The indictment says they used a pen/trap device to monitor the wirless traffic. Does that mean they busted the encryption? I'm not saying that's a shock, it would seem more likely that they would monitor the traffic from the ISP's end rather than monitoring the wireless traffic.
No, they wouldn't have looked at anything that was encrypted. A "pen/trap" means they didn't examine the contents of the traffic at all, only where it was sent to (IP address). The term dates back to the old days of telephony -- a pen register would record dots for every digit dialed on a rotary dial (e.g., 8 dots if you dialed "8"). This would only allow the police to determine what phone numbers you dialed. There i…
LulzSec indictment published
61–70 of 70 posts
Re: LulzSec indictment published
#62Earlier quoted context omitted.
To cite the first Tor research paper: https://svn.torproject.org/svn/projects/design-paper/tor-des... Not secure against end-to-end attacks: Tor does not claim to completely solve end-to-end timing or intersection attacks. Some approaches, such as having users run their own onion routers, may help; see Section 9 for more discussion. They are repeating it several times in their documentation, too. It's not really a bu…
The only way to really counter such an attack would be to have a constant stream of traffic going 24/7 that is set at such a level that your normal usage never exceeds it. Then, when you send a real message, the computer throttles back on the garbage communication and injects your real traffic into the stream. The amount of traffic thus remains constant and it would be difficult to do any type of frequency analysis o…
So if it saturates your connection for an hour for 6 hours randomly spaced throughout a day, it's not immediately apparent if that's because you're using it, or it's a decoy stream. Varying the amount used (and always adding at least a little extra when in use) would also make it harder to detect.
At least, that's how it seems to me. There may be some sort of cunning statistical attacks depending on the implementation, especially if the attackers have the endpoint under physical surveillance (and notice that your presence always matches traffic increases of some level)
Re: LulzSec indictment published
#63I'm now wondering about the whole wifi router/MAC address connection (see p. 30). Initially, they claim they intercepted "public signals," and that from this information they were able to determine the MAC addresses connecting to the router. That's all well and good as long as you're running an open access point, but using WPA (for example) would prevent this. Are we supposed to assume this guy wasn't encrypting his…
Re: LulzSec indictment published
#64Earlier quoted context omitted.
The only way to really counter such an attack would be to have a constant stream of traffic going 24/7 that is set at such a level that your normal usage never exceeds it. Then, when you send a real message, the computer throttles back on the garbage communication and injects your real traffic into the stream. The amount of traffic thus remains constant and it would be difficult to do any type of frequency analysis o…
I'm not sure it would have to consistently exceed it, as long as it varied in a random fashion, and that your actual use of the network didn't result in an observable increase in instantaneous or average traffic. So if it saturates your connection for an hour for 6 hours randomly spaced throughout a day, it's not immediately apparent if that's because you're using it, or it's a decoy stream. Varying the amount used (…
Re: LulzSec indictment published
#65I'm now wondering about the whole wifi router/MAC address connection (see p. 30). Initially, they claim they intercepted "public signals," and that from this information they were able to determine the MAC addresses connecting to the router. That's all well and good as long as you're running an open access point, but using WPA (for example) would prevent this. Are we supposed to assume this guy wasn't encrypting his…
I found this notable too. Using a hardline is probably harder to monitor and doing so would require ISP cooperation.
Re: LulzSec indictment published
#66Re: LulzSec indictment published
#67Re: LulzSec indictment published
#68I am more interested in Sabu's indictment and guilty plea, because I don't buy that they caught him because he logged into irc once with his real IP. that doesn't prove you are the Sabu from Lulzsec
I suppose, just another reason not to trust Godaddy?
Re: LulzSec indictment published
#69Earlier quoted context omitted.
It's interesting because the FBI was in a perfect position to perform the most well-known attack on Tor: a correlation / timing attack. "If your adversary can watch both ends of the connection, you lose." They could watch his end and probably knew where the chat server was located. If it was located in the US, it would have been pretty straightforward to send an agent / install a device at the data center and watch t…
http://xkcd.com/538/
Re: LulzSec indictment published
#70I am more interested in Sabu's indictment and guilty plea, because I don't buy that they caught him because he logged into irc once with his real IP. that doesn't prove you are the Sabu from Lulzsec
The ars article a few days back said that he was essentially caught because he had claimed ownership of a domain that he had registered with Godaddy Domains by Proxy, and then Godaddy leaked his information for a couple days when renewing the domain. I suppose, just another reason not to trust Godaddy?
somebody needs to sit down and work out the timeline here and figure out what happen.