5 ms·
Please let's never forget: An IP-Adress is not a person[1] [1] http://torrentfreak.com/judge-an-ip-address-doesnt-identify-a-person-120503/ http://torrentfreak
by gitarr 14y ago
Please let's never forget: An IP-Adress is not a person[1]
[1] http://torrentfreak.com/judge-an-ip-address-doesnt-identify-a-person-120503/ http://torrentfreak.com/judge-an-ip-address-doesnt-identify-...
- ben0x539 14y agoAn IP address can be assigned to a person that can be held legally responsible easily enough, though.
- Zirro 14y agoWhich raises the question often brought up in various forms: Is a person responsible if someone has been using his or her router for file-sharing because they were able to crack its WEP-encryption, while the accused in question hardly knows what a router is?
- jiggy2011 14y agoMost non tech people are just using an ISP provided router, every ISP that I know of provides a router with WPA2 and went around replacing old WEP routers a few years ago. I can't remember the last time a WEP network showed up on my smartphone. Of course there are other ways someone may have broken into your network.
- lgeek 14y agoMany APs have WPS implementations that can be trivially brute-forced and can't be disabled. Paper: http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf Open-source tool: http://code.google.com/p/reaver-wps/ http://code.google.com/p/reaver-wps/
- gnaffle 14y agoActually, many routers have easily predicable WPA2 passwords. Based on the MAC address or the access point name, it is often possible to deduce the default key (which many/most people don't change).
- tsahyt 14y agoIt's not like WPA2 would be terribly secure either. One minute of googling directs you to a step-by-step tutorial using aircrack. WiFi is nice to have but one has to be aware of the security issues that arise with it.
- jiggy2011 14y agoAll of the WPA2 attacks I've seen assume predictable SSIDs and Passwords. Again , ISPs seem to be ahead of this. Looking in my local area most of the APs have names like "BThub543897534895" and I assume that the passwords are randomly generated.
- tsahyt 14y agoaircrack-ng assumes pre-shared keys. Cracking long passwords is quite time-consuming (read: takes a VERY long time). They actually explicitly state that in their wiki. I'm not exactly sure but I think I read something about using GPUs to accelerate bruce-force times with a speedup of 100x. That's quite substantial, however even with that brute-forcing is not an option here, which gets us back to the fact that an attacker will hope for a weak password, possibly in a dictionary. You're right about ISPs being on the safe side with their SSIDs and passwords, but I think you're underestimating the users here. For the sake of it I've spent an hour and a half driving around town a year ago, logging locations of access points. I never did anything with the data except for looking at how access points are distributed across my town. Most of the AP names where common words or a combination of such. Concerning passwords, I've used wifi at friends and coworkers places quite a few times and most of them had weak passwords. An attacker might just go and do some wardriving and randomly attack access points and I believe he'll find one weak enough without much of a hassle. Bottom line it's the same as always: In the real world security isn't as depended on technology as it is on how much the user is concerned with it. How that works out in a lawsuit is a different question though.
- jdietrich 14y agoIf someone cracks your WEP, are you responsible for what they do over your connection? If someone steals your car, are you responsible if they use it as the getaway car for a bank robbery?
- jiggy2011 14y agoI read something a while ago from an IP lawyer, he said that in such an occurrence they would instead just sue you for negligence. There don't seem to be many wireless LANs using WEP anymore anyway because of the obvious security flaws. Perhaps some grandma with an old router could get away with claiming ignorance as a defence but the average HN reader probably couldn't. As for the car analogy perhaps this would be similar to leaving your car unlocked knowing full well that it was likely to be stolen by criminals.
- smokeyj 14y agoAn IP still isn't a person as your computer could be remotely controlled. Maybe grandma shouldn't have been so negligent when updating her Java package when a known zero day exists.. Expecting anyone besides a HN dork to know WEP is outdated shows how closed minded some of us are.
- ben0x539 14y agoI agree with you in principle but I don't think legal doctrine in most countries where filesharing ligitation happens does. If your computer is compromised while used to torrent a movie, you'll have a hard time convincing a court of that ten months later.
- jiggy2011 14y agoMy point is that it's usually down to the ISP or whoever provides to router to make it secure. From what I have observed WEP routers are very rare in the wild so it would seem that they are doing their diligence here. I'm also not sure how far ignorance goes as an excuse although this could well depend on whether we are talking about civil or criminal law. For example in pretty much any country there are literally thousands of laws that you are expected not to break. I doubt even veteran lawyers know all of these down to the letter , yet if I am charged with one of them that I have no knowledge of I cannot get away with saying that I didn't know it existed. In theory I guess it could be argued that you should never do anything without first consulting a legal professional. Possibly a lawyer could say to grandma "If you didn't know anything about routers or Java updates, why didn't you hire an IT expert to configure your computer for you?"
- Wilya 14y agoDepending on where you live, being the owner (or responsible, or whatever you may call it) of an IP used to pirate things can be enough to be condemned.
- njharman 14y agoI'm pretty sure the ISP (or ISP's ISP) owns the IPs and are just "renting" it to you.
- belorn 14y agoThis become even more important when anyone can add false information to a tracker.
- deno 14y ago> "All the monitors observed during the study would connect to file-sharers and verify that they were running the BitTorrent software, but they would not actually collect any of the files being shared," he said.
- qu4z-2 14y agoRunning BitTorrent software is illegal now?
- deno 14y agoThat’s why he added: > "It is questionable whether the monitors observed would actually have evidence of file-sharing that would stand up in court." However, it’s not really that much more work to verify if that peer is sharing the file in question. Just request/offer few random blocks. There’s no mechanism in place to assign peers in BT network varying degree of trust.
- tsahyt 14y agoIn Austria it is since the introduction of data retention. Every time someone is assigned an IP address by his or her ISP, an entry is made so IP addresses can be mapped back to the person at any given time. It's pretty much the same across the EU, I reckon. I haven't heard of any cases yet where this data was used in a court of law though, but it is theoretically possible. Why would there be a law to oblige ISPs to do that if not for using this data in lawsuits? Back in 2006 when the EU guideline was made the official version was the usual terrorism bullshit (data is only usable for the prosecution of severe criminal action). In April this year the EU decided that file sharing is severe enough. A side fact: Data retention hasn't proven to be very successful yet.
- jetti 14y agoThat would log an IP to a computer that is it. If I'm at your house and jump on your computer and download the latest and greatest movie. That would be logged as you doing that not me. The ISP would only have one piece of the puzzle, hence the problem with just tracking IP address.