Live data from Hacker News

Italian Anti-Corruption Authority Adopts Onion Services

blog.torproject.org

41–50 of 101 posts

Re: Italian Anti-Corruption Authority Adopts Onion Services

#41
post #8

Earlier quoted context omitted.

>Too bad onions was compromised by the NSA. that makes speaking up against the Bad Guys a bit more dangerous. Any references you would want to provide for this claim?

I'd be interested too. I'm aware of the Yasha Levine theory, and complains about js in Firefox ESR, but not much else.

Yasha Levine just released a book which is supposed to give a lot of documentation for his claims. It sounds compelling from a few interviews I listened to but I'm not that far into the book.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#42

Earlier quoted context omitted.

This opinion is controversial, and I’m not going to go into all of the reasons why, but unless you REALY know what you’re doing Tor can’t be trusted. I’d wager only 1% of people on Hacker News would be capable of using a Tor setup for more than a day without getting owned. You’re better off buying a burner iPod or iPad, stick to public wifi spots, and factory reset it once a week. Even then, watch what you type since…

Is that actually a controversy? I feel like everyone I talk to with any credible claim to security expertise recommends against it. So much so that I’d like to see an expert recommend it.

There is a wide and growing gulf between what cyber experts know and what the tech savvy public knows. The world is changing so fast right now you almost need to invent your adversary's tools to be free from them.

If you're talking with large numbers of people that don't trust Tor then it speaks more to the quality of your friends than it does about the prevalence of this opinion.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#43
post #33
post #22

It's refreshing to notice that in the typical italian political climate of general incompetence, there are still people who do a good job.

You are right in the first part (I'm italian). Regarding people doing a good job, I don't know if this is the case. I tried to use this service (just to see how it works), and: - "anonymous reports will be considered only in particular cases" (!) - you cannot report if you are a private person/company - you have no kind of legal counseling / protection - other limitations I'm not sure if it was designed to get actual…

How anonymous could it be, if they know whether a reporter is a "private person/company"?

Re: Italian Anti-Corruption Authority Adopts Onion Services

#44
post #2

Anyone able to comment on the state of Tor security and suggest an up to date OpSec guide to using Tor?

> and suggest an up to date OpSec guide to using Tor?

Use Disposable Whonix VMs in Qubes OS (available in the 4.0-rc4) for the best secure experience that you can get right now. For less security, an alternative would be to use Tails or Subgraph.

You can also control how much attack surface you expose in your browser in the Security Settings in the Tor Button (Medium (now termed Safe) disables JS on HTTP websites, JIT optimization, and sets media files to click-to-play. High (now termed Safest) disables JS everywhere, and SVG...).[1]

[1] : https://tb-manual.torproject.org/en-US/security-slider.html

Re: Italian Anti-Corruption Authority Adopts Onion Services

#45
post #6

Earlier quoted context omitted.

Even if you believe the NSA have some practical attacks against Tor, are you not still better off using Tor than not using it?

What happened to my brain? I just bought the idea that the surveillance state is overall more effective in suppressing criminality.

Poe's Law, in effect.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#46
post #19
post #3

Onion link to the service: http://bsxsptv76s6cjht7.onion/ (source linked in the article, but in Italian: http://www.anticorruzione.it/portal/public/classic/Servizi/S... )

Looks like they aren't taking advantage of the latest version of the onion services. A shame. https://blog.torproject.org/tors-fall-harvest-next-generatio...

> Looks like they aren't taking advantage of the latest version of the onion services. A shame.

Because they're still not production ready. The code for v3 onion services still needs to mature, and when it does, it will become the default.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#47

Earlier quoted context omitted.

If you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec jour…

> Tor is far more fingerprintable than people think it is You seem to have no idea about the existence of pluggable transports.[1][2] > and its riddled with adversaries and malware. Yes, and so is I2P... Freenet... the Internet? > Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. Isn't that an argument for using Tor? As Mike Perry (who works now on the vanguard…

I've been on HN for almost 10 years. You aren't going to get a cut and dry answer from most pros because most pros aren't going to post things in public forums. Pluggable transports have nothing to do with it. I've actually helped defenders against Tor based attackers. I've de-anon'd them. It was easy as fucking shit because most attackers are dumb and the Tor browser isn't 0day proof or as network isolated as people think it is.

Who is your adversary and what are the costs you are willing to bear to hide from them?

There are very few answers to that question that come out with: "Use Tor"

For the 99.9% of adversaries having a wipeable iPad will stop browser fingerprinting and switching up IPs or cafes will stop IP tracking. It wont stop network attacks, but you'll be pretty safe from 0days. For most journalists (or even drug dealers) it's the right approach.

The rest just gets you more heat than its worth.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#48

Earlier quoted context omitted.

If you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec jour…

To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?

> To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?

Maybe; if US intelligence's high-value targets can be targetted by means that Tor does not protect (compromising endpoints, emissions-based techniques, etc.), and Tor provides US intelligence agents a way to exfiltrate information in a way immune to any but more involved, specifically targetted techniques, it might still be valuable to both have Tor exist and have it used by enough people not on US intelligence payroll that it's mere use didn't finger people as agents.

You have to remember that US intelligence does more than monitor people's communications, it also needs communication channels that are accessible, unmonitored, and deniable for its own agents.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#49
post #33

Earlier quoted context omitted.

You are right in the first part (I'm italian). Regarding people doing a good job, I don't know if this is the case. I tried to use this service (just to see how it works), and: - "anonymous reports will be considered only in particular cases" (!) - you cannot report if you are a private person/company - you have no kind of legal counseling / protection - other limitations I'm not sure if it was designed to get actual…

How anonymous could it be, if they know whether a reporter is a "private person/company"?

Look at the form, they ask for you are you working, in which departments, etc.. It is just silly!

Re: Italian Anti-Corruption Authority Adopts Onion Services

#50
post #8

Earlier quoted context omitted.

>Too bad onions was compromised by the NSA. that makes speaking up against the Bad Guys a bit more dangerous. Any references you would want to provide for this claim?

If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you. Even with https, if the feds are in cahoots with the certificate authorities, you would be just as vulnerable to this sort of injection right? However, tor hidden services is another story. I think this is where a bad actor would hit a wall.

> If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you.

It's impossible for Tor to magically encrypt the whole Internet. With any network that will allow you to access the clearnet, the endpoint will see the plaintext if the website you're communicating with doesn't have HTTPS. You're criticizing Tor for something that's impossible to solve. If you think that's possible then please open a ticket to https://trac.torproject.org/ outlining the solution. (Note that the Tor network is scanned to detect bad exits, and authorities flag them with a bad exit flag but they're still used for onion services and stuff)

Also now HTTPS usage is in the 70% from FF telemetry, and onion services are end-to-end encrypted.

> If you access an http site, a government controlled exit node could inject js and eventually gather enough info through profiling mouse movements and browsing habits to ID you.

Do you realize that the Tor Browser comes with loads of patches to Firefox that seek to minimize the amount of entropy leaked by your browser fingerprint? To be specific,[1]

> Timing-based Side Channels

> Attacks based on timing side channels are nothing new in the browser context. Cache-based, cross-site timing, and pixel stealing, to name just a few, got investigated in the past. While their fingerprinting potential varies all timing-based attacks have in common that they need sufficiently fine-grained clocks.

> Design Goal: Websites MUST NOT be able to fingerprint a Tor Browser user by exploiting timing-based side channels.

> Implementation Status: The cleanest solution to timing-based side channels would be to get rid of them. This has been proposed in the research community. However, we remain skeptical as it does not seem to be trivial even considering just a single side channel and more and more potential side channels are showing up. Thus, we rely on disabling all possible timing sources or making them coarse-grained enough in order to render timing side channels unsuitable as a means for fingerprinting browser users.

> We set dom.enable_user_timing and dom.enable_resource_timing to false to disable these explicit timing sources. Furthermore, we clamp the resolution of explicit clocks to 100ms with two Firefox patches. This includes performance.now(), new Date().getTime() , audioContext.currentTime, canvasStream.currentTime, video.currentTime, audio.currentTime, new File([], "").lastModified , new File([], "").lastModifiedDate.getTime(), animation.startTime, animation.currentTime, animation.timeline.currentTime, and document.timeline.currentTime.

> While clamping the clock resolution to 100ms is a step towards neutering the timing-based side channel fingerprinting, it is by no means sufficient. It turns out that it is possible to subvert our clamping of explicit clocks by using implicit ones, e.g. extrapolating the true time by running a busy loop with a predictable operation in it. We are tracking this problem in our bug tracker and are working with the research community and Mozilla to develop and test a proper solution to this part of our defense against timing-based side channel fingerprinting risks.

[1] : https://www.torproject.org/projects/torbrowser/design/

Post reply on HN