Live data from Hacker News

Hackers breach FSB contractor, expose Tor deanonymization project

zdnet.com

51–60 of 123 posts

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#51

Earlier quoted context omitted.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…

Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that. Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up. So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm…

Im guessing that the .gov doesnt run 'many' of the nodes -- but im guessing they have MAPPED them all out and are 0-day exploiting as many as possible.

THIS is what I would guess a state entitiy would be training an AI to do as a function...

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#52
post #45

Earlier quoted context omitted.

So you're claiming that using a VPN makes correlation attacks impossible? Do you have any sources on this? I'd love to read up to better understand your thinking.

Correlation attacks are attacing anonymity. If you are an embassy, there is no need for anonymity. Ok, an embassy connected to vpn.whitehouse.gov and sent 20 gb of data, so what? (unless you are thinking about high level things, like "lots of traffic" -> "something going on", but tor won't help with that either)

>unless you are thinking about high level things, like "lots of traffic" -> "something going on", but tor won't help with that either

But is an embassy always only "phoning home"?

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#53

Earlier quoted context omitted.

Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that. Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up. So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm…

The flipside of that is that it's reasonable to assume that most (not government run) TOR nodes are run at hosters offering cheap small VPS with cheap traffic and high bandwidth. That gives a few select datacenters where sniffing and correlating network traffic is extremely beneficial for deanonymizing TOR traffic. And if the datacenter operator doesn't cooperate and isn't vulnerable to covert sniffing there are alwa…

"That gives a few select datacenters where sniffing and correlating network traffic"

Uh,

This was the whole premise of Carnivore... installed in room 641A

https://en.wikipedia.org/wiki/Room_641A

(Btw - this is the room that Twitter was originally routed through...)

Basically I take the defeatest stance at this point...

There is NO privacy or anon. It doesnt exist any longer.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#54
post #41

Earlier quoted context omitted.

Why do they need anything more than HTTPS? Just open https://nsa.gov/ and send your data.

Because that reveals that you are talking to the NSA right now. Sometimes the volume of chatter is useful information in its own right. Sure, you could script something to make the data rate constant, but that might be undesirably expensive and if you do everything over Tor then your video chat with HQ looks indistinguishable from you bit torrenting pirate episodes of My Little Pony.

I can't currently find the place on Wikipedia where I learned this, but an example of "volume of chatter" being important was e.g. before the attack on pearl harbor. While the US couldn't decrypt the internal messages, it was clear that an attack was imminent based on the pattern (including the radio silence) before the attack.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#55

What is the risk of hosting an exit node? I have heard that you can be liable for facilitating illegal actions if yours gets used for it

Hosting an exit node is not illegal (in the United States), and generally you cannot be held liable if the network was used for illegal actions as a consequence of being an exit node and not committed by you (this is not legal advice); however, you have to be able to prove that and it does not necessarily mean you are protected from being investigated, having your door kicked in, and/or your equipment seized.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#56

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

Tor was created for intelligence.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#58

> Tax-3 - a project for the creation of a closed intranet to store the information of highly-sensitive state figures, judges, and local administration officials, separate from the rest of the state's IT networks. So, is this intranet used for keeping official (confidential) records or for blackmail purposes?

Or is it the network they won’t pass laws requiring backdoors for? Literally segment society into those with power and privacy, and those with neither? Why on earth would they need separate infrastructure and the rest of us do not?

>Why on earth would they need separate infrastructure and the rest of us do not?

I imagine they wanted to build their own version of SIPRNet.

[0] - https://en.wikipedia.org/wiki/SIPRNet

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#59

What is the risk of hosting an exit node? I have heard that you can be liable for facilitating illegal actions if yours gets used for it

As I understand it, part of the risk is proving that you didn't perform the illegal act, and that an investigation itself can be damaging (loss of equipment/public reporting that you are being investigated for being involved in illegal behaviour).

If you maintain a strict separation between your traffic/equipment and the exit node, this may be less of a risk, but is subject to the laws of your jurisdiction.

> In the USA, there have been no equipment seizures due to Tor exits, but there have been phone calls and visits. In other countries, people have had all their home computing equipment seized for running an exit from their home internet connection.

https://blog.torproject.org/tips-running-exit-node

> Jan Bultmann and David Robinson, a married couple from Seattle and well-known privacy activists in that city, were awakened early one morning last month by police with a search warrant for their home. The detectives from the Seattle Police Department demanded passwords to access the couple's computers, saying they were investigating child abuse imagery [...] The couple consented to the search and gave their passwords to police, who found no child abuse imagery, didn't seize any equipment, and made no arrests.

https://nakedsecurity.sophos.com/2016/04/07/couple-hosting-t...

> The operator of a Tor [exit node] used by someone to download a pornographic image of a minor has been given a three-month suspended prison sentence by an Austrian court for abetting access to pornographic images of minors [but chats show that he was aware of this use and did not disapprove, so this is not necessarily a general ruling]

https://www.pcworld.com/article/2452320/tor-exit-node-operat...

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#60

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

Tor was created for intelligence.

So what does the US Navy use now?
Post reply on HN