6 ms·
I didn't realize just how fragile TOR is. . . While I understand that remaining anonymous requires adjusting your browser habits somewhat extensively, the fact
by pyromine 10y ago
I didn't realize just how fragile TOR is. . . While I understand that remaining anonymous requires adjusting your browser habits somewhat extensively, the fact that a ReCAPTCHA is enough to (theoretically) de-anonymize a user seems to me that it's not able to anonymize at all when browsing.
While TOR may be useful for evading firewalls, my general perception of the project has changed from general anonymity tool to a tool tailored for very specific use.
Granted, this is probably what my understanding always should have been.
- walrus01 10y agoIf I were a national signals intelligence agency with a correspondingly huge multi-billion dollar budget, it would be trivial to run a large percentage of tor exit nodes... You could probably achieve it with 500 individual 1U servers colocated with random hosting companies around the globe at a budget of $250/mo * 500 = $125,000/mo, which is a tiny drop in the bucket compared to the traffic analysis capability it would give you, with the ability to capture all traffic entering/exiting each node's world-facing public ipv4/ipv6 interfaces. edit: The major challenge would probably be continually violating various hosting companies' TOS/AUPs and getting service shut off, which would be a continual churn of provisioning new physical servers, shipping them to locations, arranging for plausibly deniable billing, etc.
- nickpsecurity 10y agoI formulated the attack myself with your numbers seeming similar. It's one of reasons I didn't trust Tor. The success rate described in Snowden docs indicate NSA might be doing this experimentally. I don't think they're fully committed to point where they're running most nodes or anything. Being careful. The difficulties wouldn't be as much as it seems. They probably wouldn't even be shut down that often. Just a small number of high-bandwidth nodes from front companies would net them a lot of intel. They could also partner with Five Eyes and Euro agencies as they all seem to want to de-anonymize Tor users. Each could have fronts doing it with their own operational techniques to muddy the situation up. Again, probably already do in a small way. We haven't even discussed QUANTUM-ing the Tor servers. They really, really need memory-safe machines & implementations from CPU up if they're expecting to withstand high-strength attackers. Haven't looked at code or supported OS's in a while but I'm guessing default implementation doesn't fit that bill. ;)
- fweespeech 10y agoWouldn't running your own entry node be enough protection still (assuming you could guarantee it wouldn't be compromised)? As far as I'm aware, control of entry & exit is required for these sorts of attacks. Running the entry node with a consistent entry point and using it as a random walk crawler with a real browser would seem to be enough for personal use as long as you aren't a criminal worth active, serious investigation that is targeted to reveal you.
- tedunangst 10y agoThese attacks require observation of entry and exit.
- nickpsecurity 10y agoExactly. Taps further enables that. Malware even more. Just a metadata, recording system could fo plenty and not take much bandwidth to leak.
- nitrogen 10y agoHypothetically an intelligence agency could "persuade" hosting companies not to shut down their boxes. One could speculate that they might do so by staging an investigation of their own box, thus getting two boxes in place.
- 0xmohit 10y ago> I didn't realize just how fragile TOR is. . . It's JavaScript that causes it (you could choose to disable it [0]). The FAQ [1] warns of it: But there's a third issue: websites can easily determine whether you have allowed JavaScript for them, and if you disable JavaScript by default but then allow a few websites to run scripts (the way most people use NoScript), then your choice of whitelisted websites acts as a sort of cookie that makes you recognizable (and distinguishable), thus harming your anonymity. ... Until we get there, feel free to leave JavaScript on or off depending on your security, anonymity, and usability priorities. [0] https://www.torproject.org/docs/faq#DisableJS https://www.torproject.org/docs/faq#DisableJS [1] https://www.torproject.org/docs/faq#TBBJavaScriptEnabled https://www.torproject.org/docs/faq#TBBJavaScriptEnabled
- deleted 10y ago[deleted]
- onecooldev24 10y agoNot only javascript, you can have a http server that can send timed responses/packets and that would still work. If network traffic is being monitored at the modified server and ISP.
- mikeash 10y agoThat was exactly my reaction upon seeing the description of the problem. Seems like the title of the article should really be, "Tor kind of sucks at anonymizing users." If all it takes is 25 requests sent in quick succession, then surely half the web pages out there share this same problem just from loading various resources.
- rohit89 10y agoAs I understand it, this is a fundamental problem for any low latency network. You could fix the problem by introducing delays but that would break the low latency requirement.
- mikeash 10y agoMakes sense. I wonder if that could be made a tuneable parameter, so users could choose what sort of tradeoff they preferred. That might impose unacceptable storage costs on the router nodes, at the least.
- SEJeff 10y agoTor was sponsored by the USG to allow intelligence informants to not be uncovered. That is the "very specific use" it was originally envisioned for. See: http://cryptome.org/0003/tor-spy.htm http://cryptome.org/0003/tor-spy.htm
- marcosdumay 10y agoAnonymity is fragile. One can only ever break it, never fix.