Live data from Hacker News

'Tor Stinks' presentation – read the full document

theguardian.com

91–100 of 115 posts

Re: 'Tor Stinks' presentation – read the full document

#91
post #32

Today's full Tor coverage by the Guardian is: (Greenwald's article) http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack... (Schneier's article) http://www.theguardian.com/world/2013/oct/04/tor-attacks-nsa... (Leaked doc #1) http://www.theguardian.com/world/interactive/2013/oct/04/tor... (Leaked doc #2) http://www.theguardian.com/world/interactive/2013/oct/04/ego... (Leaked doc #3) http://www.theguardian.com/…

A lot of these articles use abstruse acronyms. Is there perhaps a place where they're all compiled with their explanations? For instance, what is (U)? Or (S), (SI), and (REL)?

Yes, such as "EPICFAIL".

Re: 'Tor Stinks' presentation – read the full document

#92

Does anyone know what the QUANTUM attack they refer to is? It doesn't seem like quantum computing on the face of it; It looks like it may be a system used to disrupt traffic on the internet, possibly man in the middle attacks. Edit: I found a reference to something called a "Quantum Insert" in an article related to GCHQ. They state the following: According to the slides in the GCHQ presentation, the attack was direct…

"To trick targets into visiting a FoxAcid server, the NSA relies on its secret partnerships with US telecoms companies. As part of the Turmoil system, the NSA places secret servers, codenamed Quantum, at key places on the internet backbone. This placement ensures that they can react faster than other websites can. By exploiting that speed difference, these servers can impersonate a visited website to the target befor…

Can we translate that to something sane? Is it "shorter BGP/more specific route announcement?" Or some kind of MITM by being directly in line? Assuming it is TCP traffic, just being "faster to respond" doesn't help all that much without some other logic.

If I were MITMing with full cooperation of only a subset of a network carrier, I'd probably go for some route announcement tricks; easier to interface with the rest of the organization, and due to lack of filtering internally, not much config change required. Would fail safely (== non-detectably), also, and could potentially be explained away as "oh, shit, some stupid ISP leaked routes".

(I guess you could give bad dns responses, too, and then go from there, but that sounds more detectable at the end user device, which is very undesirable.)

Re: 'Tor Stinks' presentation – read the full document

#95
post #29

Earlier quoted context omitted.

It's the new red scare, the new Soviet. We American's require a boogeyman. In all fairness, most countries do. Watching South American leaders lately shows the exact same behavior. Find a foreign devil for everyone to rally against to hide domestic issues.

Soviets were not some bogeyman. They were real, their spies were real, and the international communist movement they sponsored was real. Rosenbergs and others did spy for the Soviets. They did successfully transfer secrets related to the atomic bomb. And they were ideologically motivated.

> And they were ideologically motivated.

I may be reading you incorrectly, but I get the sense you consider what the US/West does somehow isn't ideologically motivated or that having any such motivations is inherently sinister? Of course they were, just like the US is ideologically motivated. Defending and furthering capitalist goals is no less ideologically motivated than defending and furthering communist goals.

Re: 'Tor Stinks' presentation – read the full document

#96
post #16

Of course, if they actually have a really easy time de-anonymizing users, they might "leak" a document like this to encourage people to keep using it. Conspiracy theories are fun!

If I had a few million dollars to run compromized Tor nodes, and the ability to subpoena (and gag order) any Tor node operator in USA, UK and a couple of other major countries to give me their keys, I would be able to easily de-anonymize a large portion of the network.

It is commonly assumed that the NSA/CIA run a substantial portion of the exit nodes. Morever, they are a global adversary (one Tor is not designed to defeat).

Re: 'Tor Stinks' presentation – read the full document

#98
post #90
post #89

Earlier quoted context omitted.

It actually was earlier removed from frontpage, only to reappear after some 10 minutes or so.

Must be a conspiracy.

I wouldn't be so quick to dismiss weird behavior with submissions. Would you?

https://news.ycombinator.com/item?id=5008829

https://news.ycombinator.com/item?id=5008267

Re: 'Tor Stinks' presentation – read the full document

#99
post #90

Earlier quoted context omitted.

Must be a conspiracy.

I wouldn't be so quick to dismiss weird behavior with submissions. Would you? https://news.ycombinator.com/item?id=5008829 https://news.ycombinator.com/item?id=5008267

Yes, I would. You probably know less than you think you do about what the people running HN are doing/trying to do.

Re: 'Tor Stinks' presentation – read the full document

#100
post #99

Earlier quoted context omitted.

I wouldn't be so quick to dismiss weird behavior with submissions. Would you? https://news.ycombinator.com/item?id=5008829 https://news.ycombinator.com/item?id=5008267

Yes, I would. You probably know less than you think you do about what the people running HN are doing/trying to do.

Seems you knew about the the YC company-related submissions being boosted. What makes you think nothing strange is happening to any other submissions?
Post reply on HN