6 ms·
Most TOR servers are vulnerable (NSA crackable)
- doomrobo 13y agoI don't see how ECDHE has any effect on the (in)security mentioned in the article. It clearly states that the RSA keys being only 1024 bits is the problem. How does using ECDHE-RSA change this?
- eksith 13y agoDebian/Ubuntu isn't alone in this. It should be noted that the majority of nodes are using Linux and of those, the 0.2.4 package is still not available unless you're running some flavor of "untested" or other bleeding edge distro. Of course that doesn't stop operators from simply downloading the latest package themselves from the Tor project or compiling from source.
- coopdog 13y agoSo why isn't the repo up to date? I honestly don't know the answer as I don't deal with Linux repo's much
- electic 13y agoDepends on the distro and the version.
- lcedp 13y agoBecause 2.4 is still marked as alpha. Versions on the torproject download page, their repo and Ubuntu repo all match. % wajig policy tor tor: Installed: 0.2.3.25-1 Candidate: 0.2.3.25-1 Version table: *** 0.2.3.25-1 0 500 http://ua.archive.ubuntu.com/ubuntu/ raring/universe amd64 Packages 100 /var/lib/dpkg/status 0.2.3.25-1~quantal+1 0 500 http://deb.torproject.org/torproject.org/ raring/main amd64 Packages
- m_ram 13y ago2.3.25 is the current stable version. 2.4.* is in development. Tor server operators would have to compile from source or use the upstream deb/rpm repos. https://www.torproject.org/download/download-unix.html.en https://www.torproject.org/download/download-unix.html.en
- contingencies 13y agoPosted a gentoo bug: https://bugs.gentoo.org/show_bug.cgi?id=484154 https://bugs.gentoo.org/show_bug.cgi?id=484154
- anologwintermut 13y agoGiven the extent of the five eyes (NSA,GCHQ,DSD, etc) taping of major fiber lines, Tor is almost certainly useless against the NSA even without backdoors. The NSA doesn't need to resort to expensive key cracking operations to break either the anonymity or confidentiality of Tor. They just have to be able to see entry and exit node traffic. From the original paper by the Tor developers: "A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary." --- Tor: The Second-Generation Onion Router http://www.dtic.mil/dtic/tr/fulltext/u2/a465464.pdf http://www.dtic.mil/dtic/tr/fulltext/u2/a465464.pdf
- aegiso 13y agoSo I'm totally making stuff up here, and my interest in crypto has a hackish rather than academic flavor, but... Couldn't we design a system that doesn't fall in this scenario, by using a constant-rate packet-blasting network that emits "background radiation" even if nothing is happening, and then filters out the good stuff via chaffing/winnowing [1]? This would clog the tubes like a torrent and run you a similar tab, but wouldn't it be 100% anonymous even in the face of such an adversary, while still being low-latency? [1] http://en.wikipedia.org/wiki/Chaffing_and_winnowing http://en.wikipedia.org/wiki/Chaffing_and_winnowing
- sillysaurus2 13y agoYes, but Tor is already very slow, and it has a lot of resources behind it already. It would take a substantial amount of money to bootstrap your network. It'd be a worthy 1-10MM investment --- assuming you don't want any ROI on it.
- simcop2387 13y agoFreenet actually does this, though they aren't just sending random chaff, they'll actually use it to duplicate the data. It makes this particular attack impossible, but freenet has it's own potential issues. If you control all of someone's inputs and outputs you can still determine when they are using the system.
- reirob 13y ago"Of course, this is still just guessing about the NSA's capabilities. As it turns out, the newer Elliptical keys may turn out to be relatively easier to crack than people thought, meaning that the older software may in fact be more secure. But since 1024 bit RSA/DH has been the most popular SSL encryption for the past decade, I'd assume that it's that, rather than curves, that the NSA is best at cracking." So it is suggested to update to a newer version that uses EC, but we are not sure if EC is not breakable? Others ([1], [2]) suggest that RSA is more secure than EC!? I wish that the security experts could give "clear" advise. EDIT: Added proper links to sources suggesting RSA over EC. [1] Bruce Schneider in http://www.theguardian.com/world/2013/sep/05/nsa-how-to-remain-secure-surveillance http://www.theguardian.com/world/2013/sep/05/nsa-how-to-rema... "Prefer symmetric cryptography over public-key cryptography. Prefer conventional discrete-log-based systems over elliptic-curve systems; the latter have constants that the NSA influences when they can." [2] Fefe (it's in German) http://blog.fefe.de/?ts=acd52294 http://blog.fefe.de/?ts=acd52294
- pfortuny 13y agoRegarding ECC, whenever a "constant" appears in a cryptographic algorithm, BEWARE. Yes, I know about "nothing up my sleeve" numbers... However the ones used for ECC are not of this type. What a sad state of affairs.
- nullc 13y ago> However the ones used for ECC are not of this type. Yes they are. The P-XXXr curves which are used by most of the ECC using web (and Tor, when it uses ECC) were generated by using a deterministic strongly pseudo-random procedure which you can repeat for yourself. See page 187 of FIPS 186-3.
- pfortuny 13y agoAb, OK, my bad. Thanks for the pointer and sorry for the mistake.
- nullc 13y agoOkay, I need to eat my words here. I went to review the deterministic procedure because I wanted to see if I could reproduce the SECP256k1 curve we use in Bitcoin. They don't give a procedure for the Koblitz curves, but they have far less design freedom than the non-koblitz so I thought perhaps I'd stumble into it with the "most obvious" procedure. The deterministic procedure basically computes SHA1 on some seed and uses it to assign the parameters then checks the curve order, etc.. wash rinse repeat. Then I looked at the random seed values for the P-xxxr curves. For example, P-256r's seed is c49d360886e704936a6678e1139d26b7819f7e90. _No_ justification is given for that value. The stated purpose of the "veritably random" procedure "ensures that the parameters cannot be predetermined. The parameters are therefore extremely unlikely to be susceptible to future special-purpose attacks, and no trapdoors can have been placed in the parameters during their generation". Considering the stated purpose I would have expected the seed to be some small value like ... "6F" and for all smaller values to fail the test. Anything else would have suggested that they tested a large number of values, and thus the parameters could embody any undisclosed mathematical characteristic whos rareness is only bounded by how many times they could run sha1 and test. I now personally consider this to be smoking evidence that the parameters are cooked. Maybe they were only cooked in ways that make them stronger? Maybe???? SECG also makes a somewhat curious remark: "The elliptic curve domain parameters over (primes) supplied at each security level typically consist of examples of two different types of parameters — one type being parameters associated with a Koblitz curve and the other type being parameters chosen verifiably at random — although only verifiably random parameters are supplied at export strength and at extremely high strength." The fact that only "verifiably random" are given for export strength would seem to make more sense if you cynically read "verifiably random" as "backdoored to all heck". (though it could be more innocently explained that the performance improvements of Koblitz wasn't so important there, and/or they considered those curves weak enough to not bother with the extra effort required to produce the Koblitz curves).
- tptacek 13y agoOf course, this is still just guessing about the NSA's capabilities. As it turns out, the newer Elliptical keys may turn out to be relatively easier to crack than people thought, meaning that the older software may in fact be more secure. Wait, what?
- thingummywut 13y agoWhy is ECDHE+3DES a "lulz-worthy combination"?