Earlier quoted context omitted.
A Tor user at Harvard was successfully tracked when he sent a bomb threat, since he was the only user on the Harvard LAN using Tor at the time the threat was issued. That wasn't proof , of course, but it didn't need to be proof, just a good lead for law enforcement to kick-start their investigation.
My analysis of that incident: http://grugq.github.io/blog/2013/12/21/in-search-of-opsec-ma...
SecureDrop
91–99 of 99 posts
Re: SecureDrop
#92Earlier quoted context omitted.
Fortunately, they can't do that for all the open/WEP/WPS wireless APs everywhere.
They've done a pretty good job of scaring people into securing their APs (which is also a legitimate thing in most cases); just publishing some stories about people having ISP service cut off due to freeloaders doing bad stuff would probably be enough; wouldn't even need to try to prosecute some.
Re: SecureDrop
#93If the leaker visits this page before opening the Tor Browser from a regular browser to copy the onion url, the whole thing is as safe as SSL as there will be a trail of the SSL connection just before the visit to SecureDrop. And they don't even explain to avoid it. OPSEC is hard.
Re: SecureDrop
#94If the leaker visits this page before opening the Tor Browser from a regular browser to copy the onion url, the whole thing is as safe as SSL as there will be a trail of the SSL connection just before the visit to SecureDrop. And they don't even explain to avoid it. OPSEC is hard.
Please correct me if I'm wrong but, right now, at home, I visited that site. Hardly suspicious at all, since it's on HN front page. I could write down the .onion url on a piece of paper (or just print the page, as reference) and then later follow the instructions posted there, at a semi-anonymous Internet cafe, without having to visit that page, right?
Re: SecureDrop
#95In case you don't have Tor installed and want to know what it looks like: https://imgur.com/GbwKfuG,D2aWi25,glApNg3
Very refreshing to see a big, red warning in the screenshot about the fact that Javascript is enabled ! Usually you see the same thing when Javascript is disabled, asking you to enable it.
[edit] Nerdier link with exploit demo: http://resources.infosecinstitute.com/fbi-tor-exploit/
Re: SecureDrop
#96One would have to assume that all the traffic going to the server is logged by the NSA and anyone else who can manage it. If the traffic volume is low then timing correlation with even a large pool of suspects is simple. An active attacker can differentiate between the SSL connection from a web browser and one from a tor node, so the background SSL traffic to the Post would not provide cover.
I think it could be improved by using a mix network (eg mixminion) accessed over tor, rather than just tor.
Unfortunately the mixmaster/mixminion networks are currently too small to provide meaningful complexity. Large scale adoption by, eg, newspapers, is not technically hard and would significantly complicate the adversary problem.
I'd love to see more discussion of bitmessage and Pond (https://pond.imperialviolet.org/)
Re: SecureDrop
#97Earlier quoted context omitted.
I think the technology confuses two things: 1. Encrypted traffic between device and wireless hotspot 2. Restricted access to the wireless hotspot (you need a password or it won't give you service) I want to allow anonymous access, but let the traffic be encrypted. Is there a technical reason why this is not implemented? I'm very sad by the culture (and moreso, the legal necessity) of restricting wireless access. I wa…
You can run an access point with all the benefits of WPA2/AES, but make the password really simple. Setting your SSID to "PasswordIsBacon" or just using the same SSID and password is a fairly easy way to share access, without running a completely insecure, unencrypted network.
Re: SecureDrop
#98The Guardian has also released a secure drop platform: http://www.theguardian.com/technology/2014/jun/05/guardian-l... https://securedrop.theguardian.com/
This is a different deployment of the same product [1]. Which, incidentally, was originally created by Aaron Swartz. The Wikipedia page[2] has a list of well-known deployments. [1] https://pressfreedomfoundation.org/securedrop [2] http://en.wikipedia.org/wiki/SecureDrop
Re: SecureDrop
#99Earlier quoted context omitted.
This is a different deployment of the same product [1]. Which, incidentally, was originally created by Aaron Swartz. The Wikipedia page[2] has a list of well-known deployments. [1] https://pressfreedomfoundation.org/securedrop [2] http://en.wikipedia.org/wiki/SecureDrop
Thanks for pointing that out. I just watched "The Internet's Own Boy", the documentary about Aaron, and it is positively incredibly how many projects Aaron created or played a critical role in creating. An unthinkable shame that he left us so soon — one can only imagine all the things he had left to create.