Live data from Hacker News

Italian Anti-Corruption Authority Adopts Onion Services

blog.torproject.org

61–70 of 101 posts

Re: Italian Anti-Corruption Authority Adopts Onion Services

#62

Earlier quoted context omitted.

If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. Even with https, if the feds are in cahoots with the certificate authorities, you would be just as vulnerable to this sort of injection right? However, tor hidden services is another story. I think this is where a bad actor would hit a wall.

> If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. That's why Tor Browser comes with NoScript.

And why it's so annoying that it nonetheless sets it to ALLOW JS by default.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#63

Earlier quoted context omitted.

Would it be possible for you to port your work to I2P as well? It's good to have a fallback network in case issues arise in Tor and something needs to plug the gap in the interim, and I2P would fulfill that roll pretty well.

There's not really much work to speak of yet. Last I looked at i2p, it carried a JVM with it and the C impl was not full featured iirc. Will have to look again.

The C++ routers have now largely become feature complete, IIRC they've even ported I2P-Bote to work on them. And you have the JVM reference router still being developed, so there's at least three different implementations of the router and that helps with finding bugs and the like.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#64

Earlier quoted context omitted.

If you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec jour…

To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?

" if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?"

On top of dragonwriter's answer, I'll point out that "U.S. intelligence" doesn't exist as one entity in the way you ask that question. There are a number of groups that cooperate in some ways and compete or just diverge in others. The NSA and FBI want Tor cracked the most to find their targets. Whereas, the State Dept and/or the CIA that back Tor's funding want to protect both dissidents and assets overseas from state-level agencies monitoring communications. They need it to be unbreakable for some set of nation-state attackers.

Now, that doesn't mean that it needs to be unbreakable for the NSA, etc. The original guidance I read on Tor even warned that global adversaries would probably break it. The Many Eyes collaborations have visibility into a lot of the network. They're probably also honeypotting it with high-bandwidth links. It's also written in a tricky protocol in unsafe language on OS's done similarly running untrustworthy apps. They'll probably always have attacks on it for at least worthwhile targets even if State and CIA don't want that. It will still be valuable in many threat models, including NSA if combined with other methods. Especially if about delaying rather than permanently denying them info.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#65

Earlier quoted context omitted.

To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?

" if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?" On top of dragonwriter's answer, I'll point out that "U.S. intelligence" doesn't exist as one entity in the way you ask that question. There are a number of groups that cooperate in some ways and compete or just diverge in others. The NSA and FBI want Tor cracked the most to find their targets. Whereas, the State Dept a…

Of course it is true that US intelligence is far from monolithic, but I think it's a useful-enough abstraction for the purpose of thinking about the issue.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#66
post #8

Earlier quoted context omitted.

>Too bad onions was compromised by the NSA. that makes speaking up against the Bad Guys a bit more dangerous. Any references you would want to provide for this claim?

If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. Even with https, if the feds are in cahoots with the certificate authorities, you would be just as vulnerable to this sort of injection right? However, tor hidden services is another story. I think this is where a bad actor would hit a wall.

I keep toying with the idea of building a system that allows services to authenticate with you. It's not going to be useful for the general population, but for people who have a clue it would be useful for detecting CA hacks. Theoretically it's not so hard -- you send the service a key when you first start using it. The service signs challenges to prove that they have the key. Now an attacker must both hack the CA and get the private key to impersonate the service. I tried to figure out a way to do it with a plugin, but unfortunately it looks like it requires modifications to the browser to make it work. Thinking pragmatically, I suspect that it would never make it into a mainstream browser (for the same reasons that things like Persona never made it).

Re: Italian Anti-Corruption Authority Adopts Onion Services

#67

Earlier quoted context omitted.

> Tor is far more fingerprintable than people think it is You seem to have no idea about the existence of pluggable transports.[1][2] > and its riddled with adversaries and malware. Yes, and so is I2P... Freenet... the Internet? > Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. Isn't that an argument for using Tor? As Mike Perry (who works now on the vanguard…

I've been on HN for almost 10 years. You aren't going to get a cut and dry answer from most pros because most pros aren't going to post things in public forums. Pluggable transports have nothing to do with it. I've actually helped defenders against Tor based attackers. I've de-anon'd them. It was easy as fucking shit because most attackers are dumb and the Tor browser isn't 0day proof or as network isolated as people…

"For the 99.9% of adversaries having a wipeable iPad will stop browser fingerprinting and switching up IPs or cafes will stop IP tracking."

Down my way, the streets are littered with cameras and I suspect they can match time and IP address and id you easily. This is the same in most industrialized nations probably.

(Not hiding from anybody here, just a thought experiment)

Edit: Very frequently the Police will ask for drivers who have in-car cameras when there is a crime or accident. And a lot of them do have cameras. In Australia.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#68

Earlier quoted context omitted.

If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. Even with https, if the feds are in cahoots with the certificate authorities, you would be just as vulnerable to this sort of injection right? However, tor hidden services is another story. I think this is where a bad actor would hit a wall.

> If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. It's impossible for Tor to magically encrypt the whole Internet. With any network that will allow you to access the clearnet, the endpoint will see the plaintext if the website you're communicating with doesn't have HTTPS. You're criticizing…

> You're criticizing Tor for something that's impossible to solve. If you think that's possible then please open a ticket

Not criticizing tor. Just pointing out a couple of ways in which a tor user could give themselves up by doing stupid things while using tor.

Interesting stuff on timing based attacks. Thanks

Re: Italian Anti-Corruption Authority Adopts Onion Services

#69

Earlier quoted context omitted.

> Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched) That's an unfounded accusation. Micah Lee wrote a very concise refutation of his smear campaign.[1] > I would be sure someone couldn't pierce the veil of anonymity. That still doesn't contradict the fact that using Tor is better than not. [1] : https://micahflee.com/2014/12/fact-checking-pando…

That article is four years old. This claim I heard in an interview from him for his book that just came out (he got a bunch of e-mails through FOIA requests, as I understand it), and isn't addressed by this "very concise refutation." And some of the claims seem a little bit of a stretch (using the "Gate" suffix is a nod to Gamergate? Isn't it more plausible that this is the same reference to Watergate that's been app…

He posted the FOIAd docs here: https://surveillancevalley.com/the-tor-files/master-list

He and I discussed them a bit on Twitter: https://twitter.com/itdaniher/status/961307347950940161

I was not impressed by his response.

The "bunch of emails" seemed remarkably banal. I've written similar emails about sponsored open-source work myself.

edit:

email stack 1: https://www.documentcloud.org/documents/4367176-Tor-BBG-corr...

email stack 2: https://www.documentcloud.org/documents/4367193-Tor-BBG-corr...

Re: Italian Anti-Corruption Authority Adopts Onion Services

#70
post #49

Earlier quoted context omitted.

How anonymous could it be, if they know whether a reporter is a "private person/company"?

Look at the form, they ask for you are you working, in which departments, etc.. It is just silly!

Not really, they ask you other information and only these market with * are required.

In fact, only a few information are required. Your job title aka position (make sense in case is a manager reporting an illegal activity other than a cleaner which might have really small amount of information) the entity involved and if you work in that entity or you just had some sort of relationship.

After all it make sense to have a big set of data to investigate in. If not would be complicated for anyone to understand what's going on. You're still reporting it at the anti corruption authority, so even if you give them more details you should be confident that they'll treat it carefully.

All the personal data (such as name, last name and so on) are optional. And, if you choose to not share your personal data, the form will be considered only if you complied with a level of detail that's enough to do an eventual investigation (if not, since they can't reach you out to ask you or details, would be useless to say "on December 2014 I saw a guy giving 10 euro to another one in the aisle of the department X in the state company Y. But was too dark and I can't tell who they are").

Post reply on HN