Live data from Hacker News

Tor and HTTPS

eff.org

11–20 of 135 posts

Re: Tor and HTTPS

#11
post #2

When using Tor+HTTPS, the first NSA eavesdropper can see location. How serious is that?

By location they mean your IP (from which they can get your address, by asking the ISP). As long as they can't links the two captured packets, they just know that you're using Tor.

Well your IP determines your location. That other evasdropper is from your ISP, since you first connect to your ISP and then Tor. Your ISP potentially knows your location which is what the NSA evasdropper gets.

And since its shared with amongst both the evasdropper, potentially NSA knows your location even if you use Tor. They should have indicated that too I guess.

Re: Tor and HTTPS

#12
post #3

An excellent illustration for those already familiar with the concepts. However, I not sure its that easy to understand for those who don't know what "location" means, and the text is slightly small and hard to read. It would be a great improvement if they showed a small help text if one hovered over a label inside one of the yellow boxes. Still, a very excellent job of EFF.

I guess "location" means "IP Address". It's not your location in the URL bar, as HTTPS encrypts the connection, not just HTTP request body.

Re: Tor and HTTPS

#13
post #4

How secure is ssl? Can't NSA fake a certificate?

I'm sure they can "ask nicely" to get a working cert from a CA. It's why newer versions of browsers are implementing certificate pinning, which should help (but not solve) with the issue by locking the browser to a specific certificate.

Re: Tor and HTTPS

#14
post #2

When using Tor+HTTPS, the first NSA eavesdropper can see location. How serious is that?

We don't know. It slightly depends on how much worse things get in the US. You might get a permanent flag in "your file" as a potential troublemaker, but so might living in the wrong neighborhood, or going to the wrong bar, or being acquainted with someone under NSA suspicion. It's impossible to know what will or will not be put in the file, or which flags will give you grief (without you ever knowing why) when visiting an airport or when applying for a job.

Re: Tor and HTTPS

#15
post #6
post #2

When using Tor+HTTPS, the first NSA eavesdropper can see location. How serious is that?

Well only if its from your ISP. And the illustration should add that both the NSA eavesdropper(s) would get that information actually. Since data is shared.

The data is shared, but the question is whether or not they can link it.

Re: Tor and HTTPS

#16
post #3

An excellent illustration for those already familiar with the concepts. However, I not sure its that easy to understand for those who don't know what "location" means, and the text is slightly small and hard to read. It would be a great improvement if they showed a small help text if one hovered over a label inside one of the yellow boxes. Still, a very excellent job of EFF.

I guess "location" means "IP Address". It's not your location in the URL bar, as HTTPS encrypts the connection, not just HTTP request body.

HTTPS doesn't encrypt the domain. That said, Tor does.

Re: Tor and HTTPS

#17
post #11

Earlier quoted context omitted.

By location they mean your IP (from which they can get your address, by asking the ISP). As long as they can't links the two captured packets, they just know that you're using Tor.

Well your IP determines your location. That other evasdropper is from your ISP, since you first connect to your ISP and then Tor. Your ISP potentially knows your location which is what the NSA evasdropper gets. And since its shared with amongst both the evasdropper, potentially NSA knows your location even if you use Tor. They should have indicated that too I guess.

Sharing the data is not enough, they have to link it to be useful. They probably can, though.

Re: Tor and HTTPS

#18
post #2

When using Tor+HTTPS, the first NSA eavesdropper can see location. How serious is that?

well, it is serious, in that it's the most likely weak point in tor. however, exactly how serious is still an open question.

remember - what the nsa wants is both your location and the site. your location alone only means that you were using the internet (and tor, which itself might be regarded a suspicious). the site alone only means someone was using the site. what the NSA have to do is connect those.

so everything depends on whether the two NSA people can "join up the dots" (graphically, in that diagram, the dark blue dots joining them). because there's nothing "obvious" that tells them that the message with the location is connected to the message with the site.

if they can't make that connection, then they don't know anything useful.

but if they can make that connection, then they know that you (well, someone at your location - an open wifi might give you a little deniability, for example) looked at that site.

the way they might be able to do it is by comparing traffic patterns. if they can show, for example, that every time you send a request, the site receives a request, and if that happens again and again, so reliably that it cannot be chance, then they can make the connection.

so it depends on things like the frequency with which you look at the site, the amount of (tor) traffic when you are around, and the ability of the NSA to assemble and correlate large amounts of data.

[disclaimer: not an expert; i don't know the current state of play on how bad a problem this is; i just know it's a known issue. and if i were going up against the nsa, i wouldn't trust tor alone - i'd use an anonymous, disposable, portable connection device, and keep data to an absolute minimum.]

Re: Tor and HTTPS

#19
post #9
post #3

An excellent illustration for those already familiar with the concepts. However, I not sure its that easy to understand for those who don't know what "location" means, and the text is slightly small and hard to read. It would be a great improvement if they showed a small help text if one hovered over a label inside one of the yellow boxes. Still, a very excellent job of EFF.

There’s a little description text at the top explaining the meaning of the various labels, including ‘location’ (the last bullet point).

The term "IP address" would be similarly confusing. What would help is if they explained in context what it means, for example when a lawyer of one's ISP knows about location and site (possible termination of contract, providing it to NSA, selling it and so on).

Also, using a help window when hovering would be a quite better UX than a glossary.

Re: Tor and HTTPS

#20
post #3

An excellent illustration for those already familiar with the concepts. However, I not sure its that easy to understand for those who don't know what "location" means, and the text is slightly small and hard to read. It would be a great improvement if they showed a small help text if one hovered over a label inside one of the yellow boxes. Still, a very excellent job of EFF.

I guess "location" means "IP Address". It's not your location in the URL bar, as HTTPS encrypts the connection, not just HTTP request body.

You guessed right, see the key on top.
Post reply on HN