Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The IRC logs are minor pieces of evidence. It’s the VM that is hard to explain away.


There is nothing about the use of a VM that is "hard to explain away." You know what a VM is, right? You know anyone could plant things on a VM just like any other computer, right? You know there are many ways someone like the CIA could obtain a password used to encrypt a VM, right? Perhaps it was not always encrypted? Perhaps his host machine was infected with a key logger? Perhaps they used an exploit in the software he used to encrypt the VM, or a proprietary exploit designed to do exactly this, produced in conjunction with any number of software companies. There are many, many ways this could have happened, and the existence of a VM means literally nothing.

Why are you convinced the presence of a VM in this is significant?


My other comment is below. Have you read the complaint? The government is claiming that there is essentially 8 years of evidence on that VM, that in addition to the actual CP, there is a long trail of metadata and inode data that would be fairly difficult to fake.

I mean, think about it: if you were the defendant, all you'd have to do is have someone examine it and find inode activity when you had a clear alibi that the government didn't know about (which would be easy, given we're talking 8 years here, he'd just have to find when he was on a date or out to dinner or something, the government isn't going to know his entire life history for 8 years), and you'd be well on your way to creating enough doubt with a jury.

Now, it's possible the government is lying, but if they're not, it strains credulity to think that they'd go to the effort, cost, and risk to fake that VM in such elaborate detail. If they wanted to ruin his life, there are hundreds of easier ways to do it than such an elaborate fraud.


You didn't answer my question. There is nothing about the existence of a VM that makes it "difficult to explain away" and you did not establish why the fact that there is a VM being used is relevant.

What you are now saying is that it's implausible that the CIA would be able to fake logs (and that's what we're talking about with inode data) on a VM for some reason. It would absolutely not be as simple as "have someone examine it and find inode activity when you had a clear alibi" because it is very likely the guy was actually using a VM legitimately. All the CIA has to do is establish that he was in possession of child pornography. Hell, they don't even need to prove it beyond a reasonable doubt if A) the jury, defense, prosecution and / or judge is not tech savvy to understand some of these concepts, and B) if their goal is to trash this guy's life and have it be a warning to other leakers. You don't even need a conviction for that.

It does not strain credulity at all to think that the CIA would go to the effort to fake a small set of data on a VM. The "elaborate detail" is not any more elaborate than in any other instance -- it would be trivially easy to forge. If they wanted to ruin his life, this is a perfect, practical way for them to do it.

The fact that they would forge this data on a VM makes it seem even more plausible to people who don't even understand what VMs are, or how one might fabricate logs like that. It's apparently working on you right now, and you're savvy enough to know about the existence of inode data. You're apparently ready to condemn this guy despite the ludicrous amount of circumstantial evidence that maybe this guy is being set up by an organization literally dedicated to covert operations of this nature, who have even go so far as to detail exactly how they would undertake this exact kind of operation.


> all you'd have to do is have someone examine it and find inode activity when you had a clear alibi that the government didn't know about (which would be easy, given we're talking 8 years here, he'd just have to find when he was on a date or out to dinner or something, the government isn't going to know his entire life history for 8 years), and you'd be well on your way to creating enough doubt with a jury.

There are plenty of ways that happens even accidentally though, a prosecutor would be able to knock out that claim easily.

You've never seen a Linux machine write entries to the system log with the wrong timestamp? It happens all the time on machines with no RTC (Raspberry Pi) or a dead battery.


Can you elaborate further?


The complaint is here: https://www.courtlistener.com/docket/6359557/united-states-v...

Pages 3-6 detail the VM. Basically, they found a VM on his computer that was encrypted, with an encrypted file in it, that they unlocked with a password they found on his phone. In the encrypted (truecrypt) file, they found a large amount of what was unmistakenly CP. When they examined the file system, their claim is that there was evidence of a history of using that VM and moving those files around, etc., so it's not like they just appeared one day. Partial files that weren't deleted yet, caches, inode meta data, that sort of thing.

I mean, it's possible to fake, but it would be incredibly easy to fuck that up, and incredibly risky to get caught doing that. If they really wanted to make his life hell, there are easier, less risky, and even legal ways to do it without going to the effort to fabricate 8 years of computer usage that would withstand expert cross examination.


>I mean, it's possible to fake, but it would be incredibly easy to fuck that up, and incredibly risky to get caught doing that.

Maybe, but how hard would it be to convince a tech-illiterate jury of that? Is there a lawyer on earth that could explain the minutiae of metadata on virtual machines to one? And if they get caught, they go "oops!" and pay out a few million dollars as a sorry, at best.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: