He put his real name and email address in the WHOIS entry for one of the domains. Anyone with an internet connection could've tracked him down.
The proof they collected by connecting the IP to Facebook is a bit more advanced (although not complicated if you have a court order), but it appears that he didn't take any measures to hide his identity.
I thought that using a (non-US based) VPN and fake data for domains is the least you'd do if you run a website that could cause trouble. And accepting bitcoins is nice but not anonymous if you register the wallet with the apple ID that you use everywhere else as well..
I don't see that as a case of hindsight bias. I was expecting that every owner of a torrent site pays domains and hosting with bitcoins and always uses VPNs if not even TOR for work that could be logged somewhere (e.g. emails using a large provider).
Had it just been this one Apple purchase or a Facebook visit then I'd agree, there's always something you'll miss and it's much easier to point this out afterwards. But it appears that he didn't use a single method to hide his identity.
On the other hand, perhaps he thought that living in the Ukraine would give him enough protection against US agents.
It's crazy how torrent site owners are criminalised. Eg Oink who got raided and his site shut down, then found not guilty more than 2 years later, with his amazing community stomped into the ground by the copyright police. He did nothing wrong, nothing was illegal, yet they used their power to kill it.
OPSEC in the age of mass surveillance is incredibly hard. Zoz gave[1] has a very good overview of modern OPSEC. Staying anonymous requires an attention to detail that most people probably cannot do.
The hindsight bias is realizing how serious the situation might be and the level of OPSEC that is required. When the torrent site was first created the risk level wasn't known and most people didn't understand how hard it is to avoid the ubiquitous sensors of the surveillance-industriual-complex. Yes, more people probably should have assumed this level of risk much earlier, but that's easy to say now when we know names like Prism and XKEYSCORE.
The second article linked from Schneier's post says the owner of KAT "gets the Megaupload treatment".
I think the first article is much closer to being correct - KAT is like The Pirate Bay as it "facilitates" copyright infringement. I still find it wrong that linking to other content can be deemed criminal (both in the case of trackers and that there are public resources you can't legally link to).
Google results contain torrents, so it can be difficult to make a difference with Kickass Torrents. Google can even detect if a file is a torrent or not and if it infringes copyright material with hashes and audio/video recognition.
I expected Schneier to have some insight into this story but the blog posting just quotes an article from Engadget and links to another one from techdirt. And those are articles from the time when the site went down two months ago, nothing new either.
> The irony is that it was actually buying something online from Apple instead of pirating it that got him caught.
I dunno ... this gets repeated a lot because it is the official version of events but I am by default skeptical of such claims in operations like these as the authorities are fully incentivized to hide sources and methods.
Edit: I just read down a bit further in the discussion and nxzero holds a similar and well expressed view.
Of note, the DHS agent responsible for this case was the same guy who was the DHS case agent for the Silk Road investigation. I guess he is their go-to 'high profile Internet investigations' guy.
As someone that lives a largely anonymous life, not that I'm engaged in anything that would interest law enforcement, bullet proof operational security is impossible, and at some point mistakes happen. If you think it's easy, it's not.
Can someone really stay anonymous online nowadays?
Recently I have been too paranoid to even use the same throwaway account because doxing has almost become an automated process. For example if you have a reddit account you can summarize your comment history with: http://www.snoopsnoo.com/.
Note I am not even considering the case of people with privileged information. The people who run HN certainly already know who I am since I didn't bother to clean up before switching accounts.
But I think it will be an inevitable certainty for you to be automatically deanonymized with just speech/thought patterns from comments alone. For example if you google for the phrase I just used, "inevitable certainty", they are only ~7000 search results. And now that I think about it, it is a really weird way to say it but it also a phrase I have used before.
If I'd kept using weird phrasings or kept making consistent grammatical errors like that, it will eventually be enough to build a fingerprint based on my vocabulary, understanding of grammatical rules, beliefs, timezone, etc. The more I talk the more information I am giving away for people or just machine learning algorithms to cross reference and link together my anonymous and real accounts. See this post for a real example (but limited to just the bitcoin subreddit instead of across the internet):
https://www.reddit.com/r/Bitcoin/comments/3hf5z7/determining...
If you need to stay anonymous, don't interact with the world...
23 comments
[ 1.4 ms ] story [ 64.1 ms ] threadThe proof they collected by connecting the IP to Facebook is a bit more advanced (although not complicated if you have a court order), but it appears that he didn't take any measures to hide his identity.
I thought that using a (non-US based) VPN and fake data for domains is the least you'd do if you run a website that could cause trouble. And accepting bitcoins is nice but not anonymous if you register the wallet with the apple ID that you use everywhere else as well..
Had it just been this one Apple purchase or a Facebook visit then I'd agree, there's always something you'll miss and it's much easier to point this out afterwards. But it appears that he didn't use a single method to hide his identity.
On the other hand, perhaps he thought that living in the Ukraine would give him enough protection against US agents.
The hindsight bias is realizing how serious the situation might be and the level of OPSEC that is required. When the torrent site was first created the risk level wasn't known and most people didn't understand how hard it is to avoid the ubiquitous sensors of the surveillance-industriual-complex. Yes, more people probably should have assumed this level of risk much earlier, but that's easy to say now when we know names like Prism and XKEYSCORE.
[1] (note: contains rude/strong language) https://www.youtube.com/watch?v=J1q4Ir2J8P8
Accepting btc was probably more because of convenience of payments etc instead of anonymity.
I just can't get used to this terminology.
/* Regulatory capture sucks.*/
I think the first article is much closer to being correct - KAT is like The Pirate Bay as it "facilitates" copyright infringement. I still find it wrong that linking to other content can be deemed criminal (both in the case of trackers and that there are public resources you can't legally link to).
which they already do with youtube
The irony is that it was actually buying something online from Apple instead of pirating it that got him caught.
I dunno ... this gets repeated a lot because it is the official version of events but I am by default skeptical of such claims in operations like these as the authorities are fully incentivized to hide sources and methods.
Edit: I just read down a bit further in the discussion and nxzero holds a similar and well expressed view.
https://en.m.wikipedia.org/wiki/Operations_security
Yes, putting your name in a Whois record is stupid, but just because that's what was publicly disclosed doesn't mean that's how they found him.
https://en.m.wikipedia.org/wiki/Parallel_construction
Recently I have been too paranoid to even use the same throwaway account because doxing has almost become an automated process. For example if you have a reddit account you can summarize your comment history with: http://www.snoopsnoo.com/.
Note I am not even considering the case of people with privileged information. The people who run HN certainly already know who I am since I didn't bother to clean up before switching accounts.
But I think it will be an inevitable certainty for you to be automatically deanonymized with just speech/thought patterns from comments alone. For example if you google for the phrase I just used, "inevitable certainty", they are only ~7000 search results. And now that I think about it, it is a really weird way to say it but it also a phrase I have used before.
If I'd kept using weird phrasings or kept making consistent grammatical errors like that, it will eventually be enough to build a fingerprint based on my vocabulary, understanding of grammatical rules, beliefs, timezone, etc. The more I talk the more information I am giving away for people or just machine learning algorithms to cross reference and link together my anonymous and real accounts. See this post for a real example (but limited to just the bitcoin subreddit instead of across the internet): https://www.reddit.com/r/Bitcoin/comments/3hf5z7/determining...
If you need to stay anonymous, don't interact with the world...