Live data from Hacker News

Tor is a great sysadmin tool (2020)

jamieweb.net

111–120 of 125 posts

Re: Tor is a great sysadmin tool (2020)

#111
post #66

Earlier quoted context omitted.

It makes me sad every time I think about it, but Aaron Swartz did this during his saga. Well, sort of: he incremented the MAC address by 1. Point being, it's not foolproof. If some clever undergrad is thinking about dodging the suits, win by fooling them, not by fighting them. If you do insist on fighting, though, start at https://www.whonix.org/wiki/Mental_Model and then read the entire Whonix wiki https://www.whoni…

building a new computer. want to be able to trust it 100% for at least a moment. i can't figure out how to "buy" a trusted copy of any linux and don't have any machines i have 100% trust in (who does), so can't burn it. current plan is to buy a chromebook solely for the purpose of downloading and burning ubuntu. alternatively, buy MSWindows, install on the new machine, burn, and then replace but this mental exercise…

You might enjoy reading the "Cypherpunk Desert Bus" story by Peter Todd.

Re: Tor is a great sysadmin tool (2020)

#112
post #94
post #79

Earlier quoted context omitted.

“Policy made my job slightly harder so because I know better than the netsec team who clearly has or should have unlimited time and resources to help me I will do what I want anyways, and put the organization at risk.” Also known as “how to make the netsec team hate you 101” I agree with you about why shadow IT exists, but most IT departments are spread so thin that expecting them to be super responsive to anything b…

> because I know better than the netsec team For anyone who's been around the block a few times, there's a good chance this is true. Most organizations' netsec teams are too busy throwing money at vendors to keep up.

“Because I think I might know better I will act in a disrespectful way, and make someone else’s job harder instead of working with them to solve the problem”

You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this from happening. Nor are you the one who has to clean up the damage if something goes badly.

I also think you’re vastly overestimating the average developers awareness of security issues. Perhaps you are very well versed in this topic, but many developers are utterly clueless, even when it comes to basic application security practices.

Re: Tor is a great sysadmin tool (2020)

#113
post #94

Earlier quoted context omitted.

> because I know better than the netsec team For anyone who's been around the block a few times, there's a good chance this is true. Most organizations' netsec teams are too busy throwing money at vendors to keep up.

“Because I think I might know better I will act in a disrespectful way, and make someone else’s job harder instead of working with them to solve the problem” You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this f…

I'm curious how you think an SSH service exposed over TOR is going to create a security issue? SSH is exposed all over the public internet.

Re: Tor is a great sysadmin tool (2020)

#114
post #48

Earlier quoted context omitted.

Also circumventing this sort of thing in many orgs is a first class ticket to finding a new job. Friend of mine did that, they walked him to the curb with his cardboard box that day. His sin? Turned off virus scanning because it was taking 4 hours to do a 20 min build.

The organization did him a favor. Many other, far more well paying companies response to doing that is working with the developer to figure out a system to make them both happy, or just silently ignoring it until they figure out a better solution. Or just talking to the person and asking them to stop, vs firing.

Took him nearly a year to find a job and had to go on food stamps. I do not think he saw it that way. If you are in some of these smaller markets it can take time to find a job. Especially if you do not live in the area.

Re: Tor is a great sysadmin tool (2020)

#115
post #94

Earlier quoted context omitted.

> because I know better than the netsec team For anyone who's been around the block a few times, there's a good chance this is true. Most organizations' netsec teams are too busy throwing money at vendors to keep up.

“Because I think I might know better I will act in a disrespectful way, and make someone else’s job harder instead of working with them to solve the problem” You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this f…

[deleted]

Re: Tor is a great sysadmin tool (2020)

#116

Earlier quoted context omitted.

“Because I think I might know better I will act in a disrespectful way, and make someone else’s job harder instead of working with them to solve the problem” You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this f…

I'm curious how you think an SSH service exposed over TOR is going to create a security issue? SSH is exposed all over the public internet.

The idea of allowing any kind of inbound connection into a secured network (other than to/via its DMZs) is anathema.

I don't even disagree with the logic, but the BigCorp Infosec Team heavy-handed approach to working with developers invites the developers to produce creative circumventions.

Re: Tor is a great sysadmin tool (2020)

#117
post #20

Earlier quoted context omitted.

Think from the beginning what will be the end: "I thought your security policy was too overbearing, so I used tor." IT departments make their choices for reasons. The key is to help them understand your use-case, and they'll probably help you through the problem in a way that might limit collateral damage. Source: have seen firewall bypasses (with a pre-shared key) get leveraged as a way to hack an entire university…

Especially when, since it's Tor, potential attackers cannot be traced

This.

Re: Tor is a great sysadmin tool (2020)

#118
post #20

Earlier quoted context omitted.

Think from the beginning what will be the end: "I thought your security policy was too overbearing, so I used tor." IT departments make their choices for reasons. The key is to help them understand your use-case, and they'll probably help you through the problem in a way that might limit collateral damage. Source: have seen firewall bypasses (with a pre-shared key) get leveraged as a way to hack an entire university…

Especially when, since it's Tor, potential attackers cannot be traced

This makes no sense. Onion services don't hide the source, they hide the destination -- a destination that, in this threat model, you run. If the client connecting wants to hide their source, they can use Tor, a VPN, an existing botnet, etc.; whether you're running SSH over an onion service or with vanilla exposed IPs/DNS is immaterial.

Re: Tor is a great sysadmin tool (2020)

#119

Earlier quoted context omitted.

at our lab the tor traffic would be noticed by the cyber security group's ids and all traffic from your host would start dropping at the border so fast your head would spin. you'd get an unpleasant phone call or visit to your office and be warned never to try side stepping the bastion ssh hosts that log all the things ever again.

Is tor traffic that easy to detect?

By default Tor doesn't make any attempt to disguise the fact it's Tor traffic. Bridges are unlisted relays, which should work for IP blocking, while Plugable Transports are made to evade censorship-focused traffic analysis (i.e., they will prevent the adversary from detecting and blocking Tor connections as a whole, but not prevent a dedicated adversary from figuring out "has this client been using Tor?").

Re: Tor is a great sysadmin tool (2020)

#120
post #100

Earlier quoted context omitted.

"What did you accomplish during your time with X research group?" "Nothing since all our equipment broke, but we documented how it was all IT's fault. You shoulda seen the looks on their faces when we called them out on it to the dean!"

It seems weird to dump on IT when they’re a department responding to the incentive structure they’re placed under like everyone else. You going to the Dean/someone with actual authority to get top down approval for IT to give you what you want is basically how IT operates in large orgs. I have nigh infinite technical power but in return I am bound politically by polities that I’m explicitly not allowed to have any au…

The parent comment was literally suggesting that GP should have allowed the equipment to fail so that IT could be blamed. I didn't get the impression GP's situation was the result of not bothering to sit down and talk to a higher-up.

Everyone else is responding to incentive structures too, it's no less legitimate for lab workers to circumvent IT due to their incentives than it is for IT workers to be unhelpful due it their incentives.

Post reply on HN