Showing posts with label Bittorrent. Show all posts
Showing posts with label Bittorrent. Show all posts

Monday, March 26, 2007

Private Protection?

There is a statement you'll often see on p2p forums, and in IRC channels. It usually comes in a discussion about “getting caught” or “letters been sent” and it goes something like “the safest thing is to join a private site”[image]. The other oft-proposed solution, blocklists, has been discussed before. Are private sites any safer though?

In preparing this piece, I spoke to several private site admins, and a few public tracker admins as well. The results may surprise you.

There are three main areas of concern, that the server may get seized, or that an anti-p2p agent may infiltrate the site. Seizure is a risk for all torrent trackers, or indeed all servers period, as both pirateBay, and indymedia can attest to. This has both good and bad points, in that you get the site shut down quickly, but on the downside, you REALLY have to have your ducks in a row before doing so. Additionally, you may take out the site admins, but you can often create a negative publicity backlash, especially if you take down other people's servers at the same time. 'Infiltration' is a more time consuming method, but can yield better results. This was the method used to mount evidence for the elitetorrent raid (operation d-elite) in May 2005. The third method is describable in many ways, depending on your opinion of the target of it. It can range from “surrendering to extortion” to “getting paid off” but means the server owner has been contacted by one or more groups or agencies, and has agreed to hand everything over voluntarily. There is only one real example of this so far, Lokitorrent.


Seizure


Put simply, this is the method of :
  1. Going to the hosting company,
  2. Gaining entry (with or without a 100% legal and valid warrant) and
  3. Physically removing the servers from their racks,
  4. Then taking them into custody.
Often, search warrants will also be served on any members of the site also within jurisdiction and considered 'big enough'. Once they are taken into custody, the hard drives can then be examined and entered into evidence for possible criminal proceedings. How do private sites deal with this?

Well, depending on the site, you might be safe, whereas others you might as well just hand yourself in on others. All that I spoke to stored the total ratio (including upload and download counts) email address, and username/password. Many also save a list of what torrents you've uploaded to the tracker, although that list usually only contains active torrents active.

The email address and username/password is a bad thing. It counts as 'personally identifiable information', basically meaning you can't say “it wasn't me that did it'. Odds are you probably have an email from the torrent site in your email account with your username and password. If the password matches any other password you use, or if your computer shows records of having accessed that email account, that's a link made to you that will be very hard for you to explain away.

Of course, such seizures are rare, and to date there has been no activity against individual users of the sites, but it must be pointed out that of the two public tracker admins I contacted, (Anakata of the pirateBay, and the one of the tracker suppliers to EZTV and VTV's) both said that their trackers did not save any user data at all, it was all in volatile ram, meaning when they're pulled, or even when the power goes out, the data is gone. Only the most secure of the sites I spoke to (scenetorrents) offered this for its uploaders and staff)

Infiltration


This is more the sort of thing that copyright enforcement groups are generally better at. It takes a lot of time, and manpower, which they have, unlike the understaffed and overworked criminal investigators the world over . Not to say that such departments are not capable, there really are more important ACTUAL crimes, that affect everyday people in a major way that they should be dealing with instead. At its most basic, its someone, joining a site, and collecting info. Depending on the sites membership policies, and its popularity, this can be very easy, it can be hard. Quite a few are now invite-only, so first you have to find someone with an invite, and acquire one somehow. Methods for this alone have a huge range, from “hey any1 got an invite to xyz' on a forum [image], to building up a relationship and bona fides on an IRC network such as p2p-net, or EFnet. Others, such as the British TV+radio site UKnova are so popular that when an inactive account is purged, the empty membership can be snapped up within 5 minutes.

So, is there anything stopping these people joining? Well, in a word, no. It's unlikely a member of the BSA will try and register for a site from his office computer, for instance, but there is nothing stopping someone from doing so. One site however (Bitsoup) did give a sign up warning [image], albeit an old favourite making a comeback. Once someone is on, they then have the job of collecting IP addresses from the tracker. In this regard, private trackers are inherently much less secure. On most private sites, all users can view all the usernames of peers also on the torrent with them, and sometimes their upload and download averages.

If they were to compile lists of users on a torrent with the IPs on the torrent, it might be hard to match them, but do it over a few dozen torrents, and they'll start seeing the same IP ranges appearing only when a certain username is on it – they've now identified the IP address of that user. It is impossible to do this with a public tracker, as put simply, there is no username telling anyone when a certain person is on a torrent. Add in DHT, and that people tend not to have any loyalty to a certain tracker, mean its impossible to build this sort of complete peer overview without private sites.

So, copyright enforcers may be members of your favourite private tracker, do the sites do anything about it? Again, in a word, yes. None of the sites would go into detail with me how to monitor for such users (and I doubt I'd understand them if they did – software guys have a tendency to revert to their own private language when asked a technical question) but I was told by all of them that they employed a mixture of automated, and user-based methods to detect and report suspicious activity. Basically everything from a user reporting a peer acting suspiciously on up.

Conclusion


Whilst private sites can prevent you from getting the letters and emails from your ISP or enforcement agency, They are not a perfect solution. Dealing with these sites takes time and effort, a lot of it, and that's more than many rights holders care to do right now. It is relatively easy to go to somewhere like mininova, and find a torrent for your property, then grab the IPs and send an email to the corresponding ISPs, it's much more involved to do the same with private sites. In that aspect, private sites are safer. Until the majority (or at least a large percentage) of material on a private site belongs to one rights holder, that holder is unlikely to target that site. There are exceptions, of course, depending on the material in question – the elitetorrents bust over Star Wars Ep3 showed that.

In the long term however, when and if the procedure for prosecuting file sharers through civil court becomes easier, such sites will be far more hazardous to use. The very practice of restricting usage to certain identified members is its achillies heel. Using a groups own membership and activity records against itself has been a prosecution tactic for many decades. Seizures happen, infiltrations have gone on for a while now, and some might say it's only a matter of time.

In their favour, private sites have generally much faster speeds than public torrents, meaning your window of exposure for downloading is shorter. However due to the more limited availability of the torrent, and the greater importance on ratio, you can have a vastly greater upload window, and it's uploads that are usually targeted. They also generally have content policies, meaning fakes, malware and misnamed torrents are kept to a minimum.

Overall, in some ways they're safer, in just as many ways they're a liability. To put it another way, you're safer from the more common small-time infringement notification, but a much easier target for the (much rarer) big-time operations.

Ben Jones

Digg this story

With thanks to the following people
Feeling of SceneTorrents
Dragonheart, at Bitsoup
[pm] at Uknova
Anakata at the PirateBay
a staff member at Tvjunkies
and the admin for some of vtv and eztv's trackers

Monday, May 15, 2006

Blocklist Balderdash

Use a blocklist? Think it makes you safe, allows you to share with impunity? Think again. I will say this now, up front, and clearly.

The amount of overall protecton given by a blocklist is minimal at best.

Oh, don't get me wrong, for certain things, IP blocks are usefull, but for most things, they're not. Why, you might ask, and the answer is simple. If you wanted to read the news site The Register, you would go to www.theregister.co.uk, you wouldn't go to 212.100.234.54, which is its IP. Or rather, which is currently its IP. And there we have it. IPs CHANGE, that's why we have domain names. Certainly, some places will have fixed domain names, but only those who've actually bought their groups of IP addresses. Home users are not what we'd call fixed IP.

Well, what does this mean? It means that anyone can use a home connection pretty safe in the idea that these blocklists won't affect them at all. This might not seem like a big deal, but its their major weakness. There is absolutely nothing at all, stopping the head of anti-piracy for some company going home, and using the DSL connection he has there. he can log there as easily as he could at work. There is, after all, no rule saying copyright enforcement can only be done on a corporate network. Heck, he could even then charge the ISP costs to the company, citing it for work. Doesn't grab you? Why don't they then use the other common resource in a busy office building - telephone lines. They can easily get some dialup modems and use them in the office. A free AOL CD or two, and they have a connection. Doesn't matter that dialup is slow, its not the transfer of data they're interested in, its who's doing it.

Think I'm joking - take a look at the people connected to you next time you are using your favourite P2P app.
It may well say 86.137.220.74 on port 6356 (an IP picked at random from a knoppix DVD torrent) - that comes out to be a BTcentral.com user, but who is that person, and who do they work for? Can you be sure that the AOL peer in your list is not an investigator for the BPI, MPAA or any other such body? They all know the tricks and the limitations of such software as well as anyone, if not better (it is their job, after all, to know about them). Don't be mislead by the actions, and press releases, their technicians and loggers are very competant, and advanced - its the lawyers and PR people that give the impression of a eunoch running a family planning clinic.

Indeed, in some cases using lists can work against you. After all, who uses such lists, is it the kid downloading the very occasional song, or the hardcore downloaders? Why, the latter of course, the slight/casual user doesn't know, or worry about it that much. So, the ones that download heavily are the ones to target. Alas, theres no way to tell from a torrents userlist which group, light or heavy, they are in, since every torrent is seperate from each other. Solutions? Well, you could scan every torrent out there, and look for recuring IP addresses, but that has two drawbacks.
1) its very time consuming, and resource intensive. and
2) we're back to the dynamic IPs again - without a court order to the ISP, theres no way to tell if the same person was using the same IP on both monday and thursday. They might have had a power cut on tuesday night, and their modem obtained another IP.

Thankfully, blocklists to the rescue!. The easiest method is use the blocklists themselves to identify the heavy users. Its very simple and uses two groups of systems (doesn't have to be a group, can be just one system in each). One group uses IPs on the blocklist, the other doesn't. Collect peer data from both, and after a while, compare lists. the major differences will be the blocklist computers will be on only one list. Voila, IP addresses obtained. Your 'protection' has been turned into identification.

Of course, that's just the main disadvantage of the system. There is a second one, and thats best described with the old computing acronym - GIGO. In other words, the quality of the list is only as good as the person thats compiled it. Any personal bias, or other skew will similarly skew the list into ineffectiveness. I wrote about a fine example of this just over 2 months ago.

Well, thats the big minus points in such a system, there are some advantages however. Such lists, used as a hosts file, for instance, can stop annoying and irritating popup ads. They can also prevent some of the torrent poisoning that goes on, although most torrent clients should manage to deal with that on their own. These are only minor pluses, however, and not really much of a benefit.

There is one simple thing to remember in general. If something is publicly downloadable, like a blocklist, it's effectively useless. Can you see, use and edit the blocklists? What stops copyright enforcement people getting the same lists and altering their strategies to work with these lists? Absolutely nothing. A high speed connection might be usefull for downloading, but a dialup connection is all that's needed to log people infringing copyright. The only way a blocklist can be effective, is if it blocks all potential 'snitch' IPs. Alas, that means blocking every single ISP in the world, and then you've blocked yourself from any sort of transfer anyway.

Just as a side note - I remember discussing the merits of the comparative method back in 98, when I was a copyright enforcer. That was 8 years ago, if you still think blocklists are a good idea, and worthwhile, you go right ahead, and can I also interest you in this fine bridge?

Ben Jones

[Editors note: Thanks to kdsde for pointing out some of the typos in this piece]