Live data from Hacker News

Two months after FBI debacle, Tor Project still can’t get an answer from CMU

arstechnica.com

41–48 of 48 posts

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#41
post #36
post #11

Earlier quoted context omitted.

I still find it hard to ever trust an institution that wouldn't raise a huge stink about the ethical implications of this. They don't exist to serve "national security interests", that's what the NSA is for.

> They don't exist to serve "national security interests" Yes they do. From their website: "The Software Engineering Institute (SEI) is a not-for-profit Federally Funded Research and Development Center (FFRDC) at Carnegie Mellon University, specifically established by the U.S. Department of Defense (DoD) to focus on software and cybersecurity."

I interpreted the parent comment as saying that CMU doesn't exist to serve national security interests, whether or not there is an entity, like the FFRDC SEI, that does exist for related reasons.

On one hand, leading academic institutions are commonly understood to have a responsibility to preserve free speech (especially speech that is critical of military or government action), remain as a neutral education and research body decoupled from any specific political or military agendas, and help lead in social progress towards greater overall ethical standards in education, research, and scholarship.

On the other hand, many universities loan out the credential and status of being affiliated with them as a recruitment tactic to assist the DoD in the task of creating a diversified set of military research organizations, which from a superficial observation point of view (the view taken by many of the younger engineers duped into working for below market pay at such places) look like run-of-the-mill software/science/engineering jobs while having all sorts of ethical gray areas, and the end result is to create rampant ethical conflicts of interest, questionable management practices, and many other problems.

I don't think it's as simple as just pointing out that SEI is an FFRDC and moving on. The fact that universities in general continue to perpetuate this problem -- academia-military pseudo-credible research facility affiliation and status-mongering -- that is the bigger issue.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#42
post #32

I'm waiting for someone to build an implementation of Tor in a proof-verifiable language. That would be pretty cool, since anyone could prove source correctness automatically.

That would help with things like the memory safety of the daemons you run, but that hasn't been the problem when Tor has failed its users. Tor has failed its users because the idea of running a public Tor cloud with volunteer entry, onion, and exit nodes is ludicrous. It means that the entire network is under surveillance all the time, the exact opposite of what you want. There has been widespread confirmation that t…

Yes, I agree. When I wrote the parent comment I was thinking more about implementation detail correctness: memory safety, protocol implementation correctness, etc.

Like you said, Tor has architectural issues. Tor would be fine if it were low-profile, but it's not, and that's a major part of why the architecture is breaking down - it doesn't scale well with increasing users/publicity/nation-state-interest.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#43
post #8

Earlier quoted context omitted.

> Tokyo University has this pledge to make sure basically no military research is done on campus, which I feel to be pretty laudable. So, you move it off-campus. See e.g. the MIT Lincoln Lab, https://www.ll.mit.edu/

I'm at MIT proper and a good portion of our team's medical device work is DOD funded. While we are primarily designing devices to be used in civilian hospitals, our diagnostic devices could also potentially be used to optimize battlefield care for soldiers, which I personally think is great. I think a wholesale ban on military research is pretty silly; the ethical implications of projects should be considered on a ca…

> the ethical implications of projects should be considered on a case by case basis by the university

How's that work during Vietnam when the DoD dangled bags of money in front of universities?

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#44
post #43

Earlier quoted context omitted.

I'm at MIT proper and a good portion of our team's medical device work is DOD funded. While we are primarily designing devices to be used in civilian hospitals, our diagnostic devices could also potentially be used to optimize battlefield care for soldiers, which I personally think is great. I think a wholesale ban on military research is pretty silly; the ethical implications of projects should be considered on a ca…

> the ethical implications of projects should be considered on a case by case basis by the university How's that work during Vietnam when the DoD dangled bags of money in front of universities?

I can't speak to that as I wasn't alive then and have not researched the topic. Care to elaborate?

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#45

The intelligence community used to value Tor. Remember where it came from. Now they don't, presumably because the primary intelligence target has shifted from fixed actors like nation states and large businesses to the general public. Now those nation states and businesses are 'intelligence partners' in the fight against the 'lone wolfs' hiding within the masses. Perhaps then it is in Tor's interests to restart some…

I don't think they valued Tor specifically. They did value scientific research, which is what Tor was at the time. Like most research work, it got dropped once they had a working proof of concept. The State Department picked it up years later.

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#46
post #43

Earlier quoted context omitted.

> the ethical implications of projects should be considered on a case by case basis by the university How's that work during Vietnam when the DoD dangled bags of money in front of universities?

I can't speak to that as I wasn't alive then and have not researched the topic. Care to elaborate?

As someone who wasn't alive then either, it's a rather well documented period of history, albeit mostly in dead tree form. Karnow is probably the classic (http://www.amazon.com/gp/aw/d/0140265473/).

To use a more modern analogy that exists on the internet, the 2010 US military research / development / testing budget looks like it was around USD$80b.

Or in other terms, roughly equal to the total of all research spending by all other branches of the US government. (http://www.aaas.org/sites/default/files/RDGDP_1.jpg)

Now you're a university professor / dean / president. Times are hard (they always are, you're in academia). There's a huge pie sitting right next to the one you've been fighting over, and all you have to do is work on certain technologies that may or may not have lethal consequences.

I wouldn't take the bet on many people saying "No thanks, I'll be happy giving up grant money for moral reasons."

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#47
post #20

The intelligence community used to value Tor. Remember where it came from. Now they don't, presumably because the primary intelligence target has shifted from fixed actors like nation states and large businesses to the general public. Now those nation states and businesses are 'intelligence partners' in the fight against the 'lone wolfs' hiding within the masses. Perhaps then it is in Tor's interests to restart some…

NSA is schizophrenic in that regard. Remember that one of the things it does besides looking in everyone's underwear drawers is it also advises US govt (3 letter agencies, military) on what crypto to use. In other words it tells Uncle Sam how to lock his underwear drawers so other agencies don't peek in there. It is always interesting to see what they say there. Because if they know, for example, one type of crypto t…

Guess where NOBUS came from?

Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU

#48

I worry about Tor's security: 1) For security, most systems rely on their obscurity and on the fact that the assets they protect probably aren't worth much investment by the attackers. Tor can't rely on either of those circumstances: It's prominent and breaking into it is a one-stop solution to attacking many valuable targets. 2) Many organizations with large amounts of resources, from state intelligence agencies to…

If you look at Tor's concept. It's pretty clear that it cannot be considered secure.

Each time you use tor your packets actually go through a path of 3 different servers (or relays). If the attacker owns the two ends it's game over. How many relays are there out there? How many are owned by the NSA or other gov?

It's pretty obvious that this system just cannot work because a majority of relays are owned by the attacker.

Post reply on HN