Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ohmygodel
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
ohmygodel
7y ago
Yes, if you manually and wisely choose your own guard nodes, then you can avoid these attacks. You should be sure that those guards can't themselves be linked to you, either.
2.
▲
by
ohmygodel
7y ago
I assume you refer to [0]. He says "If [the adversary] can knock me off enough guards, my tor daemon will eventually choose one of his guards. Then he can identify my actual network address and directly attack my server. (This happened
3.
▲
by
ohmygodel
7y ago
The Tor protocol doesn't explicitly signal the guard relay that it is in the guard position. However, the guard relay (call it R) can use several indicators to conclude that the preceding hop (call it S) is indeed the source (e.g. the
4.
▲
by
ohmygodel
7y ago
Tor has made some improvements that would reduce the threat of deanonymizing an onion service, but none affect the above analysis (or rather, the above analysis has taken them into account). The main improvements, in my opinion, have been:
5.
▲
by
ohmygodel
7y ago
This is probably the best description of how Tor uses guards: https://gitweb.torproject.org/torspec.git/tree/guard-spec.tx... .
6.
▲
by
ohmygodel
7y ago
The page you link describes "vanguards" which apply the guard logic to positions beyond the first hop. They are only available as a plug-in that you must separately download and configure. My understanding is that no plans current
7.
▲
by
ohmygodel
7y ago
In this case, the main question is how the server was discovered, not how the operator was then deanonymized. As the article describes, after the server was discovered to be in France and run by OVH, authorities used legal treaties ("M
8.
▲
by
ohmygodel
7y ago
Fair enough! I was using as a heuristic the expected number of compromised guards, which would be 0.02*50 = 1. Moreover, things degrade exponentially over time. If half the guards rotate every month, the chance of choosing a bad guard is af
9.
▲
by
ohmygodel
7y ago
Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting service was discovered and more how it ever stayed up long en
10.
▲
by
ohmygodel
8y ago
That's basically using a proxy, and so it has the same security. If the proxy is/geos bad (say, your VPS provider reveals your IP to some interested guys with guns), then you lose (anonymity). If your proxy remains good, then all
11.
▲
by
ohmygodel
8y ago
Thanks! The protection of the delay-based ballot-mixing looks somewhat weak. I see that the delay from one ballot batch to the next is set to a uniformly-random time between 10 and 60 seconds. I also see that the ballot batch size is 10. Le
12.
▲
by
ohmygodel
8y ago
Honestly, I don't know why you need a blockchain in the first place. Just run your own accounting servers, which you already are doing for the Anonize ballots. It is certainly possible to take in money from identified (i.e. non-anonymo
13.
▲
by
ohmygodel
8y ago
> Tech alone is never enough for anything like what we are doing. You'd be surprised how far you can get. For example, protocol design exist that provide strong message anonymity: mixnets, DC-nets, and secure multiparty computation
14.
▲
by
ohmygodel
8y ago
Interesting, but decentralization does not equal privacy. Indeed, it might make privacy worse by sharing the data more widely and making it even easier to get copies of the data. Consider, for example, BitTorrent, which has a pretty decentr
15.
▲
by
ohmygodel
8y ago
> Please read up on GDPR "purpose limitation". I am reasonably familiar with the contents of GDPR, having looked into it more after attending a lecture on the subject [0]. > We cannot use IP address except for antifraud, so
16.
▲
by
ohmygodel
8y ago
An IP address is an identifier. If it weren't, there would be much less reason to use a VPN or Tor. Suppose I understand you correctly and you do see the network IPs and timestamps of submitted tokens and ballots. Is your argument then
17.
▲
by
ohmygodel
8y ago
By the way, please do let me know if I'm wrong and Brave does provide good privacy while enabling payments. I have turned off Brave Payments because of the privacy issue, but I would like to be able to re-enable them. Also, if my under
18.
▲
by
ohmygodel
8y ago
I understand that Anonize is used for anonymous ballots. I understand that Brave used to submit its ballots via a single-hop proxy. My understanding is now that Brave no longer uses this proxy, which wasn't a good solution anyway bec
19.
▲
by
ohmygodel
8y ago
I support Brave's vision for the Web, but it currently seems to represent a step backwards for privacy. Making payments to providers essentially involves sending your Web browsing history to Brave. The FAQ states that "we do not
20.
▲
by
ohmygodel
9y ago
The problem seems well-advertised to me. From the Tor FAQ ( https://www.torproject.org/docs/faq.html.en#AttacksOnOnionRo... ): "it is possible for an observer who can view both you and either the destination website
21.
▲
by
ohmygodel
9y ago
This is a pretty uncharitable comment. A nicer (and, in my opinion, more correct) take would be that their articles are written for people that enjoy reading and language. And the sentences you cite make perfect sense to me: the legislature
22.
▲
by
ohmygodel
11y ago
I'm not sure what you're arguing any more. Your argument started as that only Silk Road was a "notable" onion service, which you appeared to define as having "publicity". Then the argument became the Facebook d
23.
▲
by
ohmygodel
11y ago
My understanding is that Facebook runs an onion service (aka hidden service) primarily because it allows them to easily manage their anonymous users separately from other users. "Management" might include separate security logic
24.
▲
by
ohmygodel
11y ago
> I don't really buy the comparison that what CERT did is similar to a university-sponsored DDoS. I think a better parallel is the Dan Egerstad case. Here's why it's worse: they inserted a plaintext encoding into the respo
25.
▲
by
ohmygodel
11y ago
If by "darknet" you mean Tor hidden services, then exit relays are not used. The circuits are client->guard->middle->middle->middle->middle->guard->hidden service. The bandwidth bottleneck for hidden services
26.
▲
Some statistics about onions
(blog.torproject.org)
3 points
by
ohmygodel
12y ago
|
0 comments
27.
▲
by
ohmygodel
12y ago
There is no magic bullet here. Here are the things you were probably thinking of and why they won't work: 1. Allow relays to apply individual hidden service (HS) blacklists: HS addresses are not necessarily public, can require authenti
28.
▲
Tor security advisory: “relay early” traffic confirmation attack
(blog.torproject.org)
197 points
by
ohmygodel
12y ago
|
45 comments
29.
▲
by
ohmygodel
13y ago
> > And you really can't have a forum without pseudonyms. Users will create them on their own (by including a nickname in their posts) even if you don't build it in. > That's human self–incrimination. As long as this
30.
▲
by
ohmygodel
13y ago
I think it's cool that you're making usable security software. I do worry that "usable" has gotten more thought than "security", and providing a system that doesn't deliver the security it promises could b
More ›