Live data from Hacker News

Tor Browser 10

blog.torproject.org

41–50 of 106 posts

Re: Tor Browser 10

#42
post #5

What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.

It depends on how you use Tor. For browsing you will essentially remain anonymous forever unless you do something that can connect you between sessions, like logging into some user account. This excludes side-channel attacks and an adverse which controls a large number of nodes, or is able to listen to a lot of the global network traffic.

It's different for people who operates hidden services. They are always online, and it is easy to tie one session to another, because the session will always be tied to the service they are running. This means that over time, you will be able to identify the service even with control over a small subset of services. You can read more about the different ways this can be done here: https://www.hackerfactor.com/blog/index.php?/archives/896-To...

Re: Tor Browser 10

#43
post #19
post #5

What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.

For users wanting to prevent their ISP from sniffing around then tor works as intended. Against advertisers it also work decently as a self cleaning browsers that constantly change its IP address. For developers and sysadmins that want to get an outside look at their own services or investigate third party websites (like fraudulent lookalike) it work pretty effective with some caveats. It also works mostly fine again…

>> It is not recommended by anyone to depend on tor against that threat model.

That depends as much on the use case as the threat. Traffic analysis attacks require traffic. Short burst communication via tor (chat/email/bot control commands etc) are not traced as easily as large file downloads or random web browsing. Attacks on the client (malware) are also very hardware dependant. A target using the same Tor client on the same hardware regularly is a softer target than someone connecting randomly via a variety of devices.

The NSA (Or FSB/FBI/CIA et al) are not SHIELD. They operate in the realworld with realworld physics/math. If they did have reliable and simple backdoors into Tor we would have heard about them by now.

Re: Tor Browser 10

#44
post #5

What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.

It seems to me that most de-anonymizing attacks used human operating errors, physical attacks like snatching a laptop with an open tor browser window from a user, or side-channel attacks based on malware like Finfisher.

Running it from Tails seems pretty secure...but, in the end, who does that consistently?

Re: Tor Browser 10

#45
post #32

Earlier quoted context omitted.

I'm working for a big international project and our most important website is running fucking SSL 3.0 I reported it one year ago, and it hasn't been fixed yet. Many people are having problems connecting now, because browsers are removing support. The server is hosted in Germany, which really amuses me given their reputation for good engineering...

That reputation comes from cars and machines, not from software. Germany is one of the worst places for anything digital.

That's unfortunately so true. The thorough and strongly regulated engineering results in good quality for mechanical products, but is detrimental for the fast paced software world. SSL3.0 is from 1996. That's the life cycle of 2-3 cars and much less than a building, so "not a long time ago" in engineering terms "when it still works".

I joined a German engineering company and made the naive assumption that proficiency in engineering is correlated to proficiency in software engineering. I will not make that mistake again.

The reality is that the classical engineering disciplines (mechanical, civil, etc.) and software engineering are very different in practice. While waterfall/V model is discouraged in software, it's a very valid approach for physical goods with high iteration costs and nearly no option of upgrade after sale.

Re: Tor Browser 10

#46
post #19
post #5

What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.

For users wanting to prevent their ISP from sniffing around then tor works as intended. Against advertisers it also work decently as a self cleaning browsers that constantly change its IP address. For developers and sysadmins that want to get an outside look at their own services or investigate third party websites (like fraudulent lookalike) it work pretty effective with some caveats. It also works mostly fine again…

> Against national-level intelligence agency, "citizen scores", and whistleblowers employed within such agencies, the protection granted by tor may be very far from 100%. It is not recommended by anyone to depend on tor against that threat model.

Are there any alternatives then, that do work against this threat model? It seems like a lot of the real need for such a tool is for journalists and activists who do need protection against national-level threat actors.

Re: Tor Browser 10

#47
post #18
post #7

Earlier quoted context omitted.

I think it remains the best in class for private browsing. They have to make difficult trade-offs that achieve acceptable levels of performance while not leaking metadata like a sieve. They do also have a good track record of handling security vulnerabilities. For the average user, the greatest threat is actually everything outside the Tor browser. For example, downloading certain files using Tor, then opening it in…

There are some ways to mitigate some of the threats that you mention. Using Qubes or Whonix could prevent network access to other programs. The unencrypted requests can be blocked by turning on the EASE option in the HTTPS-Everywhere preferences. Tor doesn't have any way to protect against global adversaries performing timing analysis or attacks though.

Yeah I'm surprised HTTPSEverywhere with EASE isn't a part of the Tor browser. Maybe a contributor on here can comment?

Re: Tor Browser 10

#48
post #5

What's the current status of Tor? I remember seeing in the past many de-anonymizing attacks against it.

According to at least one person, not very promising.

https://www.hackerfactor.com/blog/index.php?/archives/896-To...

About 13 years ago, another researcher identified some suspicious patterns on the network.

https://web.archive.org/web/20070618001928/http://jadeserpen...

Also, it just doesn't seem very likely that the US DoD would fund a network which defeats their own surveillance efforts.

Being "anonymous" online is more a question of being anonymous from who's perspective. Fooling a sysadmin is easy. Fooling an ISP is hard. Fooling an NSA contractor is probably near impossible. I think you can achieve reasonable plausible deniability with enough inconvenience, though. Get rid of your smartphone, compartmentalize your activity, never enable JS, use public wifi, spoof your MAC, make a tinfoil hat, etc.

Re: Tor Browser 10

#49
If my adversary was a state, I'd be seriously worried that the act of downloading Tor is monitored and would put me as a potential threat.

Re: Tor Browser 10

#50
post #33

Earlier quoted context omitted.

Danes are the proud people who inhabit the Kingdom of Denmark.

Why are people always called "proud people"? Are there no people embarrassed of their country?

USA/Californian checking in. Embarrassed.
Post reply on HN