Live data from Hacker News

Tor trip report to an FBI conference

blog.torproject.org

31–40 of 57 posts

Re: Tor trip report to an FBI conference

#31
post #2

So that settles it for recommending Hushmail for true private communications - don't use it.

Apparently you have never been to their website. They clearly state that they will fully cooperate with law enforcement on signup. Its a mandatory checkbox on signup: I understand that Hushmail is not suitable for illegal activity and that the providers of Hushmail will cooperate fully with authorities pursuing evidence via valid legal channels. See our Security Page.

"Security" here is used in a weird way.

Security is a design feature, not a policy.

Re: Tor trip report to an FBI conference

#32
post #2

So that settles it for recommending Hushmail for true private communications - don't use it.

Most providers happily cooperate with law enforcement and other government agencies, in particular if they don't have to (or are forbidden to) inform their customers. In many cases, informal contacts are used or a polite official request without a court order is already sufficient.

Re: Tor trip report to an FBI conference

#33
post #22
post #16

Earlier quoted context omitted.

People are forgetting that if you use PGP you can post it anywhere The Petreus incident is sort of crazy for this reason. Here is the head of the CIA, doesn't even use PGP. There are other mixnets such as Mixmaster and Mixminion that do what Tor does for TCP but with email. They unfortunately need many more people to run nodes.

The head of the CIA is aware of the methods used to extract information from suspects, and thus wants his information to be easily found if he's discovered, rather than requiring him to be extra-ordinarily renditioned and water-boarded. I guess it just shows that anonymous and private communication is still really hard for most people, even though we had the work of cypherpunks trying to help.

Why would they waterboard him if he was willing to give up the keys?

Re: Tor trip report to an FBI conference

#34
post #14
post #12

Earlier quoted context omitted.

I'm not sure quite what they're using it for, though. I suppose some sites block .gov IP ranges, but you'd think they could easily proxy via some innocuous host provided by a commercial provider.

Law enforcement have for decades been anonymous, wearing plain clothes & hiding behind false identities in efforts to catch criminals. Tor just gives them digital plain clothes. If they were going through an open HTTP proxy, that box better have a decently network facing attack surface (unlikely). Sure, it's the same deal with Tor, except you have to pwn about 2/3rd of the network (4000+ boxes) before you know about…

>If they were going through an open HTTP proxy, that box better have a decently network facing attack surface (unlikely). Sure, it's the same deal with Tor, except you have to pwn about 2/3rd of the network (4000+ boxes) before you know about the equivalent of pwning 1 sole proxy.

Can you go into more detail about what you are saying? I'm sure you could drop a- ADOBE, Active-X, Java, ect- 0-day on a page and pwn said box. You can also send payloads to/from TOR; although there are limited transfer protocols you can use.

The whole point of TOR is to try to anonymize you. It's not going to save you from getting owned.

Re: Tor trip report to an FBI conference

#35
post #5
post #2

So that settles it for recommending Hushmail for true private communications - don't use it.

I do not understand why they are still in the business. It seems their reputation is destroyed, yet they are still here.

For people who only care about non-government espionage.

Re: Tor trip report to an FBI conference

#36
post #2

So that settles it for recommending Hushmail for true private communications - don't use it.

Apparently you have never been to their website. They clearly state that they will fully cooperate with law enforcement on signup. Its a mandatory checkbox on signup: I understand that Hushmail is not suitable for illegal activity and that the providers of Hushmail will cooperate fully with authorities pursuing evidence via valid legal channels. See our Security Page.

The corollary is that Hushmail is a shitty service. A good service for private e-mail should make it impossible for the server administrators to see what is going on. Obviously that checkbox should make any user that needs real security turn around in the door.

I've never used Hushmail, but I assumed "secure e-mail" == "none of my information touches the server in plaintext". So this comment is quite interesting.

Re: Tor trip report to an FBI conference

#37
post #8
post #4

Earlier quoted context omitted.

Is there a better one?

Yes, encrypt all your mails using PGP.

Actually now-a-days it's using an OTR client, since it adds deniability and forward secrecy. I don't know if it removes offline messaging. It's also a lot easier to use and easier to convince your friends and close ones to use it since they only need to flip a switch practically.

http://www.cypherpunks.ca/otr/

Re: Tor trip report to an FBI conference

#38
post #25
post #24

"The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up." We now know, that entire nations' & worldwide traffic is being intercepted and logged. One would probably see I2P as an overkill without knowing t…

> One author exposed how becoming an exit node for Tor allowed all the traffic on the Tor network to pass right through your machine. Becoming an exit node was the same as performing a Man-In-The-Middle attack. This is de-contextualised scaremongering. What the poster is referring to is that when you leave the Tor network, the connection is as it would have been before. This is by design. So if you were not using TLS…

Great explanation, just want to add that when you use Tor hidden services to communicate (i.e. no exit node involved or needed), everything is end-to-end encrypted and the MITM attack scenario doesn't apply. Hidden services are also not vulnerable to:

> "The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up."

because all traffic is within the Tor network.

Re: Tor trip report to an FBI conference

#39
post #36

Earlier quoted context omitted.

Apparently you have never been to their website. They clearly state that they will fully cooperate with law enforcement on signup. Its a mandatory checkbox on signup: I understand that Hushmail is not suitable for illegal activity and that the providers of Hushmail will cooperate fully with authorities pursuing evidence via valid legal channels. See our Security Page.

The corollary is that Hushmail is a shitty service. A good service for private e-mail should make it impossible for the server administrators to see what is going on. Obviously that checkbox should make any user that needs real security turn around in the door. I've never used Hushmail, but I assumed "secure e-mail" == "none of my information touches the server in plaintext". So this comment is quite interesting.

Supposedly lavabit.com is (from the admin perspective) about as close to zero knowledge as it gets. Logs are kept for a minimum to diagnose abuse/performance issues, and crypto keys are strictly between the user and server. As I understand it, the only legal compromise would be a national security letter style gag order to alter the binary that interfaces the client (be it Outlook, your phone, or the web-mail host) to the back-end data store, which is stored encrypted on disk.

Security flaws are another thing entirely. I have no idea if anyone, aside from internal developers, has vetted the system for flaws that typically result in server compromises.

I was a satisfied free user some years ago, and the above was my understanding of the service after a few pointed queries to the support address.

Post reply on HN