019s largest anonymous online network, claims the FBI illegally paid security researchers at a leading university $1 million to unveil the identities of the site\u2019s users, based on court documents in a Silk Road 2.0 trial.<\/p>\n<div>\n<p>The accusations against the FBI revolve around the agency\u2019s attempt to unmask the anonymous identities of Tor Project users during a criminal probe known as Operation Onymous. Without a search warrant, federal law enforcement directed researchers at Carnegie Mellon University (CMU) in Pittsburgh, Pennsylvania to reveal the names of users, the team behind the Tor Project claimed on Wednesday.<\/p>\n<p>The Tor Project also claimed that the government paid CMU for this service, but has listed no evidence to that effect.<\/p>\n<p><em>\u201cApparently these researchers were paid by the FBI to attack hidden services users in a broad sweep, and then sift through their data to find people whom they could accuse of crimes,\u201d<\/em> Tor Project Director Roger Dingledine said in a <a href=\"https:\/\/blog.torproject.org\/blog\/did-fbi-pay-university-attack-tor-users\">blog post<\/a>.<\/p>\n<p>The source of the $1 million figure came from <em>&#8220;friends in the security community,&#8221;<\/em> Dingledine told Wired.<\/p>\n<div class=\"arcticle__read-more read-more\">\n<p>Operation Onymous was an investigation into drug crimes related to the Silk Road 2.0 website, which relied on the Tor anonymity network to hide the IP addresses of all parties involved, began in January 2014. It <a href=\"https:\/\/www.rt.com\/usa\/224579-silk-road-washington-farrell\/\">resulted in the arrest<\/a> of 26-year-old Brian Farrell, who was charged with one count of conspiracy to distribute hard drugs this January.<\/p>\n<\/div>\n<p>In July 2014, the Tor Project <a href=\"https:\/\/blog.torproject.org\/blog\/tor-security-advisory-relay-early-traffic-confirmation-attack\">announced in a blog post<\/a> it had <em>\u201cfound a group of relays that we assume were trying to deanonymize users. They appear to have been targeting people who operate or access Tor hidden services.\u201d<\/em> The post noted that the relays, which are nodes of the Tor network that route traffic, joined Tor on January 30 and were removed by the project on July 4.<\/p>\n<p>It was in the search warrant for Farrell\u2019s home that first led the Tor Project to suspect the link between his arrest and the attack on the network. In that document, Special Agent Michael Larson wrote that from January 2014 to July 2014, an FBI source of information provided <em>\u201creliable IP addresses for TOR and hidden services such as SR2.\u201d<\/em><\/p>\n<p><em>\u201cThe SOI also identified approximately 78 IP addresses that accessed a vendor .onion address,\u201d<\/em> the warrant continued, referring to Tor, which is an acronym for <em>\u201cThe Onion Router.\u201d<\/em> One of those belonged to Farrell.<\/p>\n<p>The Tor Project did not appear to have any confirmation of its suspicions \u00e2\u20ac\u2019 or any idea what the FBI\u2019s source of information was \u00e2\u20ac\u2019 until a motion was filed in Farrell\u2019s case last week, Motherboard reported.<\/p>\n<p><em>\u201cOn October 12, 2015, the government provided defense counsel a letter indicating that Mr. Farrell&#8217;s involvement with Silk Road 2.0 was identified based on information obtained by a &#8216;university-based research institute&#8217; that operated its own computers on the anonymous network used by Silk Road 2.0,\u201d<\/em> the motion read.<\/p>\n<p>When Farrell\u2019s defense team asked for additional discovery evidence and information to determine the relationship between this <em>&#8220;university-based research institute&#8221;<\/em> and the government \u00e2\u20ac\u2019 as well as to find out how the FBI managed to identify Farrell <em>\u00a0\u201con what was supposed to operate as an anonymous website\u201d<\/em> \u00e2\u20ac\u2019 they were rebuffed.<\/p>\n<p><em>\u201cTo date, the government has declined to produce any additional discovery,\u201d<\/em> the defense attorneys wrote in the motion.<\/p>\n<p>Despite the lack of information from the FBI identifying the university, the Tor Project fingered CMU, based on circumstantial evidence again involving timelines that matched up a little too well.<\/p>\n<p>In July 2014, shortly after the Tor Project uncovered and removed the deanonymizing relays, two CMU researchers were set to give a much anticipated talk at the Black Hat hacking conference, but the remarks were abruptly canceled, Motherboard reported.<\/p>\n<div class=\"arcticle__read-more read-more\">\n<p>Alexander Volynkin and Michael McCord were supposed to reveal how a $3,000 piece of kit could unmask the IP addresses of Tor hidden services as well as their users in much the same way the Tor Project said their site was attacked. The two CMU researchers claimed they had tested such a hack in the wild.<\/p>\n<\/div>\n<p>The Tor Project isn\u2019t alone in their suspicions that CMU was behind the attack. Nicholas Weaver, a senior researcher at the International Computer Science Institute at University of California, told Motherboard that the Pittsburgh school is \u201calmost certainly\u201d the university that partnered with the FBI.<\/p>\n<p><em>&#8220;The capabilities used to provide the information to the FBI match the capabilities that the attack [uncovered by Tor officials] provided,&#8221;<\/em> Weaver told Ars Technica.<\/p>\n<p>CMU cooperated with the FBI without a search warrant or any institutional oversight by the university\u2019s Institutional Review Board, the Tor Project said.<\/p>\n<p><em>\u201cWe think it&#8217;s unlikely they could have gotten a valid warrant for CMU&#8217;s attack as conducted, since it was not narrowly tailored to target criminals or criminal activity, but instead appears to have indiscriminately targeted many users at once,\u201d<\/em> Dingledine wrote in the blog post.<\/p>\n<p>He excoriated the school for its actions, and added that there are legal ways in which the FBI could have used Tor for its investigation without CMU\u2019s attack on the network.<\/p>\n<p><em>&#8220;Civil liberties are under attack if law enforcement believes it can circumvent the rules of evidence by outsourcing police work to universities. If academia uses \u2018research\u2019 as a stalking horse for privacy invasion, the entire enterprise of security research will fall into disrepute. Legitimate privacy researchers study many online systems, including social networks \u00e2\u20ac\u2019 If this kind of FBI attack by university proxy is accepted, no one will have meaningful 4th Amendment protections online and everyone is at risk,&#8221;<\/em> Dingledine wrote.<\/p>\n<p>Nick Mathewson, co-founder of the Tor Project, called CMU\u2019s actions unethical.<\/p>\n<p><em>&#8220;If you&#8217;re doing an experiment without the knowledge or consent of the people you&#8217;re experimenting on, you might be doing something questionable\u2013and if you&#8217;re doing it without their informed consent because you know they wouldn&#8217;t give it to you, then you&#8217;re almost certainly doing something wrong. Whatever you&#8217;re doing, it isn&#8217;t science,\u201d<\/em> he told Motherboard in a statement.<\/p>\n<div class=\"rtcode\">\n<blockquote class=\"twitter-tweet\" lang=\"en\">\n<p dir=\"ltr\" lang=\"en\">Journalists following up on CMU\/FBI story: Call the CMU General Counsel. Ask if Tor team got IRB approval for research. If not, why not.<\/p>\n<p>\u2013 Christopher Soghoian (@csoghoian) <a href=\"https:\/\/twitter.com\/csoghoian\/status\/664494120170295296\">November 11, 2015<\/a><\/p><\/blockquote>\n<\/div>\n<p>The FBI has not commented on the Tor Project\u2019s accusations. For its part, CMU has not commented beyond denying that the school was paid.<\/p>\n<p><em>\u201cI\u2019d like to see the substantiation for their claim,\u201d <\/em>Ed Desautels, a staffer in the public relations department of the university\u2019s Software Engineering Institute, told Wired.<em> \u201cI\u2019m not aware of any payment,\u201d<\/em> he added, declining to comment further.<\/p>\n<\/div>\n<p>Via <a href=\"https:\/\/www.rt.com\/usa\/321756-tor-project-fbi-cmu-attack\/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=RSS\">RT<\/a>.\u00a0This piece was reprinted by <a href=\"http:\/\/rinf.com\">RINF Alternative News<\/a> with permission or license.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tor Project, the world\u2019s largest anonymous online network, claims the FBI illegally paid security researchers at a leading university $1 million to unveil the identities of the site\u2019s users, based on court documents in a Silk Road 2.0 trial. The accusations against the FBI revolve around the agency\u2019s attempt to unmask the anonymous identities of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":199755,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[487],"tags":[],"class_list":{"0":"post-199754","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-breaking-news"},"_links":{"self":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/199754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/comments?post=199754"}],"version-history":[{"count":0,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/posts\/199754\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media\/199755"}],"wp:attachment":[{"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/media?parent=199754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/categories?post=199754"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/rinf.com\/alt-news\/wp-json\/wp\/v2\/tags?post=199754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}