Live data from Hacker News

Use of Tor and e-mail crypto could increase chances that NSA keeps your data

arstechnica.com

101–110 of 116 posts

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#101
post #93
post #87

Earlier quoted context omitted.

It's less of a big deal because states spy on other states, even their allies. It has been that way since the beginning and everyone usually turns a blind eye unless it either gets leaked and causes embarrassment or it results in a real security risk as in the case of Pollard. Every one of the countries currently lodging complaints over the story of the UK's GCHQ hacking G20 delegates possesses a communications intel…

Sure, I agree that governments spying on other governments is something that is a necessary evil up to a certain point. In my opinion this is vastly different from a government reading and storing pretty much all foreign communication they can get their hands on from an allied state citizens though, something I understand the USA/NSA seems to be doing.

Thing is though, that doesn't matter. No country places any restrictions on whether the foreigners its spy services monitor are part of a foreign government or not because it wouldn't make any sense. To use a pertinent example, none of the dozens of countries trying to intercept al-Qaeda communications cares which country they're in as long (in most cases) as they're not domestic.

So what the NSA is doing to foreign citizens is no different to what every other country with the means does. My country will happily (and legally) spy on American citizens indiscriminately if it feels the need to, as will all of Europe.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#102
post #60
post #6

This is somewhat unrelated, but I was listening to "Leo Laporte The Tech Guy" on the local talk radio with my dad (who is a big fan, but less into tech than I) and he started describing GPG and PGP to non-tech enthusiasts. This whole NSA scandal may really push forward the use of encryption of securer communication methods.

Only if it pushes developers to make the tools dead-simple to use. If it is harder to use than facebook, 99% of the population will not bother.

Exactly this. Even though we had the company policy and Symantec PGP software installed, the engineers I worked with sill failed to use it regularly. I remember having to logmein to machine in China to try to figure out why they couldn't read our emails. This is why PGP never took off.

Until the tools take 5 min to setup. And encryption/decryption is as easy as clicking a checkbox in your mail client, PGP will never take off. Things like the public key directory have to handled transparently to the user.

It's too bad Mozilla dropped support for Thunderbird. Tight integration with GnuPG could have made mainstream PGP a reality.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#103
post #15

If you want to read the documents without having to use that awful viewer or load js from every social networking site known to man: (increment the p# from 1-9) Procedures used by NSA to target non-US persons: Exhibit A: https://s3.amazonaws.com/s3.documentcloud.org/documents/7166... Procedures used by NSA to minimize data collection from US persons: Exhibit B: https://s3.amazonaws.com/s3.documentcloud.org/documents/…

Or all pages in PDF: https://s3.amazonaws.com/s3.documentcloud.org/documents/7166... https://s3.amazonaws.com/s3.documentcloud.org/documents/7166...

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#104
post #69

Earlier quoted context omitted.

Also, if you don't want to run a node on your home network/machine http://cloud.torproject.org/ makes it ridiculously easy to set up one on EC2 (for as little as ~$3/month)

Q: Should I run an exit relay from my home? A: No. If law enforcement becomes interested in traffic from your exit relay, it's possible that officers will seize your computer. For that reason, it's best not to run your exit relay in your home or using your home Internet connection. Instead, consider running your exit relay in a commercial facility that is supportive of Tor. Have a separate IP address for your exit re…

Its worth pointing out that that is talking specifically about exit nodes. There is no (legal) problem with running relay nodes out of your own house.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#105
post #83

Earlier quoted context omitted.

What is the current number of Tor nodes? What's to say that all tor nodes are now monitored? It's possibly a smaller task than storing all voice calls etc.

It might seem a smaller task in terms of needed servers but your suspicion fails with the simple fact that anyone can add a relay to the network and thus counter the surveillance. I run a non-exit node on every webserver I got because it's cheap and feels good.

You don't need to run all of the exit nodes. If a group controls even 10% of the exit node bandwidth, then they have access to 10% of the traffic and can do major analysis. Even if you use end to end encryption (as in https), than with 10% of the endnote bandwidth, they would see the entry and exit of 1% of all packets, and can (probably) correlate them (with timing) to associate the incoming and outgoing. And if you use tor regularly, then every time either your entry or exit node changes, they get another 1% dice roll.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#106
post #69

Earlier quoted context omitted.

Q: Should I run an exit relay from my home? A: No. If law enforcement becomes interested in traffic from your exit relay, it's possible that officers will seize your computer. For that reason, it's best not to run your exit relay in your home or using your home Internet connection. Instead, consider running your exit relay in a commercial facility that is supportive of Tor. Have a separate IP address for your exit re…

Its worth pointing out that that is talking specifically about exit nodes. There is no (legal) problem with running relay nodes out of your own house.

What part of "Should I run an exit relay from my home?" was unclear? I am not trying to discourage people from supporting the tor network, quite the opposite actually. I want to make sure they are fully informed and support tor in a manner that is sustainable.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#107
post #83

Earlier quoted context omitted.

It might seem a smaller task in terms of needed servers but your suspicion fails with the simple fact that anyone can add a relay to the network and thus counter the surveillance. I run a non-exit node on every webserver I got because it's cheap and feels good.

You don't need to run all of the exit nodes. If a group controls even 10% of the exit node bandwidth, then they have access to 10% of the traffic and can do major analysis. Even if you use end to end encryption (as in https), than with 10% of the endnote bandwidth, they would see the entry and exit of 1% of all packets, and can (probably) correlate them (with timing) to associate the incoming and outgoing. And if you…

Q: What are Entry Guards?

A: Tor (like all current practical low-latency anonymity designs) fails when the attacker can see both ends of the communications channel. For example, suppose the attacker controls or watches the Tor relay you choose to enter the network, and also controls or watches the website you visit. In this case, the research community knows no practical low-latency design that can reliably stop the attacker from correlating volume and timing information on the two sides.

So, what should we do? Suppose the attacker controls, or can observe, C relays. Suppose there are N relays total. If you select new entry and exit relays each time you use the network, the attacker will be able to correlate all traffic you send with probability (c/n)2. But profiling is, for most users, as bad as being traced all the time: they want to do something often without an attacker noticing, and the attacker noticing once is as bad as the attacker noticing more often. Thus, choosing many random entries and exits gives the user no chance of escaping profiling by this kind of attacker.

The solution is "entry guards": each Tor client selects a few relays at random to use as entry points, and uses only those relays for her first hop. If those relays are not controlled or observed, the attacker can't win, ever, and the user is secure. If those relays are observed or controlled by the attacker, the attacker sees a larger fraction of the user's traffic — but still the user is no more profiled than before. Thus, the user has some chance (on the order of (n-c)/n) of avoiding profiling, whereas she had none before.

You can read more at An Analysis of the Degradation of Anonymous Protocols, Defending Anonymous Communication Against Passive Logging Attacks, and especially Locating Hidden Servers.

https://www.torproject.org/docs/faq.html.en#EntryGuards

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#108

I think that the idea that "using crypto will cause the nsa to keep your data longer" is a hindrance to progress. Everyone should be using crypto and everyone should have privacy. When we begin to be afraid of what someone will do if we protect our interests, we start giving up those interests and that is not something I am prepared to do.

Maybe the prospect of someday burning gigawatts to decipher my elliptic-curved peanut-butter-cookie recipes will alert them to what a charade they're part of.

We must create boogeymen from a vacuum so that we can burn taxpayer dollars to further enrich the right people. Unlike biochemicals, encryption, storage and analysis are benevolent forms of collateral damage as they lead to increases in computing power and mathematical insights.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#109
post #17

The only long-term way to hide data is not to use public networks for communication. Eventually, quantum computers should be able to eat though any of today's crypto. It will be interesting to see what happens when everyone running for public office has their entire life on display.

> Eventually, quantum computers should be able to eat though any of today's crypto Probably not. Quoting from http://blog.agilebits.com/2013/03/09/guess-why-were-moving-t... : A quantum of bits [Update: March 20, 2013] I reached out to the cryptographic community for any insight into Molly’s question about why the NSA insists that TOP SECRET material be encrypted using 256-bit keys. The answer came from Steven Bellov…

Thanks, that's a good read. I'm interested to see how effective it will be. I'm certainly not saying we'll be able to break non-deterministic crypto, but there's a lot we should be able to do that's out of our reach right now.

We're so early in development that we don't know how quickly we'll be able to scale them, but if we solve a few physical problems, we're looking the ability to scale up resources for linear costs for exponential rewards. With on-demand cloud pricing models for computing becoming the norm, normal people could do some pretty amazing things. It's hard to predict how quickly this will come, but it will definitely come eventually.

Re: Use of Tor and e-mail crypto could increase chances that NSA keeps your data

#110
post #106

Earlier quoted context omitted.

Its worth pointing out that that is talking specifically about exit nodes. There is no (legal) problem with running relay nodes out of your own house.

What part of "Should I run an exit relay from my home?" was unclear? I am not trying to discourage people from supporting the tor network, quite the opposite actually. I want to make sure they are fully informed and support tor in a manner that is sustainable.

Some people might not realize there are different types of nodes you can run.
Post reply on HN