Live data from Hacker News

Tor and HTTPS

eff.org

81–90 of 135 posts

Re: Tor and HTTPS

#81
post #39

Earlier quoted context omitted.

Security professionals have hypothesized many attacks against the anonymity of the tor onion and what you describe is pretty close to one of them. If the NSA was to create tons Tor nodes (enter, exit, and relay), the onion may be broken. Tor is by no means perfect. It is only obfuscating. It is easy to see how this is broken if you click the TOR button on this thing and then imagine the TOR nodes say NSA on them. I t…

There isn't really such category as a tor 'enter' node. Any node can be the first node of the chain, but it has no idea whether it is the first or one in the middle of the chain. Essentially, it's as if the 'entrance node' is running on your computer. That means that no node knows the source of the traffic, and only the exit node knows the destination. For the NSA to effectively monitor Tor, they'd need to run a larg…

If the NSA has the logs of ISPs that carry one third of the world's traffic, couldn't they execute the attack without running any Tor nodes? Or am I misunderstanding the onion protocol?

Re: Tor and HTTPS

#82

Why does the graphic portray police as mean angry people. Police are good people who provide a valuable service. They do a good thing. They are not the enemy.

In your country, maybe.

In someone else's country, maybe not.

Re: Tor and HTTPS

#83
post #55

The problem of HTTPS is that you will need certification from some CAs which may be working with government agents.

Yeah, and even if you get a certificate from a CA which isn't, it doesn't matter, since any other CA can still issue a cert for your domain.

Cert pinning and http://tools.ietf.org/html/rfc6962 would help for those cases.

Re: Tor and HTTPS

#84
post #59

Earlier quoted context omitted.

https encrypts the host header (indeed all the http headers), so yes it does encrypt the domain in that respect. What it can't encrypt is the destination IP address, which would be reverse looked up to the domain if everything was configured right in the DNS.

This is no longer true. Seeing as HTTPS sites could not previously share an IP address, making it obvious which site communications with any given IP address was directed towards, an extension was developed that now sends the desired host unencrypted before the encrypted package. This doesn't yield any more information that could previously be derived, but does allow you to serve as many HTTPS sites from a single hos…

I stand corrected and I've learnt something :)

Re: Tor and HTTPS

#85
post #62

What happens if NSA starts operating a number of Tor exit nodes and eavesdropping on the outgoing traffic? What prevents them from doing so?

Frankly, I think you have to assume that the NSA is already doing this. I also think you have to assume they have the private keys for every major CA in the world.

Worth noting: Having the private keys for all the CA's in the world just means that they could launch a man-in-the-middle attack against a secure service. (Which would be easy for a rudimentary traceroute to detect.) Not that they could decrypt SSL traffic talking directly to my server, for example.

The susceptibility to this kind of attack is a big part of the knock that a lot of people have against HTTPS. It's generally been ignored as "too hard to pull off" - but it's also generally been assumed that your own government won't bother recording your communications without probable cause.

Anyway, unless they were targeting a specific service (which they usually aren't, they usually target a person) it would require too much effort to set this up for all the secure services they use.

Re: Tor and HTTPS

#86
post #47

You can help contribute - https://cloud.torproject.org/ Note that you can reduce your costs by using spot instances.

Do you have any sense how many nodes (or I guess how much bandwidth or even something else I'm not thinking of) it would take to make a material difference on the speed of the network?

Re: Tor and HTTPS

#87
post #76

Why does the graphic portray police as mean angry people. Police are good people who provide a valuable service. They do a good thing. They are not the enemy.

No, they don't, they do a bad thing. In actual fact, all cops are bastards. Their primary function in society is to defend the property rights of the capitalist class against the working class, thus preserving inequality.

Ignoring for a moment the validity of this statement, can I ask why you visit a site that is primarily about business news/Silicon Valley Hacker errata if you're not a fan of the 'bourgeois'?

Re: Tor and HTTPS

#89
post #39

Earlier quoted context omitted.

Security professionals have hypothesized many attacks against the anonymity of the tor onion and what you describe is pretty close to one of them. If the NSA was to create tons Tor nodes (enter, exit, and relay), the onion may be broken. Tor is by no means perfect. It is only obfuscating. It is easy to see how this is broken if you click the TOR button on this thing and then imagine the TOR nodes say NSA on them. I t…

There isn't really such category as a tor 'enter' node. Any node can be the first node of the chain, but it has no idea whether it is the first or one in the middle of the chain. Essentially, it's as if the 'entrance node' is running on your computer. That means that no node knows the source of the traffic, and only the exit node knows the destination. For the NSA to effectively monitor Tor, they'd need to run a larg…

[deleted]
Post reply on HN