Live data from Hacker News

Hackers breach FSB contractor, expose Tor deanonymization project

zdnet.com

71–80 of 123 posts

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#71
post #70

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

I was pretty confused, because the title mentions "FSB", but all of this discussion in this thread is about the US. I literally assumed that FSB must be an acronym for some US intelligence agency I don't know of. Then I went and read the article, and it really is about the Russian FSB.

The majority of people don't read the articles posted, only the titles. Most TLAs are American, so if you don't know what the FSB is then "a US IC org" is a pretty safe guess.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#72

Earlier quoted context omitted.

I guess one benefit of this is only one country can control a majority of nodes.

... What about a group of countries?

I can think of five (or should I say FVEY) that would have the combined means and interest.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#73

> Tax-3 - a project for the creation of a closed intranet to store the information of highly-sensitive state figures, judges, and local administration officials, separate from the rest of the state's IT networks. So, is this intranet used for keeping official (confidential) records or for blackmail purposes?

Probably a way to avoid the massive leak of the names of intel officers when that US gov employment database got leaked. The note about operating outside of the standard state IT network is the obvious indicator.

Part of their job is counter intelligence not just offensive.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#74

It sounds like the attack is not unusual or unknown - they're spinning up malicious nodes then trying to drive traffic to those nodes via DDOS. This is a common technique and unfortunately it's my understanding that aside from increasing the number of good nodes there's not much that can done about it. (Though monitoring for malicious behavior is much better nowadays, so bad nodes will quickly get kicked off the netw…

It said the attacks were detected by a Swedish University.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#75

Earlier quoted context omitted.

Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness. A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes or who can execute unmasking attacks by traffic shaping or monitoring if they control enough relays. For the most part any country which can perform intelligen…

>Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness... For the most part any country which can perform intelligence collection out of its embassy will have sufficient budget and and technical capacity to develop their own secure means of phoning home. The CIA has it's own onion service: ciadotgov4sjwlzihbbgxnqg3xiyrg7so2r2o3lt5wz5ypk4sxyjstad.onion Tor was developed by…

Why would embassies need to be anonymous?

If I needed to design a secure system that didn't need to be anonymous I'd just have it send a HD full of random in a diplomatic pouch & ensure that the packets are sent with encrypted 0s if there isn't anything to say.

And that's only if you think that there isn't a safe pubic key protocol.

Bitcoin's security model relies on public key encryption & there is an extremely large bounty on breaking it. There doesn't seem to be evidence of it being broken yet.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#76

Earlier quoted context omitted.

1. Controlling the exit nodes doesn't mean anything unless they can use it to perform correlation attacks (because TLS, GPG, etc. Exit nodes are considered malicious regardless of who owns them.) 2. Using hidden services obviates the problem of exit nodes.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…

Wouldn't the fact that several huge organizations all try to own as many nodes as possible make Tor safer? If more than one org try to gain the majority, everyones share will be lesser. I highly doubt that FSB and NSA are both agreeing that only one of them should be allowed to host a huge amount of nodes.

>The upside is that no government would admit to having this capability

Probably because it's very improbable that they have the capability to do so.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#77
post #73

> Tax-3 - a project for the creation of a closed intranet to store the information of highly-sensitive state figures, judges, and local administration officials, separate from the rest of the state's IT networks. So, is this intranet used for keeping official (confidential) records or for blackmail purposes?

Probably a way to avoid the massive leak of the names of intel officers when that US gov employment database got leaked. The note about operating outside of the standard state IT network is the obvious indicator. Part of their job is counter intelligence not just offensive.

Counter intelligence is FSB's pretty much the only job. If they do intelligence, it's in CIS (Commonwealth of Independent States) countries such as Belarus or Kazakhstan. It's SVR and GRU that are Russia's intelligence agencies.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#78
post #73

Earlier quoted context omitted.

Probably a way to avoid the massive leak of the names of intel officers when that US gov employment database got leaked. The note about operating outside of the standard state IT network is the obvious indicator. Part of their job is counter intelligence not just offensive.

Counter intelligence is FSB's pretty much the only job. If they do intelligence, it's in CIS (Commonwealth of Independent States) countries such as Belarus or Kazakhstan. It's SVR and GRU that are Russia's intelligence agencies.

Right, same with deanonyming Tor. That’s only useful for catching people/software trying to hide themselves which is more counter intelligence than purely offensive.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#79
hacked into SyTech's Active Directory

Sure, why not? Active Directory doesn't really scream top-secret security to me. Maybe someone with more knowledge can chime in here: Is AD really considered best of breed for what it offers, esp. in terms of security? Or am I not giving it enough credit?

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#80

hacked into SyTech's Active Directory Sure, why not? Active Directory doesn't really scream top-secret security to me. Maybe someone with more knowledge can chime in here: Is AD really considered best of breed for what it offers, esp. in terms of security? Or am I not giving it enough credit?

Is there any better solution for large scale AAA than Kerberos/AD? I think it does the job pretty decently for the large problem that it encompasses.
Post reply on HN