The Nym mixnet[0] seems promising but it's still new and unproven.
I had an idea a while back to make traffic analysis more difficult by building circuits distributed across adversarial countries. Would like to hear thoughts on it.[1]
The Nym mixnet[0] seems promising but it's still new and unproven.
I had an idea a while back to make traffic analysis more difficult by building circuits distributed across adversarial countries. Would like to hear thoughts on it.[1]
- Find the "bad guy" server onion address "hidden service"
- Run a tor relay. Ideally many. No exit node shenanigans needed - hidden service, not exiting TOR. This is quite nice from a legalistic perspective since you're not on the hook for hacks coming off the exit node.
- Run a bunch of clients. Instruct to connect to "bad guy" onion.
- Gather data over time for correlation attacks. Correlate your client to relay to endpoint server.
- At some point, you'll find one of your relays is the guy connecting directly to said hidden service.
Very simple lesson here. One needs to encrypt the information, yes, but failing to consider packet timing as "information" is the fallacy.
If you’re interested in seeing what the next generation of this stuff looks like (although AFAIK is not really known outside of defence contracting circles) take a look at this https://github.com/tst-race/race-docs/blob/main/what-is-race...
So he persuaded NRL to give the project up to open source. Good thing, too, because he was a math geek but not a cryptographer. The two cryptology doctoral candidates at MIT who took the project over chucked his code, and rewrote Tor from the ground up.
Since it's open source, this can be documented. Getting spooky about it being designed for spooks is a red herring.
That GitHub doc vaguely mischaracterizes Signal -- all Signal ever sees is the connection negotiation metadata. Past that point there are no "servers" involved, or data to be retained for future discovery.
IIRC it was a US Navy project. But I didn't understand your point.
People think that just because the research came out of the Navy, it was busted or compromised from the start, which it wasn't. Efforts only spun up to wrangle it in from being an academic curiosity once it started being heavily noticed as being a frequent tool/vector in investigations of criminal/adversarial activity.