Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

81–90 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#81
post #59

Earlier quoted context omitted.

If you are doing something that would make the NSA interested in you (and I would highly highly discourage that), you'd need to focus more on tradecraft. Get the laptop from a source that can't be traced to you, like a thrift store in a city where you don't live or normally frequent. Disguise yourself, pay in cash, and either make sure there are no security cameras or wait a good year before you do whatever you are g…

Have you tested this approach?

Hah, of course not. I don't do naughty things, I just like thought experiments. And anyone who does do such things would be pretty stupid to draw attention to themselves on Hacker News by posting a proposed method for avoiding surveillance.

Re: Attacking Tor: How the NSA targets users' online anonymity

#82

It appears that the NSA has been able to target only Tor users that are using the Tor - Firefox bundle. So if you are using Chrome or some other browser - configured to use Tor, you would be safe from these exploits. Wouldn't most sophisticated hackers - or other high value targets most likely to be of interest to the NSA - be already doing that, rather than using the Firefox+Tor bundle?

Unless you put a lot of effort into the integration, I'd advise against doing that -- the Firefox included in the bundle is specifically set up to avoid leaking information, while a standard Firefox or standard Chrome will phone home or do something else (like make a DNS request over the public network) that will quickly compromise any security you thought you had.

Re: Attacking Tor: How the NSA targets users' online anonymity

#83
post #76
post #8

Earlier quoted context omitted.

here, there's a subtext that Tor actually made NSA's job easier Are you reading anything from that subtext beyond, "Tor has a high concentration of the kind of users we're interested in, so let's keep it a juicy target rather than squeezing too hard?"

I don't know that it really is subtext here, but I suspect that Tor has many people communicating electronically where they would otherwise refuse to do so at all. In other words, "Normally I would refuse to talk about this on the internet and would meet you in the back of the bar instead, but I trust Tor so let's discuss this now." It therefore puts communications that previously would not have been available to the…

Wouldn't those people have used encrypted communications over Usenet[1] or burner cell phones? Or sometimes even anonymous remailers?

And all those are just as tricky. De-anonymizing alt.anonymous.messages (http://ritter.vg/blog-deanonymizing_amm.html)

Re: Attacking Tor: How the NSA targets users' online anonymity

#84

I remember somebody from Mozilla thinking out loud "we should integrate Tor in Firefox". Glad that didn't get done.

Why? Because it seems that Tor actually does what it says it does. One of the biggest issues with it is that using it singles you out; if we could get more people using it then it would be less useful as a differentiator.

Re: Attacking Tor: How the NSA targets users' online anonymity

#85
don't forget that Tor publishes their exit nodes--they make them freely available to anyone. So a simple membership test on a client IP against that list of exit node IPs identifies that client IP as either having come through Tor via the onion router or else they are an exit node themselves.

Re: Attacking Tor: How the NSA targets users' online anonymity

#86

One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully…

The disheartening things is, though, we don't really have novel technologies (quantum crypto?) to guarantee security anymore and the existing ones will soon be exploitable on a mass scale. This is bad for internet commerce, and for internet itself as a medium. In the eyes of the layman, the internet is untrustworthy. I won't be surprised if in the future we will see closed, privately owned physical networks that guarantee security to their customers.

Re: Attacking Tor: How the NSA targets users' online anonymity

#87
post #71

One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully…

I agree with your post generally, but has Snowden said anything about CAs? I did expect to hear that at least one has signed anything the NSA put in front of them, but I don't recall Snowden providing "proof"* of this. * I'm in no position to verify anything Snowden leaks.

We didn't need these revelations to know CAs are not generally trustworthy. We already had proof. http://en.wikipedia.org/wiki/Certificate_authority#CA_compro...

Re: Attacking Tor: How the NSA targets users' online anonymity

#88

Earlier quoted context omitted.

If you are doing something that would make the NSA interested in you (and I would highly highly discourage that), you'd need to focus more on tradecraft. Get the laptop from a source that can't be traced to you, like a thrift store in a city where you don't live or normally frequent. Disguise yourself, pay in cash, and either make sure there are no security cameras or wait a good year before you do whatever you are g…

That isn't sufficient. The NSA might be able to query their databases for anyone who recently visited the city where the wifi involved is located, and you might match that if there were license plate scanners on the way, even if you paid for gas in cash. If that information isn't collected by the NSA today, it probably will be tomorrow. The NSA might be able to query their databases for anyone who "went off the grid"…

What if you ran scripts on your phone and computer so that it would appear as if you were browsing the internet and using your computer during your regular usage times?

Also using public transportation (and paying for it in cash) will help mitigate the first issue your brought up.

Re: Attacking Tor: How the NSA targets users' online anonymity

#89
post #59

Earlier quoted context omitted.

Have you tested this approach?

Hah, of course not. I don't do naughty things, I just like thought experiments. And anyone who does do such things would be pretty stupid to draw attention to themselves on Hacker News by posting a proposed method for avoiding surveillance.

But that's exactly what someone would say and do to draw attention away from the fact that they may be doing something sketchy :)

Re: Attacking Tor: How the NSA targets users' online anonymity

#90
post #72

Earlier quoted context omitted.

I think that's a pretty serious exaggeration. Designing tools to let you spy on Tor traffic has to be in a separate category from designing bombs that could kill millions. Besides, are there no ends that could justify these means? I think the means are altogether reasonable given the ends. Put aside whether you think the NSA is genuinely pursuing its national security mission: If it were, wouldn't it make perfect sen…

The Stasi and the Gestapo were genuinely pursuing a national security mission. They also did more self-inflicted harm to Germany than the A-bomb did to Japan from the outside. He's not exaggerating the amount of damage an intelligence agency can do.

I feel like you've just invoked Godwin's Law, and yet in this case the comparison actually seems apt...
Post reply on HN