Live data from Hacker News

Tor and HTTPS

eff.org

121–130 of 135 posts

Re: Tor and HTTPS

#121
post #119
post #118

Earlier quoted context omitted.

> SSL certs require cooperation of a trusted registrar even for the biggest companies -- Google's is signed by Equifax, for example. Given what we've seen in the last few days, requesting keys from the root CAs is a no-brainer. Getting a root's key does not enable them to decrypt the traffic. Getting the server's SSL private key USUALLY means you can retroactively decrypt, but it is possible (though uncommon) for ser…

I can't update my original post now, but I stand corrected. I "remembered" uploading the private key with the CSR last time I went through the process, but must have misremembered. Well, that's some good news I guess. The NSA could still easily request the private key from the company, of course.

You don't share your private key with the CA.

A certificate is an attestation (signature) by a CA's private key that a given PUBLIC key is yours, that anyone with the CA's public key can verify.

The CSR does not contain your private key.

NONE OF THIS MATTERS. This is not about bulk-decrypting SSL, though I'm sure NSA does that when and where they can, too. This is about coordinated, automated, integrated methods of transmitting the plaintext.

Why should they bother getting a key and scraping gmail's payloads when they could just have Google give them an API? Furthermore, this method would continue working perfectly even ifwhen services switched to ephemeral key modes that provide PFS.

Re: Tor and HTTPS

#122
post #117

Earlier quoted context omitted.

Valid point that anonymity is a binary property, but, if you wanted to talk about levels you could perhaps measure the level of difficulty of finding your identity, or the likelihood of accurately doing so.

The tradeoff is the same as keysize in crypto. It is time. If you choose to communicate a second time from the same endpoint with the same equipment you may achieve only pseudonymity. Since Tor doesn't limit the encapsulated protocols, it depends on the implementation and awareness of the user and you can't put a number or percentage on that. Imho the Tor-role has changed, it provides access against censorship, DPI,…

Out of curiosity, why does the equipment matter?

Re: Tor and HTTPS

#123
post #28

Assuming the NSA is tapping ISP cables, and siphoning all unencrypted data of the web, and that they need to ask the big companies in the slides for the encrypted data, would EFF's "HTTPS Everywhere" help with all the websites that are not encrypted, like say Reddit?

As another commenter mentiioned, that tool just automatically switches to HTTPS sites if available (on the same domain name) FYI: there's https://pay.reddit.com/ but it doesn't work with HTTP Everywhere because its on a different domain.

And sometimes users post links to reddit itself, and it won't be https.

Re: Tor and HTTPS

#124
post #122
post #117

Earlier quoted context omitted.

The tradeoff is the same as keysize in crypto. It is time. If you choose to communicate a second time from the same endpoint with the same equipment you may achieve only pseudonymity. Since Tor doesn't limit the encapsulated protocols, it depends on the implementation and awareness of the user and you can't put a number or percentage on that. Imho the Tor-role has changed, it provides access against censorship, DPI,…

Out of curiosity, why does the equipment matter?

There may be information leaking (as in fingerprinting) from your device (that you are not aware of) that would allow very easy correlation, like in a mac address or existing session cookie, similar address in a public open network or whatever you can imagine to compromise your anonymity, that gives an adversary any advance to successfully correlate your current session with one of your previous sessions.

At this event your anonymity becomes a pseudonym.

The next step would be to try to reproduce or predict behavior and setup a trigger for that information.

If the loss (compromise) of anonymity or pseudonymity may lead to imprisonment, torture, assassination or death this maybe an issue to consider.

If you try to obfuscate your access to porn, it is a completly different story.

Re: Tor and HTTPS

#125
post #94

Earlier quoted context omitted.

There is no level on anonymity, either you are, or you are not. Addendum for achievement: Connect to Tor from a public accessible network/wifi that is free from surveillance using a pristine installation and never use that network-device again. Addendum 2: If you use the network device twice, you may achieve only pseudonymity.

Valid point that anonymity is a binary property, but, if you wanted to talk about levels you could perhaps measure the level of difficulty of finding your identity, or the likelihood of accurately doing so.

> you could perhaps measure the level of difficulty of finding your identity

Here you go:

http://diyhpl.us/~bryan/papers2/security/Towards%20an%20info...

http://diyhpl.us/~bryan/papers2/security/Towards%20measuring...

http://en.wikipedia.org/wiki/Degree_of_anonymity

Also this is fun: http://www.gwern.net/Death%20Note%20Anonymity

Re: Tor and HTTPS

#126
post #94

Earlier quoted context omitted.

There is no level on anonymity, either you are, or you are not. Addendum for achievement: Connect to Tor from a public accessible network/wifi that is free from surveillance using a pristine installation and never use that network-device again. Addendum 2: If you use the network device twice, you may achieve only pseudonymity.

Valid point that anonymity is a binary property, but, if you wanted to talk about levels you could perhaps measure the level of difficulty of finding your identity, or the likelihood of accurately doing so.

[deleted]

Re: Tor and HTTPS

#127
post #69
post #49

The important part of the diagram for Tor is the first NSA character, as you can see it still shows "Location" before you are routed through the Tor relay. With the location information it is possible to correlate the exit information via pattern matching, though it would take considerable analysis, this can be done by logging volume and timing information on the two sides. I am sure there are even better techniques…

> With the location information it is possible to correlate the exit information via pattern matching, though it would take considerable analysis, this can be done by logging volume and timing information on the two sides. I am sure there are even better techniques to analyze exit/entry correlations, especially if you're not using a secure browser. I've thought the same. But I've also thought that if this is indeed p…

I would think that if they did have the means to attack Tor they would not show their hand but taking down something as insignificant as Silk Road.

Re: Tor and HTTPS

#128

What would be the highest level of anonymity one could achieve on the modern internet? How could you accomplish it?

Another way to accomplish anonymity is to not use the so called internets, but I guess that is either very comfy or intresting.

Re: Tor and HTTPS

#129
post #69
post #49

The important part of the diagram for Tor is the first NSA character, as you can see it still shows "Location" before you are routed through the Tor relay. With the location information it is possible to correlate the exit information via pattern matching, though it would take considerable analysis, this can be done by logging volume and timing information on the two sides. I am sure there are even better techniques…

> With the location information it is possible to correlate the exit information via pattern matching, though it would take considerable analysis, this can be done by logging volume and timing information on the two sides. I am sure there are even better techniques to analyze exit/entry correlations, especially if you're not using a secure browser. I've thought the same. But I've also thought that if this is indeed p…

AFAIK Silk road just deals in a bit of drugs (relatively low volume too, all things considered).

For intelligence agencies, having evidence (even if inadmissible) of smaller crimes, is just leverage -- and leverage against people that might be able to render useful services (eg: provide deniable assets for framing someone with drugs).

Now, if Silk Road did most of it's trade in weapons grade plutonium, things might be different.

Remember, the whole reason the NSA-thing is a news story, is that it is illegal wire tapping. The feds can't use this for setting up a case.

Re: Tor and HTTPS

#130
post #51

Earlier quoted context omitted.

Bitcoin transactions are chained, that may compromise you. But you could use an anon currency-exchange or currency-bridge like paysafecard.com to obtain some value and obtain bitcoin with that value and never use that bitcoin key again to avoid that.

Is there no system to swap ownership of coins? If not there should be. You send X amount of bitcoins to a middle man who then gives you X amount back. Technically they will be different coins and they'll go to a different account #, so you can't trace anything.

I've heard that SatoshiDice is used for this. It's technically a gambling site but you can set the odds so you have a 98% chance of winning.
Post reply on HN