How a BitTorrent Tracker Owner Hides from the MPAA/RIAA
Written by enigmax on February 06, 2008Apart from The Pirate Bay guys, most tracker administrators are acutely aware of the risks they expose themselves to, and do everything they can to hide in the shadows. We speak to a tracker owner to find out the kind of measures these guys take in order to protect their identities.
In most countries around the world, the legality of running a tracker is still uncertain, in that definitive court decisions have not been made. Even in the US, the last two big trackers to be shut down – LokiTorrent and EliteTorrents – weren’t shut down by a court, but thanks to the mainstream media, public perception is that these sites are operating illegally. The lawyers of the MPAA, RIAA and IFPI maintain they’re illegal so that’s often enough to cost an admin – if his identity is compromised – lots and lots of worry, and probably money too, regardless of his status under the law. It seems that being an admin these days is more about keeping an identity secret rather than acting within the law, as more often than not, old fashioned threats take down torrent sites, not legal action.
TorrentFreak spoke to the admin of a BitTorrent tracker to find out how he stays safe, not sorry.
Introduction
“I’m fairly paranoid and I find that’s a good start point” he told us. “I’m probably overly cautious, but if that’s what it takes for me to sleep right, that’s cool. I’m nothing special and not a huge target but I don’t leave much to chance, even though I don’t have much to worry about compared to the really big boys. I don’t claim to be an expert on security, I’m self taught only, but I’m happy to share my precautions with you (and happy to hear from others on where I need to improve!). I know of admins who run their trackers from their parents residential ISP account with little extra care at all, so any protection is better than nothing!”
Below, our admin gives a breakdown of some of the measures he takes to stay safe. Although an experienced security aware user might spot some holes in this series of measures, it’s interesting to see the lengths to which people will go to protect themselves when seemingly, others take few precautions. This article is entirely consistent with the admin’s message, but at his insistence, it has been re-written by TorrentFreak:
Identity is Everything – If you never tell anyone, no-one will ever know
If the authorities/MPAA/RIAA don’t know who I am or where I live, they can’t threaten me. When I’m working on the site I use either an encrypted connection via an Internet connection available in these premises (my name isn’t on the bill, adding another layer of confusion), or a secure VPN over a local open wireless network. For me, hiding my activities from any ISP accounts even remotely linked to me is important, as I don’t want any ISP to be able corroborate anything specific about what I do. If approached by a 3rd party for information (with a request like “can you confirm that such-and-such connected here at XX:XX time”, for example), they know little or nothing about what I’m doing, throwing any gathered evidence into doubt.
I think the recent OiNK bust was quite a wake up call. I for one was laboring under the misconception that copyright issues are mainly civil and I really only thought through evading civil actions. Once the police get involved, they can find out pretty much anything about you from anyone. Thanks to what we learned about the OiNK bust, my improved security measures should save me from the police too, in the small chance they are interested in a relatively small fish like me.
Registering a Domain
The WHOIS for the site’s main domain is protected, for that added layer of annoyance, although even this isn’t foolproof. Our main domain name isn’t owned by anyone who has anything to do with the site, so it’s pointless threatening that person, even if they find out who it is. It might not stop them making threats so just in case the domain owner complies, other domain names point to our server too and every user is aware of these. None of the domains are owned by me.
Paying for Stuff Online
When we need to pay for something we use disposable credit cards, and the same via PayPal. We also have a few other PayPal accounts scattered around which we run unverified, then dump when PayPal start asking questions. ‘We’ is a term I (we!) get into the habit of using often, it’s less focused than ‘I’.
Using Email
Use a few varied accounts and try not to ‘cross contaminate’ them by doing *any* personal stuff on them at all – site business *ONLY*! If your email address typed into Google returns results other than to do with the site, you are taking risks. Ideally a search would produce nothing at all. In addition, I always hide my IP when I pick up or send email.
Security When Using Other Sites
They’re not, but I act as if all file-sharing forums are insecure. I work on the basis that someone on the staff could be a security risk so I make a policy of never discussing site business on other sites, unless I’m asking general questions. I’d certainly never say “I’m the admin of etc-torrents, hi!” on an open forum and wherever possible I use other aliases.
Find a good host you can trust who doesn’t ask for much verification of identity
Our site has had a few hosts since it began a few short years ago. The first was a friend of a friend of a friend who accepted us with no formal contract or ‘paperwork’, paid from any old PayPal account. For a while we just got users to donate directly to the host which meant I didn’t need to get involved at all. The second and third hosts were people who had established (anonymous) reseller accounts with big ISPs. As long as they got their money, they didn’t ask any awkward questions like: ‘What’s your name and address and credit card number?’ I communicate with any host using disposable email addresses (or something like Hushmail) combined with some sort of anonymizing system previously mentioned. I guess even more precautions could be taken, but time is time and we all have to do some productive work in the end!
Server Location
I would never choose a host in my own country and I’d never put a server in a country where my worst anti-piracy enemy is located, the legal wheels turn too easily. But if the wheels do turn really easily and your host hands over your personal details, you will have been clever enough to make sure that they never had the correct information in the first place. Pay your host on time and be a good customer, you need him onside.
Online Identity
Ok, so I may be a proud super admin (j/k!) but I’m not too keen to spread my nick around carelessly or needlessly. I try to resist the ego trip, even though it can be fun using your ‘power’ to get stuff you wouldn’t normally have access to! Remember, even online nicknames can be a source of identification over time. In my opinion, any admin who features himself on Facebook or MySpace in a way that could be linked back to his torrent activities, really needs a psychiatric evaluation. But I know of a couple who do and so far, they’ve survived. Maybe I’m crazy, and they’re all sane. It’s possible!
Security on the Site, Choosing and Dealing with Staff
Any logging on the server or control panel info excludes staff members details, so a rogue moderator with a grudge can’t get any useful information, should someone try to make it worth their while to provide it. No-one on the site knows anything really useful about me, even within my own team. None of us have ever met in real-life, but I make it my business to learn as much about them as possible, just in case. The very closest people to me on the site know my first name, I guess that’s ok?
Wrong!
I never let anyone know anything important about me, no matter how small. Small clues can easily add up to answers when put together like a jigsaw. Let people think they know your real name if you like, it’s functional and no-one really gets hurt. For the survival of the site I believe it’s acceptable for me to lie about my country of origin, my age, marital status and even my sex, but beware, pretending to be a girl will get you LOTS of attention! Look after the small things and everything else looks after itself.
It’s also a good move to encourage my staff to be security conscious too but I don’t force my regime onto them. I find that when choosing staff it’s best to never let people with inflated egos get close to you - they tend to have big mouths too. They generate tension and trouble and YOU will become a target with their boasting and trigger happy attitude. I like quiet, considered staff because i’m paranoid!.. but this style doesn’t suit everyone.
Try making other forum accounts and act like a normal user on them. You’d be surprised at what people will tell you about your own site that you didn’t already know when they think they aren’t talking to anyone important.
Site Donations
Anonymous PayPal accounts (or in a 3rd party’s name) are completely desirable. Although I suggest a level of transparency in showing users how much money in donations are received, making these records public provides a level of evidence of financial income to the site and you just know that this would be used against you at some point, should the shit hit the fan. If you know and trust your host, why not let users donate directly to him?
Don’t Break the Law!
Running a tracker is a gray area in most country’s laws but I try to stick to some basic guidelines to not show blatant disregard for things that are surely illegal in most places. Under no circumstances would I seed any copyright works on my own tracker. I saw an admin recently who had uploaded 4tb of warez and was showing off his stats for all to see. Why take the risk?
If you get a DMCA type takedown request, take the torrent down! The Pirate Bay guys are going crazy at me now I guess (they’re entitled to hold their own style of course!) but I see no point in doing anything unnecessary to annoy copyright holders, especially us small guys who don’t have many resources.
Do unto others as you’d have done to you!
Try and make good contacts at other torrent sites as they can be a valuable source of information. Try to stay out of conflict with others and be known as a problem solver, not a problem maker. A good reputation is a must to maintain admin karma ;) No-one wants online enemies, especially in huge numbers! People with a grudge and keyboard can really fuck you up. Don’t badmouth people to others unnecessarily – you have no idea who they know, who they might tell and what it could lead to.
A few basic tips to hopefully keep the right side of the law
1. If you can’t be identified, they can’t do anything against you personally.
2. Always respond to proper takedown requests. Be courteous, don’t make enemies.
3. Never seed anything yourself and don’t operate a seedbox. If others operate them on your tracker, that’s up to them.
4. Don’t run any kind of pay-to-download service unless you like police attention.
5. See 1
Final Thoughts About Being Anonymous
Being as anonymous as I can is a must for me and it helps me feel safe. It’s probably already past a healthy stage and it does have drawbacks. A few of my staff I love, I really do, they’re great guys but I can never let them know my true identity, which is sad for me because maybe we could become more to each other than just text on a screen. If I thought even one person knew who I was, my confidence in security would fall dramatically.
Being anonymous can be a quite lonely experience as you struggle to keep the very things that make you an individual, private, while constantly having to view people that probably don’t deserve it, with suspicion. But in the end you gotta keep the torrents going, so it’s all good.
Previously: Pirated by iTunes, Artist Turns to BitTorrent
Next: The Pirate Bay Interrogations



121 Responses
Pages: « 1 [2] 3 4 5 » Show All
whilst i dont go to these lengths, or infact anywhere near them (the most i do is nick my wireless off the neighbour and never seed from home :P) you have to keep some anonymity whilst a site mod/admin/sysop/other…
in my opinion its mainly to protect yourself from disgruntled users though… theres alot of people out there who expect you to bend over backwards just so they can download a torrent… and as has been mentioned earlier… its not like we (in the majority) are being paid, whatever anyone thinks…
all those who wanna give props to someone… give it to the coders.. they’re the one commodity that seems to be in need out there… and without them none of the sites would exist at all
#22 Your ignorance proceeds you..
It is always good to see what others are doing to protect themselves now days. One can NEVER be too cautious.
if they want you, they will get you, no matter what precautions or measures you take.
this is the most impractical and over the top guide that i’ve seen.
it’s site’s and articles like this that bring more attention to the torrenting community, ever more so than those idiots at TPB, who just love seeing their own press.
write something good in the future, and not something that an 11 year old could have worked out in between yu-gi-oh and spying on the neighbours daughter
@ 28..
its sites like this that also increase awareness to regular users that they should be taking some simple precautions to protect themselves in the short term… if someone is trying to bust a downloader and they see 2000 users with no security and 1000 users with simple security… they’ll go down the easiest route..
treat them like eletricity i spose..
if someone can list a few utilities that help in keeping ones ip and id anonymous.. and how to encrypt internet connection for general surfing ??
addition of some more detials like names of softwares etc could help most of us ( n00bies) to keep away from trouble
( remember a lady being fined a HELL LOT for downloadin mp3s ? )
[quote]
No-one wants online enemies, especially in huge numbers! People with a grudge and keyboard can really fuck you up. Don’t badmouth people to others unnecessarily – you have no idea who they know, who they might tell and what it could lead to.[/quote]
My favorite statement in the entire story. Hopefully “SPECIFIC” admins/users of IRC P2P-Network will keep that in mind. As well as the mods at suprnova.org
Thank you.!!
+1
I feel discusted against the record labels and iTunes. It is absolutely morally discusting what they do.
shouldnt that be on the previous article?
his tracker “hosts” no copyrighted works and he responds to dmca takedown requests? does he even get any?
it must be a totally useless tracker..
i agree @ 29
there is simply no way to hide electronically from the government, but bear in mind this quote ‘empty vessels make the most noise’
i agree @ 28
there is simply no way to hide electronically from the government, but bear in mind this quote ‘empty vessels make the most noise’
Good: Be anonymous :)
amazing to do that kinda work..
A few unmentioned items for hosting torrent sites:
1) Don’t use any hosting providers or domain registrars in anti-p2p lands (USA for example)
(It’s too simple to serve a US-based registrar a fake DMCA to reveal real whois info for a domain or have a site taken down.)
2) Distribute the servers to different regions of the world, having the DNS “A” record for the site point to a “dummy” router in one location that reroutes the traffic to your web servers and torrent trackers.
3) Host your servers in lands that entertainment lobbyists (RIAA/MPAA) can’t pressure the United States to use diplomatic pressure against.
4) Use dedicated, non-shared servers that you have total control of.
5) Always have a way out :)
WTF?
“Under no circumstances would I seed any copyright works on my own tracker.”
Then why go to all the trouble? If you’re not allowing any copyrighted works, then this seems like a *long* way to go for no gain of any kind…
[quote comment="283142"]his tracker “hosts” no copyrighted works and he responds to dmca takedown requests? does he even get any?
it must be a totally useless tracker..[/quote]
Re-read what was said: “Under no circumstances would I seed any copyright works on my own tracker.”
He personally, doesn’t see anything on his tracker.
Thought I’d clear that up for you.
Using TOR might help too, especially in connecting to get mail, or using the VPN. It is a simple method.
And beware of hushmail, they’ve opened their supposedly encrypted mail before to the feds.
Didn’t mention full drive encryption, and onion router networks.
I think he means he personally doesn’t seed the copyrighted works..
everybody else on the tracker takes care of that.
^^^^^ You GIMP!! HE means under no circumstances would HE PERSONALLY seed copyrighted works!!
I was really hoping the standard of visitor to this site might have improved by now.
…..nope still full of ignoramus’ & wannabe 1337 4Chan spaks…..
Ernesto attracts the cream of the P2P with these *cough* excellent stories. [Stories as in Jackanory....fairy-tale] This article was re-written at the authors insistence..? pfft yeah right!
@42 - ‘HE’ doesn’t seed copyrighted material - that doesn’t mean others don’t…
something I do when doing some questionable things is to create a vm on my machine with a clean fresh install. Love linux!!! ESP Live CD’s!! then make it either non persistent or whatever depending on the virtualazation software. then fire it up and do my stuff from it. that way any changes or other items that might get written to your computer will be destroyed once the VM is powered down. and there is no way to track it using tracking items of any kind. then I secure wipe the file that was deleted with the deltas so it can’t be used/recovered.
yah, what dimwits bitching about how this torrent site doesnt have copyrighted material…
HE doesnt operate a seedbox, yet he has no problems(is for) uppies to utilize them.
good article, while may not be perfect, very interesting
Pages: « 1 [2] 3 4 5 » Show All
Responses are closed
All remaining responses will continue to be archived. Use the TorrentFreak forums if you want to discuss something.