I've studied Tor vulnerabilities for two years. I'm seeing signs of traffic confirmation (active), traffic confirmation (passive), stream watermarking, and a massive willingness to shape control of the network with DoS. Just about every attack on hidden services (active and passive), of which I am aware, was deployed, all at once. The malformed packet DoS was especially clever. And I'm sure a ton more were used that never made it to the academic research.
It was almost comical, like the star ship captain saying "now on my mark, fire all photon torpedoes!" They just revealed a massive amount of capability to send a message: Tor is not safe. They want everyone to know that despite that sticker on Snowden's laptop, Tor remains vulnerable.
But what remains interesting, and glaringly obviously absent, is user identification. The NSA does not appear to be able to deanonymize users at will. That is, given enough time and enough resources, they can ID hidden services and long-term users, but given an arbitrary Tor exit and and TCP stream, they can't simply follow it back to its origin.
A for effort. But in organizaton it looks like a military campaign, not a cyber attack. Straight out of the "total dominance" playbook.
But of course it won't work. Tor isn't a country. Its an idea. You can't force the Internet to "submit."
All this did was make blindingly obvious holes that many researchers have been asking to be fixed for a while.
This is very interesting. Are you suggesting that Facebook over Tor could be a step in the wrong direction? Official NSA Facebook partnerships are for now very unlikely, but I am interested to know how Facebook over Tor could in principle solve the user identification problem listed by grand parent.
Please correct me if I'm wrong, but if someone is logged in to Facebook while browsing over Tor, aren't you just one CSRF from getting all personal details for the user?
If you're using Facebook over Tor, you probably shouldn't be using an account that you created on an non-Tor connection or an account tied to your real-world identity.
If you are, and you're concerned about being identified... :/
Indeed, it works like freenet IRC where you have to make an account first then log in to it with Tor. This is solved by making a throwaway VPS or virtual desktop you ssh into with Tor, make your account, shred the VPS and then change the password when you log in directly to Fb with Tor.
You can also edit Torrc to temporarily only use your own Tor exit nodes if worried about malicious exits while setting up accounts.
Is that academic research, or in what context? I'd be interested to hear what you have to say on that; anything published anywhere? Email in profile if you'd be into that :)
It was almost comical, like the star ship captain saying "now on my mark, fire all photon torpedoes!" They just revealed a massive amount of capability to send a message: Tor is not safe. They want everyone to know that despite that sticker on Snowden's laptop, Tor remains vulnerable.
But what remains interesting, and glaringly obviously absent, is user identification. The NSA does not appear to be able to deanonymize users at will. That is, given enough time and enough resources, they can ID hidden services and long-term users, but given an arbitrary Tor exit and and TCP stream, they can't simply follow it back to its origin.
A for effort. But in organizaton it looks like a military campaign, not a cyber attack. Straight out of the "total dominance" playbook.
But of course it won't work. Tor isn't a country. Its an idea. You can't force the Internet to "submit."
All this did was make blindingly obvious holes that many researchers have been asking to be fixed for a while.