8 ms·
Anyone able to comment on the state of Tor security and suggest an up to date OpSec guide to using Tor?
by newbuser 9y ago
Anyone able to comment on the state of Tor security and suggest an up to date OpSec guide to using Tor?
- 3pt14159 9y agoThis opinion is controversial, and I’m not going to go into all of the reasons why, but unless you REALY know what you’re doing Tor can’t be trusted. I’d wager only 1% of people on Hacker News would be capable of using a Tor setup for more than a day without getting owned. You’re better off buying a burner iPod or iPad, stick to public wifi spots, and factory reset it once a week. Even then, watch what you type since vocabulary is fingerprintable. It’s very hard to stay dark these days.
- jernejzen 9y agoPretty bold claim about !%. Do you by any chance have any refs or links at hand explaining the topic more into depth. There are quite a lot on Tor www but covering more common use.
- 3pt14159 9y agoIf you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec journalists, blackhats, child pornographers. For what? What problem are you solving that warrants this heat? Just use a burner iPad and wipe it frequently. If you're truly paranoid light up a DigitalOcean droplet with a pre-paid credit card and a false name and install OpenVPN on it make an image and cycle your IP. But short of being both a data scientist & cybersec expert (or an actual state actor with training from both) you aren't going to stay black from the NSA and to pretend otherwise is stupid.
- emodendroket 9y agoTo bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?
- dragonwriter 9y ago> To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it? Maybe; if US intelligence's high-value targets can be targetted by means that Tor does not protect (compromising endpoints, emissions-based techniques, etc.), and Tor provides US intelligence agents a way to exfiltrate information in a way immune to any but more involved, specifically targetted techniques, it might still be valuable to both have Tor exist and have it used by enough people not on US intelligence payroll that it's mere use didn't finger people as agents. You have to remember that US intelligence does more than monitor people's communications, it also needs communication channels that are accessible, unmonitored, and deniable for its own agents.
- emodendroket 9y agoRight, that's the theory, and certainly they do need users on Tor to create noise for their own agents. But considering their nonstop drive to weaken other forms of encryption and insert backdoors, I'd be a little bit cautious about taking that at face value if I wanted to start the next Silk Road.
- nickpsecurity 9y ago" if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?" On top of dragonwriter's answer, I'll point out that "U.S. intelligence" doesn't exist as one entity in the way you ask that question. There are a number of groups that cooperate in some ways and compete or just diverge in others. The NSA and FBI want Tor cracked the most to find their targets. Whereas, the State Dept and/or the CIA that back Tor's funding want to protect both dissidents and assets overseas from state-level agencies monitoring communications. They need it to be unbreakable for some set of nation-state attackers. Now, that doesn't mean that it needs to be unbreakable for the NSA, etc. The original guidance I read on Tor even warned that global adversaries would probably break it. The Many Eyes collaborations have visibility into a lot of the network. They're probably also honeypotting it with high-bandwidth links. It's also written in a tricky protocol in unsafe language on OS's done similarly running untrustworthy apps. They'll probably always have attacks on it for at least worthwhile targets even if State and CIA don't want that. It will still be valuable in many threat models, including NSA if combined with other methods. Especially if about delaying rather than permanently denying them info.
- asquabventured 9y ago[Citation needed]
- danieltillett 9y agoDoes anyone know what is state of the art in vocab fingerprinting?
- kasey_junk 9y agoIs that actually a controversy? I feel like everyone I talk to with any credible claim to security expertise recommends against it. So much so that I’d like to see an expert recommend it.
- jerheinze 9y ago> So much so that I’d like to see an expert recommend it. Bruce Schneier?
- emodendroket 9y agoYeah, I've seen people go apoplectic at the idea.
- 3pt14159 9y agoThere is a wide and growing gulf between what cyber experts know and what the tech savvy public knows. The world is changing so fast right now you almost need to invent your adversary's tools to be free from them. If you're talking with large numbers of people that don't trust Tor then it speaks more to the quality of your friends than it does about the prevalence of this opinion.
- emodendroket 9y agoEven if you use it perfectly, between fingerprinting techniques which could be used to cross-reference your logged-in "normal" use and some of the communications Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched), I would be sure someone couldn't pierce the veil of anonymity.
- jerheinze 9y ago> Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched) That's an unfounded accusation. Micah Lee wrote a very concise refutation of his smear campaign.[1] > I would be sure someone couldn't pierce the veil of anonymity. That still doesn't contradict the fact that using Tor is better than not. [1] : https://micahflee.com/2014/12/fact-checking-pandos-smears-against-tor/ https://micahflee.com/2014/12/fact-checking-pandos-smears-ag...
- emodendroket 9y agoThat article is four years old. This claim I heard in an interview from him for his book that just came out (he got a bunch of e-mails through FOIA requests, as I understand it), and isn't addressed by this "very concise refutation." And some of the claims seem a little bit of a stretch (using the "Gate" suffix is a nod to Gamergate? Isn't it more plausible that this is the same reference to Watergate that's been applied to every political scandal since 1973?). And it seems like that article mostly agrees with all the factual claims it examines but disagrees with the interpretation or their level of significance, rather than exposing anything as a falsehood. > That still doesn't contradict the fact that using Tor is better than not. Is it a fact? If Tor achieves nothing for someone trying to hide from the government except announcing that you have something you want to hide (is that the case? I don't pretend to be certain, but it seems possible) then I'm not sure it's better.
- itdaniher 9y agoHe posted the FOIAd docs here: https://surveillancevalley.com/the-tor-files/master-list https://surveillancevalley.com/the-tor-files/master-list He and I discussed them a bit on Twitter: https://twitter.com/itdaniher/status/961307347950940161 https://twitter.com/itdaniher/status/961307347950940161 I was not impressed by his response. The "bunch of emails" seemed remarkably banal. I've written similar emails about sponsored open-source work myself. edit: email stack 1: https://www.documentcloud.org/documents/4367176-Tor-BBG-correspondence-Stack-1.html https://www.documentcloud.org/documents/4367176-Tor-BBG-corr... email stack 2: https://www.documentcloud.org/documents/4367193-Tor-BBG-correspondence-Stack-2.html https://www.documentcloud.org/documents/4367193-Tor-BBG-corr...
- jerheinze 9y ago> and suggest an up to date OpSec guide to using Tor? Use Disposable Whonix VMs in Qubes OS (available in the 4.0-rc4) for the best secure experience that you can get right now. For less security, an alternative would be to use Tails or Subgraph. You can also control how much attack surface you expose in your browser in the Security Settings in the Tor Button (Medium (now termed Safe) disables JS on HTTP websites, JIT optimization, and sets media files to click-to-play. High (now termed Safest) disables JS everywhere, and SVG...).[1] [1] : https://tb-manual.torproject.org/en-US/security-slider.html https://tb-manual.torproject.org/en-US/security-slider.html
- QasimK 9y agoIn what way are Disposable Whonix VMs in Qubes OS more secure than Tails? I understand that the VM won't have access to the real IP address, but isn't there a possibility of breaking through the VM (while with Tails the entire system is disposable)? Are there other ways that it is more secure?
- jerheinze 9y ago> In what way are Disposable Whonix VMs in Qubes OS more secure than Tails? To de-anonymize Tails one needs to exploit Tor Browser first, then get root access. For Disposable Whonix VMs in Qubes OS one would need the additional availability of a Xen exploit to break out of the VM in order to de-anonymize it.
- QasimK 9y agoThank you for the straightforward explanation.