Why the Tor attack matters
blog.cryptographyengineering.com
blog.cryptographyengineering.com
I do wish both sides would acknowledge this is a tricky issue. On the one hand, if I run a tor exit node or relay, it is my node and it seems like I'm allowed to do with it as I please. At the same time, it also seems obviously unethical (maybe illegal?) to be harvesting passwords off an exit node or to dole out vigilante justice to Tor users I don't like.
One other thing to keep in mind here is that SEI is a DoD funded center. It may be nominally affiliated with CMU, but all their money comes either from the DoD or external grants awarded to the researchers at SEI. So CMU the private research university and SEI the DoD-funded research center have very different obligations to the public. It's important not to conflate the two.
The big question is this: what are our responsibilities as security researchers, especially when we're working on "live" software systems? Green seems to be suggesting some form of a review board which pre-approves experiments on live targets. Maybe this is what we need, but be careful what you wish for though. The bad guys don't have review boards.
If the SEI took money to, essentially, weaponize unpublished research, the issue is not one an IRB would have prevented. DoD contractors aren't bound by scientific codes of conduct. In light of that realization, the suggestion in this blog post is confusing.
(BTW, distancing CMU and the SEI is not meant as a defense of CMU -- close ties between public science and law enforcement/military R&D are as troubling as ever...)
Here's why it's worse: they inserted a plaintext encoding into the response from the onion-address lookup relay, and so anybody observing the user (e.g. the ISP) could detect what onion address the user was connecting to. This applies after the fact to recorded traffic as well. Thus the researchers had no control over who got deanonymized, to whom they were deanonymized, and when they were deanonymized.
> I do wish both sides would acknowledge this is a tricky issue. On the one hand, if I run a tor exit node or relay, it is my node and it seems like I'm allowed to do with it as I please.
You actually are not allowed to do with your relay as you please. At least in the US, the legal theory protecting relay operators (i.e. safe harbor) also makes it illegal to observe user traffic content except in certain cases (e.g. to improve network performance).
> One other thing to keep in mind here is that SEI is a DoD funded center.
This doesn't seem very relevant. All researchers have an obligation to consider and mitigate possible harms that occur during their research (source: I work in a military research laboratory). These researchers clearly did not fulfill that obligation, and I'm sure their institution is reviewing or has reviewed their procedures to make sure it doesn't happen again.
Are you saying the problem here is simply that the effects of the attack were observable by others? If this were not the case, you'd have been fine with it?
And since you seem to be arguing that researchers shouldn't examine user traffic, do you also think that what Egerstad did was also wrong? Do you agree with his arrest?
And one more thing sort of related to this. What's your opinion on research like Arvind's Netflix deanonymization attack? Do you think the work that research involved was also unethical?
> All researchers have an obligation to consider and mitigate possible harms that occur during their research
This is nice idealism and I'm totally in support of it. But I can't help think this is pie-in-the-sky thinking, especially when organizations like the DoD are involved.
Worse: there's a view that people who get owned "deserved it." Our industry, and its academic attachments, have a really strange vindictive streak towards those who it should be looking out for. (Which is not to say that those people should be looking out for people swapping child porn--but what about the thousands and thousands of people who were not?)
"A traffic confirmation attack is possible when the attacker controls or observes the relays on both ends of a Tor circuit and then compares traffic timing, volume, or other characteristics to conclude that the two relays are indeed on the same circuit. If the first relay in the circuit (called the "entry guard") knows the IP address of the user, and the last relay in the circuit knows the resource or destination she is accessing, then together they can deanonymize her."
Interesting technical problem. They patched it, obviously, but similar attacks are still possible. It does say more research needs to be done, when that post was published. Obviously the method they used to send and receive signals from one side to the other doesn't work anymore, but statistical methods presumably do. Sort of like this:
https://mice.cs.columbia.edu/getTechreport.php?techreportID=...
Seems like a very difficult problem to solve.
which means little given the laws of nature, all that matters is what people end up doing and measuring that statistically. If statistically speaking most people aren't ethical then that's what we'll get. This whole idea that people are in control of their actions or have any freedom whatsoever given what we know about the laws of nature has to go.
I'm not actually sure this isn't sarcasm.
In my opinion, this is a wakeup call for the Tor Project. The attack would have been obvious if they'd been tracking the requisite circuit parameters. Ironically enough, it strikes me that the Tor network needs something like CERT for detecting attacks.
Sure. And we can also-- for the purpose of thinking about risks-- assume that if a government can torture people, they will.
This doesn't make it right, and it doesn't mean that people should sit idly by. Nor does the fact that people oppose and discourage such actions mean that systems can be left vulnerable to these attacks.
Opposing unethical and abusive behavior is not mutually exclusive with building systems which are robust even against unethical attackers. Human wellbeing is maximized when we do _both_.
For example, it is equally a understood that almost any government could control/manipulate any press agency if they wanted to, or break down any door with a SWAT team.
The only difference here is that `cyber` did not exist nor is cleanly appliciable to laws wich limits this type of power - laws largely written in the 1800s. Additionally it largely happens in secret, attribution is difficult, and there is a serious knowledge gap from the general public and the type of operations being done.
https://www.reddit.com/r/IAmA/comments/3sf8xx/im_bill_binney...
Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can randomly launch DDOS attack against some company and then claim "Research". This is equivalent to those youtube videos where at the end they justify assault and other egregious behaviour claiming "Social experiment" or "Prank".
Given what the Tor project thinks to be, it needs smart people to poke it.
The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.
less flippant answer—because he's probably had problems with people stealing his answers and posting them on other forums or similar issues.
All comments Copyright © 2009, 2010, 2011, 2012, 2013, 2015, 2018, 2023 Thomas H. Ptacek, All Rights Reserved.
Actually, from a security perspective, its quite understandable. If you provide a tool that claims to be safe from state actors, they can use that kind of power to attack it.
That said, if it didn't pass the usual protocols at the university for ethical standards they can and should be fired regardless of the client or reason.
While Patrick seemed to be focusing on the abstract notion of security mechanisms needing to welcome malicious scrutiny, the strong reaction against his tweet was based on the observation that Patrick failed to take into account the real, human cost of such an attack. This was further compounded by the fact that often, research requires IRB approval to determine whether the research is ethical, and the evidence is that CMU's actions weren't ethical. Yet Patrick felt it necessary to opine without understanding the ethical component of such an attack.
> Tor is having a fit of institutional pique that researchers are compromising the network's privacy guarantees by, well, looking at it.
> If you write security software, and you're not praying that loyal opposition hits you with everything they've got, you're not doing security
> Tor is intended to be, and is marketed as, robust against nation state adversaries. It cannot possibly be so if it worries about academics.
Two interpretations:
1. It's OK to go after Tor. This is dead wrong - attacking a network without permission is very bad form. Maybe it's OK to do the equivalent of checking to see if someone's front door is locked (this is a grey area), but only if you intend to warn them that their door's unlocked. Going through their stuff is obviously unethical (and probably illegal).
2. Tor should be more permissive, encouraging more attacks from researchers.
Obviously, the researchers crossed the line when they started gathering user data. But Tor should only be upset that the attack went too far, not that the attack succeeded.
I'm not sure of the context - was the Tor community pissed off that researchers found a weakness, or pissed off that the weakness was exploited?
Twitter is a pretty poor platform if you want nuance, so it's probably best to be charitable in your interpretations of what people say there.
There has always been the possibility of bad actors being involved with Tor. In addition, the Tor software is complicated enough that there undoubtedly will be bugs in it.
This is "you bet your life" serious. However, both the architecture and the implementation of software must be perfect for that to succeed. It's pretty easy for one bug to mean "game over".
People using Tor just don't have a chance when it comes to dealing with the NSA, FSB, GCHQ or any similar state actors. Even allowing for inevitable government bureaucracy and incompetence, the disparity in resources can just be staggering. A big agency can easily, easily afford to devote 100 full time people to one high value target. Those are not odds I'd like to bet against.
In the bigger picture, the NSA doesn't give a rats ass about either Silk Road or about child pornography (at least I hope they don't). Which is why an "academic institution" was enlisted to help out the FBI with this.
But if I was a dissident or protester in Turkey, Syria, Russia, or any of a large number of authoritarian countries, I certainly wouldn't use Tor. Not if my life and the life of my family was at risk.