4 ms·
This is a very big deal if it happens. Roger's linked post on the Tor site talks about "seizure" of directory authority servers; only government authorities wou
by declan 12y ago
This is a very big deal if it happens. Roger's linked post on the Tor site talks about "seizure" of directory authority servers; only government authorities would have that power. In the U.S. that would typically happens only after a court grants a seizure order, which would be under seal at this stage.
Of the countries where the servers are located, the U.S. has the most extreme copyright laws, which means, sadly, FedGov is the leading candidate to be behind any possible seizure.
It would be interesting if an enterprising journalist were to ask MIT, SF-based Applied Operations, and RiseUp if they've been contacted by law enforcement on this matter. Those organizations host some of the U.S.-based servers. RiseUp has a warrant canary but it hasn't been updated recently: https://help.riseup.net/en/canary https://help.riseup.net/en/canary
Of course we don't know what actually is going on and it all may be (I hope!) a false alarm.
PS: If multiple governments cooperate and a majority of servers are taken down, what happens to Tor after the consensus interval expires? I don't know; maybe someone more familiar with Tor does. The consensus interval was changed to 72 hours a few years ago: https://trac.torproject.org/projects/tor/ticket/7986 https://trac.torproject.org/projects/tor/ticket/7986
PPS: Remember that FedGov's "copyright infringing" domain name seizures have on occasion taken down non-infringing sites in error, as I wrote about here: http://www.cnet.com/news/dhs-abruptly-abandons-copyright-seizure-of-hip-hop-blog/ http://www.cnet.com/news/dhs-abruptly-abandons-copyright-sei...
- declan 12y agoUpdate: Someone at the Tor project kind-of-answered my question about the expiration of the consensus interval a moment ago here: "If four out of the 9 dir auths were compromised and taken offline, then the remaining 5 will continuing publishing the consensus and the network will continue operating normally. If more than 5 are taken offline then this was a horrendously large operation and the necessary corrective actions will be taken to ensure the network remains operational." https://blog.torproject.org/blog/possible-upcoming-attempts-disable-tor-network https://blog.torproject.org/blog/possible-upcoming-attempts-...
- cjbprime 12y agoI don't think the change to 72 hours was merged; I think it's still at 24 hours. > PS: If multiple governments cooperate and a majority of servers are taken down, what happens to Tor after the consensus interval expires? As I understand it, the network would die (all clients would refuse to use the consensus, and thus not connect) 24 hours after the last good consensus. > PPS: Remember that FedGov's "copyright infringing" domain name seizures have on occasion taken down non-infringing sites in error, as I wrote about here: http://www.cnet.com/news/dhs-abruptly-abandons-copyright-sei.. http://www.cnet.com/news/dhs-abruptly-abandons-copyright-sei.... I'm not sure how this is relevant -- the directory authorities are not being accessed via domain name, just IP address.
- geographomics 12y agoIs it really that much of a big deal though? I would expect that each authority server's configuration data is securely and reliably backed up, so if the physical servers are seized, then a replacement can be fairly easily provisioned. Maybe some operators will even have one waiting on standby, in case of a normal hardware failure or similar. Presumably the IP address space isn't being seized or otherwise disbanded, so it could be dropped in exactly as specified in the hard-coded configuration - that is, the same IP address and port. Any ongoing and persistent impersonation of the server wouldn't be viable, as the long-term directory authority identity keys are kept offline. Maybe I'm missing something here but it sounds like more of a symbolic violation, rather than a potentially catastrophic disabling event that brings down Tor.
- cjbprime 12y agoI think you're probably overestimating the portability of IP addresses, and underestimating the coercive power of the organization that does the seize. IP addresses are assigned to a network provider, not a customer. If I'm hosted by a US provider and the FBI seizes my server, is that provider going to say "sure, just spin up a new box on the old IP", or are they going to tell me to get off their network? What if the FBI has an opinion on which decision the provider should take? What if the FBI has an opinion on which action the directory operator should take?
- pizzeys 12y ago> IP addresses are assigned to a network provider, not a customer. Actually, they can be assigned to either. See: http://en.wikipedia.org/wiki/Provider-independent_address_space http://en.wikipedia.org/wiki/Provider-independent_address_sp...
- deleted 12y ago[deleted]
- geographomics 12y agoI'm not convinced that the FBI has this power. Can they really say to MIT, for example, that port 9131 on IP address 128.31.0.39 is now out of bounds? Or coerce all of Riseup's peers (including any future ones) to cease connecting to their entire 199.254.238.0/24 range, or even just firewall off 199.254.238.52 upstream? As far as I know, there's no precedent for this where the provider - and, crucially, the owner of the IP address block - is hosting the server itself.