Tor Blacklisting Exit Nodes Vulnerable To Heartbleed
msm1267 (2804139) writes "The Tor Project has published a list of 380 exit relays vulnerable to the Heartbleed OpenSSL vulnerability that it will reject. This comes on the heels of news that researcher Collin Mulliner of Northeastern University in Boston found more than 1,000 nodes vulnerable to Heartbleed where he was able to retrieve plaintext user traffic. Mulliner said he used a random list of 5,000 Tor nodes from the Dan.me.uk website for his research; of the 1,045 vulnerable nodes he discovered, he recovered plaintext traffic that included Tor plaintext announcements, but a significant number of nodes leaked user traffic in the clear."
You know it's bad when Tor starts blacklisting people. God help us if Edward Snowden had been trying to use a site that was vulnerable to Heartbleed.
I'm under the impression the higher-end folks are encrypting their traffic before the routing layer and anyone else is an idiot, is that about right?
... to what Tor already leaks, is the previous hop from which the exit traffic came, and possibly meta data on other tunnels relayed by (but not terminated at) the node. If the relayed connection is SSL/TLS encrypted, that encryption is end-to-end from the original client to the server; sniffing some exit-node memory does not help you there. If the related connection is in the plain, then, well, then sniffing the exit node's memory does not tell you any more than you already knew by looking at its plain-text traffic.
Now, Heartbleed is not completely harmless here: You may, if you're very lucky, be able to sniff the previous node name, but as Tor tunnels are longer than that, that does not help you much. Plus, tunnels endpoints tend to change every couple of minutes, making the cross section even smaller. Also, you may now be in a position to sniff data from nodes whose ISP network you do not control, allowing you to do network-wide attacks. That may in fact be the biggest problem.
Support a Europe-related section on Slashdot!
"It sucks unless you are Russia, China, or a terrorist."
I also think the leaks are great for improving accountability and protecting privacy. Glad to join the ranks of Russia, China, and all terrorists everywhere in this regard!
The point is that, if you know the IP address of the exit node, you can use the heartbleed bug to examine it's outgoing traffic even if you don't have control of the network the exit node is on. This makes intersection attacks much easier because you only need to have data from one end. If I control a network where I see some Tor users, all I have to do is use this exploit on exit nodes until I see outgoing traffic that matches the traffic I see on my own network. I can then link that data to clients on my network and Tor is defeated. This attack is always possible if you control both the client's network and the end point they are communicating with (or some piece of the network between the exit node and the end point), but with this attack you don't need to actually control any part of the network on the exit side because you can just query the exit nodes directly and they will tell you themselves.
So, when is this guy going to be charged for hacking under US terrorism laws?
It's all good fun until your country gets occupied, territory taken from it, or nuked. Hilarious! (You don't live in Ukraine, do you?)
The leaks will help to protect the privacy of Chinese, Russian, and Iranian spies, and terrorists. Yours, not so much.
There is at least a chance you're a fool.
It'd be neat if tor exit nodes enforced a complete no-plaintext policy (and the tor network, in turn, blacklisted exit nodes that didn't do this). Any plain http connection you try to tunnel through tor should be blocked as soon as it reaches the exit node, just as a precaution.
I feel a great disturbance in the force, as if millions of NSA agents cried out in terror
As they keep taking more and more nodes down with these policy changes, Tor becomes even slower and less reliable. These continued attacks will destroy Tor if we allow them to continue. We should fight against this attempt to shut-down nodes.
Attack is as effective as running an exit node. Wow, so dangerous.
The only thing I have against TOR or any anonymizing proxy, is that 90% of the time, they definitely being abused (not used even), for doing bad things like trolling/harassing others, or worse.
APK
P.S.=> Let's be honest here - you know it. I KNOW it, & anybody else reading here does too (it's as badly abused as sockpuppetry is here & on say, arstechnica)... apk
It's also slow as shit. Like any allegedly anonymous proxy. This includes exit nodes as well. The whole shebang, & it's not even secure (apparently, never really was) & many of these things are inflitrated by the (enter lettered agency there) most likely too is my guess. So why have "all that" (lol, not) & go SLOWER too?
Makes no sense. It sounds useless now.
APK
P.S.=> Sorry, that's my take on those, in addition to earlier about how TOR gets abused by trolls and freaks to do henous reprehensible things... apk