5 ms·
> a Tor exploit of some kind to force the browser to return the user’s actual IP address, operating system, MAC address, and other data. As part of the operatio
by uniclaude 10y ago
> a Tor exploit of some kind to force the browser to return the user’s actual IP address, operating system, MAC address, and other data. As part of the operation that took down Playpen, the FBI was then able to identify and arrest the nearly 200 child porn suspects.
So, is getting someone arrested as easy as spoofing their network information and visiting those sites? I can already imagine trolls using this to have people swatted.
- openasocket 10y agoIt would be really difficult to spoof the IP address and create valid TCP connections. Plus, your method would only work if you knew in advance that certain sites were currently being used in a sting operation. If you could figure that out, that kind of defeats the purpose of a sting operation.
- uniclaude 10y ago> Security researcher Sarah Jamie Lewis told Ars that “it’s a pretty reasonable assumption” that at one point the FBI was running roughly half of the known child porn sites hosted on Tor-hidden servers. We're talking about a very large sting operation, just browse a few of those, I guess?
- solotronics 10y agoit would be trivial to hack their wifi or insert a rogue device into their home network
- openasocket 10y agoAt that point, you might as well hack into their laptop, put a bunch of CP on there, and then call the cops. Forensic analysis of the hard drive would exonerate you though.
- uniclaude 10y agoAt this time you'd already be under arrest tough, and probably in a tiny cell for a while. That was my point, this is what trolls look for. Then, unlike with other trolling methods, I'm pretty sure you need quite the clever lawyer to get out of this.
- wyager 10y ago> Forensic analysis of the hard drive would exonerate you though. No. Anything an analyst could feasibly look at can be spoofed with root access. The only thing that could potentially approximate the actual age of a hard drive write is thermal annealing of the storage medium, but this isn't really true anymore with SSDs (and was never practical even for HDDs).
- openasocket 10y agoYeah, but it's not that simple. You'd have to install the Tor Browser Bundle, make it look like it was installed long before. You'd have to change the MAC times on the CP files to indicate a consistent pattern, and make sure the victim doesn't have an alibi for any of the times you're putting down. But you can't backdate the download time to before the image was produced, so you have to do your research on that. And of course you'd have to get your hands on a bunch of CP without getting caught yourself. I'm not saying it's impossible, but it sounds pretty difficult to me. Maybe I'm wrong though.