15 ms·
On being targeted by the NSA
- robobro 12y agoThere's no reason not to link to the primary source. https://blog.torproject.org/blog/being-targeted-nsa https://blog.torproject.org/blog/being-targeted-nsa
- eponeponepon 12y agoI found this particularly resonated: "...we designed bridges for users in countries like China and Iran, and here we are finding out about attacks by our own country." I don't really know what to say to the NSA/Snowden/etc. stories any more. Intellectually, I understand that each new worst revelation is worse than its predecessor - emotionally though, none of it even surprises me any more. ...come on Fort Meade, I want to be surprised. Drop something really juicy. Something so diabolical that it's actually cool.
- diafygi 12y agoThis isn't for your entertainment. Please set aside your emotions and contribute to stopping this. Are you registered to vote?
- eponeponepon 12y agoWay to miss the joke, champ. Never mind, though. As it happens, I am not a US citizen. I have no recourse to the ballot box or indeed any other entity to affect the NSA's actions. I, and the other 6.5 billion of us, have very little option but to sit back and watch this story.
- ibisum 12y agoHave you effectively encrypted all the things yet? Or are you in the 'I am not interesting' camp? Because, you might be interesting one of these days. Are you going to snare us all in your net?
- biafra 12y agoWho could you vote for in the US to stop this?
- diafygi 12y agoWell George Miller is my current congressional representative, and he scores an A on the EFF's scorecard, so I vote for him. Also, in a lot of the primaries that I've seen, there's at least one candidate who is anti-mass surveillance. https://standagainstspying.org/scorecard/ https://standagainstspying.org/scorecard/
- pvnick 12y agoThe release of this source code does not match Snowden's modus operandi, which is to avoid releasing technical details which would allow other governments to construct similar surveillance systems. Bruce Schneier and Glenn Greenwald believe that there are now multiple NSA leakers [1]. [1] https://twitter.com/ggreenwald/status/485081861119832064 https://twitter.com/ggreenwald/status/485081861119832064
- Globz 12y agoI agree but the details still lead to him... https://lists.torproject.org/pipermail/tor-dev/2014-July/007085.html https://lists.torproject.org/pipermail/tor-dev/2014-July/007...
- rweir 12y agothe details in these stories would be of no use to "other governments to construct similar surveillance systems.".
- dobbsbob 12y agoCould be Germany got an evaluation copy of the program and somebody there leaked it. Maybe it isn't restricted to just 5 eyes alliance
- csandreasen 12y agoI suspect the "second NSA leaker" is just Jacob Appelbaum with the same set of documents that Laura Poitras brought back to Der Spiegel. There's already several people in the infosec community doubting the veracity of some aspects of the Tor article[1][2][3], including from within the Tor developer community itself[4]. Though there's no confirmation, some have suspected that Julian Assange's most likely source for the Afghanistan revelation back in May[5] was Appelbaum[6]. [1] http://blog.erratasec.com/2014/07/validating-xkeyscore-code.html http://blog.erratasec.com/2014/07/validating-xkeyscore-code.... [2] https://twitter.com/thegrugq/status/485158875721523200 https://twitter.com/thegrugq/status/485158875721523200 [3] https://twitter.com/electrospaces/status/485193336912093185 https://twitter.com/electrospaces/status/485193336912093185 (scroll up) [4] https://lists.torproject.org/pipermail/tor-dev/2014-July/007085.html https://lists.torproject.org/pipermail/tor-dev/2014-July/007... [5] http://gawker.com/why-did-wikileaks-name-country-x-when-glenn-greenwald-1580634729 http://gawker.com/why-did-wikileaks-name-country-x-when-glen... [6] http://www.csmonitor.com/World/Security-Watch/Backchannels/2014/0520/Assange-threatens-to-release-Snowden-info-that-Greenwald-says-could-endanger-lives http://www.csmonitor.com/World/Security-Watch/Backchannels/2...
- MikeTaylor 12y agoI can't even see this blog. See the screenshot at http://www.miketaylor.org.uk/tmp/tor-mitm.png http://www.miketaylor.org.uk/tmp/tor-mitm.png Transcription follows: -- Cannot connect to the real torproject.org Something is currently interfering with your secure connection to torproject.org. Try to reload this page in a few minutes or after switching to a new network. If you have recently connected to a new Wi-Fi network, finish logging in before reloading. If you were to visit torproject.org right now, you might share private information with an attacker. To protect your privacy, Chrome will not load the page until it can establish a secure connection to the real torproject.org.
- MikeTaylor 12y agoSo who could be carrying out a man-in-the-middle attack on the TOR project? It's pretty hard to think of candidates, isn't it?
- diafygi 12y agoPlease name names. Rhetorical questions don't add to the discussion.
- MikeTaylor 12y ago> Please name names? Seriously? It's not _perfectly_ clear who I'm talking about?
- sp332 12y agoIt depends on the country. It could be Sky, or whoever does internet filtering in Australia, I forget who does that.
- sroerick 12y agohttp://cryptome.org/2013/12/Full-Disclosure.pdf http://cryptome.org/2013/12/Full-Disclosure.pdf
- agl 12y ago
- hnha 12y agoFor a little bit of fun: Try linking to https://www.torproject.org/download/download-easy.html.en https://www.torproject.org/download/download-easy.html.en on Facebook and marvel at the non-descript error messages. They depend on where you try to post it (timeline, comment). For example "could not be posted because of technical error, try again in a few minutes"...
- sigkill 12y agoHoly cow, it really doesn't work. I tried it once immediately as you posted, and then continuously via different people's accounts and different computers even. It really doesn't work, and it ain't just my computer or account. It isn't even a US thing. I don't think there's a problem with parsing the URL because it clearly is able to load up the preview. All I can say is, MAN! They really don't want you helping people with Tor.
- barsonme 12y agoInstead of error messages, I got this: http://i.imgur.com/mDTPnrq.png http://i.imgur.com/mDTPnrq.png
- anon4 12y agoI just posted that exact link without issue.
- aendruk 12y agoBefore (12:41 PDT) and after (12:56 PDT): https://i.imgur.com/GAHQIXZ.png https://i.imgur.com/GAHQIXZ.png
- nitrogen 12y ago"Worksforme" is a bad habit that we in the software industry need to get out of. When a user complains about something, they're almost never trolling, so we need to take the reports seriously.
- jordigh 12y ago
- snowfear 12y agoThe link times out for me on Verizon, but it works under Tor. For those who cannot access it, here is the text of the page: We've been thinking of state surveillance for years because of our work in places where journalists are threatened. Tor's anonymity is based on distributed trust, so observing traffic at one place in the Tor network, even a directory authority, isn't enough to break it. Tor has gone mainstream in the past few years, and its wide diversity of users -- from civic-minded individuals and ordinary consumers to activists, law enforcement, and companies -- is part of its security. Just learning that somebody visited the Tor or Tails website doesn't tell you whether that person is a journalist source, someone concerned that her Internet Service Provider will learn about her health conditions, or just someone irked that cat videos are blocked in her location. Trying to make a list of Tor's millions of daily users certainly counts as widescale collection. Their attack on the bridge address distribution service shows their "collect all the things" mentality -- it's worth emphasizing that we designed bridges for users in countries like China and Iran, and here we are finding out about attacks by our own country. Does reading the contents of those mails violate the wiretap act? Now I understand how the Google engineers felt when they learned about the attacks on their infrastructure.
- bcl 12y agoWorks fine for me on Verizon.
- joyeuse6701 12y agodemonstrate with screenshot plz.
- joyeuse6701 12y agorunning timewarner cable, all of torproject.org is timing out.
- agyl 12y agoFor me as well. But using Google DNS server or OpenDNS solves the issue.
- Create 12y agoit's worth emphasizing that we designed bridges for users in countries like China and Iran, and here we are finding out about attacks by our own country. We begin therefore where they are determined not to end, with the question whether any form of democratic self-government, anywhere, is consistent with the kind of massive, pervasive, surveillance into which the Unites States government has led not only us but the world. This should not actually be a complicated inquiry. http://www.theguardian.com/technology/2014/may/27/-sp-privacy-under-attack-nsa-files-revealed-new-threats-democracy http://www.theguardian.com/technology/2014/may/27/-sp-privac...