On the Effectiveness of Traffic Analysis Against Tor Networks Using Flow Records [pdf]
mice.cs.columbia.edu
mice.cs.columbia.edu
It relies on a malicious server and entry node. The contribution of this paper is that if you have the malicious server and entry node, you can use a less expensive data source (Cisco NetFlow data) rather than raw packets to perform a correlation attack.
The correlation they achieve in a private Tor network is impressive; however, if you look at the graphs in the actual paper[0], you can see that the differences in correlations are actually quite small in the wild.
The title of this post and article is actually incorrect; the technique demonstrated has an 81.4% accuracy. This means that the base rate fallacy will make it nearly unusable in practice, and more so as the scale of Tor traffic grows. For more on the Base Rate Fallacy, see [1].
So in summary:
* This is an incremental improvement of an already existing and known attack pattern on low-latency anonymity systems
* The technique presented in this paper is only a threat if your threat model is an adversary that can control your entry guard and the server you are trying to communicate with, but does not have the budget for packet-level correlation attacks
* This technique does not achieve sufficiently high accuracy and sufficiently low false positives to reliably identify arbitrary Tor users, but might be more successful if used in combination with a prior hypothesis that, say, a specific NSA employee is communicating with GlobalLeaks.
[0] https://mice.cs.columbia.edu/getTechreport.php?techreportID=...
To put it another way, let's say someone is posting bomb threats over Tor on Google Plus. Google cooperates with the FBI and deterministically perturbs all traffic going into the Tor network. What router does the FBI get netflow data from in order to find the bomber?
You can thank DDOS trolls for that, I guess, because that's why the ISPs paid to build that out.
If tier 1 ISP differentiate traffic on port level, then switching that setting on should bypass the filter.
Hiding in port 80 will protect you not-at-all from traffic analysis, and all the major ISPs already have the infrastructure to deploy traffic analysis.
I know that it does not do this, but couldn't it ?
http://en.wikipedia.org/wiki/Freenet
Upsides: Much more secure than Tor, (since it doesn't try to be a low-latency mixing router) not funded by USG.
Downsides: Real slow. Real slow. SLOW. Think effective throughput in the tens of kilobytes/s, latency measured in minutes.
Most academic computer science is funded by the American government. Does that mean that all academic computer science is backdoored by the military?
To put it more specifically, most compilers researchers I know have at some point been on a DARPA grant, because DARPA has money and academics want money. I'm sure plenty of LLVM contributors have been paid from DARPA grants. Is LLVM backdoored?
===========================
On an entirely different point, how is Freenet even comparable to Tor? They address totally different use cases (Tor is an anonymizing TCP overlay; Freenet is a distributed censorship-resistant store), and have very different threat models.
Further, it seems very unlikely that Tor (which is a piece of very well-maintained software with some of the foremost privacy researchers working on it) would have fewer bugs than Freenet, which is a sprawling Java program maintained by one man. Further, the security of Freenet in abstract hugely depends on having a functional small-world network, which requires Freenet to have been widely adopted to start with.
The comment parent's request was vague, but you simply cannot replace Tor with Freenet because they do totally different things. It is nonsensical to compare them because they address different threat models and accomplish different goals.
I always like to remind people that Tor is funded by the USG (currently, actively). I think it's very important that people understand that and adjust their threat models based on that.
However, it's not all bad news ... in fact, I think there's a very significant upside to the USG funding of Tor:
It provides a very compelling defense in the event that simply participating in Tor begins to be prosecuted.
There is very often a worry put forth that simply participating in Tor (as a client or by running a relay, etc.) can in itself be considered an illegal act. I think that as long as the USG is funding the development, people in the US can rest easy that they can't be prosecuted in any way for simply participating on the Tor network.
"If the USG is funding it and the state department is encouraging people to use it (think arab spring) then how could my use of it be illegal ?"
IANAL.
Also, the Tor Project periodically sends out folks to remind the FBI and friends that tor has many legitimate uses, and is routinely used by law enforcement agencies as part of their day-to-day business. [1]
[0] https://lists.torproject.org/pipermail/tor-talk/2011-March/0...
[1] https://blog.torproject.org/blog/trip-report-october-fbi-con...
For example, people use both Tor and Freenet to enable anonymized private messaging. On Tor, this is achieved by connecting to a hidden-service forum and posting. On Freenet, this is achieved through an app that uses Shared Subspace Keying to basically have two people watch one-another's RSS feeds for updates. Either way, people get to send anonymous messages and have other anonymous people see them.
If you were some one who believed that your liberty or even life depended on it, then yes, you would have to assume that. Obviously day to day, it really doesn't matter. When it actually does matter, you have to assume the worst.
Here's my blog key if you want to try:
USK@1ORdIvjL2H1bZblJcP8hu2LjjKtVB-rVzp8mLty~5N4,8hL85otZBbq0geDsSKkBK4sKESL2SrNVecFZz9NxGVQ,AQACAAE/bluishcoder/3/
And the image gallery: USK@2LK9z-pdZ9kWQfw~GfF-CXKC7yWQxeKvNf9kAXOumU4,1eA8o~L~-mIo9Hk7ZK9B53UKY5Vuki6p4I4lqMQPxyw,AQACAAE/pitcairnisland/0/Instead your node is no more statistically likely to have any portion of the objects you've uploaded than any other objects throughout Freenet. When an upload is complete your node doesn't have a full copy, all the chunks are spread out amongst the nodes within a few hops of you instead.
When it's developed entirely in the open I'm not sure I see the concern here. If you have reason to believe they are somehow compromised or backdooring Tor please do share it, otherwise this is just FUD.
Big security downside is that in the purely opennet configuration, your peer nodes are both untrusted strangers AND your own traffic is visible to them. There is NO "onion" effect going on, just reliance on the possibility that any traffic a peer node observes from your node is not necessarily YOUR traffic as all nodes are also routing requests for other nodes.
Phantom also seems to have great design, but it was discontinued quite early in its implementation. No idea if it's because it was unworkable or for other reasons. Maybe someone with experience in such networks can take a look at it:
However Tor has a big advantage in practice right now: lots of users, of every kind, to hide among.
When GCHQ talked about "staining" in this context (as in the REMATION conference docs), by the way, they generally mean either a timing-based fingerprint (as here) or cookie-based fingerprint (unfortunately it seems to be used in at least two entirely different contexts, oh well).
Seems like a lot of security products demand trust from their users (even gnunet). This implicit bossing is no less pretentious than a gas pump that says "Thankyou".
You give up a certain amount of security, but gain a lot of comfort.
Perhaps a future version of tor can offer a "comfort level" setting that introduces a varying amount of delays, bogus traffic and other concealment methods (ideally at every hop).
He who sacrifices security for comfort deserves neither :)
How well does Tor do with panopticlick?
Also, Panopticlick hasn't been updated with some possible distinguishing measurements that have been identified since it was created. In that sense it was always meant as a lower bound on uniqueness, and should still be understood that way.
That said, browser fingerprinting is very hard to fight, and it's a lot easier to come up with new fingerprinting techniques than it is to mitigate them. So I expect that determined fingerprinters have the edge in this arms race.
Update: Tor Browser in Tails 1.2 with javascript disabled returns a fingerprint that's shared by 1 in 2,615 with 11.35 bits of identifying information.
>Within our dataset of several million visitors, only one in 4,955 browsers have the same fingerprint as yours.
>Currently, we estimate that your browser has a fingerprint that conveys 12.27 bits of identifying information.
I figured it would be more unique due to my running Tor Browser on a Mac - but I don't see how the math works out. Unless it actually has a count of machines with information identical to mine?
If your fingerprint is totally unique (like mine, with 22.16 bits of information) then it is shared by only 1 in 4,697,672 browsers in their dataset.
How else would it work (not assuming even distribution)? Im sure its a hash counter.
Currently, we estimate that your browser has a fingerprint that conveys at least 22.16 bits of identifying information.
Well, shit. I'm a snowflake.
There are lots of downsides to this (epistemic attacks), but if your anon use case makes sense for such a setup, it is a valuable tool to have in the toolbox.
If you just config it with PublishServerDescriptor as 0 and someone else knows the IP (middle relays) they will be able to use it.
It's essentially a function of not announcing the node to anyone.
Edit: And to be clear, priv exit nodes don't prevent the timing attack in the article.
As for paying for services such that "customer of this VPN provider" can't be linked to you, I'd look at places that specifically accept bitcoin (I'm not a fan in general, but in this case, it signals their willingness to avoid collecting normal billing data like name, address, cc#, etc.).
I have no affiliation but they popped up in the googlings. Seems to be simple enough to get their service without giving away anything personally identifiable.
EDIT: the reason I tease out those two parts is because I'm concerned people will think TOR can protect against entities that can do a global customer-of-VPN dereference. TOR doesn't protect against global super-adversaries, consult your local security practitioner before feeling safe, etc. etc.
At the moment if I start up my VPN client and wait for the connection to my very trustworthy VPN provider, and only then open to Tor Browser Bundle, is that the right way round?
Thanks for the clarification.
TorrentFreak did a really good comparison of them recently: http://torrentfreak.com/which-vpn-services-take-your-anonymi...
Second, "no logs"... well: https://www.bestvpn.com/blog/8383/earthvpn-user-arrested-cop...
Good luck with your "no logs" operation in any NATO member/friendly country. Not sure about Russia and its allies, but I expect you'd be hard pressed to achieve "no logs" in China as well. South-Africa and Israel is probably out too. Not sure what that leaves you.
Of course, the issue is that latency in this scheme is O(n) and per-node bandwidth is O(1/n), with large constants. Also, it's a reasonable suspicion in practice that no one would set up this scheme and then actually have zero communication going on over it, so it still reveals that "at least one of the n nodes is talking to at least another of the n nodes".
I may be paranoid, but it seems to be that there is some FUD around tor lately. And if many people will stop using it, it will indeed become less secure.
Deleted comment
The paper says that NetFlow is not optimized for this kind of attack, that it is merely representative of flow data available from core routers in general ("traffic monitoring functionality built into the routers of major IXs and ASs, such as Cisco’s NetFlow"), and that you have to do research to figure out how to make it work. The authors aren't saying that Cisco intended to facilitate traffic analysis attacks against users, or that using Cisco routers in a network you set up makes you or your users more vulnerable to traffic analysis attacks by other people.
I'd love to see much more research on new approaches to anonymity, but it's also important to understand the tradeoffs. In the face of active attacks like this one, it seems that a network needs to be synchronously padded (all participants and potential participants always transmit and receive at a fixed speed, regardless of whether they're communicating or not) or else high-latency (you wait a long time to forward communications far enough through the network that they genuinely could have been from anyone in a large population based on detailed traffic statistics). Even the padded versions might be vulnerable to an adversary who can actually disrupt or degrade people's connections (to prevent particular nodes from sending or receiving the amounts of traffic that they're expected to by the protocol). Even a very successful Kickstarter project isn't going to provide a path to escape these tradeoffs.
That said, papers in computing are an exception because the audience here is informed in that field. And the thread, at this point, provides a lot of context.
Given the above I think the paper is probably the better URL, and we've changed to it from http://thestack.com/chakravarty-tor-traffic-analysis-141114.
Marking this subthread as obviously off-topic.
HN should uphold a higher standard than that. Link to the source.
Deleted comment
http://www.slate.com/articles/technology/future_tense/2014/1...
It's totally fine to see problems, even with our highly progressive and forward-looking society. Dissent is the highest form of patriotism. But we are a nation of laws, and there are established procedures for changing those laws. We have the ballot box instead of the Anonabox, and for good reason.
If you are a good, loyal citizen, true to the ideas of the founding fathers and possessed of respect for the rule of law, there is no reason to be anonymous. Either you are right, and the democratic voice of the people will join you in a chorus of freedom, or you are wrong and if you continue to inflict harm on our society it will be forced to defend itself.
> Those things might have been reasonable in the past, but we live in 2014. We live in a country that has an ethnic minority president, the first nation anywhere in the world to be progressive enough to do so. We have abolished racism, sexism, homophobia, and classism. We live in an equal, classless, democratic society.
In what world do you live that we have "We have abolished racism, sexism, homophobia, and classism" because I can tell you all 4 of those are still going strong today. Please don't associate the abolishment of slavery with the abolishment of racism, it's so wrong that it's just sad that you seem to think that they are one in the same. Just because we elected "an ethnic minority president" it doesn't mean we get to whitewash history or pretend that racism is dead. As for sexism and homophobia I have witnessed both of these first hand within the last month easily and probably within the last week if I really thought about it. And lastly I would argue classism is actually on the rise, in the US at least (Probably elsewhere but I'm only going to say the US for sure right now).
> It's totally fine to see problems, even with our highly progressive and forward-looking society. Dissent is the highest form of patriotism. But we are a nation of laws, and there are established procedures for changing those laws. We have the ballot box instead of the Anonabox, and for good reason.
"established procedures for changing those laws".... Yeah how is congress doing on that front again?
> If you are a good, loyal citizen, true to the ideas of the founding fathers and possessed of respect for the rule of law, there is no reason to be anonymous. Either you are right, and the democratic voice of the people will join you in a chorus of freedom, or you are wrong and if you continue to inflict harm on our society it will be forced to defend itself.
Majority != Right. It wasn't too long ago that voicing support for homosexuality could have easily gotten you killed (there are many parts of the work were this is still the case) and law enforcement wouldn't have batted an eye. There are and always will be the need for anonymous speech/dissent because it is impossible to change unjust/unfair laws without being associated with the thing you want to change. If you remove anonymity then you also remove the ability to change the laws that you mention we have an "established procedures for changing". Democracy cannot exist without dissent and dissent cannot easily exist without some form of anonymity or dissenting will immediately bring a mob/law enforcement to your front door.
You are incredibly optimistic here. The US government has the ability to monitor the communications of darn near the entire planet. This is new territory for human beings. Just because things are good for most of us right now, doesn't mean they always will be.