Comment by throwaway37821

Comment by throwaway37821 10 months ago

49 replies

75% [0] of all Tor nodes are hosted within 14 Eyes [1] countries, so it would actually be quite trivial for the NSA to de-anonymize a Tor user.

It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries.

[0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all

[1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes

> Edit: For all the cynics and doomsayers here, consider this: Tor has been around for a long time, but there has never been an uptick in arrests that could be correlated to cracking the core anonymity service. If you look closely at the actual high profile cases where people got busted despite using tor, these people always made other mistakes that led authorities to them.

Maybe someone, somewhere, has decided that allowing petty criminals to get away with their crimes is worth maintaining the illusion that Tor is truly private.

It's also worth noting that it's significantly easier to find the mistakes someone has made that could lead to their identity if you already know their identity.

DabbyDabberson 10 months ago

Its important to realize that TOR is primarily funded and controlled by the US Navy. The US benefits from the TOR being private.

It provides a channel for operatives to exfiltrate data out of non-NATO countries very easily.

  • firen777 10 months ago

    > It provides a channel for operatives to exfiltrate data out of non-NATO countries very easily.

    I'm not convinced this is the case. For example China's gfw has been very effective at blocking TOR traffic, and any TOR connection in other countries is like announcing to the government that you are suspicious.

    • snowwrestler 10 months ago

      It’s a little silly to say “for example” and then intentionally pick what is widely known as the most sophisticated and pervasive system for controlling Internet traffic ever created.

      The parent said “non-NATO countries”… there are 162 of those that are not China.

      (It’s also a little silly to specify “non-NATO” since U.S. intelligence services have to exfiltrate data from NATO countries too…)

      To get data out of China, the U.S. undoubtedly has special systems, which are worth the special investment because it’s China.

      • rvba 10 months ago

        If weight it by population and importance then China is probably in the top though.

        I bet western spies spend more time on China than some micro island in the middle of the ocean. Same for Chinese spies probably focus on USA first.

        Also realistically probably everyone spies everyone and they spy on those micro islands too. But priorities are clear...

    • literallycancer 10 months ago

      How do they see TOR traffic in a TLS tunnel?

      • GuB-42 10 months ago

        If you can find TOR nodes, so can the Chinese government. They can then just block these addresses.

        Furthermore, the great firewall is quite advanced, they use machine learning techniques to detect patterns, so even if it is TLS on port 443, they may be able to detect it after they have gathered enough traffic. There are workarounds of course, but it is not as simple as just using a TLS tunnel.

  • godelski 10 months ago

      > the US Navy
    
    Tor was made for spies. But you know what's really bad for spies? If accessing a certain IP/protocol/behavior reliably reveal your spy status.

    For Tor to be effective for hiding spies it has to be used by the public. Even if it's only nefarious actors (say spies + drug dealers + terrorists) it adds noise that the adversary needs to sort through.

    What I fucking hate about many of these conspiracies is how silly it is once you ever work with or for any government entities. You can't get two police agencies in neighboring cities to communicate with one another. The bureaucrats are fucking slow as shit and egotistical as fuck.

    It's important to remember that the government and even a single agency (like the NSA) is just as chaotic, disconnected, and full of competing entities as any big tech company has (if not worse). Yeah, most of the NSA is focused offense, but there's groups working on defense. Those groups are 100% at odds. This is true for the 18 intelligence agencies. They have different objectives and many times they are at odds with one another and you bet each one wants to be getting credit for anything.

    The US involvement should warrant suspicion and with any technology like Tor you should always be paranoid. But it's not proof. Because guess what, the US wants people in other countries to use high levels of encryption to hide from their authoritarian governments while the US can promote democracy movements and help put a friendly leader into a position of power. AT THE SAME TIME they also want to spy on their own people (and there are plenty of people in the gov that don't want this). Inconsistency is the default because it's a bunch of different people with different objectives. So the US gov both wants Tor to be secure and broken at the same time.

    • autoexec 10 months ago

      > It's important to remember that the government and even a single agency (like the NSA) is just as chaotic, disconnected, and full of competing entities as any big tech company has (if not worse).

      And yet even as early as 2003 they were taking a copy of every single bit that ran over the AT&T backbone (https://en.wikipedia.org/wiki/Room_641A). It's amazing how effective these "chaotic, disconnected, and full of competing entities" can be. We're entirely dependent on whistleblowers willing to risk their lives and freedom to learn about what they're doing to us.

      • godelski 10 months ago

        Yes, they can be very effective. There's no denying that. The proof is in the pudding as they say, since we have governments and businesses. But that's tangential to the point I was making.

        • salawat 10 months ago

          ...You must be working for a different government than I've experienced. Government orgs will initially suffer from siloing problems, but once a synergy is uncovered it tends to get leveraged hard after a while. Remember: when it comes down to it, the difference between government reach, and everyone else, is really just who you can communicate with smoothly.

          Now things like SCI are things; but there are ways to handle that too. It's more a slowing force than a stopper.

  • try_the_bass 10 months ago

    > The US benefits from the TOR being private.

    Slight correction: The US benefits from TOR being private to _everyone but the US_

    • wheelerwj 10 months ago

      I’m glad I didn’t have to scroll too far to see your comment.

      In fact, A major power wins by creating a mote just big enough that only they can cross.

      • fuzztester 10 months ago

        everybody does such shenanigans, bro.

        you don't have to be a major power to do such stunts.

        everybody and their uncle are already doing it. look into your life to see the truth of this.

  • HDThoreaun 10 months ago

    I dont see how TOR is better than just spinning up a server on the public cloud for each asset. Since each asset would have a different IP they couldnt use one assets knowledge to catch the others. Non-NATO countries tend to monitor internet traffic and so would know if you access TOR.

    • DrillShopper 10 months ago

      Servers in the public cloud are a lot easier to do traffic analysis on.

      • HDThoreaun 10 months ago

        Each server is only used by a single operative though, how do you even find which IP to analyze? The story with Tor and espionage is that if an asset connected to cia website the gov which monitors internet access would know they went to the site. Even if its not a public site they just need to have one operative defect and tell them the site and they can catch all the other operatives who use it. But if everyone connects to a different IP I dont see how traffic analysis helps you discover you is connecting with the cia.

      • [removed] 10 months ago
        [deleted]
  • majorchord 10 months ago

    You know what else was funded by the US government? Computers, the Internet and GPS. Also Signal (via OTF funded by Congress).

keepamovin 10 months ago

The original purpose of TOR was to provide agents and handlers with a means of secure communication, allowing them to organize subversive or espionage activities. It was created by the Department of Defense to propagate their interests and spread democracy around the world using these secure capabilities. Given this context, it's not unreasonable to assume that TOR is still being used in a similar manner today.

Because of its origins, access to the identities of users on the TOR network—even if they could be de-anonymized—would likely be extremely restricted, compartmentalized, and classified. This would make it much more difficult for such information to be used in law enforcement proceedings. Perhaps that, rather than a technical limitation, is the reason most high-profile arrests related to TOR involve criminals making some other mistake, rather than the security of the network itself being compromised.

Additionally, it’s interesting to speculate that some of the secure private defense and intelligence networks—parallel or classified world internets—could themselves be implemented as possibly enhanced forms of TOR. It would make sense that nation-states, through shell companies and other disguises, might run and control many seemingly innocuous machines acting as secure relays in these parallel networks. While I have no data to back this up, it seems logical, given that TOR was originally created by the DoD and then open-sourced.

Why wouldn’t they keep something that works, build on it, and enhance it as a means to secure their own global communications?

  • Xelbair 10 months ago

    >spread democracy

    i have to say that i love that phrase, it is peak propaganda that just works.

    • keepamovin 10 months ago

      Yes, I boldly inserted that deliberately aware of its potential provocative effect. So I am truly glad you derive some enjoyment from it. I did too! Comrades in arms? Or at least in Internet nodding hahaha! :)

      • Aerbil313 10 months ago

        Indeed old timer commies of HN might get irritated by that phrase, but in this corner of the world we love Democracy. This summer would pretty dry in my region because of global warming, but thanks to Democracy we had plenty of precipitation in the form of MK-84s. I wonder which neighboring country is going to get her share next year, it's a gift that never stopped giving since some 20 years.

        https://en.wikipedia.org/wiki/War_on_terror

    • webninja 10 months ago

      >spread democracy

      We even have a presidential candidate that spouts similar propaganda that she is going to “Save Democracy”! Yeah right, save it by subverting it at every possible point. First she was appointed into the VP role, then her party skipped holding a primary election, then she was installed into the candidacy. None of those 3 easy steps to power even vaguely resembles a Democracy.

      If those 3 succinct points aren’t enough, here’s a few more succinctly in one sentence: Members of her party have tried to deplatform her opposition, cancel her opposition, remove her opposition from the ballot, expropriate over $450 million dollars from her opposition (NY Kleptocracy), jail her opposition, and even assassinate her opposition twice! In all cases to deny and deprive the ability of voters to have a choice in the upcoming election. If her opposition is so bad as her party propaganda wants you to think, won’t that show in the general election? Why does half of America vote the other way? What have they seen that you haven’t?

      intentional pause

      There could be unlimited reasons why one of our candidates is not about “Saving Democracy” or how that slogan is just propaganda. I’ll give 4 more numbered reasons why:

      1) She represents a party that is opposed to Voter ID requirements at polls, which would keep people from voting twice, pretty much like a Bitcoin double-spend attack. Her party’s establishment claims voter ID laws are a problem because they think their voting base is so stupid they couldn’t pass a drivers license test on any number of attempts; let alone figure out how to obtain another form of photo ID. Many in her voting base find that stance pretty offensive and rightfully so. Opponents will assert they couldn’t win a fair and free election if they tried to. Both sides aside, How are voter ID laws a partisan issue? They are just common sense!

      There’s a reason their party tries to “get out the vote” every year: low-information-voters are their bread and butter. How many people actually have the time to think critically about these issues? I think America would be a better place if less low-information voter chose to vote and if more voters knew that it’s okay to leave choices on the ballot blank.

      2) One of her long standing border policies has been keeping the borders open so that illegals can flood the cities and further dilute the voting power of the constituency base. This leads to more apportionment in the House of Representatives because under the current law, illegals are counted too. This perverse incentive dilutes the vote of the American people and the constituency.

      3) Flooding American with illegals is very unpopular with the vast majority of America. If that was put to a vote with the American people, it simply wouldn’t continue. Most people are in support of legal immigration not illegal and unvetted immigration because we want the good talent and beautiful women to cross the border, not whomever can find a gap in the fence. I said beautiful women for your benefit. You’re welcome :)

      4) Her third claim to fame is she won’t be going around to very many of the 3-letter agencies (if any) and saying “You’re fired!”. A bureaucracy’s favorite leader is a puppet. They get to control her rather than her getting to control them. When left unchecked, we have power-creep. When we have a bunch of bureaucrats running the government, it subverts the will of the people because we voted for the president, not the unelected bureaucrats who tell her and the current president what to say. Some people joke that the vast number of 3-letter agencies are the 4th branch of government. Some people want all of the power but are afraid of public speaking and don’t want to stand up in front of a podium to explain their case to the American People and appear online. Some simply can’t make a reasonable argument for one point or another... I can and I’m doing that now.

      Spreading Democracy is possibly becoming a euphemism for spreading Bureaucracy. Bureaucracy is like taking the DMV and scaling it all the way up to the size of government. Thankfully due to the Chevron doctrine court case, the power of the bureaucracy has been reduced and we can appreciate the effect checks and balances have to save our system of government, which most scholars agree is a Democratic Republic.

      Instead of the word Bureaucracy, her presidential opponent uses a more specific term to describe it. He popularized the term “Deep State” from fringe usage to mainstream usage. The term Deep State usually refers to a subset of the 3-letter agencies known as the intelligence community or the intelligence agencies. One of many possible citations is the Joe Rogan podcast episode #2138 with Tucker Carlson, which, although long, is jam packed full of secrets.

      Both men talking in that episode have interviewed and have had public (and presumably private) conversations with an enormous and significant quantity and variety of people. They’re also among the best in the world at “active listening” which some people just simply can’t do. That causes interviewees to open up and spill the beans, which is where real journalism & interviewing is.

      My most memorable takeaway from that episode is:

      “The second point that’s obviously true is that weak people, which is a synonym for bad people, come together for strength and safety. They act as one. The hive mind is specific to a certain group of people: bad people. And that good people don't tend to come together, but they're coming together now.” and “It’s weak men and weak women who are instruments of evil. The weaker, the more evil that leader will be.” I’ll paraphrase: “Men and women without a backbone or spine are the most dangerous because they’re the most corruptible to do what’s wrong against what’s right. Sometimes we take it for granted that strong people wouldn’t do bad things because it compromised their morals or ethics. Like bad sportsmanship.”

      I say all this at the risk of potentially not being able to leave Canada or the UK for 18 years if one of my layover flights ever stopped there, despite being a USA citizen in the USA. I also potentially risk being added to the target list of the next virus or bioweapon that leaks out of a lab like the Wuhan institute of Virology. We only found out what was happening there because the orange man wanted to cut all free money to China and someone reviewing the spending line items found we were funding the Wuhan Institute of Virology. Apparently we still are and it’s been allegedly upgraded from BSL 2 to BSL 4 lab. It’s just one of many labs. Like nukes, bioweapons produce plenty of collateral damage. Unlike nukes, they’re deniable assets. Bioweapons are freaking scary. You get to learn how easy it is to wipe essentially all human life off the face of the earth in the popular educational simulation game Plague Inc with various plagues.

      In 1969, Bioweapons labs in Fort Detrick and Plum Island boasted to the President that they had the capacity to kill every American in America for 29 cents per life. That year President Richard Nixon surprised everyone and did one of the greatest things of his career, which is he went to Fort Detrick, then he announced the closure and termination of the U.S. Bioweapons programs. He saw that bioweapons were a poor man’s nuclear bomb. Then the Patriot Act was signed which according to Robert F Kennedy Jr had a hidden charter that while not retracting Nixon’s charter to close bioweapons progress, gave immunity to any federal official that violates those laws and who develops bioweapons and researches them. As you know, vaccine research and Gain of Function research are on a similar track so you can say you’re doing vaccine research when actually doing Gain of Function studies for bioweapons like most later evidence for COVID-19 shows. That information was suppressed because they didn’t want everyone to get all up in arms with China. Unfortunately, Gain of Function research is still continuing and being funded by tax payer dollars, no less.

      I know what I’m saying is risky but the freedom of speech in my country is a right, not a privilege.

      Last, my summary and disclaimer:

      Vote for who you think is right based on the knowledge you know. I have a large appetite for knowledge but I don’t know everything. You may know something I don’t. I believe we all have a good head on our shoulders and can make good decisions with sufficient truthful information to make those decisions. If that information is sequestered, kept hidden, or censored, then democracy is subverted. Is that politician here to “Save Democracy” as some of her low-information potential voters say or are those just words of propaganda? Above I gave 4 more numbered points in support of why that’s just more propaganda but my motive is to inform, not to persuade.

  • DrillShopper 10 months ago

    After talking to my Democracy Officer I have to say I love managed democracy!

    • keepamovin 10 months ago

      Un, Thank you I guess? Seems we are… Winning?

      • salawat 10 months ago

        That's a Helldivers 2 reference, and it doesn't reflect well for your case. I for one, am glad the work of satire exists so we can once and for all have a real talk around how phrases like "Spreading Democracy" can over time completely lose the plot about what the U.S. as a country was about. It isn't about structures of government. It's about Liberty and the preservation thereof against enemies foreign (other countries) and domestic (the Government itself). Whether Democracy or Republic, a government by it's nature is a tool to curtail or preserve some Liberty for some people to the exclusion of others (currently and in the recent past drawn along nation state or polity lines). In the work of art in question, galactically, and cross-species polity, with Managed Democracy having as one of it's tenets be the mandate to, through violence, instate itself as the "One True Governmental System" everywhere it currently isn't, no questions asked; in fact asking such questions is an act of High Treason.

        The lesson here being; if you forget the point of keeping your government around (for the U S., preserving Liberties, and asserting the supremacy of those rights over the legitimacy of any act of Government trying to curtail them), and conflate the government with the end itself, you create and perpetuate an inhuman monster capable of manufacturing the conditions for manifesting atrocity on scales that would make the despots of the past blush for how unambitious they ultimately were in comparison. For there is literally no stopping something once you've managed to elide the meaning of our most sacred values across generational boundaries from meaning one thing, to something completely different. As an example, from the work of Art in question: Freedom being taken to mean "you are Free to decide how you support the regime", but not whether you should be supporting the regime at all.

        I assure you, if winning takes you in that direction, you're barking entirely up the wrong tree.

  • autoexec 10 months ago

    > Perhaps that, rather than a technical limitation, is the reason most high-profile arrests related to TOR involve criminals making some other mistake, rather than the security of the network itself being compromised.

    I have no doubt that the government doesn't want to demonstrate how weak Tor is to the public, but it's also got to be dead simple to find those kinds of "other mistakes" they can use when they've identified the person they're looking for and can monitor whatever they do.

    • keepamovin 10 months ago

      What you’re claiming is not necessarily correct, but it’s an avenue of interesting speculation. Nevertheless, let’s clarify a few of your possible misunderstandings or points of confusion:

      I’m not saying TOR is weak, nor that the reason for its concealment is to project a false sense of government strength.

      What I am saying—and what you seem to have misunderstood—is that the TOR network is most likely used, precisely because of its strength, for highly sensitive clandestine operations. This results in blanket classification of all involved identities, making them inaccessible to law enforcement. Law enforcement likely understands this, which is why they don’t pursue it—knowing it’s a dead end. Instead, they rely on side-channel effects or mistakes made by criminals.

      To my mind, this explains the public information we see.

      Now that I’ve clarified, what do you think?

      • sangnoir 10 months ago

        > What I am saying—and what you seem to have misunderstood—is that the TOR network is most likely used, precisely because of its strength, for highly sensitive clandestine operations.

        Tor seems to be a poster child of the "Nobody But Us"[1] principle the NSA likes so much: it's strong when used by American spooks, but weak when used against them. If a country developed body armor that's impervious to all rounds except their own special alloy rounds, their use and promotion of that armor is not evidence of its utter robustness.

        I don't doubt a lot of darknet busts involve a lot of parallel construction - the intelligence community doesn't have to give detailed logs; summaries are enough (IP addresses, dates and times). This is before considering that the FBI is involved in both (counter) intelligence and law environment.

        1. https://en.wikipedia.org/wiki/NOBUS

        • keepamovin 10 months ago

          I guess i don't necessarily disagree with your NOBUS assessment of TOR strength, it's hard to say without confirmed facts tho. Funny I always think of crypto algorithms as the examples of NOBUS: the NIST ones, etc. Again, no confirmed facts but that would be a source and method you really wouldn't want to confirm and burn.

          What do you mean by parallel constructions? Is that where LE discovers evidence through extralegal means, then needs to rebuild the narrative through a legally valid chain? Could be, but then again there's probably a lot of TOR identities that are completely out of reach for LE, leaving them with only legal construction. Wouldn't you say?

          I sometimes wonder about something, too: you know those "small" cases with huge human cost, like missing child, or murder in a backwoods area? I always imagine that classified capabilities could be used to solve them. The fact they are not, is painful, and I think must be "moral trauma" for LE/IC people involved. Even more so that they can't talk to anyone about it except their organizational therapists if then.

  • jrochkind1 10 months ago

    > The original purpose of TOR was to provide agents and handlers with a means of secure communication, allowing them to organize subversive or espionage activities. It was created by the Department of Defense to propagate their interests and spread democracy around the world using these secure capabilities.

    Do you think the EFF was in on it, duped, or just thought multiple competing interests could be served?

    • keepamovin 10 months ago

      Well, I could be wrong historically here, but I think you need to recall a previous age where the interests of the state department pushing noble American values into disintegrating but strategically valuable locales might actually have been something that the EFF felt highly aligned with and wanted to support through its electronic and advocacy Capacities. For instance, why would they not support Internet and communicative freedom under a repressive regime?

      I haven’t looked closely and I wasn’t there at the time so it makes it hard to say for sure but let’s speculate. I think the people involved in EFF are most likely slightly cynical, savvypolitical maneuverers themselve who, like you said realize the utility of multiple not necessarily overlapping objectives, where all involved parties could derive some benefits.

      Certainly not an implausible situation that you lay out

  • headsupernova 10 months ago

    Ah yes, 'spread democracy around the world'

    • keepamovin 10 months ago

      I appreciate your appreciation of that statement. Thank you. :)

majorchord 10 months ago

> Maybe someone, somewhere, has decided that allowing petty criminals to get away with their crimes is worth maintaining the illusion that Tor is truly private.

This is what I believe. If they do have a way to track people, it wouldn't be worth blowing their cover for small stuff that wasn't a ridiculously huge national security threat that they could afford to throw away 20+ years of work for.

In fact there have been court cases that were thrown out because the government refused to reveal how their information was obtained... I think that usually means they're hiding it on purpose for a bigger cause. I also wouldn't be surprised if multiple SSL CAs are secretly compromised for the same reason.

amy-petrik-214 10 months ago

TOR as it exists now is a honeypot simple as. Same as that documentary called "Benedict Cumberbniamnatch's Great Work" where they cracked the radio signals of the Frenchmen but they had to let the submarine sink so that they knew that the other guy doesn't know that they knew. NSA uses ROT which is TOR-inspired but takes the techniques and incognito aspects 7 or 8 steps ahead.

  • Imustaskforhelp 10 months ago

    What? Tor is a honeypot? I don't think so. What do you instead expect me to use instead of tor?

  • widforss 10 months ago

    You do know Hitler was the German Reichskanzler, not French?

    • hnbad 10 months ago

      I'm assuming the "documentary" was the movie The Imitation Game staring Benedict Cumberbatch. If that's an intentional mistake, I'd guess by "French" they meant Austrian (as Hitler was born in Austria).

[removed] 10 months ago
[deleted]
alphan0n 10 months ago

This entirely ignores the fact that traffic to and from onion sites never leaves the Tor network, never utilizes an exit node. It doesn’t matter if a bad actor has control of every exit node if your communications are within the network unless the underlying encryption protocols have been compromised.

  • dunghill 10 months ago

    But not all traffic goes to onion sites.

    • alphan0n 10 months ago

      Right, you shouldn't expect traffic that goes outside the onion network to be secure and anonymous. That's the entire point of onion sites.

ClumsyPilot 10 months ago

> petty criminals to get away with their crimes

Like human rights activists, journalists and dissidents in totalitarian countries.