Live data from Hacker News

'Tor Stinks' presentation – read the full document

theguardian.com

81–90 of 115 posts

Re: 'Tor Stinks' presentation – read the full document

#81
General conclusion from all of the published leaks is that GCHQ punches (in technical capability and general quality of work) way above its weight class (funding and presumed staffing levels); they also seem much more willing than NSA to be completely unbound by any idea of domestic user privacy. Which is fitting for a country with the number of CCTV cameras they have.

Re: 'Tor Stinks' presentation – read the full document

#82
post #4

Page 5: "Terrorist with Tor client installed" And its a picture of a guy with a bandit mask and an AK-47. I don't know about you guys, but all my Tor activities are performed in my Halloween costume! I honestly can't believe something this tacky would end up in a presentation. Is this supposed to be propaganda?

Oh, come on, they're humans too, and thus subject to deliberately unfunny jokes in (technical or not) slide presentations like the rest of us. From a quick look this one seems more plausible than the absurd PRISM presentation.

Are they human too? I always pictured the NSA being comprised of a bunch of Vogons.

Re: 'Tor Stinks' presentation – read the full document

#84
post #16

Of course, if they actually have a really easy time de-anonymizing users, they might "leak" a document like this to encourage people to keep using it. Conspiracy theories are fun!

If I had a few million dollars to run compromized Tor nodes, and the ability to subpoena (and gag order) any Tor node operator in USA, UK and a couple of other major countries to give me their keys, I would be able to easily de-anonymize a large portion of the network.

How many times can you employ that tactic until the savvy targets move onto more secure networks?

Re: 'Tor Stinks' presentation – read the full document

#85

It's important to note this is from 2007 and thus things have probably changed immensely since then. Edit: Nevermind, it says it's sourced from a 2007 file but dated 2012.

I think your original conclusion, 2007 is correct.

What exactly does sourced vs dated even mean?

The document states "still investigating" for multiple issues. It doesn't take the NSA 6 years to investigate these things.

The questions are very basic, such as, browser/JS exploits, leftover cookies, and owning the majority of nodes. That is hardly top secret, all of these were things that were public concerns long ago.

The other alternative is they just don't care. They can still slurp down a good portion of the incoming and outgoing email traffic. If one of wikileak's origin stories are to be believed most Tor users have no idea how Tor works or what they are actually doing, including government operators (with the appropriate code name EPICFAIL on page 9.)

Going completely off topic, I had an idea earlier. Bitcoin right now is using something around 16,000 petaflops of processing. This shows that when proper incentives exist massive computational and network resources can be utilized in a distributed manner.

What if a protocol existed which forced user participation or required them to exchange a store of value to use it? For example, if a user acted as a node (relay not exit) they mined a currency (probably inflationary.) If a user did not act as a node, they had to pay a currency which would then be distributed to exit node operators. The currency could be bought and sold through exchanges rather than to a central commercial entity.

The end goal, besides having a lot more network bandwidth, would be to have so many relay and exit nodes running it would be economically impossible for a single entity to compromise a significant number of them.

Of course, easier said than done.

Re: 'Tor Stinks' presentation – read the full document

#86

I also quite like the point "Analytics: Cookie Leakage", like anyone that uses Tor doesn't use it in incognito mode with cookies disabled... or flushes their cookies before they use anything else... ... that either says they're stupid, or they're only after stupid terrorists... as if they're the ones they should really be concerned about.

I think Tor recommends surfing from a dedicated virtual machine, IIRC, which is probably the safest way to surf, though something like Flash or Java can still probably report the actual host IP.

Re: 'Tor Stinks' presentation – read the full document

#88

Today's full Tor coverage by the Guardian is: (Greenwald's article) http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack... (Schneier's article) http://www.theguardian.com/world/2013/oct/04/tor-attacks-nsa... (Leaked doc #1) http://www.theguardian.com/world/interactive/2013/oct/04/tor... (Leaked doc #2) http://www.theguardian.com/world/interactive/2013/oct/04/ego... (Leaked doc #3) http://www.theguardian.com/…

That Schneier article [1] is very technical and reveals quite a lot of interesting information. It was immediately flagged off HN front page by the flagging brigade [2]. It's highly recommended reading, though. [1] http://www.theguardian.com/world/2013/oct/04/tor-attacks-nsa... [2] https://news.ycombinator.com/item?id=6495771

No it wasn't. It at the top of the front page now.

Re: 'Tor Stinks' presentation – read the full document

#89
post #88

Earlier quoted context omitted.

That Schneier article [1] is very technical and reveals quite a lot of interesting information. It was immediately flagged off HN front page by the flagging brigade [2]. It's highly recommended reading, though. [1] http://www.theguardian.com/world/2013/oct/04/tor-attacks-nsa... [2] https://news.ycombinator.com/item?id=6495771

No it wasn't. It at the top of the front page now.

It actually was earlier removed from frontpage, only to reappear after some 10 minutes or so.
Post reply on HN