Live data from Hacker News

Why the Tor attack matters

blog.cryptographyengineering.com

21–30 of 77 posts

Re: Why the Tor attack matters

#21

What is so surprising here? The DOD is the largest funder of research grants in the US. Pretty much every university is doing research for a US agency from cyber security to lasers for missile defense. I find it very hard to believe that this is the firs time a university was conducting computer security research on live targets.

The DOD funds lasers, but it doesn't then has researchers fire them at random cars to test their effectiveness. I'm not actually sure this isn't sarcasm.

The DOD also funds development of guided, chemical, biological and nuclear weapons, and just about every other way to kill a man you can think off. "Agent Orange" was pretty much militarized by the University of Hawaii under a DOD grant during the late 60's, and they've coordinated with the USAF and the CIA and provided research and analysis to optimize the dispersal methods and study it's effects during it's combat use over Vietnam.

Re: Why the Tor attack matters

#22
post #20

I don't really buy the comparison that what CERT did is similar to a university-sponsored DDoS. I think a better parallel is the Dan Egerstad case. He ran a Tor exit node and analyzed all the plaintext traffic leaving the exit nodes. He ended up collecting a ton of sensitive usernames and passwords. He tried to contact some of these people by e-mail but they ignored him. So he posted a bunch of these passwords on his…

Understanding the nature of each organization involved -- how both motivations and expectations shift as one moves between orgnaizational barriers -- is perhaps the most important, worst reported, least understood part of this story.

If the SEI took money to, essentially, weaponize unpublished research, the issue is not one an IRB would have prevented. DoD contractors aren't bound by scientific codes of conduct. In light of that realization, the suggestion in this blog post is confusing.

(BTW, distancing CMU and the SEI is not meant as a defense of CMU -- close ties between public science and law enforcement/military R&D are as troubling as ever...)

Re: Why the Tor attack matters

#23

The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…

The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.

Some of us are more outraged by the fact that they kowtowed to authority on the BlackHat presentation, and had a disclosure policy that favored the Feds over both the Tor project and the entire security community.

The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.

Re: Why the Tor attack matters

#24

I think we have to assume that if a government can hack it, they will try. Perhaps it's sad that a university will help them but I'd also to be assumed that they're going to be trying it in some way.

The government's ability to do nearly anything by force is an obvious given. This is the reason why constitutional limitations and charters of rights exist in every modern country.

For example, it is equally a understood that almost any government could control/manipulate any press agency if they wanted to, or break down any door with a SWAT team.

The only difference here is that `cyber` did not exist nor is cleanly appliciable to laws wich limits this type of power - laws largely written in the 1800s. Additionally it largely happens in secret, attribution is difficult, and there is a serious knowledge gap from the general public and the type of operations being done.

Re: Why the Tor attack matters

#25

Earlier quoted context omitted.

The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.

Some of us are more outraged by the fact that they kowtowed to authority on the BlackHat presentation, and had a disclosure policy that favored the Feds over both the Tor project and the entire security community. The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.

[deleted]

Re: Why the Tor attack matters

#26

Earlier quoted context omitted.

The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.

Some of us are more outraged by the fact that they kowtowed to authority on the BlackHat presentation, and had a disclosure policy that favored the Feds over both the Tor project and the entire security community. The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.

I doubt they ever particularly cared about the mantle of 'hacker' and whatever ethos is supposed to go with it. That makes it hard for them to betray it.

Re: Why the Tor attack matters

#27

The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…

This is perhaps the most unnecessarily rude comment to be at the top of a hacker news thread in some time. Let's all remember that disagreeing with someone doesn't mean being glib or mean.

Re: Why the Tor attack matters

#28

The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…

The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.

Right; the ethical experiment here would be to set up one's own private Tor network and then attack that. (Think that requires a lot of effort? Well, yeah; that's why you do it as part of a university with grant funding!) This would also have the bonus effect of being able to instrument all the nodes, so you could see the effects of your attack flowing through the system in a white-box manner.

Re: Why the Tor attack matters

#29
post #27

The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…

This is perhaps the most unnecessarily rude comment to be at the top of a hacker news thread in some time. Let's all remember that disagreeing with someone doesn't mean being glib or mean.

[deleted]

Re: Why the Tor attack matters

#30
post #27

The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…

This is perhaps the most unnecessarily rude comment to be at the top of a hacker news thread in some time. Let's all remember that disagreeing with someone doesn't mean being glib or mean.

As a serious academic researcher with a research group has access to amount of data/computing power that we can make NYTIMES headline effortlessly if we were to throw our ethics out of the window, Let me tell you this isn't a fucking joke. Patio11 who seems to be darling of this forum, has no clue what he is talking about. He seems to have never participated in any kind of academic research.

Unlike some stupid bingo card creator or bubble driven recruiting startup. Academic research is a serious business, there is a reason why it is looked in positive light and a lot of things which otherwise are not allowed, are acceptable when done as research. And for it to stay that way scrutiny of research conduct is essential.

Post reply on HN