Live data from Hacker News

Why the Tor attack matters

blog.cryptographyengineering.com

11–20 of 77 posts

Re: Why the Tor attack matters

#11
post #7

What is so surprising here? The DOD is the largest funder of research grants in the US. Pretty much every university is doing research for a US agency from cyber security to lasers for missile defense. I find it very hard to believe that this is the firs time a university was conducting computer security research on live targets.

Whether or not it's surprising is perhaps the least interesting point for discussion. Universities have a responsibility to conduct human research ethically and I hope we hear a lot more about how this research in particular was conducted. This could have endangered lives depending on how it was done, and I'm quite sure the ends don't justify the means unless it was specifically done in a way which protected the anon…

>Universities have a responsibility to conduct human research ethically

which means little given the laws of nature, all that matters is what people end up doing and measuring that statistically. If statistically speaking most people aren't ethical then that's what we'll get. This whole idea that people are in control of their actions or have any freedom whatsoever given what we know about the laws of nature has to go.

Re: Why the Tor attack matters

#12
post #11
post #7

Earlier quoted context omitted.

Whether or not it's surprising is perhaps the least interesting point for discussion. Universities have a responsibility to conduct human research ethically and I hope we hear a lot more about how this research in particular was conducted. This could have endangered lives depending on how it was done, and I'm quite sure the ends don't justify the means unless it was specifically done in a way which protected the anon…

>Universities have a responsibility to conduct human research ethically which means little given the laws of nature, all that matters is what people end up doing and measuring that statistically. If statistically speaking most people aren't ethical then that's what we'll get. This whole idea that people are in control of their actions or have any freedom whatsoever given what we know about the laws of nature has to g…

If people lack free will, then the people judging/punishing them also lack free will, and the entire premise of your arguement is an absurdity.

Re: Why the Tor attack matters

#13
post #7

What is so surprising here? The DOD is the largest funder of research grants in the US. Pretty much every university is doing research for a US agency from cyber security to lasers for missile defense. I find it very hard to believe that this is the firs time a university was conducting computer security research on live targets.

Whether or not it's surprising is perhaps the least interesting point for discussion. Universities have a responsibility to conduct human research ethically and I hope we hear a lot more about how this research in particular was conducted. This could have endangered lives depending on how it was done, and I'm quite sure the ends don't justify the means unless it was specifically done in a way which protected the anon…

Ethics are tricky, especially considering these days one can earn an MSc in Guided Weapon Systems from the top Aerospace Engineering school in the UK.

Re: Why the Tor attack matters

#14
I still remember the researchers working with Facebook on some social science project or the discussion on that guy tweeting about airplane security, so the response from HN on this case baffles me somewhat.

Re: Why the Tor attack matters

#15

What is so surprising here? The DOD is the largest funder of research grants in the US. Pretty much every university is doing research for a US agency from cyber security to lasers for missile defense. I find it very hard to believe that this is the firs time a university was conducting computer security research on live targets.

The DOD funds lasers, but it doesn't then has researchers fire them at random cars to test their effectiveness.

I'm not actually sure this isn't sarcasm.

Re: Why the Tor attack matters

#16

I think we have to assume that if a government can hack it, they will try. Perhaps it's sad that a university will help them but I'd also to be assumed that they're going to be trying it in some way.

> I think we have to assume that if a government can hack it, they will try. Perhaps it's sad that a university will help them but I'd also to be assumed that they're going to be trying it in some way.

Sure. And we can also-- for the purpose of thinking about risks-- assume that if a government can torture people, they will.

This doesn't make it right, and it doesn't mean that people should sit idly by. Nor does the fact that people oppose and discourage such actions mean that systems can be left vulnerable to these attacks.

Opposing unethical and abusive behavior is not mutually exclusive with building systems which are robust even against unethical attackers. Human wellbeing is maximized when we do _both_.

Re: Why the Tor attack matters

#17
post #11

Earlier quoted context omitted.

>Universities have a responsibility to conduct human research ethically which means little given the laws of nature, all that matters is what people end up doing and measuring that statistically. If statistically speaking most people aren't ethical then that's what we'll get. This whole idea that people are in control of their actions or have any freedom whatsoever given what we know about the laws of nature has to g…

If people lack free will, then the people judging/punishing them also lack free will, and the entire premise of your arguement is an absurdity.

If free will didn't exist, it would be necessary to create it.

Re: Why the Tor attack matters

#18

The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…

The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users.

Given what the Tor project thinks to be, it needs smart people to poke it.

Re: Why the Tor attack matters

#19
None of this should be much of a surprise.

There has always been the possibility of bad actors being involved with Tor. In addition, the Tor software is complicated enough that there undoubtedly will be bugs in it.

This is "you bet your life" serious. However, both the architecture and the implementation of software must be perfect for that to succeed. It's pretty easy for one bug to mean "game over".

People using Tor just don't have a chance when it comes to dealing with the NSA, FSB, GCHQ or any similar state actors. Even allowing for inevitable government bureaucracy and incompetence, the disparity in resources can just be staggering. A big agency can easily, easily afford to devote 100 full time people to one high value target. Those are not odds I'd like to bet against.

In the bigger picture, the NSA doesn't give a rats ass about either Silk Road or about child pornography (at least I hope they don't). Which is why an "academic institution" was enlisted to help out the FBI with this.

But if I was a dissident or protester in Turkey, Syria, Russia, or any of a large number of authoritarian countries, I certainly wouldn't use Tor. Not if my life and the life of my family was at risk.

Re: Why the Tor attack matters

#20
I don't really buy the comparison that what CERT did is similar to a university-sponsored DDoS. I think a better parallel is the Dan Egerstad case. He ran a Tor exit node and analyzed all the plaintext traffic leaving the exit nodes. He ended up collecting a ton of sensitive usernames and passwords. He tried to contact some of these people by e-mail but they ignored him. So he posted a bunch of these passwords on his blog. He was promptly arrested (and eventually released). At that time the security community was outraged that an obviously well-intentioned researcher was being harassed by the police for doing his job. The response is a lot different now for reasons I don't really understand.

I do wish both sides would acknowledge this is a tricky issue. On the one hand, if I run a tor exit node or relay, it is my node and it seems like I'm allowed to do with it as I please. At the same time, it also seems obviously unethical (maybe illegal?) to be harvesting passwords off an exit node or to dole out vigilante justice to Tor users I don't like.

One other thing to keep in mind here is that SEI is a DoD funded center. It may be nominally affiliated with CMU, but all their money comes either from the DoD or external grants awarded to the researchers at SEI. So CMU the private research university and SEI the DoD-funded research center have very different obligations to the public. It's important not to conflate the two.

The big question is this: what are our responsibilities as security researchers, especially when we're working on "live" software systems? Green seems to be suggesting some form of a review board which pre-approves experiments on live targets. Maybe this is what we need, but be careful what you wish for though. The bad guys don't have review boards.

Post reply on HN