Live data from Hacker News

Hackers breach FSB contractor, expose Tor deanonymization project

zdnet.com

41–50 of 123 posts

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#41

Earlier quoted context omitted.

How do various embassies contact the mothership? I heard that a lot of them use TOR, and for smaller countries it makes sense. Big countries I suppose have their brew (which is not necessarily safer.)

Why do they need anything more than HTTPS? Just open https://nsa.gov/ and send your data.

Because that reveals that you are talking to the NSA right now. Sometimes the volume of chatter is useful information in its own right. Sure, you could script something to make the data rate constant, but that might be undesirably expensive and if you do everything over Tor then your video chat with HQ looks indistinguishable from you bit torrenting pirate episodes of My Little Pony.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#42
post #14
post #2

Last time Tor was mentioned here, a user posted this link [1], claiming Tor is a military financed destabilization project. Seems unbelievable, but there appear to be lots of supporting documents. [1]: https://surveillancevalley.com/blog/fact-checking-the-tor-pr...

This is a silly conspiracy. The facts about the initial funding of research on Tor have always been public and well-known, and the conspiracy is based on the idea that there was some grand scheme looking forward into the future for more than 16 years. It's much more likely that some researchers at some government agency implemented the known idea of onion routing in a proof of concept, their work was more successful…

Yeah, just because something was either invented or first implemented in the military doesn't mean it's tainted forever. SQLite was originally designed to be used on ballistic missiles. Heck, the internet itself was first developed by the DoD (ARPA). A lot of technologies have military origins.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#43
post #39

Earlier quoted context omitted.

Because if you don't know where traffic is going or coming from it's harder to infer what the message is about.

You properly encrypt it and regularly send data (like in a VPN). Done.

So you're claiming that using a VPN makes correlation attacks impossible? Do you have any sources on this? I'd love to read up to better understand your thinking.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#44

Earlier quoted context omitted.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…

Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that. Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up. So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm…

The flipside of that is that it's reasonable to assume that most (not government run) TOR nodes are run at hosters offering cheap small VPS with cheap traffic and high bandwidth. That gives a few select datacenters where sniffing and correlating network traffic is extremely beneficial for deanonymizing TOR traffic. And if the datacenter operator doesn't cooperate and isn't vulnerable to covert sniffing there are always their uplink providers.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#45
post #39

Earlier quoted context omitted.

You properly encrypt it and regularly send data (like in a VPN). Done.

So you're claiming that using a VPN makes correlation attacks impossible? Do you have any sources on this? I'd love to read up to better understand your thinking.

Correlation attacks are attacing anonymity. If you are an embassy, there is no need for anonymity. Ok, an embassy connected to vpn.whitehouse.gov and sent 20 gb of data, so what?

(unless you are thinking about high level things, like "lots of traffic" -> "something going on", but tor won't help with that either)

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#46
post #24

Earlier quoted context omitted.

Tor is an anonymizer. Why would embassies use an anonymizer for communicating back home? Everyone knows they’ll be communicating with home. There’s no point in hiding that. What you want to hide is the content of that communication, which Tor doesn’t do very well. You do that with standard encryption tools.

Because if you don't know where traffic is going or coming from it's harder to infer what the message is about.

It’s not hard to infer that traffic from an embassy is probably going to their home country.

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#47

Nobody with an ounce of intelligence can believe for one moment that the most powerful intelligence agencies in the most powerful country of the world will stand idly by and watch a protocol/network be completely opaque for them. Whether there is evidence or not (in such cases there may never be enough evidence), it is safe to assume that many if not most Tor exit nodes are govt run (various govts), and one or more o…

I guess one benefit of this is only one country can control a majority of nodes.

... What about a group of countries?

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#48

> Tax-3 - a project for the creation of a closed intranet to store the information of highly-sensitive state figures, judges, and local administration officials, separate from the rest of the state's IT networks. So, is this intranet used for keeping official (confidential) records or for blackmail purposes?

Or is it the network they won’t pass laws requiring backdoors for? Literally segment society into those with power and privacy, and those with neither?

Why on earth would they need separate infrastructure and the rest of us do not?

Re: Hackers breach FSB contractor, expose Tor deanonymization project

#50

Earlier quoted context omitted.

Controlling just the exit nodes doesn't mean much, but by controlling the majority of all nodes you break TOR. If I controll all nodes your connection uses I can trivially deanonymize you (even if you use hidden services). It has also been shown multiple time that it is enough to control the first and the last node of the connection because timing correlation works great. The upside is that no government would admit…

Running Tor exit node is dangerous. Very few people would dare to do so. Most of hosters will forbid that. Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up. So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm…

Govts have almost unlimited resources and willpower. They could easily just detect the tor nodes running, then spin up n /2 + 1 to compensate, giving them majority control. This could be automated.
Post reply on HN