How malicious Tor relays are exploiting users in 2020
medium.com
medium.com
Though this might be due to cops wanting to keep their own local ‘war on drugs’ going on. The statistics won't improve themselves, you know. And I know for certain that cops are aware of Tor and what people do on it.
Edit: wow, fastest downvotes in the West are coming immediately after posting in this thread. Like, less than ten seconds passed.
Upd: somebody posted a reply but deleted it before I started typing my own (what's even happening here?), so here goes. What I'm saying is that I can only wonder why Russia doesn't block Tor and would very much like to know the reason. However, I do think that the FSB might be interested in hijacking Tor traffic, even if just for shits and giggles at first. And buying some boxes in Hetzner probably isn't a problem for them. Don't forget also that FSB directly works with several criminal hacker groups here, and having both their own masqueraded Tor routes and hijacking others' traffic might be vaguely titillating for those people.
As for blocking Tor, I already mentioned that the site would be easily blocked with existing measures, as would relay IPs. For more covert nodes, afaik DPI is being implemented across the providers currently, on RosKomNadzor's orders. So I guess we might yet see Tor blocked on the protocol level (possibly along with Telegram?).
May be there're not enough juridical grounds in Russia to block Tor. But I doubt it, they tried to block Telegram when they wanted to... May be opposition does not use Tor, so it's out of sight.
That long since stopped being a problem for the state here, in general. But also, Tor is explicitly against the law that regulates VPNs—since proxy-like services must block the same sites that are blocked by RosKomNadzor, to be allowed.
Just using it makes you automatically interesting to state actors.
I mean, UK's move against porn is even bolder, but I doubt it that Tor handles video well.
YouTube blocked the network request as suspicious though I was able to view the main page fine; I did not try creating a new circuit.
The Vimeo video played perfectly fine.
I kept creating new circuits until the exit node was US, and then the PBSKids video played fine.
My own guess is the simple "follow the money" default stance on issues like this. Tor is likely enabling profits for people within the government, and turning it off has low enough political benefits in comparison. Turning off a west operated VPN has likely a very different economic trade off so it get blocked while tor does not. A direct example off that, with a few implication about the Russian government, is that that tor provide access to hidden service market places while other forms of VPNs do not.
But maybe that would mean giving the sysadmins too much inside info.
I also discovered recently that the FSB and company aren't considered monolithic, and a few departments are doing their own things in a sort of ‘competition’. So yeah, it might be that some of them want Tor and don't want the hassle of setting up the exclusions.
“It appears that they are primarily after cryptocurrency related websites — namely multiple bitcoin mixer services. They replaced bitcoin addresses in HTTP traffic to redirect transactions to their wallets instead of the user provided bitcoin address. Bitcoin address rewriting attacks are not new, but the scale of their operations is. It is not possible to determine if they engage in other types of attacks.“
1. Explicit identification. Tor relays, including exit nodes, are identified by contact information. Many of the groups of malicious exit nodes shared contact information.
2. Benign behavioral identification. Many of the identified malicious exit nodes were deployed on the same service providers, including some obscure ones. This isn't a definitive identifier, but it helps link explicitly identified groups.
3. Malicious behavioral identification. Many of the malicious exit nodes were performing similar attacks on outbound traffic, like sslstripping traffic to cryptocurrency web sites. The exact parameters of this behavior (e.g, which sites were targeted, what modifications were made to cleartext data, etc) weren't laid out in the article, but would serve as a highly accurate fingerprint for a specific attacker.
If you read between the lines, he gives a few hints with regards to the sslstripping and traffic manipulation on only a limited set of sites.
This is from another post @ https://medium.com/@nusenu/the-growing-problem-of-malicious-...:
> In autumn 2019 I stumbled on something odd: Tor relays doing something that the official tor software is unable to do. This is intentionally vague to avoid giving away the detection methodology to the adversary."
And that means many users are likely re-typing the URLs of the services they want to access every time. Any Tor user who enters bitcointumbler.com instead of https://bitcointumbler.com would be a target of this attack.
“They (selectively) remove HTTP-to-HTTPS redirects to gain full access to plain unencrypted HTTP traffic without causing TLS certificate warnings. It is hard to detect for Tor Browser users that do not specifically look for the “https://xn--ivg in the URL bar. This is a well known attack called “ssl stripping” that exploits the fact that user rarely type in the full domain starting with “https://xn--ivg. There are established countermeasures, namely HSTS Preloading and HTTPS Everywhere, but in practice many website operators do not implement them and leave their users vulnerable to this kind of attack.”
What am I missing? Is this only an option in HTTPS Everywhere (that is not on by default)?
By default, HTTPS Everywhere uses a list of HTTPS-capable sites. It doesn't automatically HTTPS-ize the sites outside of that list or block HTTP connections. You have to click the "Encrypt All Sites Eligible" option for that, and only then will it throw an error if the site doesn't have an HTTPS version.
Tor Browser doesn't have this enabled by default, probably because hidden services don't require HTTPS and it would be a pain as a default.
See the check here: https://github.com/EFForg/https-everywhere/blob/bcaf7bdecf14...
Edit: Which is not to say that there aren't rules forcing some .onion sites to https, there are. Encrypt All Sites Eligible (httpNowhereOn) just knows it doesn't have to worry about un-rewritten http .onion addresses. So it really is a good idea to turn it on, and think hard before allowing an exception.
I guess it also depends on your threat model. If you are only browsing and in "Safest" mode, I suppose it's tolerable. But I agree that logging into anything requires EASE to be on.
I don't think that a site must do anything for HTTPS Everywhere to work, since it is (or should be) entirely client-side. Obviously, if you had to fetch something over HTTP before switching to HTTPS then a proxy could slip you forged info.
So, I don't know if Tor Browser works this way, but—just don't allow plain HTTP unless explicitly requested by the user? (Instead of requiring to specify HTTPS.) Weird if TB doesn't do this.
It might be useful when you have your own 3 hosted nodes.
I guess it depends what you mean by _most_. We operate 8 relays, so you can exclude 8 more from your _most_ and make of that what you will...
https://www.ghacks.net/2020/03/24/firefox-76-gets-optional-h...
Also an editorialized title.
"How Malicious Tor Relays are Exploiting Users in 2020"
Sounds more like duplicate submissions should register as an upvote on the previous one if it's within a certain amount of time rather than posting separately. This is a feature Reddit has had for about a decade.
Additionally, the title here states "More than 23% of Tor exit relays operated by a single malicious actor", whereas the subtitle states ">23% of the Tor network’s exit capacity has been attacking Tor users"
While OP's title is confirmed deep in the article ("As far as I know this is the first time we uncovered a malicious actor running more than 23% of the entire Tor network’s exit capacity. That means roughly about one out of 4 connections leaving the Tor network were going through exit relays controlled by a single attacker."), this wasn't anywhere near the top nor was it the intent of the author to make this specific point.
Anyway, emailed per request.
Edit to add: thanks!
4:13pm eastern time. Our messages here crossed paths, no worries.
As grzm pointed out, it's not a dupe until the story has had significant attention. That's on purpose, to allow interesting stories multiple chances at getting attention.