Live data from Hacker News

Hackers breach FSB contractor, expose Tor deanonymization project

zdnet.com

31–40 of 123 posts

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#31

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

One time pads[1] are an effective and cheap measure. Certain privileged diplomatic luggage (not exactly sure of the protocols) cannot be searched by the host country. You can bring them to your embassies on a regular basis.

1 -https://en.wikipedia.org/wiki/One-time_pad

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#32
post #24

Earlier quoted context omitted.

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

Tor is an anonymizer. Why would embassies use an anonymizer for communicating back home? Everyone knows they’ll be communicating with home. There’s no point in hiding that. What you want to hide is the content of that communication, which Tor doesn’t do very well. You do that with standard encryption tools.

Because if you don't know where traffic is going or coming from it's harder to infer what the message is about.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#33
post #6

As much as I hate to say this, we all knew it was happening, right? I'm still ninety percent sure they had to scramble to justify a non-tor-breaking reason they got Ulbricht. I don't know why people are still encouraging others to use it alone. You should also be using some kind of encryption of the content itself. Their goal is to figure out who you are and what you're saying; deny them either piece, and they're foi…

Ulbricht was grossly incompetent, they didn't need a special attack on Tor to unmask someone who asks questions about connecting to Tor from a public StackOverflow account in their real name.

I agree on the competency assessment, butI think the issue was plugging the service using his gmail IIRC. (Not just that he posted about Tor).

IIRC they were able to track down the first mention of the site and it was from an account tied to Ross.

Plenty of noncriminals are Tor users and post about Tor - myself included.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#34

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

Why do they need anything more than HTTPS? Just open https://nsa.gov/ and send your data.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#35
post #12

Earlier quoted context omitted.

He really did that? Jeez, you're right. Still, such attacks have doubtless been used before. Even if they haven't broken the core protocol, I'd assume they've got a few zero-days sitting around.

He did a lot of stupid stuff. Like logging into SilkRoad from a public library. FBI agents were at the next table.

He logged in in public a lot. They were able to correlate him opening laptop/joining wifi with their suspect account signing into Silk Road.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#36
post #8
post #2

Last time Tor was mentioned here, a user posted this link [1], claiming Tor is a military financed destabilization project. Seems unbelievable, but there appear to be lots of supporting documents. [1]: https://surveillancevalley.com/blog/fact-checking-the-tor-pr...

Wikipedia: “The core principle of Tor, "onion routing", was developed in the mid-1990s by United States Naval Research Laboratory employees, mathematician Paul Syverson, and computer scientists Michael G. Reed and David Goldschlag, with the purpose of protecting U.S. intelligence communications online.“ Recently, many or all of the US’s agents in China were captured and executed: https://foreignpolicy.com/2018/08/15/…

>> dead nut jobs iPhone

I think the principle here is that the same dead nut will simply cease using iPhones the moment they become insecure.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#37

Earlier quoted context omitted.

1. Controlling the exit nodes doesn't mean anything unless they can use it to perform correlation attacks (because TLS, GPG, etc. Exit nodes are considered malicious regardless of who owns them.) 2. Using hidden services obviates the problem of exit nodes.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…

Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that.

Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up.

So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm sure that many people do. So I doubt that government control majority of Tor nodes.

If you operate a server, consider installing Tor node. It does no harm, it consumes as much of bandwidth as you will configure and you probably have a lot of unused resources anyway.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#38

Earlier quoted context omitted.

Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness. A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes or who can execute unmasking attacks by traffic shaping or monitoring if they control enough relays. For the most part any country which can perform intelligen…

>Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness... For the most part any country which can perform intelligence collection out of its embassy will have sufficient budget and and technical capacity to develop their own secure means of phoning home. The CIA has it's own onion service: ciadotgov4sjwlzihbbgxnqg3xiyrg7so2r2o3lt5wz5ypk4sxyjstad.onion Tor was developed by…

[deleted]

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#39
post #24

Earlier quoted context omitted.

Tor is an anonymizer. Why would embassies use an anonymizer for communicating back home? Everyone knows they’ll be communicating with home. There’s no point in hiding that. What you want to hide is the content of that communication, which Tor doesn’t do very well. You do that with standard encryption tools.

Because if you don't know where traffic is going or coming from it's harder to infer what the message is about.

You properly encrypt it and regularly send data (like in a VPN). Done.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#40

Earlier quoted context omitted.

I'd be surprised if the big countries used plain Tor for their vital communication. They would be having their own secret networks or tunnel through Tor. Small countries have probably simply given up hiding their intelligence from the big ones at this point and are simply interested in ensuring their immediate rivals are kept out, which Tor can probably do.

A custom protocol can potentially be fingerprinted. I wouldn't be surprised if they used something less sophisticated. Like (encrypted) direct messages on twitter/reddit/facebook. This way the traffic blends with the rest.

It doesn't need to be a completely custom protocol. HTTPS can handle a very large percentage of anyone's communication needs these days.
Post reply on HN