>>Astoria [is] both most effective and most usable when at its highest security level, the researchers say, so "Astoria is a usable substitute for the vanilla Tor client only in scenarios where security is a high priority." I'm still working through the research paper[1] linked at the end of the article, but if Astoria is as good as described, wouldn't Tor either adopt the same node selection policies, or people shif…
It would be interesting to see if this gets adopted in something like Tails where security is the priority focus.
Hackers build a new Tor client designed to beat the NSA
21–30 of 32 posts
Re: Hackers build a new Tor client designed to beat the NSA
#22I really wish more people and companies would host things on Tor's hidden services, avoiding the entire notion of exit nodes and the cleartext network.
Re: Hackers build a new Tor client designed to beat the NSA
#23Re: Hackers build a new Tor client designed to beat the NSA
#24"designed to beat" means better, not perfect. Imperfect means eventually it gets beat. The NSA might say what the IRA told Margaret Thatcher, "Today we were unlucky, but remember we only have to be lucky once. You will have to be lucky always."
Re: Hackers build a new Tor client designed to beat the NSA
#25Maybe this isn't a new idea. But it seems that more Tor exit points would be a big help. Has anyone made a tool that's both and entry and exit point. You could control the amount of bandwidth exiting. This way the exit points would be more transient - like Bittorrent peers.
I think the lack of exit nodes has more to do with legal considerations than actual computational resources/willing volunteers. See the tor blog's Tips for Running an Exit Node with Minimal Harassment - https://blog.torproject.org/blog/tips-running-exit-node-mini... "Suggest creation of LLC for large exit nodes" I'm guessing that this might be a larger barrier to entry for most willing volunteers compared to hardware…
Re: Hackers build a new Tor client designed to beat the NSA
#26Yes, their researched showed that exactly 5.8% circuits would be vulnerable with their change, and measured it accurately to 0.1%.
The research did not say that vulnerability would be around 10% of the original amount +/- 5%
Re: Hackers build a new Tor client designed to beat the NSA
#27Isn't the classical solution to this encryption problem to always send packages in the same size at regular intervals. If each host adds a layer of encryption you can't match the packages at the end points. Is this just too expensive? (I'm not an expert so genuine question from my naive POV.)
Re: Hackers build a new Tor client designed to beat the NSA
#28Re: Hackers build a new Tor client designed to beat the NSA
#29Isn't the classical solution to this encryption problem to always send packages in the same size at regular intervals. If each host adds a layer of encryption you can't match the packages at the end points. Is this just too expensive? (I'm not an expert so genuine question from my naive POV.)
Re: Hackers build a new Tor client designed to beat the NSA
#30Isn't the classical solution to this encryption problem to always send packages in the same size at regular intervals. If each host adds a layer of encryption you can't match the packages at the end points. Is this just too expensive? (I'm not an expert so genuine question from my naive POV.)