Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

161–170 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#161

Earlier quoted context omitted.

It doesn't matter. Protecting privacy is too big a goal. In the end, why does the NSA do what it does? To get specific, actionable intelligence. Everyone in the world's privacy is just collateral damage. But, turn that around. Protecting your privacy (never mind anyone else's) is too big a goal. It's too easily breached. Instead, think of what specific information you feel you need to keep private, and how you might…

"Having something specific to hide leads to questions of why? To what end? Should we be worried?" Why do you close the doors when you go to the bathroom? What are you hiding? Should we be worried?

Because it's polite and it limits the diffusion of bad smells. If you really want to see my dick all you have to do is go on chatroulette. No need to follow me to the toilet. Unless you're interested in more than just looking.

Re: Attacking Tor: How the NSA targets users' online anonymity

#162
post #13

The more we learn about the NSA's capabilities, the more it seems like the Manhattan Project. They are developing the "cyberwarfare" equivalents of weapons of mass destruction. This exploit delivery network goes so far beyond any legitimate purpose it might serve that it belongs in the same moral category as hydrogen bombs. EDIT: The above is somewhat hyperbolic and unclear. The NSA's capabilities may have legitimate…

Hardly. The NSA's techniques, as described thus far, appear to be your basic computer security fodder. The same techniques that any modest black hat could do.

The difference is in the scale and dedication.

Re: Attacking Tor: How the NSA targets users' online anonymity

#163
post #128

Earlier quoted context omitted.

> That used to be a tin-foil hat idea just a few months ago, and we know better now. If NSA comes carrying gifts, it warrant being very careful in accepting them from a party with such hostile priorities. Well, not really. The "tinfoil" idea is that NSA is breaking into crypto so that they can blackmail politicians, black-bag innocent citizens, etc. But it was never widely assumed that NSA wasn't trying to break ever…

The NSA shouldn't just be an attacker it should also provide defence. If one of their many contractors can leak details to the press for idealogical ends it's pretty safe to assume that much worse secrets have already been leaked to other nation states (China, Russia etc....) for financial gain. I think it's entirely reasonable to assume that a lot of exploits the NSA has discovered and not revealed (because it think…

If one of their many contractors can leak details to the press for idealogical ends it's pretty safe to assume that much worse secrets have already been leaked to other nation states (China, Russia etc....) for financial gain.

Especially as the agency in question appears to have no compartments or levels of access. I've been wondering how a comparatively junior contract worker could access so much information...

Re: Attacking Tor: How the NSA targets users' online anonymity

#164
post #110

Earlier quoted context omitted.

The weak point as usual are the endpoints. The attack vector described in these documents is JavaScript via some library called E4X. Makes me wonder why Tor bundle doesn't come with NoScript enabled by default.

Utopistically, how nice would be if the whole web provided no-javascript versions of the sites? In the end 90% of the cases javascript is used just to do fancy things, while actual functionalities could be achieved with much less pain (and vulnerability).

I think this would have been true a few years back, but I think more and more web-sites are using javascript in irreplaceable waves. I suspect javascript will become increasingly necessary as frameworks like angularjs become more popular. That said, if you are just interested in buying a pizza, or reading a blog post, then maybe javascript will never be really necessary.

Re: Attacking Tor: How the NSA targets users' online anonymity

#165

Earlier quoted context omitted.

Personally I had the idea a while back for a sort of time-release dead drop. Stuff a Raspberry Pi into a fake power strip, put your seekrit information onto the SD card, and go plug it in somewhere in a city you 'happen' to be passing through, near to a public wifi spot. Then a year later it wakes up and uploads the data publicly via Tor and self-wipes. Even if it's traced back to the Pi, they'll have to trace the Pi…

How can you buy a Pi untraceably? Last time I checked you could buy them from e-stores using credit cards..

Pay a stranger like $300 to buy you at $25 Raspberry Pi?

Re: Attacking Tor: How the NSA targets users' online anonymity

#166
post #159
post #147

Earlier quoted context omitted.

There is a difference between trying to break cryptography, and prioritizing breaking cryptography over protecting civilians. This is true for almost everything in the world. I want for example that the police try to stop criminals, but I do not want them to go around with minigun's and spraying the street with bullets. I want the police to prioritize the safety of civilians. Same goes for NSA. They are perfectly fre…

> When they sabotage standards, or keep vulnerabilities secret so they and criminals can break into peoples computers, then NSA is not prioritizing protecting civilians. Even the standards that they have been shown to sabotage (Lotus Notes, Clipper, Dual_EC_DRBG), they have sabotaged it in a way that should have reduced the security of the system against NSA , but not in general. I'll note that I disagree with this c…

> something rotten with them.

Like spying on us?

Re: Attacking Tor: How the NSA targets users' online anonymity

#167
post #118
post #113

Earlier quoted context omitted.

One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking. Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the underst…

> It was generally thought that government would not keep security vulnerabilities hidden Was that what people thought? Were there vulnerability reports in open-source software that were coming from the NSA or thought to be coming from the NSA? Surely everyone knew that the NSA was capable of finding exploits in software, and I would think that it would be hard to keep secret whether or not they're being reported. >…

There's a video from the RSA conference in 2011 with Dickie George, who was the director for Information Assurance at NSA when DES was being reviewed. He claims that the agreement between NIST and NSA was that: 1, NSA would only change things if they could find a specific problem with the cipher, and 2, NSA promised that DES would have security equal to its key size. The implication is then that they decided that 56 bits was how secure it was, and then picked that as the key size.

You can believe him or not, but I don't see any particular reason not to.

link to the video, the relevant bit is ~8min in: http://www.youtube.com/watch?v=0NlZpyk3PKI

Re: Attacking Tor: How the NSA targets users' online anonymity

#168
post #140

Earlier quoted context omitted.

TAILS will detect it is running inside a VM and warn you not to do it. I know quite a few folks who are sitting on escapes for popular VM products. They are not at all uncommon. I would be absolutely shocked if the NSA's little toolkit didn't detect virtualization, pop out, and backdoor the host OS.

And if you run it on your main machine it could exploit it and mount hard drive. You need another diskless computer just for this...

Are there any small, cheap laptops with optical drives?

Another alternative is having enough 1gb usb sticks to be able to throw them away on a regular basis. Sort of like burner phones.

(Personally I'm not sure I want to go so far as to buy a separate computer for private use now, but I might as well know how to do it.)

Re: Attacking Tor: How the NSA targets users' online anonymity

#169
post #140

Earlier quoted context omitted.

TAILS will detect it is running inside a VM and warn you not to do it. I know quite a few folks who are sitting on escapes for popular VM products. They are not at all uncommon. I would be absolutely shocked if the NSA's little toolkit didn't detect virtualization, pop out, and backdoor the host OS.

And if you run it on your main machine it could exploit it and mount hard drive. You need another diskless computer just for this...

Not just diskless, but somehow incapable of flashing the BIOS, rewriting the CPU microcode, and loading new firmware into the NICs and other peripherals.

Re: Attacking Tor: How the NSA targets users' online anonymity

#170
post #13

The more we learn about the NSA's capabilities, the more it seems like the Manhattan Project. They are developing the "cyberwarfare" equivalents of weapons of mass destruction. This exploit delivery network goes so far beyond any legitimate purpose it might serve that it belongs in the same moral category as hydrogen bombs. EDIT: The above is somewhat hyperbolic and unclear. The NSA's capabilities may have legitimate…

Maybe the NSA cyberwar effort did not produce new earth shaking insights; the manhattan project did that of course. Now both efforts may be compared in terms of their price tag: both did cost billions of tax dollars to implement.

Interesting that instead of reaching out for the stars we turn inwards - snooping as the new frontier that is pushing technology forward, now here is a great prospect ...

Post reply on HN