5 ms·
What I don't get about Tor is that if your adversary can see all Internet packets, all the time, wouldn't it be trivial for them to find the real source and des
by privacy101 11y ago
What I don't get about Tor is that if your adversary can see all Internet packets, all the time, wouldn't it be trivial for them to find the real source and destination of a Tor packet using it's meta-data (size,timestamp,etc...)? For example, a packet of size X was sent from host 1 to host 2 and immediately after, a similarly sized packet was sent from host 2 to host 3, etc... I think of Tor more like a tool to avoid a specific server from finding who you are, and not the government.
- Menge 11y agoI didn't look specifically at Tor, but even early p2p anonymizer proposals had each node aggregate groups of standard size newly encapsulated chunks that were only sent out when there's enough to send similar bundles to all its next hops. This made simple observation at each hop pretty worthless, though I think someone has since proposed a statistical attack that could narrow the client down eventually if given a long enough connection with certain behaviors.
- Kristine1975 11y agoThis is called a timing attack and no, Tor doesn't seem to protect you against it: http://tor.stackexchange.com/q/737 http://tor.stackexchange.com/q/737
- teddyh 11y agoYou are assuming not only that an attacker can see all packets all the time, but also at all points in the network, which is unlikely in practice.
- pyvpx 11y agoif your attacker isn't apart of the Five Eyes, sure.
- omginternets 11y agoI don't know that the Five Eyes have the kind of temporal resolution in their measures that would be needed to conduct these kinds of attacks. In fact, it's very likely that they don't.
- privong 11y ago> I don't know that the Five Eyes have the kind of temporal resolution in their measures that would be needed to conduct these kinds of attacks. In fact, it's very likely that they don't. Why is it unlikely for them to have that kind of temporal resolution? I would assume the opposite. It seems like it would be trivial to save timing information along with packets. And the timing data must be relatively small compared to whatever data they're saving on the packets, so the added storage requirement is not really a concern.
- omginternets 11y agoBecause it's unlikely that they're saving every packet. I suspect they're down-sampling somewhere, given the sheer volume of data. This isn't to say they couldn't specifically target an endpoint for monitoring, however. Perhaps I was unclear about that.
- privong 11y agoOne way around that limitation could be real-time analysis with some data buffering. In that way, the timing attack could be done and only those packets saved. I don't really have a feel for what kind of processing this would require, though. Presumably one would also need a low-latency link to the nodes of interest.
- FLUX-YOU 11y agoGCHQ were doing full takes of the internet for 3 days, Tor traffic is nothing compared to that [0]http://www.spiegel.de/media/media-34103.pdf http://www.spiegel.de/media/media-34103.pdf
- 11y ago
- hiq 11y agoThere is always a trade-off between usability / efficiency and security, and this trade-off has to take into account the attacker model. Tor is a low-latency network by design, so right from the start it gives up some security to be more usable instead. That probably still works against many attackers, including some state agencies, although not the most powerful. We should also keep the bigger picture in mind. Sure, if the NSA really wants to know everything about you, it's going to keep a record of your outgoing packets, and match it with packets from exit nodes to have all your metadata. But how much is it going to cost? How does it scale? I think we can assume that if everyone were to use Tor, mass surveillance would be at least far more costly. Each new user adds noise in the correlation measures. I can also argue that if you use Tor from your home or any location that is associated to you in any way, you're not really trying to avoid target surveillance by your government.
- imglorp 11y agoIt's everyone's civic duty to contribute to the noise and to increase the expense to all state actors.
- programmarchy 11y agoIs it also our civic duty to pay the taxes to these state actors? Asking because this tactic seems a bit like striking at the branches, rather than the root.
- deleted 11y ago[deleted]
- knodi123 11y agoHe wasn't sent to prison for asking questions any more than drug dealers are sent to prison for "asking" whether the US has a rational policy for drug enforcement.
- pdkl95 11y ago> rather than the root So run for office. I would certainly vote for someone who was against this crap. > It's everyone's civic duty to contribute to the noise That's a tactic. While it may be useful, a strategy that works to gain political influence is better in the long-run.
- ionised 11y agoAs the Tor developers themselves say, Tor should be only one tool in your overall privacy/security toolbox. Relying on Tor alone to keep you anonymous, especially against nation state actors is probably not a great idea.
- dandelion_lover 11y agoOne solution against such timing attack is to use i2p, which uses garlic routing instead of onion routing. As a downside i2p is less reliable.
- privacy101 11y agoApparently i2p is better protected against this type of attack but it might not be perfect. "This sort of attack is powerful, but its applicability to I2P is non obvious" [1] "Without protocol scrubbing or higher latency, global active adversaries can gain substantial information. As such, people concerned with these attacks could increase the latency (using nontrivial delays or batching strategies), include protocol scrubbing, or other advanced tunnel routing techniques, but these are unimplemented in I2P." [1] [1] https://geti2p.net/en/docs/how/threat-model#timing https://geti2p.net/en/docs/how/threat-model#timing
- omginternets 11y agoMy understanding is that Tor is designed to prevent you from being a suspect in the first place.
- sorokod 11y agoSuch a systems might (your geography dependent) make you a suspect immediately
- omginternets 11y agoWell that's sort of the point. Tor is special in that it helps avoid this problem, i.e.: given and endpoint, it's (for all intents and purposes) impossible to determine whence the traffic comes. At the same time, Tor can be used in such a way that nobody will know it's being used.
- GTP 11y agoUhm, not so sure: usually packets have fixed size and through a tor node can pass lots of them from different sources. And if timestamp can be a problem a tor node could randomly delay them.
- sfilipov 11y agoAnd relay them out of order i.e. a Tor node receives a packet from A, then from B, then resends packet from B, then from A.