Earlier quoted context omitted.
Anonymous random new account, I don't know how intimidated you think I'm going to by whatever your academic credentials will turn out to be when you reveal them, but nobody I know in security research is talking about this Tor work the way you are, or would take umbrage at what Patrick said. Patrick knows what he's talking about.
Dude the fact that nobody you know is worried should be the first clue that something is really wrong or you are hanging out with wrong people. Security, Privacy & Data Mining research are ripe for bureaucratic takedown. Incidences like these will only lead to harsher requirements and stifle future research. Its essential for the security community to police itself. As far as Patrick knowing what he's talking about I…
Why the Tor attack matters
61–70 of 77 posts
Re: Why the Tor attack matters
#62Earlier quoted context omitted.
Fair enough. But I would argue that qualifying Tor as a group targeting world governments is a bit dramatic. That may be propagandist commentary on their part - they're entitled to make it, and people still use Tor in spite of it - but isn't the primary intention of Tor to preserve free speech and anonymity, and to offer protection from persecution (or prosecution) by nation-states that seek to quell dissent? And if…
They provided information "on that battlefield" that shows that Tor is wholly inadequate to "offer protection from persecution by nation-states". If you're in a place where your life is on the line and you think Tor will help you, this shows clearly that is incorrect. That is useful, even critical information, since lives depend on it. Maybe you don't know the source or the method but the output is very valuable .
http://www.bloomberg.com/news/articles/2015-09-22/russia-s-p...
Re: Why the Tor attack matters
#63Worse: there's a view that people who get owned "deserved it." Our industry, and its academic attachments, have a really strange vindictive streak towards those who it should be looking out for. (Which is not to say that those people should be looking out for people swapping child porn--but what about the thousands and thousands of people who were not?)
Re: Why the Tor attack matters
#64The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
> Tor is having a fit of institutional pique that researchers are compromising the network's privacy guarantees by, well, looking at it.
> If you write security software, and you're not praying that loyal opposition hits you with everything they've got, you're not doing security
> Tor is intended to be, and is marketed as, robust against nation state adversaries. It cannot possibly be so if it worries about academics.
Two interpretations:
1. It's OK to go after Tor. This is dead wrong - attacking a network without permission is very bad form. Maybe it's OK to do the equivalent of checking to see if someone's front door is locked (this is a grey area), but only if you intend to warn them that their door's unlocked. Going through their stuff is obviously unethical (and probably illegal).
2. Tor should be more permissive, encouraging more attacks from researchers.
Obviously, the researchers crossed the line when they started gathering user data. But Tor should only be upset that the attack went too far, not that the attack succeeded.
I'm not sure of the context - was the Tor community pissed off that researchers found a weakness, or pissed off that the weakness was exploited?
Twitter is a pretty poor platform if you want nuance, so it's probably best to be charitable in your interpretations of what people say there.
Re: Why the Tor attack matters
#65"A traffic confirmation attack is possible when the attacker controls or observes the relays on both ends of a Tor circuit and then compares traffic timing, volume, or other characteristics to conclude that the two relays are indeed on the same circuit. If the first relay in the circuit (called the "entry guard") knows the IP address of the user, and the last relay in the circuit knows the resource or destination she is accessing, then together they can deanonymize her."
Interesting technical problem. They patched it, obviously, but similar attacks are still possible. It does say more research needs to be done, when that post was published. Obviously the method they used to send and receive signals from one side to the other doesn't work anymore, but statistical methods presumably do. Sort of like this:
https://mice.cs.columbia.edu/getTechreport.php?techreportID=...
Seems like a very difficult problem to solve.
Re: Why the Tor attack matters
#66I'm willing to bet that the NSA has started to hook into the Tor network and add in their own nodes, which monitor the traffic. Unless it's not possible to snoop in on data.
https://www.reddit.com/r/IAmA/comments/3sf8xx/im_bill_binney...
Re: Why the Tor attack matters
#67It would have been more ethical if the university had not blocked the "researchers" from disclosing the vulnerability at Black Hat. (Though even then they were not following responsible disclosure practices). The fact that Tor had to guess what the vulnerability was and the "researchers" still have not released their paper is unethical and probably illegal.
Re: Why the Tor attack matters
#68Earlier quoted context omitted.
To his credit, I'd guess he's not sharing his bona fides because doing so would jeopardize the program he alleges to be involved in, and there isn't a particular reason to doubt the veracity of his claim by virtue of his creating an anonymous account to protect said program. While his passion for the issue has made his message more aggressive than you'd like, don't dismiss his claim because you believe he's just full…
It is totally fine if they disagree with me. What's not fine is the way they chose to express their disagreement: by taking umbrage at the idea that anyone, let along the author of a Bingo Card site, would have an opinion contrary to theirs. I don't even think I disagree with the second part of 'AMEDICALRe's root comment. But of course, that comment has very little to do with what Patrick actually said. Patrick is re…
perhaps nitpicking, and a bit tangential to this debate, but I can't imagine the $1m on its own would be enough to break it.
I imagine they have some fairly beefy research budget with an existing infrastructure with a substantial computing power and prior research experience to begin with. So quite a tall giant to stand on. If I had to guess, the $1m was only there to cover time spent on this very specific task at hand, and for allocating researchers' time away from other tasks...
Re: Why the Tor attack matters
#69Earlier quoted context omitted.
I'm not sure what the last part of your first paragraph was supposed to mean, but if I wanted to compare my own computer security cite record with yours, would I search scholar.google.com for "AMEDICALRe"? You've misread Patrick's messages to spectacular effect, leaving me with the impression that you were simply champing at the bit to jump at him and his silly bingo card site. Tor chose world governments as their ad…
To his credit, I'd guess he's not sharing his bona fides because doing so would jeopardize the program he alleges to be involved in, and there isn't a particular reason to doubt the veracity of his claim by virtue of his creating an anonymous account to protect said program. While his passion for the issue has made his message more aggressive than you'd like, don't dismiss his claim because you believe he's just full…
Re: Why the Tor attack matters
#70In my opinion, this is a wakeup call for the Tor Project. The attack would have been obvious if they'd been tracking the requisite circuit parameters. Ironically enough, it strikes me that the Tor network needs something like CERT for detecting attacks.