Live data from Hacker News

The FBI Identified a Tor User

vice.com

231–240 of 367 posts

Re: The FBI Identified a Tor User

#231

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

According to various sources, such as Snowden's "Permanent Record", the tor network was designed to allow spies in remote locations to communicate securely with a known endpoint (such as CIA headquarters) without anyone being able to easily trace their exact location. The content of the communication itself would not be readable due to strong encryption, but the metadata (source and destination headers) could reveal who was talking to who.

However, nation-states with enough backdoors to all the servers serving as tor jumpboxes could likely deanonymize the remote user (it's assumed they'd be watching all traffic going to and from the known endpoint, which in Snowden's case was a journalist's email server).

Snowden's method IIRC was to acquire a laptop or phone without leaving any identifying marks (ownership information), then drive around until he found an open wireless network which he could log onto, then he'd use that network over tor to connect to the journalists he was talking to. The device was used for no other purpose, never turned on and connected to his home network, etc.

There doesn't seem to be any way for two anonymous parties to find and connect with each other across tor in this manner however, without having some other side channel to coordinate time and place and exchange identifying information.

You can still hide the content of communication using PGP-style strong encryption, but even then, it's likely that keys could be compromised in some manner.

Re: The FBI Identified a Tor User

#232

I think a lot of this has been covered elsewhere before: - when using tor you should disable javascript because a malicious or compromised site can use javascript to do non-tor stuff that potentially compromises your location. (can be a big pill to swallow, web without javacript is very 90s) - Run torbrowser within a secure VM or separate device using Tails to minimize your activity footprint - Use a VPN when connect…

Firefox supports proxy via unix domain socket and tor daemon supports unix sockets too, so you can setup torbrowser in a VM/container without any network access to add additional safety against leaks. The sole communication channel to the tor daemon via unix socket(s). For vm, use virtfs/9p to share between the daemon and browser, for container just bind mount it. To allow torbrowser to control the tor daemon, you can use socat as a proxy over an additional unix socket since tor's control port does not directly support using a unix socket.

The whonix project has good info on the environment variables you will need to set to get the torbrowser to play nice with an external tor daemon, so you do not need to resort to tor over tor which will make your traffic stand out.

https://github.com/Whonix/anon-ws-disable-stacked-tor/blob/m...

IMO, torbrowser, on platforms that support it, should separate daemon and browser by default, with browser in a separate network namespace with no network interfaces.

But, if zero day in tordaemon, and your adversary is US gov't or other well resourced organization, it is probably still game over. Not to mention NSA scale traffic analysis that Schneier seems to be suggesting as a possibility here, which can only be defended against by only using Internet access that can never be tracked back to you. For downloading bookwares off libgen, the above mitigation is probably sufficient, though, if not a bit overkill.

Re: The FBI Identified a Tor User

#233

Earlier quoted context omitted.

I would not be surprised given that Tor was specifically created to anonymize the traffic of US spies. It was released to the public to give plausible deniability to the spies. A new protocol that ONLY spies used would be obvious to track down, no matter how much encryption it had. But if everyone is using it for different purposes then you have to actually have to break the encryption to know if someone's using Tor…

After reading Edward Snowden's autobiography (Permanent Record, great read), I feel like Tor, end-to-end encryption and similar solutions/products are basically a dagger through the heart of intelligence services. As such, I find it hard to believe that they knowingly gave the public such tools. And if they did, it sure as hell backfired on them.

> After reading Edward Snowden's autobiography (Permanent Record, great read), I feel like Tor, end-to-end encryption and similar solutions/products are basically a dagger through the heart of intelligence services. As such, I find it hard to believe that they knowingly gave the public such tools. And if they did, it sure as hell backfired on them.

I have heard it somewhere but using Tor or end-to-end is like using armoured car to transport money between park bench and cardboard box. If someone wants you compromised, you will get compromised, it only matters how many resources they are willing to throw at you. And for average person, it's not a lot. So best way is to blend in. And using Tor, end-to-end, VPN(full of people with something to hide, it would be stupid not to infiltrate or honeypot) will make you stand out, you might even peek someone's curiosity. Not a very healthy way to operate on the Internet...

Re: The FBI Identified a Tor User

#235

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

> If you're sitting in front of a computer that you're using for something the U.S. government has significant interest in prosecuting, that device should be considered compromised and adversarial - you should act accordingly. I would say that if you are doing something the US government has a significant interest in prosecuting, you might want to reevaluate your life choices and think about whether it is something y…

https://247wallst.com/wp-content/uploads/2023/01/Martin-Luth...

Re: The FBI Identified a Tor User

#236
post #212

Earlier quoted context omitted.

Parallel construction is illegal. Why do we tolerate government corruption at the highest levels of law enforcement?

I don’t think this is true unless the original evidence was obtained in violation of the fourth amendment, which zero days are not necessarily. You’re right though using parallel construction to launder prohibited search is illegal.

Why wouldn't parallel construction be perjury, even if the real search was legal?

Re: The FBI Identified a Tor User

#237
post #110

Earlier quoted context omitted.

> If you're sitting in front of a computer that you're using for something the U.S. government has significant interest in prosecuting, that device should be considered compromised and adversarial - you should act accordingly. Yep: stop breaking the law. The vast majority the US government has significant interest in prosecuting, the general public is OK with.

Lol if you don't want to be fucked with by the government, just don't break the law! Unfortunately that doesn't work. Sometimes legal activities are best kept under wraps. I have a signed and executed federal search warrant in my drawer. I was tossed in a cell. I was dragged to a hospital. I was sent the bill for the "search" and am currently being hounded by debt collectors. Nothing was found and I did nothing wrong…

I'm sorry to hear that. I'd like to think that is a rare exception, not the rule. It certainly isn't what I experienced when I entered the USA as a foreigner (with a DAP and Sharp Zaurus which didn't get checked either back in 2005). I know there's an issue of discrimination among police; it is something we (society) need to combat.

Re: The FBI Identified a Tor User

#238
post #177

Earlier quoted context omitted.

Probably. If you use a laptop once, on a public Wi-Fi hundreds of miles from where you live, while not being caught on surveillance, while using a stripped down privacy based OS, and then route yourself through Tor, you might be okay.

Not if you brought your cellphone on the trip. Or used a car that has a built-in SIM card and cellular modem. Or you bought that laptop from a supplier that registers all MAC addresses of sold devices. Or that laptop had Computrace or some other firmware-based anti-theft mechanism.

Even if you had a car without a cell connection, license plate readers and cameras make it easy for anyone with access to replay and reverse any traveling you do with any car.

Re: The FBI Identified a Tor User

#239

Earlier quoted context omitted.

The most paranoid plan i have come up with: - tor + cubesOS set up by somebody you deeply trust (person A) - on a USB bought by a different person (person B) - with a network card bought by a different person (person C) - many miles away, wearing generic clothes in a cafe where people go to work - different hairstyle and facial hair - mask - without having a phone (obv) - navigating there by changing multiple cars wi…

> - ordering the most boring coffee The fatal flaw in the plan: Barista talking to news after person is arrested by FBI: "As soon as they ordered the brewed coffee with no customizations after standing in line for 10 minutes, I knew something was suspicious. Who comes to Starbucks, stands in line for 10 minutes, and then orders boring coffee?"

I do! I like my coffee straight up and if I want coffee, will stand in line for 10 minutes for it.
Post reply on HN