Italian Anti-Corruption Authority Adopts Onion Services
61–70 of 101 posts
Re: Italian Anti-Corruption Authority Adopts Onion Services
#62Earlier quoted context omitted.
If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. Even with https, if the feds are in cahoots with the certificate authorities, you would be just as vulnerable to this sort of injection right? However, tor hidden services is another story. I think this is where a bad actor would hit a wall.
> If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. That's why Tor Browser comes with NoScript.
Re: Italian Anti-Corruption Authority Adopts Onion Services
#63Earlier quoted context omitted.
Would it be possible for you to port your work to I2P as well? It's good to have a fallback network in case issues arise in Tor and something needs to plug the gap in the interim, and I2P would fulfill that roll pretty well.
There's not really much work to speak of yet. Last I looked at i2p, it carried a JVM with it and the C impl was not full featured iirc. Will have to look again.
Re: Italian Anti-Corruption Authority Adopts Onion Services
#64Earlier quoted context omitted.
If you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec jour…
To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?
On top of dragonwriter's answer, I'll point out that "U.S. intelligence" doesn't exist as one entity in the way you ask that question. There are a number of groups that cooperate in some ways and compete or just diverge in others. The NSA and FBI want Tor cracked the most to find their targets. Whereas, the State Dept and/or the CIA that back Tor's funding want to protect both dissidents and assets overseas from state-level agencies monitoring communications. They need it to be unbreakable for some set of nation-state attackers.
Now, that doesn't mean that it needs to be unbreakable for the NSA, etc. The original guidance I read on Tor even warned that global adversaries would probably break it. The Many Eyes collaborations have visibility into a lot of the network. They're probably also honeypotting it with high-bandwidth links. It's also written in a tricky protocol in unsafe language on OS's done similarly running untrustworthy apps. They'll probably always have attacks on it for at least worthwhile targets even if State and CIA don't want that. It will still be valuable in many threat models, including NSA if combined with other methods. Especially if about delaying rather than permanently denying them info.
Re: Italian Anti-Corruption Authority Adopts Onion Services
#65Earlier quoted context omitted.
To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?
" if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?" On top of dragonwriter's answer, I'll point out that "U.S. intelligence" doesn't exist as one entity in the way you ask that question. There are a number of groups that cooperate in some ways and compete or just diverge in others. The NSA and FBI want Tor cracked the most to find their targets. Whereas, the State Dept a…
Re: Italian Anti-Corruption Authority Adopts Onion Services
#66Earlier quoted context omitted.
>Too bad onions was compromised by the NSA. that makes speaking up against the Bad Guys a bit more dangerous. Any references you would want to provide for this claim?
If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. Even with https, if the feds are in cahoots with the certificate authorities, you would be just as vulnerable to this sort of injection right? However, tor hidden services is another story. I think this is where a bad actor would hit a wall.
Re: Italian Anti-Corruption Authority Adopts Onion Services
#67Earlier quoted context omitted.
> Tor is far more fingerprintable than people think it is You seem to have no idea about the existence of pluggable transports.[1][2] > and its riddled with adversaries and malware. Yes, and so is I2P... Freenet... the Internet? > Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. Isn't that an argument for using Tor? As Mike Perry (who works now on the vanguard…
I've been on HN for almost 10 years. You aren't going to get a cut and dry answer from most pros because most pros aren't going to post things in public forums. Pluggable transports have nothing to do with it. I've actually helped defenders against Tor based attackers. I've de-anon'd them. It was easy as fucking shit because most attackers are dumb and the Tor browser isn't 0day proof or as network isolated as people…
Down my way, the streets are littered with cameras and I suspect they can match time and IP address and id you easily. This is the same in most industrialized nations probably.
(Not hiding from anybody here, just a thought experiment)
Edit: Very frequently the Police will ask for drivers who have in-car cameras when there is a crime or accident. And a lot of them do have cameras. In Australia.
Re: Italian Anti-Corruption Authority Adopts Onion Services
#68Earlier quoted context omitted.
If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. Even with https, if the feds are in cahoots with the certificate authorities, you would be just as vulnerable to this sort of injection right? However, tor hidden services is another story. I think this is where a bad actor would hit a wall.
> If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. It's impossible for Tor to magically encrypt the whole Internet. With any network that will allow you to access the clearnet, the endpoint will see the plaintext if the website you're communicating with doesn't have HTTPS. You're criticizing…
Not criticizing tor. Just pointing out a couple of ways in which a tor user could give themselves up by doing stupid things while using tor.
Interesting stuff on timing based attacks. Thanks
Re: Italian Anti-Corruption Authority Adopts Onion Services
#69Earlier quoted context omitted.
> Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched) That's an unfounded accusation. Micah Lee wrote a very concise refutation of his smear campaign.[1] > I would be sure someone couldn't pierce the veil of anonymity. That still doesn't contradict the fact that using Tor is better than not. [1] : https://micahflee.com/2014/12/fact-checking-pando…
That article is four years old. This claim I heard in an interview from him for his book that just came out (he got a bunch of e-mails through FOIA requests, as I understand it), and isn't addressed by this "very concise refutation." And some of the claims seem a little bit of a stretch (using the "Gate" suffix is a nod to Gamergate? Isn't it more plausible that this is the same reference to Watergate that's been app…
He and I discussed them a bit on Twitter: https://twitter.com/itdaniher/status/961307347950940161
I was not impressed by his response.
The "bunch of emails" seemed remarkably banal. I've written similar emails about sponsored open-source work myself.
edit:
email stack 1: https://www.documentcloud.org/documents/4367176-Tor-BBG-corr...
email stack 2: https://www.documentcloud.org/documents/4367193-Tor-BBG-corr...
Re: Italian Anti-Corruption Authority Adopts Onion Services
#70Earlier quoted context omitted.
How anonymous could it be, if they know whether a reporter is a "private person/company"?
Look at the form, they ask for you are you working, in which departments, etc.. It is just silly!
In fact, only a few information are required. Your job title aka position (make sense in case is a manager reporting an illegal activity other than a cleaner which might have really small amount of information) the entity involved and if you work in that entity or you just had some sort of relationship.
After all it make sense to have a big set of data to investigate in. If not would be complicated for anyone to understand what's going on. You're still reporting it at the anti corruption authority, so even if you give them more details you should be confident that they'll treat it carefully.
All the personal data (such as name, last name and so on) are optional. And, if you choose to not share your personal data, the form will be considered only if you complied with a level of detail that's enough to do an eventual investigation (if not, since they can't reach you out to ask you or details, would be useless to say "on December 2014 I saw a guy giving 10 euro to another one in the aisle of the department X in the state company Y. But was too dark and I can't tell who they are").