This short piece doesn't have much detail. But if reCAPTCHA is usable to deanonymize Tor users then I would like to know about it in detail so I can do something about it.
If deanonymization would be based on size and patterns of TCP connections made to cloudfare server you should use BSD configuration flag to make them more random with net.inet.ip.random_id=1. But as long as we can't measure this... it's no proof and no defense.
Cloudflare ReCAPTCHA De-Anonymizes Tor Users
41–50 of 122 posts
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#42We do not need any more evidence, there is enough out there about gag orders, secret courts, worldwide compromise of network security.
USA tec company inhabitants and founders, read this: please move out of the country, build your companies in other places, do it now. There is no time to waste. You can not repair the system, that corrupt bureaucrats have irreversibly destroyed.
It will take one or two generations to rebuild a freedom oriented democracy in some other place. Currently Europe still seems to be a good starting point, especially now that the main USA influence channel GB is out.
Please give up the false hope and act now. Get out of that failed state! Freedom can not be rebuild in a fascist system without help from the outside - you can do help much better from outside!
People who still stay in USA will be seen as cooperators by history, the window of opportunity is closing, hurry on and get out asap. Help to defend freedom in other places!
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#43Earlier quoted context omitted.
I don't see anything that makes this unique to CloudFlare, either. (You imply this in your point, but given the specificity of the accusation, I think it's worth clearly pointing out.)
I believe the "unique to CloudFlare" element is that CloudFlare effectively sees traffic for significant portions of the web...but is one entity. So, a powerful enough hostile actor (say, a state) would only need to compromise one entity (CloudFlare) to exploit users of thousands of websites, including many major ones. Er, well, two entities, because they also need entrance data. So, if a state were to compromise an…
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#44It is an USA company - that is enough to not trust them. We do not need any more evidence, there is enough out there about gag orders, secret courts, worldwide compromise of network security. USA tec company inhabitants and founders, read this: please move out of the country, build your companies in other places, do it now. There is no time to waste. You can not repair the system, that corrupt bureaucrats have irreve…
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#45It is an USA company - that is enough to not trust them. We do not need any more evidence, there is enough out there about gag orders, secret courts, worldwide compromise of network security. USA tec company inhabitants and founders, read this: please move out of the country, build your companies in other places, do it now. There is no time to waste. You can not repair the system, that corrupt bureaucrats have irreve…
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#46This short piece doesn't have much detail. But if reCAPTCHA is usable to deanonymize Tor users then I would like to know about it in detail so I can do something about it.
I didn't see anything that makes it unique to recaptcha. Any fingerprint able traffic pattern that can be observed coming and going will work. I could make a website that adds random(1, 64) one pixel images to each page. As you browse the site, you'll be broadcasting 6 bits of identifier with every click.
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#47If it's this easy for a side effect of a recapcha image to de-anonymize a Tor user, then this seems like a failing of the Tor protocol that they should fix. Maybe they need to introduce more jitter, repackage requests into a single stream with consistent (or randomized) packet size, or pad the packets with random data.
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#48Earlier quoted context omitted.
That requires JavaScript. CloudFlare does have a JS-only challenge, which presumably does this type of thing, but this has a couple different problems. From a security perspective, you're executing arbitrary software, which is unwise, especially if you're looking for anonymity. The other issue is that the software is also proprietary. https://support.cloudflare.com/hc/en-us/articles/204191238-W... "During a JavaScrip…
Good point. The Cloudflare capthchas I've seen seemed to use Javascript, but maybe it's just incredibly good CSS. Interestingly, while a javascript calculation might leak more information to CloudFlare (since they might collect other info beseides the result of a proof-of-work function), it would probably leak less to anyone trying to analyze tor traffic from the outside? Seems to me like it would be harder to correl…
They have a non-JS version, too.
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#49Earlier quoted context omitted.
I didn't see anything that makes it unique to recaptcha. Any fingerprint able traffic pattern that can be observed coming and going will work. I could make a website that adds random(1, 64) one pixel images to each page. As you browse the site, you'll be broadcasting 6 bits of identifier with every click.
Data between you and tor nodes are encrypted, no way your idea will work.
Re: Cloudflare ReCAPTCHA De-Anonymizes Tor Users
#50Earlier quoted context omitted.
I believe the "unique to CloudFlare" element is that CloudFlare effectively sees traffic for significant portions of the web...but is one entity. So, a powerful enough hostile actor (say, a state) would only need to compromise one entity (CloudFlare) to exploit users of thousands of websites, including many major ones. Er, well, two entities, because they also need entrance data. So, if a state were to compromise an…
But if we're talking about The Adversary, then they're already deeper in than CloudFlare will ever be, so... what's different?