Like nuking a city because you're pretty sure you'll get a few bad guys.
Like nuking a city because you're pretty sure you'll get a few bad guys.
By your reasoning we should expect that they can kick in every door in a city looking for a suspect, then blame the doors for being too weak.
If the collateral damage you're referring to is loss of trust in Tor, that's not damage: that's new information.
This is network-wide. They did not and could not target just Silk Road 2 and its users, they sabotaged the anonymity of every user and service on Tor.
A title 3 wiretap requires trust in both the government and network operator, which users of Tor may be avoiding for entirely legitimate reasons.
I agree that there is no moral distinction between a title 3 wiretap and Tor infiltration, however a title 3 wiretap is a passive listener while this Tor infiltration is not. The nature of the Tor infiltration caused anonymity to be stripped and readable by anyone aware of the flaw. They used resources unavailable to others to expose that information not only for themselves but to everyone.
The equivalent would be streaming a title 3 wiretap sans filter to everyone on the internet.
I'm not sure I follow the point about how the FBI could have done grave damage to everyone's privacy. It's (hypothetically, assuming this is how the FBI did it) the relay-early traffic confirmation vulnerability that did that. The FBI didn't create that vulnerability.
In what I think you mean by a perturbation attack, the attacker would deanonymize traffic by influence timing of packets on one end and observing the other end. Only the attacker learns anything. But in this attack, the hidden service directories found a clever way of broadcasting the name of the requested service, in plaintext, to the rest of the circuit. The attackers could read the message, but so could anyone else running a Tor relay.
Given that the message could have been trivially encrypted, that does seem like pointless collateral damage.
The FBI putting it to the test provides us with valuable information both about the FBI and about Tor.
Well, it taught us that the FBI is capable of carrying out a successful attack against Tor.
Maybe you knew that already - I didn't.
1. The NSA passes along tips to FBI.
2. The NSA regularly passes along tips.
3. The FBI relies on NSA tips to do its job.
Warrants and wiretaps are narrow and selective, but this Tor intrusion potentially damaged the anonymity of everyone on the network.
If that's what happened, it wasn't a wiretap. It was a tip.
This is an especially silly bit of innuendo given that Tor is itself DoD funded.
It's well known that the DoD has funded Tor from the start. But it's at least decent of them to independently fund CMU to compromise it ;)
Knowing that "global passive" might include the FBI is still valuable.
Could Lizard Squad have executed this attack? (I assume anybody with a botnet could start new Tor relays, so yes.) Is Lizard Squad a global adversary?
The "global" adjective is just used, I think, because cryptographers presume a production deployment of the cryptosystems they discuss would be something like the Web: large enough (millions of nodes) to require globe-spanning resources (millions of other nodes owned by a single group) to execute the attack successfully.
Seen under that lens, neither Tor nor Bitcoin nor any other modern cryptosystem needs a "global" passive adversary to break it. Just a regular "passive adversary."
Imagine if China (used for population reasons) managed to send 300 million spies to the US to socially-engineer their way into all US citizens' personal lives. Now imagine India (again, for population reasons) simultaneously trying the same thing: now, one half of the time, the Chinese are just spying on "American citizens" who are really Indian spies, the Indians are just spying on Chinese spies, and one half of Americans go unmonitored.
It's sort of the same game-theoretic advantage you get from participating in a battle royale competition over participating in a 1v1 competition: for each new adversary you face, that adversary is also dragged down by all the other adversaries and becomes that much easier to deal with.
This really only applies specifically to Sybil attacks, though.
Global = can view all network traffic. Partial = can view some portion of network traffic, but not all.
Active = willing/able to modify data as it transits the network. Passive = unable/unwilling to modify data as it transits the network.
The gold standard here would be breaking a specific user's anonymity without modifying the data, i.e. a passive attack by a partial adversary. The smaller the percentage of overall traffic that the system needs to observe, the better.
* http://www.wired.com/2014/12/80-percent-dark-web-visits-rela...
That other 20% of Tor usage may very well be political dissidents, whistleblowers, or average Joes that just don't want half the world watching everything they do and say online.
[1] http://www.kaspersky.com/about/news/spam/2013/Spam_in_Q2_201...
Or me, browsing my local government website to check when the next recycling pickup day is. Because I feel some kind of duty to do my bit to make the entirely innocent portion of the haystack bigger...
I just watched it [1] yesterday, and Gareth Owen himself says that this number is the count of a certain kind of hidden service request that should not be confused with "visits" or "visitors", for a number of reasons. The main ones I remember are:
- The specific kind of request measured is the first step towards connecting to the service, but may not always represent a complete connection that can be mapped to a individual
- Various anti-childporn organizations crawl the dark web constantly searching and indexing child pornography hidden services
[1] http://media.ccc.de/browse/congress/2014/31c3_-_6112_-_en_-_...
All users of such roads should be searchable at any given moment.
If it is true that 80% of hidden service visits are for child porn, then that would be more akin to saying 'X% of cars on the highways of america are drunk drivers or drug dealers'