Feds found Silk Road 2 servers after a six-month attack on Tor?
theverge.com
theverge.com
What we know, after I and Moustache and DeepDotWeb have gone through the warrants & complaints, is that a handful (~78) IPs were deanonymized as late as July 2014 after accessing the Silk Road 2 vendor .onion. This is almost certainly due to the UC account 'Cirrus' in some form, who was perfectly placed to de-anonymize the SR2 servers and insert a payload into the landing page. A former SR2 employee says they were even using crummy commercial software like 'DeskPro' on the SR2 servers.
In other words, right now the evidence is consistent with a Freedom Hosting redux scenario: the FBI has gotten another Tor Browser or other browser exploit and then phoned home. It could also be the big mysterious attack, but why would they do that when they had an insider who was involved in hiring additional employees? And also given that the SR2 vendor onion should have been seeing a lot of traffic from vendors who almost all preferred to use it due to better uptime, a mere 78 IPs sounds low.
Further reading:
- https://www.reddit.com/r/DarkNetMarkets/comments/2sppy0/sr2_...
- https://www.reddit.com/r/DarkNetMarkets/comments/2t30hs/the_...
It seems very plausible to me.
He's saying that warrants and filings show that FBI had an insider positioned to subvert SR2's servers. If you have that vantage point, a worldwide traffic confirmation attack on Tor is a oddly elaborate way to scoop up SR2 vendors. Why not just use the SR2 servers to trick the vendors?
Observe that the relay-early traffic confirmation attack would be a technical effort unprecedented for the DoJ, whereas implanting a backdoor into a web app is already par for their course.
The Reddit threads 'gwern links to talk more about the implications of the timing. At first glance, it's an awfully big coincidence to write off, but there are mitigating factors.
Thank you.
We must assume that the FBI is a rational and intelligent adversary (even if we have a difference of opinion on specific public decisions or press releases that impact our perception of their intelligence).
They're not going to expend the resources (or, as The Grugq might say, burn a valuable capability) to compromise a server when they already had a man on the inside (Cirrus).
I would be willing to accept that it's possible they were on a dragnet fishing expedition around the same time to see what they could sweep up, and they just happened to use this information to confirm the efficacy of their Tor attack. This would also explain Doxbin going down, but so would Doxbin and another target of theirs being on the same bare metal server.
> At first glance, it's an awfully big coincidence to write off, but there are mitigating factors.
Agreed. Given what is already public knowledge, it's far from the most likely explanation.
I mean a machine set up so that even if attacker gets root, they can still only send Tor traffic.
You shouldn't trust it completely since there are always escapes from virtual environments but there's no reason not to.
Can this be ruled out or unlikely?
Currently there are only two pieces that points towards the Sybil attack being used against Tor:
1. Some Tor Hidden Services were uncovered
2. The dates just happen to match dates a research project were running
But there is a lot more pointing away from it: the main points are:
1. The FBI already had a source in SR 2.0
2. It is easier to uncover hidden services using endpoint hacks rather than global deanon
3. Given the ability to deanon parts of the Tor network, the feds would have targeted the larger markets and got a lot more arrests. It isn't a coincidence they just happen to take down the sites with the worst software stacks, security architectures and operational techniques.
My technical summary is that we now think it is the feds who initiated this 6-month long attack [1] which consisted in them using "a combination of two classes of attacks: a traffic confirmation attack and a Sybil attack." They ran many (115 to be exact) non-exit Tor relays on 50.7.0.0/16 and 204.45.0.0/16 (Sybil attack) to increase their chances of controlling both ends of a Tor circuit: the first relay (entry guard) reached by the SR2 server and the last relay used as a hidden service directory where the service is published. The feds' relays then actively modified traffic to inject a signal into the Tor protocol headers (bits encoded as a sequence of "relay" and "relay early" commands) to help them correlate traffic from one end of the circuit with the other end (traffic confirmation attack). So whenever the SR2 hidden service was being published (which happens whenever the server reconnects to the Tor cloud?) the last relay knew it was for the SR2 service (but didn't know the server IP), and could correlate it with the entry guard which knew the IP address (but didn't know the service name). Once they knew the SR2 server IP, the game was over.
[1] https://blog.torproject.org/blog/tor-security-advisory-relay...
Here is the presentation Adrian Crenshaw gave at DefCon 22 called "Dropping Docs on Darknets: How People Got Caught"
Great presentation: https://www.youtube.com/watch?v=eQ2OZKitRwc
1. Do we have the right to private, secure, anonymous communications?
2. If yes, do we have the right to be outraged when our government attempts to subvert our private communications, most especially with broadly-scoped warrants or tactics that can expose your communications to any potential listeners?
I don't want the government actively working to weaken house lock standards for a lot of the same reasons I don't want them working to subvert privacy technology.
Admittedly, in this case the metaphor is kind of flawed since SR2 is the equivalent of a drug dealer's home, which the Feds would have no qualms about breaking in to.
The point being, yes, you do need a lock or some mechanism to say "outsiders should stop here." You need this for two reasons: first so that honest people know where they are not welcome, and second so that dishonest people can be shown clearly to have broken a social contract.
However outrage doesn't do anything. It's not useful. What's useful is a better service for obtaining #1.
"Is it reasonable to be outraged..."
In case I'm not the only one who hadn't read about how the first Silk Road got caught, it's simple but interesting:
http://krebsonsecurity.com/2014/09/dread-pirate-sunk-by-leak...
https://www.nikcub.com/posts/analyzing-fbi-explanation-silk-...
Krebs also posted an update (which he should probably link to from his 'leaky captcha' post):
http://krebsonsecurity.com/2014/10/silk-road-lawyers-poke-ho...
[1] http://cryptome.org/2013/08/tor-users-routed.pdf
[2] https://mice.cs.columbia.edu/getTechreport.php?techreportID=...
Like nuking a city because you're pretty sure you'll get a few bad guys.
By your reasoning we should expect that they can kick in every door in a city looking for a suspect, then blame the doors for being too weak.
If the collateral damage you're referring to is loss of trust in Tor, that's not damage: that's new information.
This is network-wide. They did not and could not target just Silk Road 2 and its users, they sabotaged the anonymity of every user and service on Tor.
A title 3 wiretap requires trust in both the government and network operator, which users of Tor may be avoiding for entirely legitimate reasons.
I agree that there is no moral distinction between a title 3 wiretap and Tor infiltration, however a title 3 wiretap is a passive listener while this Tor infiltration is not. The nature of the Tor infiltration caused anonymity to be stripped and readable by anyone aware of the flaw. They used resources unavailable to others to expose that information not only for themselves but to everyone.
The equivalent would be streaming a title 3 wiretap sans filter to everyone on the internet.
I'm not sure I follow the point about how the FBI could have done grave damage to everyone's privacy. It's (hypothetically, assuming this is how the FBI did it) the relay-early traffic confirmation vulnerability that did that. The FBI didn't create that vulnerability.
In what I think you mean by a perturbation attack, the attacker would deanonymize traffic by influence timing of packets on one end and observing the other end. Only the attacker learns anything. But in this attack, the hidden service directories found a clever way of broadcasting the name of the requested service, in plaintext, to the rest of the circuit. The attackers could read the message, but so could anyone else running a Tor relay.
Given that the message could have been trivially encrypted, that does seem like pointless collateral damage.
The FBI putting it to the test provides us with valuable information both about the FBI and about Tor.
Knowing that "global passive" might include the FBI is still valuable.
Global = can view all network traffic. Partial = can view some portion of network traffic, but not all.
Active = willing/able to modify data as it transits the network. Passive = unable/unwilling to modify data as it transits the network.
The gold standard here would be breaking a specific user's anonymity without modifying the data, i.e. a passive attack by a partial adversary. The smaller the percentage of overall traffic that the system needs to observe, the better.
Could Lizard Squad have executed this attack? (I assume anybody with a botnet could start new Tor relays, so yes.) Is Lizard Squad a global adversary?
The "global" adjective is just used, I think, because cryptographers presume a production deployment of the cryptosystems they discuss would be something like the Web: large enough (millions of nodes) to require globe-spanning resources (millions of other nodes owned by a single group) to execute the attack successfully.
Seen under that lens, neither Tor nor Bitcoin nor any other modern cryptosystem needs a "global" passive adversary to break it. Just a regular "passive adversary."
Imagine if China (used for population reasons) managed to send 300 million spies to the US to socially-engineer their way into all US citizens' personal lives. Now imagine India (again, for population reasons) simultaneously trying the same thing: now, one half of the time, the Chinese are just spying on "American citizens" who are really Indian spies, the Indians are just spying on Chinese spies, and one half of Americans go unmonitored.
It's sort of the same game-theoretic advantage you get from participating in a battle royale competition over participating in a 1v1 competition: for each new adversary you face, that adversary is also dragged down by all the other adversaries and becomes that much easier to deal with.
This really only applies specifically to Sybil attacks, though.
Warrants and wiretaps are narrow and selective, but this Tor intrusion potentially damaged the anonymity of everyone on the network.
If that's what happened, it wasn't a wiretap. It was a tip.
This is an especially silly bit of innuendo given that Tor is itself DoD funded.
It's well known that the DoD has funded Tor from the start. But it's at least decent of them to independently fund CMU to compromise it ;)
Well, it taught us that the FBI is capable of carrying out a successful attack against Tor.
Maybe you knew that already - I didn't.
1. The NSA passes along tips to FBI.
2. The NSA regularly passes along tips.
3. The FBI relies on NSA tips to do its job.
* http://www.wired.com/2014/12/80-percent-dark-web-visits-rela...
I just watched it [1] yesterday, and Gareth Owen himself says that this number is the count of a certain kind of hidden service request that should not be confused with "visits" or "visitors", for a number of reasons. The main ones I remember are:
- The specific kind of request measured is the first step towards connecting to the service, but may not always represent a complete connection that can be mapped to a individual
- Various anti-childporn organizations crawl the dark web constantly searching and indexing child pornography hidden services
[1] http://media.ccc.de/browse/congress/2014/31c3_-_6112_-_en_-_...
That other 20% of Tor usage may very well be political dissidents, whistleblowers, or average Joes that just don't want half the world watching everything they do and say online.
[1] http://www.kaspersky.com/about/news/spam/2013/Spam_in_Q2_201...
Or me, browsing my local government website to check when the next recycling pickup day is. Because I feel some kind of duty to do my bit to make the entirely innocent portion of the haystack bigger...
All users of such roads should be searchable at any given moment.
If it is true that 80% of hidden service visits are for child porn, then that would be more akin to saying 'X% of cars on the highways of america are drunk drivers or drug dealers'