Russia offers $110,000 to crack Tor anonymous network
bbc.com
bbc.com
That doesn't quite fit into hacker culture at all.
If they aren't going to hire a well-paid hackers full-time like the NSA does to do the same thing, then at least make the prize significant similar to X-prize.
But I've got no idea how much that vulnerability would actually go for. Millions? Tens of millions? Anyone with a stronger understanding of the market have any rough estimate?
"The reward of $114,000 seems pretty cheap for this capability. And we now get to debate whether 1) Russia cannot currently deaonymize Tor users, or 2) Russia can, and this is a ruse to make us think they can't."
https://www.schneier.com/blog/archives/2014/07/russia_paying...
I wouldn't disclose something like this to the big boys , as it would reveal far too much about my own capabilities and/or connections.
Even if they could ... why say anything at-all? Perhaps - to encourage use of an exploitable method of communication, but even-then why would somebody looking to hide use a form of communication they know is actively being targeted by the government they're looking to evade?
If anyone wants to do this, I recommend shopping around first ;P
"In its 2013 financial statements, the Tor Project - a group of developers that maintain tools used to access Tor - confirmed that the US Department of Defense remained one its biggest backers. The DoD sent $830,000 (£489,000) to the group through SRI International, which describes itself as an independent non-profit research centre, last year. Other parts of the US government contributed a further $1m. Those amounts are roughly the same as in 2012."
I'm not familiar at all how those founding works, could someone, from US, explain how and why US government is giving money to TOR?
TOR as a recruitment tool?
1. Help political dissent in countries that cannot crack tor.
2. There's a reasonable chance that they can crack tor, at least to some extent ,especially with the help of the 5-eyes countries. Having that ability while "evildoers" think tor is safe is valuable.
"Tor was not started by the US Navy. The US Naval Research Labs (NRL) started a project in the 1990s called onion routing7. Tor uses the basic onion routing principles and applies them to the Internet. The volunteer Tor group started in 2001. The formal charity, The Tor Project, started in 2006. We continue to work with Dr. Paul Syverson from NRL on improving onion routing and therefore Tor."
If you ignore some of the drama, Pando has a very long and fairly comprehensive look at its funding (at least, it seemed comprehensive to me, I am not a Tor expert) - http://pando.com/2014/07/16/tor-spooks/
Yes, the government funds Tor. Pando thinks that all of the US government is akin to the NSA and wants to spy on people. This is not how it works. The government is not just one body and there are many parts of it that probably don't agree with what the NSA is doing.
Yes Tor is funded by the US government. My question is, how does it matter? The protocol is open. The code is open. There are research groups at some major universities researching on Tor.
Let the code speak, not fear mongering.
This, I think, is a very important point. It is beyond naive to assume that a large body of structures that together are called "the US government" is a homogeneous entity that can be ascribed goals as if it were a single agent.
There is a very widespread and dangerous misconception that Tor is a one-stop shop for secure or anonymous communication. This is not true. You need to encrypt your messages separately. When outside the onion network, Tor actually exposes all content sent through it to a third-party, the exit node. This means using Tor may be more dangerous than not using Tor if you don't know what you're doing.
That's very interesting. Could you provide sources that back this up, especially the employment history of TOR developers?
$100,000 is for a research paper.
Translation of the auction lot title: "Research the possibility of getting technical information about Tor users (their hardware)".
Here's the talk that claims the possibility to deanonymize Tor users for less than $3,000 http://web.archive.org/web/20140705114447/http://blackhat.co...
There are published papers on the topic e.g., http://www.syverson.org/tor-vulnerabilities-iccs.pdf
Lesson one is that Tor guards against traffic analysis not traffic confirmation. If there is reason to suspect that a client is talking to a destination over Tor, it is trivial to confirm this by watching them both. </quote>
Imagine if the CIA offered $1M to crack TOR. They would be the laughingstock of the intelligence community.
I think there is something else going on. I would not touch this. It looks like bait.
If the attack is particularity disastrous then there will likely be a large fork. But once a project is started and a community built its unlikely that force will be stopped.
With the Russian word for torus being "тор" which could be transliterated as "tor" I see why people might get excited. But I'd like to see something more concrete than word play to support the news articles' theory.
This seems rather bizarre... ~$5500 cannot simply be a symbolic sum to deter idiots.
[1]: http://www.helsinkitimes.fi/finland/finland-news/domestic/11...
Nowadays most of them emigrated and those who don't, they mostly will not work for KGB spooks.
What is the normal process for selling these exploits? They'd want to see the exploit first, I'm guessing in person, then they transfer over the money, then you give the code and details?
What if someone wanted to remain anonymous during the transaction? What would be the best method of doing that? You couldn't really send a friend because it might be easy to trace back to you, and it would be hard to trust a stranger.
They should just provide funds on a site such as https://hackerone.com/
I really wish the US government would offer bounties for their sites and systems. Right now if people try to exploit a US government system, even if they have the intention to properly disclose the vulnerability they face prosecution.
Look no further than the tender page: http://zakupki.gov.ru/epz/order/notice/zkk44/view/common-inf...
Here they explicitly state that it's a tender for 'Выполнение научно-исследовательской работы, шифр «ТОР (Флот)»' (Research and Development works, code "TOR (Navy)")
Then it's a closed tender (stated in the same document), meaning that they come up with a list of organisations they invite to participate in this tender. No organization they did not invite can participate.
So you see this is nothing like a bounty.
>it seems like researchers have to pay to enter
I wager they are required by law to demand some sum of money, maybe this sum is determined as a function of a tender value; I don't believe there is some additional meaning to asking people to pay 5500 usd to participate in a closed tender.
To reiterate:
1. Get the Tor user in question to visit a website controlled by you ( or at least a site where you can cause JS to run; such as an advertisement )
2. Know which ISP the user is on, and be allowed to install a high speed device watching all traffic for a sequence of specific sized packets.
3. Use the JS to send a specifically crafted sequence of sized packets with specific time periods in between them. After sending this preamble, send sized packets to send the 'pseudo identity' of the user ( whatever pseudonym you wish to attach back to their real IP )
4. Use your monitored ISP device to detect the preamble, then log IP and the data.
Note this method could be done en-masse and would only require high speed FPGA devices at each ISP "trunk". Inject JS code correlating users back for any system which you wish to identify the users.
Done. Whichever Russian demonstrates this and wins the $100k; throw me a bone please. :)
So you cannot find the identity of a tor user.
* Either the TOR user is a 'newbie' (no offense), and he will use the tor package wich come with a version of firefox where JS is disabled by default
* Either he is a seasoned user and knows that disabling JS while using TOR is mandatory.
If you have to know already which ISP the suspected user is using, you're not really finding the user, you're just confirming their identity.
And as others have pointed out, running with JS enabled is a vulnerability. If the user is that careless, it's probably easier to get them to load a particular file over plain HTTP and just listening to requests for that file.
But suppose we broke it, now we have to fix it, right? Start padding everything to power-of-two size boundaries with a minimum of 16. Or if that would make Tor traffic too identifiable, then instead add random()%packetsize padding to each packet. Either would reduce the number of detectable packet sizes below a 1500 byte MTU to 8 at the cost of less than doubling the bandwidth consumption.
How easy would it be to do this (even with JS on)?
And anyway why cant people then just use Freenet or some such network?