Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

111–120 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#111

Earlier quoted context omitted.

It is important to realize that all useful comparisons to the Holocaust will be made against situations that are not as dire as the Holocaust. If there is a situation as dire as the Holocaust, then rhetoric about things being as bad as the Holocaust is no longer useful. Useful points made in a situation that horrifically dire are made with machine guns and bombs, not rhetoric. The proper time for rhetoric is well bef…

To think about that a bit: Actually, there have been several pretty brutal genocidal events in history that have points of comparison to the Holocaust. In no particular order, it is instructive to look at the Holodomr of Ukraine, Pol Pot, Stalin's purges, the Hutu-Tutsi conflict. There's no sense in calling forum moderators nazis in general, which is why Godwin came about. But when considering large-scale genocide an…

There have absolutely been genocides that can be compared to the Holocaust. I probably mis-emphasized my above post.

What I mean is that statements comparing incidents to the Holocaust lack utility if the situation has escalated to the level of brutal genocide. Any sort of statement delivered with words is useless at that point, that isn't the sort of situation that you can talk yourself or somebody else out of. If you want words to have an effect, you need to use them before the situation ever escalates that far.

A house-fire can be prevented with a stern lesson about deep-frying turkeys indoors, but once that actually starts happening, your lecture is of no use. At that point, you need to call in the fire fighters.

Talking about genocides can conceivably prevent a genocide, but talk about genocides can never stop a genocide.

Re: Attacking Tor: How the NSA targets users' online anonymity

#112

Wait, so simply by using Tor the government will install malware on your computer. How is that legal?

My interpretation of the article was that they identify prior to attacking.

I suppose they could use a "spray and pray" attack on anyone using Tor, but that would be easily detected.

Re: Attacking Tor: How the NSA targets users' online anonymity

#113

One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully…

One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking.

Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the understanding that NSA primary priority is to be able to hack other peoples computers. Be that a encryption algorithm, or a kernel module, NSA priority is 100% clear.

That used to be a tin-foil hat idea just a few months ago, and we know better now. If NSA comes carrying gifts, it warrant being very careful in accepting them from a party with such hostile priorities.

Re: Attacking Tor: How the NSA targets users' online anonymity

#114
post #110

One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully…

The weak point as usual are the endpoints. The attack vector described in these documents is JavaScript via some library called E4X. Makes me wonder why Tor bundle doesn't come with NoScript enabled by default.

There is an answer about this in their FAQ that basically states that having NoScript on by default breaks too much of the web.

Re: Attacking Tor: How the NSA targets users' online anonymity

#115
post #43
post #35

Earlier quoted context omitted.

Yeah, I was wondering if a virtual machine is safe from malicious attacks, though. Can anyone comment on the feasibility of this method as fail-safe?

Ideally you'd want to be running Tor with transparent proxying of all traffic on a physically separate (and locked down) host. I believe there are guides on how to do all that on a raspberry pi out there. On your primary browsing/whatever machine, I believe (but have not exhaustively researched) that it would still make sense to run inside a VM/container, because that would provide a much more 'generic' set of system…

Another option is to run an amnesiac OS on a material that is not re-writable (CD-R). Note this would replace the VM, not the separate Tor machine.

Re: Attacking Tor: How the NSA targets users' online anonymity

#116
post #93

Earlier quoted context omitted.

tptacek, I'm not sure I understand: do these new revelations really indicate indie developers don't have a fighting chance against Iran ? U.S. - absolutely, no fighting chance. China - chances look slim. Iran, Belarus - are you familiar with the technical achievements of their NSA equivalents, and so came to the conclusion they're likely as good as the NSA? Or maybe what the NSA did is just generally easy to do in yo…

Iran spends ~10bn/yr for the "on the books" part of their military. How much vulnerability research do you think $500MM buys? Answer: a lot.

Sure, still got hacked by Russian usb's though. What I'm seeing (the slides, Mr Alexander and so forth) is a huge list of incompetent dinosaurs in key positions. Sure there are skilled - very skilled - people all over the place, NSA, Iran, India, China, Australia, Cyprus (you name it). Sure the NSA employs more mathematicians than anybody else.

They have vision of hackers with AK Rifles on their back, wearing masks? Logos with a planet and a huge eye spying on it?

The flops these Agencies do, might surpass the successes by far. The thing is that you need dig in order to find out the real story. Hollywood even makes movies, advertising epic failures for wins (i.e. Argo, seriously???).

Re: Attacking Tor: How the NSA targets users' online anonymity

#117

Is nobody slightly concerned that the date shown in the PDF file which sparked this commentary ( http://www.theguardian.com/world/interactive/2013/oct/04/tor... ) shows the PDF as being created in 2007? It looks like they had some trouble picking out users 5 years ago... lord only knows how easy it must be for them now.

I think this depends vastly on the number of rogue tor nodes. However, picture this: NSA isn't the only organization going after TOR right? Probably there are others.So if you are China, Iran, Syria, Russia, etc. What do you do? You set up your 'own' poisonous tor relays. What you end up doing is disrupting and diminishing the potential of a single agency or a group of agencies of controlling a big % of tor traffic.

So all in all, might be a good thing and way more difficult thatn it was 7 years earlier. Not to mention that at the time we were browsing through tor at 50 kb/s while now we browse at 400 kb/s.

Re: Attacking Tor: How the NSA targets users' online anonymity

#118
post #113

One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully…

One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking. Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the underst…

> It was generally thought that government would not keep security vulnerabilities hidden

Was that what people thought? Were there vulnerability reports in open-source software that were coming from the NSA or thought to be coming from the NSA? Surely everyone knew that the NSA was capable of finding exploits in software, and I would think that it would be hard to keep secret whether or not they're being reported.

> That used to be a tin-foil hat idea just a few months ago, and we know better now.

It's well-known that the NSA pushed to have DES limited to 56-bit keys. There were suspicions about Dual_EC_DRBG long before there were any leaks from Snowden. In the 90s, they pushed the Clipper chip, in which they'd engineered a back door. I think that everyone understood that the NSA had somewhat of an interest in weaker cryptography. That's why the cryptographic standardization processes happened in the open and when constants were needed, they were taken from the digits of pi or some such sequence.

Re: Attacking Tor: How the NSA targets users' online anonymity

#120
what about the nonsense on the quantum system? i think the reporter left some key info out.

why does speed is a factor to mitm attacks? the slide shows a proper mintm diagram... or is this quatum thing exploiting a package arriving before the honest response? and why they would need to do that if they are in a position to do a proper mitm attack and not expose themselves for someone who monitors man-on-the-side attacks?

Post reply on HN