Exploiting the TOR-Browser
hackerfactor.com
hackerfactor.com
> Although the Tor Project could promote options to restrict these malicious actions, they choose to do nothing. Seriously: if a TOR hidden service offers hard-core drugs or human trafficking or fake IDs, then they should be shut down.
I hope I can convince some folks here to be skeptical of this kind of thinking.
Think about it: If the Tor project came up with some clever way to take down bad hidden services, then what would be stopping a government from forcing them to take down legitimate hidden services too? And meanwhile, the criminals would move on to some other Tor-like service, and keep doing their thing.
In short, you're not going to stop criminals, who will always find a way to keep doing what they're doing. You will, on the other hand, impede the free speech of honest users.
The Tor project should focus on making it impossible for hidden services to be taken down--even by the Tor project itself! And they do :)
In both freedom of speech and privacy, you have to be willing to support the rights of those people consider 'horrible' in order to help the greater population as a whole.
Letting people say whatever they want on the Internet does result in bullies, trolls, extremists and other horrible people talking louder than more thoughtful speech, and in the end it silences reasonable people.
There is no law that forces me as an individual to respect what you say or to not try to silence you.
Censorship can only be done by the government, not by individuals; no one should trust the unfair bully who cries unfairness at being silenced.
***
It's the silencing of obnoxious voices
that allows thoughtful voices to be heard.
***Merely because they don't (directly) have the power of law behind them, doesn't make them less dangerous than a government.
See how that works? "Horrible," "thoughtful," "reasonable"--as defined by you. Might-makes-right and the-ends-justify-the-means. Astounding hubris and a stubborn refusal to learn from history. And an apparent inability to reason from abstract principles.
This is why national borders (and federalism within national borders) are good: compartmentalization prevents damage from spreading. Without bulkheads, flooding easily sinks the whole ship.
It is ok if someone that doesn't understand it says those sorts of things, but when an organization like cloudflare[1] jumps on the goof-troop bandwagon, it really does make a difference.
They specifically built controls so that web sites can remove CAPTCHAs for Tor users completely.[0]
They also do not block/CAPTCHA Tor users automatically. They treat Tor IPs like any IPs: if they detect abuse from the IP, they start giving the CAPTCHA.
Finally, Cloudflare has stated publicly[1] that they have a desire to setup .onion sites for their customers automatically. But they cannot do so until the Tor project is able to upgrade the hashing algorithm used for .onion addresses. If the two organizations could work together, this could be game-changing for online anonymity. Imagine millions of web sites automatically supporting Tor!
I can't understand why the HN crowd is so anti-Cloudflare. This Tor thing seems to be one of the major misconceptions.
Disclaimer: I'm not affiliated with with either Tor or Cloudflare in any way.
[0] https://support.cloudflare.com/hc/en-us/articles/203306930-D...
In addition, their response to the memory leak issue a few months back left a bad taste in a lot of people's mouths. They attacked Google unfairly for not purging their leaked content fast enough, while trying to downplay the severity of the mistake they made.
I do not believe cloudflare on your first link (that they treat tor ips like any ips).
I can tell you from experience that I have never connected to a cloudflare backed site with tor that didn't require multiple captchas. So every tor ip is hostile to cloudflare sites? If so, how is that practically different than just blocking tor?
I think that if you read the response at your first link again, you can see that they are implying what you are saying, but that are not saying what you are saying. I think they are blocking tor, but explaining it in a diplomatic way.
> My link was a direct response to your second link.
Yes, and they only take issue with the the claim that 94% of Tor requests to Cloudflare are malicious. It's a shame that Cloudflare hasn't responded with the data they requested, and it's fair to hold that against them. But I'm also not aware of a response from Tor regarding Cloudflare's desire to make automatic SSL certificate generation possible for .onion addresses.
As a huge fan of both organizations, I wish they would act like adults and work together, rather than spend so much time pointing fingers.
> If so, how is that practically different than just blocking tor?
Because Cloudflare allows their web sites to disable CAPTCHAs for Tor if they choose to.
> I think they are blocking tor, but explaining it in a diplomatic way.
We'll have to disagree on that. The Cloudflare post outlines not one, but two ways that the two organizations could work together to solve the problem.
But again, I agree it would be great if Cloudflare would release more detailed data about the attacks they see from Tor.
OP blog post claims 96% of the traffic going to their tor hidden service is hostile. It doesn't seem unreasonable to me at all that every tor ip is hostile.
so you manually looked up the provider of every site you visited?
sounds like 100% of cloudflare sites that are configured to require captchas require captchas.
Mitigating abuse while supporting the TOR ecosystem is an open problem and they have certainly done more than any other CDN afaik to explore ways to allow legitimate TOR users past their firewall. Unfortunately, if I remember correctly the solution involves tracking IDs which can deanonymize users.
I had an idea a while back of a distributed, anonymous reputation system with rotating tokens. I still believe this is a better solution than the permanent tracking IDs currently used and maintained by other companies. It would return control to the user.
Cloudfare /did/ invest a lot of time communicating and trying to remedy the situations with the DDoS. The is evident in the amount of communication that can be found in the bugtracker.
The prescient Upton Sinclair: “It is difficult to get a man to understand something, when his salary depends on his not understanding it.”
I mean, yeah, it's not the early 1990s anymore, where mostly academics and enthusiasts were on the internet. But is the hacker manifesto a standard to hold infosec practitioners who likely were in diapers during the halcyon days you refer to?
Look, I agree that anonymity is important. I agree that the world is better if some things are kept absolutely private, from everyone, to whatever extent is possible. But let's not pretend that there aren't trade-offs.
I wish these values were more popular.
You could partially refute this argument by claiming that gun control is hard to ignore or bypass (although not that hard, speaking as someone who knows a fair amount about fabrication and guns).
On the other hand, this argument ported over to Tor doesn't make any sense; if Tor intentionally cripples its functionality, criminals will move over to non-crippled solutions like I2P. The best you can hope for is to mildly and temporarily inconvenience criminals while really hurting innocent people who need Tor.
> The things that makes TOR useful for people avoiding prosecution also makes it useful for people avoiding prosecution.
You lost me here.
https://www.wired.com/2017/01/half-web-now-encrypted-makes-e...
For example: https://www.ssllabs.com/projects/client-fingerprinting/
Anecdotally, I can tell you I have heard of ad tracking companies actively using this (for years now).
TLS versions tell you someone is one of a billion users of iOS version X; with HTTP they can piece together session cookies across every site and service you use, or with active attacks use things like the Verizon injected tracking code uniquely identifying you across devices.
Could you explain your reasoning on that? If they're using the Tor browser every user is going to be very similar on crypto suites, user-agent, etc. — it's a rebadged Firefox distributable so it's going to be using their HTTPS implementation and you won't even get the OS version variations unless someone at the Tor project massively screws up.
The bigger problem is that if you are being targeted by the website, there are far more interesting attacks they can try – convince the user to turn on JavaScript and do all of that profiling for WebGL/canvas rendering, local fonts, network resource timing to look for cached content from other sites, etc.
> unless someone at the Tor project massively screws up
And that is what the author of the article is claiming.
My comments here aren't in agreement with the author of the article, and I'm not claiming "HTTPS is bad" or anything like that. It's simply a categorical fact that HTTPS has more vectors to be fingerprinted than HTTP.
But of course, as you mentioned, features enabled by Javascript are the bigger problem, which is why users who wish to be anonymous should completely disable it!
That's a pretty small percentage of users for whom HTTPS isn't an across-the-board win for privacy.
> His research focus on anti-anonymity technologies combines fields as vast as ergonomics and child development to artificial intelligence and theoretical biophysics.
If it were possible to do this, TOR would lose any shred of value it has for people using it to fight oppression.
Ok, let's say we put technology in place to "shut down" sites that sell fake IDs to teenagers (god forbid!).
Well now, Mr. Lawman from the U.K. or China is going to come in and say "hey, wait a minute, you can shut down websites that illegally peddle fake IDs, so you obviously have the ability to shut down websites that peddle illegal extremism (meaning falun gong, anti-government groups, etc.)." The only defense against the TOR project and its supporters being forced to do this is that it's not technically feasible.
It's really bad that this isn't manifestly obvious to someone who is apparently involved with the TOR project to a substantial degree.
Most people in that field mess up their opsec sufficiently often that this is very well possible, see SilkRoad and its successors.
When it comes to the kiddyfuckers, I'm a bit torn myself when I ask myself if child pornography (and apparently people even shared videos of raped toddlers) is an excuse for hacking and exposing actually innocent TOR users. It's the classic 4chan/reddit dilemma: what kind of content justifies which measures, and when is it worth to limit the right to free speech?
For the record, I support anything done to bring child porn offenders to justice, but I also recognize that this opens dangerous doors - from the issue of "now it's an excuse for the Chinese/Russians/Iran/Saudi-Arabians to crack down on legitimate activities" to "people are actually already planting fake child-porn evidence, including in scareware/ransomware".
By removing all evil from tor, you expose the good, leaving it vulnerable. That defeats the purpose, I suppose.
Child porn is just ... inexcusable no matter how you think about it. Fine, if some porn stars make themselves look young, okay, but that's consenting adult performers. Abusing Toddlers and children for porn is not just violent in itself, it literally creates wrecks.
Let's not try to justify serious crime, because other crime may be seen as more serious.
Human trafficking, drugs and hitmen services, however, are not - the most notable exception being the various kinds of mafia or other organized crime.
People ruin their lifes, some using drugs. It's true that drugs, like alcohol, may be an existential risk to the life and potential of a small quantity of people. So are casinos, fast food, extreme sports, or videogames.
See also: https://panopticlick.eff.org/
"Panopticlick will analyze how well your browser and add-ons protect you against online tracking techniques. We’ll also see if your system is uniquely configured—and thus identifiable—even if you are using privacy-protective software."
Tor bug #6119 (https://trac.torproject.org/projects/tor/ticket/6119) talking about using this tool specifically for Tor browser. There are also continuous efforts in Tor Browser to remove fingerprintability (e.g. #22127 - https://trac.torproject.org/projects/tor/ticket/22127).
At some point it claims it can also detect screen size
> However, there are not too many people using the same OS and same screen size and visiting the same sites at around the same time. You will likely stand out.
but both my tests and themselves contradict that:
> On a normal desktop browser, the Window Size is smaller than the Screen Size. (Mobile devices may show a Windows Size that is larger than the Screen Size.) To prevent screen profiling, the TOR-Browser sets them to be the same size.
Note that detecting Tor Browser is doable from the User-Agent, so there's no point in setting Window Size = Screen Size.
Definitely not "exploiting", and I suspect that's why it couldn't get a reply from security MLs, which see a lot of these. Flagged.
[1] Psychedelics and cognitive liberty: Reimagining drug policy through the prism of human rights
Tor it's just a channel that horrible people uses, but the horrible stuff that they do happens in real life.
There is one approach that for sure it's going to solve the horrible activities that people do. Put a camera in every house. Put a camera in every corner. Then you can monitor every person and check if they're doing horrible things.
Would be worth to live in a world like that?
for asynchronous messaging, agl had something really promising with pond, but for "reasons" decided to abandon it, and nobody bothered to continue its development.
Not sure how the Tails [0] distribution handles it, but IIRC it notified me of the screen size / view port size problem as I maximize the browser.
Thanks to gzip compression, this shouldn't even take much data to transfer.
Oh, and as I think of it, would this here still work?
<a href="http://reddit.com"><span class="tracker" /></a>
a#mylink span.tracker { background-image: url(http://myservice.onion/track.php?uid=xxx&trackedsite=reddit.com); }He would try and sell larger vulnerabilities? It only proves the point, but I still consider this a little bit disturbing.
https://news.ycombinator.com/item?id=13623735
(For people unfamiliar: Tor and Tor Browser are not the same thing!)
And while I understand the motivation to avoid an exploit magnet, what do you mean by "inferior security design"?
Tor is spelled Tor, not TOR.
You have a significantly different definition of "not an acronym" than I do.
When the complaint is that there isn't a way to report a security flaw surely that's a reason to complain.