Why the Tor attack matters
51–60 of 77 posts
Re: Why the Tor attack matters
#52Earlier quoted context omitted.
If you had cut the ridiculous and mean first sentence out of this comment it would have been fine, but then, as you know, nobody would have cared about it, because you'd have been saying nothing everyone else hadn't already been saying.
Why do you copyright your comments?
Re: Why the Tor attack matters
#53The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
This is perhaps the most unnecessarily rude comment to be at the top of a hacker news thread in some time. Let's all remember that disagreeing with someone doesn't mean being glib or mean.
Re: Why the Tor attack matters
#54The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
If you had cut the ridiculous and mean first sentence out of this comment it would have been fine, but then, as you know, nobody would have cared about it, because you'd have been saying nothing everyone else hadn't already been saying.
Re: Why the Tor attack matters
#55Earlier quoted context omitted.
the revelation that there is or was a flaw of that scale is a service to the Internet Right on all points regarding Tor's failures, except this above is the crux of the problem. Specifically, that the researchers did NOT disclose this to either the Tor project or the broader security community. They disclosed it to the Feds, pulled their presentation, and sat on it presumably forever until third parties smelled somet…
Where do you think Tor came from in the first place? The US Naval Research Lab. Why do you think the USG went to CMU for this research? Because CMU has been a bastion of state-funded computer security research since the 1990s. No, the big story here is that Tor was broken for a pittance. But that story is a lot less fun than demanding scalps from CMU, because it suggests that you might not in fact be able to thwart n…
Re: Why the Tor attack matters
#56Earlier quoted context omitted.
If you had cut the ridiculous and mean first sentence out of this comment it would have been fine, but then, as you know, nobody would have cared about it, because you'd have been saying nothing everyone else hadn't already been saying.
Why do you copyright your comments?
less flippant answer—because he's probably had problems with people stealing his answers and posting them on other forums or similar issues.
Re: Why the Tor attack matters
#57The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
Re: Why the Tor attack matters
#58The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
What was the patio11 comment? It seems to have been deleted, making this thread a bit harder to follow.
While Patrick seemed to be focusing on the abstract notion of security mechanisms needing to welcome malicious scrutiny, the strong reaction against his tweet was based on the observation that Patrick failed to take into account the real, human cost of such an attack. This was further compounded by the fact that often, research requires IRB approval to determine whether the research is ethical, and the evidence is that CMU's actions weren't ethical. Yet Patrick felt it necessary to opine without understanding the ethical component of such an attack.
Re: Why the Tor attack matters
#59Earlier quoted context omitted.
It is totally fine if they disagree with me. What's not fine is the way they chose to express their disagreement: by taking umbrage at the idea that anyone, let along the author of a Bingo Card site, would have an opinion contrary to theirs. I don't even think I disagree with the second part of 'AMEDICALRe's root comment. But of course, that comment has very little to do with what Patrick actually said. Patrick is re…
Fair enough. But I would argue that qualifying Tor as a group targeting world governments is a bit dramatic. That may be propagandist commentary on their part - they're entitled to make it, and people still use Tor in spite of it - but isn't the primary intention of Tor to preserve free speech and anonymity, and to offer protection from persecution (or prosecution) by nation-states that seek to quell dissent? And if…
I don't understand what you're trying to say. Surely, if the primary intention of Tor is to protect users from persecution by nation-states, then their adversaries are world governments?
Re: Why the Tor attack matters
#60Earlier quoted context omitted.
Anonymous random new account, I don't know how intimidated you think I'm going to by whatever your academic credentials will turn out to be when you reveal them, but nobody I know in security research is talking about this Tor work the way you are, or would take umbrage at what Patrick said. Patrick knows what he's talking about.
Dude the fact that nobody you know is worried should be the first clue that something is really wrong or you are hanging out with wrong people. Security, Privacy & Data Mining research are ripe for bureaucratic takedown. Incidences like these will only lead to harsher requirements and stifle future research. Its essential for the security community to police itself. As far as Patrick knowing what he's talking about I…
They're not anonymized?
When I'm asked to provide data to medical researchers it also has to be anonymized.