Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
nusenu.medium.com
nusenu.medium.com
I would not be opposed to having some sort of operator validation of exit nodes. Where you can actually validate who runs an operator node, get a person behind them. And perhaps rate those higher than others.
Interesting/Awesome. Just curious, what day/event specifically motivated you to get started with this?
To be honest, my impression -- which could be wrong -- is most exit node operators do so for nefarious reasons, Pr0n (hence your username INT-Penis), or are Fed.
(to be clear, appreciate what you are doing regardless)
Helping people around make me feel better.
Wait I can't tell if you're joking, do you really think their username is a reliable indication that they run Tor nodes for pornography, and not a stupid internet pun? Because if you're joking I lol'd, but if you're not I ... I'm worried about you, I guess?
I wanted to use the name NaturalsticPhallacy, because it's a prevalent fallacy I see people fall for, and humans have found dicks funny since recorded history but it's too long for HN so I had to shorten it to this one.
I do not build or operate any sort of porn or even porn adjacent software or service and never have. Not that I wouldn't if the right job came along, but I never have and currently don't.
But I digress. Usernames are generally best ignored. The content of their writing is what matters.
This part of your comment is completely unnecessary and unwarranted.
You already asked your question, just wait for an answer instead of jumping to uncharitable conclusions.
I'm not stupid, with anonymity comes abuse. But I don't think that's a reason to get rid of the option to be anonymous.
I'd say your impression is wrong about tor operators, I've met a few of them at various events. (Not including the tor operators who try to subvert anonymity of course, whoever they are.)
But the tor network is absolutely mostly used for illegal activity. I can't be dishonest about this, that would mean denying human nature. Give humans a way to be anonymous and they will absolutely abuse that.
But I've also met one reporter in person who thanked me for the tor network, that's enough for me.
As in, 28.8K or 56K or so ...
This would force tor into being a text only communications channel which would obviate many of the most egregious illegal use-cases.
You'd lose nothing with regard to freedom of speech and thought and communication. For instance, you can publish, and consume, a site like HN without any issues on 56K.
But I don't see it working in reality because there is the argument that you might need to share leaks anonymously and that would take days.
So the choice is either anonymity and crime, or no anonymity at all. And crime won't go away, it just won't be able to use an anonymous channel for communications.
And it's not like criminals are getting away with it by being anonymous either. If you go on tor to commit crimes then you will be hunted down by the international police. And if you commit heinous crimes against children then you will find no refuge. That's not a good life to live. Odds are you will end up in prison sooner or later.
Sure, as an attacker it's interesting, but cost vs. how interesting isn't clear. The law enforcement case for specific investigations makes some sense, general counter intelligence value of keeping track of which web sites are attracting people who take precautions, maybe there is a general list of suspected dissident minds states maintain?
https://nusenu.medium.com/how-malicious-tor-relays-are-explo...
Or are these MITM's somehow signing stuff with well known root certs? That seems like it would be a much bigger story. Or are TOR users really accepting self-signed certs when passing around their bitcoin addresses?
Maybe there are bitcoin clients that don't validate the chain when doing TLS? Given the sorry security posture of so many exchanges this is somewhat more plausible.
Moral of the story, if you a are a site operator use HSTS. And if you're on tor, you should maybe consider configuring things so you only use tls.
Also, if someone is running a bitcoin exchange that has port 80 open for anything more than a redirect I would not do business with them.
Verizon puts an MITM proxy from Mcaffe on people's routers (with their consent) that does this.
PROTIP: Your browser already comes with all the malicious root certs a Five-Eyes-aligned attacker would ever need. The Tor Browser uses Mozilla's Root Store if you want to go see what's in it. To pick a random example look at VeriSign's root, the company that runs dot-com and dot-net, and manages dot-gov. Do you think they might be Best Fwends with the DoD/NSA/etc? https://www.ntia.doc.gov/page/verisign-cooperative-agreement
I also think it's a pretty safe bet that many many other roots are compromised many times over even if nobody ever willingly cooperated with anything.
More importantly, I think your fear about state actors abusing trusted root certificates is unfounded. As soon as a malicious cert is found, the issuing root cert will be nuked from orbit by all the major browser vendors. It's not a viable option for state actors, especially when they have much better options (like the NSA tapping Google's internal networks, for example).
Clients (most particularly, popular browsers such as Chrome) can and do require SCTs (effectively proof the certificate was logged) to accept a certificate, but that just means if you issue a certificate under a trusted root without logging it, it just won't work in such browsers until somebody logs it.
You can even do this intentionally, if you're Google for example you get yourself (unlogged) certificates for shiny-new-product.google.example and shiny-new-product.example on Monday, and you don't need to worry that some eagle-eyed journalist spots that in the logs before your official product launch on Thursday evening, live in front of millions of people. You can log the certificate yourself minutes before launch, then attach the SCTs and it'll work.
[Google even got this wrong once, mistakenly using a certificate they didn't have enough SCTs for due to a bug. Chrome rejected these certificates and so, for a brief period until they fixed the problem, Google's own sites didn't work in Chrome]
Now, that last part is technically not trivial to do correctly (chances are your existing web dev tooling can't do SCT stapling, or at least you'd need to go read a bunch of instructions that you aren't going to bother with) and so when you get a Let's Encrypt cert, or you buy something cheap from a reseller, it is already logged for you, the SCTs are baked inside the certificate you get -- but that's just because there isn't a big market for unlogged certificates, not because such certificates can't or mustn't exist.
> To pick a random example look at VeriSign's root
But why though? Verisign is not in fact operating a trusted CA, so that makes as much sense for an example as looking at some root you just minted on your laptop.
Most likely, as so often with conspiracy theorists, you didn't stop to see if the facts line up with your beliefs, after all "VeriSign" is named right there in a certificate Mozilla trusts, surely that's a smoking gun right?
Er, no. DigiCert owns the business behind that, collecting rights to names for a whole bunch of long obsolete CAs. The "smoking gun" CA that has the "VeriSign" branding is only trusted by Mozilla to sign S/MIME email certificates, something you likely couldn't care less about and certainly won't be using in the Tor Browser.
This all reminds me of what ekr said about this years ago, the most likely explanation for why we do not see practical attacks on security protocols like TLS is that it's almost always easier to find a weaker link elsewhere, see the parts of this thread explaining much simpler tricks that we know work.
Even if that's true, why would the NSA exploit it for such a stupid and shotgun application as MITM'ing Tor exit nodes? It would basically be leaving a calling-card that results in a ton of pointless friendly-fire damage, and I don't think spies like to do stuff like that (you know, the whole cloak part of cloak and dagger).
Here's an example with HN (notice the protocol in the req/res):
$ curl -v http://news.ycombinator.com
[...]
< HTTP/1.1 301 Moved Permanently
< Location: https://news.ycombinator.com/
However, the first request is over http, before it gets redirected and encrypted. This is where the malicious relay node would intercept and change the response.People have all these fancy high-tech Hollywood-style theories about how they imagine things being attacked, but the reality is almost always far more boring.
It's unfortunate that this very simple attack remains extremely successful even a decade later. I'm surprised Tor Browser didn't enforce HTTPS Everywhere for all domains by default years ago. HTTPS Everywhere was released in 2010, before sslstrip, even. HSTS and HSTS preloading helps, but individual site owners still have to explicitly submit their site to be added to the preload list.
i highly doubt that. in fact i knew about ssl striping before i knew moxie or even sslstrip and this attack was probably already well known when someone came up with a seperate url scheme for https...
For anyone who remembers it, "Firesheep" also had a big impact, too. It didn't do anything special or novel whatsoever, but it was a really easy-to-use tool that drove home to the average person just how dangerous plaintext HTTP was. Lots of people immediately started using it in school classes and logging into everyone else's Facebook and Twitter accounts. I'm not sure if it was the direct cause, but I know not long after that, all the big services began switching to HTTPS for everything rather than just login and payment pages.
There's probably some startup lesson buried in there...
So if you own example.foo or example.dev you don't need to do anything and indeed can't choose, because Google (owners of the foo and dev top level domains) preloaded the entire TLD.
http://some.example.dev/ can still exist, but you can't go there in a typical modern web browser, it will take you to https://some.example.dev/ regardless. So software that knows it actually wants the plaintext protocol can use it, but your ordinary users can't get SSL stripped.
Many bitcoin mixers are not HSTS preloaded. And to avoid creating a trail, TOR Browser doesn't save frequently visited sites, history for autocomplete, cached redirects, or cached HSTS headers between sessions.
And as Tor users prize secrecy, many don't bookmark their bitcoin mixer. Instead they key in the address manually - and sometimes they're used to doing without the https://www. prefix. And by convention, browsers use http when you do that.
The exit node then removes the http-to-https redirect, and presents the bitcoin mixer over http, with the bitcoin addresses replaced.
The result looks like this: https://imgur.com/otaBerJ
No MITM of encrypted connections needed.
It's almost impossible for the Tor project to detect this, as the attackers only target a small whitelist of sites - so the Tor project can only detect attackers by guessing the sites on the attack whitelist.
1) When I want to make sure a site doesn't get saved to my network/client profile on search engines and content sites.
2) When I need to verify that something is up/down compared to what I or a customer is seeing.
3) When I need to force IPv4 (tor is ipv4 only)
4) Hidden services.
5) Hotel/Airport wifi.
The breach was limited - but it doesn't inspire confidence.
[0] https://www.techradar.com/news/whats-the-truth-about-the-nor...
NordVPN left the backdoor open themselves - they left a remote admin console enabled. Then, they proceeded to hold their silence for _six months_, before informing their customers... And take no responsibility. They struggled to even admit they got their dates wrong.
That kind of behaviour, and lack of transparency, is the problem. Not that a breach occurred.
For 2), Tor browser is a single executable that I can just start and run on any computer, even through a remote control if I want to very the network through a customers own computer. No credentials, no payments, no waiting.
Don't know enough about nordvpn for 3).
4) Hidden services is tor only.
5) Nordvpn would work fine for that.
Different security threat need different security measures. The biggest risk to my own security is not that someone mitm my tor connection because I do not use tor for services which I have an account with, and would never do banking on a tor connection. My bank can more or less find what my network is anyway by looking at my transaction and which of those is an ISP. Leaks from companies however seems so common that one get posted here on HN every month, and haveibeenpawned feel more relevant today than antivirus.
Remember that Tor only routes TCP. It's not a substitute for a VPN in many circumstances.
Or they really are just shitty and impatient Russians, I could go either way.
But there's no rule saying that these are average malicious exit node operators. They could just be particularly stupid ones. We don't know about the competent ones.
Not only did an actor commit a string of seemingly sloppy and unrelated "mistakes", where they had correctly executed that same things n times before for x amount of time, but they then brought their own existence to the attention of a technically empowered group to see how many of those seemingly unrelated and sloppy mistakes the system tolerates.
I'm not sure how this is an example of the "toupée fallacy", as I'm just positing as ti why this toupée would look so intentionally bad; to figure out the tolerance for a bad toupée and discover what about it made the toupée "bad".
> When Tor Browser migrates to Firefox 91esr we will look at enabling https-only mode for everyone, but there remains a significant concern that there are many sites that do not support HTTPS (especially more region specific sites) and the question of what messaging Tor Browser should use in that case.
Source: https://lists.torproject.org/pipermail/tor-relays/2021-April...
Edit: clarified
https://sites.cs.ucsb.edu/~vigna/publications/2013_RAID_i2p....
1. Live in a country in which law enforcement follows the law and the law does not prohibit running tor, as noted in a response.
2. Hire a lawyer competent on cybercrime, intellectual property and freedom of speech.
3. Set up a non-profit or other legal entity with the explicit purpose of running tor exits/relays (stated in the articles of incorporation or similar founding documents, depending on the country and type of legal entity). Make sure its address is not your home address.
4. Purchase or rent the necessary hardware through the legal entity (don't ever do anything unrelated to the tor exits from this entity). Make sure you co-lo it in a datacenter, do not run any exits in your office and especially not in your home. Avoid having any hardware you rely on not being seized in close (physical -- same rack or logical -- e.g. same network) proximity. Explain to your host that you'll be running tor exits. Clearly label your systems as tor exits in any possible way you can manage, including physically on the cases/bezels. Run a web server on their public IPs with a page explaining that this is a tor exit node run by such and such legal entity, set WHOIS data with the same info if possible. Set up reverse DNS with hostnames that clearly state this is a tor exit node.
5. Be ready for trips to the PD in order to explain what tor is and why what you're doing is legal and that it's not you that sent that phishing e-mail, etc. It is a matter of when an illegal activity will be traced back to y̵o̵u̵r̵ the legal entity's exit and no amount of labelling will deter law enforcement from summoning you as a representative of the entity. Reasons being incompetence, desire/requirement to investigate thoroughly, or plainly using inconvenience as a way to discourage you from running the nodes (in the end, tor both creates more work for law enforcement and is a big obstacle to them so they'd rather not have to deal with it if possible).
This is the gist of it. The details need to be discussed with a lawyer. And again all of this relies on the law enforcement and justice systems to follow the law and the law to not prohibit tor. Don't do this in a country in which there's risk of you being black-bagged or held legally responsible for running tor or not keeping traffic logs.
Source: my poor understanding my country's and EU's laws. IANAL.
(I am not your lawyer) AFAIK this is still up in the air for U.S. persons - many states make it a crime to help criminals, including when not in the event of commissioning the crime, so you might be considered an accomplice to said crimes by running the exit node (or even just a relay). This isn't exactly a hot issue nor a clear-cut one so I would doubt D.A.s are interested in bringing you to court after a few times of being explained the situation.
Closely related to this, why wouldn't this position create criminal liability for running an open wifi network, if it turned out to have been used by a criminal? How about for a public library that allows unidentified members of the public to use public computer terminals? How about for running a commercial ISP?
Is the likely argument some kind of common-law imputed duty to not provide too much more privacy to network users than the average ISP does?
But you're right in that, in reality, police departments aren't going to blame a library or a fast food joint for letting illegal activity happen given they didn't know about it and that Wi-Fi is usually not used for such actions. I just think the law gives enough leadway for an extraordinary event to occur where [for example] some U.S. actor gets prosecuted simply for running nodes, likely as the only way for a state actor to take down some criminal enterprise in the event of there not enough evidence to convict of a major crime.
I also did some case searches regarding public wifi and there are not many results in general. https://scholar.google.com/scholar?hl=en&as_sdt=80006&q=%22p...
https://blog.torproject.org/support-tor-network-donate-exit-...
If the MITM operators have stolen a well known root cert then we have a much bigger problem.
https://blog.cloudflare.com/performing-preventing-ssl-stripp...
If it's a hidden service you're connecting to, it's fine, there's no way for a malicious exit node to alter what's sent to you. If it's a normal website (i.e: not .onion) that you're getting the address from, then the exit node could perform SSL stripping [0], an attack in which a website which would normally be served over HTTPS is served to you via HTTP, and so the malicious exit node could alter the content. In this case, the attacker could change any cryptocurrency addresses present in the website to convince you to send currency to the wrong address. It would be visible in your browser that the website is being served over HTTP, not HTTPS.
It should be noted, this scenario is getting rarer with the introduction of HSTS [1], especially in conjunction with HSTS preloading, which prevents your browser from accessing the website over plain HTTP. Tools like HTTPS Everywhere [2] can help ensure that you never access websites over plain HTTP also.
Also, this isn't a vulnerability in Tor per se, the exact same is possible without Tor, it's just that when you connect to a website via Tor, you're deliberately introducing extra hops between you and your destination, which wouldn't normally be there.
So, things that would need to come together for this attack to work: First, you're not connecting to a hidden service. Second, the website you're connecting to doesn't use HSTS, or you've not connected to them before & they're not in the preload list. Third, you aren't using a tool like HTTPS everywhere and you don't notice the website is coming to you over HTTP. Fourth, you don't verify that the address you've been given is correct independent of the website before sending a payment. This seems to me to be a fairly rare set of circumstances on the modern internet.
0: https://security.stackexchange.com/questions/41988/how-does-...
1: https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
Then there's another kind of tech (and tactics and practices) that could hope to keep you safe when you are targeted by state-level actors in both digital space and meat space.
Tor barely belongs in the former category.
If you seriously feel paranoid about being watched then you'll want to own the hardware you're actually passing through. And I assume that any large organizations that demand this level of invisibility (cartels etc...) have essentially done this - likely locating some of those servers behind armed guards that will protect the physical device.
That said, I think it's unlikely that Tor has been majority compromised at this point, but as it fades from the minds of folks and becomes more and more niche the probability will escalate.
how do you keep the hardware physically secure? What prevents a gov actor replacing it with their own mitm proxy?
I mean. That’s what I uhh, would do if I was doing something dodgy on the internet…
Edit; with a second hand android bought from a pawn shop running nethunter as an ap ofc…
Send me your address and I uhhh
Tough to do encryptluks2-approved opsec if you have to use tools that don't exist.
Maybe a bluetooth autolocking thing could have delayed the inevitable, but it would just be a delay.
Presumably they acted the way they did because they had reasonable belief that their plan would work. If Ross behaved differently i assume they would have a different plan of action
I "like" this explanation, but are you going with your gut on that or do you have any concrete signs that point in that direction?
Furthermore, using a zero-day on Ulbricht would be optimal as he is no security researcher. You are unlikely to “burn” a zero-day unless you are using it in a dragnet sort of fashion while a vigilant security researcher is watching.
By definition, it’s hard to find proof of parallel construction. However, former intelligence officials have confirmed its use as a “bedrock technique” for catching criminals [1].
> simplifies solving the crime to a matter of using the exploit and merely observing for gaps in opsec
By this logic, could one get away with a "crime" indefinitely given good enough (perfect?) opsec?
People say that part of Ulbricht’s shitty opsec was that he left his laptop unlocked, but think of this - the FBI was already ready to grab his laptop the very moment he left it alone. Clearly, they knew he was the criminal well beforehand, and were just lying in wait for him to slip up just one single time.
All in all, this is really cool work. I wonder what it would be like to work for the FBI or NSA solving high profile cybercrime. I imagine it would definitely feel more impactful than my current FAANG position, even if the compensation would be lower.
Is there another laptop of his that they physically accessed somehow prior to distracting and arresting him? (I don't understand how someone could think from that story that the laptop seizure played any part in initially identifying him, since it was done by FBI agents in the course of arresting him pursuant to a warrant.)
It's unfortunately entirely possible that they didn't tell the judge about all of it, but it's still not as though seizing his laptop was the event that convinced the FBI that he was guilty, or even that they claimed to be particularly unsure about their suspicions before that.
What if you live 3 blocks away from a public library but a few floors higher? With direct line of sight and some wireless networking gear?
Would they really try to triangulate the client packets? It is a large leap past "oh he is in the library, let's go find him". You aren't triangulating the AP, you need to logically isolate the packets from the client, calculate their dB and somehow triangulate on just that.
This is smart, and a good idea. But it really just adds a step. Once they go to the library and don't find him, they'll start looking for something 'smart'. And doing 'smart' things like this really get the hackles of the feds up because they start thinking exciting things like 'state actor', and "I'll get a promotion out of this".
The best place to hide something is right out in the open. Preferably behind a SEP field.
Not hating on your idea, just exploring it further.
There is no safe when it comes to determined state actors.
Pretty sure that gets you on a list?
This is going to be difficult: <https://arstechnica.com/information-technology/2014/07/the-n...>
But it doesn't mean much as DARPA's seems to fund a lots of projects with seemingly opposite goals.
Which is why you should generally only use https when using tor. The last leg may be snooped on so you need to use encryption during it. (http is fine with hidden services though)
Its important to keep in mind that anonoyminity and data integrity are separate properties. You can have one without the others.
Think of tor like the open wifi network of dubious origin at a black hat hacker convention. You are probably fine if using https, but plain http is a bad idea.
Using a vpn is more questionable. Generally a paid vpn already knows who you are so hiding you origin ip with tor would be pointless. Also sometimes combining vpn technologies can cause traffic congestion algorithms to interact poorly and make things really slow, but that will depend on which technologies are in use.