Belarus finally bans Tor
ooni.torproject.org
ooni.torproject.org
Great read, especially the annotated version: http://fermatslibrary.com/s/examining-how-the-great-firewall...
Edit: thanks!
Probed ISPs: Beltelecom (AS 6697)
Censorship method: TCP injections
We have recently heard of network anomalies in Belarus. Tor has been finally blocked in December 2016, although it had been explicitly declared that Tor should be blocked since February 2015.
Directly connected users from Belarus
An anonymous cypherpunk has helped to gather some evidence regarding Tor being blocked in Belarus. It’s neither a complete study nor an in-depth research and it’s unclear if any other further evidence will be gathered, so we decided to share current knowledge as-is:
Tor directory authorities are not blocked Public onion routers have their ORPort blocked by TCP RST injection The onion routers’ DirPort is not blocked Plain-old non-obfuscated Tor Bridges from BridgeDB circumvent the interference Beltelecom (or its upstream) has strange configuration of the networking gear injecting reset packets The strangeness in equipment is the following. The first injected RST packet does not have have proper SEQ/ACK numbers. These packet fields are just filled with zeroes. So this packet is dropped by the client’s TCP/IP stack per RFC5961 and does not actually terminate the client’s connection:
$ tshark -Tfields -eframe.time_relative -eip.src -etcp.srcport -eip.dst -etcp.dstport \ -eip.ttl -etcp.flags.str -etcp.seq -etcp.ack -r urandom.pcap | sed | awk | perl 0.000000 192.168.1.2 42555 87.118.94.227 443 64 S* 899897236 0 0.029459 87.118.94.227 443 192.168.1.2 42555 125 R* 0 0 (sic!) 0.096914 87.118.94.227 443 192.168.1.2 42555 52 AS 1984028404 899897237 0.096958 192.168.1.2 42555 87.118.94.227 443 64 A* 899897237 1984028405 0.136874 87.118.94.227 443 192.168.1.2 42555 125 R* 1984028405 0
That’s all for today. Remember, fried potato is better with onion!
Probed ISPs: Beltelecom (AS 6697)
Censorship method: TCP injections
We have recently heard of network anomalies in Belarus. Tor has been finally blocked in December 2016, although it had been explicitly declared that Tor should be blocked since February 2015.
Directly connected users from Belarus
An anonymous cypherpunk has helped to gather some evidence regarding Tor being blocked in Belarus. It’s neither a complete study nor an in-depth research and it’s unclear if any other further evidence will be gathered, so we decided to share current knowledge as-is:
Tor directory authorities are not blocked
Public onion routers have their ORPort blocked by TCP RST injection
The onion routers’ DirPort is not blocked
Plain-old non-obfuscated Tor Bridges from BridgeDB circumvent the interference
Beltelecom (or its upstream) has strange configuration of the networking gear injecting reset packets
The strangeness in equipment is the following. The first injected RST packet does not have have proper SEQ/ACK numbers. These packet fields are just filled with zeroes. So this packet is dropped by the client’s TCP/IP stack per RFC5961 and does not actually terminate the client’s connection:
$ tshark -Tfields -eframe.time_relative -eip.src -etcp.srcport -eip.dst -etcp.dstport \
-eip.ttl -etcp.flags.str -etcp.seq -etcp.ack -r urandom.pcap | sed | awk | perl
0.000000 192.168.1.2 42555 87.118.94.227 443 64 **********S* 899897236 0
0.029459 87.118.94.227 443 192.168.1.2 42555 125 *********R** 0 0 (sic!)
0.096914 87.118.94.227 443 192.168.1.2 42555 52 *******A**S* 1984028404 899897237
0.096958 192.168.1.2 42555 87.118.94.227 443 64 *******A**** 899897237 1984028405
0.136874 87.118.94.227 443 192.168.1.2 42555 125 *********R** 1984028405 0
That’s all for today. Remember, fried potato is better with onion!Hope you still have access to archive.org ;)
Country: Belarus
Probed ISPs: Beltelecom (AS 6697)
Censorship method: TCP injections
We have recently heard of network anomalies in Belarus. Tor has been finally blocked in December 2016, although it had been explicitly declared that Tor should be blocked since February 2015.
Directly connected users from Belarus
An anonymous cypherpunk has helped to gather some evidence regarding Tor being blocked in Belarus. It’s neither a complete study nor an in-depth research and it’s unclear if any other further evidence will be gathered, so we decided to share current knowledge as-is:
Tor directory authorities are not blocked
Public onion routers have their ORPort blocked by TCP RST injection
The onion routers’ DirPort is not blocked
Plain-old non-obfuscated Tor Bridges from BridgeDB circumvent the interference
Beltelecom (or its upstream) has strange configuration of the networking gear injecting reset packets
The strangeness in equipment is the following. The first injected RST packet does not have have proper SEQ/ACK numbers. These packet fields are just filled with zeroes. So this packet is dropped by the client’s TCP/IP stack per RFC5961 and does not actually terminate the client’s connection:$ tshark -Tfields -eframe.time_relative -eip.src -etcp.srcport -eip.dst -etcp.dstport \ -eip.ttl -etcp.flags.str -etcp.seq -etcp.ack -r urandom.pcap | sed | awk | perl 0.000000 192.168.1.2 42555 87.118.94.227 443 64 S* 899897236 0 0.029459 87.118.94.227 443 192.168.1.2 42555 125 R* 0 0 (sic!) 0.096914 87.118.94.227 443 192.168.1.2 42555 52 AS 1984028404 899897237 0.096958 192.168.1.2 42555 87.118.94.227 443 64 A* 899897237 1984028405 0.136874 87.118.94.227 443 192.168.1.2 42555 125 R* 1984028405 0
That’s all for today. Remember, fried potato is better with onion!
The Onion
archive.org archive.is archive.today archive.fo webcache.googleusercontent.com
edit: in the interests of clarification, this means I expect to see attacks on Tor within the US before the UK.
TOR actually amplifies the asymmetry betweem the NSA and smaller actors: the NSA by owning the whole network can easily break it, but it prevents smaller players from getting the same access.
Of course, the FBI seem to routinely compromise TOR sites they don't like.
How does Raspberry Pi help here? If it routes traffic at IP level, it will be transparent at an application level. Firewall/IDS won't help against zero days either.
It is just one potential brick in your security wall.
1) Pi only supports about 6MB/s on its ethernet port, meaning that you get 3MB/up and 3MB/down
2) TOR itself is just super slow, so why am I paying for a 350Mbps connection?
3) Most VPN services are fast enough for the above bandwidth, and offer sufficient security against state-based snooping.
They also claim Silk Road was classical hacking, but given what we know of parallel construction and their vagueness in describing their locating of the servers, we can't really know what happened there.
Kinda like the Berlin Wall. Easier to shoot people attempting to cross than hermetically seal the entire border.
From a quick search it seems a shot at Belarus' desire to ban Tor back in 2015 but only now achieving it.
Checking the certificate details, I found out that the certificate is issued to the organization "OpenDNS, Inc." I use OpenDNS's family safety DNS.
I don't think that TOR is owned by OpenDNS. Is it possibly that OpenDNS is MITMing me like previously Avast was reported? But how is that possible? I don't have any OpenDNS software installed that could change certificates.
Belarus laws and politics had been for a long time a playground for Russia. Kinda "before implementing it for all users in production, let's try it on a smaller audience to see if it works or not."
So this ban is mostly an exercise for Russia, to get some experience.
That's my understanding of the document http://www.pravo.by/main.aspx?guid=12551&p0=T21503059&p1=1&p...
Moreover, in this particular case there are facts which don't fit into the idea that Russia first experiments in Belarus. For example Russia has a regulation that personal info of user should be stored inside the country (LinkeIn was banned recently for not obeying this regulation). There is no such regulation in Belarus. If Russia was experimenting first in Belarus they would try it here first.
Also, there is Chinese experience to study, I don't see any need for additional experiments.
So, it's nothing more than a conspiracy superstition.
So you're now saying China's firewall is also a Russian experiment?
> So, it's nothing more than a conspiracy superstition.
Well, we do know that state sponsored internet trolls exist and have done for some time. They are not always subtle, but that doesn't mean that they are not very successfully subtle also.
I read an interesting article recently (though I can't find it now, sorry), which made an attempt to guess the number of such trolls on a country by country basis. Any comment either enhancing or detracting from a national reputation is suspect now, I fear.
And I apologize in advance if my evidence is actually on topic and doesn't have funny pictures.
[1]https://techcrunch.com/2016/12/05/section-702-mohamud-appeal...
so they sit, they listen, then do what exactly?
Someone has to read through the material, decipher it, translate it, interpret it. and how exactly do you act on it?
its also only really a problem for americans. since the us government is paying to ensure other countries governments cant interfer with free communication.
its a matter of opinion wether they also managed to gain the ability to interfere with free communication themselves.
but since the "Next best alternative" is ssl/tls.
kinda a moot point.
But yeah, no mention of TOR in that article.
And many in Belarus said the country’s reputation as Europe’s last dictatorship is no hindrance to their work. “Success stories and a business’s scalability are more important than politics,” said Nick Vyhouski [...]
Charming.
Besides, law enforcement never just "takes your word for it". I've got a lot of friends in law enforcement and -- as far as "suspects" go -- they'll pretty much (attempt to) verify every claim you make.
I don't know how the system works in Belarus so I understand it may not really matter there. The point is that it's going to be difficult to prove that the accused made an intentional connection to Tor as long as the accused and/or his/her lawyer has some technical literacy and knows what to say.
Ostensibly the term is meant to imply that the players there have about as much capability of thought as a potato.
Wat een aardappel! "What a dummy!"
Same in France with "patate". Funny to notice that the more common French expression for "potato" is "pomme de terre" ("apple of earth"), just like in Dutch!
Though in the south (both south NL and Flemish Belgium) they're called "friet", as in "gefrituurd" ("fries" as in "they're fried"). Still, patat is officially Dutch and according to some website 95% of the Flemish people and 100% of the Dutch people know the word.
(... which nobody gets.)
Onion = Onion Router
... and this is why they lifted the restriction early.
It's strange to me that so many people heard "just for a week" as "forever" and are continuing to comment as if those mean the same thing. The internet is weird.
I would be comparing a) data after the first announcement b) data after your comment in an unrelated thread saying the experiement is over c) data after the week is over and d) data after you write the promised lessons learnt post.
Making an announcement a la Tell HN doesn't necessarily disseminate information. In this case it would almost certainly turn into a huge rehash of the original argument, with new information getting drowned out in the process. There are so many counterintutive effects to this, and we're still learning--indeed I feel like we're still taking baby steps. Turning up the volume definitely doesn't necessarily turn up the communication.
I see nothing about security or routing technology, just reportage on the actions of a government - politics.