March 26, 2012

SurvivalBlog.com is one of the most widely visited sites devoted to preparing for an economic crisis.

Recently, the editor of SurvivcalBlog posted this message.

It has come to my attention that from August of 2011 to November of 2011, the FBI secretly redirected the web traffic of more than 10% of SurvivalBlog’s US visitors through CJIS, their sprawling data center situated on 900 acres, 10 miles from Clarksburg, West Virginia. There, the Feebees surreptitiously collected the IP addresses of my site visitors. In all, 4,906 of 35,494 selected connections ended up going to or through the FBI servers. (Note that this happened several months before we moved our primary server to Sweden.) Furthermore, we discovered that the FBI attached a long-lived cookie that allowed them to track the sites that readers subsequently visited. I suspect that the FBI has done the same to hundreds of other web sites. I find this situation totally abhorrent, and contrary to the letter of 4th Amendment as well as the intent of our Founding Fathers.

I recognize that I am making this announcement at the risk of losing some readers. So be it. But I felt compelled to tell my readers immediately, because it was the honorable and forthright course of action.

Working on my behalf, some volunteer web forensics experts dissected some cached version histories. (Just about everything is available on the Internet, and the footprints and cookie crumb trails that you leave are essentially there for a lifetime.) The volunteers found that the bulk of the FBI redirects were selected because of a reader’s association with “Intellectual Property” infringing sites like the now defunct Megaupload.  But once redirected, you were assigned a cookie.  However, some of these were direct connections to the SurvivalBlog site (around 4% of the total.) So if they had kept this practice up long enough and if you visited us enough times then the FBI’s computers would have given you a cookie. This has been verified with sniffer software.

He went on to recommend that users install VPN software on their computers. This allows anonymous surfing. If you want more information, click the link.

thoughts on "FBI Tracked SurvivalBlog Visitors

  31. I have to say that this report is lacking in an understand of how cookies work. Even with the lack of details, there are significant errors in the findings of the person making the investigation that would lead me to believe that the person just doesn't understand what happened and is being driven by paranoia.

    1) Cached versions of histories do not contain cookies or headers.
    2) Cookies aren't on your computer for a lifetime.
    3) Cookies can not cross through multiple domain names. Therefore, if the FBI was going to use cookies to track visitors of one site, they would not use what the author describes here as a man-in-the-middle attack. The FBI has no need of hijacking the server or domain name of the site it wants to track. They would do it the way ad networks do.

    Ad networks, such as google, tracks users across multiple sites, but they do it by embedding resources from a unified domain (their own). You as the owner of the site agree to place a snippet of code on your site that makes reference to theirs, usually for the purpose of embedding ads from their network onto your site. The browser of a visitor to your site requests the ad from the ad-network servers, and the ad-network servers send a header requesting your browser to store a cookie on your computer. The cookie stored isn't categorized under your domain, it's categorized under the ad networks domain. Your web browser will deny access to any other domain (besides the ad network) when requesting the contents of the cookie.

    If I worked for a federal organization that wanted to track visitors to your website, it would be very easy to do and it would not take place as described here. In fact, you wouldn't even know about it and it wouldn't even make a difference if it were hosted in sweden, canada or the US.

  Last night on "Harry's Law" TV program they showed a very real example of where our Police Dept's. are going with this spy crap. They sent a drone to spy on a young woman through her bedroom window. She was checking out the opportunity of doing a nude video for some extra money. She never actually submitted the video, but the info leaked out and she lost her job as a school teacher. It's time we pay more attention to our private moments. It's very possible we are being watched. Close your damned drapes!

