Live data from Hacker News

Hackers breach FSB contractor, expose Tor deanonymization project

zdnet.com

21–30 of 123 posts

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#21

Earlier quoted context omitted.

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness. A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes or who can execute unmasking attacks by traffic shaping or monitoring if they control enough relays. For the most part any country which can perform intelligen…

Unless they communicate via a hidden service, in which case there is no exit node, so that particular problem is easy to avoid.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#22

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

1. Controlling the exit nodes doesn't mean anything unless they can use it to perform correlation attacks (because TLS, GPG, etc. Exit nodes are considered malicious regardless of who owns them.)

2. Using hidden services obviates the problem of exit nodes.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#23

Earlier quoted context omitted.

I'd be surprised if the big countries used plain Tor for their vital communication. They would be having their own secret networks or tunnel through Tor. Small countries have probably simply given up hiding their intelligence from the big ones at this point and are simply interested in ensuring their immediate rivals are kept out, which Tor can probably do.

A custom protocol can potentially be fingerprinted. I wouldn't be surprised if they used something less sophisticated. Like (encrypted) direct messages on twitter/reddit/facebook. This way the traffic blends with the rest.

There's a companion project to Tor called obs4proxy which is designed to hide the protocol's implementation.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#24

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

Tor is an anonymizer. Why would embassies use an anonymizer for communicating back home? Everyone knows they’ll be communicating with home. There’s no point in hiding that. What you want to hide is the content of that communication, which Tor doesn’t do very well. You do that with standard encryption tools.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#25
It sounds like the attack is not unusual or unknown - they're spinning up malicious nodes then trying to drive traffic to those nodes via DDOS. This is a common technique and unfortunately it's my understanding that aside from increasing the number of good nodes there's not much that can done about it. (Though monitoring for malicious behavior is much better nowadays, so bad nodes will quickly get kicked off the network)

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#26
post #8
post #2

Last time Tor was mentioned here, a user posted this link [1], claiming Tor is a military financed destabilization project. Seems unbelievable, but there appear to be lots of supporting documents. [1]: https://surveillancevalley.com/blog/fact-checking-the-tor-pr...

Wikipedia: “The core principle of Tor, "onion routing", was developed in the mid-1990s by United States Naval Research Laboratory employees, mathematician Paul Syverson, and computer scientists Michael G. Reed and David Goldschlag, with the purpose of protecting U.S. intelligence communications online.“ Recently, many or all of the US’s agents in China were captured and executed: https://foreignpolicy.com/2018/08/15/…

Good points.

RE CIA v. FBI - I wouldn't be surprised if it ended up being a loose handshake that they (CIA/NSA/FBI) will allow Tor (benefits CIA), in exchange for technical assistance in investigations (benefits FBI) -- namely the ability to own an endpoint. Don't need to own the service/protocol if I can own the host it is running on.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#27

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

1. Controlling the exit nodes doesn't mean anything unless they can use it to perform correlation attacks (because TLS, GPG, etc. Exit nodes are considered malicious regardless of who owns them.) 2. Using hidden services obviates the problem of exit nodes.

Browser exploits and fingerprinting for when you get off Tor and use the same browser have been used in the past by exit nodes.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#28

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

1. Controlling the exit nodes doesn't mean anything unless they can use it to perform correlation attacks (because TLS, GPG, etc. Exit nodes are considered malicious regardless of who owns them.) 2. Using hidden services obviates the problem of exit nodes.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great.

The upside is that no government would admit to having this capability, so your only worries are extrajudicial measures (e.g. the US does plenty of extrajudicial killings of middle easterners with its drone program) and parallel construction.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#29

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

I guess one benefit of this is only one country can control a majority of nodes.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#30

Earlier quoted context omitted.

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness. A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes or who can execute unmasking attacks by traffic shaping or monitoring if they control enough relays. For the most part any country which can perform intelligen…

>Not a single intelligence agency or diplomatic service will rely on ToR for security that’s madness... For the most part any country which can perform intelligence collection out of its embassy will have sufficient budget and and technical capacity to develop their own secure means of phoning home.

The CIA has it's own onion service: ciadotgov4sjwlzihbbgxnqg3xiyrg7so2r2o3lt5wz5ypk4sxyjstad.onion

Tor was developed by the US naval research lab, it was opened up because an anonymity network only spooks use isn't anonymous.

Smart intelligence agencies are not going to reinvent the wheel (or in this case, the onion router).

>A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes

If traffic is encrypted this does not matter. (HTTPS also provides integrity checking to show messages were not modified in transit)

Also, traffic to onion services does not exit the Tor network - there is no "exit node"

>Also for highly sensitive material a diplomatic pouch is still the most secure means of transport as it never leaves your sight and is never inspected and if you do get intercepted then destroying physical media is much easier than securing network traffic to the same level of assurance.

They may use diplomatic pouches for especially sensitive information, but the need for low latency communication is strong. What's more likely is that one time pad codes for said communications are sent via pouch, and the communication itself then goes over Tor or some other channel.

Post reply on HN