Author Topic: It's official: TOR has been compromised  (Read 1910 times)

Balog

  • Unrepentant race traitor
  • friends
  • Senior Member
  • ***
  • Posts: 17,774
  • What if we tried more?
It's official: TOR has been compromised
« on: January 27, 2014, 12:49:53 PM »
http://arstechnica.com/security/2014/01/scientists-detect-spoiled-onions-trying-to-sabotage-tor-privacy-network/

Some of the exit node computers are carrying out Man in the Middle attacks on the TOR traffic going through them. Article says it's "unlikely" to be NSA et al. I would be highly surprised if they weren't doing something similar but just tracking everything instead of interfering with it.
Quote from: French G.
I was always pleasant, friendly and within arm's reach of a gun.

Quote from: Standing Wolf
If government is the answer, it must have been a really, really, really stupid question.

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: It's official: TOR has been compromised
« Reply #1 on: January 27, 2014, 12:57:00 PM »
http://arstechnica.com/security/2014/01/scientists-detect-spoiled-onions-trying-to-sabotage-tor-privacy-network/

Some of the exit node computers are carrying out Man in the Middle attacks on the TOR traffic going through them. Article says it's "unlikely" to be NSA et al. I would be highly surprised if they weren't doing something similar but just tracking everything instead of interfering with it.

It's known that Tor exit nodes are poisoned.
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.

Waitone

  • friend
  • Senior Member
  • ***
  • Posts: 3,133
Re: It's official: TOR has been compromised
« Reply #2 on: January 27, 2014, 08:22:09 PM »
I thought it was known that exit nodes were open and that if you land on one you got a problem if a bad guy is monitoring it.
"Men, it has been well said, think in herds. It will be seen that they go mad in herds, while they only recover their senses slowly, and one by one."
- Charles Mackay, Scottish journalist, circa 1841

"Our society is run by insane people for insane objectives. I think we're being run by maniacs for maniacal ends and I think I'm liable to be put away as insane for expressing that. That's what's insane about it." - John Lennon

French G.

  • friend
  • Senior Member
  • ***
  • Posts: 10,200
  • ohhh sparkles!
Re: It's official: TOR has been compromised
« Reply #3 on: January 27, 2014, 08:39:15 PM »
Okay, not a computer geek here. What do I need TOR for anyway? Assume I buy a used laptop for cash F2F or at a pawn shop. Then I use public free WiFi, never from my home. I don't post here or to social networks and I have a discrete e-mail that I do not contact my normal people with. Assuming I can figure out how to set up some form of online money without Id'ing myself am I not good to go? Not really sure how to pull of the money stunt. The other would be the where of hard products being shipped to. Hmm...
AKA Navy Joe   

I'm so contrarian that I didn't respond to the thread.

drewtam

  • friend
  • Senior Member
  • ***
  • Posts: 1,985
Re: It's official: TOR has been compromised
« Reply #4 on: January 27, 2014, 08:58:46 PM »
Okay, not a computer geek here. What do I need TOR for anyway? Assume I buy a used laptop for cash F2F or at a pawn shop. Then I use public free WiFi, never from my home. I don't post here or to social networks and I have a discrete e-mail that I do not contact my normal people with. Assuming I can figure out how to set up some form of online money without Id'ing myself am I not good to go? Not really sure how to pull of the money stunt. The other would be the where of hard products being shipped to. Hmm...

I am not an IT expert, but I think these things are true...

Your MAC address is leaving a trail.
Your IP address is leaving a trail.

If someone were to investigate it, they would know to check the traffic from your 3 common wifi hot spots that you consistently surf from. A seized laptop can be positively identified with the MAC address. And all of the traffic is coherent (maybe not the right word), on one channel (again, probably not the right word for what I have in mind) so its easier for a snooper to observe what communication is being done.
I’m not saying I invented the turtleneck. But I was the first person to realize its potential as a tactical garment. The tactical turtleneck! The… tactleneck!

Firethorn

  • friend
  • Senior Member
  • ***
  • Posts: 5,789
  • Where'd my explosive space modulator go?
Re: It's official: TOR has been compromised
« Reply #5 on: January 27, 2014, 11:47:32 PM »
I am not an IT expert, but I think these things are true...

Your MAC address is leaving a trail.
Your IP address is leaving a trail.

If someone were to investigate it, they would know to check the traffic from your 3 common wifi hot spots that you consistently surf from. A seized laptop can be positively identified with the MAC address. And all of the traffic is coherent (maybe not the right word), on one channel (again, probably not the right word for what I have in mind) so its easier for a snooper to observe what communication is being done.

Exactly.  The important part is that TOR masks *LOCATION*.  If the feds or foreign equivalent* can't even be sure you're in the country, they can't track you down.  If I know you're doing something illegal, even if I don't know your name, but I DO know which of 3 hotspots you frequent, I can wait until I know you're in one of them then have the team roll to pick you up.  Heck, I could get a warrant to have a monitoring device on the coffee shop's router so I know when you connect

*Remember, TOR was originally intended to be a way to get unfiltered internet access