Possible upcoming attempts to disable the Tor network
blog.torproject.org
blog.torproject.org
You can see the list of trusted directory authorities in Tor's src/or/config.c:
https://gitweb.torproject.org/tor.git/tree/src/or/config.c#n...
There are nine of them (actually ten, but one is just for bridges), so you'd have to disrupt at least five of them to prevent them forming a majority vote on consensus together. Looks like the countries that own the IP address allocations for each dirauth are:
Austria, Germany, Germany, Holland, Holland, Sweden, US, US, US
If the above is all correct, a US<->Germany collaboration - to pick the largest set from two countries - would be one way to cause a large problem.
$ curl -s https://gitweb.torproject.org/tor.git/plain/src/or/config.c | grep -Eo "([0-9]{1,3}\.){3}[0-9]{1,3}:" config.c | sed 's/://'
128.31.0.39
86.59.21.38
194.109.206.212
82.94.251.203
131.188.40.189
193.23.244.244
208.83.223.34
171.25.193.9
154.35.32.5
199.254.238.52
I get the same country list as you: $ cat ips | xargs -I% curl -s http://ipinfo.io/%/country | paste - ips | sort
AT 86.59.21.38
DE 131.188.40.189
DE 193.23.244.244
NL 194.109.206.212
NL 82.94.251.203
SE 171.25.193.9
US 128.31.0.39
US 154.35.32.5
US 199.254.238.52
US 208.83.223.34
And here are the organizations they're associated with: $ cat ips | xargs -I% curl -s http://ipinfo.io/%/org | paste ips -
128.31.0.39 AS3 Massachusetts Institute of Technology
86.59.21.38 AS8437 Tele2 Telecommunication GmbH
194.109.206.212 AS3265 XS4ALL Internet BV
82.94.251.203 AS3265 XS4ALL Internet BV
131.188.40.189 AS680 Verein zur Foerderung eines Deutschen Forschungsnetzes e.V.
193.23.244.244 AS50472 Chaos Computer Club e.V.
208.83.223.34 AS40475 Applied Operations, LLC
171.25.193.9 AS198093 Foreningen for digitala fri- och rattigheter
154.35.32.5 AS14987 Rethem Hosting LLC
199.254.238.52 AS16652 Riseup NetworksFor what it's worth, XS4ALL has a tremendous reputation when it comes to privacy in The Netherlands, being one of the first ISPs in NL, founded by true hackers. They were the first (and only one?) that started disclosing how many subpoenas they were receiving from the government, have fought a lot against blocking TPB in court, etc -- I'm not surprised at all they are the ones hosting the Tor servers (I am a customer, and am allowed to run an Exit node, and they are very supportive when they receive abuse complaints, their entire customer support staff knows about Tor). I would be surprised if they would easily cave to a government order / seizure of their servers.
I do however have my doubts about KPN...
On the other hand, XS4ALL is always looking for the boundaries of privacy and free speech -- if there is no more (legal) room left, and as such have reached the boundary, I have no doubt they would comply. But they probably make a big stunt out of it again, using it as a marketing opportunity, which KPN, of course, will have no problems with. As long as they comply with the law.
Stop.
Counterintuitively sometimes the best protection is to operate under another agency. That makes moving against Tor a battle of internal politics rather than a legal battle.
'The government' rarely has uniform views on something as complex as Tor.
I Don't want to believe, if I can trust a Tor Network passing through that gate in MIT
$ traceroute 128.31.0.39
...
15 mitnet.trantor.csail.mit.edu (18.4.7.65) 40.218 ms 40.661 ms 40.900 ms
16 asperta.helicon.csail.mit.edu (128.30.0.246) 45.345 ms 47.082 ms *
17 belegost.csail.mit.edu (128.31.0.39) 44.074 ms !X 45.023 ms !X 45.549 ms !XOf the countries where the servers are located, the U.S. has the most extreme copyright laws, which means, sadly, FedGov is the leading candidate to be behind any possible seizure.
It would be interesting if an enterprising journalist were to ask MIT, SF-based Applied Operations, and RiseUp if they've been contacted by law enforcement on this matter. Those organizations host some of the U.S.-based servers. RiseUp has a warrant canary but it hasn't been updated recently: https://help.riseup.net/en/canary
Of course we don't know what actually is going on and it all may be (I hope!) a false alarm.
PS: If multiple governments cooperate and a majority of servers are taken down, what happens to Tor after the consensus interval expires? I don't know; maybe someone more familiar with Tor does. The consensus interval was changed to 72 hours a few years ago: https://trac.torproject.org/projects/tor/ticket/7986
PPS: Remember that FedGov's "copyright infringing" domain name seizures have on occasion taken down non-infringing sites in error, as I wrote about here: http://www.cnet.com/news/dhs-abruptly-abandons-copyright-sei...
"If four out of the 9 dir auths were compromised and taken offline, then the remaining 5 will continuing publishing the consensus and the network will continue operating normally. If more than 5 are taken offline then this was a horrendously large operation and the necessary corrective actions will be taken to ensure the network remains operational." https://blog.torproject.org/blog/possible-upcoming-attempts-...
> PS: If multiple governments cooperate and a majority of servers are taken down, what happens to Tor after the consensus interval expires?
As I understand it, the network would die (all clients would refuse to use the consensus, and thus not connect) 24 hours after the last good consensus.
> PPS: Remember that FedGov's "copyright infringing" domain name seizures have on occasion taken down non-infringing sites in error, as I wrote about here: http://www.cnet.com/news/dhs-abruptly-abandons-copyright-sei....
I'm not sure how this is relevant -- the directory authorities are not being accessed via domain name, just IP address.
I would expect that each authority server's configuration data is securely and reliably backed up, so if the physical servers are seized, then a replacement can be fairly easily provisioned. Maybe some operators will even have one waiting on standby, in case of a normal hardware failure or similar.
Presumably the IP address space isn't being seized or otherwise disbanded, so it could be dropped in exactly as specified in the hard-coded configuration - that is, the same IP address and port.
Any ongoing and persistent impersonation of the server wouldn't be viable, as the long-term directory authority identity keys are kept offline.
Maybe I'm missing something here but it sounds like more of a symbolic violation, rather than a potentially catastrophic disabling event that brings down Tor.
IP addresses are assigned to a network provider, not a customer. If I'm hosted by a US provider and the FBI seizes my server, is that provider going to say "sure, just spin up a new box on the old IP", or are they going to tell me to get off their network? What if the FBI has an opinion on which decision the provider should take? What if the FBI has an opinion on which action the directory operator should take?
Actually, they can be assigned to either. See: http://en.wikipedia.org/wiki/Provider-independent_address_sp...
Can they really say to MIT, for example, that port 9131 on IP address 128.31.0.39 is now out of bounds? Or coerce all of Riseup's peers (including any future ones) to cease connecting to their entire 199.254.238.0/24 range, or even just firewall off 199.254.238.52 upstream?
As far as I know, there's no precedent for this where the provider - and, crucially, the owner of the IP address block - is hosting the server itself.
My first guess would be that a nation has made some demands of the project that the project won't comply with, and that country has suggested they will seize the directory authority servers located inside it if the demands aren't met soon. [Edit: a new comment by arma on the original story, "To be sure to keep our source safe, we're not providing more details quite yet", makes this seem less likely.]
Or perhaps an insider has leaked some plans to the project.
Along another line of thought, if the US government wanted to further complicate online privacy, I imagine they'd choose a time like now, when headlines about the "cyber intrusions" of 2014 are at a peak. I wonder what other actors could have large enough power over their directory authority servers for the project to post this message.
Edit: Indeed, from a post below by paralelogram [0] and by checking https://atlas.torproject.org , it appears 4 of 9 are in the US. There are also two in Germany, one in the Netherlands (as well as another there that is only for bridge relays), one in Austria, and one in Sweden.
edit: this question was asked in the blog comments, here is arma's response
> There are a bunch of research papers looking at exactly this question. Check out http://freehaven.net/anonbib/#usenix11-pirtor for one direction, and then http://freehaven.net/anonbib/#wpes09-dht-attack http://freehaven.net/anonbib/#ccs09-shadowwalker http://freehaven.net/anonbib/#ccs09-torsk http://freehaven.net/anonbib/#ccs10-lookup for another direction to consider. The current situation is that nobody knows of a better design that is actually better in practice. The one we have is well-studied and has well-understood downsides, so I'm not eager to move to one that is poorly-studied and has poorly-understood downsides.
The TOR clients come hard coded with a list of directory authorities. Without the ability to query the directory authorities they cannot find a usable TOR route. I don't know if there is some caching involved, but if not then this would effectively stop the network for anyone trying connect to TOR.
Actually, to put it another way, Freenet is itself the optimal bootstrapping mechanism for Tor. Maybe the two projects should merge, such that Tor would effectively be an optimization over the specific case of two peers generating and searching for one-another's signed Freenet documents (this effectively being an IP tunnel already).
To be sure to keep our source safe, we're not providing more details quite yet.
But actually, we don't know many more details than the ones we posted. And as for your 'why', that's an excellent question, and one we've been wrestling with too. There are nine directory authorities, spread around the US and Europe. If they're trying to hunt down particular Tor users, most possible attacks on directory authorities would be unproductive, since those relays don't know anything about what particular Tor users are doing.
Our previous plan had been to sit tight and hope nothing happens. Then we realized that was a silly plan when we could do this one [post the warning] instead.
If there are some seizures of directory authorities or other project infrastructure, this won't be some totally unpredictable occurrence. It was only about a month and a half ago that some relays were seized as part of a general takedown against Tor hidden services. The Tor project posted this blog in response:
https://blog.torproject.org/blog/thoughts-and-concerns-about...
That blog post convinced me to shut down my relay. The reason is, to an ambitious prosecutor this blog post looks like:
"We view law enforcement operations as attacks and are looking for ways to defeat them, because we are determined to shield the identities of our criminal clients"
... which is exactly what resulted in the operators of the Silk Roads getting arrested even though they were not personally selling drugs.
The blog post makes casual reference to the "enormous social value" of hidden services and claim they're worried about "secret police repressing dissidents", but doesn't cite any actual examples. Actually I've never heard of a hidden service that has enormous social value - whilst there are a small number of .onion addresses that aren't completely illegal or unethical, for all the examples I know of the operators are not anonymous.
To police forces around the world who keep having investigations hit a dead end because of Tor, going after the project directly will not seem very different than going after services like Liberty Reserve. The people running it are stating publicly that they will do their best to frustrate investigations, and that is dangerously close to admitting participation in a criminal conspiracy. Thin ice doesn't even begin to describe their current situation.
You make it sound like you've actually looked. Perhaps you've spoken to some Ukrainians, or protesters in Turkey or Honk Kong, and they've assured you they have little use for "hidden services"?
Additionally, Tor gets way less traffic from people trying to evade national firewalls than VPN services do. They aren't the big fish in that space at all.
Besides, I'm not sure what your point is. Societies don't tend to judge a thing by whether there's a single good use, somewhere. They weigh things up.
Hidden services can be enumerated, so it's not impossible to find one if there's some awesome hidden service somewhere. But such a site would get a lot of attention very quickly. It wouldn't be secret very long.
Hopefully this whole story will amount to nothing. It'd be very sad if Tor disappeared. But let's face it - when you have the Prime Minister of a technically advanced western country tasking one of the worlds most advanced intelligence agencies with "break the dark web" they were going to hit serious problems sooner or later anyway. And mostly that's because of hidden services. It'd be a crying shame if this one feature with hardly any legitimate usage caused the entire project to tank.
Societies don't 'weigh' anything up. Governments with idealogical leanings make decisions regardless of evidence. You only have to look at the 'war on drugs' to see how, regardless of the evidence put before them, politicians will blindly follow their ideologies. 'Weighing up' implies a reasoned judgement, based on the arguments for and against and based on the available evidence. To think that the UK or US (or any other) government works that way is naive.
I think for most people, China is the first country that comes to mind when you think about internet censorship. But my experience is that it is impossible to connect to Tor there. Maybe they are acknowledging that tacitly.
Or maybe they were trying to make the blog post more palatable to US government readers, since Iran, Syria, and Russia are currently bad guys, while things with China are supposed to be fine.
instead of casting aspersions on a free software project, i would encourage you to please help make tor more useful for these users, or to build your own alternative.
[0] https://metrics.torproject.org/userstats-relay-country.html?...
[1] https://metrics.torproject.org/userstats-bridge-country.html...
For what it's worth, I have unsuccessfully tried using Tor (and Tor bridges) a few times in Shenzhen and I'm a lot more tech savvy than your average political dissident. Tor's blog even has a post about how it is being blocked in China if you don't believe me: https://blog.torproject.org/blog/closer-look-great-firewall-...
> instead of casting aspersions on a free software project, i would encourage you to please help make tor more useful for these users, or to build your own alternative
I doubt I could build a better alternative and I was not criticising the Tor project as a whole.
Interestingly it's partially the same issue - the directory servers have static IP's. ISP's are simply blocking traffic to these directory server IPs. Without access to the directory servers, can you still use Tor?
Also see above article for thoughts on how to circumvent this mode of censorship.
1. https://www.torproject.org/docs/bridges.html.en
2. https://www.torproject.org/docs/bridges.html.en#PluggableTra...
There isn't really any way around that which scales, which is why Tor is basically a non-entity in China right now. Everyone I know from the west who spends time in China just uses commercial VPN services, not Tor.
I'll give you one:
Russia currently has laws that, among other things, require the author of a blog to register personal information with the government if the blog has more than 3,000 daily readers[1]. The law is specifically intended to prevent anonymity.
When working as intended, hidden services enable those blog authors to protect their identity and ensure the government doesn't harass, arrest or kill them.
The big advantage is - anyone can read your blog. Not just people who are willing to download and use the Tor browser.
Most famous cases of dissent in recent times have preferred to play jurisdictional arbitrage rather than use Tor. Snowden is being kept safe by Russia, his information was published by a British newspaper that then shifted reporting to New York to avoid the UK government goons. Apparently for now that's good enough.
This is why I talked about specific examples of hidden services being used in this way and actually getting real traction - I can't think of any.
Also if you're hosting on a site like Wordpress or Blogger all the government sees is an SSL connection to wordpress.com or google.com. They don't get to see if you're reading or composing. So in practice it's probably good enough.
I also understand that this list of trusted DA's is hardcoded into Tor clients. Since this is the case, I'd be curious how the network could be restored if there is a coordinated action on these servers.
forgive my ignorance, why would they do this in the first place? fear of MITM?
It wouldn't be very secure of Tor could be over-riden by an ISP inserting a bad DNS record in their servers.
You can read more about how this works at this URL: https://gitweb.torproject.org/torspec.git/tree/dir-spec.txt
Previously, it also joined an IRC channel and got the list of hostnames from all of the other users in the channel.
Example: The Patriot Act written many years before 9/11 by law enforcement agencies to help them in the War on Drugs, and then shamelessly used the 9/11 excuse to pass it. If the Patriot Act was "just about terrorists", then it should've referred only to terrorists. But it didn't. And now 99 percent of NSLs are used in drug cases.
http://www.cnet.com/news/how-bin-laden-and-911-attacks-shape... "Long before 9/11, the U.S. Department of Justice drafted the so-called Enhancement of Privacy and Public Safety in Cyberspace Act (PDF), which goes by the awkward and not very memorable acronym of EPPSCA. In July 2000, the Clinton administration forwarded EPPSCA to Congress, where it was introduced by Sen. Patrick Leahy (D-Vt.) and met with a generally chilly response... EPPSCA was designed to give police more authority to conduct Internet surveillance, not thwart terrorists armed with box cutters... within hours of the 9/11 attacks, the Justice Department had dusted off EPPSCA as a way to respond to bin Laden. On September 13, 2001, two days after the worst terrorist attack in U.S. history, the U.S. Senate approved the "Combating Terrorism Act of 2001," which includes portions copied directly from EPPSCA."
As for the rest of the above comment, this is likely to be a fluid situation and I'm reserving judgment until we know more. It is possible that the good folks at Tor are wrong (I'd like them to be!) and no seizure happens. Government authorities sometimes bluff.
http://www.justice.gov/usao/vae/victimwitness/mega_files/Meg...
There wasn't any info on the blog about what regular users can do to help with this, if anything.
What jurisdictions are these Directory Authorities located in?
194.109.206.212: Netherlands, XS4ALL Internet BV
154.35.32.5: United States, Cogent Communications
131.188.40.189: Germany, Friedrich Alexander Universitaet Erlangen Nuernberg
199.254.238.52: United States, Riseup Networks
171.25.193.9: Sweden, Foreningen for digitala fri- och rattigheter
128.31.0.34: United States, Massachusetts Institute of Technology
82.94.251.203: Netherlands, NAH6 BV
86.59.21.38: Austria, SILVER:SERVER GmbH
208.83.223.34: United States, Applied Operations, LLC
http://en.wikipedia.org/wiki/Global_surveillance_disclosures...
Lots of people around the world depend on the anonymity of Tor today and having the Government take it out, whilst indirectly kick-starting the next generation anonymity network is all and well for me and my armchair, but it's going to be life threatening for many.
Until this 100x better solution exists Tor must be kept running at any cost, many lives depend on it.
roger's dirauth (author of the post) moria1 (US) restarted ~1d ago and shows a blip in traffic earlier today, which may or may not have something to do with the post: https://atlas.torproject.org/#details/9695DFC35FFEB861329B9F...
peter's tor26 (austria) restarted 12h ago: https://atlas.torproject.org/#details/847B1F850344D7876491A5...
dizum (netherlands) was also recently restarted 16h ago: https://atlas.torproject.org/#details/7EA6EAD6FD83083C538F44...
Tonga (netherlands) looks mostly normal, restarted ~7d ago: https://atlas.torproject.org/#details/4A0CCD2DDC7995083D73F5...
sebastian's gabelmoo (germany) restarted 2d ago: https://atlas.torproject.org/#details/F2044413DAC2E02E3D6BCF...
CCC's dannenberg (germany) restarted 3d ago: https://atlas.torproject.org/#details/7BE683E65D48141321C5ED...
jake's urras (US) is showing relatively low bandwidth & restarted ~2d ago: https://atlas.torproject.org/#details/0AD3FA884D18F89EEA2D89...
Faravahar (US) restarted 4d ago: https://atlas.torproject.org/#details/CF6D0AAFB385BE71B8E111...
riseup's longclaw (US) restarted 9d ago: https://atlas.torproject.org/#details/74A910646BCEEFBCD2E874...
linus's maatuska (sweden) has been up for 30d: https://atlas.torproject.org/#details/BD6A829255CB08E66FBE7D...
recent activity in tor's commit log may also offer up some clues: https://gitweb.torproject.org/tor.git/log/?showmsg=1
but at the moment, moriatoo is running 0.2.6.0-alpha-dev and moria1 is running 0.2.6.1-alpha-dev
What are these not-so-rare reports of mass unmasking of people then? I'm genuinely curious, not begging the question.
Allowing js and plug-ins to run puts you in the "low hanging fruit" category.
That threat model explicitly does not provide protection against a global observer.
That means tor is NOT safe against a state level attacker with an extensive surveillance network.
But the latter one has nothing to do with users, but with "website" operators inside the Tor network.
If funded, a user governed foundation will be set up to help prevent influence by misaligned interests, such as those seen with existing providers and closed source software vendors. Infrastructure was always meant to be open, transparent and trustworthy.
Especially for those who don't know any better.
Three days ago I updated the longer video version from that page and put it on the Kickstarter page, down below the other video. In addition to removing other content, I edited out the amounts you are referring to because they change constantly and are less important to my pitch now I'm doing a Kickstarter campaign. Also, AWS added a 10th region to their list a few months ago. I don't 'count' the government cloud as a public offering.
It remains a truth that AWS runs out of ten geographic regions. So, 80% of the world's public cloud is run out of (by your math) <~40 physical buildings. Not a cloud, IMHO.
Besides, there doesn't appear to be any public information on how many physically different locations Amazon runs for AWS, which makes it impossible to say how many physical locations (datacenters) they run. I'm not 100% convinced that a 'zone' maps to a physical building, given my memory of ping times across zones and having issues with two neighbor zones at the same time in the early days of using AWS.
Amazon having different terminology than the industry's causes confusion and my comments reflected that confusion when I used the term 'datacenter' erroneously. FWIW, Rackspace calls their dataceneters 'datacenters': http://www.rackspace.com/about/datacenters.
Any remaining minutia related to this topic will be resolved by the end of the week. I'm updating Utter.io in preperation for the Kickstarter launch.