12 ms·
Attacking Tor: How the NSA targets users' online anonymity
- aroch 13y agoAt least according the the slides, Tor appears to be safe for the most part. Which is good.
- deleted 13y ago[deleted]
- lambada 13y agoActually the slidedeck states that Tor Browser Bundle defeats some of the attacks they use that plain Tor+Vidalia is vulnerable to. And if you're referring to the previous Freedom Hosting attack, that only affected users of TBB on Windows who had ignored "Security Update Available" messages for over a month.
- mcphilip 13y agoedit: removing meta discussion about flagging. the story should get the attention. apologies for the distraction.
- kevinh 13y agoThere's another article from the Guardian on the NSA regarding Tor in the #6 slot on HN. This is in the #3 position. I think you're overestimating the impact. Edit: This article is now in the #1 position. Flagging isn't hurting these articles any.
- tptacek 13y agoI don't think this is being flagged. I flag soap opera NSA stuff for instance, but wouldn't flag this.
- mcphilip 13y agoIt was at mid second page with 10 up votes after 35 minutes when I made this post originally.
- deleted 13y ago[deleted]
- TeMPOraL 13y agoMaybe it's time to make flagging public, Quora-style?
- eli 13y ago1) It's currently first on the front page 2) Complaining about voting is really tedious to read about
- pc86 13y agoAlmost as tedious as reading complaints about complaining about voting :)
- neves 13y agoI've been playing with vagrant and ansible to create a new server in a snap. Here is a good weekend project: Instead of having just an Tor/browser bundle, build a vagrant machine specification that installs the Tor bundle. This virtual machine would be destroyed and recreated from time to time. Now put the machine specification in GitHub and let anyone use it.
- error54 13y agoThat's a great idea! Please let us know how that goes.
- tptacek 13y agoMetacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world governments. If Tor can't provide meaningful assurances (here, there's a subtext that Tor actually made NSA's job easier), you'd need an awfully convincing reason for how you're going to do better than they are before "liberating" the Chinese internet, especially given that it your users who assume the real risks.
- twoodfin 13y agohere, there's a subtext that Tor actually made NSA's job easier Are you reading anything from that subtext beyond, "Tor has a high concentration of the kind of users we're interested in, so let's keep it a juicy target rather than squeezing too hard?"
- rz2k 13y agoAs I understand it, which admittedly isn't well, it made surveillance jobs easier when its users mistook anonymity and privacy. That is, sending something through the tor network means that it's more likely that your traffic is going through a node belonging to a group that records everything than if your traffic randomly found a point to point route across the internet. I don't see how using the Tor network could make you less anonymous, unless as you point out, it's use suggests a user's greater likelihood of sending and receiving interesting information. It hurts the system that exit nodes have been targeted for content that other users were responsible, but from how I have read, Tor can provide people meaningful anonymity that is difficult breach. As an aside: What is the effect of such parenthetical statements? I think they just create a vague idea of uncertainty and fear. If there is a vulnerability, there has to be a mechanism, not just a sense of omnipotent government surveillance. Maybe that mechanism is the probabilistic likelihood of an organization controlling a large portion of the Tor nodes' ability to identify users. Maybe it's a flaw that has been surreptitiously put into the source code. I'm pretty sure more people who know would suspect the former as far more likely than the latter. It's easier to address the questions when you know what the parenthetical utterance was even referring to in the first place.
- anologwintermut 13y agoThis is one way the NSA can attack Tor. if they just want to de-anonymize a connection, not get access to the content, (.e.g to locate the Silk Road Sever), in theory they can just analyze all their passively collected data form major fiber backbones to identify and locate the user. Tor, including hidden services, was never designed to protect against someone who could observe all or almost all traffic in the Tor network. Given that data, it's rather easy to correlate timing information. Indeed, Tor fundamentally allows this since it aims to be a low latency network. Given the NSA's extensive tapping of key fiber lines, we should assume they can actually observe the necessary traffic.From the original paper announcing Tor: "A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary." --- Tor: The Second Generation Onion Router [0] [0] https://svn.torproject.org/svn/projects/design-paper/tor-design.pdf https://svn.torproject.org/svn/projects/design-paper/tor-des...
- elwin 13y agoThe more we learn about the NSA's capabilities, the more it seems like the Manhattan Project. They are developing the "cyberwarfare" equivalents of weapons of mass destruction. This exploit delivery network goes so far beyond any legitimate purpose it might serve that it belongs in the same moral category as hydrogen bombs. EDIT: The above is somewhat hyperbolic and unclear. The NSA's capabilities may have legitimate uses. Similarly, there may be legitimate military uses for nuclear weapons. But building nuclear weapons creates the risk of worldwide nuclear destruction. Similarly, building this kind of highly efficient exploit system creates the risk of destroying all Internet security. The potential destruction far outweighs whatever good the weapons might accomplish. That is why I said they belong in the same category.
- twoodfin 13y agoI think that's a pretty serious exaggeration. Designing tools to let you spy on Tor traffic has to be in a separate category from designing bombs that could kill millions. Besides, are there no ends that could justify these means? I think the means are altogether reasonable given the ends. Put aside whether you think the NSA is genuinely pursuing its national security mission: If it were, wouldn't it make perfect sense to figure out how to attack Tor?
- res0nat0r 13y agoSucks you are being downvoted for not agreeing with the hyperbole, but I think you are correct. The NSA's job is to spy on things. TOR represents a place where illegal things occur, so it is a perfectly reasonable thing that they would be tasked with trying to stop such illegal things there.
- elwin 13y agoAttacking Tor by passive analysis is one thing. Installing spyware, creating a botnet, and making the infection process quick and easy is another. There might be some justification for the former. The latter is too risky.
- tptacek 13y ago
- danso 13y agoThis accompanying article has useful context: http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack-tor-network-encryption http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack... > But the documents suggest that the fundamental security of the Tor service remains intact. One top-secret presentation, titled 'Tor Stinks', states: "We will never be able to de-anonymize all Tor users all the time." It continues: "With manual analysis we can de-anonymize a very small fraction of Tor users," and says the agency has had "no success de-anonymizing a user in response" to a specific request. So only with "manual analysis" can intel agencies have any success, and that appears to be with a small subset of users who have other vulnerabilities. But when targeting a specific user, the NSA appears to have had no success in de-anonymizing them.
- lambada 13y agoThis needs to be higher. I think this was the best scenario anyone who knows Tor could hope for. The attacks against Tor, when used correctly, are well understood. And, assuming this presentation is accurate,the capabilities of adverserial semi-global attackers aren't much different from what we were expecting. I would love to see if they have similar slide-decks for I2P, which is often compared with Tor for Hidden Service/eepsite usage.
- ktr100 13y agoOn page 5 of the 'Tor Stinks' full document is a clipart picture of a terrorist. So... Somewhere in the bowels of the NSA is a graphic artist that slaps beards and guns to stock clip-art. fun job. http://www.theguardian.com/world/interactive/2013/oct/04/tor-stinks-nsa-presentation-document http://www.theguardian.com/world/interactive/2013/oct/04/tor...
- galapago 13y agoThis kind of news should encorage people to create and use better tools for find and fix vulnerabilities in software.
- spindritf 13y agoSo how does Tails[1] stack up? It seems to thwart most of those attacks. It block non-anonymized traffic and makes permanent changes difficult. OTOH, privilege escalation bugs happen frequently on Linux. https://tails.boum.org/ https://tails.boum.org/
- steveklabnik 13y agoAccording to the article, > "Tails... adds severe misery to CNE equation."
- conductor 13y ago> Once the computer is successfully attacked, it secretly calls back to a FoxAcid server, which then performs additional attacks on the target computer to ensure that it remains compromised long-term It would be nice if somebody could honeypot them to find out the vulns and malware types they are using.
- antocv 13y agoHow so I get on the list of most interesting persons so I can setup my honeypots? do I have to be jacob appelbaum or assange? what freaked me out is that they deliver sensible exploits for techie people. go damnit.
- antocv 13y agoHow so I get on the list of most interesting persons so I can setup my honeypots? do I have to be jacob appelbaum or assange? what freaked me out is that they deliver sensible exploits for techie people. go damnit.
- coldcode 13y agoSure these folks are smart and have all sorts of powerful weapons; what are the odds that someone out there could successfully repurpose some of these weapons? What is the likelihood that vulnerabilities exist in the NSA's systems? We can never know since it's all secret. If someone does take over these systems we wouldn't know that either.
- elwin 13y agoHistorically, different nations' intelligence agencies have often infiltrated each other. I'm sure someone will eventually gain access to the NSA's weapons, but I think they would be more likely to steal details to add to their own systems than "repurpose" the NSA's.
- wil421 13y agoI am loving every minute of this NSA-Gate or Snow-Gate. Nothing like holding GOVT accountable for decisions they make behind closed doors, decisions that had an impact on the whole world not just US citizens. Its also great all the technical details that are being released about how they Intel Agencies collect data. Its all fascinating.
- kilroy123 13y agoSounds like, if you're going to do something very sensitive on tor, you need to: - always have an update to date version of tor bundle! - compile the bundle yourself from source - run it virtually, and always roll back to a clean snapshot (before installing it tor) when done - if possible use from a network that is not your own (open wifi, public wifi, etc.) - spoof your mac address - do not run JS, Java applets, etc.! I know this seems extreme, but from what I read, it's the best you can do to protect yourself.
- bryze 13y agoYeah, I was wondering if a virtual machine is safe from malicious attacks, though. Can anyone comment on the feasibility of this method as fail-safe?
- shabble 13y agoIdeally you'd want to be running Tor with transparent proxying of all traffic on a physically separate (and locked down) host. I believe there are guides on how to do all that on a raspberry pi out there. On your primary browsing/whatever machine, I believe (but have not exhaustively researched) that it would still make sense to run inside a VM/container, because that would provide a much more 'generic' set of system characteristics (MAC address, clock jitter stats, CPUinfo, etc) than your actual hardware. It does provide a greater attack surface, so you'd have to weigh up the value of potentially masking physical identity vs likelihood of gaining root due to VM exploits. There's also the risk of overconfidence because of these measures, which might lead you to overlook important details in the host OS, or in your communication habits.
- sirsar 13y agoAnother option is to run an amnesiac OS on a material that is not re-writable (CD-R). Note this would replace the VM, not the separate Tor machine.
- sitkack 13y agoThere are plenty of ways to breakout of a VM. What if the VM has a filesystem that is readonly by the host? Drive by download, cookie fs drop, etc. Attack the indexing server, file previews, etc. You really want to run the VM on an external host like a raspberry pi and the VM should different than the host running Tor. Tor should really be rewritten in a Coq proven Haskell program.
- chrisduesing 13y agoWait, so simply by using Tor the government will install malware on your computer. How is that legal?
- boon 13y agoMy interpretation of the article was that they identify prior to attacking. I suppose they could use a "spray and pray" attack on anyone using Tor, but that would be easily detected.
- shawn-furyan 13y agoOne heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully since on the whole we seem to have good instincts about what is trustworthy and what is untrustworthy. I think that it actually has tended to clarify thinking about security so that fewer and fewer engineers are able to delude themselves into trusting something that they know deep down is really untrustworthy.
- antocv 13y agonot to be a downer but I do feel these systems and exploits are designed by us the hackers we so much want to belive are good, but it looks like most hackers have a price and probably derive joy from designing these systems for the government. we know what is trustworthy we know how to build and do the right thing. yet look there is tens of thousands of brilliant minds working for the nsa against everybody else.
- anologwintermut 13y agoPrior to this one should not have (and arguably should sill not) assumed Tor is safe against the NSA. Tor was explicitly not designed to protect against a global passive adversary. That's the price it pays for low latency. With the amount of network data the NSA has, they probably constitute such an adversary. It is actually rather surprising that Tor gives them this much trouble.
- jlgreco 13y ago> It is actually rather surprising that Tor gives them this much trouble. I am not really convinced that what we have seen demonstrates conclusively that it does. There is the possibility that we are looking at parallel construction, or that these attacks are genuine but they are sitting on more dramatic capabilities for targets they think are worth it (perhaps because the Chinese continuing to trust and use Tor is a better situation for the NSA to be in than the Chinese doing everything the old fashioned way with microfilm and dead-drops). The best way to go forward is to continue to assume that Tor does not present any significant difficulty to the NSA.
- pitchups 13y agoIt appears that the NSA has been able to target only Tor users that are using the Tor - Firefox bundle. So if you are using Chrome or some other browser - configured to use Tor, you would be safe from these exploits. Wouldn't most sophisticated hackers - or other high value targets most likely to be of interest to the NSA - be already doing that, rather than using the Firefox+Tor bundle?
- andrewaylett 13y agoUnless you put a lot of effort into the integration, I'd advise against doing that -- the Firefox included in the bundle is specifically set up to avoid leaking information, while a standard Firefox or standard Chrome will phone home or do something else (like make a DNS request over the public network) that will quickly compromise any security you thought you had.
- deleted 13y ago[deleted]
- ksrm 13y agoCan one use something like Lynx with Tor? I doubt there are very many exploits for it.
- GigabyteCoin 13y agoIs nobody slightly concerned that the date shown in the PDF file which sparked this commentary ( http://www.theguardian.com/world/interactive/2013/oct/04/tor-stinks-nsa-presentation-document http://www.theguardian.com/world/interactive/2013/oct/04/tor... ) shows the PDF as being created in 2007? It looks like they had some trouble picking out users 5 years ago... lord only knows how easy it must be for them now.
- atmosx 13y agoI think this depends vastly on the number of rogue tor nodes. However, picture this: NSA isn't the only organization going after TOR right? Probably there are others.So if you are China, Iran, Syria, Russia, etc. What do you do? You set up your 'own' poisonous tor relays. What you end up doing is disrupting and diminishing the potential of a single agency or a group of agencies of controlling a big % of tor traffic. So all in all, might be a good thing and way more difficult thatn it was 7 years earlier. Not to mention that at the time we were browsing through tor at 50 kb/s while now we browse at 400 kb/s.
- welder 13y agoThe NSA is like Tor's pentesters, except Tor doesn't get to see the results.
- dragonwriter 13y agoGiven that the US government is Tor's main funder, the first part may be more accurate than the second part.
- frank_boyd 13y agoI remember somebody from Mozilla thinking out loud "we should integrate Tor in Firefox". Glad that didn't get done.
- andrewaylett 13y agoWhy? Because it seems that Tor actually does what it says it does. One of the biggest issues with it is that using it singles you out; if we could get more people using it then it would be less useful as a differentiator.
- g8oz 13y agoI'm more glad that they didn't do it the other way around - considering how confident the NSA is about being able to keep finding new vulnerabilities in Firefox.
- rdl 13y agoShould really make a packaged vm in vm failsecure tbb equivalent. Nothing is really works from a usability standpoint while giving reasonable protections against this kind of endpoint attack.
- doug1001 13y agodon't forget that Tor publishes their exit nodes--they make them freely available to anyone. So a simple membership test on a client IP against that list of exit node IPs identifies that client IP as either having come through Tor via the onion router or else they are an exit node themselves.
- deleted 13y ago[deleted]
- jstalin 13y agoSo how does one determine which sites are being intercepted through Tor and served malformed code? Start doing CURLs from within Tor and outside of it and comparing hashes?
- hawkharris 13y agoApparently, John Grisham works for the NSA, naming its programs.
- gcb1 13y agowhat about the nonsense on the quantum system? i think the reporter left some key info out. why does speed is a factor to mitm attacks? the slide shows a proper mintm diagram... or is this quatum thing exploiting a package arriving before the honest response? and why they would need to do that if they are in a position to do a proper mitm attack and not expose themselves for someone who monitors man-on-the-side attacks?
- malandrew 13y agoIf someone makes disposable Raspberry Pi Tor exit and non-exit nodes sealed in hard plastic resin, we could all buy them and drop them off in random places throughout the world on open networks. If enough people the world over does this, we would make it a lot harder for a global passive attacker to succeed. Tor's biggest vulnerability is the risk associated with operating exit nodes means that the number of exit nodes remains relatively low at ~1000 worldwide. If hundreds of thousands of exit nodes started popping up all over the globe. It would be very hard to counter. I'm also curious if enough governments unhappy with what is happening could go as far as hosting many tor nodes outside the control of the NSA. Is the Global Passive Adversary threat still valid if there are many of them that are non-cooperative with one another (i.e. China can't monitor US and Russian tor nodes, Russia can't monitor US and Chinese nodes, and the US can't monitor Chinese and Russian nodes)? My intuition tells me that the global passive adversary would have to be able to monitor most of the nodes, but if others came on the scene doing the same, they would dilute the percentage of nodes that any single global passive adversary could monitor.
- pygy_ 13y ago> FoxAcid tags are designed to look innocuous, so that anyone who sees them would not be suspicious. An example of one such tag [LINK REMOVED] is given in another top-secret training presentation provided by Snowden. Anyone knows what these tags look like?
- espeed 13y agoFoxacid sounds like an NSA version of BeEF (http://beefproject.com/ http://beefproject.com/), which hooks browsers that would then be monitored from the Lockheed-Martin-style SOC (https://www.youtube.com/watch?v=x1tCJfy_iZ4 https://www.youtube.com/watch?v=x1tCJfy_iZ4 :-). However, for those with more limited resources, Ryan Barnett is working on an open-source monitoring system for BeEF (https://vimeo.com/54087884 https://vimeo.com/54087884).
- reirob 13y agoIn the slide titled "Exploitation: Shaping" the status says "Can stain user agents working on shaping." How do they achieve to make tor use NSA/GCHQ nodes? If they achieved to do this 5 years ago (the PDF is from 2007) would it then be reasonable to assume that since then they have managed to modify the TOR source code in a way that nobody remarked to do exactly this?