Tor and HTTPS
eff.org
eff.org
SSL certs require cooperation of a trusted registrar even for the biggest companies -- Google's is signed by Equifax, for example. Given what we've seen in the last few days, requesting keys from the root CAs is a no-brainer.
For Tor, a bunch of attacks are possible by owning only a small percentage of all nodes. Recently, Tor was issuing a "call for relays" due to a dwindling number of participants that was endangering the network. Considering that Tor came out of Navy research, if you don't think they have a statistically interesting number of nodes, you're crazy. If they don't, it's only because they don't think that Tor is an interesting source right now.
TL;DR: Security depends on your threat model, and while I think that Tor and HTTPS provide strong protection from run-of-the-mill attackers, I don't think that either provides meaningful security if you're worried about the NSA.
I concur with your statement that SSL isn't really secure end-to-end communication when 3rd party certificates are involved.
Also, if your platform supports it, Gmail has perfect forward secrecy meaning that even if the NSA records all HTTPS traffic to gmail and later demands Google's private key they can't decrypt any of that captured traffic.
Tor on the other hand is a problem. It has several fundamental flaws as you pointed out like by controlling some gateway nodes and a few others you can start breaking any sort of secrecy that you would get from Tor. Really the only good thing about Tor is that it's well known. I really wish Tor would just die and people would move over to something better like I2P where it's an anonymous network, not just a kludged together anonymous proxy with hidden services slapped on as an afterthought.
Since I don't seem to be understanding the associated technology as well as I thought I was, could you point me towards some relevant reading on this topic? How/Why are the current implementations of HTTPS considered to have perfect forward security?
As for subpoenaing keys: Most CAs will allow for you to generate your key pair and certificate signing request on your own hardware. You'd then submit the CSR which the CA would in turn generate a signed certificate from. The private key should never be shared with the CA. In order to eavesdrop on communications, the NSA would then need to subpoena each targeted company's key. Wide reach is easy (go for the 5-10 biggest fish), comprehensive reach nigh impossible.
[1] http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-se...
Getting a root's key does not enable them to decrypt the traffic. Getting the server's SSL private key USUALLY means you can retroactively decrypt, but it is possible (though uncommon) for servers to be configured to use ephemeral keys (EDH modes) which provide perfect forward secrecy (that is, the property that the session key can't be recovered even with later compromise of the server's long-term key).
Interesting sidenote: AFAIK there are no widely-supported (TLS 1.1 or below) methods of mitigating the BEAST attack while enabling PFS - those modes are TLS 1.2+ which isn't widely spoken yet.
This is all irrelevant though. The issue is with the tech companies giving them the plaintext data themselves. No amount of transport-layer encryption helps with that.
You have to stop using US services.
A certificate is an attestation (signature) by a CA's private key that a given PUBLIC key is yours, that anyone with the CA's public key can verify.
The CSR does not contain your private key.
NONE OF THIS MATTERS. This is not about bulk-decrypting SSL, though I'm sure NSA does that when and where they can, too. This is about coordinated, automated, integrated methods of transmitting the plaintext.
Why should they bother getting a key and scraping gmail's payloads when they could just have Google give them an API? Furthermore, this method would continue working perfectly even ifwhen services switched to ephemeral key modes that provide PFS.
With the location information it is possible to correlate the exit information via pattern matching, though it would take considerable analysis, this can be done by logging volume and timing information on the two sides. I am sure there are even better techniques to analyze exit/entry correlations, especially if you're not using a secure browser.
So having a private VPS doesn't really matter, in fact it can make matters worse because you are adding layers that can be "watched" before you hit an entry node, the more data that can be logged the easier it is to track.
You're best option is to choose random nodes, connect at random times and also look into using Tor bridges. If possible using several different IPS's or even better random wi-fi hotspots, though this is hardly convenient for most users.
Tor bridges: https://www.torproject.org/docs/bridges.html.en
Whitepaper on Tor passive logging attacks (pdf): http://people.cs.umass.edu/~mwright/papers/wright-passive.pd...
I've thought the same. But I've also thought that if this is indeed possible, why does Silk Road still exist? Or does this analysis only apply Tor clients connecting to websites, and not Tor hidden services?
For intelligence agencies, having evidence (even if inadmissible) of smaller crimes, is just leverage -- and leverage against people that might be able to render useful services (eg: provide deniable assets for framing someone with drugs).
Now, if Silk Road did most of it's trade in weapons grade plutonium, things might be different.
Remember, the whole reason the NSA-thing is a news story, is that it is illegal wire tapping. The feds can't use this for setting up a case.
However, I not sure its that easy to understand for those who don't know what "location" means, and the text is slightly small and hard to read. It would be a great improvement if they showed a small help text if one hovered over a label inside one of the yellow boxes.
Still, a very excellent job of EFF.
Also, using a help window when hovering would be a quite better UX than a glossary.
Seeing as HTTPS sites could not previously share an IP address, making it obvious which site communications with any given IP address was directed towards, an extension was developed that now sends the desired host unencrypted before the encrypted package.
This doesn't yield any more information that could previously be derived, but does allow you to serve as many HTTPS sites from a single host as you wish.
Note that you can reduce your costs by using spot instances.
If the NSA was to create tons Tor nodes (enter, exit, and relay), the onion may be broken.
Tor is by no means perfect. It is only obfuscating.
It is easy to see how this is broken if you click the TOR button on this thing and then imagine the TOR nodes say NSA on them.
I think it is more fun to imagine security this way (extremely challenging and like you are protecting yourself from the perfect attacker, and the NSA is a good face to put on the perfect attacker). People don't realize how much trust they are putting in their hosting provider, cell carrier, etc.etc. It's insane.
That means that no node knows the source of the traffic, and only the exit node knows the destination.
For the NSA to effectively monitor Tor, they'd need to run a large proportion of the nodes - one paper thought it would require an attacker to run at least one third of the network.
It would be really interesting to determine how much this would cost
The susceptibility to this kind of attack is a big part of the knock that a lot of people have against HTTPS. It's generally been ignored as "too hard to pull off" - but it's also generally been assumed that your own government won't bother recording your communications without probable cause.
Anyway, unless they were targeting a specific service (which they usually aren't, they usually target a person) it would require too much effort to set this up for all the secure services they use.
Running an exit node may be a different story. You could get false DMCA takedown notices or get charged with someone else's crime. Think of it this way; you're running an open proxy. Uses of Tor can send any traffic through your connection. That being said, some ISPs are ok with it, others won't tolerate it.
I suggest you checkout https://blog.torproject.org/running-exit-node if your really serious about running an exit node.
But you could use an anon currency-exchange or currency-bridge like paysafecard.com to obtain some value and obtain bitcoin with that value and never use that bitcoin key again to avoid that.
If not there should be. You send X amount of bitcoins to a middle man who then gives you X amount back. Technically they will be different coins and they'll go to a different account #, so you can't trace anything.
(IANAL, may not be legal in all countries)
In terms of trust, your mileage may vary.
In someone else's country, maybe not.
FYI: there's https://pay.reddit.com/ but it doesn't work with HTTP Everywhere because its on a different domain.
http://www.bivio.net/products/dpi/
http://arstechnica.com/tech-policy/2010/06/deep-packet-inspe...
It makes imho no sense to authenticate using Tor.
Does that count as HTTPS, or are they referring to 'SITE.COM' having an HTTPS certificate?
Is it possible to use Tor and a VPN together?
[0] e.g. I use https://ipredator.se
If you use Tor to connect to your VPN-provider, you can hide your location from your VPN-provider.
Since your VPN-provider may have payment information from your creditcard it makes no sense to use a VPN and Tor together, its just a cascade.
What about protection from the average NSA sysadmin or analyst with slightly less moral fiber than Edward Snowden? (or gambling debt, or a mental disease, or an obsession with your significant other etc.)
And since its shared with amongst both the evasdropper, potentially NSA knows your location even if you use Tor. They should have indicated that too I guess.
And the illustration should add that both the NSA eavesdropper(s) would get that information actually. Since data is shared.
remember - what the nsa wants is both your location and the site. your location alone only means that you were using the internet (and tor, which itself might be regarded a suspicious). the site alone only means someone was using the site. what the NSA have to do is connect those.
so everything depends on whether the two NSA people can "join up the dots" (graphically, in that diagram, the dark blue dots joining them). because there's nothing "obvious" that tells them that the message with the location is connected to the message with the site.
if they can't make that connection, then they don't know anything useful.
but if they can make that connection, then they know that you (well, someone at your location - an open wifi might give you a little deniability, for example) looked at that site.
the way they might be able to do it is by comparing traffic patterns. if they can show, for example, that every time you send a request, the site receives a request, and if that happens again and again, so reliably that it cannot be chance, then they can make the connection.
so it depends on things like the frequency with which you look at the site, the amount of (tor) traffic when you are around, and the ability of the NSA to assemble and correlate large amounts of data.
[disclaimer: not an expert; i don't know the current state of play on how bad a problem this is; i just know it's a known issue. and if i were going up against the nsa, i wouldn't trust tor alone - i'd use an anonymous, disposable, portable connection device, and keep data to an absolute minimum.]
That way you would obfuscate your endpoint against your vpn endpoint/provider.
It would add no further benefit to location obfuscation with Tor, since your VPN-provider will always snitch on you when opposed with lethal force.
Addendum for achievement: Connect to Tor from a public accessible network/wifi that is free from surveillance using a pristine installation and never use that network-device again.
Addendum 2: If you use the network device twice, you may achieve only pseudonymity.
If you choose to communicate a second time from the same endpoint with the same equipment you may achieve only pseudonymity.
Since Tor doesn't limit the encapsulated protocols, it depends on the implementation and awareness of the user and you can't put a number or percentage on that.
Imho the Tor-role has changed, it provides access against censorship, DPI, region-partioning and hidden services. Simply try to access youtube or any other global service via different tor exits, that may be intresting, not from an anonymity point of view.
At this event your anonymity becomes a pseudonym.
The next step would be to try to reproduce or predict behavior and setup a trigger for that information.
If the loss (compromise) of anonymity or pseudonymity may lead to imprisonment, torture, assassination or death this maybe an issue to consider.
If you try to obfuscate your access to porn, it is a completly different story.
Here you go:
http://diyhpl.us/~bryan/papers2/security/Towards%20an%20info...
http://diyhpl.us/~bryan/papers2/security/Towards%20measuring...
http://en.wikipedia.org/wiki/Degree_of_anonymity
Also this is fun: http://www.gwern.net/Death%20Note%20Anonymity