Attacking and Defending the Tor Network
Trailrunner7 writes "In a talk at the USENIX LEET workshop Tuesday, Nick Mathewson of the Tor Project discussed the group's recent challenges in responding to suppression efforts by governments in Egypt, China and elsewhere. What the Tor members have learned in these recent incidents is that while governments are becoming more up front about their willingness to shut off Internet access altogether or censor content, users are also becoming more resourceful. Mathewson said that the group is working on methods for alleviating the problems that national-level restrictions cause for Tor users. One method involves moving to a modular transport method in order to get around some of the throttling that ISPs perform on encrypted traffic in order to make Tor usage more difficult. In a separate talk at LEET, Stevens LeBlond of INRIA in France presented research on methods for tracing Tor users back to their IP address. One of the attacks, which LeBlond and his co-authors titled 'Bad Apple,' used an exit node that the researchers controlled in order to trace the streams of data sent by users of BitTorrent over Tor back to their IP addresses."
Information is like water and it will always find a way to get through.
... and it was too slow to do anything at all.
meh...
I guess that the research demonstrated by Stevens LeBlond just goes to prove what most of us have known for a long time - even using TOR (and the same will go for any other type of encryption, IP masking etc) you are not 100% safe if somebody wants to work out who you are. The governments may not care too much if you are just sharing a few pirated movies around, although some companies may, but I can guarantee that those carrying out the real illegal activity, such as sharing child-pr0n, will be tracked down one way or another.
All that TOR does is provides people who aren't really that switched-on with a false sense of security about their activities.
Ugh. Goatse. You asshole.
hello.jpg EXIT! DO NOT CLICK.
Hopefully this does more help than a mod down.
Ohoho, nice try, but you won't goatse me today! ;)
"When information is power, privacy is freedom" - Jah-Wren Ryel
Ugh. Goatse. You asshole.
UID >2000000 and blog.com. Coincidentally the same problem with anonymous networks, except it's more extreme there. No, goatse is not the worst you can see.
Live today, because you never know what tomorrow brings
As far as I understand it, if you want to host a Tor exit node it should be public knowledge that the address serves as a Tor exit node. This means you should advise your ISP that it is, and list the reasons.
how is babby formed?
I'd like to see better integration with Tor and Chrome's Incognito Mode. Normal plain-jane internet route for all my apps, but route all incognito traffic through Tor. Otherwise, I find it a pain in the rear (not to mention more error prone) to keep toggling OSX between "performance mode" and "tinfoil hat mode." Doesn't really matter what I'm viewing in tinfoil hat mode, I just would rather have the same kind of barriers on my local cookie/history storage as I have out in the world.
[
Oh geez. I replied without clicking the link. It's a goatse. Don't go.
how is babby formed?
Steganography. Make it impossible to determine what traffic is encrypted by embedding the encrypted traffic as noise in, say, a video extolling the virtues of the dictator.
I've abandoned my search for truth; now I'm just looking for some useful delusions.
I've been urging that someone more capable than myself look into that. Unfortunatly routing would be a nightmare and latency just as bad - I imagine that it would be unuseable for real-time communcations, certainly so in sparsely populated areas. But it could still function using some sort of shared caching system, similar to Freenet - or even just using Freenet, with adaptations to run on portable devices and with ad-hoc connections between nodes.
Steganography. Make it impossible to determine what traffic is encrypted by embedding the encrypted traffic as noise in, say, a video extolling the virtues of the dictator.
and when the secret police begin asking the right questions about the source of the video, what then?
Steganography is all about blending into the background.
Not drawing attention to yourself.
Recently discussed on Bruce Schneier's blog ("Identifying Tor Users Through Insecure Applications"):
http://www.schneier.com/blog/archives/2011/03/identifying_tor.html
IP over Avian Carrier could bypass the problem entirely! http://www.faqs.org/rfcs/rfc2549.html
Rest assured, your webcam WAS recording. Just not to your hard drive.
an excellent way to bring down beijing, ... havana,
People in China are generally enjoying a steadily rising quality of life, regardless of how politically repressive the state may be. Revolutions don't happen because some blogger got arrested or a site was blocked. If anything will cause real unrest there, it will be the sort of falling wages that caused Tienanmen.
People in Cuba are well educated and free from disease and starvation. Unlike China, the internet isn't very prolific and is difficult to use at all. They really can't even use Tor because the USA won't allow Cuba to connect to the fiber, so their only access is satellite (until they finish linking with Venezuela). And, of course, there is no private ownership of computers. Last I heard, there's only about 50 political prisoners in the whole country, hardly the level of police state it is made out to be. Consider Guantanamo; the USA has more political prisoners in Cuba than Cuba does!
Certainly the USA-created governments in Iraq and Afghanistan cause more terror and provide fewer opportunities for their citizens than Cuba.
It would take far more than an internet propaganda operation to topple China or Cuba.
Yup. Though, I tend to include the USAs rather broken form of "Democracy" on the "nondemocracy" list.... alot of people don't get.... I ONLY criticize the US (generally). Its not that I think Cuba is great... or that China is wonderful (but truth be told, they seem to be way more open and making a lot more progress towards openness than I ever would have predicted 10 years ago, never mind 20.... not giving them a pass, just, some credit for improvement).
I always get "Where would you rather live". Nowhere, I think this place is the best there is, but that doesn't mean I think its sufficiently good. There is no such thing, always strive for better.
That said, I answer your question as no. Its not "acceptable".... but how "Acceptable" is it that the US jails people for growing plants that it doesn't like? Its put people in jail for decades for nothing more than that. How is that acceptable? I see it as just as bad...but the difference.... we also have the highest per capita incarceration rates.
We have LOTS of what I would term "unacceptable imprisonment" right here.
"I opened my eyes, and everything went dark again"
Reading this I feel the US is going to have some revolts very soon.
In America we are technically still better but we are falling very very fast. In China the country is much poorer but they rising and getting better. If wages fall people protest and the problems at home are always the issue that drives people first regardless if the government is a democracy or a dictatorship.
I am not a tea partier or anyone who hates Obama, but how many banks will we keep bailing out, how many more jobs must we outsource, how many more social services do we have to keep cutting. The unemployed and underemployed will have enough sooner or later.
I feel if the opportunity arouse for people to protest you could bet millions would join.
http://saveie6.com/
Considering TOR was an invention of the US Navy, you'd assume that the military, at least, considers it a boon.
Your ad here. Ask me how!
Because "One bad apple spoils the bunch" as the old saying goes.
If I have been able to see further than others, it is because I bought a pair of binoculars.
I used to think that it's the lack of exit nodes that makes TOR somewhat slow until I tried some internal services, i.e. *.onion. So I proceeded to configure an unthrottled intermediate node on a box with a 100/100 Mb/s connection. After 1-2 weeks of warming up, the node routed over 1 TB of traffic _daily_. As my monthly cap is 5 TB, I had to throttle it, unfortunately.
TL;DR: If you have spare bandwidth and want to help the TOR network without the potential risks of an exit node, please setup an intermediate node.
I hate to say it, but personally I feel when it gets to the rioting portion of the fall the feds will just quit pretending and accept our fate to be the next "bad guys" on the world's stage. Germany got to go twice, now its our turn. The bitch is a smart leader could probably pull it off with almost ZERO interference. How? Deals baby, deals.
The Chinese want Africa, its resources would help China a lot...so give it to them. Help yourselves our Chinese friends. Taiwan? Fuck 'em, help yourself. in return you stay our buddy or stay out of the fight, your choice. That leaves our former enemy mother Russia and the Eu, and we could take care of both with one shot. Old Putin is a classic Ruskie, and would just loove the old USSR back...so let him have it. Hey Putin buddy, its ALL yours, help yourself. in return you stay on our side or stay out, you choice again. The Eu will be too busy shitting itself over the return of the USSR to say much of anything. Seriously what are they gonna do? They have what...maybe 4 aircraft carriers put together? We got 11 baby, you lose!
So what does the USA get, to quell those rioting mobs? Why the whole damned north and south hemispheres of course! We'll tell the Canadians to keep those oil sands pumping if they don't want to say hello to Mr air strike, they'll STFU. And there are a HELL of a lot of resources in South America, more than enough to make the USA fat with wealth and give the poor plenty of "bread and jobs". Cue the patriotic music, wave the flag, stick a fork baby!
Who would stand against us if China and the USSR are sticking with us? England...ha! They're on an island, wolf packs showed how to shut them down. The French will bitch, who cares, same for Italy. Germany will be too busy trying to control the western EU and worrying about old grudges from the east to deal with us.
Sad to say that is what I figure we'll end up doing. I can't see those in power going silently into that good night, not with all that killer hardware, and I don't see them being stupid enough to roll the tanks here and start another French revolution. So they'll need resources to quell the masses but quick, and a false flag blaming one of our old enemies (Hi Chavez!) would be just the excuse to rally folks around the flag. Then once the big three have what we want, we can split the middle east and anything left over. Combine the Chinese Army with the USA and USSR? Make the Axis look like third stringers.
ACs don't waste your time replying, your posts are never seen by me.
I would be interested in the possible reasons one could come up with that would have your ISP say "oh, OK, that's fine - exit node away" At least in the US, an ISP will be far more concerned with maintaining good relations with the Gov't than with an individual end user...
"As the intrepid kobold companion continues his journey, he begins to wonder... if priests raises dead, why anybody die?
And why not just host the node at a hosting service and not on your personal machine. I recall reading that it's best to set it up that way but I'm not sure where I read it - perhaps the TOR site. The TOR site has a list of "tor friendly" ISP's.
You're using a hosting service and thus are still to be held responsible if used improperly, the hosting service will hold you accountable which they can easily do because you're paying the bills. This is why what I said still applies even if you use a hosting service. It must be public knowledge that your host is a Tor exit node.
how is babby formed?
Right. But I'm assuming that if you hosted at an ISP that you might avoid a visit to your personal residence by the authorities. I'm probably wrong though and some over zealous jackasses will still come and kick your door down.
My guess is the authorities would have no problem finding a reason to knock on your door if shady things are done using your hosted exit node.
how is babby formed?