Live data from Hacker News

Law Enforcement Undermines Tor

marx.wtf

71–80 of 86 posts

Re: Law Enforcement Undermines Tor

#71

Earlier quoted context omitted.

It’s 2024 and I can’t tell if this is sarcasm or not.

Then allow me to knock it up a notch! Encryption isn't needed, because nothing important happens over the internet. Nobody shops online, or does their banking online. Nobody would ever work from home over the internet - how would the boss know if workers were sleeping on the job? People who want to buy stocks from their phone simply phone their stockbroker. Anyone can post any nonsense on the internet, so it's useles…

> so there's no need for anything online to be private

I disagree. Unless you’re being sarcastic?

Re: Law Enforcement Undermines Tor

#72

It's not directly mentioned in this article, but the four deanonymized users were admins of a CSAM site with hundreds of thousands of users. If you're concerned about being targeted by law enforcement, step one is probably: don't be that. https://www.dw.com/de/darknet-missbrauchsplattform-boystown-... https://www.sueddeutsche.de/panorama/kindesmissbrauch-boysto...

This is what everyone here seems to forget when they're ranting on about surveillance: that there are serious criminals out there who need to be caught. In this case, child abusers.

Whoever the engineers are who've worked on the technical aspects of deanonymizing Tor connections, they should feel very proud of their work and the good it's doing in the world.

Re: Law Enforcement Undermines Tor

#73
post #58

Would using VPN prevent prying eyes from detecting the IP address? This issue seems to be related only to Tor users who do not use VPN?

Yes, the German monitoring would point to the VPN provider, instead of directly at the user. However, they would then install a monitoring device at your VPN node.

Re: Law Enforcement Undermines Tor

#74

Earlier quoted context omitted.

Cool, we got the “if you don’t have anything to hide” argument out of the way early. Now we can discuss the actual privacy implications of this news

Are you discussing the privacy implications? It looks like your only comment is this asinine middlebrow dismissal. Meanwhile, I've given actionable advice.

I don't think you get to charge anyone else with assinine.

If a tool does not perform as designed, all users of the tool have an interest in knowing that, and working towards correcting that.

It doesn't matter that there are both good and bad users.

Re: Law Enforcement Undermines Tor

#75

Are there any projects that generates random traffic? Like a website where you have it open it keeps sending random traffic. It will make traffic analysis very hard.

Decades ago when first hearing about timing attacks I thought every network switch and nic should generate essentially white noise at all times on the wire, with the actual traffic just mixed in. Random amounts of random data going to random destinations, completely filling the pipe 100% at all times like how a carrier wave is on at all times, just as a feature of lighting up the port. If the electricity is on, the noise is on. Or at least in the switches and maybe not needed at the end points.

A fantasy.

Re: Law Enforcement Undermines Tor

#77

Earlier quoted context omitted.

In actual fact, your proposal is too modest. Why should only electronic messages be so publicized? After all, relevant communication, either for our protectors in law enforcement (and secret services, don't forget their hard work for our prosperity) or for us members of society, happens via all kinds of mediums. Privacy of correspondence might have had some relevance in the past, but today, with LLMs helping us work…

In fact, your proposal is too modest still. We are still free to think whatever we want! We should fast forward the development of neuralink chips and broadcast everyone's thoughts live to everyone at all times so that you can make a judgement of unethical behavior

Your lack ambition. We should instead proceed with Human Instrumentality Project and turn the mankind into an abstract singularity.

Re: Law Enforcement Undermines Tor

#78
post #8

I have suspected Tor has been busted for quite a long time. LE is only using this power selectively for now - the last thing that they want is to scare users away lest they go and build something more secure. The Nym mixnet[0] seems promising but it's still new and unproven. I had an idea a while back to make traffic analysis more difficult by building circuits distributed across adversarial countries. Would like to…

It's a basic correlation attack. As follows:

- Find the "bad guy" server onion address "hidden service"

- Run a tor relay. Ideally many. No exit node shenanigans needed - hidden service, not exiting TOR. This is quite nice from a legalistic perspective since you're not on the hook for hacks coming off the exit node.

- Run a bunch of clients. Instruct to connect to "bad guy" onion.

- Gather data over time for correlation attacks. Correlate your client to relay to endpoint server.

- At some point, you'll find one of your relays is the guy connecting directly to said hidden service.

Very simple lesson here. One needs to encrypt the information, yes, but failing to consider packet timing as "information" is the fallacy.

Re: Law Enforcement Undermines Tor

#79
post #71

Earlier quoted context omitted.

Then allow me to knock it up a notch! Encryption isn't needed, because nothing important happens over the internet. Nobody shops online, or does their banking online. Nobody would ever work from home over the internet - how would the boss know if workers were sleeping on the job? People who want to buy stocks from their phone simply phone their stockbroker. Anyone can post any nonsense on the internet, so it's useles…

> so there's no need for anything online to be private I disagree. Unless you’re being sarcastic?

@michaelt: looks like you need to knock it further up still!

Re: Law Enforcement Undermines Tor

#80

Earlier quoted context omitted.

Are you discussing the privacy implications? It looks like your only comment is this asinine middlebrow dismissal. Meanwhile, I've given actionable advice.

I don't think you get to charge anyone else with assinine. If a tool does not perform as designed, all users of the tool have an interest in knowing that, and working towards correcting that. It doesn't matter that there are both good and bad users.

The tool performed as designed. This took a months-long international investigation using social engineering and monitoring of hundreds of nodes to to identify four users that were being specifically targeted. It wasn't some novel attack, it's literally something that has always been possible with enough resources.

Ergo, users: don't warrant the resources. Your threat model should not be the same as CSAM site operators.

Also, you misspelled asinine.

Post reply on HN