Tiny Wireless Device Offers Tor Anonymity
Lucas123 writes: The Anonabox router project, currently being funded through a Kickstarter campaign, has surpassed its original $7,000 crowdfunding goal by more than 10 times in just one day. The open source router device connects via Wi-Fi or an Ethernet cable making it harder for your IP address to be seen. While there have been other Tor-enabled routers in the past, they aren't small enough to fit in a shirt pocket like the Anonabox and they haven't offered data encryption on top of the routing network. The device, which is being pitched as a way for consumers to securely surf the web and share content (or allow businesses to do the same), is also being directed at journalists who may want to share stories in places where they might otherwise be censored.
Making Tor dead simple to use is great, but this is such a nice device for three-letter agencies to target inserting a backdoor into.
Its a cool idea. There are things that are problematic about it though, like the fact that the browser itself hasn't been properly anonymized. The Tor browser package tries to disable plugins and third party software that might inadvertently reveal your identity or cause other information leakage. There is no such guarantee in this instance, which is a bit of a false sense of security. Tor isn't a panacea for all anonymity issues, and you wouldn't want to route most of your traffic over it.
I'm personally more interested in the hardware, any specifics on that? I think it would be a nice platform for a lot of interesting projects, hardware based firewalling etc.
The weak link in Tor security has always been its users.
Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways
Freeze! Is that a crew membership badge of pirate Tor's ship in your pocket, or are you just happy to see me?
Aye, 'tis hard to arrrgue...
You have the right to remain sentient. If you give up the right to remain sentient, you will be elected to public office
According to the kickstarter page, the campaign is over $170,000.
A $51 pledge gets you one shipped to your house in the USA.
$5 / month hosted VPS on linux = awesome!
Using tor to acces a website that is served via cloudfront will get you a captcha to solve.
The capchas are sometime way too hard for humans to solve.
Most of the anonbox users will be annoyed by the constant capthca onslaught and decide that the device is broken and stop using it.
Internet restriction circumvention device. But *NOT* an anonymity device. Tor is great for avoiding deep packet inspection monitoring/blocking at the ISP level, but without a chain of anonymous accounts proxies outside the tor network, etc it's useless as an anonymity device. Sure you might be able to troll slashdot, or reddit, or digg, or whatever your favorite website is, but if even one of those is done with an account you made via the 'normal' net, it has the potential of being identified and tied back to you.
Given the comments about Comcast and Tor mentioned in an article here a few weeks back, I expect we'll see more of the social engineering angle coming at us from hostile incumbent ISPs. The FBI/NSA/USAFCC will mostly not care since they can probably use Tor as probable cause to hack your system (when you finish laughing over 'probable cause', like that would stop them from hacking you either way!)
Overall I think these devices, assuming the hardware is secure and the software is suitably hardened (and lacking either a heartbleed-esque memory leak, or remote exploitable hole offering root level system access), and firmware upgrades are not trojan'd en-route, should see a net increase in tor usage and perhaps wider adoption of anonymity enhancing technology. After all, it's a net gain for all of us if more people use tor, and if this device takes off, hopefully dozens more will spring up. Assuming consolidation is avoided, 10 different types of Tor routers with no more than 20-30 percent compromisation should ensure sufficient route anonymity for the average user.
That said, Windows, your CPU ID, your ethernet hardware address, and now Nvidia's GPU UUID, all seem like much larger and more immediate anonymity holes than tor network compromise. Can anyone verify for me if AMD's GPUs have a similiar UUID feature as Nvidia's cards, and if either or both have a method of disabling the return of said ID's to non-root/administrator applications (The latter obviously won't help with videogames however, since most have administrator level access through their DRM.)
No it's not great, and no it's not a back door you need to worry about.
The fundamental problem is that anonymity is hard, very hard. There have been several people identified via Tor, seemingly smart people who thought they were covering their tracks. In many ways making Tor easy to use, and making a Tor proxy style router is the single worst way of using Tor.
We leave tracks everywhere we go. Our browser configuration, plugins, OS, etc all leave fingerprints for people to follow and using Tor doesn't stop that. Tor should be hard to use. It should require reading a manual. It should require understanding everything about anonymity. It should be used like Tails, a burner Linux distribution which should leave no trace on the system on which it was used.
The TLAs don't need to backdoor this device. It's quite likely that they welcome its use.
The problem with Tor is that there are hundreds of leechers, even the agencies are using it to cover their tracks and it wouldn't be surprising if they controlled most of the exit nodes too!
What we need is to have every internet user to be an exit node, otherwise Tor will just collapse.
This device should at least be a client and relay device, being just a client is being a leecher.
One of the kickstarter rewards for buy the device is...
"Get your name on the sponsors page of our website"
I got a little chuckle at the irony in that.
This is a different flavor of the TP-Link TL-WR703N wireless router I ordered from the SLBoat store on ebay.com. It comes preloaded with OpenWRT and I can then flash it with the PORTAL bin file from github.com. PORTAL uses TOR for all access to the Internet.
https://github.com/grugq/portal