Live data from Hacker News

Hackers breach FSB contractor, expose Tor deanonymization project

zdnet.com

121–123 of 123 posts

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#121

Earlier quoted context omitted.

Is there any better solution for large scale AAA than Kerberos/AD? I think it does the job pretty decently for the large problem that it encompasses.

Maybe I'm just judging too much from personal experience working under a system that may be poorly implemented.

You are partially not wrong. I think the real issue is that MSFT AD is so bloody point-and-click-and-go easy to stand up that a lot of orgs didn't ever put any proper thought or design into it. Just "go" now and figure it out later (when we get owned).

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#122
post #40

Earlier quoted context omitted.

A custom protocol can potentially be fingerprinted. I wouldn't be surprised if they used something less sophisticated. Like (encrypted) direct messages on twitter/reddit/facebook. This way the traffic blends with the rest.

It doesn't need to be a completely custom protocol. HTTPS can handle a very large percentage of anyone's communication needs these days.

An application level protocol implemented on top of HTTPS can be fingerprinted. If you look up "Website Traffic Fingerprinting" you will see what I mean. That traffic is encrypted.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#123

Earlier quoted context omitted.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…

Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that. Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up. So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm…

> Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that.

Even in the richest parts (relevant because they love forbidding things) of the EU you can find hosters that accept tor exit nodes. As for it being dangerous, that is kind of a spurious argument. Why do you think it is dangerous? Do you know because you tried, or do you "know" because you heard someone tell you it was?

Post reply on HN