OPSEC for hackers
slideshare.net
slideshare.net
"Against [Law Enforcement Officials], it's fine. Against a nation-state, the TOR network has insufficient resources and has sufficient bad actors that it is not actually secure. So if you're going to hack the shit out of the NSA and do really really bad planning and do not actually evalute the targets you are after, you will go to jail."
He also expands on how to unmask a user by controlling both the exit and entry nodes:
"So if you can purchase 300 VPS accounts at $5 each then you can set up 1% of the TOR network and statistically, over a month, you will be able to uncover a large number of users. [...] You are better of selecting your targets so they will not be state actors."
(The link is on the video of the full talk.)
Ordinary people (and even trained professionals [1]), get sloppy and make mistakes. Thus, this line from the presentation is golden:
"Amateurs practice until they get it right, professionals practice until they can't get it wrong.
[1]: Another excellent essay by the same person - grugq (of +HCU and Fravia+ fame) on the major OPSEC fuck-up by CIA in Lebanon and the factors that likely have lead to the full compromise of a big informant network, and possibly the deaths of a number of people [2]: http://grugq.github.io/blog/2013/03/12/anonymity-is-hard/
[2]: http://www.wired.com/dangerroom/2011/11/pizza-cia/
added: even small things like complaining about freezing your ass off due to the cold weather, accidentally linking two nicknames, emerging at regular times (synced with a specific timezone) could be used to uncover your identitiy. As evidenced, slip-ups like could get you in jail. You can check the discussion from a few weeks back about the hassles of creating a truly anonymous page on Internet: https://news.ycombinator.com/item?id=5638988
We really need something like automatically mutating protocols, not the TOR "I'm HTTPs that no one would ever use for HTTPs" stuff.
Sabu was blatantly poor at covering up his identity. He was doxed by other hackers online long before the FBI found him (apparently it was one of the anti-anonymous 'patriot' hackers who passed on Sabu's real ID to the FBI).
Without Sabu, they wouldn't know where to park the van, or which VPN providers and ISP's they need to subpoena.
Sabu made two mistakes. First he pasted a link to a file in IRC that was hosted on prvt.org. Somebody looked up the historic whois records for that domain and found the name Hector Monsegur.
His second mistake was that his Tor setup didn't "fail close", and when his local SOCKS server died his IRC client accidentally logged him in using his real IP address.
The feds can't match Tor activity if they don't know where to park the van. They also relied on Jeremy having a weak Wifi setup where they could watch his network connections. All of these other leads, including the personal details to match against, relied on first flipping Sabu.
The idea Tor setup is having an intermediary isolating proxy, and preferably one that is hosted offshore in another jurisdiction. For extra security, run a VPN connection over that, so it would look like:
laptop => OpenVPN or SSH tunnel => offshore server => privoxy (header munging) => VPN connection => tor => tor exit node => VPN server => internet
To prevent matching against a shared circuit, setup multiple tor circuits and random load balance across them, and do the same with the VPN.
Tor is just like a lot of other things, it can be setup and used in such a way where it leaks a lot of data and information, but it can also be used as part of a chain that makes the job of unmasking the user a lot more difficult.
But the talk was about "OPSEC for Hackers". If the hacker's adversary is already monitoring his internet connection for correlation to specific and ongoing attacks, he's pwned.
This was filed in court in at least one of the Anonymous prosecutions. Basically the investigators said "We observed the suspect walk into his house, we observed his Mac connect to his wifi, we observed Tor traffic over his wifi, and we subsequently observed the suspect's hacker alias join the IRC channel."
First, it's never good to rely on anything. Second, it's well known that people run tor gateways as a means to acquire 'interesting' traffic, and that probably includes law enforcement (though Applebaum does seem to have an honest aura, the project did originate from US government funding). Many people relying on tor probably do not realise this.
Be careful out there!
Also, one of the questions he answered at the end of the talk was about whether Tor could protect you against determined state actors, and he talked about a certain flaw where if you have control over a certain percentage of the Tor network you could infer people's source IPs. He also speculated on what levels of government Tor would or would not be a viable means of protection against, so I think he'd agree with you about the risks of Tor.