Live data from Hacker News

The talk about de-anonymizing Tor at the BlackHat conference has been removed

tux.so

41–50 of 52 posts

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#41
post #22
post #20

Earlier quoted context omitted.

I have to imagine that this is for some sort of internal bureaucratic reason. I don't see who is in a position to even want to stop this talk - almost certainly not the Tor project itself. The mundane (and thus most likely) answer is that the CMU lawyers wanted to pull it either because they want to sort out some sort of intellectual property first, or they're worried about some sort of liability.

I don't see who is in a position to even want to stop this talk A government agency that wants to stay a step ahead of the competition or of its targets?

It's possible, but I think that's the paranoid / Hollywood spy version of this. Not saying that this sort of thing doesn't happen - the spy agencies take themselves very seriously but aren't big on effective policies anyway, but unless there's a specific operation that is relying on this specific exploit, and someone in the government got advance details of the nature of the exploit, it doesn't seem to have a particularly high prior probability. Anyone with a significant budget can probably pay for any number of zero days so they don't have a single weak point like "if anyone fixes this bug in the software our operation / malware will stop working".

Generally when you see some outside force trying to suppress security research and the presentation thereof, it comes from the companies who will actually have to fix the problems and deal with support calls (or companies who feel that security through obscurity is sufficient and are hoping to somehow suppress the information from ever getting out). In this case, that would be maybe the Tor Project, but they generally are very receptive to this kind of thing.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#42
post #32

Earlier quoted context omitted.

True, but if everyone were to use Tor all the time, everyone would be suspicious all the time, and therefore no one would be suspicious ever. I'd like to see a pay-per-install Tor browser program materialize, one that would incentivize retailers and ISP techs to install Tor browser on customer devices. Every device should be connected to Tor from the moment it is powered on. Then we could at least go back to having f…

"...suspiciuous all the time"? What nonsense. When Everyone uses Tor (or anything else), by definition that is "normal". Or do you view envelopes with this same paranoia? https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html

He addressed that in literally the rest of the sentence:

>everyone would be suspicious all the time, and therefore no one would be suspicious ever.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#44
post #20

A Black Hat spokeswoman told Reuters that the talk had been canceled at the request of lawyers for Carnegie-Mellon University, where the speakers work as researchers. A CMU spokesman had no immediate comment. Source: http://www.reuters.com/article/2014/07/21/cybercrime-confere...

I have to imagine that this is for some sort of internal bureaucratic reason. I don't see who is in a position to even want to stop this talk - almost certainly not the Tor project itself. The mundane (and thus most likely) answer is that the CMU lawyers wanted to pull it either because they want to sort out some sort of intellectual property first, or they're worried about some sort of liability.

I would imagine the researchers broke quite a few laws verifying this attack on the public Tor network, if they indeed did so. And since Tor is incredibly hard to simulate at that level, it's likely that they did. Even if they developed the attack on a simulated network they may have run the tool for verification against the live network. Maybe they did it to de-anonymize a drug marketplace or something else they thought they could get "ethical hacker points" for. Maybe they sent the information to the feds and thought they were doing the right thing.

This is something that has always been legally murky, enough so that I feel like some technical people could decide that they didn't care and just go with it. More people under them might have as well, pulled along by sheer groupthink if not genuine agreement.

This attack was unique not in that it made strong claims, but that it had unusually specific strong claims that indicated some amount of empiricism. I feel like you could only reasonably claim that number if you actually tested it against a very strong network simulation (which doesn't exist for Tor) or the real network.

It's not like other researchers haven't done similar things to get results about Tor. There are a few workshop and academic conference papers that talk about results obtained by analyzing Tor traffic; this is technically wiretapping according to the Tor project, but previously it's always been mundane enough that nobody has gotten involved. This experiment might have compromised some people's very personal information, and it's incredibly public.

This is all really just an expansion of "they're worried about some sort of liability." In any case that's by far the likelier of the two; I can't imagine you could sell IP related to this.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#45
post #3

Speakers drop out all the time. Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues.

>>> Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues. To some degree, isn't this what the Black Hat conference is all about?

Not at all... Black Hat is one of the more commercial, "industry" security conferences out there.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#46
post #3

Speakers drop out all the time. Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues.

>>> Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues. To some degree, isn't this what the Black Hat conference is all about?

Every year that some controversial BH talk happens that exposes some company's unpatched security vulnerabilities (or even questions the company's integrity), either the talk is pulled, or the talk materials are literally ripped out of the books or CDROMs given to attendees. As soon as a company gets wind that a talk might catch them with their pants down they threaten to file suit and Black Hat pulls the talk.

The Black Hat conference is about promoting the security industry. DEFCON, on the other hand, is about promoting hacker culture. It's a lot more common to see 0-day talks at DEFCON because there's much less industry spotlight [and thus, fewer general business professionals that could get scared by some new attack being announced].

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#47

Earlier quoted context omitted.

This is not realistic though and as I said it would actually help the security establishment and military if more people used Tor.

No it wouldn't. How is it possibly helpful to the security establishment if I use tor for what is essentially an innocuous purpose?

It helps them because they are using the service for covert operations. If they were the only ones using it, it would be useless to them. They did very cleverly position it as an instrument for dissidents and at the same time told the generals that this would actually be an advantage. On top of that the NSA is known to successfully target Tor users. If you are really doing something that is against US security interests, you would be mad to use Tor, that was all I was trying to say.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#48
post #44
post #20

Earlier quoted context omitted.

I have to imagine that this is for some sort of internal bureaucratic reason. I don't see who is in a position to even want to stop this talk - almost certainly not the Tor project itself. The mundane (and thus most likely) answer is that the CMU lawyers wanted to pull it either because they want to sort out some sort of intellectual property first, or they're worried about some sort of liability.

I would imagine the researchers broke quite a few laws verifying this attack on the public Tor network, if they indeed did so. And since Tor is incredibly hard to simulate at that level, it's likely that they did. Even if they developed the attack on a simulated network they may have run the tool for verification against the live network. Maybe they did it to de-anonymize a drug marketplace or something else they tho…

>This is all really just an expansion of "they're worried about some sort of liability." In any case that's by far the likelier of the two; I can't imagine you could sell IP related to this.

I more or less agree that liability seems more likely, but I have no idea what the nature of the attack is, so it's always possible it's an offshoot of some other research they are doing which can be patentable. Alternatively, it could be that CMU procedure is to require approval for all talks for brand and IP protection reasons and he just hasn't gone through the proper procedure, so in the meantime they pulled it (rather than pulling it in response to an actual analysis of the talk). This last one seems unlikely, though, as you'd imagine there was no rush to pull the abstract (which contained no details).

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#49
post #48
post #44

Earlier quoted context omitted.

I would imagine the researchers broke quite a few laws verifying this attack on the public Tor network, if they indeed did so. And since Tor is incredibly hard to simulate at that level, it's likely that they did. Even if they developed the attack on a simulated network they may have run the tool for verification against the live network. Maybe they did it to de-anonymize a drug marketplace or something else they tho…

> This is all really just an expansion of "they're worried about some sort of liability." In any case that's by far the likelier of the two; I can't imagine you could sell IP related to this. I more or less agree that liability seems more likely, but I have no idea what the nature of the attack is, so it's always possible it's an offshoot of some other research they are doing which can be patentable. Alternatively, i…

At a school like CMU it's hard for me to believe they'd cancel a researcher's talk because it wasn't properly disclosed. It'd create a headache for the IP team, but they wouldn't cancel the talk. That just makes them look awful.

Re: The talk about de-anonymizing Tor at the BlackHat conference has been removed

#50
post #40
post #28

Earlier quoted context omitted.

Privacy or "oversight," pick one. With strong croup and deniability privacy is absolute, unless you want torture to be a law enforcement tactic. If you can't handle that, you might as well communicate in the clear.

What? Oversight is a legal measure applied to police and security agencies to ensure that they are obeying the law, not something you do to the general public.

Ideally, but in these times...
Post reply on HN