Live data from Hacker News

The FBI Identified a Tor User

vice.com

111–120 of 367 posts

Re: The FBI Identified a Tor User

#111
post #78

Earlier quoted context omitted.

After reading Edward Snowden's autobiography (Permanent Record, great read), I feel like Tor, end-to-end encryption and similar solutions/products are basically a dagger through the heart of intelligence services. As such, I find it hard to believe that they knowingly gave the public such tools. And if they did, it sure as hell backfired on them.

Tor was developed by the US Navy. The military understands how crucial encrypted messaging is, and doesn't particularly care whether or not it's a dagger through the heart of other TLAs. In a bureaucratic battle between the military and domestic intelligence agencies, the military wins.

And additionally funded by the US State Department to provide anonymity for users seeking political expression in countries where that expression may be dangerous.

Re: The FBI Identified a Tor User

#112
post #42

Earlier quoted context omitted.

So you did illegal things illegally. Yep. I said I don't understand people who do illegal things over their own connection, i.e., stupidly. And who owned the public AP? McDonald's.

McDonald's has video cameras pointing at every inch of their property 24/7. All they need is a timestamp from the AP and they'll go find your license plate in the parking lot on the surveillance tapes.

What kind of idiot drives a car with a valid personal license plate while committing crime?

I don't even drive a car when I'm selling shit on craigslist for fear they'll look up the plate and do dumb shit when they're mad the drill I sold them has normal battery life.

Re: The FBI Identified a Tor User

#113

Earlier quoted context omitted.

After reading Edward Snowden's autobiography (Permanent Record, great read), I feel like Tor, end-to-end encryption and similar solutions/products are basically a dagger through the heart of intelligence services. As such, I find it hard to believe that they knowingly gave the public such tools. And if they did, it sure as hell backfired on them.

BBC which is run by BritishIntel Services, one of the very first things that they did when the war in Ukraine exploded was to set up many new TOR nodes But yeah, TOR is certainly a double edged sword, but I am led to believe that they assess that it's offensive capabilities to pierce against Anglo-Oligarchy enemies offsets the drawbacks it produces on how they themselves deal with homefront dissidents My take is that…

As long as Ukraine exists, the Darknet has free roam to proliferate with US's half-baked OKAY'ing.

It is sharpest triple-edged sword in modern intelligence existence.

Re: The FBI Identified a Tor User

#114
post #3

Original article this is referencing: https://www.vice.com/en/article/z34dx3/fbi-wont-say-hacked-d... And the relevant court document: https://www.documentcloud.org/documents/23569961-motion-to-r...

Even leaving aside the question of whether the FBI actually compromised Tor, or just did something way more mundane like infect the defendant's PC with malware, the linked court document is really interesting.

Not only does the FBI decline to say how they determined what IP address the defendant used to access the Tor hidden service, but they're also trying to hide the fact that the defendant asked to see that information by requesting the court label the defendant's court filing itself a "highly sensitive document"? And the court granted that request? Is that normal? It seems really bizarre to me, but I'm not a lawyer.

Re: The FBI Identified a Tor User

#115

Earlier quoted context omitted.

I would not be surprised given that Tor was specifically created to anonymize the traffic of US spies. It was released to the public to give plausible deniability to the spies. A new protocol that ONLY spies used would be obvious to track down, no matter how much encryption it had. But if everyone is using it for different purposes then you have to actually have to break the encryption to know if someone's using Tor…

After reading Edward Snowden's autobiography (Permanent Record, great read), I feel like Tor, end-to-end encryption and similar solutions/products are basically a dagger through the heart of intelligence services. As such, I find it hard to believe that they knowingly gave the public such tools. And if they did, it sure as hell backfired on them.

E2E and onion routing are potentially problematic -- if they aren't compromised by the government. When controlled by the government, they can lull the targets of government surveillance into a false sense of security. For instance, the government-run Anom[0] network that was completely compromised, but claimed E2E encryption. I wouldn't exactly call it a dagger through the heart of government sigint activity.

0 - https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted...

Re: The FBI Identified a Tor User

#117

Earlier quoted context omitted.

McDonald's has video cameras pointing at every inch of their property 24/7. All they need is a timestamp from the AP and they'll go find your license plate in the parking lot on the surveillance tapes.

What kind of idiot drives a car with a valid personal license plate while committing crime? I don't even drive a car when I'm selling shit on craigslist for fear they'll look up the plate and do dumb shit when they're mad the drill I sold them has normal battery life.

I would ask what kind of idiot drives with an invalid license plate

Re: The FBI Identified a Tor User

#118

Earlier quoted context omitted.

> Based on what little I know of SSL, this suggests the server was compromised too? Not necessarily. If a passive snooper knows I used Tor Browser to make an SSL request to en.wikipedia.org and received 987,654 bytes then immediately made a SSL request to upload.wikimedia.org and received 1,234,567 bytes that might be enough information to work out I visited https://en.wikipedia.org/wiki/National_Security_Agency .

BRB, padding all of my webpages to be exactly 650mb each.

[deleted]

Re: The FBI Identified a Tor User

#119

Earlier quoted context omitted.

Parallel construction. They use their real methods to identify the user, then once they know the user, specifically target them with simpler known methods to build evidence for the case. In the court filing, they present evidence that they've gained through known methods which don't work all that well unless you already have a suspect, but they actually caught the suspect using methods that are not public (and won't…

Is there proof of anything like this or is it just a conspiracy theory you’re peddling?

Parallel construction is not a theory in any way in the US. It is a "decades old, a bedrock concept" according to the DEA.

Outside the US, I have no idea.

Re: The FBI Identified a Tor User

#120
Tor Browser by default it's useless, as it enables Javascript. Links+ with 127.0.0.1:9050 as the Socks4a proxy, enforcing everything connected into proxies (it has a setting for TOR) and not allowing cookies would be a safer option.
Post reply on HN