4 ms·
Tl;dr: By placing load on suspected hidden service hosts (over normal, non-anonymous IP), one can then measure the change in clock skew (as a result of higher C
by awda 12y ago
Tl;dr: By placing load on suspected hidden service hosts (over normal, non-anonymous IP), one can then measure the change in clock skew (as a result of higher CPU / chassis temperature from the higher load) over the anonymous channel to confirm it is the same host (by comparison with clock skew before load).
The result holds over many hops and onion layers (this is the usual "the average of random noise is zero" thing). Very cool.
- anon4 12y agoIf the machine has no public services running, would that attack still work? What if it's behind NAT or a hw firewall with ssh exposed only via port knocking?
- awda 12y agoIt needs to be connectible over IP (and TCP, I think?) for it to talk to Tor, which is necessary for running a hidden service. You could imagine an anonymizing network where that is not necessary, I guess, by having the service connect to some other internal node over NAT. (Although then you could just Sygil attack with a bunch of nodes and wait for the target to connect to you.)