Live data from Hacker News

Tor: From the Dark Web to the Future of Privacy

direct.mit.edu

91–100 of 100 posts

Re: Tor: From the Dark Web to the Future of Privacy

#91

Earlier quoted context omitted.

The scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.

"don't become an enemy of the state" is my go-to security posture

What about whistleblowers?

Re: Tor: From the Dark Web to the Future of Privacy

#92

Earlier quoted context omitted.

Which story is this? I've heard a few famous stories of people getting caught using Tor, but none that were like this.

https://www.thecrimson.com/article/2013/12/17/student-charge...

Yeah, that's the one I meant. It would've been fine if he was the only one using Tor, but:

- Guerilla mail let the FBI know it was being accessed with Tor (or they saw it in the email header)

- You have to login to use Harvard wifi with your student account, which means they could see who was using Tor.

If anything, Harvard wifi is the honeypot.

Re: Tor: From the Dark Web to the Future of Privacy

#93
post #75

Earlier quoted context omitted.

Right, like China and Russia are going to let USA tap their fibre?

Conveniently, tor nodes are blocked by the Chinese and Russian governments.

Your post was 'Governments will just get other governments to let them tap their fiber.'

You have, conveniently, moved your point back to tor when I pointed out the folly of your statement.

Re: Tor: From the Dark Web to the Future of Privacy

#94

I don't think much of this writing style. What's the tor attack surface? Are all the tor boxes on the internet backdoored by the NSA? Is tor a honeypot or is tor not a honeypot? As far as I can tell tor was designed by spooks to allow remote agents operating in foreign countries a means to communicate with headquarters without being traced. It was never designed to allow two entities to communicate anonymously. The m…

There was a guy in a dorm who thought he was anonymous using tor on the schools website. They caught him because it turns out he was the only one using tor. In some ways it is a honeypot.

He should have run tor from a VPS node and then created a SSH socks tunnel to reach it. It's common to see SSH sessions and large packets flowing through it could easily be SFTP. Even if someone should suspect anything it's still plausible deniability.

Re: Tor: From the Dark Web to the Future of Privacy

#95

Earlier quoted context omitted.

https://www.thecrimson.com/article/2013/12/17/student-charge...

Yeah, that's the one I meant. It would've been fine if he was the only one using Tor, but: - Guerilla mail let the FBI know it was being accessed with Tor (or they saw it in the email header) - You have to login to use Harvard wifi with your student account, which means they could see who was using Tor. If anything, Harvard wifi is the honeypot.

I think the takeaway from this is you can hide your origin from a web server, but if you use an uncommon pathway to the server, your traffic sticks out.

My memory of this case is that Harvard was able to easily determine who had recently used tor, possibly through netflow logs.

Same sort of thing used to happen with Signal traffic to their servers in AWS. I've been in countries where Signal does not work at all because the local government blocked Signal traffic after lobbying from companies that profit from expensive SMS charges.

I've read privacy activists stress that it's great that e2e encryption exists, but that intelligence agencies are mostly interested in the metadata (who you communicate with, how you communicate with them).

Re: Tor: From the Dark Web to the Future of Privacy

#96
post #93

Earlier quoted context omitted.

Conveniently, tor nodes are blocked by the Chinese and Russian governments.

Your post was 'Governments will just get other governments to let them tap their fiber.' You have, conveniently, moved your point back to tor when I pointed out the folly of your statement.

The discussion is about tor. If you look at the countries where tor nodes are hosted fiber tapping is a relevant attack vector.

Re: Tor: From the Dark Web to the Future of Privacy

#97

Earlier quoted context omitted.

Yeah, that's the one I meant. It would've been fine if he was the only one using Tor, but: - Guerilla mail let the FBI know it was being accessed with Tor (or they saw it in the email header) - You have to login to use Harvard wifi with your student account, which means they could see who was using Tor. If anything, Harvard wifi is the honeypot.

I think the takeaway from this is you can hide your origin from a web server, but if you use an uncommon pathway to the server, your traffic sticks out. My memory of this case is that Harvard was able to easily determine who had recently used tor, possibly through netflow logs. Same sort of thing used to happen with Signal traffic to their servers in AWS. I've been in countries where Signal does not work at all becau…

Completely

Re: Tor: From the Dark Web to the Future of Privacy

#98

Earlier quoted context omitted.

The scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.

"don't become an enemy of the state" is my go-to security posture

"don't become an enemy of any state" which is a little trickier.

Re: Tor: From the Dark Web to the Future of Privacy

#99

Earlier quoted context omitted.

> because these institutions protect them. All I am saying is that you could replace your antagonists in that line with "journalists" and you'd be like, "no wait, that's not true," and you'd be as wrong about journalists as anyone else. Either there are some powerful institutions protecting journalists too, OR Tor is powerful enough to protect journalists. If it's not good enough for journalists, why bother? If it's…

I would absolutely agree that there's journalists who get significant power and protection from their proximity to major institutions and centres of power. Tor is useful for protecting journalists in situations where they don't have access to that kind of protection. I would agree as you say that's also the case for people that it protects who want to commit really awful forms of harm (who might not have access to th…

> Actually the relay community is pretty diverse - they have some colourful characters but actually a lot of them are just IT professionals, activists, and people working for libraries or universities.

Unless the son or daughter of an important politician, journalist or rich person, there are no pedigreed Ivy League people under 40 running exit nodes. No chance. There are tons of them working for NGOs. I am just trying to distill the cultural divide that people are really complaining about.

A great example of this is the Stanford student who won that journalism award, who was the son of a very important New York reporter. No chance a "normal" student would have gotten away with the campaign against the admins that he did, and yet, he gets the award! I mean bless his heart, but when talking about the most laudable aspect of Tor - protecting journalists - there's a complicated story there too, with bitter rivalries and dramas, that really characterize the "hair on fire" problem for most journalists.

Re: Tor: From the Dark Web to the Future of Privacy

#100
post #93

Earlier quoted context omitted.

Your post was 'Governments will just get other governments to let them tap their fiber.' You have, conveniently, moved your point back to tor when I pointed out the folly of your statement.

The discussion is about tor. If you look at the countries where tor nodes are hosted fiber tapping is a relevant attack vector.

And I was pointing out that governments need to be on particularly friendly terms to achieve this, which doesnt make it a universal attack vector.

Here, have an example:

https://www.telegraph.co.uk/news/worldnews/asia/japan/104090...

Post reply on HN