11 ms·
Tor 0day: Finding IP Addresses
- smegcicle 6y agotheory: silkroad dpr, as sloppy as his opsec was, was parallel construction
- p1necone 6y agoThis is absolutely plausible
- ltbarcly3 6y agoI think the known construction only required access to his public writings posted to silkroad, google, and patience. He posted uncommon unique phrases to both the silkroad as well as public websites using accounts linked to his real identity. If anything I think it shows quite a bit of incompetence that it took so long to figure out his real identity.
- bawolff 6y agoHis opsec was so poor, even if parallel construction was a possibility, im not sure why they would bother.
- stef25 6y agoNot so sure. Don't remember the exact details but it involved a post on the shroomery website and another one on Stack Overflow and he was using the same handle on various sites. It seemed much easier to unravel than exploiting the Tor network, it was almost surprising it took them that long.
- soulofmischief 6y agoDPR advertised for / discussed Silk Road using public accounts with email associations and usernames which led to his public persona. It was just bad opsec.
- 0xy 6y agoThat's the public explanation. It doesn't preclude parallel construction nor does it mean that's how they caught him.
- soulofmischief 6y agoWhy would you need to create parallel construction when the process of finding out Ulbricht's identity was painstakingly simple after basic utilizing basic OSINT? He posted stupid things in very public and monitored places and it only took a little research in the right places to put the pieces together. The economics of the parallel construction theory are simply untenable. Anyone can search for keywords on Shroomery and other forums. It's grunt work and loads easier than actual hacking.
- 0xy 6y agoIf it's "painstakingly simple", why did it take 2.5 years for them to find him?
- soulofmischief 6y agoOSINT is a simple process, it just takes time. In hindsight the red flags were obvious but you don't just immediately know where to look when investigating or what to look for. Your argument doesn't hold water because if parallel construction is so much easier then why did it take them 2.5 years?
- 0xy 6y agoI don't think it was easy to find him at all. Parallel construction is also not easy, they have to figure out how to unmask the server through whatever 0day they choose, then they have to issue NSL or, more likely, get diplomatic assistance to clone the server's hard drives. Do you know how long it takes to get another country to cooperate with an investigation, even if you're buddy-buddy with the country?
- lilboiluvr69 6y agoInteresting article, but I don't see why it's titled '0-day' when he references a research paper from 2012. "Although these are old, they are classified as zero-day attacks because there is no solution." They are?
- ltbarcly3 6y agoSo back a long time ago, we counted days from the time an exploit was 'known'. Now people seem to use it for the time since a patch has been released? I don't know, but every time I ask I get downvoted.
- judge2020 6y agoA 0-day generally means either one person, a single organization, or a small group of people, know about the exploit in question. As soon as an exploit is widely known or published, it's not a 0-day since anyone can find it, even if the exploit is for abandoned software that'll never receive a security fix.
- ltbarcly3 6y agoYep, that's what I said I think (by 'known' I meant publicly). Once it's widely known, it's a 0 day for 24 hours, then it's not anymore. That's what we used to mean by 0-day anyway. Other people will tell you that it's a 0-day until there is a patch against it. I think different people use this this phrase so divergently that using it isn't a useful way to communicate anymore.
- neltnerb 6y agoWhat is it called after there is a patch against it? Does it just stay at like a 27-day if it takes 27 days to patch? I feel like in common parlance calling something a 0-day would imply that it is something the manufacturer didn't expect and has no solution for which is a big problem. I guess whatever communicates information best. I kind of feel like we just use 0-day to mean big problems, everything else is just a bug that has some age, and then fixed stuff doesn't get remembered. Right? That seems fairly useful, at least in communicating to the general tech media.
- Mizza 6y agoThis has been well known for a long time. It's even vaguely referenced in the Snowden leaks. I wish Tor never became an activist project. There are a lot of groups with nice sounding names like 'Human Rights Watch' - that seem less nice once you find out who funds them and some of the things they support - that started offering loads of money starting around 2010 to groups which produced this kind of technology. Tor took the money and transformed from an academic project into an activist one in both terms of both staff and marketing, and I think a lot of people are now using technology they have been told will keep them safe but is actually only a few steps away from bunkum.
- tjbiddle 6y agoDo you have a better alternative to Tor? All of my understanding and reading has lead to it being a great solution for anonymous web browsing.
- Mizza 6y agoI mean, I still like Tor. It depends entirely about what your threat models and goals are. I2P never gets any attention compared to Tor, but it keeps chugging along. In many ways, it's a lot better. Their most recent release was on 2020-08-24. https://geti2p.net/en/ https://geti2p.net/en/
- pmontra 6y agoI can't assess the merits of i2p but in the comment section of the post I found this > i2p is substantially worse. > It is worse BECAUSE every user is also a relay. I can sit at watch the connection, allowing me to map out each user's address. If your server is up long enough, you should see everyone eventually.
- Mizza 6y agoReally, it's just a different thing. It is an entirely P2P network, so yes, that's what you get. But, anybody can run a Tor node too, as the article points out. (Practically speaking, I2P better for torrents.)
- stealthbot 6y agohttps://fingerprintjs.com/demo https://fingerprintjs.com/demo shows that Tor can still be fingerprinted and uniquely identified across IP addresses. Your Javascript (navigator) user-agent and timezone are some of the dead giveaways as they leak the true values.
- c-c-c-c-c 6y agoAnd javascript is disabled, the rest spoofed
- derefr 6y agoTor will hide/obscure your true identity (i.e. the one that gets fingerprinted when you use a non-Tor-proxied browser) behind a separate, distinct "Tor identity"; but Tor makes no claim to be fit-for-purpose for obscuring/garbling the persistent aspects of said "Tor identity." (The Tor Project has this as a long-term goal, but they're nowhere near there yet.) There's a "new Tor circuit for this site" button in the Tor Browser, but it's for circumventing dumb WAFs who've blacklisted a Tor exit node's IP. It's not for OPSEC. > Javascript Nobody who cares about doing anything secretive is using Tor with Javascript enabled. (Fun fact: most of the "dark web" stuff operates using early-2000s-era phpBB forum tech, which works perfectly fine without JS.)
- aj3 6y agoTOR brosser != TOR
- stealthbot 6y agoyes the network is different than the browser, but the point is that IP based anonymity is already obsolete
- aaron695 6y ago5 minute exercise to try - Download Tor https://www.torproject.org/download/ https://www.torproject.org/download/ Go to your site, and see if you think it works - https://fingerprintjs.com/demo https://fingerprintjs.com/demo (Also notice how Tor changes the screen size everytime you open it)
- Santosh83 6y agoIs strong anonymity even theoretically possible on IP based networks?
- deleted 6y ago[deleted]
- pfundstein 6y agoOf course, and Tor is an excellent example of an accessible turnkey solution to the problem. But you should never rely solely Tor or any single measure. 50% of anonymity is your own opsec.
- bawolff 6y agoYes (under certain, decently reasonable assumptions), but all solutions have very significant tradeoffs. High latency mixnets (e.g. https://en.m.wikipedia.org/wiki/Anonymous_remailer https://en.m.wikipedia.org/wiki/Anonymous_remailer ) have the drawback that latency means it cannot work with interactive protocols. Dining cryptographer networks have much lower latency but scale very poorly. (https://en.m.wikipedia.org/wiki/Dining_cryptographers_problem https://en.m.wikipedia.org/wiki/Dining_cryptographers_proble... ) Tor (a low latency mixnet) trades a weaker threat model for low latency and scalability. So basically you can pick two of scalability, low-latency and resistence to global passive adversaries.
- jandrese 6y agoIf your adversary has a god level view of the network then it's really hard to achieve strong anonymity. The article mentioned large network operators that can monitor a significant fraction of all traffic in the country. If you were the Chinese Government you would have an even better view into the network. Especially if you send a large file somewhere which makes it easy to correlate the TCP session. For real anonymity you need something that scrambles and delays your traffic to make it harder to track. Something that breaks big transfers up into a bunch of small transfers, sends them via different routes, and generally makes your experience miserably slow.
- londons_explore 6y ago
- peacemakr_io 6y agoThis is not news.
- sneak 6y agoI spoke to Adam Levine on the same topic in the summer of 2013, right after Snowden told us (for the nth time; credit also of course to Mark Klein et al) about the large-scale passive monitoring of network traffic. This is a known issue, which, like GMail being accessible to the US government without a warrant, one that a lot of people simply need to block out to go on with their daily lives. It's difficult to emotionally integrate the fact that you can't travel anywhere while holding a cellphone without the military knowing exactly where you are, and exactly where you've been, for the entire time you've had a cellphone. I encourage you to watch the interview, where I describe this precise attack: https://youtu.be/9k4GP3Evh9c?t=2018 https://youtu.be/9k4GP3Evh9c?t=2018
- adam0c 6y agohow is this 0-day... old news of whats been public for a long time sounds more like a n00b on tor
- kodablah 6y ago> The last hop is the exit node. It can see all of your decrypted network traffic. Didn't see it clarified in the article, but IIRC for onion services like OP's the traffic doesn't go out of traditional internet exit nodes and traffic is end-to-end encrypted. Not only can the last relay before the onion service not see all of your decrypted network traffic, I don't believe they can tell they are even the last relay. Traffic analysis has been a known issue as long as Tor has existed. What I'd like to see are solutions. Can Tor be used with some kind of fixed-rate noise type of protocol (I toyed w/ a rudimentary fixed-rate traffic algo once[0])? Or is it too broken and do we need another P2P (fixed-transfer-rate) protocol? i2p, tribbler, etc haven't gained mass adoption. 0 - https://github.com/cretz/deaf9/blob/master/mask/context_read_write_closer.go https://github.com/cretz/deaf9/blob/master/mask/context_read...
- abstractbarista 6y agoThis is a very good point. There is a huge difference between a Tor client chatting with a Tor hidden service, and a Tor client chatting with a clearnet service. Furthermore, it's not as simple as 'see all of your decrypted network traffic'. Perhaps the Tor client is talking with the clearnet server over TLS 1.3. This presents much more difficulty for the malicious exit node.
- ui9ohNe9 6y agoSo, what I understand is that hidden services can easily be deanonymized. People using tor only as a proxy are safe, provided they do not download big files (who want to do that anyway, given how slow it is?). As a Tor user, I'm quite glad to read that, actually. Tor hidden services are the reason why Tor has this ugly and well-deserved reputation of being a tool for everything illegal and morally unacceptable. As someone who just want strong privacy, I see hidden services as problematic neighbors and I would be glad to see them go.
- zdkl 6y agoWell sample size of 1 and all that but I can attest to at least my legit use case. I'm hosting some friends-and-family small services from home and front them with a couple Hidden Services. That gives me some measure of mutual privacy from my users as well as strict access control via auth being baked in the transport protocol. The alternative would have been providing a dynamic DNS type URL, mucking around with LetsEncrypt and the DNS provider periodically and then implementing all access control in the servers. I'm lazy, Tor works for this use case and I'm lucky my users understand the 3 steps to configure their Tor browser so I'm sold on the usefulness of this mechanism!
- ui9ohNe9 6y agoOh yes, indeed, I'm not implying that all hidden services are objectionable, but that those who are are many and a major reputation problem - to the point where we would be better off without hidden services. I love how you used it for relatives group privacy, though, that sounds cool.
- t0astbread 6y agoJust thinking: From a client's standpoint could the "large download" traffic correlation be avoided if the client split the large download into multiple HTTP requests (assuming the server supports that) that are about as large as a regular webpage request with random delays in between so that it looks like normal web noise? Of course, it'd take wayyy longer to download but wouldn't this make the traffic indistinguishable from page requests?
- optimalsolver 6y agoThe fundamental flaw in TOR (and, by extension, all other anonymity clients) is that its traffic patterns make you stand out from everybody else. Just using it makes you automatically interesting to state actors.
- dannyw 6y agoThis is not a theoretical assumption: leaked XKEYSCORE “selectors” target anyone (1) searching for Tor on search engines or (2) using Tor. Code: https://daserste.ndr.de/panorama/xkeyscorerules100.txt https://daserste.ndr.de/panorama/xkeyscorerules100.txt
- t0astbread 6y agoTor relays are publicly known so you don't need traffic pattern analysis to know if someone is using Tor. Or were you referring to something else?
- mr__y 6y agoYou could be using a vpn or a proxy making it harder to be matched only based on IP address you connect to. Traffic pattern analysis would still work.
- a5withtrrs 6y agoWho are the providers referred to in this as 'God'? Is that providers like akamai/cloudflare/L3 that have big pipes/route lots of traffic? Edit: I'm assuming Tier 1 network providers for AT&T/CenturyLink (aka L3) etc as per this list https://en.wikipedia.org/wiki/Tier_1_network https://en.wikipedia.org/wiki/Tier_1_network
- GuB-42 6y agoIt looks like they are specialized monitoring companies. They aggregate traffic data from many ISPs and give them back a global picture. It is to mitigate DDOS attacks at the network level.
- ingen0s 6y agoExcellent read, if you are going to be using Tor and want to stay off the grid, ie. journalism, keeping sources hidden - you need a laptop (netbook that has no personal info, pre-loaded with your own bridge node as first hop) and a wifi stick - only connect from remote wifi sites and don't create any patterns in visiting your physical locations nor sit in front of security cameras. Swapping the wifi stick between each use will make you virtually invisible.
- greenbush 6y agoWhy swap wifi sticks? Why not just change the MAC address via the OS between each use?
- aaron695 6y ago> I read off the address: "152 dot" and they repeated back "152 dot". "19 dot" "19 dot" and then they told me the rest of the network address. This line seems like the big deal. Doesn't matter if it's from 2012 or not a 0 day or about previous posts from this author, how is this possible in 2020 by anyone, but even a corporation? Is it this line? - "They just didn't know that this specific address was mine." Tor should have shutdown Onions if this line is true as it seems to read.
- deleted 6y ago[deleted]
- hyproxia 6y agoThis article is obviously written by someone that doesn't know what they're talking about. >0day This is not a "0day". >As it turns out, this is an open secret among the internet service community: You are not anonymous on Tor. Careful there with the big assertions. >The last hop is the exit node. It can see all of your decrypted network traffic. I thought we were talking about onion services here, why the subtle context switch? Does the author even know that onion services don't use exit nodes at all? >(Don't assume that HTTPS is keeping you safe.) Why? >One claimed to see over 70% of all internet traffic worldwide. Another claimed over 50% The key word here is "claimed". >If you're a low volume hidden service, like a test box only used by yourself, then you're safe enough. But if you're a big drug market, counterfeiter, child porn operator, or involved in any other kind of potentially illegal distribution, then you may end up having a bad day. I like how the author assumes that these are the only two uses of Tor. >you simply need a list of known onion services Good luck getting that with v3 addresses (unless the author of the service has poor OPSEC). Not to mention that Tor has provided many fixes for the DDoS issues, but the author obviously didn't mention them.
- worldofmatthew 6y agoThe author is salty that Tor would not fix a "bug" of being able to tell a publuclly listed Tor Node is a Tor Node.
- matheusmoreira 6y ago> Does the author even know that onion services don't use exit nodes at all? Does this mean that traffic correlation and confirmation attacks cannot be performed on users of hidden services?
- tga_d 6y agoNo, those attacks still work. Traffic correlation and timing attacks don't actually interact with Tor at all; while a Tor exit relay is a good spot to be in for one (if you're targeting streams that use it), all you need is two vantage points that uniquely identify the network route as a whole. So e.g., the client and server's respective ISPs, or in the case of an onion service, both guard relays. GP is correct though, onion service connections are e2e encrypted, there's no vantage point on the network that sees any plaintext or TLS client traffic. The author of this blog clearly has no idea what they're talking about.
- auganov 6y agoAccording to this [0] there are only about 1.5k exit nodes and over 6k relays total. It's a pretty small network. I'm not an expert on tor internals but it sounds to me like a sufficiently dedicated player could easily control a big chunk of this. Don't even need crazy money. I understand that they have mechanisms preventing obviously fake new servers from flooding the network. But still at these numbers it doesn't seem that tough to play the long game. [0] https://metrics.torproject.org/networksize.html https://metrics.torproject.org/networksize.html
- worldofmatthew 6y agoAre you planning to add any relays?
- sarakayakomzin 6y ago> Are you planning to add any relays? does not adding relays invalidate the criticism somehow? do you want them to add 20k relays in order for their justified opinion to...still be an opinion?
- tga_d 6y agoYeah, it happens: https://blog.torproject.org/bad-exit-relays-may-june-2020 https://blog.torproject.org/bad-exit-relays-may-june-2020 One reason why it's not devastating to the network as a whole is that the process for getting your relays to make up such a large fraction of the network is social. If you run a ton of capacity, especially if added all at once, people are going to notice, and reach out to find out who you are (and if they can't, expect to get removed). This means that while yes, you can do this (and as above, people have), once it's detected, all of your resources are dropped at once, and you have to start a pretty expensive and time-consuming process over again. It's also the case that adversaries generally don't collude, so e.g., the above attack was for cryptocurrency theft, and those adversaries likely aren't working with the FBI or China to deanonymize circuits. This means you only have to worry about a few of these happening at a time, which makes it easier to detect (pull on one thread, and the rest start to unravel). That said, just based on the blog post above, it's something that TPO seems to be thinking about new ways to address, and sibyl detection has a long history of research in the academic community as well that has plenty of space left to explore. Something like Salmon[0] is in the process of being implemented by TPO for bridge distribution[1], and the constraints for this reputation problem are far less onerous than that setting. [0] https://content.sciendo.com/view/journals/popets/2016/4/article-p4.xml?language=en https://content.sciendo.com/view/journals/popets/2016/4/arti... [1] https://gitlab.torproject.org/tpo/anti-censorship/bridgedb/-/issues/31873 https://gitlab.torproject.org/tpo/anti-censorship/bridgedb/-...
- DINKDINK 6y agoI don't think anyone in the net-privacy realm would be surprised by anything written in this blog. A better title would have been: "On overview of Traffic Analysis intelligence leaks on Tor". All tor does is provide onion addressing and strong authentication with increased the observation costs for passive observers. Anything beyond that is a user's myopic extension of crypto-is-a-panacea. Cryptography can provide protections for observability, it cannot provide protection against identifiability. Mixnets like remailers or modern traffic mixing like Nym attempt to address identifiability. >I read off the address: "152 dot" and they repeated back "152 dot". "19 dot" "19 dot" and then they told me the rest of the network address. (I was stunned.) Tor is supposed to be anonymous. It's hard to tell the author's genuine understanding of Tor is versus what is hyperbolic. How surprising is the quoted feat? IPv4 is roughly 2^32 in size. There's roughly 2.4 million tor users [1], so an observer would need ~22.2 bits to exactly identify them. The author gives at-least (assuming uniformly random IP address distribution, which isn't the case) ~16 bits of entropy (log(255)/log(2)*2). Which leaves their counter party a 1/32 eg 2^(22.2-16) chance of guessing their IP. Unless your ip space is chock full of tor users, it's not surprising an exit node was able to autocomplete the rest of your ip address. PS If we know the country of their IP, we need at least ~15.3 bits and at most ~19.7 bits The trick is akin to living on a street with a unique name and a retailer auto completing your address and customer details because you've ordered from them before and you gave them your street name. If I was a Global Passive Adversary, I would be probing and rerouting traffic to see how systems responded: https://www.ndss-symposium.org/wp-content/uploads/2017/09/NDSS2015_Mind_Your_Blocks_Stealthiness_Malicious_BGP_Attacks.pdf https://www.ndss-symposium.org/wp-content/uploads/2017/09/ND... https://www.muckrock.com/foi/united-states-of-america-10/request-for-information-on-bgp-hijacking-attacks-in-2013-federal-bureau-of-investigation-77293/ https://www.muckrock.com/foi/united-states-of-america-10/req... [1] https://metrics.torproject.org/userstats-relay-table.html https://metrics.torproject.org/userstats-relay-table.html
- hridoyjoy94 6y agouse whois. Good online tool to find ip addresses