Tor says it’s "still safe" amid reports of police deanonymizing users

https://www.bleepingcomputer.com/news/security/tor-says-its-still-safe-amid-reports-of-police-deanonymizing-users/

195 points · 80 comments · view on lemmy.world

80 Comments

ShortN0te@lemmy.ml · 60 pts · 1y (15 replies)

This attack has been known for years now. And tor is simply not able to defend against it without a complete redesign.

orcrist@lemm.ee · 30 pts · 1y (1 reply)
[ removed ]
ShortN0te@lemmy.ml · 4 pts · 1y

Yes, sorry i worded it incorrectly you can try to make it harder but timing attacks are still possible.

Nope, just a summary that this is just old news. There is nothing new in the article.

EherNicht@feddit.org · 13 pts · 1y (12 replies)

Redesign being I2P

possiblylinux127@lemmy.zip · 4 pts · 1y (4 replies)

I2p has issues that can more easily lead to deanonymization attacks. It says it on the FAQ

MigratingtoLemmy@lemmy.world · 7 pts · 1y (3 replies)

Confirmed the troll.

From the FAQ:

Before you use I2P, use Basic Computer Hygiene Always! Apply your OS vendor provided software updates in a prompt manner. Be aware of the state of your firewall and anti-virus status if you use one. Always get your software from authentic sources.

It may be dangerous to use I2P in what the project calls "Strict Countries"

Most I2P peers are not in those strict countries and the ones that are, are placed in "Hidden Mode" where they interact with the rest of the network in more limited ways, so that they are less visible to network observers.

Unlike Tor, "exit nodes" - or "outproxies" as they are referred to on the I2P network - are not an inherent part of the network. Only volunteers who specifically set up and run separate applications will relay traffic to the regular Internet. There are very, very few of these.

There is an outproxy guide available on our forums, if you would like to learn more about running an outproxy.

If you are hosting something sensitive, then your services will go down at the same time that your router goes down. Someone who observes your downtime and correlates it to real-world events could probably de-anonymize you with enough effort.

I2P has defenses available against this like multihoming or Tahoe-LAFS

I2P does not encrypt the Internet, neither does Tor - for example, through Transport Layer Security (TLS). I2P and Tor both aim to transport your traffic as-is securely and anonymously over the corresponding network, to its destination.

In addition, you may be vulnerable to collusion between the outproxy operator and operators of other I2P services, if you use the same tunnels ("shared clients").

In theory, if you're accessing the clearnet, then it is no better or worse than TOR. It is a little better if you're stay in I2P land.

Don't listen to me or him. If you're reading this, go to the FAQ (https://geti2p.net/en/faq) and make your own decisions.

possiblylinux127@lemmy.zip · 3 pts · 1y (2 replies)

I2p lacks the ability to mask your traffic. It is obvious that you use i2p and someone could identity you from analyzing the network for long enough

MigratingtoLemmy@lemmy.world · 6 pts · 1y

TOR is obvious too to someone snooping on your network, unless you're using bridges (and that's hit or miss). If you don't want someone to know you're using I2P, use OpenVPN and mask your traffic as HTTPS.

You're going to have to explain better about "I2P not masking your traffic" and especially about "someone identifying you" - timing attacks are possible in both cases and the I2P Devs have mitigations against it. Please provide sources which define how I2P is weaker and more susceptible to TOR against network forensics

tired_n_bored@lemmy.world · 1 pts · 1y

Not true. I2P actively tries to mask the traffic

ShortN0te@lemmy.ml · -1 pts · 1y (6 replies)

Nope, I2P is still vulnerable to timing attacks. https://en.m.wikipedia.org/wiki/Garlic_routing

C126@sh.itjust.works · 8 pts · 1y (3 replies)

You linked an article that doesn't say anything to back up your claim. Why do you say i2p is vulnerable to timing attacks?

ShortN0te@lemmy.ml · 2 pts · 1y (2 replies)

Garlic routing[1] is a variant of onion routing that encrypts multiple messages together to make it more difficult[2] for attackers to perform traffic analysis and to increase the speed of data transfer.[3]

First sentence. Check up the linked article as source.

C126@sh.itjust.works · 2 pts · 1y (1 reply)

Ok, technically still vulnerable in the sense that if you transfer a huge file in excess of other parts of the bundle, it might be identifiable by a bad actor, but that's really misleading, since i2p has a lot of built in logic that makes that scenario pretty unlikely.

ShortN0te@lemmy.ml · 2 pts · 1y

Not only huge files. At the end of the article the author goes on about changing the load or manipulating the timing of the traffic.

For both you need to be part of the network and (to some degree) the traffic you want to trace needs to go through a node you are controlling if i understand it correctly. With increasing size it becomes more difficult.

EherNicht@feddit.org · 1 pts · 1y (1 reply)

I would also like to see prove for your claim.

ShortN0te@lemmy.ml · 2 pts · 1y

Garlic routing[1] is a variant of onion routing that encrypts multiple messages together to make it more difficult[2] for attackers to perform traffic analysis and to increase the speed of data transfer.[3]

First sentence. Check up the linked article as source.

ExtremeDullard@lemmy.sdf.org · 46 pts · 1y (17 replies)

The TOR network itself is safe - at least assuming the TLAs don't control at least half of the nodes, which is far from impossible. But let's assume...

The weak point comes from the browser: that's how the fuzz deanonymizes users. The only safe browser to use on TOR is the TOR browser, and that's the problem: it disables so many unsafe functionalities that it's essentially unusable on a lot of websites. So people use regular browsers over TOR, the browser leaks identifying data and that's how they get caught.

Trainguyrom@reddthat.com · 11 pts · 1y

I mean, the advice I've heard for one who's threat model is "the feds are actively trying to identify me" is to have a dedicated burner computer that you do all of your illegal activities on and no other activities. Then of course on top of that avoid saving secrets onto the device and type them in manually every time (ephemeral distros like Tails are good for that)

delirious_owl@discuss.online · 11 pts · 1y (3 replies)

My understanding is that Tor Browser works fine, there's just some dumb website owners that block Tor traffic by IP address.

CCRhode@lemmy.ml · 15 pts · 1y (2 replies)

And ... guess what ... www.bleepingcomputer.com, the source of the story, is one of those.

delirious_owl@discuss.online · 10 pts · 1y (1 reply)

Maybe email them and let them know about the misconfiguration

Let them know that tor users can't read their article about Tor

CCRhode@lemmy.ml · 1 pts · 1y

CRhode

Done!

chappedafloat@lemmy.wtf · 1 pts · 1y (11 replies)

Do you think it's better to use a VPN if you aren't using TOR Browser?

schnurrito@discuss.tchncs.de · 15 pts · 1y (10 replies)

All VPNs do is change who has your browsing data: your ISP or the VPN operator. You may or may not trust either of them not to keep records, in either case you have no way of verifying this.

HelixDab2@lemm.ee · 17 pts · 1y (9 replies)

ISPs definitely keep records. At least some VPNs claim that they don't, and that their networks are set up in such a way that they can't. Some organizations claim to validate the claims of the VPNs, but it's unclear if they're trustworthy.

So your choice is to use something that definitely keeps logs, or to use a company that at least says that they don't/can't.

communism@lemmy.ml · 8 pts · 1y (3 replies)

Yes, and there's also the fact that some VPNs such as Mullvad let you be anonymous so even if Mullvad were keeping logs, if you pay privately they have no way of knowing whose logs they are (unless the content itself of your internet history reveals your identity). Meanwhile your ISP definitely knows who you are, and absolutely will collaborate with the police if asked to.

electric_nan@lemmy.ml · 10 pts · 1y (2 replies)

You can pay anonymously, but if you regularly connect from your home IP address, it hardly matters.

sunzu2@thebrainbin.org · 1 pts · 1y (1 reply)
[ removed ]
electric_nan@lemmy.ml · 1 pts · 1y

Yeah I use mullvad for mostly that reason myself.

possiblylinux127@lemmy.zip · 6 pts · 1y (3 replies)

The VPN company themselves may not keep logs. However, they might be a little black box somewhere in the data center...

NauticalNoodle@lemmy.ml · 7 pts · 1y (2 replies)

As Proton made evident, VPNs can be legally compelled to start keeping logs on specific accounts as the result of a court order. So if you're gonna do something incriminating, then I guess you should create a new account each time.

orcrist@lemm.ee · 5 pts · 1y (1 reply)
[ removed ]
Crashumbc@lemmy.world · 2 pts · 1y

Yeah, VPN at the very least adds another hoop they have to jump through.

tired_n_bored@lemmy.world · 1 pts · 1y

That's exactly the reasoning I did for choosing a VPN. I know that VPNs are falsely advertised as "anonymous black magic" but better Proton or Mullvad than my ISP which definitely sells data to advertisers

h4lf8yte@lemmy.ml · 28 pts · 1y (5 replies)

As I read, they used timing analysis which should be preventable by using an anonymous VPN to connect to tor and streaming something over the VPN connection at the same time. Some of them support multi-hop, like mullvad, which will further complicate the timing analysis because of the aggregated traffic.

hate2bme@lemmy.world · 5 pts · 1y (4 replies)

How do you get an anonymous VPN? I see mullvad has a pay in cash option. Is that how?

Katzastrophe@feddit.org · 3 pts · 1y

You literally put the money + a piece of paper with your account number into an envelope and mail it to them

h4lf8yte@lemmy.ml · 3 pts · 1y

Yes exactly and some providers also accept crypto.

qwerty@discuss.tchncs.de · 2 pts · 1y (1 reply)

Mullvad accepts monero, that's probably the most convenient way to pay for it anonymously.

hate2bme@lemmy.world · 1 pts · 1y

I forgot about that.

sumguyonline@lemmy.world · 25 pts · 1y (2 replies)

First, randomize your mac, shutdown anything that can "dial home" (updates, sync, logged in apps, etc) then connect to internet then anonymous VPN, then connect to the tor network, use an anonymized browser with NO java enabled, never download anything -copy paste text, and screen cap images-, if your network drops the popo's are trying to do a "reconnect" attack to see if they can get an unprotected connection to the material you were looking at. Use a livedisk on USB and you likely won't get bios level attacks, as live disks make it harder to access your bios. Source: a boring ass individual that just wants the gov off their jock strap, suck it Joe my FBI agent, you know what you did.

PM_Your_Nudes_Please@lemmy.world · 10 pts · 1y

This looks like it was a timing analysis attack. Basically, they’re trying to figure out which user did something specific. They match the timing of the event with the traffic from the user, and now they know which user did the thing.

It can be fuzzed by streaming something at the same time, because now your traffic is way harder to time analyze when you have a semi-constant stream of data running. But streaming something over Tor is an exercise in patience, (and it’s not something the typical user will just always have running in the background) so timing analysis attacks are gaining popularity.

sunzu2@thebrainbin.org · 5 pts · 1y
[ removed ]
MigratingtoLemmy@lemmy.world · 22 pts · 1y (19 replies)

If I understand correctly, stream isolation will route different connections through different circuits. If you're doing two different things of a sensitive nature, open different browsers and applications, use random user-induced delays in your actions/responses and PGP-encrypt everything. And listen to what the TOR project says about the mitigations. I have some reading to do myself I guess

chappedafloat@lemmy.wtf · 7 pts · 1y (1 reply)

whonix docs is very good to learn about this stuff

delirious_owl@discuss.online · 3 pts · 1y

Heh, whonix docs for privacy have become the arch wiki for Linux

possiblylinux127@lemmy.zip · 1 pts · 1y (16 replies)

PGP? That's for email and isn't great

MigratingtoLemmy@lemmy.world · 7 pts · 1y (15 replies)

That's for encrypting text, regardless of the medium. Explain "not very good"?

unconfirmedsourcesDOTgov@lemmy.sdf.org · 7 pts · 1y (4 replies)

Well it's not very good, it's just pretty good.

MigratingtoLemmy@lemmy.world · 3 pts · 1y (3 replies)

Possiblylinux127 seemed like he had founds faults in PGP's encryption which got me interested

unconfirmedsourcesDOTgov@lemmy.sdf.org · 3 pts · 1y (2 replies)

Oh, I was just interested in making a pun based on the name. 😂

To be perfectly honest I was under the impression that we had collectively bailed on PGP in favor of GPG, but based on the Wikipedia article it seems like PGP is still getting updates so maybe that's not the case?

MigratingtoLemmy@lemmy.world · 3 pts · 1y (1 reply)

PGP is the protocol, GPG is the implementation. People tend to use GPG because it is FOSS.

unconfirmedsourcesDOTgov@lemmy.sdf.org · 2 pts · 1y

Thank you for distilling that down, cleared up all of the confusion I had. Cheers.

possiblylinux127@lemmy.zip · 1 pts · 1y (9 replies)

It uses the same public key unless you manually change it. You don't get the rolling keys provided by other systems

MigratingtoLemmy@lemmy.world · 2 pts · 1y (8 replies)

I don't think I understand what you're implying. Are you arguing that PGP implements less secure operations because it doesn't have perfect forward secrecy? As far as I know there's not much out there in terms of encryption schemes for data at rest which includes PFS. Even AGE didn't have it last time I checked. If you know about something that does provide PFS for data at rest, let me know

possiblylinux127@lemmy.zip · 1 pts · 1y (7 replies)
MigratingtoLemmy@lemmy.world · 1 pts · 1y (6 replies)

This is a good read. I think it's a good solution if it can be implemented properly. Are there applications you know of that allow you to personally (manually) encrypt text and communicate with another person like GPG does?

possiblylinux127@lemmy.zip · 1 pts · 1y

https://simplex.chat/

https://signal.org/

You should not be doing manual communications as that opens the door for human error and is time consuming. Also these cryptography protocols are far to complex to easily be used for text.

some_guy@lemmy.sdf.org · 19 pts · 1y

I have considered Tor safe for illicit activities for at least half a decade. Luckily, there's no need for me to be on there. But this is bad news for people living in places where speech is heavily regulated plus journalists and would-be whistle-blowers.

autonomoususer@lemmy.world · 10 pts · 1y (17 replies)

What else you going to use?

Prunebutt@slrpnk.net · 25 pts · 1y (16 replies)

I wish more people would try out I2P as a result. AFAIK, garlic routing makes this kind of attack impossible.

SplashJackson@lemmy.ca · 10 pts · 1y (1 reply)

Insane 2lown Posse?

ShortN0te@lemmy.ml · 10 pts · 1y (1 reply)

AFAIK it only makes it harder not impossible.

Prunebutt@slrpnk.net · 1 pts · 1y

At least they can't utili'e the applied tactic to host their own node.

HelixDab2@lemm.ee · 1 pts · 1y (1 reply)

I've tried to use it, but have not managed to get it to work. Which is a bummer.

I should probably try again now that I have a new computer. My old computer was so old that a lot of stuff wasn't working correctly.

Prunebutt@slrpnk.net · 5 pts · 1y

Remember that you need to let the server run for a bit, so it can establish , the routes.

I have a service constantly running on my server. When I want to browse, I tunnel the ports to my laptop.

possiblylinux127@lemmy.zip · 1 pts · 1y (9 replies)

We use it but it doesn't have the same protections or reliability as Tor

MigratingtoLemmy@lemmy.world · 3 pts · 1y (8 replies)

Really? Care to explain?

possiblylinux127@lemmy.zip · 1 pts · 1y (7 replies)

Check the FAQ

Also it lacks the more advanced features of Tor

MigratingtoLemmy@lemmy.world · 1 pts · 1y (6 replies)

Please mention the "advanced features" it lacks compared to TOR. I have read the FAQ

possiblylinux127@lemmy.zip · 1 pts · 1y (5 replies)

You can't use snowflakes and it can't pretend to be https

MigratingtoLemmy@lemmy.world · 2 pts · 1y

Use OpenVPN configured to look like HTTPS if you really need it. I2P is meant to be its own network, not a gateway to the clearnet. I still do not see how it has less measures in place for privacy and anonymity.

possiblylinux127@lemmy.zip · 9 pts · 1y

What are you going to use instead?

Tor is the best tool you just need to know how to use it

endofline@lemmy.ca · 7 pts · 1y

I think the only still secure network is i2p. In there you don't have the exit node