I didn't realize just how fragile TOR is. . . While I understand that remaining anonymous requires adjusting your browser habits somewhat extensively, the fact that a ReCAPTCHA is enough to (theoretically) de-anonymize a user seems to me that it's not able to anonymize at all when browsing. While TOR may be useful for evading firewalls, my general perception of the project has changed from general anonymity tool to a…
Cloudflare ReCAPTCHA De-Anonymizes Tor Users
111–120 of 122 posts
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#112Earlier quoted context omitted.
Good opsec involves multiple layers of security. There's a fun talk at defcon next month on extending wifi range to avoid detection along with signal 'hiding' via SDR: https://www.defcon.org/html/defcon-23/dc-23-speakers.html#Gr...
good opsec also involves logging access to the internet and seeing who sent bomb threats... oh wait, whose side am I on?
Protecting livestock, so they can be fleeced by their proper owner, on the otherhand, doesn't imbue the same sort of charisma upon the good shepherd.
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#113Earlier quoted context omitted.
Tor is already slow - people use it because they want security. The addition of another VPN increases security greatly and only adds a minimal amount of more latency.
> Tor is already slow Relatively, sure. But I've found it very usable in recent times actually. Used it almost full-time (besides a normal Firefox instance for the company's intranet) to get around some silly firewall that wouldn't let me download "hack tools" (I was an intern in the cyber security department, security tools were part of my job). There were times where I didn't notice at all that I was using Tor, and…
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#114Earlier quoted context omitted.
I remember someone at a security conference talking about a kid at a University who sent a bomb threat via Tor. The University simply looked their their logs to see who was connecting to known Tor nodes, narrowed it down by time and found the kid. Source: http://www.theregister.co.uk/2013/12/18/harvard_bomb_hoax_ch...
God I wish grugq still wrote currently. https://grugq.github.io/blog/2013/12/21/in-search-of-opsec-m... I discovered he moved to Github pages after years only to realize he has not published much since I first heard of him.
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#115Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#116Earlier quoted context omitted.
I remember someone at a security conference talking about a kid at a University who sent a bomb threat via Tor. The University simply looked their their logs to see who was connecting to known Tor nodes, narrowed it down by time and found the kid. Source: http://www.theregister.co.uk/2013/12/18/harvard_bomb_hoax_ch...
God I wish grugq still wrote currently. https://grugq.github.io/blog/2013/12/21/in-search-of-opsec-m... I discovered he moved to Github pages after years only to realize he has not published much since I first heard of him.
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#117Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#118Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#119I stopped visiting sites with image recognition reCAPTCHAs. It has to be one of the worst UX patterns ever devised. It's dirt cheap to automate them away so it doesn't really stop any self-respecting bot maker, and it comes at a price of being a huge pain in the ass for a real user. Every time I run into them I felt used and abused. It's really sad. So much brain power and this is what they come up with. Apologies fo…
Have any examples?
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#120Earlier quoted context omitted.
> Tor is already slow Relatively, sure. But I've found it very usable in recent times actually. Used it almost full-time (besides a normal Firefox instance for the company's intranet) to get around some silly firewall that wouldn't let me download "hack tools" (I was an intern in the cyber security department, security tools were part of my job). There were times where I didn't notice at all that I was using Tor, and…
You probably should have spent some time fixing that hole in the firewall that let you bypass your company's download restrictions. ;-)
And as for monitoring, I guess it might be possible, but if someone thinks to use bridge nodes that's also defeated.