Live data from Hacker News

The talk about de-anonymizing Tor at the BlackHat conference has been removed

tux.so

31–40 of 52 posts

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#31
post #3

Speakers drop out all the time. Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues.

>>> Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues. To some degree, isn't this what the Black Hat conference is all about?

[deleted]

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#32

At this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.

True, but if everyone were to use Tor all the time, everyone would be suspicious all the time, and therefore no one would be suspicious ever. I'd like to see a pay-per-install Tor browser program materialize, one that would incentivize retailers and ISP techs to install Tor browser on customer devices. Every device should be connected to Tor from the moment it is powered on. Then we could at least go back to having f…

"...suspiciuous all the time"? What nonsense. When Everyone uses Tor (or anything else), by definition that is "normal".

Or do you view envelopes with this same paranoia? https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#33
post #29
post #22

Earlier quoted context omitted.

I don't see who is in a position to even want to stop this talk A government agency that wants to stay a step ahead of the competition or of its targets?

Or a University who doesn't want to get sued / get bad publicity for screwing with a tool used by government agencies...

Legality aside, I'm surprised this wasn't pulled on ethical grounds. Does Black Hat not require "researchers" to follow responsible/coordinated disclosure?

What about the political dissidents who use Tor? They could be at risk of certain death if caught by the authoritarian regimes they live under. Without coordinated disclosure, the "researchers" might as well have been signing death warrants.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#34
post #3

Speakers drop out all the time. Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues.

>>> Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues. To some degree, isn't this what the Black Hat conference is all about?

No, to some degree BH is about compromising X in public after X has been repeatedly contacted with the necessary details AND given ample time to address the issues.

What these "researchers" were doing was just reckless. When it comes to Tor, lives are on the line. This kind of irresponsible disclosure is abhorrent, at best.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#35
post #29

Earlier quoted context omitted.

Or a University who doesn't want to get sued / get bad publicity for screwing with a tool used by government agencies...

Legality aside, I'm surprised this wasn't pulled on ethical grounds. Does Black Hat not require "researchers" to follow responsible/coordinated disclosure? What about the political dissidents who use Tor? They could be at risk of certain death if caught by the authoritarian regimes they live under. Without coordinated disclosure, the "researchers" might as well have been signing death warrants.

Black Hat is a venue for presenting research. They don't influence the procedures used by researchers at all. And the Black Hat review board is not stuffed full of people who buy into "responsible disclosure".

In fact: I'm not aware of a vulnerability research conference that does get nosy about this stuff. I even reviewed for Usenix WOOT one year, and we didn't vet research for "coordinated disclosure". Not even Usenix works the way you want BH to.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#36
post #32

Earlier quoted context omitted.

True, but if everyone were to use Tor all the time, everyone would be suspicious all the time, and therefore no one would be suspicious ever. I'd like to see a pay-per-install Tor browser program materialize, one that would incentivize retailers and ISP techs to install Tor browser on customer devices. Every device should be connected to Tor from the moment it is powered on. Then we could at least go back to having f…

"...suspiciuous all the time"? What nonsense. When Everyone uses Tor (or anything else), by definition that is "normal". Or do you view envelopes with this same paranoia? https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html

To the NSA, a normal Internet citizen is a terrorist. Just searching the Web for anything Tor-related gets you put on a list. You are preaching to the choir.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#37

Earlier quoted context omitted.

>>> Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues. To some degree, isn't this what the Black Hat conference is all about?

No, to some degree BH is about compromising X in public after X has been repeatedly contacted with the necessary details AND given ample time to address the issues. What these "researchers" were doing was just reckless. When it comes to Tor, lives are on the line. This kind of irresponsible disclosure is abhorrent, at best.

I don't know what BH you've been attending for the last 10 years, but it's not the one I've been going to.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#38

Earlier quoted context omitted.

Well Tor is obviously not the answer, it introduces too much latency and at the moment very few nodes mostly located in the US bear the majority of all traffic. No technical solution will prevent governments from monitoring all important network hubs. It seems impossible to prevent them to gather at least metainformation there. If enough routers in an onion routing scheme are compromised the same is true. If there wo…

Yes, Tor is not the answer. I can think of a hypothetical technical solution to the problem, however. If everyone used an onion-routing protocol where everyone also acts as an exit node, you could create a situation where even meta-information would be unobtainable.

As it stands Tor is deliberately routing the majority of the traffic through a minority of the available exit nodes, they explain that they do that for performance reasons. Given that they are financed almost exclusively by the US government and some of the developers have very friendly relations with law enforcement to this day, it is at least plausible that there are other reasons at work. In some of the leaked NSA memos they even state that while they have not been able to fully compromise the tor network so far, at least the majority of their targets are using it. All of this is a clear indication to me, that TOR should be abandoned sooner rather than later.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#39
post #9

A Black Hat spokeswoman told Reuters that the talk had been canceled at the request of lawyers for Carnegie-Mellon University, where the speakers work as researchers. A CMU spokesman had no immediate comment. Source: http://www.reuters.com/article/2014/07/21/cybercrime-confere...

Thank you for the information packetlss! http://www.qatar.cmu.edu/iliano/svc/meetings/PX/2004-09-21/s... http://www.cmu.edu/silicon-valley/research/tech-showcase/pdf...

Interesting, they did a talk at Education City in Qatar and I had no idea about it? Very disappointed, and surprised they had talks with these kinds of experts on this talk (censorship avoidance is not looked kindly upon there).

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#40
post #28
post #15

Earlier quoted context omitted.

> The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. The vast majority of people do not want that Internet. See, for example, the popularity of Facebook. (About 1.2bn users per month). You need technical measures, and law, and effective oversight.

Privacy or "oversight," pick one. With strong croup and deniability privacy is absolute, unless you want torture to be a law enforcement tactic. If you can't handle that, you might as well communicate in the clear.

What?

Oversight is a legal measure applied to police and security agencies to ensure that they are obeying the law, not something you do to the general public.

Post reply on HN