Live data from Hacker News

The talk about de-anonymizing Tor at the BlackHat conference has been removed

tux.so

11–20 of 52 posts

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#12

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

I disagree. The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. No political action is going to stop all such entities in the world from monitoring web traffic, let alone prevent non-government entities from doing so. I am not saying Tor is the answer, but whatever the answer is, it will have to be technical.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#13

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

I think the opposite is the right thing. We should try to get everyone on that list.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#14

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

True, but if everyone were to use Tor all the time, everyone would be suspicious all the time, and therefore no one would be suspicious ever.

I'd like to see a pay-per-install Tor browser program materialize, one that would incentivize retailers and ISP techs to install Tor browser on customer devices. Every device should be connected to Tor from the moment it is powered on. Then we could at least go back to having free speech on the Internet.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#15

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

I disagree. The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. No political action is going to stop all such entities in the world from monitoring web traffic, let alone prevent non-government entities from doing so. I am not saying Tor is the answer, but whatever the answer is, it will have to be technical.

> The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible.

The vast majority of people do not want that Internet. See, for example, the popularity of Facebook. (About 1.2bn users per month).

You need technical measures, and law, and effective oversight.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#16

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

I disagree. The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. No political action is going to stop all such entities in the world from monitoring web traffic, let alone prevent non-government entities from doing so. I am not saying Tor is the answer, but whatever the answer is, it will have to be technical.

Well Tor is obviously not the answer, it introduces too much latency and at the moment very few nodes mostly located in the US bear the majority of all traffic. No technical solution will prevent governments from monitoring all important network hubs. It seems impossible to prevent them to gather at least metainformation there. If enough routers in an onion routing scheme are compromised the same is true. If there would be laws that guaranteed the physical integrity of data centers, it would definitely be much easier to devise safe routing protocols.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#17
post #13

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

I think the opposite is the right thing. We should try to get everyone on that list.

This is not realistic though and as I said it would actually help the security establishment and military if more people used Tor.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#18
post #13

Earlier quoted context omitted.

I think the opposite is the right thing. We should try to get everyone on that list.

This is not realistic though and as I said it would actually help the security establishment and military if more people used Tor.

It's pretty realistic given the impetus towards tor-enabled FOSS routers. Many people may begin using tor without ever realizing it, if certain people get their way and the tor network expands to allow such usage realistically.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#19
post #15

Earlier quoted context omitted.

I disagree. The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. No political action is going to stop all such entities in the world from monitoring web traffic, let alone prevent non-government entities from doing so. I am not saying Tor is the answer, but whatever the answer is, it will have to be technical.

> The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. The vast majority of people do not want that Internet. See, for example, the popularity of Facebook. (About 1.2bn users per month). You need technical measures, and law, and effective oversight.

I would guess that the vast majority of users don't know enough to have an opinion about the security and privacy of their browsing experience, but would be in support of such improvements if it caused them no inconvenience.

Law and "oversight" are really not likely to be effective. They're only useful as part of a "defense in depth" strategy, where we make it technically impossible for any attacker to get this information, and if our protocols have flaws in them, the government shouldn't be allowed to look at them anyway, so we have a second (weaker) layer of defense behind our primary defense.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#20

A Black Hat spokeswoman told Reuters that the talk had been canceled at the request of lawyers for Carnegie-Mellon University, where the speakers work as researchers. A CMU spokesman had no immediate comment. Source: http://www.reuters.com/article/2014/07/21/cybercrime-confere...

I have to imagine that this is for some sort of internal bureaucratic reason. I don't see who is in a position to even want to stop this talk - almost certainly not the Tor project itself.

The mundane (and thus most likely) answer is that the CMU lawyers wanted to pull it either because they want to sort out some sort of intellectual property first, or they're worried about some sort of liability.

Post reply on HN