Live data from Hacker News

How Secure is Tor? Not secure at all

csam-bib.github.io

41–50 of 57 posts

Re: How Secure is Tor? Not secure at all

#41
post #31

Earlier quoted context omitted.

You can adjust the code on the page easily (it’s open source javascript) to determine the question you are after, which is a valid one: if an adversary starts today and adds x nodes to the existing network, what is their success rate? BUT the author asked a different (but valid) question: assuming the adversary controls x out of N existing nodes, what is the success rate? I am unclear: is the assertion that everyone’…

No, the author is presenting an idea that $25 a month can buy you a node. That fits adding a new node to the network, not taking over an existing node.

I am the author. I am telling you are wrong about that.

Re: How Secure is Tor? Not secure at all

#42
Correct me if I'm wrong, but this feels like a long-winded way of saying: if an adversary could control a significant portion of relays without being found out and for a not-insignificant period of time, it could defeat Tor.

Is it correct? Probably. Does it justify the "Not secure at all" indictment? No.

Re: How Secure is Tor? Not secure at all

#43

Correct me if I'm wrong, but this feels like a long-winded way of saying: if an adversary could control a significant portion of relays without being found out and for a not-insignificant period of time, it could defeat Tor. Is it correct? Probably. Does it justify the "Not secure at all" indictment? No.

The calculator also misleads in another direction, in that it could underestimate the probability of failure by only considering the "takeover" scenario, while I think it is much more likely to be defeated via other OpSec failures.

Re: How Secure is Tor? Not secure at all

#44

Earlier quoted context omitted.

It’s extremely unlikely that they would be able to find an end user (not an onion site operator, a user) with good opsec who connects occasionally, such as a journalist uploading a few documents to a secure onion drop. All existing known attacks were against onion site operators running for long periods from a static location (still took a lot of resources and time to track them down) or end users with poor opsec/inf…

The site linked takes a shot at enumerating how unlikely it is. Do you claim it is wrong? If so, what is your calculated chance? To me, TOR is not adequate to protect users targeted by a nation state who are the ones that TOR claims to be created for.

Given that onion sites require six hops and that the Tor team keeps watch for suspicious node behavior, and that there is no “exit node” where you can more closely observe outgoing traffic, onion connections are actually very tough to correlate. It requires a large number of compromised nodes plus cooperation with ISPs and backbone providers, as seen in the arrest of the onion site operator a few years ago. There were some good writeups at the time. You basically need to use DDoS techniques combined with targeted disconnections to narrow down the list of potential targets, even while owning many nodes. And onions have seen some DDoS hardening since this time.

Clearnet traffic via exit node is a bit different. With only three hops it might be possible to correlate targeted traffic by owning a huge number of nodes, but even then, unless you also control the server being connected (or it barely receives any traffic) then it may not give you anything actionable. (Using Tor is not a crime.) Unless you can see what is being done on the server by the unmasked user, or you can establish a pattern of behavior, or you see something like a large data transfer whose size matches a known event of interest, then all you know is someone accessed the server over Tor. And even then, owning both the entry and exit isn’t sufficient if the user is masking their traffic with decoy and/or relay traffic.

Re: How Secure is Tor? Not secure at all

#45

Earlier quoted context omitted.

You are welcome to fork Tor and create a version that uses this approach, but good luck getting people to use it. Conversely, even if the official project implemented an onion blacklist, a fork would quickly appear to remove it. And node operators would likely prefer that one. Anyone with any sense understands that introducing a node blacklist creates the capability to expand the use of that blacklist in the interest…

That’s not at all what I proposed. Not even close. Edit: on second look I can see how you could think it was. I’m just proposing that if you run a node you be allowed to not become a rendezvous point for onion sites.

Ah, I misunderstood. In any case, onion traffic is not flagged as such, so nobody but the last hop would even know that onion traffic is being passed. Allowing the last node to kill the whole circuit seems like it would cause routing problems and/or contribute towards deanonymization, as would flagging onion traffic at every step of the journey.

Re: How Secure is Tor? Not secure at all

#46

Earlier quoted context omitted.

Pretty much everything claimed on this site is false or grossly misleading.

Really? Tell me why.

The primary claims of the site, both made without any evidence (presumably by you), are that

1. Tor is primarily used to distribute CSAM,

2. a single organization with a budget of $150k could deanonymize every Tor user simultaneously.

Since pretty much every firat world law enforcement organization can cough up this amount in spare budget, either

- at least one of the claims above is false; or

- there's a global conspiracy involving every major law enforcement organization in the planet being taken over by pedos.

In fact, both claims (you?) made without evidence are simply false.

Having published calculations for the second claim is like having published calculations for "the Sun went supernova yesterday". The conclusion is blatantly wrong, so the calculations have a mistake, and an intellectually honest author would double check them, find that mistake, then retract the claim (or would not have made it in the first place).

Re: How Secure is Tor? Not secure at all

#47

Earlier quoted context omitted.

There is a known solution. Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok. However, if a relay refuses to service an onion site directory look up, it will be banned by the Directory Authority. They could allow this today. But they don’t. That’s the simple solution. No surveillance. Not back door. No less privacy for everyone else. edit: This is easy to…

>Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok. That's simply not true. Exit operators who intentionally block websites are flagged as bad relays. https://community.torproject.org/policies/relays/expectation... https://gitlab.torproject.org/tpo/network-health/team/-/wiki...

I think that is referring to the node exit policy, which explicitly allows particular ports and IP addresses to be blocked.

https://support.torproject.org/relay-operators/exit-policies...

The documents you referred to just say you need to honor your own exit policy.

Re: How Secure is Tor? Not secure at all

#48
post #31

Earlier quoted context omitted.

No, the author is presenting an idea that $25 a month can buy you a node. That fits adding a new node to the network, not taking over an existing node.

I am the author. I am telling you are wrong about that.

We are all, in unison, saying you -the author- is the one who is wrong.

Posting some words on a URL does not make them factually accurate.

Re: How Secure is Tor? Not secure at all

#49

Earlier quoted context omitted.

Really? Tell me why.

The primary claims of the site, both made without any evidence (presumably by you), are that 1. Tor is primarily used to distribute CSAM, 2. a single organization with a budget of $150k could deanonymize every Tor user simultaneously. Since pretty much every firat world law enforcement organization can cough up this amount in spare budget, either - at least one of the claims above is false; or - there's a global cons…

1. I said “extensively” used for csam. What’s my source/evidence for that claim? This list of peer reviewed papers, cases, and government reports: https://csam-bib.github.io.

2. My site shows a mathematical model of security that Tor provides in terms of its design for relays alone. I say on the site I’m not including staff and other costs. In fact bringing someone to court is a further cost. My point in making the site is to quantify solely the costs that the design brings to the table. You can then compare that design to some other anonymous system. Or compare it to a doublespend attack on bitcoin or to brute force decryption. That’s important for users.

Unlike the Tor Project, I’m being transparent by showing assumptions, the math, and the code. Do you have a better model? Great, then publish it. I’m trying to start a formal conversation. The Tor Project should be relying on science, and not strong assertions, to ensure its security.

And while there are costs to, say, bring someone to court for csam, do you believe all adversaries are going to do that? That’s why it’s not part of the costs I model.

Finally, to be more clear, Onion Services in particular are the problem when it comes to CSAM (and ransomeware). Tor Browser is not the issue when it comes to CSAM.

Re: How Secure is Tor? Not secure at all

#50

Correct me if I'm wrong, but this feels like a long-winded way of saying: if an adversary could control a significant portion of relays without being found out and for a not-insignificant period of time, it could defeat Tor. Is it correct? Probably. Does it justify the "Not secure at all" indictment? No.

The website actually states “not very secure at all”. This hacker news submission changed the title.
Post reply on HN