Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

11–20 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#11
post #7

Metacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world g…

I didn't read it that way at all, in fact, it sounds like Tor is sufficiently robust that a good number of NSA employees were tasked with finding exploits. In terms of the exploits found, it looks like all were against the browser.

  Tor is a well-designed and robust anonymity tool, and 
  successfully attacking it is difficult. The NSA attacks we 
  found individually target Tor users by exploiting 
  vulnerabilities in their Firefox browsers, and not the Tor 
  application directly.

Re: Attacking Tor: How the NSA targets users' online anonymity

#12
This is one way the NSA can attack Tor. if they just want to de-anonymize a connection, not get access to the content, (.e.g to locate the Silk Road Sever), in theory they can just analyze all their passively collected data form major fiber backbones to identify and locate the user.

Tor, including hidden services, was never designed to protect against someone who could observe all or almost all traffic in the Tor network. Given that data, it's rather easy to correlate timing information. Indeed, Tor fundamentally allows this since it aims to be a low latency network.

Given the NSA's extensive tapping of key fiber lines, we should assume they can actually observe the necessary traffic.From the original paper announcing Tor: "A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary." --- Tor: The Second Generation Onion Router [0] [0] https://svn.torproject.org/svn/projects/design-paper/tor-des...

Re: Attacking Tor: How the NSA targets users' online anonymity

#13
The more we learn about the NSA's capabilities, the more it seems like the Manhattan Project. They are developing the "cyberwarfare" equivalents of weapons of mass destruction. This exploit delivery network goes so far beyond any legitimate purpose it might serve that it belongs in the same moral category as hydrogen bombs.

EDIT: The above is somewhat hyperbolic and unclear. The NSA's capabilities may have legitimate uses. Similarly, there may be legitimate military uses for nuclear weapons. But building nuclear weapons creates the risk of worldwide nuclear destruction. Similarly, building this kind of highly efficient exploit system creates the risk of destroying all Internet security. The potential destruction far outweighs whatever good the weapons might accomplish. That is why I said they belong in the same category.

Re: Attacking Tor: How the NSA targets users' online anonymity

#14
This accompanying article has useful context: http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack...

> But the documents suggest that the fundamental security of the Tor service remains intact. One top-secret presentation, titled 'Tor Stinks', states: "We will never be able to de-anonymize all Tor users all the time." It continues: "With manual analysis we can de-anonymize a very small fraction of Tor users," and says the agency has had "no success de-anonymizing a user in response" to a specific request.

So only with "manual analysis" can intel agencies have any success, and that appears to be with a small subset of users who have other vulnerabilities. But when targeting a specific user, the NSA appears to have had no success in de-anonymizing them.

Re: Attacking Tor: How the NSA targets users' online anonymity

#18
> Once the computer is successfully attacked, it secretly calls back to a FoxAcid server, which then performs additional attacks on the target computer to ensure that it remains compromised long-term

It would be nice if somebody could honeypot them to find out the vulns and malware types they are using.

Re: Attacking Tor: How the NSA targets users' online anonymity

#19
post #13

The more we learn about the NSA's capabilities, the more it seems like the Manhattan Project. They are developing the "cyberwarfare" equivalents of weapons of mass destruction. This exploit delivery network goes so far beyond any legitimate purpose it might serve that it belongs in the same moral category as hydrogen bombs. EDIT: The above is somewhat hyperbolic and unclear. The NSA's capabilities may have legitimate…

I think that's a pretty serious exaggeration. Designing tools to let you spy on Tor traffic has to be in a separate category from designing bombs that could kill millions.

Besides, are there no ends that could justify these means? I think the means are altogether reasonable given the ends. Put aside whether you think the NSA is genuinely pursuing its national security mission: If it were, wouldn't it make perfect sense to figure out how to attack Tor?

Post reply on HN