4 ms·
If you are using Tor correctly, they can't target 'you' because they don't know who 'you' are. Also, have fun storing indefinitely all of my banal communicatio
by binarymax 13y ago
If you are using Tor correctly, they can't target 'you' because they don't know who 'you' are. Also, have fun storing indefinitely all of my banal communications until forever.
- lscritch 13y ago>If you are using Tor correctly How can you be sure "they" are not running the exit node?
- vinceguidry 13y agoControlling the exit node does not inherently compromise anonymity, only allows access to the plaintext message. If using end-to-end encryption on top of Tor, you should be able to maintain both anonymity and protection from tampering and snooping.
- delinka 13y agoThey still don't know the source of the communication. Running an exit node means they can see where traffic is headed as it emerges from Tor, not that they can magically determine from whence it came. The problem here is that the destination can identify you. You, after all, are the one paying for that VM instance at that IP address within AWS. Who else would be connecting via SSH?
- gambiting 13y agoControlling the exit node does not help with Tor <-> Tor traffic.
- greyman 13y agoBut is it also true if they can monitor the whole Internet traffic?
- lgeek 13y agoAs far as I know, Tor is theoretically vulnerable to a correlation attack by an entity capable of monitoring the entry and exit nodes. Personally, I thought having this capability, plus actually implementing the attack was a bit far-fetched for most cases. However, reading about what the NSA might or might not be be doing, plus the fact that GCHQ is tapping the transatlantic cables and knowing that the US and western European intelligence agencies tend to cooperate, I'm not so sure anymore. I think at this point we can assume that other countries have similar capabilities as well. Knowing that the infrastructure for this kind of attacks is in place, I think the cost is a lot lower than I would have expected a few months ago.
- DanBC 13y agoI'd be interested to know if the number of people running tor servers, or if donations of servers, or donations of money to fund servers, has increased much recently. How many machines would Tor need to make traffic analysis tricky?
- wjgotie 13y agothe number of tor servers has increased. https://metrics.torproject.org/networksize.png?start=2013-03-27&end=2013-06-25 https://metrics.torproject.org/networksize.png?start=2013-03... https://metrics.torproject.org/direct-users.png?start=2013-03-27&events=off&end=2013-06-25&country=all https://metrics.torproject.org/direct-users.png?start=2013-0...
- greyman 13y agoYes, this is exactly what I was thinking. Moreover, they could run their own exit nodes.
- DennisP 13y agoMixnets like Tor generally aren't considered secure against an adversary who's monitoring the whole network. Maybe the NSA isn't there quite yet, but they're sure trying. If they succeed, a DC-Net can still provide perfect anonymous communications, but it's hard to make those scale. There's been some work to improve matters, eg: https://www.usenix.org/conference/osdi12/strong-scalable-anonymity-safetynet https://www.usenix.org/conference/osdi12/strong-scalable-ano... Edit: also this (pdf): http://secan-lab.uni.lu/images/stories/christian_franck/FRANCK_Christian_Master_Thesis.pdf http://secan-lab.uni.lu/images/stories/christian_franck/FRAN...
- orthecreedence 13y agoI may be ignorant, but doesn't it take a lot of statistical analysis to do attacks like this? The point being not that the NSA cannot do it, but that they have to be specifically targeting you to pull it off. Unless they know what's going through the wire, how will they know to target you?