4 ms·
>Modern anonymity breaks generally work by getting code to run on your local system Would you have any reference to specifics on this? Fine if not ofc, just ge
by ZoF 10y ago
>Modern anonymity breaks generally work by getting code to run on your local system
Would you have any reference to specifics on this? Fine if not ofc, just genuinely curious.(and agree that you're right)
Yes though, I would not recommend using a local machine to browse/etc
E.g. contrived:
Local->VPN->ssh/vnc/etc to a temp box->tor->internet
In this scenario, if the box is found and compromised before it's wiped, the anonymity of the VPN is important.
Regarding using a sim, they can only get rough location from tower usage/signal strength(I wasn't talking about using a burner phone, just the sim+a dongle(careful buying these)). Agreed this can get more granular quite quick, depending on area between neighbors it could be specific enough right away.
Like I said, last resort, shouldn't happen. I should have stated destroy sim after use, don't get lazy and reuse.
>Of course this level of paranoia doesn't really apply to your average web browser.
Agreed heh, hope we have more general awareness/prevention of commercial surveillance as well.
- TheSpiceIsLife 10y agoSince we're in the mood for unsolited amateur advice on how to communicate with regard to criminal acts... I generally try to leave organised crime to organised crime syndicates. And governments, of course. If you have to do any anonymous communication, with people you can't authenticate the identity of, over the internet, you're doing crime wrong, should assume the other party is a government plant / agent / honeypot, and should quit while you're ahead. Preferably before you start.
- alcari 10y ago> >Modern anonymity breaks generally work by getting code to run on your local system > Would you have any reference to specifics on this? FBI using a Firefox js bug to unmask tor users a couple years ago: http://arstechnica.com/security/2013/08/attackers-wield-firefox-exploit-to-uncloak-anonymous-tor-users/ http://arstechnica.com/security/2013/08/attackers-wield-fire... http://arstechnica.com/tech-policy/2013/09/fbi-admits-what-we-all-suspected-it-compromised-freedom-hostings-tor-servers/ http://arstechnica.com/tech-policy/2013/09/fbi-admits-what-w...
- mindslight 10y agoThis very case. From the first link of the article: > According to the Playpen warrant, when a visitor logged in to the site with a username and password, the NIT would be secretly installed on the visitor’s personal computer. The NIT would then send the government identifying information about the user’s computer, most importantly the computer’s true IP address from inside the user’s machine. The way this is worded, it could either be a sandbox exploit or just javascript taking advantage of eg defects in webrtc. But either way is local code execution. I would be interested in any examples where this method wasn't used to track down TOR users. I know that lately there was some bomb threat at a university through TOR, and the university investigated the single user with outgoing TOR traffic at that time. But that feels like a rare exception. I'm sure global passive adversary packet correlation attacks are being done by NSA et al, but domestic law enforcement isn't likely to see the proceeds of those. And if they were given a lead from them, the details would be parallel constructed anyway.
- ZoF 10y agoThat's what I was actually asking about, specifics about this case. I was aware of the previous JS vulns. Turns out this one was actually a .swf from an abandoned metasploit project.