Tor Browser Exposed: Anti-Privacy Implantation at Mass Scale
hackernoon.com
hackernoon.com
I recommend you read this instead, which provides a more level-headed and technically correct analysis of the vulnerability (which was there, even if not properly in the terms described by OP):
https://hackernoon.com/postmortem-of-the-firefox-and-tor-cer...
[0] https://github.com/IndependentOnion/rotor-browser/commit/916...
[1] https://github.com/IndependentOnion/rotor-browser/issues/7
EDIT: s/Tor/Tor Browser/
I suspect that wasn't planned, but regardless, he did fork the "right" repo.
It's also a very pragmatic plan: rebooting the whole Tor relay/exit node community is going to be a long term project without clear gains in the end; if your replacement looks like Tor in that you continue to invite volunteers to run nodes if the previous set of nodes are compromised what prevents those nodes from joining your network too? Arguably better to focus on forking what you can fix, which is apparently the browser.
But that's all a charitable explanation: the less charitable explanation was he forked the browser because that's where the Tor branding is... Fork the relay codebase and you can't take pretty screenshots of your new fork.
Hahaha, what?
Still, I seem to recall that when the tor browser auto-update mechanism was deployed, the idea was that HTTPS with pinning was only the first step, and that going forward the updater would also check PGP signatures. It's a bit disappointing to see that hasn't happened yet.
Especially with reproducible builds and several trusted signers independently verifying the built binaries and signing the resulting package, this would add considerable security to the update process.
"Old news. This was fixed in 6.0.5.
https://blog.torproject.org/blog/tor-browser-605-released
Interesting note: The author is part of the rotor browser fork that is going no where so far. Doesn't look like the reported issue has been fixed there. In fact, no commits since before this blog post."
https://www.reddit.com/r/TOR/comments/53u1cd/tor_browser_exp...
6.0.5 was released five days ago. There is no universe where this qualifies as old news.
> I'd honestly suspect the author was COINTELPRO were it not for the fact that so many of his statements and code are literally laughable.
So there's that!
This didn't used to be a problem, as it was essentially run as a sandbox project for the academic anonymity community. It was very up front about its capabilities and limitations.
Unfortunately, in recent years, the US government has been bankrolling more "privacy" software development through its propaganda arms (OTF, RFA, etc.), and the Snowden revelations have led private foundations to follow suit.
As such, the organization doubled down on rebranding to be a "human rights" _tool_, as this is what grant giving organizations love to promote (free speech in Iran, activist publishing, etc.) This combined with a overly-enthusiastic do-gooders gaining more and more prominence in the Tor organization has led to the dangerous situation of promoting inherently insecure software as a security solution to vulnerable people. This is a general problem in the scene (remember when those activists in South America got vanned for using CryptoCat?) - and one that I've been guilty of myself in the past.
I really hope the new boards steers them back to the academic realm and slaps a big red USE AT YOUR OWN RISK warning on the tin. Unfortunately, I think the opposite will happen.
TOR is still a valid tool. No, it wasn't designed to foil NSA level surveillance, because it was built by the US. But this vulnerability isn't even related to TOR, it has to do with the TOR Browser.
The Snowden leaks contain slides where the NSA clearly laments the use of TOR, so saying that it never has been trustworthy is simply not true.
Re: The NSA Tor slides - they're really not as damning as you say - http://i.imgur.com/cnOeVQf.png - and they're also made before the FBI was caught using remote code execution exploits against Tor users.
How do you know what the development environment 'felt' like? Are you Roger Dingledine or Nick Mathewson?
And I doubt that you will find any evidence that it was used before being made public. Using TOR before it was public would be like screaming, "HEY I'M HIDING SOMETHING! AND I'M US MILITARY OR INTELLIGENCE!". The whole point of releasing it was to gather a userbase. Otherwise, TOR wouldn't be very anonymous at all.
Is it even possible to protect against end-to-end time correlation attacks without massively increasing latency?
It's been a couple years since I studied this, so I might be wrong.
When i was a kid a friend of my grand mother was arrested because a neighbor said he was a communist. He was tortured for a week and his party, kind of center/right wing took him out as they were a close party to the current government. Oppressive regimes usually don't need evidences.
A friend of mine was arrested for two years, accused for terrorism. The proofs? a war and peace copy (not even a photocopied book) and a guns and roses poster. And this was in "democracy"... so stupid proofs are also used, and whatever can be a proof, like a book about cubism was considered that was a book of cuba's ideology.
Tor has been for years looked by "regular"/"normal"/"common" people as a tool for drug dealers or child molesters. The switch to a human rights tool doesn't seem to really put it more into the illegal line.
Anyway, oppressive regimes do whatever they want, Tor can avoid some of the spying but if the state is already taking your computer you are screw up with Tor or without it.
And people on Pieter's side of this issue probably think it also logically follows to prevent that mental connection from happening in government officials' minds. Just gotta change how it's branded.
If it's as concepts, "human rights" triggers less alarms than anonymity, first because while I don't know which regimes you consider oppressive there is a big probability they themselves think they comply and/or promote human rights. Iran for example have a Islamic Human Rights Commission and proudly promote it. Israel would be another country that fits this example.
Then we have that anonymity could mean something it scares them the most, which is not human rights defenders but spying. Tor is already in a bad list for this reason, same as any anonymity software. The biggest threat those countries face is still military intervention or terrorism. A friend was arrested while taking pictures in Palestine, when questioned he was asked if he had Tor or i2p installed, PGP or any encryption software on his laptop. They didn't took his laptop away, but that was before the switch to "human rights" brand.
Then there is another vector we can take, Tor as circunvention. Another friend when visiting sudan got a pamflet to not use Tor, VPNs or Proxies when asked for the visa. The hotel made the same requeriment. This was 4 years ago. The reason was not that Sudan has been in the list of the worst human rights offenders but that you could access immoral content with it.
So, while I understand the point, it doesn't seem to have a backed reality to be sustained.
What is the inherently secure alternative available to these vulnerable people?
> I really hope the new boards steers them back to the academic realm and slaps a big red USE AT YOUR OWN RISK warning on the tin.
What causes you to believe that activists and vulnerable people would stop using Tor if this warning were in place?
This might not deter people from using Tor entirely, but at least they'd understand the threat model a bit better so they could change their behavior accordingly, for instance maybe not using it at their own home, not using it for Facebook, etc.
As much as we might want to believe that we can code our way out of anything, human rights demands more than software.
Just out of curiosity and for purely educational purposes (I admittedly know very little about the topic), how about something like I2P or FreeNet? Are these at all viable alternatives?
What other choices do we have for "anonymity" outside of the usual VPN/Proxy?
I like I2P as it has a reduced threat footprint compared to Tor as it's all internal, but it's also a smaller network, probably more vulnerable to Sybil, less audited code, etc.
Again, my point is that there is no perfect solution, it all depends on the situation and the requirements.
0: https://bugs.chromium.org/p/chromium/issues/detail?id=80722#...
I'm not sure I follow. Tor Browser is the default browser of both operating systems.
Note: This just answers the question about browsers or other pieces of software that don't allow control of their network components. It doesn't address a vulnerability in that software.
The whole situation can be worked around by using a custom prefs.js that disables auto updating addons (there are various other attacks that can be prevented by tweaking settings in about:config such as the webrtc related ones) and there are various websites providing privacy oriented prefs.js. A better workaround would be for the TOR browser maintainers to ship such a file with it, and a solution would of course be Mozilla fix things on their side.
1. You'd need to be able to MitM all of them (where controlling a ton of TOR exit nodes comes in handy)
2. You'd need to know an extension lots of people have (I'm guessing NoScript is default on TOR browsers)
At least when I connect to Microsoft, Google, Facebook, etc. I don't expect to get hit by a driveby JS exploit, and Google does help with "safe browsing".
With Tor, you're one HTTP website (or not HSTS website) away from a driveby virus, with no way to tell that you're connecting to a dangerous exit node
The problem is that people actually make money from malware. It's not bored college kids showing off skills. It's pros.
So think like a pro. You use a zero day to hack into Verizon to feed malware, get noticed, and your hack gets reversed after an hour.
You open an exit Tor node on a VPS, use it to feed malware, profit. They close it, you re-open it on another host. They play wack-a-mole, and you rake it in.
In any case, you can solve the problem of distributing software over Tor by setting up a hidden service. The Tor devs have been making noise for a while about creating an "onion service" that isn't hidden, but has the same guarantees as a hidden service (an improved version of exit enclaving).
Seriously? That seems like a really weird - to say the least - decision to make about something this important...
To be clear, I don't think it's so much a problem on Mozilla's part; perhaps manual review would be a good idea, but I doubt they have the resources. The problem here is that Tor Browser has claims made for it that aren't supported by the amount of work that's actually gone into making it secure. That would appear to be entirely on the people who run the Tor foundation, or whatever nonprofit structure it is that they use.
This is the joke right?