Two months after FBI debacle, Tor Project still can’t get an answer from CMU
1–10 of 48 posts
Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#2Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#3This continues to reflect very poorly on CMU and CERT.
Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#4This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol nature, then maybe it's time to look for a successor (we aren't using WEP anymore, right?)
As to the CMU stuff... Tokyo University has this pledge to make sure basically no military research is done on campus, which I feel to be pretty laudable.
I wonder if there's a similarly worded pledge for this sort of thing. But at the same time, universities can do a lot of good security research that can, in the end, strengthen the systems we use.
The "$1 million to target these specific people" sounds dirty, but "$1 million to do research on the vulnerabilities of Tor"... well that sounds like research to me. Pretty tricky.
Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#5This continues to reflect very poorly on CMU and CERT.
Yes, but if they're under some Kafkaesque gag order there not much they can do right?
But it looks like they put themselves in that position. Either by voluntary working with the FBI and allegedly taking a $1M grant, and/or doing unethical research by doing it on the live network.
Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#6>... a few weeks earlier had canceled a security conference presentation on a low-cost way to deanonymize Tor users. The Tor officials went on to warn that an intelligence agency from a global adversary also might have been able to capitalize on the vulnerability. This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol natur…
[0] https://blog.torproject.org/blog/tor-security-advisory-relay...
Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#7Earlier quoted context omitted.
Yes, but if they're under some Kafkaesque gag order there not much they can do right?
To be clear, NSL are anti-democratic and wrong. But it looks like they put themselves in that position. Either by voluntary working with the FBI and allegedly taking a $1M grant, and/or doing unethical research by doing it on the live network.
(I mean, I guess it's possible for an NSL to order you to do anything, because America.)
Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#8>... a few weeks earlier had canceled a security conference presentation on a low-cost way to deanonymize Tor users. The Tor officials went on to warn that an intelligence agency from a global adversary also might have been able to capitalize on the vulnerability. This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol natur…
So, you move it off-campus. See e.g. the MIT Lincoln Lab, https://www.ll.mit.edu/
Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#9>... a few weeks earlier had canceled a security conference presentation on a low-cost way to deanonymize Tor users. The Tor officials went on to warn that an intelligence agency from a global adversary also might have been able to capitalize on the vulnerability. This is kind of worrying. I hope the Tor Project has information on the attack is looking into ways to mitigate this. But if it's due to the protocol natur…
People needing a high level of protection can use and should use Tor in their workflow but they should not expect a one-click solution. On the other hand, it's perfectly adequate for day to day use of privacy minded individuals that are not targeted by active attacks.
Re: Two months after FBI debacle, Tor Project still can’t get an answer from CMU
#10Earlier quoted context omitted.
To be clear, NSL are anti-democratic and wrong. But it looks like they put themselves in that position. Either by voluntary working with the FBI and allegedly taking a $1M grant, and/or doing unethical research by doing it on the live network.
Is it possible for an NSL to order you to conduct your research on the live network? (I mean, I guess it's possible for an NSL to order you to do anything , because America.)