4 ms·
I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with
by gumber 12y ago
I refuse to believe that the FBI is privy to a funamental TOR break that's completely eluded the cryptographic community, and they're risking revealing it with some darknet busts.
If TOR was broken, they'd be encouraging its use while secretly mining it for parallel construction opportunities across the board. Instead, we get warning shots.
TOR is fine, but now that we know that the FBI has its tendrils everywhere perhaps we should be a lot more cautious about trusting people we meet online. At the very least we shouldn't be granting administrator privileges to people we don't know the identities of, which is a mistake some of these operators seemingly made.
- owenmarshall 12y ago> I refuse to believe that the FBI is privy to a funamental TOR break[...] and they're risking revealing it with some darknet busts. This is probably the best analysis I've heard. If the Tor protocol was broken in some way, agencies would be sitting on it to vacuum up as much information as possible. If the underlying cryptographic primitives were broken in any way, that information would be restricted to the highest levels of government and used against state actors. Darknet busts mean JS browser injection attacks, poor development practices on the server side, or bad human factors (probably this one, from what we're hearing). But more importantly, increasing the frequency of darknet busts gives a hint of what the authorities think about Tor: they don't have fundamental attacks, so it's best to scare people away as much as possible to discourage use.
- uptownJimmy 12y agoThis rings true. And I think those "bad human factors" are the same as always: the folks slinging the goods are also tasting the goods, which inevitably results in sloppiness.. Good highs and good judgement are seldom seen hand-in-hand.
- justcommenting 12y agoI would caution against drawing arbitrary lines between agencies like FBA and NSA or GCHQ or the "cryptographic community" in terms of information/skills, e.g. http://www.foreignpolicy.com/articles/2013/11/21/the_obscure_fbi_team_that_does_the_nsa_dirty_work http://www.foreignpolicy.com/articles/2013/11/21/the_obscure... It might be more accurate to conclude that information is a currency in an unregulated market: GCHQ shares with NSA who shares with FBI DITU amongst many other public and private sector customers. In a world of parallel construction, the most reasonable assumption is that anyone can be privy to anything, or at least information derived from it.
- mike-cardwell 12y agoThey don't have to break Tors crypto to figure out where hidden services are. They just need to identify which IPs are consistantly connected to the Tor network, and then prod them and see if the hidden service goes offline. That is one of the reasons why you're absolutely not supposed to run a relay from the same IP that you run a hidden service from. Because your IP is published if you do that. If I were to run such a service, I would want to make sure that the IP that the hidden service is running from has as little connection to me as possible. [edit] If it were my full time job to locate Tor hidden services, I'm pretty sure I could make a decent go of it. Certainly for a lot of them. Given the resources the NSA and GCHQ have, I have to believe that they can do a much better job of it.
- venomsnake 12y agoActually a relay will be awesome way to mask a hidden service, if TOR encryption holds.
- mike-cardwell 12y agoNo, it is an extremely bad idea to do that: http://cybermashup.com/2013/09/04/dont-run-a-tor-router-and-a-hidden-service-from-the-same-connection/ http://cybermashup.com/2013/09/04/dont-run-a-tor-router-and-... And something a little more "official" from https://www.torproject.org/docs/tor-hidden-service.html.en https://www.torproject.org/docs/tor-hidden-service.html.en - "It is generally a better idea to host hidden services on a Tor client rather than a Tor relay, since relay uptime and other properties are publicly visible."
- mike_hearn 12y agoYou don't even need to take them offline. Just send them a lot of traffic: done. QUANTUM + XKEYSCORE + some MapReductions would make mincemeat of this problem.
- lotsofmangos 12y agoIf you have enough of a view of the network it is running over, TOR has major weaknesses. TOR has always been traceable to anyone with enough resources as it makes no attempt to guard against timing attacks. TOR has never been a secure defense against a collaboration between rich states, especially if you are running permanent services with lots of users. Also, I do not quite see the intelligence benefits of trying to hide something that is mentioned in the TOR faq, this is not a secret weakness, but something that has been a known weakness since the project's inception. The only secret revealed here is that the security services have been busy tapping lots of stuff, but that cat has been firmly out of the bag for a while and has since had kittens.
- xorcist 12y agoCouldn't you at least narrow it down to the AS by correlating outages, if you're watching it for an extended period of time? The rest should be possible with more standard police work, once you know where to look (there are probably not more nodes in an AS that you could check them all, disregard known relays etc.).