German foreign spy agency BND attacks the anonymity network Tor
netzpolitik.org
netzpolitik.org
> Precisely how the BND plans to „chop“ Tor is unfortunately redacted in the document we obtained. But as before, the spy agency refers to public research. To implement the attack, it is likely that the spies runs their own servers in the Tor network. M.S. points to passive snooping servers, which are presumably operated by the NSA, and emphasizes the „protection of the anonymity“ of the spy agencies.
And indeed, there are no specifics.
Tor Project acknowledges that Tor is vulnerable to global adversaries. With enough intercepts, they can correlate traffic at various relays, and connected users and servers. There's nothing magic about onion services. It's just that there are seven relays between users and servers, rather than just the normal three for Tor.
But hey, it provides better anonymity than any alternative. Other than meeting in remote locations, anyway. And you can add VPNs to the mix. I always use Tor through nested VPN chains. That adds misdirection. But perhaps most importantly, it adds latency and jitter, which mitigate traffic correlation attacks.
Edit: As a fun science project, you can play with traffic correlation between you and your private onion service. You use unlisted private bridges as entry guards, both locally and for the onion service. So it's only your traffic that gets analyzed. And you don't need sophisticated software. Wireshark and a spreadsheet are enough. So you have packet captures from your local machine, and from the VPS running the onion service. Using Wireshark, you export bitrate in millisecond bins. Then in the spreadsheet, you have two columns, one with each bitrate series. Just create a third column for the product. Each sheet will hold 1E6 lines, or 1000 seconds. Excel works best, because it uses multiple cores. R would be better, because you could crunch segments in parallel.
We are in the middle of a golden age for surveillance, and a golden age for the avoidance of surveillance.
A couple of these products function on unlicensed bands, which is what you'd need. The latency is very low and close to constant regardless of the length of the haul, which means that it could be difficult to tell that your packets even originated from a location other than your exit.
https://www.ubnt.com/products/#airfiber
> a project
Not sure if anyone has documented doing this, seems like it would defeat the purpose for anyone with a practical need for it. Maybe I'll need to be the one to show it.
The hard part is probably tamper alarming the enclosure, the rest is just standard setup for the equipment and maybe some site security concerns. For example, considering what to do when the station goes down, since coming to fix it would be a good way to be discovered if your adversary is monitoring it.
Indeed! I was hoping for a collection of methods, maybe some form of best practices regarding anti-tampering. Thanks for the links to the APs, fun rabbithole to fall down in.
0) https://dl.ubnt.com/datasheets/bulletm/bm_ds_web.pdf
1) https://www.amazon.com/Antenna-World-G2424-Directional-Parab...
Wireshark alone is enough http://blog.davidvassallo.me/2010/03/22/measuring-bandwidth-...
If you would want to really see if there are differences in bandwidth for 2 pcap files you would have to graph it cumulatively.
I may have something to do that in Python.
Yes, I did that too. Had to analyze traffic to QA a VPN app.
> But Tor-specific parameters are buried in encrypted payloads, so amplitude is decent enough.
Indeed it is. It's even possible to do traffic shape fingerprinting on that.
What I have seen is people being able to detect data when each high level request can be cleanly separated.
I take your 'not seen', and raise you a several years old snowden publish.
multiple intercept locations + timing information + flow size captures + crawling data from destination sites + a big honking graph database would probably get someone with deep pockets fairly far as far as fingerprinting..
from here, select various targets and add more traditional methods and you've got yourself a pretty good 'lets see whats going on with the key players' sort of tool..
But we are talking about a specific attack vector here: Correlation attacks. flow size captures and destination site fingerprints are great if the traffic can be isolated.
Imagine a actually fingerprint. A computer will transform the image into specific dot values, and from there create a unique value. Now imagine you put 100 different fingerprints with the exact same outer finger shape on top of each other. No method will be able to say with confidence if a specific fingerprint is in it, regardless deep pockets and honking databases.
But there are a few catches. Reduce the number of simultaneous signals and the problem goes down. If you can introduce additional traffic into the signal, you can often isolate the traffic you are interested in. While we can never know with certainty what the big agencies can do, the general advice I have heard is to not send a single message through the tor network and always do it as a part of multiple simultaneous messages (both for sender and receiver).
Exactly. If enough ISPs cooperate and share traffic data, then you can correlate traffic. Especially if it is a low traffic. The more traffic, then more difficult it becomes but even then it is still doable.
> And you can add VPNs to the mix.
As long as the VPNs themselves are legal ( china has started to ban them ) and they aren't compromised or they aren't government created VPNs to secretly track you or the VPNs themselves are honest. Nothing prevent the VPNs from collecting your traffic data and selling it to governments.
You can't trust anyone. But with nested chaining -- whether it's Tor relays or VPN servers -- you can distribute trust. And the more stuff you nest, the more adversaries need to compromise.
See https://www.ivpn.net/privacy-guides/advanced-privacy-and-ano...
This isn't possible. Your tor daemon fetches the consensus from a directory server and picks the relays and exits itself.
The directory server can't tamper with that consensus because its signed by the directory authorities, a small set of servers that are necessary because of this attack.
What has always surprised me is that someone hasn't tried to install Tor nodes into compromised IoT devices, etc. If a virus is installing millions of nodes in the wild, that might be enough to keep the network majority non-attacker. As it stands, NSA or China, or whoever just ends up buying the whole network.
If you had the skill to compromise the devices with a tor node. Won't you use that node in your own private "tor" network, instead of sharing it with the wild?
That would be enough to get thousands of nodes. (And probably a bit less illegal, although still not legal)
Also the case if they are missing a few nodes in the middle, as long as they control the entrance, exit, and never miss two in a row.
Servers on the tor network aren't some magical machines. They sit in the same datacenter as any other server, and all their traffic reaches them via the internet. Controlling the nodes connected to them should give you a pretty good idea of at least the magnitude of traffic they're seeing. And even without running any nodes, attacking blocks of IPs suspected to include the service while measuring any potential impact on its latency allows you find their public IP (given enough resources and/or time). Then, there's the attack of try
If you're going to do illegal things, or want anonymity, remain on the network - domains ending with .onion. The regular web is inherently not anonymous.
[0] https://www.cia.gov/library/center-for-the-study-of-intellig...
[1] https://www.nsa.gov/news-features/declassified-documents/tru...
In the US, you have way more agencies. The five most famous are Central Intelligence Agency (CIA), National Security Agency (NSA), Defense Intelligence Agency (DIA), National Geospatial-Intelligence Agency (NGA), and National Reconnaissance Office (NRO) [0]. Germany does have other military intelligence agencies, such as Kommando Strategische Aufklärung or Militärischer Abschirmdienst (domestic military intelligence). They are subdivisions of the German military (Bundeswehr). Some of the US agencies are child agencies of the DoD. So arguably it's similar?
And because Europe is countries but the US is states, it isn't really comparable in size, so splitting these roles into different agencies makes less sense. There are benefits of having only one agency/organisation, e.g. re-assigning personnel and easier cooperation (inner-agency vs inter-agency).
[0] https://en.wikipedia.org/wiki/United_States_Intelligence_Com...
In this article, it's supposed to set up the surprise that they were not, after all, completely stupid.
The translation is a bit off, I think. I can't really figure out what to make of all these apparently self-aggrandising statements, and I can assure you that no German bureaucrat would use the term "Yanks".
Well then let me assure everybody your assurance is mistaken. Two examples:
> Wir haben den Amis ja was versprochen und Mitte März ist AL [Harald Fechner] dort.
and
> Das, was wir jetzt haben, wäre ein guter Stand, um mit den Experten der Amis zu reden.
When reading "Yanks", I automatically assumed it's a translation of "Ami". How would you translate it better? "Yankee" has negative and benign connotations, as does "Ami", and in this context they're clearly benign. While looking into the word I came across this:
https://en.wikipedia.org/wiki/New_York_Yankees
> New York Press Sports Editor Jim Price coined the unofficial nickname Yankees (or "Yanks") for the club as early as 1904, because it was easier to fit in headlines and because "Yankee" was and is a commonly-used synonym for "American".
Where's the biggie?
bonus rant:
German bureaucrats use all sorts of words in all sorts of contexts. If you mean for public communications, you're right of course, but at the workplace and in internal emails all sorts of things are possible. It's not like repression and conformity generates civility, they just generates masks, a pretense of civility. That's why the stereotypical bureaucrat, nationality irrelevant, will sign off the murder of millions as long as the paperwork is in order, but apologize profusely if they spill their drink on your clothes, and that outwardly gentleman-like behavior is compensation supposed to ward off the inevitable collapse of a house of cards built on a sinkhole, not an actual expression of the inner reality.
Ask any high ranking prostitute who has the weirdest kinks or the most destructive fantasies. Maybe it won't be German bureaucrats, but it will be people who behave the total opposite in real life, and are considered super proper or even admirable. It usually won't be the guy who spits on the ground all the time and calls everybody names. Okay, maybe because he can't afford a prostitute, but at any rate, the idea that a German bureaucrat is less likely to be abusive than the average person just doesn't sit at all with me.
It's very hard and you spend most nights worrying the police will kick your door in. Not too worthwhile.
Those who are serious should learn from the Whonix wiki. It's hard to find a more stellar source of unbiased and comprehensive information. They have pros and cons of both VPN to Tor and Tor to VPN, but that's like 2% of the overall concerns you have to worry about.
The only reason I ever left Qubes was because Xen still has not implemented a workaround for GPU passthrough with consumer NVIDIA cards like KVM does. I need this for gaming. I now run a KVM system with separate VMs for each domain similarly to Qubes, but the moment GPU passthrough functionality is addressed by Xen I'm moving back.
The KVM experience is quite subpar, for example it is lacking a secure copy-paste between domains and forces me to type out my passwords from my password manager VM when I need them.
I'm posing the question, as I don't see an answer in the article. Nobody gets better at opsec if flawed methodologies aren't picked apart in detail. I'm surprised I was downvoted, but I don't comment here frequently and maybe didn't pose the question in enough detail. This is usually how I was accessing Tor based on the assumption that most of the exit nodes are compromised.
That, of course, assumes that none of the locks come with a vulnerability which would allow an attacker to bypass all the locks at once.
I always rot13 twice for good measure, too.