Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

21–30 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#21
post #7

Metacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world g…

I don't think your fears are justified by the article. The first thing you read is a pull-out quote that says:

>Tor is a well-designed and robust anonymity tool, and successfully attacking it is difficult.

Maybe you're referring to:

>The very feature that makes Tor a powerful anonymity service, and the fact that all Tor users look alike on the internet, makes it easy to differentiate Tor users from other web users.

Your kind words about the Tor project are accurate, but they have never claimed that it's possible to reliably hide Tor use.

The next sentence is:

>On the other hand, the anonymity provided by Tor makes it impossible for the NSA to know who the user is, or whether or not the user is in the US.

There is no Tor exploit or new information here. The NSA has enough resources to recognize Tor users in the USA enmasse, as well as single-out individual connections. From this point on, FoxAcid works the same whether you're using Tor or not.

Re: Attacking Tor: How the NSA targets users' online anonymity

#22
Sure these folks are smart and have all sorts of powerful weapons; what are the odds that someone out there could successfully repurpose some of these weapons? What is the likelihood that vulnerabilities exist in the NSA's systems? We can never know since it's all secret. If someone does take over these systems we wouldn't know that either.

Re: Attacking Tor: How the NSA targets users' online anonymity

#23
I am loving every minute of this NSA-Gate or Snow-Gate. Nothing like holding GOVT accountable for decisions they make behind closed doors, decisions that had an impact on the whole world not just US citizens.

Its also great all the technical details that are being released about how they Intel Agencies collect data. Its all fascinating.

Re: Attacking Tor: How the NSA targets users' online anonymity

#24
post #20
post #3

edit: removing meta discussion about flagging. the story should get the attention. apologies for the distraction.

1) It's currently first on the front page 2) Complaining about voting is really tedious to read about

Almost as tedious as reading complaints about complaining about voting :)

Re: Attacking Tor: How the NSA targets users' online anonymity

#25
Sounds like, if you're going to do something very sensitive on tor, you need to:

- always have an update to date version of tor bundle!

- compile the bundle yourself from source

- run it virtually, and always roll back to a clean snapshot (before installing it tor) when done

- if possible use from a network that is not your own (open wifi, public wifi, etc.)

- spoof your mac address

- do not run JS, Java applets, etc.!

I know this seems extreme, but from what I read, it's the best you can do to protect yourself.

Re: Attacking Tor: How the NSA targets users' online anonymity

#27
post #13

The more we learn about the NSA's capabilities, the more it seems like the Manhattan Project. They are developing the "cyberwarfare" equivalents of weapons of mass destruction. This exploit delivery network goes so far beyond any legitimate purpose it might serve that it belongs in the same moral category as hydrogen bombs. EDIT: The above is somewhat hyperbolic and unclear. The NSA's capabilities may have legitimate…

I think that's a pretty serious exaggeration. Designing tools to let you spy on Tor traffic has to be in a separate category from designing bombs that could kill millions. Besides, are there no ends that could justify these means? I think the means are altogether reasonable given the ends. Put aside whether you think the NSA is genuinely pursuing its national security mission: If it were, wouldn't it make perfect sen…

Sucks you are being downvoted for not agreeing with the hyperbole, but I think you are correct.

The NSA's job is to spy on things. TOR represents a place where illegal things occur, so it is a perfectly reasonable thing that they would be tasked with trying to stop such illegal things there.

Re: Attacking Tor: How the NSA targets users' online anonymity

#28
post #14

This accompanying article has useful context: http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack... > But the documents suggest that the fundamental security of the Tor service remains intact. One top-secret presentation, titled 'Tor Stinks', states: "We will never be able to de-anonymize all Tor users all the time." It continues: "With manual analysis we can de-anonymize a very small fraction of Tor users,…

This needs to be higher. I think this was the best scenario anyone who knows Tor could hope for. The attacks against Tor, when used correctly, are well understood. And, assuming this presentation is accurate,the capabilities of adverserial semi-global attackers aren't much different from what we were expecting.

I would love to see if they have similar slide-decks for I2P, which is often compared with Tor for Hidden Service/eepsite usage.

Re: Attacking Tor: How the NSA targets users' online anonymity

#29
post #13

The more we learn about the NSA's capabilities, the more it seems like the Manhattan Project. They are developing the "cyberwarfare" equivalents of weapons of mass destruction. This exploit delivery network goes so far beyond any legitimate purpose it might serve that it belongs in the same moral category as hydrogen bombs. EDIT: The above is somewhat hyperbolic and unclear. The NSA's capabilities may have legitimate…

I think that's a pretty serious exaggeration. Designing tools to let you spy on Tor traffic has to be in a separate category from designing bombs that could kill millions. Besides, are there no ends that could justify these means? I think the means are altogether reasonable given the ends. Put aside whether you think the NSA is genuinely pursuing its national security mission: If it were, wouldn't it make perfect sen…

Attacking Tor by passive analysis is one thing. Installing spyware, creating a botnet, and making the infection process quick and easy is another. There might be some justification for the former. The latter is too risky.

Re: Attacking Tor: How the NSA targets users' online anonymity

#30
post #8
post #7

Metacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world g…

here, there's a subtext that Tor actually made NSA's job easier Are you reading anything from that subtext beyond, "Tor has a high concentration of the kind of users we're interested in, so let's keep it a juicy target rather than squeezing too hard?"

As I understand it, which admittedly isn't well, it made surveillance jobs easier when its users mistook anonymity and privacy. That is, sending something through the tor network means that it's more likely that your traffic is going through a node belonging to a group that records everything than if your traffic randomly found a point to point route across the internet.

I don't see how using the Tor network could make you less anonymous, unless as you point out, it's use suggests a user's greater likelihood of sending and receiving interesting information.

It hurts the system that exit nodes have been targeted for content that other users were responsible, but from how I have read, Tor can provide people meaningful anonymity that is difficult breach.

As an aside: What is the effect of such parenthetical statements? I think they just create a vague idea of uncertainty and fear. If there is a vulnerability, there has to be a mechanism, not just a sense of omnipotent government surveillance.

Maybe that mechanism is the probabilistic likelihood of an organization controlling a large portion of the Tor nodes' ability to identify users. Maybe it's a flaw that has been surreptitiously put into the source code. I'm pretty sure more people who know would suspect the former as far more likely than the latter. It's easier to address the questions when you know what the parenthetical utterance was even referring to in the first place.

Post reply on HN