Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

131–140 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#131
post #128
post #113

Earlier quoted context omitted.

One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking. Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the underst…

> That used to be a tin-foil hat idea just a few months ago, and we know better now. If NSA comes carrying gifts, it warrant being very careful in accepting them from a party with such hostile priorities. Well, not really. The "tinfoil" idea is that NSA is breaking into crypto so that they can blackmail politicians, black-bag innocent citizens, etc. But it was never widely assumed that NSA wasn't trying to break ever…

The NSA shouldn't just be an attacker it should also provide defence. If one of their many contractors can leak details to the press for idealogical ends it's pretty safe to assume that much worse secrets have already been leaked to other nation states (China, Russia etc....) for financial gain.

I think it's entirely reasonable to assume that a lot of exploits the NSA has discovered and not revealed (because it thinks they are "secret") have actually been sold to other governments by it's own contractors. By not revealing these exploits to citizens they are actually leaving them open to attack by foreign governments. Large companies trying to defend against industrial espionage are probably most at risk.

Re: Attacking Tor: How the NSA targets users' online anonymity

#132
post #118
post #113

Earlier quoted context omitted.

One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking. Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the underst…

> It was generally thought that government would not keep security vulnerabilities hidden Was that what people thought? Were there vulnerability reports in open-source software that were coming from the NSA or thought to be coming from the NSA? Surely everyone knew that the NSA was capable of finding exploits in software, and I would think that it would be hard to keep secret whether or not they're being reported. >…

DES was about speed. DES was in an age when computers were slow, DES was slow, and the NSA was already helping defeat a cryptanalysis attack on it.

Limiting the keys to a sensible number means it can be used in a practical sense.

Re: Attacking Tor: How the NSA targets users' online anonymity

#133
post #98

Earlier quoted context omitted.

I think Facebook proves definitively that the layman doesn't care about "trustworthiness of the internet".

They do for anything that requires money and beyond. That's why banks etc. try hard to persuade people they have high security standards.

That will be a problem once you can by a quantum computer from the local IT shop, not while their are 5 of them in the world and you need a team of physicists to operate them.

Re: Attacking Tor: How the NSA targets users' online anonymity

#134
post #44
post #7

Metacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world g…

>(here, there's a subtext that Tor actually made NSA's job easier) I'm not sure how you reached that conclusion. The slides mention that Tor is: * Very difficult to identify on the network-level, since Tor-tls traffic is indistinguishable from Apache-tls traffic as of 2011 * Impossible to fully deanonymize * Only exploitable via a handful of browser exploits. Further, later in the "Tor is the King" slide deck, there'…

Will tails still only use ram and no disk within a vm? If not, you'll just have a slightly better tor browser bundle (plus other features) right? I always thought the "ram only" portion of tails was one of the biggest anonymity wins.

Re: Attacking Tor: How the NSA targets users' online anonymity

#135
post #72

Earlier quoted context omitted.

The Stasi and the Gestapo were genuinely pursuing a national security mission. They also did more self-inflicted harm to Germany than the A-bomb did to Japan from the outside. He's not exaggerating the amount of damage an intelligence agency can do.

I feel like you've just invoked Godwin's Law, and yet in this case the comparison actually seems apt...

[deleted]

Re: Attacking Tor: How the NSA targets users' online anonymity

#136

Earlier quoted context omitted.

That isn't sufficient. The NSA might be able to query their databases for anyone who recently visited the city where the wifi involved is located, and you might match that if there were license plate scanners on the way, even if you paid for gas in cash. If that information isn't collected by the NSA today, it probably will be tomorrow. The NSA might be able to query their databases for anyone who "went off the grid"…

I think that what you are saying is true, but there is always a level of risk. It's more about mitigating it than eliminating it - you can't really do that. Again, this is all hypothetical, don't go and do anything naughty.

Yes, that has always stopped me from doing some things, I would like to do covertly and aren't exactly ok. But there is no safe way to do it. How do you make sure that you won't get into traffic accident when going on mission or returning from it. It would be really nice to hear how you make roads 100% safe.

I'm also too security oriented and been monitoring this field for over 15 years. So I know how hard it is to be absolutely anonymous. I also know that my Finnish & English aren't exactly textbook examples, so I can be profiled easily out even if I would be technically 100% anonymous.

I always surf the web from virtual container which is fully reset after each session. I also don't ever process, email, im, web, archives or what ever on host system. I also have completely separate (hardware), similarly safe configuration for handling PGP/GPG encrypted messages, which is connected only via serial-link so I can view the ASCII armored payload before sending it for processing. Anything else than ascii armored payload isn't being sent over that 7 bit link ever.

It's also obvious that I have prepaid dumb phone(s), one for each identity, which are circulated on random schedule. I only use those phones at single location (without other tracking devices), because moving with those would allow linking my (moving) position with my other phone(s). Making it easy to correlate those. Yes, I know this is non-optimum solution, if you're expecting someone to hunt you down. But it's good for generic privacy as long as you don't expect anyone to be there waiting for you.

Getting rid of habits is also very hard and requires huge effort. That single thing (service, program, password, etc), word or phrase you just used, will single you out from larger group.

Re: Attacking Tor: How the NSA targets users' online anonymity

#137
post #128
post #113

Earlier quoted context omitted.

One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking. Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the underst…

> That used to be a tin-foil hat idea just a few months ago, and we know better now. If NSA comes carrying gifts, it warrant being very careful in accepting them from a party with such hostile priorities. Well, not really. The "tinfoil" idea is that NSA is breaking into crypto so that they can blackmail politicians, black-bag innocent citizens, etc. But it was never widely assumed that NSA wasn't trying to break ever…

Unfortunately it's politcians in 6 countries who try to dismantle the now totalitarian levels of surveillance who end up on this shit list too. Then soon it will be you and me.

Re: Attacking Tor: How the NSA targets users' online anonymity

#138
post #130

Earlier quoted context omitted.

I think a lot of that depends on exactly who's being targeted, and for what reasons. Those revelations haven't made it out yet. The only information we have is the NSA director answering "Not intentionally, no" when asked if the NSA ever spied on American citizens, along with Snowden's allegations that there are no checks and balances if an employee of the NSA believed that they did, and Russ Tice's claim that the NS…

A lot of those questions simply tie back into the age-old debate over capability. You can talk about checks and balances all you want, but if you hand a "trusted soldier" a rifle he may yet kill many of the wrong people before he can be stopped. Yet people don't typically lie awake at night staring at the ceiling worrying about the local National Guard violating Posse Comitatus and imposing martial law. But on the ot…

There are plenty of checks and balances against a local national guard violating posse comitatus, namely that the federal government would then send in the rest of the army - all of whom are sworn to protect and defend America and its citizens - to right the situation.

The problem with the NSA is that if they are abusing their power, nobody will ever know about it, because everybody they deal with is sworn to secrecy. Abuses are far more likely to happen in this situation, not because of any inherent maliciousness, but because whenever you have a large organization that never has to face an opposing viewpoint you end up with groupthink and a large possibility of ill-considered decisions.

I'd be satisfied with detailed congressional oversight. Unfortunately, the last time the NSA director was called before a congressional subcommittee, his statements don't seem to match up with the actual operations of his agency, as they've been leaked since. I hear some congressional reps are pretty mad about that.

Re: Attacking Tor: How the NSA targets users' online anonymity

#139
post #71

One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully…

I agree with your post generally, but has Snowden said anything about CAs? I did expect to hear that at least one has signed anything the NSA put in front of them, but I don't recall Snowden providing "proof"* of this. * I'm in no position to verify anything Snowden leaks.

I don't know about the NSA, but I've personally negotiated a deal with a CA to add whatever domains we wanted to a certificate without validation. They just "trusted us."

Re: Attacking Tor: How the NSA targets users' online anonymity

#140
post #44
post #7

Metacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world g…

>(here, there's a subtext that Tor actually made NSA's job easier) I'm not sure how you reached that conclusion. The slides mention that Tor is: * Very difficult to identify on the network-level, since Tor-tls traffic is indistinguishable from Apache-tls traffic as of 2011 * Impossible to fully deanonymize * Only exploitable via a handful of browser exploits. Further, later in the "Tor is the King" slide deck, there'…

TAILS will detect it is running inside a VM and warn you not to do it.

I know quite a few folks who are sitting on escapes for popular VM products. They are not at all uncommon.

I would be absolutely shocked if the NSA's little toolkit didn't detect virtualization, pop out, and backdoor the host OS.

Post reply on HN