Live data from Hacker News

Zed Shaw: Why I Don't Use Tor

sheddingbikes.com

141–150 of 170 posts

Re: Zed Shaw: Why I Don't Use Tor

#141
post #138
post #124

Earlier quoted context omitted.

The difference is that with cryptography the actors are nation states v. nation states. With steganography the actors are activists v. nation states. Also, what makes you think activists have the technical expertise available to know what the "most secure techniques available" are and what methods have been broken?

"The difference is that with cryptography the actors are nation states v. nation states. With steganography the actors are activists v. nation states." I don't know where you got the idea that nation states are the only ones who use cryptography. Plenty of activists, along with other non-state actors do so all the time. Plenty of cryptography is also designed by individuals not in the service of any nation state (as…

I don't know where you got the idea that nation states are the only ones who use cryptography. Plenty of activists, along with other non-state actors do so all the time.

We're not talking about users, we're talking about attackers and developers. Why would users have anything to do with our discussion?

Plenty of cryptography is also designed by individuals not in the service of any nation state (as far as we know, anyway). In fact, some argue that such encryption is more trustworthy than encryption developed by nation states themselves.

Developed by academics, but tested by both academics and the government. The testing is the thing that's actually important.

I can't speak for any and all activists. It's really up to them to acquire such expertise or get advice from people who have such expertise.

The point is that the technical expertise is not available. It's not up to them. It's not available. What you suggest they do is not possible.

That said, the problem here is no different from figuring out which encryption to use. So your criticism applies equally to encryption as it does to steganography.

Nope. Get back to me when we get government backed standards and recommendations for anonymity (hint: we have them for crypto).

Re: Zed Shaw: Why I Don't Use Tor

#142
post #44

It's shit like this Zed... Two basic claims: Tor is tainted because (1) the concepts the software is based on were developed with partial funding from the military and (2) Zed thinks one of the committers is untrustworthy. Guess what? That describes a huge amount of software, including Mac OS X and Firefox . God damn Zed, this Hitler sandwich shit is pretty weak. Zed also has a problem with Tor because he thinks ther…

Thomas is very right, but I was more interested in my reasons why I don't use Tor based on all the crap I see going on around it.

Do you avoid software like FreeBSD, Linux, Mac OS X, and all other software that fits the criteria of your post? Point is, you have shitty reasons and probably aren't consistant in your application of them. Government funding and a committer you don't like preclude the usage of a huge amount of software.

    curl -s http://www.kernel.org/pub/linux/kernel/CREDITS | grep gov
    E: becker@cesdis.gsfc.nasa.gov
    E: snyder@fnald0.fnal.gov


    curl -s http://gcc.gnu.org/viewcvs/trunk/MAINTAINERS?view=co | grep gov
    Asher Langton					langton2@llnl.gov
My general frustation with your blog post is that your arguments apply to many popular pieces of software. It feels disingenuous and it feels like it's provocative solely for the purpose of being provocative.

Re: Zed Shaw: Why I Don't Use Tor

#143
post #116

Earlier quoted context omitted.

Sure, steganography and steganalysis are in an arms race, just like encryption and cryptanalysis. But if the existence of such an arms race doesn't stop someone from using encryption it shouldn't stop them from using steganography. Of course, you need to be prudent about it. Use the most secure techniques available, and don't use methods you know have been broken. Finally, know that you are taking a risk, that nothin…

We're talking about individuals versus nation states. You're handwaving.

And your two-sentence reply that didn't specifically address a single point in my post is supposed to be some deep, thorough analysis?

Pot, meet kettle.

Despite this, I'll do you the kindness of actually addressing the point you made by giving you a big, "so what?"

Activists and dissidents often go up against nation states. That's the nature of the business. And they knowingly take risks to do so.

The question is, are they simply going to use bare encryption, thereby virtually guaranteeing to draw attention to themselves in a state like China? Or are they going to wrap their encrypted message in a layer of steganography, thus giving themselves at least a chance to avoid detection in the first place?

Re: Zed Shaw: Why I Don't Use Tor

#144
post #137
post #118

Earlier quoted context omitted.

No, all they require is being just as trustworthy as the other browsers and operating systems, even if that level is zero. Tor is an extra inconvenience and calls extra attention to you and therefore requires a credible claim of providing extra security to make up for the downside.

Nope. If the trustworthiness of all browsers was zero, people would do their banking in person. You're trying to get away with arguing only the relative and not absolute trust of browsers is the only thing that matters. Not gonna happen.

Security is relative and depends on your particular goals. I may have zero confidence that the government has not subverted Firefox, but that would not stop me from using it. If there are government back doors in Firefox, they aren't being exploited on a large scale for robbery or identity theft, and that makes it good enough for online banking. It wouldn't make Firefox good enough for evading government surveillance, but depending on your purposes, using a web browser you don't trust might be better than not using a web browser at all.

If someone of sufficient expertise decides to hack you and take your banking info, they will, just like if someone decides to rob you on the street, they will. We assume there are vulnerabilities in any piece of software as big as Firefox. Your security depends on not being a particularly tempting individual target for highly skilled attackers and staying up-to-date enough to avoid mass automated attacks, and those factors depend on relative risks that can't even be objectively measured.

Edit/PS: I am also confident that the government would not insert back doors that are likely to be found by criminals, because those vulnerabilities would be exploited by foreign governments and would hurt U.S. commercial interests, which I imagine is the only kind of mistake that would result in Congress taking drastic punitive action (slashing budgets, reducing autonomy, increasing oversight) towards an intelligence agency.

Re: Zed Shaw: Why I Don't Use Tor

#145
Am I wrong in taking the cheese sandwich from Hitler if it's a very good cheese sandwich? After all, I'm writing this on a Mac, a platform owned by a company that has interesting views on what people should and shouldn't be able to do with their own kit. I buy Windows from Microsoft (which according to many Usenet postings is clearly the closest thing to accepting a cheese sandwich from Hitler, especially in the Linux groups).

I think Zed's fallen wide of the mark here. He's failed to address the technical failings with Tor, instead opting to launch his own ad hominem attack on Jacob Applebaum (who's done more than just work on Tor and Wikileaks) and the history of the project as a US Navy tool.

If he has such a problem with Tor then it's worth auditing the code and seeing for yourself. It's not perfect, but Tor has it's uses. If you really need the kind of anonymity to protect something life threatening then don't use Tor (due to it's failings in the cheese sandwich quality department, not because of it's history or contributors).

Re: Zed Shaw: Why I Don't Use Tor

#146
post #143

Earlier quoted context omitted.

We're talking about individuals versus nation states. You're handwaving.

And your two-sentence reply that didn't specifically address a single point in my post is supposed to be some deep, thorough analysis? Pot, meet kettle. Despite this, I'll do you the kindness of actually addressing the point you made by giving you a big, "so what?" Activists and dissidents often go up against nation states. That's the nature of the business. And they knowingly take risks to do so. The question is, ar…

How about a third option: they use a method of communication that wont get them killed. You're presenting a false dichotomy.

Re: Zed Shaw: Why I Don't Use Tor

#147
post #141
post #138

Earlier quoted context omitted.

"The difference is that with cryptography the actors are nation states v. nation states. With steganography the actors are activists v. nation states." I don't know where you got the idea that nation states are the only ones who use cryptography. Plenty of activists, along with other non-state actors do so all the time. Plenty of cryptography is also designed by individuals not in the service of any nation state (as…

I don't know where you got the idea that nation states are the only ones who use cryptography. Plenty of activists, along with other non-state actors do so all the time. We're not talking about users, we're talking about attackers and developers. Why would users have anything to do with our discussion? Plenty of cryptography is also designed by individuals not in the service of any nation state (as far as we know, an…

"We're not talking about users, we're talking about attackers and developers. Why would users have anything to do with our discussion?"

Actually, in the message you responded to, I was specifically talking about users. I've been talking about users of crypto/stego all along!

They're the ones who take virtually all of the risk. The people who write the crypto/stego often aren't even in the same country, and they do their development in countries where crypto/stego are perfectly legal.

So I don't know why you started talking about developers all of a sudden.

However, I thought you might have switched subjects, so I specifically addressed crypto development in my second paragraph.

"Developed by academics, but tested by both academics and the government. The testing is the thing that's actually important."

That testing is only worthwhile if your threat model does not include the government itself, which has a vested interest in breaking all encryption, whether or not it has been "certified" by them.

"The point is that the technical expertise is not available. It's not up to them. It's not available. What you suggest they do is not possible."

How is it not available? There are plenty of people who design and analyze stego. There's your expertise.

"Get back to me when we get government backed standards and recommendations for anonymity (hint: we have them for crypto)."

Get back to me when that actually matters.

Re: Zed Shaw: Why I Don't Use Tor

#148
post #132

Earlier quoted context omitted.

This is silly. You can programatically detect e.g. anomalous keyframes from traffic today. Anything you do to try and embed messages in any rich media format (audio, lossy images, video, &c) can be reversed and turned into a filter. The filters won't even need to be accurate; they'll baseline, wait for you to trip a threshold, and then send people to your door to collect your machine. I'm particularly amused by the c…

Two videos, X and Y, are uploaded to youtube. X is a video of a completely featureless white screen. Y is a video of a jungle canopy in the midst of a storm. At some point in both videos, one pixel changes color slightly. Which video do you think it will be easier to spot the change in? Of course, the amount of information that can be transmitted in the color change of one pixel is ridiculously small, so in a real li…

Steganalysis doesn't work by noticing a pixel gone awry in a video of a storm. Your notion of how this works seems drawn from movie plots, like the guys who sneak past motion detectors by moving real, real slow. Also, "the contributing editor of the Infoworld Test Labs and author of the Morgan Kaufman book _Disappearing Cryptography_, as summarized by Wikipedia" loses to academic crypto researchers. Sorry.

Re: Zed Shaw: Why I Don't Use Tor

#149
post #29

(I rather suspect that Mr Shaw is trolling, but anyway.) It's certainly true that humans have all manner of interesting behaviors owing to the fact that we're smart apes with huge numbers of survival heuristics. I would pause before taking a sandwich from Hitler, because I'm human, but it's not pertinent to the question of whether the sandwich is any good. (Except in as far as you think it more or less likely that th…

Then again, you might be a hacker on the NSA payroll and are currently reading my raunchy emails to the hot chick in the marketing department.

Re: Zed Shaw: Why I Don't Use Tor

#150
post #77
post #58

Earlier quoted context omitted.

This assumes that political dissidents, whistleblowers and spies are using tor in any significant numbers. It seems quite unlikely to me that this is true. I think you'd find that the vast majority of tor traffic is comprised of people trying to mask their location for criminal reasons, people looking to bypass local firewall restrictions and people using it as a free VPN.

Yes, but even criminals talk. If there were a string of busts and the item connecting them all was the fact that Tor was used by the criminals then it would be an easy conclusion to say that Tor has been compromised. Most of the CP cases are done with a lot social engineering. Instead of having some sort of super router that can sniff through all the packets its just a bunch of LEOs in an office trying to gain the co…

This was my thinking as well. The overwhelming majority of cases you hear about are broken using old-fashioned police work. Even petitioning ISPs for records seems to be a fairly minor part of the equation.

A pedophile running a hidden TrueCrypt volume and using Tor to trade chid pornography on onion sites is likely to get caught only if they pull a Bradley Manning, that is, saying the wrong thing to the wrong person. Unfortunately, most pedophiles these days that trade in child porn are likely more technologically advanced than the people responsible for tracking them.

Post reply on HN