Live data from Hacker News

Hackers breach FSB contractor, expose Tor deanonymization project

zdnet.com

91–100 of 123 posts

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#91

Earlier quoted context omitted.

1. Controlling the exit nodes doesn't mean anything unless they can use it to perform correlation attacks (because TLS, GPG, etc. Exit nodes are considered malicious regardless of who owns them.) 2. Using hidden services obviates the problem of exit nodes.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…

> because timing correlation works great

I have read that research. It works great in a controlled environment without the parallel requests of modern browsers, where packages all arrive in order, and where a high rate of false positives are acceptable. Outside of a lab settings the research gets much more muddy and more speculative that it maybe can be used, but I have yet to see an actually experiment that demonstrate it.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#92

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

Tor was created for intelligence.

"Against", not "for". It was against the enemy being able to get intelligence about communications. And it was also not created for an intelligence agency, in case what's how you meant it. I'm really not sure what you're trying to say here.

If Tor was made for intelligence (agencies), why would anyone ever use it? Makes no sense.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#93

What is the risk of hosting an exit node? I have heard that you can be liable for facilitating illegal actions if yours gets used for it

Hosting an exit node is not illegal (in the United States), and generally you cannot be held liable if the network was used for illegal actions as a consequence of being an exit node and not committed by you (this is not legal advice); however, you have to be able to prove that and it does not necessarily mean you are protected from being investigated, having your door kicked in, and/or your equipment seized.

> being investigated, having your door kicked in, and/or your equipment seized.

True and good to be aware of (upvoted), but I think it is fair to note that this is a very small number of cases. It's not small odds like "win the lottery" odds, but it's also not likely that it'll happen to you. Definitely something to be aware of and plan for (e.g. don't also use that server for important stuff, say, your email and website).

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#94

Earlier quoted context omitted.

Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that. Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up. So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm…

Im guessing that the .gov doesnt run 'many' of the nodes -- but im guessing they have MAPPED them all out and are 0-day exploiting as many as possible. THIS is what I would guess a state entitiy would be training an AI to do as a function...

Its extremely risky to use 0 days in an indiscriminate manner, especially against targets that are likely to be watching closely.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#95

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

I guess one benefit of this is only one country can control a majority of nodes.

Perhaps other countries can use the same vulnerability or point of entry. Either way that one country can tip allies with valuable data.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#96
a) All that article states is that Russian intelligence runs their own servers to scan through the traffic. That isn't a huge threat; only when a party attempts to run a big majority of the entire network, it becomes an issue.

b) There are merely around 7000 servers active. With more funding or contributors, the danger of any single party taking over would quickly diminish. Here's one way you could help: https://www.torservers.net/about.html

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#97

Earlier quoted context omitted.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…

Wouldn't the fact that several huge organizations all try to own as many nodes as possible make Tor safer? If more than one org try to gain the majority, everyones share will be lesser. I highly doubt that FSB and NSA are both agreeing that only one of them should be allowed to host a huge amount of nodes. >The upside is that no government would admit to having this capability Probably because it's very improbable th…

TOR isn't like bitcoin where you have to own N/2+1 nodes, you only have to see the traffic of the first and last node in each connection you care about. That means any one node can belong to more than one organization.

Suppose the NSA has a project to deanonymize TOR, so they set up TOR nodes. To be less conspicuous (TOR node ips are monitored for geographic distribution) they set up small clusters in various locations, one of them an apartment in Amsterdam. The FSB manages to get a double agent that installs software in those nodes to send the same information to Russia. India finds a 0-day exploit and installs their own data-extraction on those nodes as well. Since it's an undercover installation in Amsterdam usual US government rules don't apply and the ISP used uses Huawei networking equipment, giving China a way to listen in as well. Meanwhile the ISP itself is run by Mossad agents specifically to extract dutch traffic for Israeli analysis, and they struck gold with this NSA op choosing them because they are cheap and have no data cap. The ISP routes the traffic to the internet backbone, where most of it will pass through a GCHQ facility on the British coast.

That's 6 different agencies using the same pair of nodes to deanonymize TOR users, without any deliberate data sharing.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#98
post #92

Earlier quoted context omitted.

Tor was created for intelligence.

"Against", not "for". It was against the enemy being able to get intelligence about communications. And it was also not created for an intelligence agency, in case what's how you meant it. I'm really not sure what you're trying to say here. If Tor was made for intelligence (agencies), why would anyone ever use it? Makes no sense.

It was extensively funded by DARPA and the Navy and released to the public so that there would be other users.

I’m not suggesting that the code of Tor is compromised, as it has been under the control of others for years. I am suggesting that military/intelligence interests have been associated with the network from the beginning and no doubt have significant presence in terms of infrastructure, etc.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#99

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

[deleted]

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#100
post #70

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

I was pretty confused, because the title mentions "FSB", but all of this discussion in this thread is about the US. I literally assumed that FSB must be an acronym for some US intelligence agency I don't know of. Then I went and read the article, and it really is about the Russian FSB.

A bunch of the comments are saying multiple governments and using lots of plurals. If you are reading such comments and assuming they only mean US I think you are misreading.
Post reply on HN