7 ms·
Why the Tor attack matters
- deleted 11y ago[deleted]
- dogma1138 11y agoWhat is so surprising here? The DOD is the largest funder of research grants in the US. Pretty much every university is doing research for a US agency from cyber security to lasers for missile defense. I find it very hard to believe that this is the firs time a university was conducting computer security research on live targets.
- zaroth 11y agoWhether or not it's surprising is perhaps the least interesting point for discussion. Universities have a responsibility to conduct human research ethically and I hope we hear a lot more about how this research in particular was conducted. This could have endangered lives depending on how it was done, and I'm quite sure the ends don't justify the means unless it was specifically done in a way which protected the anonymity of untargeted users.
- Umn44 11y ago>Universities have a responsibility to conduct human research ethically which means little given the laws of nature, all that matters is what people end up doing and measuring that statistically. If statistically speaking most people aren't ethical then that's what we'll get. This whole idea that people are in control of their actions or have any freedom whatsoever given what we know about the laws of nature has to go.
- throwaway2048 11y agoIf people lack free will, then the people judging/punishing them also lack free will, and the entire premise of your arguement is an absurdity.
- borkabrak 11y agoIf free will didn't exist, it would be necessary to create it.
- dogma1138 11y agoEthics are tricky, especially considering these days one can earn an MSc in Guided Weapon Systems from the top Aerospace Engineering school in the UK.
- middleclick 11y agoIt was also done without a warrant it seems.
- revelation 11y agoThe DOD funds lasers, but it doesn't then has researchers fire them at random cars to test their effectiveness. I'm not actually sure this isn't sarcasm.
- dogma1138 11y agoThe DOD also funds development of guided, chemical, biological and nuclear weapons, and just about every other way to kill a man you can think off. "Agent Orange" was pretty much militarized by the University of Hawaii under a DOD grant during the late 60's, and they've coordinated with the USAF and the CIA and provided research and analysis to optimize the dispersal methods and study it's effects during it's combat use over Vietnam.
- deleted 11y ago[deleted]
- LukaAl 11y agoThe article raises the issue for computer security but computer science is used in many other fields where it could have ethical implications. Self-driving cars is on top of my mind, but for sure other applications has issue too. So I agree with his point and should be extended.
- AMEDICALRe 11y agoThe response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can randomly launch DDOS attack against some company and then claim "Research". This is equivalent to those youtube videos where at the end they justify assault and other egregious behaviour claiming "Social experiment" or "Prank".
- maxerickson 11y agoThe problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.
- vox_mollis 11y agoSome of us are more outraged by the fact that they kowtowed to authority on the BlackHat presentation, and had a disclosure policy that favored the Feds over both the Tor project and the entire security community. The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.
- deleted 11y ago[deleted]
- maxerickson 11y agoI doubt they ever particularly cared about the mantle of 'hacker' and whatever ethos is supposed to go with it. That makes it hard for them to betray it.
- derefr 11y agoRight; the ethical experiment here would be to set up one's own private Tor network and then attack that. (Think that requires a lot of effort? Well, yeah; that's why you do it as part of a university with grant funding!) This would also have the bonus effect of being able to instrument all the nodes, so you could see the effects of your attack flowing through the system in a white-box manner.
- guelo 11y agoIt would have been more ethical if the university had not blocked the "researchers" from disclosing the vulnerability at Black Hat. (Though even then they were not following responsible disclosure practices). The fact that Tor had to guess what the vulnerability was and the "researchers" still have not released their paper is unethical and probably illegal.
- DickingAround 11y agoI think we have to assume that if a government can hack it, they will try. Perhaps it's sad that a university will help them but I'd also to be assumed that they're going to be trying it in some way.
- nullc 11y ago> I think we have to assume that if a government can hack it, they will try. Perhaps it's sad that a university will help them but I'd also to be assumed that they're going to be trying it in some way. Sure. And we can also-- for the purpose of thinking about risks-- assume that if a government can torture people, they will. This doesn't make it right, and it doesn't mean that people should sit idly by. Nor does the fact that people oppose and discourage such actions mean that systems can be left vulnerable to these attacks. Opposing unethical and abusive behavior is not mutually exclusive with building systems which are robust even against unethical attackers. Human wellbeing is maximized when we do _both_.
- dmix 11y agoThe government's ability to do nearly anything by force is an obvious given. This is the reason why constitutional limitations and charters of rights exist in every modern country. For example, it is equally a understood that almost any government could control/manipulate any press agency if they wanted to, or break down any door with a SWAT team. The only difference here is that `cyber` did not exist nor is cleanly appliciable to laws wich limits this type of power - laws largely written in the 1800s. Additionally it largely happens in secret, attribution is difficult, and there is a serious knowledge gap from the general public and the type of operations being done.
- revelation 11y agoI still remember the researchers working with Facebook on some social science project or the discussion on that guy tweeting about airplane security, so the response from HN on this case baffles me somewhat.
- PhantomGremlin 11y agoNone of this should be much of a surprise. There has always been the possibility of bad actors being involved with Tor. In addition, the Tor software is complicated enough that there undoubtedly will be bugs in it. This is "you bet your life" serious. However, both the architecture and the implementation of software must be perfect for that to succeed. It's pretty easy for one bug to mean "game over". People using Tor just don't have a chance when it comes to dealing with the NSA, FSB, GCHQ or any similar state actors. Even allowing for inevitable government bureaucracy and incompetence, the disparity in resources can just be staggering. A big agency can easily, easily afford to devote 100 full time people to one high value target. Those are not odds I'd like to bet against. In the bigger picture, the NSA doesn't give a rats ass about either Silk Road or about child pornography (at least I hope they don't). Which is why an "academic institution" was enlisted to help out the FBI with this. But if I was a dissident or protester in Turkey, Syria, Russia, or any of a large number of authoritarian countries, I certainly wouldn't use Tor. Not if my life and the life of my family was at risk.
- wsxcde 11y agoI don't really buy the comparison that what CERT did is similar to a university-sponsored DDoS. I think a better parallel is the Dan Egerstad case. He ran a Tor exit node and analyzed all the plaintext traffic leaving the exit nodes. He ended up collecting a ton of sensitive usernames and passwords. He tried to contact some of these people by e-mail but they ignored him. So he posted a bunch of these passwords on his blog. He was promptly arrested (and eventually released). At that time the security community was outraged that an obviously well-intentioned researcher was being harassed by the police for doing his job. The response is a lot different now for reasons I don't really understand. I do wish both sides would acknowledge this is a tricky issue. On the one hand, if I run a tor exit node or relay, it is my node and it seems like I'm allowed to do with it as I please. At the same time, it also seems obviously unethical (maybe illegal?) to be harvesting passwords off an exit node or to dole out vigilante justice to Tor users I don't like. One other thing to keep in mind here is that SEI is a DoD funded center. It may be nominally affiliated with CMU, but all their money comes either from the DoD or external grants awarded to the researchers at SEI. So CMU the private research university and SEI the DoD-funded research center have very different obligations to the public. It's important not to conflate the two. The big question is this: what are our responsibilities as security researchers, especially when we're working on "live" software systems? Green seems to be suggesting some form of a review board which pre-approves experiments on live targets. Maybe this is what we need, but be careful what you wish for though. The bad guys don't have review boards.
- throwaway111315 11y agoUnderstanding the nature of each organization involved -- how both motivations and expectations shift as one moves between orgnaizational barriers -- is perhaps the most important, worst reported, least understood part of this story. If the SEI took money to, essentially, weaponize unpublished research, the issue is not one an IRB would have prevented. DoD contractors aren't bound by scientific codes of conduct. In light of that realization, the suggestion in this blog post is confusing. (BTW, distancing CMU and the SEI is not meant as a defense of CMU -- close ties between public science and law enforcement/military R&D are as troubling as ever...)
- ohmygodel 11y ago
- zatkin 11y agoI'm willing to bet that the NSA has started to hook into the Tor network and add in their own nodes, which monitor the traffic. Unless it's not possible to snoop in on data.
- SturgeonsLaw 11y agoWilliam Binney claimed in a recent reddit AMA that the NSA is monitoring packet routes throughout the tor network in a program called Treasuremap. https://www.reddit.com/r/IAmA/comments/3sf8xx/im_bill_binney_former_nsa_tech_director_worked/cwwr7y9 https://www.reddit.com/r/IAmA/comments/3sf8xx/im_bill_binney...
- eropple 11y ago> But there's also a view that computer security research can't really hurt people, so there's no real reason for sort of ethical oversight machinery in the first place. Worse: there's a view that people who get owned "deserved it." Our industry, and its academic attachments, have a really strange vindictive streak towards those who it should be looking out for. (Which is not to say that those people should be looking out for people swapping child porn--but what about the thousands and thousands of people who were not?)
- Absentinsomniac 11y agoSeems like more research needs to go into preventing traffic confirmation attacks: https://blog.torproject.org/blog/tor-security-advisory-relay-early-traffic-confirmation-attack/ https://blog.torproject.org/blog/tor-security-advisory-relay... "A traffic confirmation attack is possible when the attacker controls or observes the relays on both ends of a Tor circuit and then compares traffic timing, volume, or other characteristics to conclude that the two relays are indeed on the same circuit. If the first relay in the circuit (called the "entry guard") knows the IP address of the user, and the last relay in the circuit knows the resource or destination she is accessing, then together they can deanonymize her." Interesting technical problem. They patched it, obviously, but similar attacks are still possible. It does say more research needs to be done, when that post was published. Obviously the method they used to send and receive signals from one side to the other doesn't work anymore, but statistical methods presumably do. Sort of like this: https://mice.cs.columbia.edu/getTechreport.php?techreportID=556&format=pdf https://mice.cs.columbia.edu/getTechreport.php?techreportID=... Seems like a very difficult problem to solve.
- mirimir 11y agoFrom their website, I get that CMU/SEI/CERT works with both DHS and DoD.[0] Although I don't see anything specific about the FBI, it's not too much of a stretch. As DHS has grown and evolved since 9/11, distinctions between police and military have weakened. A decade ago, CERT would have been carefully shielded through parallel construction. In my opinion, this is a wakeup call for the Tor Project. The attack would have been obvious if they'd been tracking the requisite circuit parameters. Ironically enough, it strikes me that the Tor network needs something like CERT for detecting attacks. [0] https://www.cert.org/about/ https://www.cert.org/about/