5 ms·
There is a node that delivers your packet to the target server, is there not?
by dumbo-octopus 2y ago
There is a node that delivers your packet to the target server, is there not?
- alphan0n 2y agoIf the server is on the Tor network, an onion server, then it is encrypted end to end and no traffic or identity is exposed to either the onion server or any intermediary. That is to say, if I started an onion server on one side of the world, then connected to it from somewhere else, my connection to it would be anonymous and encrypted to any external entity.
- dumbo-octopus 2y agoHow are you imagining the penultimate node in the chain connects to the target server without knowing anything about them?
- alphan0n 2y agoThis is well understood public knowledge. https://community.torproject.org/onion-services/overview/ https://community.torproject.org/onion-services/overview/
- dumbo-octopus 2y agoHook, line, and sinker. https://www.sciencedirect.com/science/article/pii/S2667295222000514 https://www.sciencedirect.com/science/article/pii/S266729522... https://www.usenix.org/system/files/raid2019-iacovazzi.pdf https://www.usenix.org/system/files/raid2019-iacovazzi.pdf https://www.ndss-symposium.org/ndss-paper/flow-correlation-attacks-on-tor-onion-service-sessions-with-sliding-subset-sum/ https://www.ndss-symposium.org/ndss-paper/flow-correlation-a...
- alphan0n 2y agoThis: https://www.sciencedirect.com/science/article/pii/S2667295222000514 https://www.sciencedirect.com/science/article/pii/S266729522... Uses a dataset created from aggregation of logs from all nodes in a simulated Tor environment to train a model that can identify the onion server's IP based on fingerprints created from that model. >We ran the modified Tor software in the Shadow simulation environment to obtain a large amount of circuits for analysis. Shadow is a discrete-event network simulator developed specifically for Tor network simulation experiments and can run Tor software directly. Therefore, Shadow follows all logic related to Tor circuits. In the simulation environment provided by Shadow, we can build servers, clients, directory authorities, onion services and relays, and can control all nodes. Therefore, we can get circuit data in Shadow without the real Tor network. This is: a) Not a real world example b) Not an example of interception of unencrypted traffic between a client and an onion site c) Not de-anonymization of a client This: https://www.usenix.org/system/files/raid2019-iacovazzi.pdf https://www.usenix.org/system/files/raid2019-iacovazzi.pdf Is super interesting, it's a real world example of using collusion of an entry node that inserts "watermarked" data to identify an onion service. It does not: a) Intercept or break encryption between client and onion service b) De-anonymize a client This: https://www.ndss-symposium.org/ndss-paper/flow-correlation-attacks-on-tor-onion-service-sessions-with-sliding-subset-sum/ https://www.ndss-symposium.org/ndss-paper/flow-correlation-a... Is the same data watermarking scheme to use entry collusion to identify onion services. None of your examples show that a connection to an onion server is insecure insofar as data integrity or client anonymity is concerned.
- dumbo-octopus 2y agoOk so you admit we can identify onion services, and it’s common knowledge that the NSA knows your personal traffic patterns. If you think they can’t correlate the two, I have a bridge to sell you.
- alphan0n 2y ago[flagged]
- deleted 2y ago[deleted]