Live data from Hacker News

Law Enforcement Undermines Tor

marx.wtf

31–40 of 86 posts

Re: Law Enforcement Undermines Tor

#31
post #12

Is there something new here? I’m under the impression that we knew this kind of thing was possible with enough resources.

The articled confirms that the authorities are conducting a dragnet operation. Everyone who connected to a certain entry relay was tracked and reported. Does the tor daemon connect automatically? If so, even people who installed tor for fun and forget about may be on the list. Did the lucky ones have the "Bundestrojaner" (gov surveillance app) installed on their machines?

>If so, even people who installed tor for fun and forget about may be on the list.

Good. That reduces the quality of the list.

Re: Law Enforcement Undermines Tor

#33
post #30

Earlier quoted context omitted.

So you're aware of those cases and just going with "yeah, let's ignore those account takeovers, impersonations, data theft, etc. across any service from social media to banking and payment" because just bad people need encryption? Walk me through the process of a non-vile person using banking securely from a cafe/hotel in your scenario.

Do you not understand what I am doing?

If you're being facetious, it's hard to tell, because you're not over the top enough. There are people who genuinely hold that position and you can occasionally find them on HN. Often under the "HTTPS is a scam and makes everything slower and hard to debug" banner though.

Re: Law Enforcement Undermines Tor

#34
post #10

[flagged]

Yeah that's all fun, I don't have anything to hide either. But what if I actually WILL in the future, retroactively? I've said a few things here and there, what if certain types of speech end up getting banned and if you don't remove it on time (or lost access), you risk jail-time?

Seems far away, but it's literally happening in England.

Please watch out with this kind of thinking - it's dangerous to everyone.

Re: Law Enforcement Undermines Tor

#35
post #10

[flagged]

"everyone is assumed to be acting in good faith". Right. I think that when it comes to network service security the old adage told to my father by an Irish Catholic priest applies: "Bill, once you understand that most people are just no damn good, then you'll be fine".

Or, in the words of the NSA, "Trust, but verify".

I agree that HTTPS is bad though, as it is used. We only do one-sided TLS, not mutual. Most people don't verify the server's cert by looking at it. Most apps don't encrypt messages before they go over TLS. In a more secure world a proxy with stateful packet inspection would not be possible.

As is often the case, the problem isn't technical (or at least not mainly technical). Employers, governments, and ISPs want proxies that inspect traffic, either for CYA or to increase budgets by increasing situational awareness. For governments, situational awareness increases wins by enabling them to catch people they deem bad actors. For employers and governments, increased SA means a decreased chance of leaks and people not doing what they're supposed to do with their time. For ISPs, it means they can monitor the traffic and restrict certain things (like video streaming, or running a server from home) to increase profit.

I can think of at least one potential solution. Still, it requires a technically savvy public, a patient public, and money: Open Source phones in everyone's hands, circles of trust, distributed freenet with data passed E2E encrypted via gossip protocol when two phones get near enough for Bluetooth data transmission (figure 50m roughly) where both phones are within some N degrees of separation via circles of trust. However, this mean's getting/sending data is asynchronous with long delays and no guarantees.

Re: Law Enforcement Undermines Tor

#36
post #10

[flagged]

Yeah that's all fun, I don't have anything to hide either. But what if I actually WILL in the future, retroactively? I've said a few things here and there, what if certain types of speech end up getting banned and if you don't remove it on time (or lost access), you risk jail-time? Seems far away, but it's literally happening in England. Please watch out with this kind of thinking - it's dangerous to everyone.

> what if certain types of speech end up getting banned and if you don't remove it on time (or lost access), you risk jail-time?

So racism, homophobia, and transphobia? Why would you support technologies that promote and support the dissemination of hate speech and misinformation?

Re: Law Enforcement Undermines Tor

#39
post #5

One advantage of imperfect privacy solutions like Tor is they force authorities to invest if they want to snoop. In the before times if soneone wanted to read your mail they'd need to at least convince a judge and then spend manpower interecepting the envelopes, today they can just ping google for a bcc.

Is that true? IIRC they still need to do the legal paperwork to get an email from google et al (FISA request?).

Re: Law Enforcement Undermines Tor

#40

Are there any projects that generates random traffic? Like a website where you have it open it keeps sending random traffic. It will make traffic analysis very hard.

It probably doesn't; think about it, most websites already have a load of random stuff, plus all users combined is also heaps of randomness. No self-respecting analyist would go through logs manually, it's all fed into search / analysis software, filtering through noise.
Post reply on HN