Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While I won't justify anything this person allegedly did.. it seems open to speculation whether the child pornography stuff was actually legitimate, or some sort of targeted attack. (whether to destroy his character/career or keep him under judicial watch / within the country)


I suspect that once they stick you with possession of child porn __everything__ you do or have done is subject to legal review. That is, there are no bounds to where and when the law can look; no bounds and no on going need for warrants, etc.

Your rights go out the door, and your digital life probed endlessly.


I read the IRC logs, and I'm skeptical that anyone not deeply versed in the lingo, tone, and character of that scene could fake them.

It's not impossible, but it was pretty convincing to me.


You don't think the CIA would be able to fake the lingo, tone, and character of the scene? I mean, they certainly have access to a ton of real IRC logs about the subject, would probably be pretty easy to swap out some usernames.


The IRC logs are minor pieces of evidence. It’s the VM that is hard to explain away.


There is nothing about the use of a VM that is "hard to explain away." You know what a VM is, right? You know anyone could plant things on a VM just like any other computer, right? You know there are many ways someone like the CIA could obtain a password used to encrypt a VM, right? Perhaps it was not always encrypted? Perhaps his host machine was infected with a key logger? Perhaps they used an exploit in the software he used to encrypt the VM, or a proprietary exploit designed to do exactly this, produced in conjunction with any number of software companies. There are many, many ways this could have happened, and the existence of a VM means literally nothing.

Why are you convinced the presence of a VM in this is significant?


My other comment is below. Have you read the complaint? The government is claiming that there is essentially 8 years of evidence on that VM, that in addition to the actual CP, there is a long trail of metadata and inode data that would be fairly difficult to fake.

I mean, think about it: if you were the defendant, all you'd have to do is have someone examine it and find inode activity when you had a clear alibi that the government didn't know about (which would be easy, given we're talking 8 years here, he'd just have to find when he was on a date or out to dinner or something, the government isn't going to know his entire life history for 8 years), and you'd be well on your way to creating enough doubt with a jury.

Now, it's possible the government is lying, but if they're not, it strains credulity to think that they'd go to the effort, cost, and risk to fake that VM in such elaborate detail. If they wanted to ruin his life, there are hundreds of easier ways to do it than such an elaborate fraud.


You didn't answer my question. There is nothing about the existence of a VM that makes it "difficult to explain away" and you did not establish why the fact that there is a VM being used is relevant.

What you are now saying is that it's implausible that the CIA would be able to fake logs (and that's what we're talking about with inode data) on a VM for some reason. It would absolutely not be as simple as "have someone examine it and find inode activity when you had a clear alibi" because it is very likely the guy was actually using a VM legitimately. All the CIA has to do is establish that he was in possession of child pornography. Hell, they don't even need to prove it beyond a reasonable doubt if A) the jury, defense, prosecution and / or judge is not tech savvy to understand some of these concepts, and B) if their goal is to trash this guy's life and have it be a warning to other leakers. You don't even need a conviction for that.

It does not strain credulity at all to think that the CIA would go to the effort to fake a small set of data on a VM. The "elaborate detail" is not any more elaborate than in any other instance -- it would be trivially easy to forge. If they wanted to ruin his life, this is a perfect, practical way for them to do it.

The fact that they would forge this data on a VM makes it seem even more plausible to people who don't even understand what VMs are, or how one might fabricate logs like that. It's apparently working on you right now, and you're savvy enough to know about the existence of inode data. You're apparently ready to condemn this guy despite the ludicrous amount of circumstantial evidence that maybe this guy is being set up by an organization literally dedicated to covert operations of this nature, who have even go so far as to detail exactly how they would undertake this exact kind of operation.


> all you'd have to do is have someone examine it and find inode activity when you had a clear alibi that the government didn't know about (which would be easy, given we're talking 8 years here, he'd just have to find when he was on a date or out to dinner or something, the government isn't going to know his entire life history for 8 years), and you'd be well on your way to creating enough doubt with a jury.

There are plenty of ways that happens even accidentally though, a prosecutor would be able to knock out that claim easily.

You've never seen a Linux machine write entries to the system log with the wrong timestamp? It happens all the time on machines with no RTC (Raspberry Pi) or a dead battery.


Can you elaborate further?


The complaint is here: https://www.courtlistener.com/docket/6359557/united-states-v...

Pages 3-6 detail the VM. Basically, they found a VM on his computer that was encrypted, with an encrypted file in it, that they unlocked with a password they found on his phone. In the encrypted (truecrypt) file, they found a large amount of what was unmistakenly CP. When they examined the file system, their claim is that there was evidence of a history of using that VM and moving those files around, etc., so it's not like they just appeared one day. Partial files that weren't deleted yet, caches, inode meta data, that sort of thing.

I mean, it's possible to fake, but it would be incredibly easy to fuck that up, and incredibly risky to get caught doing that. If they really wanted to make his life hell, there are easier, less risky, and even legal ways to do it without going to the effort to fabricate 8 years of computer usage that would withstand expert cross examination.


>I mean, it's possible to fake, but it would be incredibly easy to fuck that up, and incredibly risky to get caught doing that.

Maybe, but how hard would it be to convince a tech-illiterate jury of that? Is there a lawyer on earth that could explain the minutiae of metadata on virtual machines to one? And if they get caught, they go "oops!" and pay out a few million dollars as a sorry, at best.


I'd wager they couldn't. It's not likely they themselves would have those kids either. It would be the FBI prosecuting child pornography and being knowledgeable about it (with even more knowledge on how to lose a CP prosecution) and the NSA that would be hoarding those logs.

Of course, nothing says they wouldn't be cooperating in this.


Maybe I'm missing something here, but ISTM the question isn't really whether the logs are of a genuine conversation about CP, but rather whether the accused really was a part of that conversation? After all, if he really took part in a conversation about procuring such material, it wouldn't have mattered if he talked like a newb. Likewise, if he wasn't in on it, it doesn't matter that everyone who was in on it got "the lingo" right.

ps. How would one know enough about the scene to motivate such skepticism?


Send an undercover agent to immerse himself in the community, learn the lingo, etc, and use opsec to protect him from detection by external authorities (the same authorities that failed to bus everyone else in the community already). Then when you want to disappear someone, create some links between the real person and the online persona created by the undercover agent.


Read the transcript and decide for yourself, I'm referring strictly to how I've seen people speak on IRC. Warning, there is disturbing text in there.

https://dd80b675424c132b90b3-e48385e382d2e5d17821a5e1d8e4c86...


I’ve been on IRC for decades, a few years running a file distribution for audiobooks, which sadly meant I ran across some things I’ll never unsee. I’ve never seen anyone actually say “kiddie porn” who was actually looking for or offering it. It’s all “loli” or filename references, and “#yo” stuff. Those chat logs sound ridiculous, but I have to admit that my experience is limited to channels where cp wasn’t welcome. Maybe when they’re on their own they start talking like a special agent?

To me, it would be like being in a warez channel full of people saying, “I want pirated material.” That at least I have experience with, and someone saying “Where the copyright violations at?” Rather than “any good ftp’s and xdcc’s?” Would raises red flags.


Wow you really misrepresented those chat logs. The personas portrayed within appear to be interested in the concept of CP, seemingly mostly for its forbidden nature. Whenever they discuss an individual file, there are questions about whether the participants are 15yo or older, or whether the file is "really porn". If these are really the deepest depths plumbed by that "scene", the whole thing has been wildly misrepresented.


Honestly? If we can generate a video of Barack Obama saying that "Killmonger was right" and render existing paintings in the style of other paintings, then we can absolutely generate culturally-sound text.


Excellent point.


> I read the IRC logs

Oh really, and did you ask how it is that IRC logs from 2009 just happened to be sitting in someone's back pocket?

It is actually quite obvious from the conversation that "STURM" is a CI or other operative who is trying to entrap "JOSH".

If this guy was breaking the law back in 2009 why did the CIA hire him exactly?

Maybe we should be investigating how law enforcement and intel agencies use child exploitation and child pornography to entrap people, and how many of the people involved in those ops have "inclinations" that trend in that direction.

Then we might find some real criminals.


Completely agree. To me it seems unlikely that people working for the cia are pedos. It is possible but goes counter to all demographic studies on the characteristics of pedos. Most pedos are low income, uneducated social misfit types. The educated people who do it are mostly the outliers in the demographic studies.

Meanwhile all of these leakers having some sort of cp charge is a significant enough to look deeper into what is going on.


The IRC logs in the papers linked in this thread make the suspect out to be an imbecile -- discussing highly illegal activity in plain text using the most obvious keywords ...?


Not to mention... searching... Google?

Really.

Does that sound like something anyone would ever expect to return fruitful results enabling criminal activity? Does anyone imagine this being the sort of thing a person operating an encrypted server would do either deliberately or inadvertently? And what would it even mean, to have that in Google search logs?

Here on HN, to most of us, figure it means less than nothing. On some level, it might actually harm the authenticity of the prosecution's technical credibility.

I'd imagine the goal of the prosecutors though, is to select the most technically inept grandmas, to pack the jury with.


So you're saying you're "deeply versed in the lingo, tone, and character of that scene"?

Reminds me of: https://www.youtube.com/watch?v=SYkbqzWVHZI


The feds are notorious for doing stuff like that. Just look at how they were trying to bag assange with rape charges back when he was on the run. Also look at how they prosecute bigger criminals. They dont go after them for smuggling or drug dealing. It is always tax fraud, wire fraud etc. They dont care what crime you committed as long as they get the person behind bars.


>Just look at how they were trying to bag assange with rape charges back when he was on the run.

Those charges were Swedish.


Look up five eye agreement. Different governments often work with each other to catch people. You help me out and ill help you out type of stuff.


You might be right about some Swedish quid pro quo here, but Sweden is actually not a member of Five Eyes.


I think FVEY was used as an example of collaboration, not because the poster thought Sweden was part of it.


Exactly, it was an example. The point is governments often work with each other.


Sweden is a member of the Fourteen Eyes, not Five Eyes.


Sweden is also a member of One Hundred Ninety-Three Eyes and One Hundred Ninety-Five Eyes.


[flagged]


It’s an indictment, aka one side of the story presented in the best possible light. Of course it’s convincing. That doesn’t mean it isn’t completely accurate, but judging guilt or innocence based on limited information provided from one party is nuts.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: