Hackers breach FSB contractor, expose Tor deanonymization project
11–20 of 123 posts
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#12As much as I hate to say this, we all knew it was happening, right? I'm still ninety percent sure they had to scramble to justify a non-tor-breaking reason they got Ulbricht. I don't know why people are still encouraging others to use it alone. You should also be using some kind of encryption of the content itself. Their goal is to figure out who you are and what you're saying; deny them either piece, and they're foi…
Ulbricht was grossly incompetent, they didn't need a special attack on Tor to unmask someone who asks questions about connecting to Tor from a public StackOverflow account in their real name.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#13Earlier quoted context omitted.
Ulbricht was grossly incompetent, they didn't need a special attack on Tor to unmask someone who asks questions about connecting to Tor from a public StackOverflow account in their real name.
He really did that? Jeez, you're right. Still, such attacks have doubtless been used before. Even if they haven't broken the core protocol, I'd assume they've got a few zero-days sitting around.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#14Last time Tor was mentioned here, a user posted this link [1], claiming Tor is a military financed destabilization project. Seems unbelievable, but there appear to be lots of supporting documents. [1]: https://surveillancevalley.com/blog/fact-checking-the-tor-pr...
However, I'd be more weary about more recent projects. A lot has happened during the past two decades in cryptography and privacy, and I do think it's credible that all kinds of agencies from all over the world nowadays have the task of subverting privacy projects right from the start. But back in the 90s? Unlikely.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#15Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#16Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…
How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#17Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…
How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)
A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes or who can execute unmasking attacks by traffic shaping or monitoring if they control enough relays.
For the most part any country which can perform intelligence collection out of its embassy will have sufficient budget and and technical capacity to develop their own secure means of phoning home.
Also for highly sensitive material a diplomatic pouch is still the most secure means of transport as it never leaves your sight and is never inspected and if you do get intercepted then destroying physical media is much easier than securing network traffic to the same level of assurance.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#18Earlier quoted context omitted.
Ulbricht was grossly incompetent, they didn't need a special attack on Tor to unmask someone who asks questions about connecting to Tor from a public StackOverflow account in their real name.
He really did that? Jeez, you're right. Still, such attacks have doubtless been used before. Even if they haven't broken the core protocol, I'd assume they've got a few zero-days sitting around.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#19Earlier quoted context omitted.
How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)
I'd be surprised if the big countries used plain Tor for their vital communication. They would be having their own secret networks or tunnel through Tor. Small countries have probably simply given up hiding their intelligence from the big ones at this point and are simply interested in ensuring their immediate rivals are kept out, which Tor can probably do.
Re: Hackers breach FSB contractor, expose Tor deanonymization project
#20Last time Tor was mentioned here, a user posted this link [1], claiming Tor is a military financed destabilization project. Seems unbelievable, but there appear to be lots of supporting documents. [1]: https://surveillancevalley.com/blog/fact-checking-the-tor-pr...
Wikipedia: “The core principle of Tor, "onion routing", was developed in the mid-1990s by United States Naval Research Laboratory employees, mathematician Paul Syverson, and computer scientists Michael G. Reed and David Goldschlag, with the purpose of protecting U.S. intelligence communications online.“ Recently, many or all of the US’s agents in China were captured and executed: https://foreignpolicy.com/2018/08/15/…
The most sinister change in information technology is cloud and the fact that you have no 4th Amendment protections for anything stored there. Our laws simply aren't keeping up. But it was a neat trick to get everyone using cloud and then pulling the rug out of privacy by say "oh, and by the way, since the files aren't on your property, you have no legal protections for them."