Exploit vendor drops Tor Browser zero-day on Twitter
zdnet.com
zdnet.com
You basically add some anonymity but change your threat model to include an extremely high likelihood of injection attacks, and practically provoke every state level agency to monitor you, where they might have previously ignored you.
This was the pgp problem in the 90s where you would essentially be sending a tracer round across the network saying, "hey everyone, these two people are using encryption!"
Tor is a great effort and it gets people involved in privacy, but onion routing to exit nodes on the internet has diminishing efficacy, and I think everyone needs a clearer articulation of what and whose problem it solves.
Source for this claim? I don't doubt they monitor what they can - but the sheer volume of internet traffic makes it unlikely that they are able to monitor everything and instead must target specific things to monitor. They have a lot of money and a lot of smart people, but they don't have wizard magic.
https://en.wikipedia.org/wiki/Tempora
>The Guardian claims that no distinction is made in the gathering of data between public citizens and targeted suspects.
> The processing centres apply a series of sophisticated computer programmes in order to filter the material through what is known as MVR – massive volume reduction. The first filter immediately rejects high-volume, low-value traffic, such as peer-to-peer downloads, which reduces the volume by about 30%.
They have access, but it isn't necessarily analysed or kept.
From the data presented by the tor project, it seems clear that tor services many people in nations where they're likely to be targeted by the state or other organizations for online activity.
With that said, I think defining what and whose problem it solves has a limit imposed by the nature of what we're doing, which is giving people the option to be anonymous and connect to the internet. The more details you articulate, the less effective this system becomes.
That statement is the insight that was missing for me.
It's correct, but for someone of the belief that things that work magically, necessarily also fail magically, it's hard to place faith in.
If Tor depends on a "Tinkerbell effect," I would hope its uses get the quality of scrutiny that ciphers and protocols do.
How about onion routing to peers? Tor provides a great backbone to do this yet so few applications employ it. I have ideas of course, but in general, it's very easy to have a desktop app on your home computer that fires up an onion service you can access from anywhere including mobile. Why more apps that don't have high bandwidth requirements don't use it I'll never know.
That makes it sound like it is simple, but without looking at the dependencies code it might just be a simple interface to a implementation of a complex protocol.
It is all three, but it's not technical NAT hole punching as much as just connecting to relays. So any device that can call out to the internet can setup a local onion service, similar to how those localhost-to-public-address dev tunnels work.
https://github.com/n8fr8/talks/blob/master/onion_things/Inte...
I tried to use the Tor browser. The problem isn't "big corporations" but speed, latency and my MacBook fans spinning when I try to read the newspaper.
https://motherboard.vice.com/en_us/article/d73yd7/how-the-ns...
(I do occasionally, but it's a bit slow for some things)
The original/official upload of the panel discussion use to be here, but it's been taken down since. :(
You just need to accept that the US Government's agenda of regime change in Vietnam, China, Iran, Cuba, Egypt, Venezuela, North Korea, Belarus, Russia, Ukraine, and Turkey is the correct course of action of the continuing development of international human rights.
Also it helps to ignore any chance that there could a majority of the population who sees their government's action as necessary, just, or even acceptable. They're simply wrong and uninformed due to the oppression of their government. Western European liberal capitalist representative democracy is the only successful government which stands the test of time, we have nearly 200 years of data to support this, every other model by comparison simply doesn't work.
I would like to see some citations that the US is pursuing regime change in Vietnam, Egypt and Ukraine. The US is a direct supporter of both the Egyptian and Ukrainian governments and on fairly decent terms with the government of Vietnam.
>Also it helps to ignore any chance that there could a majority of the population who sees their government's action as necessary, just, or even acceptable. They're simply wrong and uninformed due to the oppression of their government.
How do you gauge the support for censorship within non-democracies like North Korea especially when opposition to censorship may be brutally punished? I'm not saying that the population of North Korea is anti-censorship, I don't know what they believe. I'm curious how you arrived at the conclusion that they are pro-censorship.
The goal of TOR is to subvert local attempts to control internet access. Generally this takes the form of censoring pro-western internet views as the internet in its more open access form the internet is a product of the western hegemony and its filled with praises for the western hegemony's polices and its propaganda.
Attempts made by Governments to censor the external internet, and attempts made by those outside of the government cannot escape the political elements of their actions. The goal is either the preservation of the current regime, or the change/overthrow of the regime/party/structure all political actions boil down this.
In light of these facts. The diplomatic relationships effectively serve as a short term tools, while projects like TOR are long term tools. The former exists for PR, and making concrete treaties. The later exists for building political divisions over longer periods of time which can trigger national instability and crises. See: Arab Spring.
How do you gauge the support for censorship within non
democracies like North Korea especially when opposition to
censorship may be brutally punished?
DPRK regularly has multi-party elections so I think we could gauge how the people vote?>DPRK regularly has multi-party elections so I think we could gauge how the people vote?
In a country such as North Korea where even minor disagreements with the government result in torture it seems unlikely to me that a non-secret ballot would be an effective way of gauging public views on controversial issues.
> This Tor Browser exploit was acquired by Zerodium many months ago as a zero-day and was shared with our government customers
Of course it was. The surface area of browser tech is just so large. We need a subset of html+css and a browser that only renders that with a really simple implementation (plus side, low bandwidth and terminal friendly). Not a full browser with features conditionally disabled. I haven't put enough thought into client-side scriptability so I'd punt on it for now, but I did put thought into other parts the other day [0]. Many onion services don't want all the features of the modern web anyways. The TBB can still exist for users of full sites of course.
If your threat profile involves governments targeting you, this bug is critical, more so than the code execution exploits because these bugs are rarer.
TBB has value for general browsing, but secure browsing needs to be by document format as much as implementation. Right now, the only reasonable option for onion services is to have their site browsed via the large, feature-rich bundle. Unfortunately, it requires a good bit of funding to build a document browsing platform of any size so I definitely understand the current practical approach.
But honestly, the parent's idea seems quite likely.
So they essentially lose nothing over it. People won't stop using internet and move toward written letters... they will just move toward other browser or update their browser, they will still be using something that Zerodium are buying and selling zero days for.
It'd be much easier to just strip it all out, despite breaking site support in the process. Especially since Tor is usually used to access hidden services instead of the clearnet.
I've always thought that the highest security setting would set it to false on its own, but apparently it does not.
The old addon system made it far too easy to make catastrophic mistakes like this. Web Extensions, which are an API that was actually designed with security in mind, constitute a huge security improvement.
My assumption is the opposite but I have no data to cite here, is it even possible to tell?
Several years ago, the FBI used JS-based identification scripts on an entire hidden-service hosting service to identify visitors.
https://www.wired.com/2013/09/freedom-hosting-fbi/
I wonder if it's already being used in the wild by governmental agencies.
> This Tor Browser exploit was acquired by Zerodium many months ago as a zero-day and was shared with our government customers.
It's a possibility that it has been used. I'm not sure if a government would buy an exploit and not use it before it's patched, unless they couldn't find any use for it. This exploit is different than the one the FBI used on the child porn site though. They'd need to combine it with something that can bypass the Tor Browser's socks5 setting. It would be a much bigger deal if they had an exploit that could do that.
> We've launched back in December 2017 a specific and time-limited bug bounty for Tor Browser and we've received and acquired, during and after the bounty, many Tor exploits meeting our requirements
If we have to take their words for granted, "many exploits" probably means they have a LPE too. And when you escalate, you are able to bypass both SOCKS5 and Tails' firewall.
I was wondering if this was related to the Playpen case. I thought the FBI refused to release any information on that (and subsequently charged were dropped against several of the people they arrested).
Who has discovered with was the Tor Brower's socks5 setting?
Also, what's a good way to capture all HTTP traffic (after decryption) to find/analyze exploits like this being used against me?
Web Extensions were designed with security in mind and are much safer as a result.
It isn't allowed to have multiple content-types. (And it would make no sense.)
I will do mental gymnastics to try and figure out if something was meant to be a certain way or not.