<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: Fake aXXo Torrents Bombard BitTorrent</title>
	<atom:link href="http://torrentfreak.com/fake-axxo-torrents-bombard-bittorrent-090313/feed/" rel="self" type="application/rss+xml" />
	<link>http://torrentfreak.com/fake-axxo-torrents-bombard-bittorrent-090313/</link>
	<description>Breaking File-sharing, Copyright and Privacy News</description>
	<lastBuildDate>Tue, 28 Oct 2014 16:30:54 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.9.2</generator>
	<item>
		<title>By: Daily newsfeed 03/19/2009 &#171; baixachiado</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-541483</link>
		<dc:creator><![CDATA[Daily newsfeed 03/19/2009 &#171; baixachiado]]></dc:creator>
		<pubDate>Wed, 18 Mar 2009 20:40:40 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-541483</guid>
		<description><![CDATA[[...] Fake aXXo Torrents Bombard BitTorrent &#124; TorrentFreak [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Fake aXXo Torrents Bombard BitTorrent | TorrentFreak [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Technology Blog: Fake aXXo Torrents Bombard BitTorrent TorrentFreak</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540706</link>
		<dc:creator><![CDATA[The Technology Blog: Fake aXXo Torrents Bombard BitTorrent TorrentFreak]]></dc:creator>
		<pubDate>Sun, 15 Mar 2009 17:33:07 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540706</guid>
		<description><![CDATA[[...] as unscrupulous individuals try to abuse the networks for their own ends.Read the full story here:http://torrentfreak.com/fake-axxo-torrents-bombard-bittorrent-090313/      Posted by Makin   at [...]]]></description>
		<content:encoded><![CDATA[<p>[...] as unscrupulous individuals try to abuse the networks for their own ends.Read the full story here:<a href="http://torrentfreak.com/fake-axxo-torrents-bombard-bittorrent-090313/" rel="nofollow">http://torrentfreak.com/fake-axxo-torrents-bombard-bittorrent-090313/</a>      Posted by Makin   at [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: makin257 - Fake aXXo Torrents Bombard BitTorrent &#124; TorrentFreak</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540705</link>
		<dc:creator><![CDATA[makin257 - Fake aXXo Torrents Bombard BitTorrent &#124; TorrentFreak]]></dc:creator>
		<pubDate>Sun, 15 Mar 2009 17:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540705</guid>
		<description><![CDATA[[...] a growing phenomenon, as unscrupulous individuals try to abuse the networks for their own ends.Link:http://torrentfreak.com/fake-axxo-torrents-bombard-bittorrent-090313/      Leave a comment     Powered by LiveJournal.comAdvertisement  Customize       if (SnapShots) { [...]]]></description>
		<content:encoded><![CDATA[<p>[...] a growing phenomenon, as unscrupulous individuals try to abuse the networks for their own ends.Link:<a href="http://torrentfreak.com/fake-axxo-torrents-bombard-bittorrent-090313/" rel="nofollow">http://torrentfreak.com/fake-axxo-torrents-bombard-bittorrent-090313/</a>      Leave a comment     Powered by LiveJournal.comAdvertisement  Customize       if (SnapShots) { [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540498</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Sat, 14 Mar 2009 16:16:03 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540498</guid>
		<description><![CDATA[#71 : I don&#039;t care about YOUR &quot;opinions&quot;
do us all a favor and STFU with cherries on top

I want to read this topic and I have to go through your idiotic rants.

Just wanted to say I agree with #67.
You can&#039;t get fakes if you DL torrents
from the trusted uploader&#039;s account.
All you need is common sense]]></description>
		<content:encoded><![CDATA[<p>#71 : I don&#8217;t care about YOUR &#8220;opinions&#8221;<br />
do us all a favor and STFU with cherries on top</p>
<p>I want to read this topic and I have to go through your idiotic rants.</p>
<p>Just wanted to say I agree with #67.<br />
You can&#8217;t get fakes if you DL torrents<br />
from the trusted uploader&#8217;s account.<br />
All you need is common sense</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lt200420</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540494</link>
		<dc:creator><![CDATA[lt200420]]></dc:creator>
		<pubDate>Sat, 14 Mar 2009 15:57:40 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540494</guid>
		<description><![CDATA[aXXo rips suck]]></description>
		<content:encoded><![CDATA[<p>aXXo rips suck</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540492</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Sat, 14 Mar 2009 15:41:56 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540492</guid>
		<description><![CDATA[#64: How the hell do you &quot;execute&quot; a guide moron?
All you have to do is read. Can you do that dumbass?

You saw an &quot;invisible&quot; forum?
You&#039;re really stupid and you&#039;re hallucinating now

get well soon LoL]]></description>
		<content:encoded><![CDATA[<p>#64: How the hell do you &#8220;execute&#8221; a guide moron?<br />
All you have to do is read. Can you do that dumbass?</p>
<p>You saw an &#8220;invisible&#8221; forum?<br />
You&#8217;re really stupid and you&#8217;re hallucinating now</p>
<p>get well soon LoL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Virate</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540486</link>
		<dc:creator><![CDATA[Virate]]></dc:creator>
		<pubDate>Sat, 14 Mar 2009 15:15:15 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540486</guid>
		<description><![CDATA[If u can&#039;t spot a fake torrent then you deserve to download absolute sh*te.]]></description>
		<content:encoded><![CDATA[<p>If u can&#8217;t spot a fake torrent then you deserve to download absolute sh*te.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacker/pirates of the world UNITE</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540485</link>
		<dc:creator><![CDATA[Hacker/pirates of the world UNITE]]></dc:creator>
		<pubDate>Sat, 14 Mar 2009 15:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540485</guid>
		<description><![CDATA[-scene
-private trackers
-public trackers
-the banned everywhere

let ssee where they at public.....]]></description>
		<content:encoded><![CDATA[<p>-scene<br />
-private trackers<br />
-public trackers<br />
-the banned everywhere</p>
<p>let ssee where they at public&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540474</link>
		<dc:creator><![CDATA[Jacob]]></dc:creator>
		<pubDate>Sat, 14 Mar 2009 14:39:46 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540474</guid>
		<description><![CDATA[Lol time to sue MPAA and RIAA for spamming, well we just need proof first.]]></description>
		<content:encoded><![CDATA[<p>Lol time to sue MPAA and RIAA for spamming, well we just need proof first.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ahso</title>
		<link>/fake-axxo-torrents-bombard-bittorrent-090313/#comment-540471</link>
		<dc:creator><![CDATA[ahso]]></dc:creator>
		<pubDate>Sat, 14 Mar 2009 14:16:08 +0000</pubDate>
		<guid isPermaLink="false">http://torrentfreak.com/?p=10921#comment-540471</guid>
		<description><![CDATA[@32 &amp; @43 &amp; @48 &amp; @51:

Good discussion. Something definitely needs to be done on the technology side to reduce the number of fake torrents. Your ideas of PGP/GPG signatures sounds like a good start.

@48: You mentioned that a PGP signature wouldn&#039;t really help because fake uploaders could supply their fake aXXo key, for example, and so the fake torrent would falsely validate correctly. 

This is a good point. So what else could we do? Part of the way PGP public keys appear to work is to have a trusted place where people can acquire the public key in the first place for any given individual/uploader. These already exist: they&#039;re called PGP public key servers. 

If these PGP public key servers require too much personal information for registration, we could create anonymous PGP public key servers if the existing PGP public servers don&#039;t provide enough anonymity. Trackers/torrent sites can then check the public key registered with the user name/ID at these (anonymous) PGP public key servers with the public key used to sign the uploaded torrent.

The only new requirement for users wishing to upload torrents then is to register a public key with an (anonymous) public key server.

@48: The point you made about 3.7Gb file being used to generate a signature taking a very long time is another good point, but this can be alleviated by employing your followup statement of using the MD5/SHA1 hash of the content instead. It&#039;s okay if there are collisions, the point being that the likelihood of collisions is extremely small, and almost non-existent if someone is trying to duplicate content (fake) to have exactly the same SHA1 hash.

You said that you could easily make a fake file and give it the same MD5/SHA1 hash as the aXXo release, then paste everything from aXXo&#039;s post (public key, signature etc.) into your fake post. This wouldn&#039;t work if you adopt the strategy I mentioned above coupled to your (good) suggestion of using the MD5/SHA1 hash. For example, you could generate the SHA1 hash for the content. Then generate the signature for the SHA1 hash using your *registered* public key on a PGP public key server. Trackers and torrent sites could simply verify that the SHA1 hash is correct for the content using the uploaders p2p client, and then the torrent could be &quot;signed&quot; by signing the SHA1 hash. So these are the steps in point form:

The uploader performs the following prior to making their torrent content available:

1. Generate a SHA1 hash for the content.
2. Sign the SHA1 hash using their public key available on an (anonymous) PGP public server. This will generated a Signed-SHA1 key.
3. Upload their torrent using their p2p client providing the SHA1, Signed-SHA1, user name/ID.

The tracker/torrent site would then perform the following steps at the beginning of the upload process:

1. Confirm the SHA1 hash for torrent content using the uploaders p2p client.
2. Obtain the public key of the uploader from the (anonymous) PGP public key server using their user name/ID.
3. Confirm that the Signed-SHA1 hash resolves to the original SHA1 hash using the public key to decrypt the Signed-SHA1 hash.

And voila! No more fake torrents from uploaders posing as others.

Now, a fake uploader not using any of the popular names aXXO, KlaXXoN could still upload a fake as a different/new user and have their public key registered on the (anonymous) PGP public key server. In this case, one additional piece of information that the trackers/torrent sites could obtain from the (anonymous) PGP public key servers is the time that the user has been registered with the PGP public key server. The tracker/torrent site could have new registrants tagged as &quot;untrusted&quot;. In fact a new column could appear in every tracker/torrent site listing showing the level of public trust associated with a given uploader. The longer they&#039;ve been registered, coupled to the greater number of non-fake uploads, the greater their trust rating.

Users uploading fakes would have to change their registration and user names frequently and re-register as new users on the PGP public key servers because the trackers/torrent sites would tag them with a very low trust rating given their previous fake uploads.

Thoughts?]]></description>
		<content:encoded><![CDATA[<p>@32 &amp; @43 &amp; @48 &amp; @51:</p>
<p>Good discussion. Something definitely needs to be done on the technology side to reduce the number of fake torrents. Your ideas of PGP/GPG signatures sounds like a good start.</p>
<p>@48: You mentioned that a PGP signature wouldn&#8217;t really help because fake uploaders could supply their fake aXXo key, for example, and so the fake torrent would falsely validate correctly. </p>
<p>This is a good point. So what else could we do? Part of the way PGP public keys appear to work is to have a trusted place where people can acquire the public key in the first place for any given individual/uploader. These already exist: they&#8217;re called PGP public key servers. </p>
<p>If these PGP public key servers require too much personal information for registration, we could create anonymous PGP public key servers if the existing PGP public servers don&#8217;t provide enough anonymity. Trackers/torrent sites can then check the public key registered with the user name/ID at these (anonymous) PGP public key servers with the public key used to sign the uploaded torrent.</p>
<p>The only new requirement for users wishing to upload torrents then is to register a public key with an (anonymous) public key server.</p>
<p>@48: The point you made about 3.7Gb file being used to generate a signature taking a very long time is another good point, but this can be alleviated by employing your followup statement of using the MD5/SHA1 hash of the content instead. It&#8217;s okay if there are collisions, the point being that the likelihood of collisions is extremely small, and almost non-existent if someone is trying to duplicate content (fake) to have exactly the same SHA1 hash.</p>
<p>You said that you could easily make a fake file and give it the same MD5/SHA1 hash as the aXXo release, then paste everything from aXXo&#8217;s post (public key, signature etc.) into your fake post. This wouldn&#8217;t work if you adopt the strategy I mentioned above coupled to your (good) suggestion of using the MD5/SHA1 hash. For example, you could generate the SHA1 hash for the content. Then generate the signature for the SHA1 hash using your *registered* public key on a PGP public key server. Trackers and torrent sites could simply verify that the SHA1 hash is correct for the content using the uploaders p2p client, and then the torrent could be &#8220;signed&#8221; by signing the SHA1 hash. So these are the steps in point form:</p>
<p>The uploader performs the following prior to making their torrent content available:</p>
<p>1. Generate a SHA1 hash for the content.<br />
2. Sign the SHA1 hash using their public key available on an (anonymous) PGP public server. This will generated a Signed-SHA1 key.<br />
3. Upload their torrent using their p2p client providing the SHA1, Signed-SHA1, user name/ID.</p>
<p>The tracker/torrent site would then perform the following steps at the beginning of the upload process:</p>
<p>1. Confirm the SHA1 hash for torrent content using the uploaders p2p client.<br />
2. Obtain the public key of the uploader from the (anonymous) PGP public key server using their user name/ID.<br />
3. Confirm that the Signed-SHA1 hash resolves to the original SHA1 hash using the public key to decrypt the Signed-SHA1 hash.</p>
<p>And voila! No more fake torrents from uploaders posing as others.</p>
<p>Now, a fake uploader not using any of the popular names aXXO, KlaXXoN could still upload a fake as a different/new user and have their public key registered on the (anonymous) PGP public key server. In this case, one additional piece of information that the trackers/torrent sites could obtain from the (anonymous) PGP public key servers is the time that the user has been registered with the PGP public key server. The tracker/torrent site could have new registrants tagged as &#8220;untrusted&#8221;. In fact a new column could appear in every tracker/torrent site listing showing the level of public trust associated with a given uploader. The longer they&#8217;ve been registered, coupled to the greater number of non-fake uploads, the greater their trust rating.</p>
<p>Users uploading fakes would have to change their registration and user names frequently and re-register as new users on the PGP public key servers because the trackers/torrent sites would tag them with a very low trust rating given their previous fake uploads.</p>
<p>Thoughts?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
