Privacy Router Anonabox Gets $600K in Crowdfunding and Huge Backlash
wired.com
wired.com
Maybe we, as the FOSS community, need to start utilizing crowd sourcing more. Maybe we can use the marketing from Heartbleed etc. to launch a Kickstarter to audit OpenSSL, and use the NSA revelations to launch a Kickstarter to run more exit nodes (which are depereately needed -- about 1k nodes for 2M users). The project to audit Truecrypt seemed to reap the benefits of this quite effectively.
I'm not familiar with the TOS for Kickstarter so maybe this isn't possible, but clearly the general public clearly has more interest than we (I) thought. They just don't know how to channel their support effectively.
If not. Someone should build one.
Here's the link:
In fact, there is a page for the Tor community, so if you want to support them, go there and give them some money ;)
If it's not permitted on Kickstarter, we would probably do better to convince them to allow it, with certain restrictions of course. A purpose-built site simply wouldn't have the traffic to produce that kind of funding for smaller projects.
What is the ideal ratio of exit nodes to users? It seems that too close to 1:1 is going to be almost as bad as too few nodes, at least to my (not particularly well versed in Tor infrastructure) thinking.
[0] - http://arstechnica.com/information-technology/2014/05/openss...
The big thing is that most FOSS fundraisers adopt the same perks used by proprietary software. These are typically vanity rewards or early-access. Early access is straight up anti-social when it comes to FOSS. Giving people the ability to steer the project makes a lot more sense.
Of course no one has software for that, so I had to make my own.
Successful fundraiser: http://igg.me/at/rtlsdr
Backend: https://github.com/keenerd/featuritis
Old-ish progress report: http://kmkeen.com/igg-report/
I've seen those devices retail for as much as $30. $50 isn't unreasonable. That price should ensure they can deliver.
After it's done with Germar, the reddit mob should take its pitchforks over to Starbucks. What a scam that place is. Slapping their logo on coffee from some third world country, claiming they made it. Outrageous!
You understand that your router came with the username 'admin' and the password 'password' when you bought it right?
(don't get me wrong, there's some weird stuff going on with that kickstarter, but the password/username thing is such a strawman it hurts me to see people talking about it)
I've literally never encountered a router that didn't have a default password on it.
Some times service providers will set a random (or user) password before shipping the device, but they all reset to the default one when you factory reset it.
I thought it was just universal.
I'm actually quite interested to know which manufacturers ship a custom rom per device with a unique password.
The fritz box default password is 'password'.
http://www.routeripaddress.com/routers/10609/avm-fritz-box-f...
A lot of devices running OpenWRT that are shipped these days (e.g. mainly routers of some sort) come with WPA-PSK encrypted wireless network, not an open wireless network. It's common to see the password put on a sticker on the device or supplied with it, and it's usually algorithmically or randomly generated.
Because the default wifi is open anyone in the local area will be able to connect to the device, passively sniff wireless traffic going through the bridge etc. before it hits tor, including any usernames and passwords used to log into the router other than through SSH.
So I agree that making a fuss over the price is silly. Especially since their initial goal was low. A $7500 kickstarter to fund a bit of developer time to put together something nice is not unreasonable. Everything beyond that should pretty much be considered pre-orders.
But the lies and deception, false claims and apparent total lack of understanding of how to make the device secure on the other hand, goes far beyond stupid.
The source shipped so far is a bunch of config files that appear to be hand-loaded onto devices running an existing image according to a forum post[1]. You would expect to see a firmware image built using OpenWRT the imagebuilder or complete toolchain with some degree of code audit if you want to promise no backdoors.
The firewall configuration uses both OpenWRT's UCI and a separate unintegrated iptables script. The configuration means that the device will leak protocols other than TCP and UDP with specific destination ports out through the wan interface onto the other network or the Internet.
There's a hard coded root password in the build. OpenWRT doesn't have one and asks you to set your own.
The lan side wifi is completely open and unencrypted. If you were to use this device thinking you're safe, anyone can sniff what you're doing if they're within wireless range before it goes through Tor. Because Tor provides transport encryption, almost all .onion sites use HTTP.
The device exposes port 9040 on all interfaces, this is the tor socks port. I don't yet know whether this could be used to get to the lan side network (e.g. 127.0.0.1 HTTP interface) from tor as I haven't looked into it yet by chaining proxies as I haven't had time, but I don't think it's needed.
There's hard-coded host key material, the startup entropy state is unknown - basically lots of potential crypto problems that to be honest can be saved until we see actual thing and it's code.
From the config files it looks like the hardware uses kernel modules that load firmware in binary blob form from the device's flash memory. This is common in routers and makes kernel upgrades difficult because the blobs are designed for specific kernel versions.
The source code for the device's OS is not available. There's an upgrade firmware available but looking at the firmware using various extraction and carving tools yielded nothing. Some initial analysis shows that there's a prologue and a higher entropy possibly compressed or encrypted component. This is not an open hardware platform.
Without some serious modifications the device will almost certainly suffer from a transparent proxy leak problem[2].
In conclusion the technical claims don't match what has been provided at this stage. I'd be quite happy to discuss things with the developers, but fundamentally this project is not going to deliver the anonymity customers have been told they will even if the security problems are fixed and the source for everything is opened up. I'm a bit disheartened that they're taking the money and going to ship, but I accept that it's hard to turn down half a million dollars.
[1] - http://www.torouter.com/developer/showthread.php?tid=4
[2] - https://trac.torproject.org/projects/tor/wiki/doc/Transparen...
Coming to the technical aspects of the box, the product is fine in the sense that it does exactly what it says technically - routing your connection via Tor. Using verified credentials over Tor is a bad idea for that specific identity. If you're the kind of person who's going to buy this, I can take a guess that a large percent of the population wouldn't really know how it works and will think "I'm anonymous and private now, thanks to this little box" and use the Internet exactly as they were using it before - bad idea. The concept is flawed simply because a layman will use email and facebook over Tor and then bam! you can identify him instantly.
TL;DR - Operation successful, patient is dead.
> He is taking a bunch of things and putting them in a
> nice shiny box with almost zero end user configuration
> required
This is a stronger value proposition than most social media startups.About what is to invent or not.
> The concept is flawed simply because a layman will use
> email and facebook over Tor and then bam! you can
> identify him instantly.
This doesn't match my understanding of how Tor works, and I'm happy to be wrong on this. Do you mean that their actions when logged-in/authorized will be identifiable as them, or if while using a Tor service, if you make any identifiable internet calls, the whole of the rest of your session is identifiable?Still, it is an educating experience and the success of the kickstart is a great indicator of a itch the wants to be scratched. I think the way to view this is that people want to have privacy but are unaware of how to go about it or what it takes. We should view this as an opportunity to educate people about TOR and it's benefits and costs to each of us personally and as a society. Having people log into TOR to use Fb is dumb, yes, but at least they are using TOR at all!
In the product world this is generally known as every product ever.
iPod : a bunch of things and putting them in a nice shiny box with almost zero end user configuration required
Chocolate Bar: a bunch of things and putting them in a nice shiny box with almost zero end user configuration required
Tide: a bunch of things and putting them in a nice shiny box with almost zero end user configuration required
Bulk bins at a supermarket: a bunch of things and putting them in a nice shiny box with almost zero end user configuration required
hackernews: a bunch of things and putting them in a nice shiny box with almost zero end user configuration required
"Little did we know, it would take over four years, and a lot more tacos and beer, to create a device with the security, speed, functionality and easy-of-use that is the anonabox."
It certainly could have taken them four years, even if that only means they were tinkering with it for four years before they stumbled across a $20 board from China that finally made it feasible given their apparent lack of skills necessary to create a custom device. While I certainly won't be buying one of these, the description on the site seems fairly accurate. It's an OpenWRT-based router that they pre-configure to work with TOR. It seems like it probably does what it says.
I just don't see pitchfork-worthy issues here.
By our fourth round of prototypes we had created a model
with 64mb memory and a 580mhz CPU. This not only runs the
software well, it flies! At last happy with the board, we
designed a simple, minimalist case in plain white to house
it. The end result is our current model. We decided to name
it the anonabox.
They did not create the board nor did they design the case.I'm not sure about you but saying "we had created" is a pretty clear indication of where they thought they stood in the creation process here.
If Apple was buying fully-functional iPhone hardware that only lacked a case then it would be ridiculous for them to claim they had created the iPhone.
For you to say 'complete box' is misleading, because the plastic shell doesn't actually do anything, the bare board is functionally already complete.
The board is not a mere component, it is 95% of the end result.
And especially the wording of creating a model, then evaluating the performance of the board, then designing a case... creation can only apply to the uncased board in that paragraph. If they didn't make the board it's a pack of lies.
http://www.reddit.com/r/anonabox/comments/2ja22g/hi_im_augus...
> By the way, here is the original project, Hackaday Prize (not yet finished) semi-finalist, and based on the Adafruit onionPi : http://hackaday.com/2014/09/06/secure-your-internets-with-we...
> There are many obvious similarities and anonabox are even using almost the same sentences I'm using for my HaD project, same arguments.
> The anonabox campaign started one day before the contest judging, and his website has been registered on 18 of september, (after I released the project details). This is a very aggressive move and everyone should be carefull about this campaign.
https://lists.torproject.org/pipermail/tor-relays/2014-Octob...
I've got a pile of money and an idea... let's make a mint by stealing peoples ideas.....
"Well, we have enough capital to do anything we want. We could have a new board made in the US with a new layout if we wanted. Its ultimately up to all of you, the backers"
https://www.kickstarter.com/projects/augustgermar/anonabox-a...
It's more than time to boycott this thing.
Rocket seems to have made it their business and it seems to work for them ;)
Oh, and I can't forget the other motto in business: "ideas are worthless...execution is everything"
This results in higher costs because people are being altruistic... so let's make the cost $80 starters... $40 for Hardware (There are better mini routers out there for the price). $10 for Shipping. $10 for Software. $10 for Security Audit. $10 for TOR donation, because you're exploiting them for profit (higher pledges to TOR = TOR merch).
The more you sell, the better bulk hardware (increases in RAM/decreases in cost) order you can manage... but for 10,000~ units you'll need somebody with feet on the ground in China to deal with the local team. plus QA and taxes and lawyers and.. ARGGHHHHH
plus, should have an open and detailed platform with a threat model and design documentation before you even start.
Which OS/disto?, which packages/why these packages?, GCsecurity? firewall? administration UX? Update path? Stretch goals?! Feature set? Less is more in this kind of thing...
Btw you can achieve the same thing with open hardware: http://www.pcengines.ch/apu.htm + pfSense + tor
It was embarrassing to read, but it also leaves a bad taste in the mouth with regards to the integrity of the project.
[1] https://www.reddit.com/r/anonabox/comments/2ja22g/hi_im_augu...
From another perspective, the network on the Pi's connected via USB so it's not particularly great but it ought to be just fine for Tor. (Never actually tried an Onion Pi setup myself, but I have a few lying around, so I might do.)
All they did was smear away the logo in photochop, though their OEM might have provided this image. Anybody can make their own Anonbox with a Cubieboard or similar Allwinner A1x/A20 box for under $60. Or use thegrugqs PORTAL on a chipped TP-Link router you can find plenty on amazon/ebay for $40 https://github.com/grugq/portal/blob/master/README.md
[1] https://www.reddit.com/r/anonabox/comments/2ja22g/hi_im_augu...
It also doesn't help that it appears that their default setup is hideously insecure.
I just pulled my funding. This is way to sketchy. If the Tor project can put something together I'd be happy to put my money into that instead.
http://motherboard.vice.com/read/how-reddit-got-huge-tons-of...
Now that they have solved the chicken-and-the-egg problem, they're legit.
Point being, lot's of startups over-promise (and exaggerate) in the beginning. It takes time fix bugs and find things. If you waited for a perfect product and were 110% honest you would likely not get any traction.
That's not to say that this guy shouldn't be penalized for lying about where he sourced his products though!
The only thing worse than no security is the illusion of security. This product, as sold, provided just that -- a minimal but ultimately illusory security.
Exaggeration is normal. Nobody expects an entrepreneur to be objective and unbiased.
It's Kickstarter. They don't even need to pretend to be finished.
But if they are only providing software glue, why pretend at custom hardware?
It makes them look like less of a middleman, which is a confidence trick, and leaves a bad taste in people's mouths, much more than exaggeration does.
So reddit employees having multiple accounts? Closer to exaggeration, and something that had a legitimate purpose to it: helping conversations happen. This has only illegitimate purpose.