Live data from Hacker News

'Tor Stinks' presentation – read the full document

theguardian.com

31–40 of 115 posts

Re: 'Tor Stinks' presentation – read the full document

#31
post #16

Of course, if they actually have a really easy time de-anonymizing users, they might "leak" a document like this to encourage people to keep using it. Conspiracy theories are fun!

It already says they want people to keep using Tor. Read the last slide:

> Critical mass of targets use Tor. Scaring them away from Tor might be counterproductive.

In other words, they'd rather only have to break one anonymization service instead of five.

Re: 'Tor Stinks' presentation – read the full document

#32

Today's full Tor coverage by the Guardian is: (Greenwald's article) http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack... (Schneier's article) http://www.theguardian.com/world/2013/oct/04/tor-attacks-nsa... (Leaked doc #1) http://www.theguardian.com/world/interactive/2013/oct/04/tor... (Leaked doc #2) http://www.theguardian.com/world/interactive/2013/oct/04/ego... (Leaked doc #3) http://www.theguardian.com/…

A lot of these articles use abstruse acronyms. Is there perhaps a place where they're all compiled with their explanations?

For instance, what is (U)? Or (S), (SI), and (REL)?

Re: 'Tor Stinks' presentation – read the full document

#34
post #4

Page 5: "Terrorist with Tor client installed" And its a picture of a guy with a bandit mask and an AK-47. I don't know about you guys, but all my Tor activities are performed in my Halloween costume! I honestly can't believe something this tacky would end up in a presentation. Is this supposed to be propaganda?

Especially... I can't imagine this is clip art. Someone must have sat down and drawn that to order.

That must be a really wierd job, doing tacky but still sophisticated illustrations for top secret internal presentations.

Re: 'Tor Stinks' presentation – read the full document

#35
Does anyone know what the QUANTUM attack they refer to is? It doesn't seem like quantum computing on the face of it; It looks like it may be a system used to disrupt traffic on the internet, possibly man in the middle attacks.

Edit: I found a reference to something called a "Quantum Insert" in an article related to GCHQ. They state the following:

According to the slides in the GCHQ presentation, the attack was directed at several Belgacom employees and involved the planting of a highly developed attack technology referred to as a "Quantum Insert" ("QI"). It appears to be a method with which the person being targeted, without their knowledge, is redirected to websites that then plant malware on their computers that can then manipulate them

http://www.spiegel.de/international/europe/british-spy-agenc...

This might be what they are referring to, or a system that was built for targeting specific individuals.

Re: 'Tor Stinks' presentation – read the full document

#36
post #4

Page 5: "Terrorist with Tor client installed" And its a picture of a guy with a bandit mask and an AK-47. I don't know about you guys, but all my Tor activities are performed in my Halloween costume! I honestly can't believe something this tacky would end up in a presentation. Is this supposed to be propaganda?

Oh, come on, they're humans too, and thus subject to deliberately unfunny jokes in (technical or not) slide presentations like the rest of us.

From a quick look this one seems more plausible than the absurd PRISM presentation.

Re: 'Tor Stinks' presentation – read the full document

#37
post #5
post #4

Page 5: "Terrorist with Tor client installed" And its a picture of a guy with a bandit mask and an AK-47. I don't know about you guys, but all my Tor activities are performed in my Halloween costume! I honestly can't believe something this tacky would end up in a presentation. Is this supposed to be propaganda?

This presentation seems very odd. Page 4: Dumb Users (EPICFAIL)

Isn't EPICFAIL an operation nickname? (Like "GREAT EXPECTATIONS" and the others)

Re: 'Tor Stinks' presentation – read the full document

#38
post #16

Of course, if they actually have a really easy time de-anonymizing users, they might "leak" a document like this to encourage people to keep using it. Conspiracy theories are fun!

If I had a few million dollars to run compromized Tor nodes, and the ability to subpoena (and gag order) any Tor node operator in USA, UK and a couple of other major countries to give me their keys, I would be able to easily de-anonymize a large portion of the network.

Re: 'Tor Stinks' presentation – read the full document

#39
post #23
post #9

Depressingly, the document talks about plans to make Tor less reliable to dissuade people from using it: > Could we set up a lot of really slow Tor nodes ... to degrade the quality of the network? > Given CNE access to a web server make it painful for Tor users? At least the document seems to confirm that GCHQ has a really, really hard time de-anonymising Tor users.

I'm pretty sure Tor does smart peer profiling/selection to optimize for throughput. Lots of people run Tor relays on their silly little home DSLs and Tor still works.

Which is why the slide also talks about reporting as if being a high throughput node. i.e. Report back that you're handling a lot of traffic quickly while handling traffic very badly. Does Tor have protection against a node doing that?
Post reply on HN