Live data from Hacker News

The talk about de-anonymizing Tor at the BlackHat conference has been removed

tux.so

21–30 of 52 posts

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#21

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

On the opposite, everyone should use it. I love using it for queries I feel embarassed about, like googling for illness symptoms or watching wildlife documentaries.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#22
post #20

A Black Hat spokeswoman told Reuters that the talk had been canceled at the request of lawyers for Carnegie-Mellon University, where the speakers work as researchers. A CMU spokesman had no immediate comment. Source: http://www.reuters.com/article/2014/07/21/cybercrime-confere...

I have to imagine that this is for some sort of internal bureaucratic reason. I don't see who is in a position to even want to stop this talk - almost certainly not the Tor project itself. The mundane (and thus most likely) answer is that the CMU lawyers wanted to pull it either because they want to sort out some sort of intellectual property first, or they're worried about some sort of liability.

I don't see who is in a position to even want to stop this talk

A government agency that wants to stay a step ahead of the competition or of its targets?

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#23
post #13

Earlier quoted context omitted.

I think the opposite is the right thing. We should try to get everyone on that list.

This is not realistic though and as I said it would actually help the security establishment and military if more people used Tor.

No it wouldn't. How is it possibly helpful to the security establishment if I use tor for what is essentially an innocuous purpose?

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#24
post #21

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

On the opposite, everyone should use it. I love using it for queries I feel embarassed about, like googling for illness symptoms or watching wildlife documentaries.

but then how can amazon.com bombard you with ads for Anal Wart Cream for the next six weeks?

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#25

Earlier quoted context omitted.

I disagree. The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. No political action is going to stop all such entities in the world from monitoring web traffic, let alone prevent non-government entities from doing so. I am not saying Tor is the answer, but whatever the answer is, it will have to be technical.

Well Tor is obviously not the answer, it introduces too much latency and at the moment very few nodes mostly located in the US bear the majority of all traffic. No technical solution will prevent governments from monitoring all important network hubs. It seems impossible to prevent them to gather at least metainformation there. If enough routers in an onion routing scheme are compromised the same is true. If there wo…

Yes, Tor is not the answer. I can think of a hypothetical technical solution to the problem, however. If everyone used an onion-routing protocol where everyone also acts as an exit node, you could create a situation where even meta-information would be unobtainable.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#26
Roger's response here is probably relevant:

https://lists.torproject.org/pipermail/tor-talk/2014-July/03...

  Hi folks,

  Journalists are asking us about the Black Hat talk on attacking Tor
  that got cancelled. We're still working with CERT to do a coordinated
  disclosure of the details (hopefully this week), but I figured I should
  share a few details with you earlier than that.

  1) We did not ask Black Hat or CERT to cancel the talk. We did (and still
  do) have questions for the presenter and for CERT about some aspects
  of the research, but we had no idea the talk would be pulled before the
  announcement was made.

  2) In response to our questions, we were informally shown some
  materials. We never received slides or any description of what would
  be presented in the talk itself beyond what was available on the Black
  Hat Webpage.

  3) We encourage research on the Tor network along with responsible
  disclosure of all new and interesting attacks. Researchers who have told
  us about bugs in the past have found us pretty helpful in fixing issues,
  and generally positive to work with.
(imho 2) and 3) is a polite way of saying that this particular talk did not feature much in terms of responsible disclosure. But these are not related to 1).)

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#27
post #21

Earlier quoted context omitted.

On the opposite, everyone should use it. I love using it for queries I feel embarassed about, like googling for illness symptoms or watching wildlife documentaries.

but then how can amazon.com bombard you with ads for Anal Wart Cream for the next six weeks?

As soon as I learned that companies are people, I suspected Sprint might have something like that.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#28
post #15

Earlier quoted context omitted.

I disagree. The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. No political action is going to stop all such entities in the world from monitoring web traffic, let alone prevent non-government entities from doing so. I am not saying Tor is the answer, but whatever the answer is, it will have to be technical.

> The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. The vast majority of people do not want that Internet. See, for example, the popularity of Facebook. (About 1.2bn users per month). You need technical measures, and law, and effective oversight.

Privacy or "oversight," pick one. With strong croup and deniability privacy is absolute, unless you want torture to be a law enforcement tactic. If you can't handle that, you might as well communicate in the clear.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#29
post #22
post #20

Earlier quoted context omitted.

I have to imagine that this is for some sort of internal bureaucratic reason. I don't see who is in a position to even want to stop this talk - almost certainly not the Tor project itself. The mundane (and thus most likely) answer is that the CMU lawyers wanted to pull it either because they want to sort out some sort of intellectual property first, or they're worried about some sort of liability.

I don't see who is in a position to even want to stop this talk A government agency that wants to stay a step ahead of the competition or of its targets?

Or a University who doesn't want to get sued / get bad publicity for screwing with a tool used by government agencies...

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#30
post #26

Roger's response here is probably relevant: https://lists.torproject.org/pipermail/tor-talk/2014-July/03... Hi folks, Journalists are asking us about the Black Hat talk on attacking Tor that got cancelled. We're still working with CERT to do a coordinated disclosure of the details (hopefully this week), but I figured I should share a few details with you earlier than that. 1) We did not ask Black Hat or CERT to cance…

Coordinated disclosure is the proper term.
Post reply on HN