20 ms·
BitTorrent study finds most file-sharers are monitored
- pervycreeper 14y ago>researchers found that nearly every file-sharer they monitored, was monitored.
- bluetidepro 14y agoHaha, I cracked up when I read this. This just seems like a (very typical) BBC scare tactic article.
- parham 14y agoLOOL typical scaremongering
- wmf 14y agoI guess now we know who watches the watchers.
- ansman 14y agoThis feels like a scare tactic to get people scared, they could never go after all downloaders.
- eckyptang 14y agoIt probably is. The BBC are notorious for jumping on top of every scare tactic out there and promoting it.
- azar1 14y agoAnd yet we see today the claim that 1m+ Apple UDIDs were allegedly stolen from a single FBI agent's laptop. We are easier to track than ever.
- ljf 14y agoDon't forget all (well nearly all) Bit Torrent downloaders are also (by default) uploaders - seeding back to the pool while their file downloads. MAFIAA and others don't care about downloaders (as yet I don't believe a single user who downloads only, has been sued successfully), but they DO care about those sharing their material. The fines levied so far are not for downloading tracks, but for sharing them.
- Nav_Panel 14y agoThe key word in the article is "popular" content. It is well known that (a) relatively new and (b) relatively mainstream + popular content (especially movies) is heavily monitored. The article title is misleading. They logged only popular, public torrent content. I'm certain that many, many other file sharers were not even seen by their study. It's all just scare tactics.
- zimbatm 14y agoA serious journalist would have given us a link to the source. Here it's not possible to verify the claim without serious digging.
- jiggy2011 14y agoCouldn't they? Letters are cheap to send. They could simply send out a few million or so letters, maybe costing a million £ or so. Offer everyone a settlement of a few hundred £ to cover all past transgressions with the threat of suing for a much greater sum if there is a repeat offence or if they do not comply. If you work on the basis that about 50% just pay up straight away that's quite a lot of money. This money can be used to subsidize going thermonuclear on at least a few thousand of those who don't. Besides, they don't need to sue everyone to make people scared enough to avoid pirate sites.
- deleted 14y ago[deleted]
- gitarr 14y agoPlease let's never forget: An IP-Adress is not a person[1] [1] http://torrentfreak.com/judge-an-ip-address-doesnt-identify-a-person-120503/ http://torrentfreak.com/judge-an-ip-address-doesnt-identify-...
- ben0x539 14y agoAn IP address can be assigned to a person that can be held legally responsible easily enough, though.
- Zirro 14y agoWhich raises the question often brought up in various forms: Is a person responsible if someone has been using his or her router for file-sharing because they were able to crack its WEP-encryption, while the accused in question hardly knows what a router is?
- jiggy2011 14y agoMost non tech people are just using an ISP provided router, every ISP that I know of provides a router with WPA2 and went around replacing old WEP routers a few years ago. I can't remember the last time a WEP network showed up on my smartphone. Of course there are other ways someone may have broken into your network.
- gnaffle 14y agoActually, many routers have easily predicable WPA2 passwords. Based on the MAC address or the access point name, it is often possible to deduce the default key (which many/most people don't change).
- lgeek 14y agoMany APs have WPS implementations that can be trivially brute-forced and can't be disabled. Paper: http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf Open-source tool: http://code.google.com/p/reaver-wps/ http://code.google.com/p/reaver-wps/
- webjunkie 14y agoWhat does 3 hours mean? I don't need that long to download anything. And I doubt that if I download some rare indie music stuff, that anyone would care to monitor this torrent.
- klearvue 14y agoI think it means 3 hours from the initial torrent availability on trackers.
- lgeek 14y agoActually webjunkie appears to be correct. From the paper: > Average time before monitors connect. 40% of the monitors that communicated with our clients made their initial connection within 3 hours of the client joining the swarm; the slowest monitor took 33 hours to make its first connection. The average time decreases for torrents appearing higher in the Top 100, implying that enforcement agencies allocate resources according to the popularity of the content they monitor.
- notimetorelax 14y agoExcept that it is illegal to collect IP addresses in some European countries (Switzerland for example). Here's the link: http://www.edri.org/edrigram/number8.18/collecting-ip-addresses-illegal-switzerland http://www.edri.org/edrigram/number8.18/collecting-ip-addres...
- tsahyt 14y agoIt's the law in others
- Zirro 14y agoThis should not come as a surprise to anyone who has been following the developments within the P2P-world. If you still care about privacy while you connect to a large amount of computers, a proper VPN or a similar service to mask your origin is the way to go.
- sillysaurus 14y agoAny recommendations?
- Zirro 14y agoI live in Sweden, and lack experience from VPN-services which are not close to home, but have a look at: http://torrentfreak.com/which-vpn-providers-really-take-anonymity-seriously-111007 http://torrentfreak.com/which-vpn-providers-really-take-anon...
- rada 14y agohttp://torrentfreak.com/which-vpn-providers-really-take-anon.. http://torrentfreak.com/which-vpn-providers-really-take-anon.... My personal choice is privateinternetaccess.com: $40/year, unlimited bandwidth (cloak and many others limit bandwidth), multiple platforms (Windows/MAC/*nix/iOS/Android), multiple protocols (PPTP, OpenVPN and IPSEC/L2TP), multiple gateways (US/UK/Switzerland), and most importantly, NO user activity logs. Also, per http://news.ycombinator.com/item?id=4474529 http://news.ycombinator.com/item?id=4474529 you could use any vpn that routes through Switzerland.
- sedachv 14y agoSome tips on anonymizing VPNs from a previous HN discussion: http://news.ycombinator.com/item?id=3913985 http://news.ycombinator.com/item?id=3913985
- rm999 14y agoThis shouldn't be a surprise. It is trivial to capture that kind of data from large bittorrent clouds like piratebay, and that data may have some useful applications. For example, getting statistics on what movies, tv shows, and music people are interested in (often before commercial release) with really precise geographic information.
- synctext 14y agohttp://www.cs.bham.ac.uk/~tpc/Papers/P2PSecComm2012.pdf http://www.cs.bham.ac.uk/~tpc/Papers/P2PSecComm2012.pdf Link to 18-page scientific article by University of Birmingham. This is the actual meat behind the BBC article. Not an alarmist paper, just boring work with Bittorrent download progress bitmap monitoring. Some juicy bits on their usage of Tor, from the paper: "we created our own indirect monitoring client that gathers newly-published torrent files from the Top 100 in each category on The Pirate Bay, and continually contacts each of the trackers and stores (IP address, port number, infohash, time) tuples from the peer lists that are returned; it then attempts to establish a TCP connection with each host and sends a handshake message to ensure that the host is in fact a BitTorrent peer. [..] We collected data from July 21–28, 2009, routing our traffic through the Tor anonymity network."
- fluxon 14y agoAren't there bittorrent clients which autodetect and autoblock clients which connect, but neither upload nor download? Doh! Link to a somewhat more informative, less beeby, story: http://www.newscientist.com/blogs/onepercent/2012/09/honeytrap-catches-copyright-co.html http://www.newscientist.com/blogs/onepercent/2012/09/honeytr... And the lead researcher http://www.cs.bham.ac.uk/~tpc/home.html http://www.cs.bham.ac.uk/~tpc/home.html Published paper link snaked below! :) (A previous paper: Analysis of BitTorrent Peers' Behavior and Monitoring Trends http://www.kaspersky.com/images/camilo_andr%D1%83s_gonzalez_toro-10-75858.pdf http://www.kaspersky.com/images/camilo_andr%D1%83s_gonzalez_... which was based on the Snark Project, updated)
- brazzy 14y agoIt would have to be the tracker, not the client, and at best it could somewhat reduce the number of other clients' IP addresses available to suspicious clients, since the classification is based on how they interact with other clients, whose IP addresses they of course have to know.
- baltcode 14y agoIt says a lot of the trackers were not on the blocklists.
- TazeTSchnitzel 14y agoI was worried, then remembered that the only things I tend to pirate are anime. And I expect the fansubbed torrents are not quite so well-monitored.
- maurits 14y agoHave a peek at the peers next time. You might be unpleasantly surprised.
- TazeTSchnitzel 14y agoTrue. But even so, it's usually torrents with very few peers.
- octopine 14y agoThe original paper without all of the scaremongering: "The Unbearable Lightness of Monitoring: Direct Monitoring in BitTorrent" http://www.cs.bham.ac.uk/~tpc/Papers/P2PSecComm2012.pdf http://www.cs.bham.ac.uk/~tpc/Papers/P2PSecComm2012.pdf
- pessimizer 14y agoA lot of it is definitely for consulting purposes. I thought of going into that line - seeing how what movies, TV, and music wouldn't be taken even for free would be interesting to the producers of that content. Looking at activity on torrents gives you a really good idea of relative interest in something, and in addition, on membership torrent sites, it could be cross referenced with the other interests of the downloader simply by using their history to give you some idea of demographic and to guide marketing strategies.
- jiggy2011 14y agoThat's an interesting point, I imagine stuff that is popular with a more tech savvy demographic (sci-fi etc) is more frequently pirated. It might be interesting to know if your show is unpopular because nobody wants to watch it or if everyone who wants to watch it prefers bittorrent. On the other hand , I don't know what you would do with this information unless you had a strategy for monetising bittorrent.
- pessimizer 14y agoI mean more like "People who pirate your show also pirate Breaking Bad and Sons of Anarchy, but of the people who pirate Breaking Bad and Sons of Anarchy, there's more pirating of Futurama than your show." or "Though you think your show appeals to Friends fans, the people who pirate your show tend to pirate 2 Broke Girls more significantly than they pirate Friends." Even more interesting to me are the surprising highly trafficked music and movies that are long out of print. Might be a good indicator of when to bring them back, and what fora to announce that in.
- teagoat 14y agoI was interested in how they were detecting monitors and whether they were just picking out any anomalous peers (say ones that don't accept connections). I was also wondering if the paper was going to be obviously flawed and funded by some copyright agency with the aim of articles such as the one we just read being created. I still wouldn't rule it out, but I feel that the methodology was sound. To summarize for others indicators were: """ 1. The proportion of a subnet that has been seen in BitTorrent swarms. Monitoring agencies may use a large proportion of their subnet for monitoring. 2. The length of time a peer spends in a swarm. Monitors may spend more time in the swarm than regular file-sharers. 3. The number of different (IP, port, infohash) combinations per IP address. Monitoring agencies may operate many clients from a single IP address. 4. Whether a peer reported by a tracker accepts incoming connections. Monitors may block all incoming connection attempts. (((This was discarded as an unreliable indicator))) 5. The number of swarms in which IP addresses from a particular subnet appear. Monitoring agencies may monitor many torrents from their subnet. 6. The number of times the same (IP, port) pair is observed concurrently in different swarms. ... we found 1,139 IP addresses that were in the top first percentile for all four features (((1,2,3 and 5))) IP addresses assigned to a company named Checktor [3], which offers commercial BitTorrent monitoring services, and 16 addresses assigned to a medium-sized computer security consultancy company that does not publicly acknowledge monitoring BitTorrent. Another subnet, which we saw in over 500 swarms, belongs to a company that advertises itself as providing “intellectual property advice” ... We also found two subnets assigned to hosting companies ... We speculate that copyright enforcement companies are using these hosting companies as a front to disguise their identities. We also identified a number of IP addresses allocated to large ISPs, such as Vodafone, Etisalat and SingNet. ... This feature (((6))) found IP addresses assigned to Peer Media Technologies [16] (a well-known copyright enforcement agency) monitoring seven Harry Potter ebook and movie torrents, and the INRIA research institution [10], which had been overlooked by features 1–5 because so few torrents were being monitored, and because a very small proportion of INRIA’s subnet was being used for monitoring """ I didn't read too much further into their methodology for detecting "direct monitoring" other than to see a pretty graphic showing peer lying about their download completion.
- vlisivka 14y agoHey, look at any torrent sharing site: you will see result of monitoring (e.g. 10 seeders, 5 leechers, 140Mb, healthy) near to each torrent file. Of course, each torrent file, which you will see at torrent sharing site, is monitored by torrent sharing site.
- ivanbernat 14y agoIt's a little know fact, but all telcos here in Croatia monotor and store all torrent traffic info of their customers. They have massive rooms with monotors dediated to showing which customer in which building is currently using torrents. And all of this data is stored for once the Gov decides to "crack-down" on illegal file downloads, they will have massive amounts of evidence.
- pavel_lishin 14y agoThe storage costs must be astronomical. So astronomical, in fact, that I don't believe you.
- aw3c2 14y agoproof?
- jiggy2011 14y agoThis strikes me as unlikely. Perhaps they can track some of it, but IIRC many torrent clients will use random ports and end to end encryption which is there to evade traffic shaping. My router has various features to block P2P traffic, as an experiment I tried enabling these features and then downloading torrents (Linux distro ISOs). Every time I enabled these the data rate on the torrent client would start to drop, but then within minutes it would be right back to full power again. At the end of the day you can just make a bunch of connections to port 443 on a remote host, start an SSL session and you are now indistinguishable from HTTPS traffic. The only way I could effectively block it was to disable NAT and force everything to go through an HTTP proxy.
- aw3c2 14y ago"Most" does not seem to mean much here, while it probably is correct. According to the paper they only used thepiratebay as originating tracker. Right now the homepage lists 30 million peers. what.cd shows 9 million peers. I do not know how many peers Demonoid had, probably a similar or higher number. Some smaller trackers I checked all had around 100k peers. So just think of 60 smaller trackers like that and poof, the "most" is not true anymore. This also only covers Bittorrent, not "most file-sharers".
- tsahyt 14y agoAll the monitors were checking whether the file sharer used BT software? Why? I mean, there's not much of a reason to connect to a swarm if you're not seeding or leeching. Then again, does that mean that spoofing the name/id/whatever of the software gets you off the monitors radar?
- nvmc 14y agoPeople know that I'm downloading the new Fast and Furious movie from TPB?
- brink 14y agoThey don't watch tpb traffic so much as actual torrent traffic. Basically, if you want to be more anonymous, pay to be a part of a vpn.
- nvmc 14y agoI was being entirely sarcastic. Where I live, people have been getting stung by honeypots for at least the last five years. I figured everyone (here on HN) either used private trackers or a VPN.