Live data from Hacker News

Tor: From the Dark Web to the Future of Privacy

direct.mit.edu

51–60 of 100 posts

Re: Tor: From the Dark Web to the Future of Privacy

#51
I don't think much of this writing style. What's the tor attack surface? Are all the tor boxes on the internet backdoored by the NSA? Is tor a honeypot or is tor not a honeypot?

As far as I can tell tor was designed by spooks to allow remote agents operating in foreign countries a means to communicate with headquarters without being traced. It was never designed to allow two entities to communicate anonymously. The metadata always gets exposed, doesn't it?

Using tor also violates the hide in plain view principle, which all real spooks adhere to religiously.

Re: Tor: From the Dark Web to the Future of Privacy

#52
post #49

Earlier quoted context omitted.

I mean, bitcoin is a lot more anonymous if you host your own wallet and don't cash out through an exchange (or don't cash out at all) - you're just a number. That's definitely not the modal use case today (where its primary use is as a vehicle for ~~gambling~~financial speculation denominated in dollars), but was a lot more common 10 years ago when that project was created.

Or you just use a crypto currency with anonymity build in.

Sure, but that was probably pretty hard to do ten years ago when this was being developed, because, y'know, Monero didn't exist yet (or had only existed for a few months and had no users)

Also, bitcoin actually was more private back then, because KYC rules were much more lax.

Re: Tor: From the Dark Web to the Future of Privacy

#53

Earlier quoted context omitted.

There's a lot in the book about this - it depends what you mean. Tor has a lot of social and technical design elements that try as best they can to minimise this risk. It would be pretty hard for intelligence services to compromise the Tor organisation in ways that meant they were deploying malicious code, for example. Plus, the way it's grown over the years has also given them some protections. In terms of deanonymi…

The scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.

"don't become an enemy of the state" is my go-to security posture

Re: Tor: From the Dark Web to the Future of Privacy

#54
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

There are no incentives. I'm pretty sure the vast majority does it for altruistic reasons. At least all those I've met. Many run relays with spare resources they pay for anyway. Others rent a cheap VPS to run a relay. $10 gives you a surprisingly large amount of bandwidth if you avoid the cloud like the plague. Governments have other possibilities. Why should they run a relay if they can force the ISP to mirror the t…

Can you expand on that last bit? I don’t understand how this compromises the entire network or any individual user. The ISPs only have layer 3 data in plaintext. We can perform timing/throughput analysis attacks against individuals, but not the entire network. These operations are VERY expensive/difficult.

Re: Tor: From the Dark Web to the Future of Privacy

#55
post #54

Earlier quoted context omitted.

There are no incentives. I'm pretty sure the vast majority does it for altruistic reasons. At least all those I've met. Many run relays with spare resources they pay for anyway. Others rent a cheap VPS to run a relay. $10 gives you a surprisingly large amount of bandwidth if you avoid the cloud like the plague. Governments have other possibilities. Why should they run a relay if they can force the ISP to mirror the t…

Can you expand on that last bit? I don’t understand how this compromises the entire network or any individual user. The ISPs only have layer 3 data in plaintext. We can perform timing/throughput analysis attacks against individuals, but not the entire network. These operations are VERY expensive/difficult.

Not an expert at all but from my understanding a traffic correlation attack doesn't require someone to run the relay he just needs to see what traffic enters and leaves it. So the German BND for example can just go to Hetzner (15% Tor traffic) and ask them to mirror the traffic of all relays to them. They don't have to run any relays themselves.

Alt227 has a point but the Tor network is centered around a handful countries where traffic is cheap and there aren't that many huge IXs and Tier 1 ISPs where much of the traffic flows through.

I'm not saying that this is done but it's IMHO more likely than state actors running thousands of relays.

Re: Tor: From the Dark Web to the Future of Privacy

#56

Earlier quoted context omitted.

What are your thoughts on the integrity of the network against state actors?

There's a lot in the book about this - it depends what you mean. Tor has a lot of social and technical design elements that try as best they can to minimise this risk. It would be pretty hard for intelligence services to compromise the Tor organisation in ways that meant they were deploying malicious code, for example. Plus, the way it's grown over the years has also given them some protections. In terms of deanonymi…

[deleted]

Re: Tor: From the Dark Web to the Future of Privacy

#57
post #54

Earlier quoted context omitted.

Can you expand on that last bit? I don’t understand how this compromises the entire network or any individual user. The ISPs only have layer 3 data in plaintext. We can perform timing/throughput analysis attacks against individuals, but not the entire network. These operations are VERY expensive/difficult.

Not an expert at all but from my understanding a traffic correlation attack doesn't require someone to run the relay he just needs to see what traffic enters and leaves it. So the German BND for example can just go to Hetzner (15% Tor traffic) and ask them to mirror the traffic of all relays to them. They don't have to run any relays themselves. Alt227 has a point but the Tor network is centered around a handful coun…

I think we have the same understanding. I read this as

“a state actor has the physical capabilities/resources to perform an attack that determines Alice was speaking to Bob.”

I totally agree. Im just pointing out that we still have layer 5 encryption to protect the contents of our messages. Also at that point, if you’re so important they would just grab a warrant and raid your home.

Re: Tor: From the Dark Web to the Future of Privacy

#58

Earlier quoted context omitted.

The scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.

"don't become an enemy of the state" is my go-to security posture

same, though there are ppl that become so by chance or occupation

Re: Tor: From the Dark Web to the Future of Privacy

#59
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

> What are the incentives for running a node? It costs my ISP resources but I pay a flat rate. That would have value to me.

if enough customers of the ISP do this, they will no longer charge a flat rate. It's just that some people manage to consume resources that other customers don't atm.

Re: Tor: From the Dark Web to the Future of Privacy

#60

Earlier quoted context omitted.

Also - it's completely free open access, but you can also buy a copy here if you like spending money: https://mitpress.mit.edu/9780262548182/tor/

> it's completely free open access Why are the PDFs individually watermarked? It seems antithetical to the spirit of releasing a book about Tor and "future of privacy", and to then not only watermark each PDF, but to not explicitly state that this is the case, let alone explain why.

I agree it seems a bit scummy, yet likely unavoidable for the author due to the way MIT Press distributes things.

It's thankfully licensed under Creative Commons Attribution-NonCommercial-NoDerivatives 4.0, which allows for converting the content to other formats (given attribution and non-commercial use, same license, etc etc) [0]. I'd reckon that making a de-fingerprinted version and redistributing it as an epub, md, or pdf again would be allowed, then.

As for getting a clean copy to work from, using Tor would be quite fitting. I plan to convert the version I downloaded to epub for ereader use, maybe downloading it a couple times over different routes and combining to see if that has any impact on the fingerprinting. I'll comment with a download if I get to that and feel it's of a quality worth sharing.

0: https://creativecommons.org/licenses/by-nc-nd/4.0/deed.en#re...

Post reply on HN