Live data from Hacker News

Two months after FBI debacle, Tor Project still can’t get an answer from CMU

arstechnica.com

11–20 of 48 posts

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#11
post #2

This continues to reflect very poorly on CMU and CERT.

Yes, but if they're under some Kafkaesque gag order there not much they can do right?

I still find it hard to ever trust an institution that wouldn't raise a huge stink about the ethical implications of this. They don't exist to serve "national security interests", that's what the NSA is for.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#12
post #7
post #5

Earlier quoted context omitted.

To be clear, NSL are anti-democratic and wrong. But it looks like they put themselves in that position. Either by voluntary working with the FBI and allegedly taking a $1M grant, and/or doing unethical research by doing it on the live network.

Is it possible for an NSL to order you to conduct your research on the live network? (I mean, I guess it's possible for an NSL to order you to do anything , because America.)

No, it's a (formally, administrative subpoena) request for transactional records related to a national security investigation.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#14
post #7

Earlier quoted context omitted.

Is it possible for an NSL to order you to conduct your research on the live network? (I mean, I guess it's possible for an NSL to order you to do anything , because America.)

All an NSL can do is request subscriber information and simultaneously gag you from telling them that the request occurred.

So then it must be the $1,000,000 that made CMU adjust their ethical standards.

What's worse - that CMU did this in the first place or that they did it so cheaply?

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#15
> Personally, I use it maybe 10, 20 percent of the time. I know that there are people out there that are using it a lot of the time. But for me as much as I might hate Flash, there are times that I need to watch something on YouTube.

YouTube has been working for me using Tor Browser for months, if not years.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#16
post #15

> Personally, I use it maybe 10, 20 percent of the time. I know that there are people out there that are using it a lot of the time. But for me as much as I might hate Flash, there are times that I need to watch something on YouTube. YouTube has been working for me using Tor Browser for months, if not years.

That was an analogy, not a bug report.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#17
The intelligence community used to value Tor. Remember where it came from. Now they don't, presumably because the primary intelligence target has shifted from fixed actors like nation states and large businesses to the general public. Now those nation states and businesses are 'intelligence partners' in the fight against the 'lone wolfs' hiding within the masses. Perhaps then it is in Tor's interests to restart some rivalry between nation states.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#18
post #8
post #4

>... a few weeks earlier had canceled a security conference presentation on a low-cost way to deanonymize Tor users. The Tor officials went on to warn that an intelligence agency from a global adversary also might have been able to capitalize on the vulnerability. This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol natur…

> Tokyo University has this pledge to make sure basically no military research is done on campus, which I feel to be pretty laudable. So, you move it off-campus. See e.g. the MIT Lincoln Lab, https://www.ll.mit.edu/

I'm at MIT proper and a good portion of our team's medical device work is DOD funded. While we are primarily designing devices to be used in civilian hospitals, our diagnostic devices could also potentially be used to optimize battlefield care for soldiers, which I personally think is great.

I think a wholesale ban on military research is pretty silly; the ethical implications of projects should be considered on a case by case basis by the university.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#19

Earlier quoted context omitted.

All an NSL can do is request subscriber information and simultaneously gag you from telling them that the request occurred.

So then it must be the $1,000,000 that made CMU adjust their ethical standards. What's worse - that CMU did this in the first place or that they did it so cheaply?

SEI/CERT is for all intents and purposes completely independent of CMU

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#20

The intelligence community used to value Tor. Remember where it came from. Now they don't, presumably because the primary intelligence target has shifted from fixed actors like nation states and large businesses to the general public. Now those nation states and businesses are 'intelligence partners' in the fight against the 'lone wolfs' hiding within the masses. Perhaps then it is in Tor's interests to restart some…

NSA is schizophrenic in that regard. Remember that one of the things it does besides looking in everyone's underwear drawers is it also advises US govt (3 letter agencies, military) on what crypto to use. In other words it tells Uncle Sam how to lock his underwear drawers so other agencies don't peek in there.

It is always interesting to see what they say there. Because if they know, for example, one type of crypto technique or implementation is vulnerable will they still recommend it for TS classified material storage? Will they recommend for US military or diplomatic service? If they don't, it might leave that open to attack, and they are not doing their job. If they do say "don't use this combination of AES, prime numbers, or OpenSSL implementations", that also gives something away.

I wonder if people people who make these recommendations even talk to people who discover, exploit, and actively penetrate systems? Because everything is very compartmentalized, they actually might not be able to.

That is why they are probably very interested (like we saw) in somehow subverting or weakening some algorithms and implementation so they are the only ones that have a key (Dual_EC_DRBG) , or they are the only ones that potentially have a computational capacity to exploit (DES).

Post reply on HN