Jump to content

Police Seized a Torrent Proxy & 33K Users Kept Accessing it


NelsonG

Recommended Posts

In July 2013 a new anti-censorship service [url="https://torrentfreak.com/unblock-torrent-sites-blocked-proxies-camerons-porn-filter-with-immunicity-130728/"]arrived on the scene[/url]. Targeted at users who found VPNs too expensive and Tor too slow, Immunicity provided free access to a wide range of blocked websites.

A year later and with support from Hollywood, City of London Police [url="https://torrentfreak.com/uk-police-takes-down-proxy-service-over-piracy-concerns-140806/"]arrested Immunicity’s then 20-year-old operator[/url]. He’s still on police bail facing an uncertain future.

For many months the Immunicity website remained online but with a very much changed appearance. Gone was the advice on how to unblock sites such as The Pirate Bay to be replaced by a City of London Police banner explaining that the site was under criminal investigation.

Police previously [url="https://torrentfreak.com/police-let-seized-pirate-domains-expire-some-up-for-sale-150704/"]admitted[/url] that they’d been logging traffic to that site (and many other seized sites for that matter) but recent developments indicate that they could’ve had access to more than straightforward visits to the Immunicity website. Here’s how.

Central to the Immunicity system was providing its users with access to a Proxy Auto-Config ([url="https://en.wikipedia.org/wiki/Proxy_auto-config"]PAC[/url]) file. Browsers are easily configured to use PAC files and in just a couple of minutes Immunicity users were able to download a custom PAC and begin opening blocked sites via the Immunicity.org domain.

However, police took effective control of that domain when they arrested its owner last year and while former users might have been disappointed that the service no longer worked as advertised, thousands left their browsers configured to continue using it. How do we know that? Well, the UK Police Intellectual Property Crime Unit no longer has control of the domain.

At the end of August activists from [url="https://brasshorncommunications.uk/"]Brass Horn Communications[/url], a non-profit entity which operates Tor exits and other anti-censorship systems such as [url="http://PacketFlagon.is"]Packetflagon[/url], managed to obtain the Immunicity domain. Until three days ago it displayed a modified version of the famous police seizure notice.

[img]http://torrentfreak.com/images/pipcu-immunicity.png[/img]

Speaking with TorrentFreak the operator of Brass Horn Communications says that since taking over the Immunicity domain it has become apparent that tens of thousands of former Immunicity users failed to remove the service’s PAC file from their browsers. This means that even after the police took control of Immunicity.org they continued to direct their traffic to the seized domain.

“More than a year [after the police raid] there were over 33k unique addresses still surrendering control of their operating systems / browsers (plus Steam, OS updates, [url="https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol"]OCSP[/url] / [url="https://en.wikipedia.org/wiki/Revocation_list"]CRL requests[/url] etc) over to the Immunicity Proxy Auto-Config file,” he reveals.

“The Police (or another malicious actor had they acquired the domain) could have done a lot of damage.”

We asked Brass Horn’s spokesperson about the best and worst case scenarios for the users whose browsers continued to access the Immunicity PAC file. The best case is that nothing happened, the worst is more complicated.

“We know that the Police were [url="https://twitter.com/The_IPO/status/649894131716648960"]monitoring the access logs[/url] of the seized domains so in theory they could simply have monitored everyone who requested the PAC file and recorded that,” he explains.

“But they could have also published a PAC file that sent *all* traffic through a proxy under their control and gathered metadata. They would have been able to alter HTTP content in flight and monitor which IPs were going to which websites, even if they were over SSL. Granted they couldn’t see which URL was being visited but that’s besides the point.”

Brass Horn’s operator says people should be aware that while routing their traffic through third parties has the ability to decrease censorship efforts, there are always security considerations to keep in mind.

“People need to be aware of the risks of PAC proxies, VPNs etc (e.g. all their traffic is at the whim of the VPN / Proxy operator). With that said, Brass Horn Communications won’t surrender any domains and will be publishing DNSSEC records, [url="https://en.wikipedia.org/wiki/List_of_DNS_record_types#TLSA"]TLSA DNS[/url] records and long lived [url="https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security"]HSTS headers[/url] to hopefully break any seizures from having an effect.”

For now, however, Immunicity is in safe hands. Nevertheless, its new operator is advising former users to immediately delve into their browser settings to disable access to the old PAC file.

Full instructions on how to create and install a new PAC file are provided at [url="https://immunicity.org/"]Immunicity.org[/url], which is now a fully operational [url="https://torrentfreak.com/takedown-resistant-hydra-proxy-launches-to-beat-censorship-150822/"]PacketFlagon site-unblocking shard[/url].

Source: [url="https://torrentfreak.com"]TorrentFreak[/url], for the latest info on copyright, file-sharing, [url="http://torrentfreak.com/top-popular-torrent-sites-2015-150104/"]torrent sites[/url] and [url="http://torrentfreak.com/anonymous-vpn-service-provider-review-2015-150228/"]ANONYMOUS VPN services[/url].

[url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=K6zvUHyP8q0:qbNPl2TX-X4:yIl2AUoC8zA"][img]http://feeds.feedburner.com/~ff/Torrentfreak?d=yIl2AUoC8zA[/img]</img>[/url] [url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=K6zvUHyP8q0:qbNPl2TX-X4:D7DqB2pKExk"][img]http://feeds.feedburner.com/~ff/Torrentfreak?i=K6zvUHyP8q0:qbNPl2TX-X4:D7DqB2pKExk[/img]</img>[/url][img]http://feeds.feedburner.com/~r/Torrentfreak/~4/K6zvUHyP8q0[/img]

[url=http://feed.torrentfreak.com/~r/Torrentfreak/~3/K6zvUHyP8q0/]View the full article[/url]

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...