Live data from Hacker News

The FBI Identified a Tor User

vice.com

291–300 of 367 posts

Re: The FBI Identified a Tor User

#291

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

> lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days Schneier himself predicted this in Applied Cryptography in the mid-90's.

Still one of the best foundational texts on the topic!

Re: The FBI Identified a Tor User

#292

Earlier quoted context omitted.

Oh oh I know! 38% the US government, 36% individual donors (people like me), 16% private foundations, 5% other (not US) governments, 9% corporations and 1.5% "other" https://blog.torproject.org/transparency-openness-and-our-20...

exactly. this isn’t to say that US agencies have backdoors written into TOR per se, but they have had TOR delay the patching of exploits in order to achieve the same end

And where is the proof of that?

Just because someone gives money to the Tor Project doesn't mean they get to tell them exactly what to do.

Re: The FBI Identified a Tor User

#293

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

If I were hiding from a state actor I'd use a high-bandwidth communications medium like video. In another life I worked for a large live streaming service, the infrastructure required to process terabits of video is mind-boggling in size, extremely technically challenging, and usually involves custom built ASICs and hardware that's expensive and in short supply.

Even with the NSA's budget and infrastructure, I don't think it's technologically feasible for them to decrypt and then semantically process or store that much content. Video is also the vast majority of traffic on the Internet so it would be trivial to hide in plain sight with some creativity (Using stenography to hide content in the video) With 4k you can pack a ridiculous amount of information into even a single frame, and that's one frame among hundreds of thousands, among billions of videos.

Re: The FBI Identified a Tor User

#294

Earlier quoted context omitted.

>I ran a tor webserver for discussing geopolitics with friends on a pi for a few months before finding it had been compromised. Not the fault of Tor. HSDir nodes could snoop on announced v1 .onion adresses. This isn't the case anymore for Onion v2 addresses. But even if an attacker has the onion address of your webserver, he needs a way to compromise it. Either through a vuln in your website or your webserver.

the malicious process had tor as a parent process/uid. Which makes me say it was definately the tor server that had some rce.

It is really hard to believe that a malicious actor is throwing expensive tor 0-days at random onions.. or your website to "discuss geopolitics with friends" was a bit greater.

In both cases you could run a honeypot to catch 0-days.

Re: The FBI Identified a Tor User

#295

Earlier quoted context omitted.

> the appropriate prior is that you are doing something supremely heinous and evil Generally speaking I can agree but more specifically cases like Julian Assange come to mind. Certainly there are at least some people who are at risk of this kind of persecution and otherwise not doing something that would so immediately be considered in such a negative light.

Reality Winner is probably a better example since she is a US citizen. How about ransomware gangs bricking hospital IT infrastructure? Seems like that is a much more common occurrence than the types of examples you are referring to. Hence the appropriate prior - absent evidence to the contrary - is that someone is doing heinous shit.

Fair points. I appreciate the nuance you bring up.

Re: The FBI Identified a Tor User

#297
post #241

Earlier quoted context omitted.

CIA likely hidden in plain sight so you wouldn't figure out their Tor node. Likely hosted in some DC rest of USA also uses, for example a colo or dedicated at Rackspace. As for Snowden you just described a burner however he would still need to find or know that open WiFi hotspot.

Most coffee shops?

[deleted]

Re: The FBI Identified a Tor User

#298
post #177

Earlier quoted context omitted.

Probably. If you use a laptop once, on a public Wi-Fi hundreds of miles from where you live, while not being caught on surveillance, while using a stripped down privacy based OS, and then route yourself through Tor, you might be okay.

Not if you brought your cellphone on the trip. Or used a car that has a built-in SIM card and cellular modem. Or you bought that laptop from a supplier that registers all MAC addresses of sold devices. Or that laptop had Computrace or some other firmware-based anti-theft mechanism.

[deleted]

Re: The FBI Identified a Tor User

#299

I think a lot of this has been covered elsewhere before: - when using tor you should disable javascript because a malicious or compromised site can use javascript to do non-tor stuff that potentially compromises your location. (can be a big pill to swallow, web without javacript is very 90s) - Run torbrowser within a secure VM or separate device using Tails to minimize your activity footprint - Use a VPN when connect…

> - Use a VPN when connecting to TOR (I also put my TOR services behind their own VPN so even if the entry point is known you can't get the origin IP from it) Has this advice been studied? If everyone uses a VPN you could be reducing network diversity. A single compromised provider could make correlation attacks easier across the entire network. I'm not saying that's certain, but I'm generally skeptical of "hone reme…

… ROT13 is known to be a very insecure method of encryption, therefore you should run it twice on your messages to keep adversaries from reading your secrets.

Unless you’re completely certain it’s impossible for the VPN providers to coordinate, that sounds like a way to short circuit the entire tor infrastructure.

Re: The FBI Identified a Tor User

#300

I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor. Recently this has started getting increasing levels of press exposure[1] including in CSAM cases. The FBI has also continued to run CSAM websites after takeover to collect intel, and likely run honeypots for other content. If your adversary is a state actor, p…

> I have second hand knowledge of lawsuits that have been dropped by the FBI during discovery because it would require them revealing zero days they have on Tor.

Really?

What's stopping them from just lying?

Or claiming they had an anonymous tip?

Post reply on HN