Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

181–184 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#181
post #159

Earlier quoted context omitted.

> When they sabotage standards, or keep vulnerabilities secret so they and criminals can break into peoples computers, then NSA is not prioritizing protecting civilians. Even the standards that they have been shown to sabotage (Lotus Notes, Clipper, Dual_EC_DRBG), they have sabotaged it in a way that should have reduced the security of the system against NSA , but not in general. I'll note that I disagree with this c…

> something rotten with them. Like spying on us?

They're doing it to spy on the rest of the world, which is something that they've done for their entire existence. It's one of the two major reasons they exist at all.

It happens that now the rest of the world is using the same crypto we're using, but that's not NSA's fault. Nor is it a major degradation over a status quo; the government has usually been able to "spy on us", it's only been a short time comparatively speaking that it was even possible for the average citizen to completely encipher their communications. Telegrams, for instance, were copied and read as a matter of course if they crossed international boundaries.

Re: Attacking Tor: How the NSA targets users' online anonymity

#182

Earlier quoted context omitted.

The NSA shouldn't just be an attacker it should also provide defence. If one of their many contractors can leak details to the press for idealogical ends it's pretty safe to assume that much worse secrets have already been leaked to other nation states (China, Russia etc....) for financial gain. I think it's entirely reasonable to assume that a lot of exploits the NSA has discovered and not revealed (because it think…

If one of their many contractors can leak details to the press for idealogical ends it's pretty safe to assume that much worse secrets have already been leaked to other nation states (China, Russia etc....) for financial gain. Especially as the agency in question appears to have no compartments or levels of access. I've been wondering how a comparatively junior contract worker could access so much information...

They're very compartmented, as it turns out.

But Snowden was a sysadmin and successfully managed to digitally impersonate persons actually in the right compartments, among other things, in order to get access to the data he wanted.

I suppose it's better to say that NSA is too reliant on contracted systems administrators to handle what should be inherently governmental functions, and that they don't properly compartment sysadmin functions. But then again, is it even possible to completely protect a computer network against an insider sysadmin threat?

Re: Attacking Tor: How the NSA targets users' online anonymity

#183
In the slide titled "Exploitation: Shaping" the status says "Can stain user agents working on shaping."

How do they achieve to make tor use NSA/GCHQ nodes? If they achieved to do this 5 years ago (the PDF is from 2007) would it then be reasonable to assume that since then they have managed to modify the TOR source code in a way that nobody remarked to do exactly this?

Re: Attacking Tor: How the NSA targets users' online anonymity

#184
post #161

Earlier quoted context omitted.

Because it's polite and it limits the diffusion of bad smells. If you really want to see my dick all you have to do is go on chatroulette. No need to follow me to the toilet. Unless you're interested in more than just looking.

Point is not that you have an altruistic reason for wanting privacy for certain parts of your life (which I'm sure you do). The point is that once the very act of wanting privacy starts becoming suspicious, we've moved away from a free society towards the totalitarian end of the spectrum.

And some of us are quite happy on that side of the spectrum.
Post reply on HN