29 ms·
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
- geek_at 5y agoThese days I mainly use tor for hidden services. It's hard to use it for normal surfing anyways
- arthurcolle 5y agoyeah captcha's are so user hostile
- judge2020 5y agohostile to some users, but most bots, so they're widely used.
- belorn 5y agoI use it for so many different purpose: 1) When I want to make sure a site doesn't get saved to my network/client profile on search engines and content sites. 2) When I need to verify that something is up/down compared to what I or a customer is seeing. 3) When I need to force IPv4 (tor is ipv4 only) 4) Hidden services. 5) Hotel/Airport wifi.
- dotBen 5y agoWhy don't you just use a VPN for this (self hosted or 3rd party like NordVPN)? Especially given the additional risk of tor users being attacked, which the author refers to in the opening paragraphs of the post.
- AlexAndScripts 5y agoNord VPN is incredibly bad for a multitude of reasons. Look for a reputable VPN, and ignore the shills.
- idiotsecant 5y agoWhy are they bad?
- tuco86 5y agoSleazy marketing promises makes me dismiss them outright.
- shakna 5y agoLast time they had a breach, they took 6 months to notify the public and did everything in their power to blame anyone else. [0] The breach was limited - but it doesn't inspire confidence. [0] https://www.techradar.com/news/whats-the-truth-about-the-nordvpn-breach-heres-what-we-now-know https://www.techradar.com/news/whats-the-truth-about-the-nor...
- windy_willow 5y agoI get your point here, but its been years since that happened and they kept clean since then as far as I know. That server didn't store any user data just as none of their servers do, I've also read their audits and no evidence of logs were ever found. Even with that breach, it was not directly their fault, but a data center that left a backdoor. Since then they cut ties with the and nothing similar happened again. What I'm trying to say is that no one is 100% safe from a breach as the tech world changes daily and new exploits are growing just as fast. Once company can stay breach free for a decade and then get one. All that such companies can do is work to constantly improve and keep such problems under control.
- shakna 5y agoNo one is immune to a breach. You're absolutely right. Which is why the response to the breach is what is so important. NordVPN left the backdoor open themselves - they left a remote admin console enabled. Then, they proceeded to hold their silence for _six months_, before informing their customers... And take no responsibility. They struggled to even admit they got their dates wrong. That kind of behaviour, and lack of transparency, is the problem. Not that a breach occurred.
- zelon88 5y agoStop and break that down... "Why don't you just send your browsing history to NordVPN instead of risking using a compromised exit node....."
- vbezhenar 5y agoExit node does not know your source IP and will only see your connections for 10 minutes. NordVPN knows your source IP and will see your entire connection history.
- belorn 5y agoFor the first usecase, the #1 problem in privacy security is that databases get leaked at some point in the future. Some VPN's has been caught logging way to much, and then either having to disclose it or have it leaked. Three hops with with no logs with my name and banking information, and only a gate node that has an ip address is fine enough for privacy sensitive visits to regular (legal) websites. For 2), Tor browser is a single executable that I can just start and run on any computer, even through a remote control if I want to very the network through a customers own computer. No credentials, no payments, no waiting. Don't know enough about nordvpn for 3). 4) Hidden services is tor only. 5) Nordvpn would work fine for that. Different security threat need different security measures. The biggest risk to my own security is not that someone mitm my tor connection because I do not use tor for services which I have an account with, and would never do banking on a tor connection. My bank can more or less find what my network is anyway by looking at my transaction and which of those is an ISP. Leaks from companies however seems so common that one get posted here on HN every month, and haveibeenpawned feel more relevant today than antivirus.
- wolverine876 5y ago> 5) Hotel/Airport wifi. Remember that Tor only routes TCP. It's not a substitute for a VPN in many circumstances.
- Analemma_ 5y agoTo be honest I just take it for granted that all exit relays are either run by Feds or at least compromised by Feds. If you use Tor for anything you wouldn't want Five Eyes to know about, you're an idiot.
- golergka 5y agoWhat would you use instead?
- Analemma_ 5y agoI don't really do anything worth hiding from state-level attackers, but if I did I wouldn't do it over the internet at all.
- gruez 5y agoso you'll do it in meatspace where there are witnesses and facial recognition/ALPR cameras everywhere?
- vinay_ys 5y agoThere's one kind of tech that's good enough to protect your privacy from corporations that want to profile your behavior or keep you safe from malicious hackers who want to steal your data by luring you into digital spider nets. Then there's another kind of tech (and tactics and practices) that could hope to keep you safe when you are targeted by state-level actors in both digital space and meat space. Tor barely belongs in the former category.
- munk-a 5y agoPurchase some hardware with cash and distribute it around the world to tunnel through. Then expose them as public proxy servers (or even Tor nodes) so that a fair amount normie traffic passes through them. If you seriously feel paranoid about being watched then you'll want to own the hardware you're actually passing through. And I assume that any large organizations that demand this level of invisibility (cartels etc...) have essentially done this - likely locating some of those servers behind armed guards that will protect the physical device. That said, I think it's unlikely that Tor has been majority compromised at this point, but as it fades from the minds of folks and becomes more and more niche the probability will escalate.
- motohagiography 5y agoTrying to figure out what makes MITM'd exit nodes valuable. Sure, as an attacker it's interesting, but cost vs. how interesting isn't clear. The law enforcement case for specific investigations makes some sense, general counter intelligence value of keeping track of which web sites are attracting people who take precautions, maybe there is a general list of suspected dissident minds states maintain?
- avidiax 5y agoPart 1 says that they use SSL-stripping attacks to replace cryptocurrency addresses with their own address, allowing them to capture e.g. transfers to a crypto mixer. https://nusenu.medium.com/how-malicious-tor-relays-are-exploiting-users-in-2020-part-i-1097575c0cac https://nusenu.medium.com/how-malicious-tor-relays-are-explo...
- jandrese 5y agoThe thing that confuses me about that is if you have not installed the malicious MITM's root cert in your browser isn't that going to fail? Or are these MITM's somehow signing stuff with well known root certs? That seems like it would be a much bigger story. Or are TOR users really accepting self-signed certs when passing around their bitcoin addresses? Maybe there are bitcoin clients that don't validate the chain when doing TLS? Given the sorry security posture of so many exchanges this is somewhat more plausible.
- bawolff 5y agoSsl stripping usually means replacing https links with http (when on http) and blocking TLS so users retry with http. Moral of the story, if you a are a site operator use HSTS. And if you're on tor, you should maybe consider configuring things so you only use tls.
- deleted 5y ago[deleted]
- 5y ago
- grouphugs 5y agothis project fucked over freenode so bad, would still not recommend joining that organization
- a2tech 5y agoAs a believer in the Tor mission—-how do I run a non-evil exit node?
- flatiron 5y agorunning an exit node is a really bad idea. someone is going to do something dumb on Tor and the local PD isn't going to know anything about Tor and will come knock on your door. i used to run a relay and even that became too much of a hassle. first my bank blocked me (they block all tor traffic even from relays) and then my companies IT did an audit and saw traffic "coming from tor" to them and politely asked me to stop using Tor. that was the last straw for me, and i took it down.
- scrose 5y agoI've had a similar experience just connecting to my school's Wifi network. Someone left a threatening message on the now dead 'anonymous' chat app(YikYak) using the campus Wifi. Campus PD checked the IP address, saw one of my devices now had that IP, and gave me a call. I spent 5 mins trying to understand what this app was that they were even talking about, and another 10 mins explaining how IP addresses work to them.
- SubiculumCode 5y agoBut why would you do that from you home IP and not rent a server somewhere?
- flatiron 5y agoMakes sense in hindsight. But I never thought I would have any issues running a relay. Also just got a raspberry pi v1 and was looking for a project.
- phoronixrly 5y agoAFAIK 1. Live in a country in which law enforcement follows the law and the law does not prohibit running tor, as noted in a response. 2. Hire a lawyer competent on cybercrime, intellectual property and freedom of speech. 3. Set up a non-profit or other legal entity with the explicit purpose of running tor exits/relays (stated in the articles of incorporation or similar founding documents, depending on the country and type of legal entity). Make sure its address is not your home address. 4. Purchase or rent the necessary hardware through the legal entity (don't ever do anything unrelated to the tor exits from this entity). Make sure you co-lo it in a datacenter, do not run any exits in your office and especially not in your home. Avoid having any hardware you rely on not being seized in close (physical -- same rack or logical -- e.g. same network) proximity. Explain to your host that you'll be running tor exits. Clearly label your systems as tor exits in any possible way you can manage, including physically on the cases/bezels. Run a web server on their public IPs with a page explaining that this is a tor exit node run by such and such legal entity, set WHOIS data with the same info if possible. Set up reverse DNS with hostnames that clearly state this is a tor exit node. 5. Be ready for trips to the PD in order to explain what tor is and why what you're doing is legal and that it's not you that sent that phishing e-mail, etc. It is a matter of when an illegal activity will be traced back to y̵o̵u̵r̵ the legal entity's exit and no amount of labelling will deter law enforcement from summoning you as a representative of the entity. Reasons being incompetence, desire/requirement to investigate thoroughly, or plainly using inconvenience as a way to discourage you from running the nodes (in the end, tor both creates more work for law enforcement and is a big obstacle to them so they'd rather not have to deal with it if possible). This is the gist of it. The details need to be discussed with a lawyer. And again all of this relies on the law enforcement and justice systems to follow the law and the law to not prohibit tor. Don't do this in a country in which there's risk of you being black-bagged or held legally responsible for running tor or not keeping traffic logs. Source: my poor understanding my country's and EU's laws. IANAL.
- 02020202 5y agowow, quarter of the entire tor network is compromised....shiiiiet. at least it seems forcing https solves the problem.
- ajcp 5y agoThe almost willful lack of tradecraft, scale of deployments, small time-frames, and "loudness" of action the highlighted entity displays, combined with the technical knowledge required to take part in this narrow space, suggests that someone is tolerance-checking the system rather than actually seeking to inhabit it. Or they really are just shitty and impatient Russians, I could go either way.
- notriddle 5y agoYou're suffering from the Toupée Fallacy. You assume that these people must be intentionally making themselves noticeable, because there's no way the average malicious Tor node operator could be this dumb. But there's no rule saying that these are average malicious exit node operators. They could just be particularly stupid ones. We don't know about the competent ones.
- ajcp 5y agoI'm not assuming this actor must be doing this intentionally *because* these are a lot of stupid things, nor that it is indictive of the average, malicious Tor node operator. I'm arguing the opposite. Not only did an actor commit a string of seemingly sloppy and unrelated "mistakes", where they had correctly executed that same things n times before for x amount of time, but they then brought their own existence to the attention of a technically empowered group to see how many of those seemingly unrelated and sloppy mistakes the system tolerates. I'm not sure how this is an example of the "toupée fallacy", as I'm just positing as ti why this toupée would look so intentionally bad; to figure out the tolerance for a bad toupée and discover what about it made the toupée "bad".
- makomk 5y agoThe attacks they want to carry out are inherently loud. They're attacking visits to well-known websites at scale in ways that require changing the response returned when visiting those websites in a way that's trivial to detect (the websites should immediately redirect to the SSL version but the attack has to remove that redirect in order to modify the contents in malicious ways, regardless of the exact details of the modification or how sneaky they make it). There's no real way around that. It's easy to just scan the entire exit node list for nodes launching this attack if you know what sites they're targetting.
- f430 5y agoQuick question: if you use Tor to send and receive crypto are you at risk of MITM?
- jandrese 5y agoIf you aren't in the habit of answering yes to big browser warnings about self-signed certs it seems like it shouldn't be an issue. If the MITM operators have stolen a well known root cert then we have a much bigger problem.
- avidiax 5y agoSSL stripping allows attackers to avoid the big browser warnings, yet view and tamper with your data. https://blog.cloudflare.com/performing-preventing-ssl-stripping-a-plain-english-primer/ https://blog.cloudflare.com/performing-preventing-ssl-stripp...
- vbezhenar 5y agoHTTP is marked as " Not Secure". It's not big, but it's noticeable if you're paying attention and you definitely should pay attention for financial operations.
- deleted 5y ago[deleted]
- opheliate 5y agoIn most cases, it should be okay, it's a specific scenario where MITM is possible. The issue arises if you're using Tor to access a website which gives you an address to send crypto to, and you trust that address is correct. If it's a hidden service you're connecting to, it's fine, there's no way for a malicious exit node to alter what's sent to you. If it's a normal website (i.e: not .onion) that you're getting the address from, then the exit node could perform SSL stripping [0], an attack in which a website which would normally be served over HTTPS is served to you via HTTP, and so the malicious exit node could alter the content. In this case, the attacker could change any cryptocurrency addresses present in the website to convince you to send currency to the wrong address. It would be visible in your browser that the website is being served over HTTP, not HTTPS. It should be noted, this scenario is getting rarer with the introduction of HSTS [1], especially in conjunction with HSTS preloading, which prevents your browser from accessing the website over plain HTTP. Tools like HTTPS Everywhere [2] can help ensure that you never access websites over plain HTTP also. Also, this isn't a vulnerability in Tor per se, the exact same is possible without Tor, it's just that when you connect to a website via Tor, you're deliberately introducing extra hops between you and your destination, which wouldn't normally be there. So, things that would need to come together for this attack to work: First, you're not connecting to a hidden service. Second, the website you're connecting to doesn't use HSTS, or you've not connected to them before & they're not in the preload list. Third, you aren't using a tool like HTTPS everywhere and you don't notice the website is coming to you over HTTP. Fourth, you don't verify that the address you've been given is correct independent of the website before sending a payment. This seems to me to be a fairly rare set of circumstances on the modern internet. 0: https://security.stackexchange.com/questions/41988/how-does-sslstrip-work https://security.stackexchange.com/questions/41988/how-does-... 1: https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security 2: https://www.eff.org/https-everywhere https://www.eff.org/https-everywhere
- INTPenis 5y agoI'm a long time exit node operator, I operate X currently and all are in Asia where they're most needed imho. I would not be opposed to having some sort of operator validation of exit nodes. Where you can actually validate who runs an operator node, get a person behind them. And perhaps rate those higher than others.
- WORMS_EAT_WORMS 5y ago> I operate X currently and all are in Asia where they're most needed imho. Interesting/Awesome. Just curious, what day/event specifically motivated you to get started with this? To be honest, my impression -- which could be wrong -- is most exit node operators do so for nefarious reasons, Pr0n (hence your username INT-Penis), or are Fed. (to be clear, appreciate what you are doing regardless)
- Forbo 5y agoConsidering that I see a large number of Tor nodes running from the same addresses as many pool.ntp.org nodes, I think your view is a bit uncharitable. Some people believe in Internet freedom and privacy, and see Tor as a way to help bring that vision to the world. In my opinion, it's just people contributing another piece of infrastructure run as a public service.
- dmantis 5y agoI had ran exit node for several years because it, you know, a good thing to do in life. Like donating to charity or publish GPL code. Freedom sometime is underrated, but if you live in authoritarian state you may understand. Helping people around make me feel better.
- maybelsyrup 5y ago> Pr0n (hence your username INT-Penis) Wait I can't tell if you're joking, do you really think their username is a reliable indication that they run Tor nodes for pornography, and not a stupid internet pun? Because if you're joking I lol'd, but if you're not I ... I'm worried about you, I guess?
- bawolff 5y agoWhy does tor even allow plain http by default. The internet has changed, most sites support https now, seems like a better default is in order.
- Ajedi32 5y agoAs the article notes, Firefox has an HTTPs-only mode now and Tor Browser is based on Firefox ESR, so there's a chance they might add that feature in the next major version update: > When Tor Browser migrates to Firefox 91esr we will look at enabling https-only mode for everyone, but there remains a significant concern that there are many sites that do not support HTTPS (especially more region specific sites) and the question of what messaging Tor Browser should use in that case. Source: https://lists.torproject.org/pipermail/tor-relays/2021-April/019628.html https://lists.torproject.org/pipermail/tor-relays/2021-April...
- batch12 5y agoIf you stay within the Tor network and don't exit, you dont really need the cert for encryption-- the traffic is encrypted end-to-end and decrypted on the hosting server already. Most onion sites are http. For these sites, proving identity to get a trusted cert is the barrier. If let's encrypt had an onion service, that could solve some of this. Edit: clarified
- bawolff 5y agoI meant for clearnet sites. There is essentially no benefit for an onion site to use https. Maybe if you want an extra layer of security potentially using different ciphers than the rest of the tor network. I suppose EV certs to prevent fake sites, although i think its debatable how well that works and its inherently not practical in many usecases.
- azalemeth 5y agoOut of curiosity, is there much of a (legal, sensible) community on i2p nowadays? I think its crypto is stronger than tor's, but unfortunately when I looked (many, many years ago) it was an absolute cesspool of humanity, of the "oh god, I am uninstalling this now" variety.
- saurik 5y agoFWIW, the security researchers I talked to about I2P--such as the authors of the paper I link after this paragraph, which is an example that comes to mind readily--mostly had felt that there was no reason to write papers about it anymore as there had been so many attacks on it already and that none of them had been taken seriously (unlike the Tor people, who care deeply and fix things quickly) that it wasn't fun or pointful. https://sites.cs.ucsb.edu/~vigna/publications/2013_RAID_i2p.pdf https://sites.cs.ucsb.edu/~vigna/publications/2013_RAID_i2p....
- GoblinSlayer 5y agoIt's that dude who can't figure out how to use ssl?