Live data from Hacker News

Hackers breach FSB contractor, expose Tor deanonymization project

zdnet.com

11–20 of 123 posts

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#11
Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more of the top intelligence agencies of the world can break Tor by more than one method. The only form of safe communication is one that relies on old fashioned and proven methods, utilising code and algo that has been scrutinised by researchers from many nations. People really wanting to be anonymous will do well to be wary of heavily 'promoted' solutions.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#12
post #6

As much as I hate to say this, we all knew it was happening, right? I'm still ninety percent sure they had to scramble to justify a non-tor-breaking reason they got Ulbricht. I don't know why people are still encouraging others to use it alone. You should also be using some kind of encryption of the content itself. Their goal is to figure out who you are and what you're saying; deny them either piece, and they're foi…

Ulbricht was grossly incompetent, they didn't need a special attack on Tor to unmask someone who asks questions about connecting to Tor from a public StackOverflow account in their real name.

He really did that? Jeez, you're right. Still, such attacks have doubtless been used before. Even if they haven't broken the core protocol, I'd assume they've got a few zero-days sitting around.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#13
post #12

Earlier quoted context omitted.

Ulbricht was grossly incompetent, they didn't need a special attack on Tor to unmask someone who asks questions about connecting to Tor from a public StackOverflow account in their real name.

He really did that? Jeez, you're right. Still, such attacks have doubtless been used before. Even if they haven't broken the core protocol, I'd assume they've got a few zero-days sitting around.

We do know that the US government used a Flash applet to deanonymise a lot of Tor Browser users. It was revealed in some lawsuit I think.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#14
post #2

Last time Tor was mentioned here, a user posted this link [1], claiming Tor is a military financed destabilization project. Seems unbelievable, but there appear to be lots of supporting documents. [1]: https://surveillancevalley.com/blog/fact-checking-the-tor-pr...

This is a silly conspiracy. The facts about the initial funding of research on Tor have always been public and well-known, and the conspiracy is based on the idea that there was some grand scheme looking forward into the future for more than 16 years. It's much more likely that some researchers at some government agency implemented the known idea of onion routing in a proof of concept, their work was more successful than anticipated, and later some other researchers at some other government agency were told to try to de-anonymize their colleagues' invention again.

However, I'd be more weary about more recent projects. A lot has happened during the past two decades in cryptography and privacy, and I do think it's credible that all kinds of agencies from all over the world nowadays have the task of subverting privacy projects right from the start. But back in the 90s? Unlikely.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#15

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#16

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

I'd be surprised if the big countries used plain Tor for their vital communication. They would be having their own secret networks or tunnel through Tor. Small countries have probably simply given up hiding their intelligence from the big ones at this point and are simply interested in ensuring their immediate rivals are kept out, which Tor can probably do.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#17

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness.

A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes or who can execute unmasking attacks by traffic shaping or monitoring if they control enough relays.

For the most part any country which can perform intelligence collection out of its embassy will have sufficient budget and and technical capacity to develop their own secure means of phoning home.

Also for highly sensitive material a diplomatic pouch is still the most secure means of transport as it never leaves your sight and is never inspected and if you do get intercepted then destroying physical media is much easier than securing network traffic to the same level of assurance.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#18
post #12

Earlier quoted context omitted.

Ulbricht was grossly incompetent, they didn't need a special attack on Tor to unmask someone who asks questions about connecting to Tor from a public StackOverflow account in their real name.

He really did that? Jeez, you're right. Still, such attacks have doubtless been used before. Even if they haven't broken the core protocol, I'd assume they've got a few zero-days sitting around.

He did a lot of stupid stuff. Like logging into SilkRoad from a public library. FBI agents were at the next table.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#19

Earlier quoted context omitted.

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

I'd be surprised if the big countries used plain Tor for their vital communication. They would be having their own secret networks or tunnel through Tor. Small countries have probably simply given up hiding their intelligence from the big ones at this point and are simply interested in ensuring their immediate rivals are kept out, which Tor can probably do.

A custom protocol can potentially be fingerprinted. I wouldn't be surprised if they used something less sophisticated. Like (encrypted) direct messages on twitter/reddit/facebook. This way the traffic blends with the rest.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#20
post #8
post #2

Last time Tor was mentioned here, a user posted this link [1], claiming Tor is a military financed destabilization project. Seems unbelievable, but there appear to be lots of supporting documents. [1]: https://surveillancevalley.com/blog/fact-checking-the-tor-pr...

Wikipedia: “The core principle of Tor, "onion routing", was developed in the mid-1990s by United States Naval Research Laboratory employees, mathematician Paul Syverson, and computer scientists Michael G. Reed and David Goldschlag, with the purpose of protecting U.S. intelligence communications online.“ Recently, many or all of the US’s agents in China were captured and executed: https://foreignpolicy.com/2018/08/15/…

Even when Tor was new I had my doubts about it due to its origins among other factors. My dissertation was on privacy technologies in that era (early '00s). I covered a lot of ground at the time.

The most sinister change in information technology is cloud and the fact that you have no 4th Amendment protections for anything stored there. Our laws simply aren't keeping up. But it was a neat trick to get everyone using cloud and then pulling the rug out of privacy by say "oh, and by the way, since the files aren't on your property, you have no legal protections for them."

Post reply on HN