Live data from Hacker News

Tor trip report to an FBI conference

blog.torproject.org

21–30 of 57 posts

Re: Tor trip report to an FBI conference

#21
post #8

Earlier quoted context omitted.

Yes, encrypt all your mails using PGP.

The problem with PGP is that while it keeps the content of your mail exchange secret, it does not protect the information that two persons exchanged emails. So if the investigators have a lead to person A that sells drugs and see that he's communicating with person B that accepts payments, the might just guess what relationship the two have.

Yes. There is a difference between "private" and "anonymous".

Encryption often removes anonymity by tying an identity to keys and to a web of trust.

Re: Tor trip report to an FBI conference

#22
post #16
post #11

Earlier quoted context omitted.

@Xylakant then you have to pull an "Petraeus" and just keep the emails unsent in the draft folder. Not sure if this is still a viable option.

People are forgetting that if you use PGP you can post it anywhere The Petreus incident is sort of crazy for this reason. Here is the head of the CIA, doesn't even use PGP. There are other mixnets such as Mixmaster and Mixminion that do what Tor does for TCP but with email. They unfortunately need many more people to run nodes.

The head of the CIA is aware of the methods used to extract information from suspects, and thus wants his information to be easily found if he's discovered, rather than requiring him to be extra-ordinarily renditioned and water-boarded.

I guess it just shows that anonymous and private communication is still really hard for most people, even though we had the work of cypherpunks trying to help.

Re: Tor trip report to an FBI conference

#24
"The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up."

We now know, that entire nations' & worldwide traffic is being intercepted and logged.

One would probably see I2P as an overkill without knowing the downfalls of its predecessor. Tor was once a wonderful multi-proxy used for hiding IP addresses and bouncing off servers all over the world. At one time, it was even trusted by most governments for strong anonymity. All of that seemed to change after an article was posted in 2600 Hacker Quarterly. One author exposed how becoming an exit node for Tor allowed all the traffic on the Tor network to pass right through your machine. Becoming an exit node was the same as performing a Man-In-The-Middle attack. All one had to do was open up a packet sniffer and see all the traffic going through encrypted. Tor is still used by people trying to protect their privacy. But at the same time it has become a playground for hackers and governments monitoring what they consider suspicious. I2P has secured this problem while adding more functionality.

Proper German engineering: http://www.i2p2.de/index.html

Re: Tor trip report to an FBI conference

#25
post #24

"The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up." We now know, that entire nations' & worldwide traffic is being intercepted and logged. One would probably see I2P as an overkill without knowing t…

> One author exposed how becoming an exit node for Tor allowed all the traffic on the Tor network to pass right through your machine. Becoming an exit node was the same as performing a Man-In-The-Middle attack.

This is de-contextualised scaremongering.

What the poster is referring to is that when you leave the Tor network, the connection is as it would have been before. This is by design. So if you were not using TLS, then your traffic could be read, as is the case with ALL http etc. Simple. Use SSL/TLS/SSH/ etc

Do a trace route to google. All those intermediate parties are capable of the same thing.

But if you use TLS the attack is useless.

Tor provides one property, Anonymity, and it does this incredibly well. Anonymity and Privacy are related by distinct properties. Obviously if you send traffic to a site and sign off with your name, Tor can't help you be anonymous there. Tor cannot prevent misuse & ignorance.

As for this 'MITM' attack, Tor's design is such that you do not have to trust the exit nodes for it to work.

As for the comparison with I2P, I don't know much about it, but I support any FOSS project that aims to provide new types of anonymity. As I understand it the problem with I2p at the moment is that there is 1 exit node facing the regular net. It's not entirely clear how I2P evades what you consider 'the problem with Tor' when connecting with the regular net.

EDIT: Yep, did a bit of research and i2p is subject to the same sort of "attack" you describe "Like Tor, I2P does not magically encrypt the Internet. You are vulnerable to snooping by the outproxy operators." http://www.i2p2.de/faq.html#outproxy

Re: Tor trip report to an FBI conference

#26
post #14
post #12

Earlier quoted context omitted.

I'm not sure quite what they're using it for, though. I suppose some sites block .gov IP ranges, but you'd think they could easily proxy via some innocuous host provided by a commercial provider.

Law enforcement have for decades been anonymous, wearing plain clothes & hiding behind false identities in efforts to catch criminals. Tor just gives them digital plain clothes. If they were going through an open HTTP proxy, that box better have a decently network facing attack surface (unlikely). Sure, it's the same deal with Tor, except you have to pwn about 2/3rd of the network (4000+ boxes) before you know about…

Another good reason might be because there are a ton of illegal onion sites on Tor that they are investigating.

Re: Tor trip report to an FBI conference

#27
post #2

So that settles it for recommending Hushmail for true private communications - don't use it.

Apparently you have never been to their website. They clearly state that they will fully cooperate with law enforcement on signup.

Its a mandatory checkbox on signup:

I understand that Hushmail is not suitable for illegal activity and that the providers of Hushmail will cooperate fully with authorities pursuing evidence via valid legal channels. See our Security Page.

Re: Tor trip report to an FBI conference

#28
post #26
post #14

Earlier quoted context omitted.

Law enforcement have for decades been anonymous, wearing plain clothes & hiding behind false identities in efforts to catch criminals. Tor just gives them digital plain clothes. If they were going through an open HTTP proxy, that box better have a decently network facing attack surface (unlikely). Sure, it's the same deal with Tor, except you have to pwn about 2/3rd of the network (4000+ boxes) before you know about…

Another good reason might be because there are a ton of illegal onion sites on Tor that they are investigating.

Sure, but that is a newer feature, and Roger Dingledine has been giving these talks to law enforcement for some years (the earliest I am aware of is 2008).

Re: Tor trip report to an FBI conference

#29
post #25
post #24

"The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up." We now know, that entire nations' & worldwide traffic is being intercepted and logged. One would probably see I2P as an overkill without knowing t…

> One author exposed how becoming an exit node for Tor allowed all the traffic on the Tor network to pass right through your machine. Becoming an exit node was the same as performing a Man-In-The-Middle attack. This is de-contextualised scaremongering. What the poster is referring to is that when you leave the Tor network, the connection is as it would have been before. This is by design. So if you were not using TLS…

[deleted]
Post reply on HN