Earlier quoted context omitted.
And if you run it on your main machine it could exploit it and mount hard drive. You need another diskless computer just for this...
Are there any small, cheap laptops with optical drives? Another alternative is having enough 1gb usb sticks to be able to throw them away on a regular basis. Sort of like burner phones. (Personally I'm not sure I want to go so far as to buy a separate computer for private use now, but I might as well know how to do it.)
Attacking Tor: How the NSA targets users' online anonymity
171–180 of 184 posts
Re: Attacking Tor: How the NSA targets users' online anonymity
#172Earlier quoted context omitted.
And if you run it on your main machine it could exploit it and mount hard drive. You need another diskless computer just for this...
Not just diskless, but somehow incapable of flashing the BIOS, rewriting the CPU microcode, and loading new firmware into the NICs and other peripherals.
Used to have some machines with zip flash sockets you could remove while the machine was running (useful for flashing linuxbios aka coreboot in the old days).
Not really your modern laptop though.
Re: Attacking Tor: How the NSA targets users' online anonymity
#173Earlier quoted context omitted.
Iran spends ~10bn/yr for the "on the books" part of their military. How much vulnerability research do you think $500MM buys? Answer: a lot.
Yes, but I'm not sure that justifies the end conclusion: 1. Do we actually know Iran spends $500MM on vulnerability research? What about Belarus? 2. Suppose they do. So they have zero-day exploits, sure. IIUC, you need MITM capabilities to execute an attack on tor like the NSA did. This sounds costly, and I'm not sure it can be outsourced like buying zero-days. It also requires, ummm, "being on good terms" with telco…
Re: Attacking Tor: How the NSA targets users' online anonymity
#174Earlier quoted context omitted.
One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking. Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the underst…
> That used to be a tin-foil hat idea just a few months ago, and we know better now. If NSA comes carrying gifts, it warrant being very careful in accepting them from a party with such hostile priorities. Well, not really. The "tinfoil" idea is that NSA is breaking into crypto so that they can blackmail politicians, black-bag innocent citizens, etc. But it was never widely assumed that NSA wasn't trying to break ever…
The NSA also has been found to give good advice sometimes, so just doing the opposite of what they say doesn't work either.
Re: Attacking Tor: How the NSA targets users' online anonymity
#175Earlier quoted context omitted.
> It was generally thought that government would not keep security vulnerabilities hidden Was that what people thought? Were there vulnerability reports in open-source software that were coming from the NSA or thought to be coming from the NSA? Surely everyone knew that the NSA was capable of finding exploits in software, and I would think that it would be hard to keep secret whether or not they're being reported. >…
There's a video from the RSA conference in 2011 with Dickie George, who was the director for Information Assurance at NSA when DES was being reviewed. He claims that the agreement between NIST and NSA was that: 1, NSA would only change things if they could find a specific problem with the cipher, and 2, NSA promised that DES would have security equal to its key size. The implication is then that they decided that 56…
Re: Attacking Tor: How the NSA targets users' online anonymity
#176One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully…
One iffy part I would like to add is government itself. It was generally thought that government would not keep security vulnerabilities hidden, prioritizing to protect citizens rather than having a minor advantage in hacking. Together with the earlier leaks regarding sabotaged security standard, US government is the most damaging entity to computer security today. Anything they do need to be viewed under the underst…
The response was 100% boilerplate. "We have a system for evaluating it," was the basic answer, in more words than that. I didn't really expect anything more, but it was worth a shot.
I've never believed that their "system" was in any way primarily for the public interest. I can't point to any specific evidence, it just never felt like the type of thing they would do. Good exploits just seemed far too useful to be worth giving up.
Re: Attacking Tor: How the NSA targets users' online anonymity
#177Earlier quoted context omitted.
Yes, but I'm not sure that justifies the end conclusion: 1. Do we actually know Iran spends $500MM on vulnerability research? What about Belarus? 2. Suppose they do. So they have zero-day exploits, sure. IIUC, you need MITM capabilities to execute an attack on tor like the NSA did. This sounds costly, and I'm not sure it can be outsourced like buying zero-days. It also requires, ummm, "being on good terms" with telco…
Would you bet your life on the answer?
If your point is that Iranian and Belarusian dissidents need to be aware of the risk, I agree.
Re: Attacking Tor: How the NSA targets users' online anonymity
#178Earlier quoted context omitted.
TAILS will detect it is running inside a VM and warn you not to do it. I know quite a few folks who are sitting on escapes for popular VM products. They are not at all uncommon. I would be absolutely shocked if the NSA's little toolkit didn't detect virtualization, pop out, and backdoor the host OS.
And if you run it on your main machine it could exploit it and mount hard drive. You need another diskless computer just for this...
Re: Attacking Tor: How the NSA targets users' online anonymity
#179One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully…
The disheartening things is, though, we don't really have novel technologies (quantum crypto?) to guarantee security anymore and the existing ones will soon be exploitable on a mass scale. This is bad for internet commerce, and for internet itself as a medium. In the eyes of the layman, the internet is untrustworthy. I won't be surprised if in the future we will see closed, privately owned physical networks that guar…
Re: Attacking Tor: How the NSA targets users' online anonymity
#180Earlier quoted context omitted.
"Having something specific to hide leads to questions of why? To what end? Should we be worried?" Why do you close the doors when you go to the bathroom? What are you hiding? Should we be worried?
Because it's polite and it limits the diffusion of bad smells. If you really want to see my dick all you have to do is go on chatroulette. No need to follow me to the toilet. Unless you're interested in more than just looking.