Tor Connections To Hidden Services Could Be Easy To De-Anonymize
angry tapir writes with news of a report presented Friday at Hack In The Box which outlines a counterintuitive fact about Tor:
Identifying users who access Tor hidden services — websites that are only accessible inside the Tor anonymity network — is easier than de-anonymizing users who use Tor to access regular Internet websites.
That's because the addresses of the Hidden Service Directories (HSDirs) used to index those Tor-network-only sites, though shuffled daily, can be predicted (and hijacked) with cheap brute-force techniques.
"The researchers managed to place their own nodes as the 6 HSDirs for facebookcorewwwi.onion, Facebook's official site on the Tor network, for the whole day on Thursday. They still held 4 of the 6 spots on Friday. Brute-forcing the key for each node took only 15 minutes on a MacBook Pro and running the Tor relays themselves cost US$62 on Amazon's EC2 service.
TOR is getting a lot more research attention now. That can only make it stronger in the long run.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
The simple fact that it uses "directory servers" for Tor stuff (including hidden services) means that there is centralization in the network. Centralization of control is the enemy of anonymous communications because it vastly shrinks the target surface area required to damage or intercept that communications. This is just another hole in the bottom of the anonymity boat for Tor users. A better system would publish services using the public key of a strong asymmetric encryption algorithm such that the only valid responses could be encrypted with the private key; flooding the network with bad information to turn yourself into the correct node for a given "hidden service" name simply wouldn't work.
This is not de-anonymizing anyone.
Really? The slides go over the needed steps to become an HSDir... or several HSDirs... and perform a correlation attack to de-anonymize someone. -1, Overrated.
The researchers essentially brute forced their way into running Tor's "hidden service DNS servers" for a day.
You only need 4 days uptime to become an HSDir. That's a pretty insignificant bar. They also still held 4 of those 6 spots on day #2. It cost a pittance. -1, Overrated.
The new hidden service proposal that fixes this issue among plenty of other improvement is being worked on.
Possibly the only useful part of your comment. +1 Informative.