Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

141–150 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#141
post #116

Earlier quoted context omitted.

Iran spends ~10bn/yr for the "on the books" part of their military. How much vulnerability research do you think $500MM buys? Answer: a lot.

Sure, still got hacked by Russian usb's though. What I'm seeing (the slides, Mr Alexander and so forth) is a huge list of incompetent dinosaurs in key positions. Sure there are skilled - very skilled - people all over the place, NSA, Iran, India, China, Australia, Cyprus (you name it). Sure the NSA employs more mathematicians than anybody else. They have vision of hackers with AK Rifles on their back, wearing masks?…

Sure, still got hacked by Russian usb's though.

It seems unlikely that similar systems in any country would have remained unpenetrated in the face of that attack.

Just because one entity in a country got hacked, it doesn't mean other entities in the same country can't hack others. At the moment attack seems much easier than defence.

We don't know if the NSA has been penetrated, but given that Google's law enforcement search system was penetrated by unknown parties originating from China it would surprise me if the NSA has remained free from breaches.

Re: Attacking Tor: How the NSA targets users' online anonymity

#142

Earlier quoted context omitted.

A better chance than one would think from that phrasing, as there are a lot of highly motivated and intelligent people working on privacy tech.

It doesn't matter. Protecting privacy is too big a goal. In the end, why does the NSA do what it does? To get specific, actionable intelligence. Everyone in the world's privacy is just collateral damage. But, turn that around. Protecting your privacy (never mind anyone else's) is too big a goal. It's too easily breached. Instead, think of what specific information you feel you need to keep private, and how you might…

"Having something specific to hide leads to questions of why? To what end? Should we be worried?"

Why do you close the doors when you go to the bathroom? What are you hiding? Should we be worried?

Re: Attacking Tor: How the NSA targets users' online anonymity

#143

> Once the computer is successfully attacked, it secretly calls back to a FoxAcid server, which then performs additional attacks on the target computer to ensure that it remains compromised long-term It would be nice if somebody could honeypot them to find out the vulns and malware types they are using.

How so I get on the list of most interesting persons so I can setup my honeypots? do I have to be jacob appelbaum or assange?

what freaked me out is that they deliver sensible exploits for techie people. go damnit.

Re: Attacking Tor: How the NSA targets users' online anonymity

#144

> Once the computer is successfully attacked, it secretly calls back to a FoxAcid server, which then performs additional attacks on the target computer to ensure that it remains compromised long-term It would be nice if somebody could honeypot them to find out the vulns and malware types they are using.

How so I get on the list of most interesting persons so I can setup my honeypots? do I have to be jacob appelbaum or assange?

what freaked me out is that they deliver sensible exploits for techie people. go damnit.

Re: Attacking Tor: How the NSA targets users' online anonymity

#145
post #88

Earlier quoted context omitted.

What if you ran scripts on your phone and computer so that it would appear as if you were browsing the internet and using your computer during your regular usage times? Also using public transportation (and paying for it in cash) will help mitigate the first issue your brought up.

Until CCTV is combined with facial recognition!

trapwire

http://www.theguardian.com/world/2012/aug/13/trapwire-survei...

Re: Attacking Tor: How the NSA targets users' online anonymity

#146
post #44

Earlier quoted context omitted.

>(here, there's a subtext that Tor actually made NSA's job easier) I'm not sure how you reached that conclusion. The slides mention that Tor is: * Very difficult to identify on the network-level, since Tor-tls traffic is indistinguishable from Apache-tls traffic as of 2011 * Impossible to fully deanonymize * Only exploitable via a handful of browser exploits. Further, later in the "Tor is the King" slide deck, there'…

Will tails still only use ram and no disk within a vm? If not, you'll just have a slightly better tor browser bundle (plus other features) right? I always thought the "ram only" portion of tails was one of the biggest anonymity wins.

If the VM doesn't have a disk, then yes...

Re: Attacking Tor: How the NSA targets users' online anonymity

#147
post #128
post #113

Earlier quoted context omitted.

One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking. Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the underst…

> That used to be a tin-foil hat idea just a few months ago, and we know better now. If NSA comes carrying gifts, it warrant being very careful in accepting them from a party with such hostile priorities. Well, not really. The "tinfoil" idea is that NSA is breaking into crypto so that they can blackmail politicians, black-bag innocent citizens, etc. But it was never widely assumed that NSA wasn't trying to break ever…

There is a difference between trying to break cryptography, and prioritizing breaking cryptography over protecting civilians.

This is true for almost everything in the world. I want for example that the police try to stop criminals, but I do not want them to go around with minigun's and spraying the street with bullets. I want the police to prioritize the safety of civilians.

Same goes for NSA. They are perfectly free to try break hostile entities encryption, but they should not sabotage US civilians security while doing so. When they sabotage standards, or keep vulnerabilities secret so they and criminals can break into peoples computers, then NSA is not prioritizing protecting civilians.

Re: Attacking Tor: How the NSA targets users' online anonymity

#149
post #140
post #44

Earlier quoted context omitted.

>(here, there's a subtext that Tor actually made NSA's job easier) I'm not sure how you reached that conclusion. The slides mention that Tor is: * Very difficult to identify on the network-level, since Tor-tls traffic is indistinguishable from Apache-tls traffic as of 2011 * Impossible to fully deanonymize * Only exploitable via a handful of browser exploits. Further, later in the "Tor is the King" slide deck, there'…

TAILS will detect it is running inside a VM and warn you not to do it. I know quite a few folks who are sitting on escapes for popular VM products. They are not at all uncommon. I would be absolutely shocked if the NSA's little toolkit didn't detect virtualization, pop out, and backdoor the host OS.

And if you run it on your main machine it could exploit it and mount hard drive. You need another diskless computer just for this...

Re: Attacking Tor: How the NSA targets users' online anonymity

#150
post #93

Earlier quoted context omitted.

tptacek, I'm not sure I understand: do these new revelations really indicate indie developers don't have a fighting chance against Iran ? U.S. - absolutely, no fighting chance. China - chances look slim. Iran, Belarus - are you familiar with the technical achievements of their NSA equivalents, and so came to the conclusion they're likely as good as the NSA? Or maybe what the NSA did is just generally easy to do in yo…

Iran spends ~10bn/yr for the "on the books" part of their military. How much vulnerability research do you think $500MM buys? Answer: a lot.

Yes, but I'm not sure that justifies the end conclusion:

1. Do we actually know Iran spends $500MM on vulnerability research? What about Belarus?

2. Suppose they do. So they have zero-day exploits, sure. IIUC, you need MITM capabilities to execute an attack on tor like the NSA did. This sounds costly, and I'm not sure it can be outsourced like buying zero-days. It also requires, ummm, "being on good terms" with telcos, backbone providers etc., which I'm not sure Iran is.

So I'm not saying it's inconceivable that Iran can attack tor users, but the opposite also sounds plausible.

Post reply on HN