Live data from Hacker News

Tor trip report to an FBI conference

blog.torproject.org

11–20 of 57 posts

Re: Tor trip report to an FBI conference

#11
post #8
post #4

Earlier quoted context omitted.

Is there a better one?

Yes, encrypt all your mails using PGP.

@Xylakant then you have to pull an "Petraeus" and just keep the emails unsent in the draft folder. Not sure if this is still a viable option.

Re: Tor trip report to an FBI conference

#12
post #9

I like the idea that some agents are regularly using Tor, whilst others are asking the Tor guy if he can track Tor users...

I'm not sure quite what they're using it for, though. I suppose some sites block .gov IP ranges, but you'd think they could easily proxy via some innocuous host provided by a commercial provider.

Re: Tor trip report to an FBI conference

#14
post #12
post #9

I like the idea that some agents are regularly using Tor, whilst others are asking the Tor guy if he can track Tor users...

I'm not sure quite what they're using it for, though. I suppose some sites block .gov IP ranges, but you'd think they could easily proxy via some innocuous host provided by a commercial provider.

Law enforcement have for decades been anonymous, wearing plain clothes & hiding behind false identities in efforts to catch criminals. Tor just gives them digital plain clothes. If they were going through an open HTTP proxy, that box better have a decently network facing attack surface (unlikely). Sure, it's the same deal with Tor, except you have to pwn about 2/3rd of the network (4000+ boxes) before you know about the equivalent of pwning 1 sole proxy. Keep in mind there is a good mix of software, a whole variety of kernels etc.

If you have one of the less common architectures around, consider running a Tor node on it :-) Then we get a mix against random machine-code backdoors too.

Re: Tor trip report to an FBI conference

#15
post #8

Earlier quoted context omitted.

Yes, encrypt all your mails using PGP.

The problem with PGP is that while it keeps the content of your mail exchange secret, it does not protect the information that two persons exchanged emails. So if the investigators have a lead to person A that sells drugs and see that he's communicating with person B that accepts payments, the might just guess what relationship the two have.

For that use tor to access your emails and/or use tormail.org which will not be able to disclose that information.

Re: Tor trip report to an FBI conference

#16
post #11
post #8

Earlier quoted context omitted.

Yes, encrypt all your mails using PGP.

@Xylakant then you have to pull an "Petraeus" and just keep the emails unsent in the draft folder. Not sure if this is still a viable option.

People are forgetting that if you use PGP you can post it anywhere

The Petreus incident is sort of crazy for this reason. Here is the head of the CIA, doesn't even use PGP.

There are other mixnets such as Mixmaster and Mixminion that do what Tor does for TCP but with email. They unfortunately need many more people to run nodes.

Re: Tor trip report to an FBI conference

#17
post #8

Earlier quoted context omitted.

Yes, encrypt all your mails using PGP.

The problem with PGP is that while it keeps the content of your mail exchange secret, it does not protect the information that two persons exchanged emails. So if the investigators have a lead to person A that sells drugs and see that he's communicating with person B that accepts payments, the might just guess what relationship the two have.

Right, that's why you use Tor. PGP provides privacy and accountability. Tor provides anonymity.

Just remember you have to trust the security of the receiving party as well. Make sure not to reveal yourself with the contents of your emails since the other party might not be as disciplined with their tor and pgp use as you are.

Re: Tor trip report to an FBI conference

#18
post #16
post #11

Earlier quoted context omitted.

@Xylakant then you have to pull an "Petraeus" and just keep the emails unsent in the draft folder. Not sure if this is still a viable option.

People are forgetting that if you use PGP you can post it anywhere The Petreus incident is sort of crazy for this reason. Here is the head of the CIA, doesn't even use PGP. There are other mixnets such as Mixmaster and Mixminion that do what Tor does for TCP but with email. They unfortunately need many more people to run nodes.

"The Petreus incident is sort of crazy for this reason. Here is the head of the CIA, doesn't even use PGP."

He's just a bureaucrat, hired after retiring as an Army general. I seriously doubt if he had any personal spy craft training beyond "use this secure computer and this secure phone when you're working on company business, sir. And don't talk about Fight Club."

Re: Tor trip report to an FBI conference

#20
post #12
post #9

I like the idea that some agents are regularly using Tor, whilst others are asking the Tor guy if he can track Tor users...

I'm not sure quite what they're using it for, though. I suppose some sites block .gov IP ranges, but you'd think they could easily proxy via some innocuous host provided by a commercial provider.

They're not using it to evade website blocks, they're using it to anonymize themselves and evade being identified as FBI agents.
Post reply on HN