Attacking Tor: How the NSA targets users' online anonymity
51–60 of 184 posts
Re: Attacking Tor: How the NSA targets users' online anonymity
#52Earlier quoted context omitted.
Attacking Tor by passive analysis is one thing. Installing spyware, creating a botnet, and making the infection process quick and easy is another. There might be some justification for the former. The latter is too risky.
It's not a "Manhattan Project" if it's within the capabilities of any decent-sized organized crime syndicate. People here have short memories. In the 1990s, teenaged hackers owned up the backbone.
Re: Attacking Tor: How the NSA targets users' online anonymity
#53Re: Attacking Tor: How the NSA targets users' online anonymity
#54It looks like they had some trouble picking out users 5 years ago... lord only knows how easy it must be for them now.
Re: Attacking Tor: How the NSA targets users' online anonymity
#55Sounds like, if you're going to do something very sensitive on tor, you need to: - always have an update to date version of tor bundle! - compile the bundle yourself from source - run it virtually, and always roll back to a clean snapshot (before installing it tor) when done - if possible use from a network that is not your own (open wifi, public wifi, etc.) - spoof your mac address - do not run JS, Java applets, etc…
If you are doing something that would make the NSA interested in you (and I would highly highly discourage that), you'd need to focus more on tradecraft. Get the laptop from a source that can't be traced to you, like a thrift store in a city where you don't live or normally frequent. Disguise yourself, pay in cash, and either make sure there are no security cameras or wait a good year before you do whatever you are g…
"Wear gloves": Why? Are you thinking someone will pierce the veil of all these other precautions but then be stymied when they find a smashed laptop with no fingerprints on it?
"Sir, we followed him for a year, watched him buy a laptop and use it in a park, but when we recovered the laptop from the dumpster, there were no fingerprints on it!"
"Curses, our plan is foiled!"
Re: Attacking Tor: How the NSA targets users' online anonymity
#56Sounds like, if you're going to do something very sensitive on tor, you need to: - always have an update to date version of tor bundle! - compile the bundle yourself from source - run it virtually, and always roll back to a clean snapshot (before installing it tor) when done - if possible use from a network that is not your own (open wifi, public wifi, etc.) - spoof your mac address - do not run JS, Java applets, etc…
If you are doing something that would make the NSA interested in you (and I would highly highly discourage that), you'd need to focus more on tradecraft. Get the laptop from a source that can't be traced to you, like a thrift store in a city where you don't live or normally frequent. Disguise yourself, pay in cash, and either make sure there are no security cameras or wait a good year before you do whatever you are g…
Still, I completely agree with you.
Re: Attacking Tor: How the NSA targets users' online anonymity
#57Earlier quoted context omitted.
It's probably the best you can do, but it still doesn't prevent your anonymity from being compromised. As soon as the malware is installed, it can phone home, even if you end up wiping it after you are done.
The malware would have to escape the virtual machine. The VM needs to be firewalled off from the host and NOT have the host guest tools installed.
- If the host guest tools are installed on the guest host, then it would be possible for the malware to install them itself.
- If the host guest tools can't be enabled/disabled on a per-VM basis, then that could be an issue, as you would probably have VMs that you wish to use in a less convert capacity.
- The malware would have access to your browser for the duration of that session. Presumably any information that you accessed during that session is compromised. If they are consistently able to compromise you during every session, then any slip-up with PII during any session could compromise you.
Re: Attacking Tor: How the NSA targets users' online anonymity
#58Earlier quoted context omitted.
It's not a "Manhattan Project" if it's within the capabilities of any decent-sized organized crime syndicate. People here have short memories. In the 1990s, teenaged hackers owned up the backbone.
I called them analogous because of their potential effects and their development in secret by governments. I don't think a crime syndicate could do it so effectively; when the NSA "owns up the backbone", even if the operator discovers the intrusion, it stays owned.
I don't think there is really an analogy here.
Re: Attacking Tor: How the NSA targets users' online anonymity
#59Sounds like, if you're going to do something very sensitive on tor, you need to: - always have an update to date version of tor bundle! - compile the bundle yourself from source - run it virtually, and always roll back to a clean snapshot (before installing it tor) when done - if possible use from a network that is not your own (open wifi, public wifi, etc.) - spoof your mac address - do not run JS, Java applets, etc…
If you are doing something that would make the NSA interested in you (and I would highly highly discourage that), you'd need to focus more on tradecraft. Get the laptop from a source that can't be traced to you, like a thrift store in a city where you don't live or normally frequent. Disguise yourself, pay in cash, and either make sure there are no security cameras or wait a good year before you do whatever you are g…
Re: Attacking Tor: How the NSA targets users' online anonymity
#60Sounds like, if you're going to do something very sensitive on tor, you need to: - always have an update to date version of tor bundle! - compile the bundle yourself from source - run it virtually, and always roll back to a clean snapshot (before installing it tor) when done - if possible use from a network that is not your own (open wifi, public wifi, etc.) - spoof your mac address - do not run JS, Java applets, etc…
If you are doing something that would make the NSA interested in you (and I would highly highly discourage that), you'd need to focus more on tradecraft. Get the laptop from a source that can't be traced to you, like a thrift store in a city where you don't live or normally frequent. Disguise yourself, pay in cash, and either make sure there are no security cameras or wait a good year before you do whatever you are g…
The NSA might be able to query their databases for anyone who recently visited the city where the wifi involved is located, and you might match that if there were license plate scanners on the way, even if you paid for gas in cash. If that information isn't collected by the NSA today, it probably will be tomorrow.
The NSA might be able to query their databases for anyone who "went off the grid" for a day or two around the event they're interested in. That's not good enough to id a suspect, but it narrows the pool. If you stopped making google searches from your normal internet connection within a day of the event in the other city, and you normally use your computer every day, or if your phone was off within a day of the event, that's suspicious. Enough of those kinds of data points and you become a suspect.
Even simpler, and a staple of crime fiction, stuff happens that you have no control over that can place you in the vicinity at the time of the event. If you have bad luck and get a ticket or get in a car accident in the city in question, for instance...
Far from suggesting that you simply need to be more careful, my view is that you can't take sufficient precautions to get risk down to a tolerable level if whatever you're doing brings you to the attention of the NSA.