▲ 308 ▼ Reddit: IP Address Disclosure Puts User Anonymity At Risk * TorrentFreak (torrentfreak.com) submitted 2 years ago by TheOneWithTheHair@lemmy.world to c/technology@lemmy.world 40 comments fedilink hide all child comments
[+] MagneticFusion@lemm.ee 9 points 2 years ago (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] bamboo@lemmy.blahaj.zone 40 points 2 years ago (4 children) IANAL but withholding evidence from a court order can hold you in contempt of court. I remember hearing a story of a person who was accused of having CSAM on an encrypted hard drive, and refused to decrypt it, and is in jail until he decrypts it. Just because you're a person doesn't mean you can ignore a warrant. permalink fedilink source parent hideshow 8 child comments replies: [–] originalucifer@moist.catsweat.com 46 points 2 years ago (2 children) information itself is a liability. best to have a policy of 'we keep no IPs in logs, so are happy to hand over whatever'.. dump data the moment you dont require it permalink fedilink source parent hideshow 4 child comments replies: [–] Tangent5280@lemmy.world 29 points 2 years ago yeah, this sounds like a much more sustainable solution. Do it the way signal does it. Collect as little as necessary, and delete it as soon as you dont need it. permalink fedilink source parent [–] cmnybo@discuss.tchncs.de 9 points 2 years ago (1 child) Just store what logs you need on a ram drive. The logs will be gone the instant the server shuts down and there is no way to recover them. permalink fedilink source parent hideshow 2 child comments replies: [–] nevemsenki@lemmy.world 8 points 2 years ago (1 child) Downsides include : if any intrusion happens on the server, red team just needs to reboot it to wipe evidence. permalink fedilink source parent hideshow 2 child comments replies: [–] Perhyte@lemmy.world 5 points 2 years ago* If they have the root access typically needed to reboot a server^1^ they could also just wipe the logs without rebooting. ^1^: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers. permalink fedilink source parent [–] Davel23@kbin.social 7 points 2 years ago I looked into that guy somewhat recently, he was in jail for something like five years then eventually released. Kind of a sickening situation all around. permalink fedilink source parent [+] MagneticFusion@lemm.ee 4 points 2 years ago [deleted] permalink fedilink source parent [–] Rai@lemmy.dbzer0.com 3 points 2 years ago Imagine contempt of court but you don’t live in the US permalink fedilink source parent [–] esserstein@sopuli.xyz 1 point 2 years ago (1 child) With the federation does that also mean that the ip records are replicated? Because that would be a lot of parties that can be threatened, with only one required to give in... permalink fedilink source parent hideshow 2 child comments replies: [–] sir_reginald@lemmy.world 2 points 2 years ago I could be wrong, but I believe you only disclose your IP to your Lemmy instance. permalink fedilink source parent
[–] bamboo@lemmy.blahaj.zone 40 points 2 years ago (4 children) IANAL but withholding evidence from a court order can hold you in contempt of court. I remember hearing a story of a person who was accused of having CSAM on an encrypted hard drive, and refused to decrypt it, and is in jail until he decrypts it. Just because you're a person doesn't mean you can ignore a warrant. permalink fedilink source parent hideshow 8 child comments replies: [–] originalucifer@moist.catsweat.com 46 points 2 years ago (2 children) information itself is a liability. best to have a policy of 'we keep no IPs in logs, so are happy to hand over whatever'.. dump data the moment you dont require it permalink fedilink source parent hideshow 4 child comments replies: [–] Tangent5280@lemmy.world 29 points 2 years ago yeah, this sounds like a much more sustainable solution. Do it the way signal does it. Collect as little as necessary, and delete it as soon as you dont need it. permalink fedilink source parent [–] cmnybo@discuss.tchncs.de 9 points 2 years ago (1 child) Just store what logs you need on a ram drive. The logs will be gone the instant the server shuts down and there is no way to recover them. permalink fedilink source parent hideshow 2 child comments replies: [–] nevemsenki@lemmy.world 8 points 2 years ago (1 child) Downsides include : if any intrusion happens on the server, red team just needs to reboot it to wipe evidence. permalink fedilink source parent hideshow 2 child comments replies: [–] Perhyte@lemmy.world 5 points 2 years ago* If they have the root access typically needed to reboot a server^1^ they could also just wipe the logs without rebooting. ^1^: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers. permalink fedilink source parent [–] Davel23@kbin.social 7 points 2 years ago I looked into that guy somewhat recently, he was in jail for something like five years then eventually released. Kind of a sickening situation all around. permalink fedilink source parent [+] MagneticFusion@lemm.ee 4 points 2 years ago [deleted] permalink fedilink source parent [–] Rai@lemmy.dbzer0.com 3 points 2 years ago Imagine contempt of court but you don’t live in the US permalink fedilink source parent
[–] originalucifer@moist.catsweat.com 46 points 2 years ago (2 children) information itself is a liability. best to have a policy of 'we keep no IPs in logs, so are happy to hand over whatever'.. dump data the moment you dont require it permalink fedilink source parent hideshow 4 child comments replies: [–] Tangent5280@lemmy.world 29 points 2 years ago yeah, this sounds like a much more sustainable solution. Do it the way signal does it. Collect as little as necessary, and delete it as soon as you dont need it. permalink fedilink source parent [–] cmnybo@discuss.tchncs.de 9 points 2 years ago (1 child) Just store what logs you need on a ram drive. The logs will be gone the instant the server shuts down and there is no way to recover them. permalink fedilink source parent hideshow 2 child comments replies: [–] nevemsenki@lemmy.world 8 points 2 years ago (1 child) Downsides include : if any intrusion happens on the server, red team just needs to reboot it to wipe evidence. permalink fedilink source parent hideshow 2 child comments replies: [–] Perhyte@lemmy.world 5 points 2 years ago* If they have the root access typically needed to reboot a server^1^ they could also just wipe the logs without rebooting. ^1^: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers. permalink fedilink source parent
[–] Tangent5280@lemmy.world 29 points 2 years ago yeah, this sounds like a much more sustainable solution. Do it the way signal does it. Collect as little as necessary, and delete it as soon as you dont need it. permalink fedilink source parent
[–] cmnybo@discuss.tchncs.de 9 points 2 years ago (1 child) Just store what logs you need on a ram drive. The logs will be gone the instant the server shuts down and there is no way to recover them. permalink fedilink source parent hideshow 2 child comments replies: [–] nevemsenki@lemmy.world 8 points 2 years ago (1 child) Downsides include : if any intrusion happens on the server, red team just needs to reboot it to wipe evidence. permalink fedilink source parent hideshow 2 child comments replies: [–] Perhyte@lemmy.world 5 points 2 years ago* If they have the root access typically needed to reboot a server^1^ they could also just wipe the logs without rebooting. ^1^: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers. permalink fedilink source parent
[–] nevemsenki@lemmy.world 8 points 2 years ago (1 child) Downsides include : if any intrusion happens on the server, red team just needs to reboot it to wipe evidence. permalink fedilink source parent hideshow 2 child comments replies: [–] Perhyte@lemmy.world 5 points 2 years ago* If they have the root access typically needed to reboot a server^1^ they could also just wipe the logs without rebooting. ^1^: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers. permalink fedilink source parent
[–] Perhyte@lemmy.world 5 points 2 years ago* If they have the root access typically needed to reboot a server^1^ they could also just wipe the logs without rebooting. ^1^: GUIs typically have a way to reboot without such privileges, but those are typically not installed on machines just used as servers. permalink fedilink source parent
[–] Davel23@kbin.social 7 points 2 years ago I looked into that guy somewhat recently, he was in jail for something like five years then eventually released. Kind of a sickening situation all around. permalink fedilink source parent
[–] Rai@lemmy.dbzer0.com 3 points 2 years ago Imagine contempt of court but you don’t live in the US permalink fedilink source parent
[–] esserstein@sopuli.xyz 1 point 2 years ago (1 child) With the federation does that also mean that the ip records are replicated? Because that would be a lot of parties that can be threatened, with only one required to give in... permalink fedilink source parent hideshow 2 child comments replies: [–] sir_reginald@lemmy.world 2 points 2 years ago I could be wrong, but I believe you only disclose your IP to your Lemmy instance. permalink fedilink source parent
[–] sir_reginald@lemmy.world 2 points 2 years ago I could be wrong, but I believe you only disclose your IP to your Lemmy instance. permalink fedilink source parent