13 ms·
The FBI stole an Instapaper server in an unrelated raid
- mrcharles 15y agoAll the more reason for data havens to exist. Run your server from a country where the police can't just take it with impunity.
- pavel_lishin 15y agoOf course, then you have to keep careful tabs on that country's politics. The police can't confiscate your data in June, until a new bill is passed in July, and suddenly it's up for grabs. Furthermore, I'm not sure I'd want to host my data in a country where the police cannot pursue digital criminals.
- 5l 15y agoLike it or not it's still the wild west, and I suspect most people here trust their own ability to protect themselves more than they trust the sheriff who only investigates crimes against the mayor and can't even ride a horse or shoot straight.
- 16BitTons 15y agoDo you have any suggestions on safe countries? As far as I can tell, the USA is still has the best mixture of freedom and protection available.
- mrlase 15y agoThe Netherlands, Sweden, etc. provide pretty good coverage and is where a lot of the seedboxes for torrenting are held. If you have something you want the government to have a almost nonexistent (depending on what it is) chance of getting to, go with Russia, China, etc. and other countries that probably don't have the best relations with the United States.
- InnocentB 15y agoRussia and China are perhaps good examples of places to host something the US government has little chance of getting to, but the governments of those countries are far worse about this sort of thing than that of the States, so I wouldn't want my data to be stored there.
- oikjhgbpokj 15y agoDepends on your data, you don't want your company IP or your bank details held there. But they are hardly likely to pass onto the FBI the fact that you read the wiki article on Marx and so might be a security risk.
- cma 15y agoThe CIA doesn't even need warrants.
- dkubb 15y agoI think it's probably safer to proceed with the assumption that any sufficiently motivated government can seize your physical machine anytime they wish. I should note that I'm not disagreeing with you, I just think there are more important considerations to make before physical location of the data.
- jarin 15y agoLooks like the FBI is operating from the Department of Homeland Security playbook now.
- idonthack 15y agowhat do you mean "now"? DHS got their handbook from the FBI
- ktsmith 15y agoThe FBI has been doing these kinds of raids for years and years, there just hasn't been one in the news lately.
- Symmetry 15y agoIts pretty similar to what the US Secret Service was doing in 1990. http://www.sjgames.com/SS/ http://www.sjgames.com/SS/
- nbpoole 15y agoSo, the FBI has a copy of Instapaper's complete database and a copy of their website code. The database includes: - Salted SHA-1 hashed passwords for Instapaper - Encrypted passwords for linked Pinboard accounts (with the encryption key stored in the website code) - OAuth tokens for linked Facebook/Twitter/Tumblr accounts (and presumably also the secret keys used by Instapaper to use those tokens). That's (potentially) a lot of personal information.
- midnightmonster 15y agoPerhaps even more important, they have a list of hundreds (thousands?) of pages I thought were interesting enough to read later. Seems like a fine base from which to build or enhance profiles of thousands of citizens.
- foobarbazoo 15y agoEven better, they can use that information to build or enhance profiles WITHOUT getting any kind of judicial approval or oversight. Yay, Patriot Act (not).
- imrehg 15y agoAs a real practical question out of curiosity: how would you design their system differently so unauthorized people having only your hard drives couldn't get any data at all?
- forgotAgain 15y agoIf the hardware is in hand then I don't see any practical way to protect the information. The only way that works is to not store the information in cloud servers.
- jonah 15y agoThe only way that works is to not store the information in cloud servers. Where would your servers be safe? Colo? No. In your basement? No? In another country? Possibly, depends. At HavenCo? Maybe.
- yuvadam 15y agoI'm trying to think of an analogy which can explain why this might be reasonable from the FBIs perspective. Suppose you were using a shared storage space (shared servers, or server farm) with several other dudes. One of them is a drug dealer. One day the police/FBI decide to raid the storage space since the drug dealer has been using it to store illegal drugs. Is it not reasonable to consider this collateral damage (which, granted, is totally unnecessary) during law enforcement operations? I'm not saying this is OK in any case, but might this not be a reasonable move by the law enforcement agencies?
- mrcharles 15y agoNo. Even if it was shared space, it should be possible to, through software and IT, extract the necessary data and bar it from further operation.
- sharth 15y agoUnless you don't trust the hosting provider. Then their best bet is to take down the proper machines.
- falcolas 15y agoI think it's always important to remember that the first order of business in a raid is to preserve evidence against deletion or modification. This means that their first task is to remove the hardware from anybody's hands but theirs. At which point they can peruse the data as they are able. Why did they take an entire rack, instead of a few servers? I can think of a couple of potential reasons. - VM's, which could potentially live on any physical server in a VM pool - Insufficient information on which physical servers belong to their suspects - They just don't trust the colo operators to not be involved, and thus limit the suspect data to the servers they provide. While I wholly agree that it's unfortunate that Instapaper and Pinboard were affected, it's not an unexpected consequence of having your servers alongside (or on the same physical machines) of people you don't know.
- WettowelReactor 15y ago
- mrcharles 15y agoThe more I think about it, the more I think this should be treated the same as any of the other thefts of data information to have happened in the past few months. Sony, Toyota, Sega, etc. A potentially hostile group now has a ton of personal info. People should know.
- pavel_lishin 15y agoA potentially hostile group that also has much greater resources at its disposal than LulzSec, and much more ambiguous motivations.
- deleted 15y ago[deleted]
- tptacek 15y agoI didn't downvote you, but your "If you're the FBI and you want X, you'd simply Y" has nothing to do with reality. In reality, when any law enforcement organization needs digital evidence of any kind, they take everything. There are chain-of-custody rules that require it.
- deleted 15y ago[deleted]
- pyre 15y agoBut is all of the collateral damage that results in the public's best interests?
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- Astrohacker 15y agoI think it may be prudent to begin encrypting all data on disk that can reasonably be encrypted while being able to set up the server remotely so that no one can just snatch your server and get all your data. This could work by encrypting your database in a truecrypt volume that must be mounted by entering the password. Thus, the data is only ever saved on disk in encrypted form, and the key to access the data is not saved on the disk. Of course, it is still in principle possible for anyone to access that information if they have physical access to the computer while it's running, but at least this makes that much harder.
- pavel_lishin 15y agoHow fast is Truecrypt? How much would this slow down database and file access?
- Astrohacker 15y agoI don't know. It would obviously slow down database access. It would be nice if someone tested this.
- ineedtosleep 15y agoTruecrypt is significantly slower, especially on the higher strength encryption methods. The program itself has a benchmark in it, so download it and check it out for yourself if you're that curious. (Note that it is relative to your hard drive's speed)
- Wilya 15y agoI suspect this would only be reasonably applicable if you manage to reduce disk accesses to the very minimum. I'm not very familiar with these setups, but I assume they slow down disk accesses quite a lot.
- cheez 15y agoI don't think this is reasonable. If you lose power, the the volume is toast as I understand it.
- bestes 15y agoI think the OP was unreasonably harsh on DigitalOne (never heard of them let alone have any interests). It is very possible that they are consumed with FBI questioning, gag orders or who knows what else. I would give them a pass for a few days until more detail comes out.
- lamnk 15y agoI think so too. He says: I have no idea whether I’ll ever see the server again In this case the host probably doesn't know better than him. According to the NYTimes they are a swiss company, they only rent space and connectivity from the data center. I see people jump up and down accusing their host being a bad host when their websites go down for 10 minutes. The thing is, shit like this happens all the time. Some years ago even Rackspace was taken offline because a truck hit their data center. Bizarre, right? Yes, but it did happen.
- idlewords 15y agoThe problem with DigitalOne was a complete lack of communication around this event. It was a long time (and a lot of badgering) before any of us learned anything about what had happened. I can sympathize with being busy during a crisis, but total silence for 24+ hours, with no working website, email, status page, or twitter account, is not acceptable.
- lamnk 15y agoYeah, that is what hosting companies often lack: communication with their customer during crisis. I totally agree that DigitalOne should inform their customers about the incident and they handled the case poorly. But, like I said, put all the blame on them is too harsh.
- jsdalton 15y agoSurely there is a legal precedent which provides at least some framework for what can or cannot be seized during a warrant search? This can't be the first time government agents have mistakenly seized property in an otherwise lawful search. Also, while I completely understand Instapaper's unwillingness to pursue this through the courts, that is the way our legal system is structured. If you believe you have been harmed in some way by a government action, the courts are the avenue through which you must obtain recourse. (Not a lawyer, so if I'm wrong about any of the above please correct me.)
- cheez 15y agoIt's called the constitution of the United States. If the enforcers don't follow it, your only recourse is the Supreme Court which will probably throw out your claim for national security reasons.
- danielsoneg 15y agoNot necessarily. I (also) am not a lawyer, but the question isn't whether the FBI has the authority, constitutional or otherwise, to seize the servers owned by the target of the warrant, the question is whether they overstepped their bounds in seizing three whole racks of servers. If it's shown they were careless or did not take sufficient caution in their raid to avoid seizing unrelated servers, they could be held liable for damages. In this case in particular, the number of unrelated companies that have been affected by this (and the number of servers present in 3 racks) makes a case for negligence. Again, though, the question isn't whether they had the right to seize the servers they had warrants for - they did, and you won't get that questioned by any court - but whether they did so properly, and it's not unheard of for a law enforcement agency to get slapped for overstepping their bounds. It's not Common, but it's not unheard of, and it's not a 4th amendment issue either.
- gte910h 15y agoIt is a 4th amendment issue: That's why they can't just take the server of people not under investigation...
- leon_ 15y agoHmm. I've built something similar to instapaper for myself. (Using a native OS X app). People were making jokes at me how I was re-inventing the wheel. Now I'm somewhat happy having done the extra work. At least the FBI doesn't have my "read later" bookmarks. (Which often consist of the words 'hack', 'malware' and 'reverse engineering'.) I guess I will reinvent the wheel instead of using cloud services more often in the future.
- pavel_lishin 15y agoAn in between solution would be better - write an open source version of Instapaper that people could install on their own servers, instead of everyone rolling their own.
- Xk 15y agoInstapaper stores only salted SHA-1 hashes of passwords, so those are relatively safe. -- Obligatory statement on NEVER USING SHA-1 HASHES to make passwords "safe". Any normal person can brute force millions of SHA-1 hashes (salted however much you want) per second on a GPU. If the FBI so wanted (although I don't believe they do) I'm sure they could brute force almost every single password in that database. Granted, it's the government and they have better ways of obtaining such information, but if there is someone the FBI is watching on Instapaper's databases and they so wanted, storing the SHA-1 hash of the password all but handed them over to the FBI. I am now glad my Instapaper password was generated randomly, 16 characters long, and I will now change it just to be safe. For anyone running a database which stores ussername/passwords, take a look at bcrypt or scrypt. They're millions (no, I am not exaggerating) of time better than SHA-1. (Edit: Grammar)
- IgorPartola 15y agoI have been thinking about switching everything to bcrypt, but there is definitely way too much confusion about bcrypt vs scrypt, how many rounds to set for bcrypt, etc. What is the definitive source for figuring out what the new standard should be? Does anyone have any links to something that's peer-reviewed and approved for use by someone with enough authority to do so?
- tptacek 15y agoNo there isn't. You only think that because when geeks discuss anything that involves one or more knobs, a huge debate must necessarily ensue about the proper values of those knobs. Just use the bcrypt defaults. You will be fine. You will in particular be so much better off than salted SHA-1 that this topic will be mooted. Later on, maybe in 5-10 years, you can re-engage with the debate about what a good cost factor for bcrypt will be in 2020.
- IgorPartola 15y agoThanks. I am just trying to navigate the sea of misinformation that spews forth everywhere about salted hashes vs bcrypt vs scrypt. I can see that lots of people claim that bcrypt is better, but I am not aware of anything about it other than the original paper. Basically, I want to know what the chances are that two months after I implement bcrypt a huge issue with it will be discovered and I'll have to move everything to some new scheme.
- teoruiz 15y agoI can't help to compare this raid with the feds raid to the Novus Ordo Seclorum hosting company pictured in Cryptonomicon.
- lukejduncan 15y agoEvery HN post can easily have a Stephenson reference.
- drjoem 15y agoi am wondering why these companies wern't using EC2?
- seiji 15y agoThat brings up an interesting point: can the FBI seize EC2 servers?
- lwat 15y agoOf course they can. If they get a judge to sign their warrant they can seize anything they please.
- chow 15y agoEC2 is not always a good substitute for dedicated servers for numerous reasons, I/O performance chief among them.
- andrewcooke 15y agois there a better solution that encrypting data and putting the password in the source? obviously this is for cases where you can't use a hash. it seems to me that, at least, it would make sense to have the db and web server physically separate in that case (although i guess someone stealing hardware is not normally a common scenario).
- tritchey 15y ago"a Swiss hosting company leasing blade servers" If they are truly blade servers, then they were possibly sharing the same chassis, power supply and backplane. Could the FBI have pulled just the blades in question? Possibly. But I can very easily imagine the entire blade chassis being viewed as a monolithic component that they would want to be able to perform whatever forensic analysis they are planning. They could also have pulled whatever blades they were not after, and left them, but until you replace the chassis, you are dead in the water.
- mmaunder 15y agoContact the ACLU, they will probably take your case.
- smackfu 15y agoTo be clear, the server stopped responding, and the host he is paying for the server has not responded at all. The server could simply be unplugged, or all the network cables were unplugged during the raid. Who knows? I guess "The FBI stole my server is a better headline" though. In my experience with our leased data center cages, we are expected to fly in to town if we ever need to physically manipulate the servers or even plug things in. The data center employees don't even go into the locked cages. If the FBI forced open a locked cage, and did stuff in there, I would not expect anything to be addressed until DigitalOne showed up to fix it.
- protomyth 15y agoIf DigitalOne's people are out of country, a truly evil tactic for the FBI would be to ask customs to reject any reps entry.
- gcb 15y agowho watches the watchers?
- johngalt 15y agoWhy isn't Facebook having their servers seized? Google? Amazon? If the FBI is really targeting the "badguys" I'm sure there have been more badguys using facebook/gmail/AWS than any single colo. Why haven't there been similar seizures of any larger corporate entities? Even if the current FBI practices are valid, should the application of those practices be a function of size/wealth/power? Which servers of Sony's were seized after distributing rootkits?
- maw 15y agoGood question. No solid answers here, but my guess would be some combination of more redundancy, better and more active lawyers, and the large players not talking about it when it does go down.
- epoxyhockey 15y agoFB, Google, etc all provide a nice procedure for LEO to query all desired info. It is not necessary to seize equipment. Example: https://www.eff.org/files/filenode/social_network/Facebook2010_SN_LEG-DOJ.PDF https://www.eff.org/files/filenode/social_network/Facebook20... (pdf)
- bhartzer 15y agoyet another reason to make regular backups of your site.
- bproper 15y agoYou think it's a coincidence they nabbed Whitey Bulger this morning, after 16 years on the run? His Instapaper account was probably full of stories about Santa Monica.
- VladRussian 15y agoi think his Instapaper account was full of stories about Whitey Bulger and his old friends/partners/etc... and this is how they "Big Data"-sifting-found him :)
- gokhan 15y agoWhat's the proper way of storing OAuth tokens in this situation? Given that all the tokens of users and your private key is on the server (even if it's embedded in code), there's no way for Instapaper for keeping those tokens secure in case of a compromise (by FBI or Lulzdudes or anyone). Seems like Instapaper should change it's private key for, say, Facebook.
- roc 15y agoI would think encrypting the third-party tokens with the user's password would be a decent start. When the user's password is verified, it could be used to unlock those tokens and store them in the active session structure in RAM. There'd still be some exposure, particularly in the case of being rooted, but an attacker couldn't just dump the database.
- deleted 15y ago[deleted]
- ChuckMcM 15y agoIt would make for an interesting Freedom of Information (equipment) request. "Give me my damn server back." But the damage is of course done. If you are a voting citizen of the US I recommend you write (not email, write a letter, put postage on it and everything) to your elected congressional representatives and ask that Congress immediately put curbs on the police powers of the FBI when it comes to infrastructure seizures.
- justinweiss 15y agoLooks like it's back: http://twitter.com/instapaper/status/84106275796946944 http://twitter.com/instapaper/status/84106275796946944 "As of 2 minutes ago, my DigitalOne server is back online. The logs indicate that it was off and not booted during the time it was missing."
- m0nastic 15y agoBut that would mean that the FBI weren't bumbling morons who salted the earth after tearing out everything in the datacenter with a power supply... I'm not sure I can deal with the possibility.
- engtech 15y agoJulian Assange stated that the feds have backdoor, no court order access to gmail, yahoo, facebook, et all. Why worry about this?
- iqster 15y agoTurns out the server was not stolen! https://twitter.com/#!/instapaper/status/84106275796946944 https://twitter.com/#!/instapaper/status/84106275796946944
- neckbeard 15y agoUpdate: http://blog.instapaper.com/post/6854208028 http://blog.instapaper.com/post/6854208028