TorrentFreak

The place where breaking news, BitTorrent and copyright collide

Are Private BitTorrent Trackers Safe?

There is a statement you’ll often see on p2p forums, and in IRC channels. It usually comes in a discussion about “getting caught” or “letters been sent” and it goes something like “the safest thing is to join a private site. The other oft-proposed solution, blocklists, has been discussed before. Are private sites any safer though?

In preparing this piece, I spoke to several private site admins, and a few public tracker admins as well. The results may surprise you.

There are three main areas of concern, that the server may get seized, or that an anti-p2p agent may infiltrate the site. Seizure is a risk for all torrent trackers, or indeed all servers period, as both pirateBay, and indymedia can attest to. This has both good and bad points, in that you get the site shut down quickly, but on the downside, you REALLY have to have your ducks in a row before doing so. Additionally, you may take out the site admins, but you can often create a negative publicity backlash, especially if you take down other people’s servers at the same time. ‘Infiltration’ is a more time consuming method, but can yield better results. This was the method used to mount evidence for the elitetorrent raid (operation d-elite) in May 2005. The third method is describable in many ways, depending on your opinion of the target of it. It can range from “surrendering to extortion” to “getting paid off” but means the server owner has been contacted by one or more groups or agencies, and has agreed to hand everything over voluntarily. There is only one real example of this so far, Lokitorrent.

Seizure

Put simply, this is the method of :

** Going to the hosting company
** Gaining entry (with or without a 100% legal and valid warrant) and
** Physically removing the servers from their racks
** Then taking them into custody

Often, search warrants will also be served on any members of the site also within jurisdiction and considered ‘big enough’. Once they are taken into custody, the hard drives can then be examined and entered into evidence for possible criminal proceedings. How do private sites deal with this?

Well, depending on the site, you might be safe, whereas others you might as well just hand yourself in on others. All that I spoke to stored the total ratio (including upload and download counts) email address, and username/password. Many also save a list of what torrents you’ve uploaded to the tracker, although that list usually only contains active torrents active.

The email address and username/password is a bad thing. It counts as ‘personally identifiable information’, basically meaning you can’t say “it wasn’t me that did it’. Odds are you probably have an email from the torrent site in your email account with your username and password. If the password matches any other password you use, or if your computer shows records of having accessed that email account, that’s a link made to you that will be very hard for you to explain away.

Of course, such seizures are rare, and to date there has been no activity against individual users of the sites, but it must be pointed out that of the two public tracker admins I contacted, (Anakata of the pirateBay, and the one of the tracker suppliers to EZTV and VTV’s) both said that their trackers did not save any user data at all, it was all in volatile ram, meaning when they’re pulled, or even when the power goes out, the data is gone. Only the most secure of the sites I spoke to (scenetorrents) offered this for its uploaders and staff)

Infiltration

This is more the sort of thing that copyright enforcement groups are generally better at. It takes a lot of time, and manpower, which they have, unlike the understaffed and overworked criminal investigators the world over . Not to say that such departments are not capable, there really are more important ACTUAL crimes, that affect everyday people in a major way that they should be dealing with instead. At its most basic, its someone, joining a site, and collecting info. Depending on the sites membership policies, and its popularity, this can be very easy, it can be hard. Quite a few are now invite-only, so first you have to find someone with an invite, and acquire one somehow. Methods for this alone have a huge range, from “hey any1 got an invite to xyz’ on a forum [image], to building up a relationship and bona fides on an IRC network such as p2p-net, or EFnet. Others, such as the British TV+radio site UKnova are so popular that when an inactive account is purged, the empty membership can be snapped up within 5 minutes.

So, is there anything stopping these people joining? Well, in a word, no. It’s unlikely a member of the BSA will try and register for a site from his office computer, for instance, but there is nothing stopping someone from doing so. One site however (Bitsoup) did give a sign up warning [image], albeit an old favourite making a comeback. Once someone is on, they then have the job of collecting IP addresses from the tracker. In this regard, private trackers are inherently much less secure. On most private sites, all users can view all the usernames of peers also on the torrent with them, and sometimes their upload and download averages.

If they were to compile lists of users on a torrent with the IPs on the torrent, it might be hard to match them, but do it over a few dozen torrents, and they’ll start seeing the same IP ranges appearing only when a certain username is on it , they’ve now identified the IP address of that user. It is impossible to do this with a public tracker, as put simply, there is no username telling anyone when a certain person is on a torrent. Add in DHT, and that people tend not to have any loyalty to a certain tracker, mean its impossible to build this sort of complete peer overview without private sites.

So, copyright enforcers may be members of your favourite private tracker, do the sites do anything about it? Again, in a word, yes. None of the sites would go into detail with me how to monitor for such users (and I doubt I’d understand them if they did , software guys have a tendency to revert to their own private language when asked a technical question) but I was told by all of them that they employed a mixture of automated, and user-based methods to detect and report suspicious activity. Basically everything from a user reporting a peer acting suspiciously on up.

Conclusion

Whilst private sites can prevent you from getting the letters and emails from your ISP or enforcement agency, They are not a perfect solution. Dealing with these sites takes time and effort, a lot of it, and that’s more than many rights holders care to do right now. It is relatively easy to go to somewhere like mininova, and find a torrent for your property, then grab the IPs and send an email to the corresponding ISPs, it’s much more involved to do the same with private sites. In that aspect, private sites are safer. Until the majority (or at least a large percentage) of material on a private site belongs to one rights holder, that holder is unlikely to target that site. There are exceptions, of course, depending on the material in question , the elitetorrents bust over Star Wars Ep3 showed that.

In the long term however, when and if the procedure for prosecuting file sharers through civil court becomes easier, such sites will be far more hazardous to use. The very practice of restricting usage to certain identified members is its achillies heel. Using a groups own membership and activity records against itself has been a prosecution tactic for many decades. Seizures happen, infiltrations have gone on for a while now, and some might say it’s only a matter of time.

In their favour, private sites have generally much faster speeds than public torrents, meaning your window of exposure for downloading is shorter. However due to the more limited availability of the torrent, and the greater importance on ratio, you can have a vastly greater upload window, and it’s uploads that are usually targeted. They also generally have content policies, meaning fakes, malware and misnamed torrents are kept to a minimum.

Overall, in some ways they’re safer, in just as many ways they’re a liability. To put it another way, you’re safer from the more common small-time infringement notification, but a much easier target for the (much rarer) big-time operations.

With thanks to the following people:

  • Feeling of SceneTorrents
  • Dragonheart, at Bitsoup
  • [pm] at Uknova
  • Anakata at the PirateBay
  • a staff member at Tvjunkies
  • and the admin for some of vtv and eztv’s trackers
  • Related Posts

    Previous Post | Next Post

    • Ric

      Great article. I’ve stopped using public trackers completely now, but rarely use private trackers too. If so, it’s for something rather unique I can’t get somewhere else.

      It’s amazing how easy it is to get invites nowadays. A music forum I visit has a thread offering invite trades, and the forum has nothing to do with torrents to begin with! OiNK invites are the new Gmail invites it seems, and the more members these sites get, the less secure they stay.

      Anyway, thanks for the read. I only noticed this site yesterday and just came back out of curiosity. Will probably subscribe to your RSS now after this.

    • Navitron

      I do my File downloading in this order…
      Newsgroups -> IRC and Forums (via Rapidshare, Megaupload ect) -> Private Trackers -> Public Trackers -> ed2k

    • TJ

      what happened to to RSS feed? It now only shows an intro to the article..Im using google reader, is there anyway to get the full article as rss?

    • marcel weiss

      yeah, partialfeeds suck

    • Tom

      Agreed, bring back the full feeds!

    • Brian

      Nice one, I use mainly public trackers , but this is for casual downloading and gets deleted nearly as fast as it reaches the desktop.

      Not only that but in terms of Movies and TV shows, streaming is slowly become the way to go I think. Especially with the hoard of youtube type of sites springing up all over the place.

    • mcangeli

      I tend to only use BT these days for downloading open source software such as Linux Distributions ( http://linuxtracker.org is a public tracker for this).

      Not saying, I’ve stopped downloading other stuff via BT, I’m just being more selective in what I download….

    • blahblah

      Interesting that Feeling, the admin for Scenetorrents would provide feedback on this document. He is the admin of a site that recently introduced and advertised a Pay2Leech capability on ScT.

    • spammo

      i say download whatever u want how u want. if u get caught FUCKIT if u dont LOVE It

    • Zingo

      I get amused when I see Pixar probing my PC. Hey Pixar: Toy Story was cool but everything else you’ve produced has been crap. And Disney? BAHAHAHAHHA!

      Isn’t breaking into my computer without my consent a violation of anti-hacking laws? Ok I see. You guys can do what you want because you have corrupt congressmen in your pocket, and you steal from the people who make your films. You know the guy who wrote “Gump” didn’t earn a cent from the movie? Look up “Hollywood Accounting” on Google.

    • Yatti

      PeerGuardian2!! Helps in security in my opinion..

    • Trevor

      Nothing is ever safe.

      http://www.myiproxy.com

    • deadredeyes

      “There are three main areas of concern, that the server may get seized, or that an anti-p2p agent may infiltrate the site. ”

      Ummm, what’s the 3rd one?

    • Pingback: wareznews.net » Tracker De BitTorrent Privados Seguros?

    • longer attention span

      #13 read further in the text to find the 3rd

      “The third method is describable in many ways, depending on[...]“

    • Pingback: Are Private BitTorrent Trackers Safe? at a g33k’s blog

    • Pingback: Piracy investigators infiltrate private Torrent sites at The p2p Blog

    • Kupo

      [quote comment="74175"]Interesting that Feeling, the admin for Scenetorrents would provide feedback on this document. He is the admin of a site that recently introduced and advertised a Pay2Leech capability on ScT.[/quote]

      You know how much it costs to run servers for a private bt site? A lot if you want it to run well. Also Sct takes donations, and offers incentive in the form of some credit, that’s not exactly pay to leech, hit and running is still bannable.

      Check just about any private site they definitely exist because of donations, or do you want to run a site with thousands of member traffic and pay for it all yourself?

    • ANTi-P2P

      Just a FYi Feeling was a mod at EliteTorrents :p

    • ro643ck

      m657k

    • Pingback: Blog of Blogs » Blog Archive » 10 Private BitTorrent Trackers Open for Signup

    • Pingback: Why Are The IFPI and BPI Allowed To Hijack OiNK? | TorrentFreak

    • n3ur0

      didn’t Clinton pass a law in ’95 disallowing law enforcement agencies and copyright holders from entering such sites? just a thought.

    • Devl

      Must’ve been Al Gore. He invented the Internet, after all.

    • Tweek

      [quote comment="103154"][quote comment="74175"]Interesting that Feeling, the admin for Scenetorrents would provide feedback on this document. He is the admin of a site that recently introduced and advertised a Pay2Leech capability on ScT.[/quote]

      You know how much it costs to run servers for a private bt site? A lot if you want it to run well. Also Sct takes donations, and offers incentive in the form of some credit, that’s not exactly pay to leech, hit and running is still bannable.

      Check just about any private site they definitely exist because of donations, or do you want to run a site with thousands of member traffic and pay for it all yourself?[/quote]

      Very VERRRY low cost. a hundred or so a month. Bandwidth is cheap, servers are cheap. Dont kid yourself.

    • Pingback: Techo Zed Meuw » Are Private BitTorrent Trackers Safe?

    • Pingback: Hey is there THAT much of a risk using sites like STmusic? - Page 2 - P2P Talk!

    • BTGuard - BitTorrent Anonymously

    NewsBits

    Even more news...

    • The Pirate Bay Isn’t Down Completely, Just Having a Few Issues

      Twitter and Facebook, not to mention the TorrentFreak inbox, are currently alive with complaints that The...

    • Pirate Bay Founder Gottfrid Svartholm on Freedom of Speech

      Freedom of speech is a highly valued commodity, but should people be allowed to say whatever...

    • Blu-ray Anti-Piracy Tech Stops Discs and Promotes Purchases

      An anti-piracy system present in all official Blu-ray players since 2012 has received a fresh update...

    • Foxtel Breeds Pirates by Locking Up Game of Thrones

      One of the main reasons why people turn to piracy is the lack of legal alternatives....

    • UK Student Admits Breaching Sony Copyrights With Leak of PS3 SDK

      Last year an Internet user known as El Nomeo leaked version 3.70 of Sony’s Playstation3 SDK...

    MostDiscussed

    Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

    CopyQuote

    Left Quote

    “The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

    Peter Sunde Left Quote

    PopularArticles

    A selection of some TorrentFreak's classics dug up from our archives.