Live data from Hacker News

Two months after FBI debacle, Tor Project still can’t get an answer from CMU

arstechnica.com

1–10 of 48 posts

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#4
>... a few weeks earlier had canceled a security conference presentation on a low-cost way to deanonymize Tor users. The Tor officials went on to warn that an intelligence agency from a global adversary also might have been able to capitalize on the vulnerability.

This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol nature, then maybe it's time to look for a successor (we aren't using WEP anymore, right?)

As to the CMU stuff... Tokyo University has this pledge to make sure basically no military research is done on campus, which I feel to be pretty laudable.

I wonder if there's a similarly worded pledge for this sort of thing. But at the same time, universities can do a lot of good security research that can, in the end, strengthen the systems we use.

The "$1 million to target these specific people" sounds dirty, but "$1 million to do research on the vulnerabilities of Tor"... well that sounds like research to me. Pretty tricky.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#5
post #2

This continues to reflect very poorly on CMU and CERT.

Yes, but if they're under some Kafkaesque gag order there not much they can do right?

To be clear, NSL are anti-democratic and wrong.

But it looks like they put themselves in that position. Either by voluntary working with the FBI and allegedly taking a $1M grant, and/or doing unethical research by doing it on the live network.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#6
post #4

>... a few weeks earlier had canceled a security conference presentation on a low-cost way to deanonymize Tor users. The Tor officials went on to warn that an intelligence agency from a global adversary also might have been able to capitalize on the vulnerability. This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol natur…

I believe this particular attack[0] has been fixed.

[0] https://blog.torproject.org/blog/tor-security-advisory-relay...

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#7
post #5

Earlier quoted context omitted.

Yes, but if they're under some Kafkaesque gag order there not much they can do right?

To be clear, NSL are anti-democratic and wrong. But it looks like they put themselves in that position. Either by voluntary working with the FBI and allegedly taking a $1M grant, and/or doing unethical research by doing it on the live network.

Is it possible for an NSL to order you to conduct your research on the live network?

(I mean, I guess it's possible for an NSL to order you to do anything, because America.)

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#8
post #4

>... a few weeks earlier had canceled a security conference presentation on a low-cost way to deanonymize Tor users. The Tor officials went on to warn that an intelligence agency from a global adversary also might have been able to capitalize on the vulnerability. This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol natur…

> Tokyo University has this pledge to make sure basically no military research is done on campus, which I feel to be pretty laudable.

So, you move it off-campus. See e.g. the MIT Lincoln Lab, https://www.ll.mit.edu/

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#9
post #4

>... a few weeks earlier had canceled a security conference presentation on a low-cost way to deanonymize Tor users. The Tor officials went on to warn that an intelligence agency from a global adversary also might have been able to capitalize on the vulnerability. This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol natur…

There's is no WPA2 alternative, this is it, this is the bleeding edge of Internet privacy algorithms. And since privacy is seen as a public enemy, a public sponsored attack is underway to weaken it, to the point where you can't really trust Tor for the type of world changing, nation state adversary, Snowden or Wikileaks level missions.

People needing a high level of protection can use and should use Tor in their workflow but they should not expect a one-click solution. On the other hand, it's perfectly adequate for day to day use of privacy minded individuals that are not targeted by active attacks.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#10
post #7
post #5

Earlier quoted context omitted.

To be clear, NSL are anti-democratic and wrong. But it looks like they put themselves in that position. Either by voluntary working with the FBI and allegedly taking a $1M grant, and/or doing unethical research by doing it on the live network.

Is it possible for an NSL to order you to conduct your research on the live network? (I mean, I guess it's possible for an NSL to order you to do anything , because America.)

All an NSL can do is request subscriber information and simultaneously gag you from telling them that the request occurred.
Post reply on HN