Live data from Hacker News

Things You Should Know About Tor

eff.org

1–10 of 115 posts

Re: Things You Should Know About Tor

#2
This isn't accurate. It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that.

Re: Things You Should Know About Tor

#3
post #2

This isn't accurate. It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that.

This is not factually correct.

If you use tor correctly (https everywhere, don't leak cookies) you can be pretty safe.

I'm fairly sure I know what I'm talking about, but feel free to point to some articles and I will try to explain one by one what Tor can and what it can't do.

Here, some links on Tor operational security, do read them carefully:

- https://www.torproject.org/download/download#warning

- http://cryptome.org/0005/tor-opsec.htm

- the server side: https://trac.torproject.org/projects/tor/wiki/doc/Operationa...

Re: Things You Should Know About Tor

#4
post #2

This isn't accurate. It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that.

A passive observer that is as big as NSA/GCHQ etc. can correlate traffic to de-anonomise some traffic, some very small amount of the time. It is extremely unlikely that a single ISP would ever have enough information to do that though.

Re: Things You Should Know About Tor

#5
post #3
post #2

This isn't accurate. It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that.

This is not factually correct. If you use tor correctly (https everywhere, don't leak cookies) you can be pretty safe. I'm fairly sure I know what I'm talking about, but feel free to point to some articles and I will try to explain one by one what Tor can and what it can't do. Here, some links on Tor operational security, do read them carefully: - https://www.torproject.org/download/download#warning - http://cryptome…

http://dl.acm.org/citation.cfm?id=2516651

Full article is at : http://web.elastic.org/~fche/mirrors/www.jya.com/2013/09/tor...

And i've read other work that talks about using machine leanring to create realistic attacks, and another by a guy that even deanonimized some anonymous remailers. And let's not forget most implemented protocols like tls have bugs.

A somewhat pessimistic view would probably say that the only protection you get is that the nsa doesn't use this capability too often, because it doesn't want to expose it.

Re: Things You Should Know About Tor

#6
post #2

This isn't accurate. It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that.

A passive observer that is as big as NSA/GCHQ etc. can correlate traffic to de-anonomise some traffic, some very small amount of the time. It is extremely unlikely that a single ISP would ever have enough information to do that though.

a) http://www.washingtonpost.com/blogs/the-switch/wp/2013/10/04...

> "With manual analysis we can de-anonymize a very small fraction of Tor users."

> "We will never be able to de-anonymize all Tor users all the time"

b) https://www.schneier.com/blog/archives/2013/10/how_the_nsa_a...

> Tor is a well-designed and robust anonymity tool, and successfully attacking it is difficult. The NSA attacks we found individually target Tor users by exploiting vulnerabilities in their Firefox browsers, and not the Tor application directly.

Re: Things You Should Know About Tor

#7
post #5
post #3

Earlier quoted context omitted.

This is not factually correct. If you use tor correctly (https everywhere, don't leak cookies) you can be pretty safe. I'm fairly sure I know what I'm talking about, but feel free to point to some articles and I will try to explain one by one what Tor can and what it can't do. Here, some links on Tor operational security, do read them carefully: - https://www.torproject.org/download/download#warning - http://cryptome…

http://dl.acm.org/citation.cfm?id=2516651 Full article is at : http://web.elastic.org/~fche/mirrors/www.jya.com/2013/09/tor... And i've read other work that talks about using machine leanring to create realistic attacks, and another by a guy that even deanonimized some anonymous remailers. And let's not forget most implemented protocols like tls have bugs. A somewhat pessimistic view would probably say that the only…

As of the Snowden-leaked documents creation (so at least 2006-2009), the NSA was not, in fact, using that capability at all.

Nor was the FBI or DEA in a recent high-profile case against a certain Tor hidden website. Nor were international LEAs going after Freedom Hosting.

Also note that the final author on the Users Get Routed paper is Paul Syverson, inventor of onion routing and still an active Tor designer. Academic attacks are pretty common against Tor because Tor is the most serious and therefore most well-studied anonymity system. Most of them aren't feasible in the real world regardless of what the abstracts say.

Re: Things You Should Know About Tor

#8
post #2

This isn't accurate. It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that.

A passive observer that is as big as NSA/GCHQ etc. can correlate traffic to de-anonomise some traffic, some very small amount of the time. It is extremely unlikely that a single ISP would ever have enough information to do that though.

Even the NSA has to deal with the base rate fallacy. You can't just magically "correlate" traffic.

Re: Things You Should Know About Tor

#9
post #5
post #3

Earlier quoted context omitted.

This is not factually correct. If you use tor correctly (https everywhere, don't leak cookies) you can be pretty safe. I'm fairly sure I know what I'm talking about, but feel free to point to some articles and I will try to explain one by one what Tor can and what it can't do. Here, some links on Tor operational security, do read them carefully: - https://www.torproject.org/download/download#warning - http://cryptome…

http://dl.acm.org/citation.cfm?id=2516651 Full article is at : http://web.elastic.org/~fche/mirrors/www.jya.com/2013/09/tor... And i've read other work that talks about using machine leanring to create realistic attacks, and another by a guy that even deanonimized some anonymous remailers. And let's not forget most implemented protocols like tls have bugs. A somewhat pessimistic view would probably say that the only…

Or even better, the full paper:

http://cryptome.org/2013/08/tor-users-routed.pdf

And from 2009:

https://blog.torproject.org/blog/one-cell-enough

> The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up. Because we aim to let people browse the web, we can't afford the extra overhead and hours of additional delay that are used in high-latency mix networks like Mixmaster or Mixminion to slow this attack. That's why Tor's security is all about trying to decrease the chances that an adversary will end up in the right positions to see the traffic flows.

Well yeah, that sucks. Correlation attacks are a real threat. If an adversary controls both entry and exit, they can correlate. I personally don't think NSA are doing it (yet!) but that's a speculation. I still claim your statement is incorrect:

> It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that.

Correlation attacks are a real threat but if they are "high likelihood" it only depends on your path selection and use case. Rotate your paths, don't use bittorrent, choose entry and exit points wisely.

> A somewhat pessimistic view would probably say ...

A somewhat optimistic view would say: the tools are there, use them, use them wisely! Using tor is still _so much_ better for anonymity than pretty much anything else.

Re: Things You Should Know About Tor

#10
Things I've used Tor for:

- Accessing BBC Liveplayer as if I'm in England (using lots of normally discouraged add-ons and defined exit-nodes)

- Bypassing paywalls (possibly still criminal?)

- Bypassing censorship (which is what it really is) on organizational wifi networks (in Canadian hospitals). The funniest block was to ginger.io, a big data smartphone data analysis play (but blocked by an over-aggressive filter for obvious reasons).

Does anyone else have some unexpected/interesting use cases?

Post reply on HN