Live data from Hacker News

The FBI Identified a Tor User

vice.com

281–290 of 367 posts

Re: The FBI Identified a Tor User

#281
post #97

Earlier quoted context omitted.

That size-inference side channel leak has been patched for years, random padding is added between hops to mitigate this. It is large files / DDoS going over the network that is still hard to obfuscate. Which is why TOR is intentionally slow, especially when requesting larger files. If it wasn't, you could watch the lump of data traverse across the pipe. source: n/a

source: padding spec, https://gitweb.torproject.org/torspec.git/tree/padding-spec....

Thank you. My brain is very damp but knew it was somewhere.

Re: The FBI Identified a Tor User

#282
post #247

Earlier quoted context omitted.

> If you're sitting in front of a computer that you're using for something the U.S. government has significant interest in prosecuting, that device should be considered compromised and adversarial - you should act accordingly. I would say that if you are doing something the US government has a significant interest in prosecuting, you might want to reevaluate your life choices and think about whether it is something y…

> I would say that if you are doing something the US government has a significant interest in prosecuting, you might want to reevaluate your life choices and think about whether it is something you ought to be doing in the first place. Sounds like the people who ran the Underground Railroad would have had significant thinking to do, by your logic. They probably should have gone home and abided by the law of the land,…

I am pretty sure the people who ran the Underground Railroad thought very long and hard about what they were doing.

I think a much stronger / more contemporary argument for you would be something like facilitating access to abortion for people residing in states where it is now illegal.

But a few questions here. Is something like this an exception rather than the rule? Do you think the FBI would burn a zero day to prosecute someone for this?

Re: The FBI Identified a Tor User

#283
post #260

Earlier quoted context omitted.

That's possible, but the blog never claims otherwise. In fact it says "There are lots of ways to de-anonymize Tor users" so I think it's unfair to say Bruce is making unsubstantiated claims.

When you say "de-anonymize a Tor user", the implicit but unambiguous meaning is that you attacked Tor, not found the information from somewhere else. Just like when you say "a BMW driver crashed into a mall", you mean that they did it with their BMW, not with the Subaru that they also own.

The language in the blog post, "There are lots of ways to ..." is explicitly highlighting the ambiguity.

Re: The FBI Identified a Tor User

#284

Earlier quoted context omitted.

> If you're sitting in front of a computer that you're using for something the U.S. government has significant interest in prosecuting, that device should be considered compromised and adversarial - you should act accordingly. I would say that if you are doing something the US government has a significant interest in prosecuting, you might want to reevaluate your life choices and think about whether it is something y…

> the appropriate prior is that you are doing something supremely heinous and evil Generally speaking I can agree but more specifically cases like Julian Assange come to mind. Certainly there are at least some people who are at risk of this kind of persecution and otherwise not doing something that would so immediately be considered in such a negative light.

Reality Winner is probably a better example since she is a US citizen.

How about ransomware gangs bricking hospital IT infrastructure? Seems like that is a much more common occurrence than the types of examples you are referring to. Hence the appropriate prior - absent evidence to the contrary - is that someone is doing heinous shit.

Re: The FBI Identified a Tor User

#285

The feds run all the entrance and exit nodes. Tor was created by the feds for spies to use, then they made it public yo hide the traffic. This is the official story that everyone has evidently forgotten.

Source? or you just speculating?

There is no source. It is nonsense.

Re: The FBI Identified a Tor User

#286
post #42

Earlier quoted context omitted.

So you did illegal things illegally. Yep. I said I don't understand people who do illegal things over their own connection, i.e., stupidly. And who owned the public AP? McDonald's.

McDonald's has video cameras pointing at every inch of their property 24/7. All they need is a timestamp from the AP and they'll go find your license plate in the parking lot on the surveillance tapes.

I wasn't in the parking lot or anywhere near it for that matter.

Re: The FBI Identified a Tor User

#287
post #221

Earlier quoted context omitted.

Is there really any way to hide from a motivated state actor? Asking about it on HN is definitely not one. Relevant xkcd: 538 [1] [1] https://xkcd.com/538/

One of my favorite HN comments of all time [0] suggested that MMO's provide plentiful means of covertly communicating: >MMO's are packed with possible communication channels in addition to chat. Ever wonder if that annoying gnome in the auction hall is jumping in morse code? Could signals be sent with bids? Could a character's inventory contents be arranged to leave a message to someone else who shares the login info…

[deleted]

Re: The FBI Identified a Tor User

#288
post #185

Earlier quoted context omitted.

>I ran a tor webserver for discussing geopolitics with friends on a pi for a few months before finding it had been compromised. Not the fault of Tor. HSDir nodes could snoop on announced v1 .onion adresses. This isn't the case anymore for Onion v2 addresses. But even if an attacker has the onion address of your webserver, he needs a way to compromise it. Either through a vuln in your website or your webserver.

> This isn't the case anymore for Onion v2 addresses You're right, except you meant v3.

Oh yeah, ofc. Thank you for the correction! :)

Re: The FBI Identified a Tor User

#289

if you’re surprised that the US government can identify TOR users, then you should look up who primarily funds the TOR foundation

Oh oh I know! 38% the US government, 36% individual donors (people like me), 16% private foundations, 5% other (not US) governments, 9% corporations and 1.5% "other" https://blog.torproject.org/transparency-openness-and-our-20...

exactly. this isn’t to say that US agencies have backdoors written into TOR per se, but they have had TOR delay the patching of exploits in order to achieve the same end

Re: The FBI Identified a Tor User

#290

I think a lot of this has been covered elsewhere before: - when using tor you should disable javascript because a malicious or compromised site can use javascript to do non-tor stuff that potentially compromises your location. (can be a big pill to swallow, web without javacript is very 90s) - Run torbrowser within a secure VM or separate device using Tails to minimize your activity footprint - Use a VPN when connect…

> Use a VPN when connecting to TOR

You should not do this. It is at best useless, at worst strictly negative.

A VPN tunnels all your traffic through their own servers, so they are a single point of failure roughly equivalent to your ISP. Anyone with access to the VPN servers could spy on all of your traffic, completely bypassing Tor. If you pay for the VPN with a credit card, you can be easily identified.

Post reply on HN