"It is also important to remember that if you log into services like Google and Facebook over Tor, you will be sacrificing your anonymity to those services." It is important to note that both Google and FB can track you on 3rd party websites through things like "Like" button. Consider disabling 3rd party cookies completely or using plugins like Ghostery.
I've been browsing the internet for 15 years with 3rd-party cookies disabled. I never had ANY problems with any website - no idea if there would have been more functionality with 3rd-party cookies enabled. But then again, how can functionality depend on THIRD parties? Also activated the setting for my girlfriend years ago, no complaints so far. This feature should really be the default for any browser and any user. T…
Things You Should Know About Tor
101–110 of 115 posts
Re: Things You Should Know About Tor
#102I have a very strong suspicion that Tor is completely compromised, and that's actually how they caught Ross Ulbricht (Silk Road). All the stuff about his previous posting, etc, is tenuous and circumstantial-- it seems totally feasible that it is parallel construction. The "Tor Sucks" document is from 2012. It talks about the GCHQ running Tor nodes. What could have happened in the years since? https://metrics.torproje…
The latter part of that theory, that law enforcement agencies intentionally stepped up the resources for both the FH and SR cases in order to intentionally create disgust and distrust of Tor, is of course merely conjecture. Basically I find it an amazing coincidence that the two most notorious parts of the Tor hidden service world where busted very quickly after a huge amount of positive public attention was brought to Tor right after the Snowden leaks. Additionally if you actually look at the details of the FH exploit the FBI unleashed it is fairly useless, but very terrifying when you read just the headline. Legally there seems no useful reason to use such an easy to discover exploit that would have delivered no particularly interesting information. However from the stand point of creating public fear it worked marvelously. If you talk to even technical people that don't understand security and Tor well they often assume that the feds "hacked Tor". Which, in my opinion, is exactly what state actors want people to think.
As for the former part of the claim, that Tor is secure, look at the Snowden leaks about the methods that the NSA was thinking about for attacking Tor. Egotistical Giraffe, the attack used on FH, as mentioned was not a particularly useful exploit, and attacks user behavior not the network. Other similar leaks also suggest that neither the NSA nor any other state agency, has the ability to completely compromise Tor.
Finally,if you are a state agency and you have completely compromised Tor, you would actually want the general public to think it is safe. It is an amazing advantage to have your adversary think they are on a secure line when they absolutely are not. On the other hand if you haven't (and probably can't) compromised Tor you want the majority of people to think you have so that they disregard one of their best tools for defense.
Now of course there is plenty of evidence that federal agencies can perform targeted timing attacks against specific individuals. Tor does not and really cannot guard against this, and this has always been the case and fairly well known. If a state agency is targeting you specifically, I don't think there is anything you can do. However, given the information that is available to us, I do think it's reasonable to assume that Tor is secure from general, large scale, untargeted surveillance.
Re: Things You Should Know About Tor
#103Tails is not fool-proof when it comes to determining the IP address of a Tor user. A live CD would not have helped any FreedomHosting victim. The only way to do secure TOR is to use a distinct machine (NOT a VM!) as a gateway.
Yes it would have. That attack relied on both a Windows-specific vulnerability, and accessing the internet without Tor. Neither would have happened to a user of Tails.
Re: Things You Should Know About Tor
#104I have a very strong suspicion that Tor is completely compromised, and that's actually how they caught Ross Ulbricht (Silk Road). All the stuff about his previous posting, etc, is tenuous and circumstantial-- it seems totally feasible that it is parallel construction. The "Tor Sucks" document is from 2012. It talks about the GCHQ running Tor nodes. What could have happened in the years since? https://metrics.torproje…
My suspicion is essentially the opposite: Tor is secure, but the two high profile arrests (Freedom Hosting and Silk Road) where given priority to make the general public a.) feel that the entire function of Tor is illegal and often repulsive activity b.) that Tor is not safe. The latter part of that theory, that law enforcement agencies intentionally stepped up the resources for both the FH and SR cases in order to i…
Re: Things You Should Know About Tor
#105>They have been able to compromise certain Tor users in specific situations. Historically this has been done by finding an exploit for the Tor Browser Bundle or by exploiting a user that has misconfigured Tor. I'm not touching TOR until I figure out how they managed to capture Ross Ulbricht. I highly doubt that he had his TOR misconfigured.
He exposed his email address containing his name as a contact email for silkroad business, so he pretty much gave himself in. With that kind of "attention to details", I wouldn't be surprised if he even had misconfigured TOR.
Re: Things You Should Know About Tor
#106Earlier quoted context omitted.
This is not factually correct. If you use tor correctly (https everywhere, don't leak cookies) you can be pretty safe. I'm fairly sure I know what I'm talking about, but feel free to point to some articles and I will try to explain one by one what Tor can and what it can't do. Here, some links on Tor operational security, do read them carefully: - https://www.torproject.org/download/download#warning - http://cryptome…
http://dl.acm.org/citation.cfm?id=2516651 Full article is at : http://web.elastic.org/~fche/mirrors/www.jya.com/2013/09/tor... And i've read other work that talks about using machine leanring to create realistic attacks, and another by a guy that even deanonimized some anonymous remailers. And let's not forget most implemented protocols like tls have bugs. A somewhat pessimistic view would probably say that the only…
Re: Things You Should Know About Tor
#107Earlier quoted context omitted.
My suspicion is essentially the opposite: Tor is secure, but the two high profile arrests (Freedom Hosting and Silk Road) where given priority to make the general public a.) feel that the entire function of Tor is illegal and often repulsive activity b.) that Tor is not safe. The latter part of that theory, that law enforcement agencies intentionally stepped up the resources for both the FH and SR cases in order to i…
You don't address my specific point; namely that it is not only possible but relatively inexpensive for any nation-state to compromise users' anonymity on Tor en masse not by cracking its cryptography but by running >50% of the nodes themselves.
Re: Things You Should Know About Tor
#108It is possible to de-anonymise any Tor user if they have JS enabled and you have passive listeners at their ISP. See http://webcache.googleusercontent.com/search?q=cache:kVKMeKx... The described attack on Tor may not be well known, but at the very least I told the FBI how to do it myself, so they certainly know about it.
Re: Things You Should Know About Tor
#109Earlier quoted context omitted.
Lets address your concern by talking about security and probability for each of those issues. Credit card thieves in Comcast vs in TOR. Given the number of employees who has remote access to customers routers (ie support), sysadmins that has remote server access, and personale who has physical access to switching equipment, whats the risk that one of those people has a criminal record? This will always be non-zero, a…
You can test Comcast in the same way that you can test a Tor exit node - the technique is exactly the same. The threat of a rogue network admin is similar to that of a rogue waitress stealing credit card info - significant criminal liability if caught. To top that, people in a position to carry out such an attack are generally easily identifiable by their employers if there is a criminal investigation. The same can't…
With a tor exit-node, the operator can't identify who is sending them the traffic. They can't distinguish a investigating police from a victim.
You can disagree and think that rouge Comcast employees are easier identified than Tor operator. This is a trust question, and everyone is free to pick who they trust and who they don't. The argument given in favor of Comcast just don't sway me, and it would likely require a research paper with test data in order to actually prove what has higher risk associated with it.
The NSA do not target people specifically. That was proven by the revelations from Snowden, and has been quite obvious for quite a long time. NSA doesn't care who their victim is when they are collecting the information. It is cheaper and more effective to target everyone, and then data mine the result after everything is in their hands.
Re: Things You Should Know About Tor
#110I'm probably going to take some flack for this, but I don't trust Tor. When you access Tor, you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes who raised their hands and said "Trust me! You can route all of your internet traffic through me and I promise I won't monitor or inject anything..." I think most Tor users don't have an adequate understanding of the th…
While man-in-the-middle attacks may be detectible ( http://www.cs.kau.se/philwint/spoiled_onions/techreport.pdf ) just recording all the unencrypted traffic would be worthwhile. The simple answer is most people that use an electronic device -- Tor or otherwise -- have no idea what they are doing. Because Tor is advertised as extremely safe, they think they are safe. Anyone wanting an interesting stream of data just h…