The feds pay for 60 percent of Tor’s development. Can users trust it?
washingtonpost.com
washingtonpost.com
I am really sick of these arguments. Do you realize how much research goes into Tor and how many university researchers are associated with it (Cambridge, Waterloo)? Furthermore, can you really think someone like the Tor core developers (Dingledine and Mathweson) can sacrifice their entire reputation just for putting a backdoor? The code is out there. They have a Git repository and they have an active, healthy developer community. It's not like TrueCrypt, where change logs read like, "Minor fixes" and there is no public repository in 2013.
Someone should bring proof of the alleged backdoors or just shut up. Because conspiracy theories are not only stupid, they are annoying. This issue has been addressed on the tor-talk list many times. Please show one iota of proof.
And I say this as a Tor user who has not only donated to the project but also runs a relay.
I also think, though, that the question isn't completely over-the-top given recent revelations. For example, you state:
> Do you realize how much research goes into Tor and how many university researchers are associated with it (Cambridge, Waterloo)? Furthermore, can you really think someone like the Tor core developers (Dingledine and Mathweson) can sacrifice their entire reputation just for putting a backdoor?
You're right.
But how many university researchers and mathematicians vet the security standards at NIST? NIST doesn't just take the math at face-value from NSA.
I don't think that Tor is compromised, but I don't think it's beyond questioning, either.
No, definitely not. Science should never be above questioning, or be subject to fanboyism.
My point was -- people keep bringing this argument up time and again but do not bring any proof to the table. The code is out there. Don't you perhaps think that the professors at some of the most reputed universities in the world who research on Tor would perhaps eventually find some alleged backdoor, given the code goes through so much scrutiny? I maybe wrong of course but some proof of this would be good. Honestly. And I am not being sarcastic, I have donated money and if I ever found out that something remotely like this is happening, do you think that people like me or the organizations who fund Tor will give it any more money?
It's a question of whether the idea is fundamentally sound.
You're routing your data through several strangers, who are all volunteers and may be individuals who support anonymity or governments who are trying to break it, relying on them discarding logs in order to preserve your anonymity. Since the data is encrypted, and routed between several nodes, you do have some redundancy in place in case one of the middle nodes is an attacker.
However, there are several problems. The data coming out of the exit nodes is unencrypted. Now, everyone advises you to always encrypt anything that will pass through an exit node, but that's not always possible. Some protocols just don't have widely available encrypted versions (like DNS), or even with encryption, where you are connecting to is leaked, as well as some information in things like the TLS handshake that may be de-anonymizing.
There are also lots of ways that data can leak at your endpoint. For instance, many programs may make DNS queries that don't go through Tor, so what you are looking up may be leaked.
Furthermore, Tor doesn't sent data at a constant bitrate. Someone who can monitor traffic on a large portion of the network can correlate it across points.
Finally, due to the nature of routing traffic between several points, a fairly limited number of exit nodes, and the encryption, Tor is fairly slow. So most people won't really be able to use it on a day to day basis, making mere use of it somewhat suspicious, and likely to subject you to more scrutiny.
None of these are fatal flaws, but they are some fundamental weaknesses, and many of them can't really be fully fixed.
I think that focusing on widespread, end-to-end encryption, rather than anonymity service like Tor, would be more valuable. Yes, you will still be vulnerable to metadata monitoring, which is a problem, but it would help a lot more with the content of your communications.
The problems it has are clearly discussed in multiple places -- websites, research papers, etc. I don't think it can be more sound than that.
> You're routing your data through several strangers, who are all volunteers and may be individuals who support anonymity or governments who are trying to break it, relying on them discarding logs in order to preserve your anonymity.
It doesn't matter. That is the entire idea behind Tor.
> However, there are several problems. The data coming out of the exit nodes is unencrypted. There are also lots of ways that data can leak at your endpoint. For instance, many programs may make DNS queries that don't go through Tor, so what you are looking up may be leaked.
The TBB already takes care of this. So unless you use some crappy third-party browser, you are safe from these problems because they know about it and they have been fixed.
Of course the exit node is not something you can trust. But your argument does not always hold true because TBB ships with HTTPS Everywhere by default. So almost all major websites will automatically use HTTPS and therefore the exit node sniffing your connection is rendered useless. Now if you are sending out your information over plain-HTTP, then yes, you will have it compromised.
> Furthermore, Tor doesn't sent data at a constant bitrate. Someone who can monitor traffic on a large portion of the network can correlate it across points.
Because Tor is a low-latency network, timing analysis is easy to perform if the entry and the exit node are controlled by the same entity. Now this depends on whether the NSA runs Tor exits or not and I cannot answer this question.
> Finally, due to the nature of routing traffic between several points, a fairly limited number of exit nodes, and the encryption, Tor is fairly slow. So most people won't really be able to use it on a day to day basis, making mere use of it somewhat suspicious, and likely to subject you to more scrutiny.
Anonymity loves diversity. Tor has a diverse userbase and it is getting better. I do not think it is that slow -- surely we can't expect it to be as fast as your normal internet connection -- but it is not bad either. I think FWIW, given what it does and what we need, there is no better solution so I think we might as well stick to it than trusting some proprietary software.
If running Tor exit nodes is what is necessary for the NSA to snoop on traffic, why wouldn't they do so?
If your security depends on "well, the NSA isn't going to run a service they need to snoop on your traffic", you're doing it wrong.
> I think FWIW, given what it does and what we need, there is no better solution so I think we might as well stick to it than trusting some proprietary software.
That's not really the choice. It's a question of where your priorities lie.
I don't think our biggest threats to privacy are in the NSA monitoring merely who we connect to. For some users, it's a substantial threat; for instance, for protesters in Iran, it may be a big problem, and for them Tor is invaluable (especially since it's unlikely that the Iranian government has the same resources to attack Tor that the NSA does).
Instead, our biggest (technical, as opposed to political or social) threats to privacy lie in a few places:
1) Email. Email has all kinds of problems (it's not verifiable, no good identity management, spam, and it's unencrypted in transit in many of its hops). 2) Google, Facebook, Yahoo, Twitter, etc. Big, closed services, that lock you in, and provide centralized places for monitoring. For many people in my social circles, Facebook is their primary means of online communication. 3) Web tracking: cookies and other web de-anonymization techniques 4) Unencrypted HTTP 5) Identity on the web. Almost every account you create requires an email address, which can trivially be used by the NSA to correlate data between accounts. Anonymous email services can be used to fight this, but managing databases of email addresses, usernames, and passwords to preserve anonymity is beyond most people's capabilities. The solutions to this are mostly to use one of the big services for login, which of course down't solve the anonymity problem at all. 6) The phone system. Telecoms have demonstrated repeatedly that they're more than willing to hand your data over without a court order. Tech companies at least act embarrassed about it in public; phone companies just lobby for retroactive immunity to keep themselves safe from their customers.
There may be more that I'm not thinking of, but those are some of the biggest.
Tor does very little to protect you from these kinds of threats. All it protects you from is someone monitoring who you are connecting to; but if most of the traffic they are interested in is to Google or Facebook, they don't need to attack it by monitoring your connection, they can just get the data straight from the endpoint.
I think that the biggest things we need, to preserve privacy, are replacements for many of the above problems, that even our grandmothers can use. Sure, a few privacy conscious geeks, a few Iranian protesters, some online griefers, some drug dealers, and some pedophiles can take advantage of Tor. It provides a useful service for some, but a fairly small portion, of people.
Getting ubiquitous encryption, better key management and identity management, a return to federated or peer-to-peer services rather than a few large centralized players, and getting all of that widely deployed and usable by your grandparents, are what we want to really improve privacy and security.
You realize there are tens of thousands fiber lines in a city, right? Tapping fibers going from ISP cusomers to PoPs isn't scalable.
Hiding the equipment from the people working every day on splicing smaller fiber cables to the trunks would also be a major issue.
The trouble with that is that often the illusion of security/anonymity is worse than not having it at all. See also: Enigma
Definitely don't trust proprietary software though.
DNSCrypt encrypts communication between the user and the OpenDNS servers.
In 20 years Tor will have served its purpose and the government will have a new strategy. Maybe they'll just try outlawing encryption again. Certainly we'll forget all about the Clinton era by then.
Or they can just find existing exit nodes, and ask the data centers to install splitters for them.
Exit nodes and relay nodes are not secret, so specifically targetting them for analysis would be pretty easy.
Well. Maybe not as much anymore. But exactly that has in fact happened in the past: https://en.wikipedia.org/wiki/Data_Encryption_Standard#NSA.2...
Here's just one such paper.
http://www.cl.cam.ac.uk/~sjm217/papers/oakland05torta.pdf
You don't need backdoors in the program to make Tor less anonymous. You work with traffic patterns & other information gleaned from the network. You can also congest the network & find out more information that way.
Tor is useful but you're kidding yourself if you think it protects you from the NSA. And please, shut up about conspiracy theories. Many of these theories have become verified fact, and the rest are up to bayesian judgement. You should brush up on your history starting circa WWII & learn to what extent the intelligence communities go to have an upper hand. Tor is low hanging fruit compared to breaking certain cryptographic primitives.
I believe nobody sensible involved in Tor would claim it provides strong anonymity. Anonymous networks are a trade-off between efficiency and anonymity. Because it is efficient enough to allow web browsing, Tor provides relatively weak anonymity.
Isn't this exactly what someone would have said about the NSA spying on us even just a few months back? Did we learn from that AT ALL or just anytime we don't like a theory we will call that person a tin foil hat wearing nutcase?
The NSA is a different case. We do not know anything about it, except from the leaks. But we do know things about Tor.
a). Actively developed, follows the best principles possible. Open discussions in IRC, active mailing list, developers who respond to queries.
b). Highly researched by some of the best universities in the world. Cambridge and Waterloo come to mind instantly.
c). There has not been a single case of mistrust on their part that should make someone suspicious about them.
The day Tor does something like this, not only they lose their funding, they lose users and they become a dead project. With so much reputation at stake -- and they are respected people in the community -- Dingledine and Mathewson doing something like this? I don't think so.
This story is neither helpful nor enlightening in that regard as it has no evidence. Just mere speculation and insinuation.
There is value in discussing these conspiracy theories, if only to disseminate information and allow others to determine their own risk assessment. The conflict of interest inherent in a law enforcement agency funding a tool for circumventing detection is enough to raise alarm bells for some classes of users.
Completely agree, but its a little silly for the person who was just proven wrong to continue to heap the burden of proof on everyone but themselves.
I'd be more wary of NSA contributing code directly or through anon HUMINT accounts, hoping some of it slips through.
Trust is a funny thing, isn't it? It doesn't respond to demands or browbeating.
This is why open source crypto is so important these days.
https://www.schneier.com/blog/archives/2007/11/the_strange_s...
The source is there. The standards are there. We know that timing attacks may be possible. The rest is just a matter of audits. Questions are good, but they are just questions until someone looks at the code, the implementation, the design, and the rest and says "here's a problem."
When you speak of it only being a "matter of audits," that standard breaks down when there are none possible (or at least available) with these organizations and agencies, and that is the fundamental ingredient that produces suspicion.
At the end of the day, though, the distinction I'm drawing is one between technical problems and people problems. However, recent events have taught us that the people problems in crypto are real, where before they had only really been suspected or at least minimized.
I was thinking of just this the other day. In light of all the recent news, what's people's feeling about TrueCrypt. Elaborate ruse by the NSA or really good software that is very secure?
But he is working on Tor, which can be attacked by global passive attackers, something that in past consider very unlikely to exist. We know today nsa is a global passive attacker.
And today, mixmaster still hasn't been working, and the size of email anonymity networks is so small, to be useless.
It all worked out very nicely for the nsa. And what, they just got lucky? No conspiracy?
A lot of companies probably should, or at least severely limit its use.
By realizing my comment was tongue-in-cheek ;)
Just curious, where do you run your relay? Is it under your home internet connection? Does it ever give you any trouble (authorities come knocking the door, etc)?
'pg: Find a way to make it stop or I will use HN less and less.
This might work on your mother, but is less effective on people who don't care about you.
"Against [Law Enforcement Officials], it's fine. Against a nation-state, the TOR network has insufficient resources and has sufficient bad actors that it is not actually secure. So if you're going to hack the shit out of the NSA and do really really bad planning and do not actually evalute the targets you are after, you will go to jail."
He also expands on how to unmask a user by controlling both the exit and entry nodes:
"So if you can purchase 300 VPS accounts at $5 each then you can set up 1% of the TOR network and statistically, over a month, you will be able to uncover a large number of users. [...] You are better of selecting your targets so they will not be state actors."
TOR is not perfect. The NSA, or any other sufficiently large global passive adversary, can defeat it, with global timing correlation. However, a connection over TOR probably requires more resources to track down than a direct connection. On the downside, a connection over TOR may go through a foreign country, which removes any domestic safeguards the NSA does have in place, subjecting it to indiscriminate spying.
TOR is also insufficient on its own. You need to use strong crypto, and be careful of your privacy in other ways (cookies, caches, etc) on top of it.
Bear in mind that Tor avoids making circuits in the same country, specifically to avoid things like this. You'd need at least two large farms.
I'd love to see this kind of evidence end up in court. It would be hilarious to see them try and prove anything beyond reasonable doubt with millions of random logs.
<conspiracy>Maybe that's why they continue to fund it...</conspiracy>
then, shit like this happened: https://www.eff.org/pages/tor-and-https
I understand that using HTTPS through Tor can provide to NSA your rough location (entry node) and the site you are browsing to. But your user name and password will be safe (assuming that NSA cannot hack HTTPS). Using HTTPS only can provide the same information to NSA as the HTTPS+TOR, so for httpS sites Tor does not provide extra security against NSA?
If my understanding is correct then Tor would provide only value when using Tor services, aka onion sites, but not when using public Internet services?!
I would appreciate if somebody could provide their expertise on this.
I imagine the NSA would task a team of researchers to analyze the source code, find a vulnerability, and develop a tool to exploit it. I imagine they'd then hand the tool over to a team to deploy and operate it.
No person from the TOR community would need be involved or made aware. And, assuming the NSA was the only one with the exploit, there would be no reason to stop funding Tor, since it advances American interests without (now, thanks to the exploit) threatening them.
I always thought that was a pretty neat attack.
Is it conceivable that nodes could hold packets for a period of time long enough that traffic is "really" mixed with other traffic? Or does this just add the equivalent of a random delay which is easily defeated?
I don't, however, trust it to do anything else: namely, I don't think of it as a security panacea. Goals of security are confidentiality, integrity, and availability. Anonymity is only a small part of confidentiality: tor provides a somewhat reasonable guarantee (i.e., much better than nothing or use of proxies) that I can anonymous browse censored web sites. However, alone it doesn't in any way help with secure communications to others, it doesn't ensure that the sites I am visiting aren't MITM'd, it does not protect against attacks that reduce availability of end points.
Since online content censorship is not currently a big problem in the United States -- but now a huge problem pretty much elsewhere, including in the Western World -- in most cases it isn't really an ailment for the ills inflicted by the current government overreach.
Also, it's entirely possible that the government is using the same software (or a slight fork) on a different network, but using the public deployment of Tor as a way to easily get public review of the cryptosystem.
http://blog.erratasec.com/2013/09/tor-is-still-dhe-1024-nsa-...
* I'm not accusing anyone. It's easy to believe so much in propaganda that you start to spread it too. One even honestly creates more unrelated reasons to believe. I know that I'll never trust RSA as much again, and will probably migrate to 3kb keys.
<conspiracy> With that much information on hand I could play the foreign stock markets like mad. And also forex. It will be sane for NSA to have capabilities to crash a potential adversaries currency and stock market. </conspiracy>
1) It's highly possible that there are federal government agencies with knowledge of encryption and security beyond the current state of the art in academia. There could be deliberate vulnerabilities that even the most highly regarded researchers/academics in the field could not detect.
2) Even if you trust the source, the source can be compromised elsewhere in the toolchain (the compiler could turn safe code into malicious code). Unless you trust every element of your toolchain, you trust nothing (from a mathematical sense -- of course it's much more complicated, and thus less likely, to compromise Tor through its own source code rather than gcc's source code).
That's true, but Tor uses encryption that is common in many other products. Even if it were a privately owned product, it probably would have been implemented in a very similar way.
> Even if you trust the source, the source can be compromised elsewhere in the toolchain (the compiler could turn safe code into malicious code). Unless you trust every element of your toolchain, you trust nothing (from a mathematical sense -- of course it's much more complicated, and thus less likely, to compromise Tor through its own source code rather than gcc's source code).
OP is not talking about whether or not perfect security is possible. They are talking about the possibility of Tor specifically being backdoored, since it originated within and is funded by the U.S. government.
While I agree toolchain compromises are a concern, this particularly famous one of backdooring a compiler has a counter: http://www.dwheeler.com/trusting-trust/
How many users are downloading and compiling source? If you're running a binary you didn't compile, it's really no different than being closed source. (Unless you get the MD5 sig from an independent, trusted third party, and verify yourself)
a). For all the bundles, they are signed by the Tor developer who packages them. The signatures are clearly visible with the downloads.
b). Most importantly:
Tor is moving towards deterministic builds: https://blog.torproject.org/blog/deterministic-builds-part-o...
Different people build the Tor Browser Bundles on Gitian (look it up), and they will have the same hashes. So unless ALL of these people are lying, if their hashes match, you can be convinced that it is the same binary as you would get by compiling it.
That writeup is really fucking cool. You should submit it as its own story!
It goes back to the design of DES - the NSA influenced small design changes in the SBoxes that had implications that only they understood. This gave an advantage, even though the algorithms were completely "open source".
http://en.wikipedia.org/wiki/Data_Encryption_Standard#NSA.27...
In that case, they made the encryption STRONGER. But they certainly showed how that type of influence could happen.
I don't happen to be enough of a conspiracy theorist to believe that they're messing with Tor - there are better ways, especially when a vast majority of the traffic isn't through Tor.