Live data from Hacker News

LulzSec: 50 Days of Lulz statement

pastebin.com

91–97 of 97 posts

Re: LulzSec: 50 Days of Lulz statement

#91
post #26

Earlier quoted context omitted.

Even if authorities were able to track down someone through TOR, I doubt they'd publish it. More easy to let black hats think they are safe.

If you are interested in some hypothetical pondering about how secure Tor is not, here's some food for thought: http://sheddingbikes.com/posts/1293530004.html

There's a lot to be said about super-node pattern analysis with TOR, as well as the flaws in the exit nodes with regard to unencrypted communications, but I couldn't get past the fact that Zed's entire post was a massive Godwin.

Re: LulzSec: 50 Days of Lulz statement

#92
post #91

Earlier quoted context omitted.

If you are interested in some hypothetical pondering about how secure Tor is not, here's some food for thought: http://sheddingbikes.com/posts/1293530004.html

There's a lot to be said about super-node pattern analysis with TOR, as well as the flaws in the exit nodes with regard to unencrypted communications, but I couldn't get past the fact that Zed's entire post was a massive Godwin.

Zed will be Zed.

Re: LulzSec: 50 Days of Lulz statement

#93
post #26

Earlier quoted context omitted.

Even if authorities were able to track down someone through TOR, I doubt they'd publish it. More easy to let black hats think they are safe.

If you are interested in some hypothetical pondering about how secure Tor is not, here's some food for thought: http://sheddingbikes.com/posts/1293530004.html

Addressing his points one by one (quotation marks should in no way be thought of as referring to a quote):

"The Navy made it, why'd they release it?"

-They released it because it's entirely useless if the military are the only ones using it.

"It's not theoretically effective. There's lots of ways to break it."

-Sure, there have been papers written about ways to break TOR. I've yet to see someone actually do it. That doesn't mean the NSA or whoever isn't doing it, but you'd think if someone had compromised the system you'd see some story about it. Somebody who was using TOR would have been tracked down and they would have thought, "hey, wait a minute..."

"Project Vigilant"

-Meh. Again, if they compromised TOR, you'd hear about it. They'd have given the IPs of hidden wiki visitors to the feds, and some pedo would have been arrested. If PV don't care about pedos, they would have given the feds some information about somebody that would have led to some sort of action. The fact that none of this has come to light is pretty strong evidence that PV has not compromised TOR.

"Wikileaks uses TOR"

-So the fuck what? They have a pretty clear use case, and the fact that ioerror is a contributor means he's concerned about anonymity (for obvious reasons), not that Wikileaks has hatched a plot to snoop on anonymized traffic and leak details. Why the hell would they bother? They've got more than enough stuff to leak handed to them. What are the chances that someone using TOR would be transmitting data that WL would care about?

This is just stream-of-consciousness FUD from Zed, of the type we're used to seeing from him. He throws out a bunch of what ifs and pretends it's an argument. Show me the evidence. Show me some indication that TOR has been breached and I'll be the first one to question whether it should be used. In the meantime, TOR is only getting more secure as more people talk about it and use it.

Re: LulzSec: 50 Days of Lulz statement

#94
post #72

Earlier quoted context omitted.

This mirrors an idea that I had. TOR is a military project, and you know at least some of the exit nodes are controlled by the US gov't. Why not replicate TOR with a botnet? Bounce your communications around a plethora of average joes and you have yourself a more stable tor. If you spread the botnet without a CnC server and have the infected machines bounce random traffic around, it would be damned difficult to break…

> you know at least some of the exit nodes are controlled by the US gov't http://www.google.com/search?q=high+traffic+colluding+tor+ro...

http://www.boingboing.net/2007/05/17/report_hightraffic_c.ht...

Re: LulzSec: 50 Days of Lulz statement

#95
post #72

Earlier quoted context omitted.

> you know at least some of the exit nodes are controlled by the US gov't http://www.google.com/search?q=high+traffic+colluding+tor+ro...

http://www.boingboing.net/2007/05/17/report_hightraffic_c.ht...

Oh, neat. I didn't realise the issue had been resolved. Thanks.

Re: LulzSec: 50 Days of Lulz statement

#96
post #40

Earlier quoted context omitted.

What do you mean by large projects? The size of the files they transfer? Your machine -> TOR -> hacked home user or server -> your target. This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too. Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quick…

This mirrors an idea that I had. TOR is a military project, and you know at least some of the exit nodes are controlled by the US gov't. Why not replicate TOR with a botnet? Bounce your communications around a plethora of average joes and you have yourself a more stable tor. If you spread the botnet without a CnC server and have the infected machines bounce random traffic around, it would be damned difficult to break…

http://www.youtube.com/watch?v=v7nfN4bOOQI

People do run their own private onions.

Re: LulzSec: 50 Days of Lulz statement

#97
post #64

Damn, the AT&T-release is especially juicy. It contains a lot of highly confidential information about technology and strategy that their competitors would love to get their hands on. I'm a quite technical guy and I barely understand a thing. No wonders AT&T are having troubles with fixing their network troubles, it looks like a massive, massive beast of technology. I found the frequency chart fascinating. It's avail…

Given the juiciness of this, I'm surprised that more companies don't have corp espionage groups to carry out little lulsec attacks.

Based on the HBGary leak, I'd say that they currently do.
Post reply on HN