Live data from Hacker News

The FBI Identified a Tor User

vice.com

41–50 of 367 posts

Re: The FBI Identified a Tor User

#41
I keep saying this, but the inescapable fact about Tor is that its traffic patterns make you stand out prominently.

Just the fact you’re using it automatically makes you interesting and worthy of a closer look.

All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?

Re: The FBI Identified a Tor User

#42
post #26

I will never understand people who do illegal things over their own IP. Is it really that hard to find an open access point? Way back in the day when I torrented all my content I used a long-range wifi antenna connected to a public AP and a dedicated PC with a scrubbed drive that never connected to my home network.

So you did illegal things illegally. And who owned the public AP? Someone not as smart as you? You sure?

So you did illegal things illegally.

Yep. I said I don't understand people who do illegal things over their own connection, i.e., stupidly.

And who owned the public AP?

McDonald's.

Re: The FBI Identified a Tor User

#43

I keep saying this, but the inescapable fact about Tor is that its traffic patterns make you stand out prominently. Just the fact you’re using it automatically makes you interesting and worthy of a closer look. All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?

Is your intention in repeating that to keep Tor usage below the critical threshold where that remains true?

Re: The FBI Identified a Tor User

#44

I wouldn't get so excited about this. There have been tons of javascript exploits to leak IP addresses in the past, it's more likely that than the FBI running thousands of servers.

Or even something way simpler, like the FBI secretly compromising the user's PC with malware prior to the arrest. Without more detail it's impossible to know whether this is even news.

Re: The FBI Identified a Tor User

#45

The feds run all the entrance and exit nodes. Tor was created by the feds for spies to use, then they made it public yo hide the traffic. This is the official story that everyone has evidently forgotten.

Well, not all the exit nodes by now. But many of them.

Most people are probably leery of running an exit node, because its traffic is in the clear (modulo ssh) and often connects to disparate and shady servers.

Re: The FBI Identified a Tor User

#47
post #25

Earlier quoted context omitted.

Direct link to the PDF (because DocumentCloud's web viewer appears to be down): https://s3.documentcloud.org/documents/23569961/motion-to-re...

Seems like this is a case of the government saying "trust us". They noted two ways that the feds could have gotten the IP address but how about a third, they targeted the guy and got the IP address from the ISP and said "look!, we found our guy" -occams razor.

Wouldn't they need to know who he is before they could target him and acquire his IP? Unless your suggesting parallel construction?

Re: The FBI Identified a Tor User

#48

Earlier quoted context omitted.

> The FBI also found what specific pages Al-Azhari visited, including a section on donating Bitcoin; another focused on military operations conducted by ISIS fighters in Iraq, Syria, and Nigeria; and another page that provided links to material from ISIS’s media arm Based on what little I know of SSL, this suggests the server was compromised too? Or does tor do a bad job of certificate pinning? Edit: Or the clients a…

> Based on what little I know of SSL, this suggests the server was compromised too? Not necessarily. If a passive snooper knows I used Tor Browser to make an SSL request to en.wikipedia.org and received 987,654 bytes then immediately made a SSL request to upload.wikimedia.org and received 1,234,567 bytes that might be enough information to work out I visited https://en.wikipedia.org/wiki/National_Security_Agency .

BRB, padding all of my webpages to be exactly 650mb each.

Re: The FBI Identified a Tor User

#49
post #13

Earlier quoted context omitted.

If you control both exit and entrance nodes, you can corralate connections with a timing analysis.

I don't think that is how timing analisis works. User can say to "entrance node" that it is also a node and that is how it can deny that it is originator. "Entrance node" doesn't know its position in a chain. Only Exit node knows its position.

It is a volume+timing attack. From 2014:

https://www.bbc.com/news/technology-28573625

"The Tor Project suggests the perpetrator compromised the network via a "traffic confirmation attack".

This involves the attacker controlling both the first part of the circuit of nodes involved - known as the "entry relay" - as well as the exit relay.

By matching the volumes and timings of the data sent at one end of the circuit to those received at the other end, it becomes possible to reveal the Tor user's identity because the computer used as an entry relay will have logged their internet protocol (IP) address."

Re: The FBI Identified a Tor User

#50

I wouldn't get so excited about this. There have been tons of javascript exploits to leak IP addresses in the past, it's more likely that than the FBI running thousands of servers.

Doesn't the tor browser disable javascript entirely?

The user can enable javascript.
Post reply on HN