6 ms·
First: it seems like the author has come up with a number of useful custom modifications to the Tor daemon to mitigate common attacks against onion operators. W
by noident 7y ago
First: it seems like the author has come up with a number of useful custom modifications to the Tor daemon to mitigate common attacks against onion operators. Why not work with the Tor Project to upstream some of the more useful ones, as well as the additional debugging information? Reading past Hacker Factor posts, is it just me, or is there a tone of slight disdain towards the Tor project?
Second:
>However, there's a second attack. The attacker can run one or more hostile guard nodes. If he can knock me off enough guards, my tor daemon will eventually choose one of his guards. Then he can identify my actual network address and directly attack my server. (This happened to me once.)
A guard node is going to get a lot of traffic from both onion services and normal Tor users. How can an evil guard node tell which IP belongs to the author's server?
Overall, this is startling to read. History suggests that it is only a matter of time before an onion service gets unmasked by the latest attack on the Tor network.
- Operyl 7y agoIf you read his various articles, and even in this article, he mentions that the Tor team is resistant to a lot of his proposed changes.
- noident 7y agoI have read the articles, but have not found an explanation or specific examples. It's not as if Tor doesn't care about onion services; they just spent 4 years designing and implementing the v3 onion service protocol.
- SolarNet 7y agoIt's pretty obvious when one gets stonewalled for political reasons when attempting to contribute to a project. He doesn't need to provide specific examples or explanations, doing so just makes the issue worse. Often these issues involve specific people and specific intuitions that will be hard to interpret without lots of context. It will put the problem people on the defensive and likely cause some sort of outrage or personal attacks, or other unwanted drama. Being polite yet firm on his own page is the best that can really be done in these situations. It allows the technical problem to be magnified while not focusing on drama.
- onlydeadheroes 7y agoPeople like that have no place in software or any form of engineering.
- onlydeadheroes 7y agoI consider Tor to be completely compromised. Consider this: 1) Political entryism by ideologues. These people stand against merit, and these are the same people who every few weeks post a lead-balloon of a thread against it in this very forum and others. 2) Recent purge of non-aligned team members on trumped up bullshit that only offends the now-dominant political ideas 3) Large, long redesign with obvious flaws 4) Unwillingness to address the reported flaws We are not talking about ICQ here, we are talking about Tor. If the Tor team is not concerned about this, then what are they concerned about? What else are they even doing? Why is it that in this age of total surveillance, when even Torvalds had to face the wall while they purged his team, nobody in power is bothered by Tor? Ain't that the fucking shit?
- dang 7y agoPlease don't post the same comment repeatedly to HN. That lowers the signal/noise ratio. If you want to refer to something you posted elsewhere, please use a link. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- mirimir 7y agoLots of onion services have been deanonymized. The "relay early" bug that CMU researchers exploited deanonymized perhaps hundreds of sites. And, both directly and indirectly via malware served by compromised sites, thousands of users. There's been much discussion since mid 2019 on the tor-dev list about DoS defense measures.[0] 0) https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-dev https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-de...
- onlydeadheroes 7y agoI consider Tor to be completely compromised. Consider this: 1) Political entryism by ideologues. These people stand against merit, and these are the same people who every few weeks post a lead-balloon of a thread against it in this very forum and others. 2) Recent purge of non-aligned team members on trumped up bullshit that only offends the now-dominant political ideas 3) Large, long redesign with obvious flaws 4) Unwillingness to address the reported flaws We are not talking about ICQ here, we are talking about Tor. If the Tor team is not concerned about this, then what are they concerned about? What else are they even doing? Why is it that in this age of total surveillance, when even Torvalds had to face the wall while they purged his team, nobody in power is bothered by Tor? Ain't that the fucking shit?
- mirimir 7y agoI share your concerns. But I haven't given up on it entirely. I mean, what else do we have? VPNs, sure. And maybe I2P. But it'd be very sad if Tor were totally compromised.
- onlydeadheroes 7y agoWe have our skills, and the ability to implement anything that we can imagine (with the necessary detail). They can't take that away.
- mirimir 7y agoSure. However, I2P is the only alternative that's been implemented at any scale, to my knowledge. Papers have been published, yes. But I'm not aware of any other anonymity networks that have even gone public. Why that is, I'm not sure. Maybe it's just network effect.
- onlydeadheroes 7y agoI consider Tor to be completely compromised. Consider this: 1) Political entryism by ideologues. These people stand against merit, and these are the same people who every few weeks post a lead-balloon of a thread against it in this very forum and others. 2) Recent purge of non-aligned team members on trumped up bullshit that only offends the now-dominant political ideas 3) Large, long redesign with obvious flaws 4) Unwillingness to address the reported flaws We are not talking about ICQ here, we are talking about Tor. If the Tor team is not concerned about this, then what are they concerned about? What else are they even doing? Why is it that in this age of total surveillance, when even Torvalds had to face the wall while they purged his team, nobody in power is bothered by Tor? Ain't that the fucking shit?
- Iv 7y agoOnion services are incapable of resisting a determined government-scale attacker. Just filter Tor traffic to random groups of users for like 10 seconds, find one such groups that prevents the target onion service from being routed. Bissect until you locate a precise node. IMO, Tor is to be used to escape censorship as a reader or host services anonymously in not tech-savvy governments (which are becoming increasingly rare). In the end, Tor only buys 10 to 20 years of freedom until governments figure out what to outlaw and filter. Censorship is a political problem, technical solutions provide a temporary hotfix, but the political problem has to be solved at one point.
- Ajedi32 7y ago> Just filter Tor traffic to random groups of users for like 10 seconds, find one such groups that prevents the target onion service from being routed. Bissect until you locate a precise node. That only works if you have the ability to filter out Tor traffic in the first place. (In which case, why not just preemptively block all Tor traffic in your country? Problem solved.) But Tor has systems in place designed specifically to prevent that sort of blocking by disguising Tor traffic as other, more common traffic types (like HTTP). There's also no guarantee that the Tor service in question is running on a host that's under your government's control. Cloud hosting is pretty common these days.
- Iv 7y agoYes, you can ban Tor altogether and be done with the whole thing. It is doable and there is no technical workaround for it. The scenario I am proposing is actually worse: you use the feeling of anonymity Tor proposes to uncover opponents. Yes, my tactic proposes you have a backdoor into all of ISP's infrastructure. I don't see that as a crazy requirement for most countries, even democracies. Disguising Tor traffic does not work well, and China has deployed several years ago already a tech that recognizes weird streams. Yes, you could be cloud hosting from outside the country. In the case of China though, that's likely to not work as most encrypted traffic crossing the border gets dropped (I guess unless it is HTTPS from a whitelisted source )