Tor is no longer secure; the U.S. government paid Carnegie Mellon (CMU) to research ways of de-anonymizing users by inserting specially designed packets into Tor user data at controlled nodes. [1]
Nearly a year-and-a-half after CMU canceled a Black Hat presentation, hints were dropped that CMU's Tor-related efforts may not have been for research purposes only. An anonymous tipster claimed the FBI had paid CMU $1 million to unmask Tor users. A quasi-confirmation popped up during the DOJ's prosecution of Brian Ferrell, who was allegedly assisting Blake Benthall in running Silk Road 2.0. Ferrell and Benthall were both swept up in the wake of a Tor-related FBI raid known as "Operation Onymous," which began a few months after the hastily-cancelled Black Hat talk.
Included in the information handed over to Farrell's legal representative was the following:
On October 13, 2015, the government provided defense counsel a letter indicating that Mr. Farrell’s involvement with Silk Road 2.0 was identified based on information obtained by a “university-based research institute” that operated its own computers on the anonymous network used by Silk Road 2.0.
This was covered by Motherboard[1]. The Tor Project put out the following statement in response: "the Tor network is secure and has only rarely been compromised. The Software Engineering Institute ("SEI") of Carnegie Mellon University (CMU) compromised the network in early 2014 by operating relays and tampering with user traffic. That vulnerability, like all other vulnerabilities, was patched as soon as we learned about it. The Tor network remains the best way for users to protect their privacy and security when communicating online."
I think that Tor, like Bitcoin, will always be vulnerable if a particularly powerful entity is able to obtain a majority of nodes. (Or, in the case of Bitcoin, a majority of hashing power).
And the more troubling aspect is that the courts have accepted the government's arguments that no warrant is required to disclose IP addresses:
> ... Tor users clearly lack a reasonable expectation of privacy in their IP addresses while using the Tor network. In other words, they are taking a significant gamble on any real expectation of privacy under those circumstances.
If both of these statements are true (that the government could easily run a majority of Tor relays, and that the government does not need a subpoena), then any particular vulnerability being patched is irrelevant to the inherent insecurity of the network.
Though note that Tor is also vulnerable to someone who doesn't control a majority of nodes, but can monitor the traffic of a majority of nodes from upstream. This is probably easier to achieve for a global adversary than actual control of the nodes' computation.
This doesn't make it bad software; it's the best we have, and being able to monitor traffic across the entire Internet is a huge ask of an attacker.
Also, remember that the NSA has had that kind of capabilities for a while, yet what came out of the Snowden leaks was “Tor stinks” (read: “We don't know how to break it in any practical sense”).
yup. Though apparently they could deanonymize some folks, but couldn't target the users they wanted.
But I'd expect that to change, a low-latency network like tor that also doesn't create cover traffic just architecturally isn't equipped to deal with something approaching a global passive adversary. Though networks for even that can be built..
The takeaway was indeed that they could deanonymise individual users, but they couldn't target it and it required significant amounts of human effort (i.e. it did not scale).
AFAIK, Tor developers are willing to implement cover traffic; the main reason it hasn't happened so far is that there is no known way to do this that clearly helps against that kind of threat. Until we have this (either from academic research, the Tor Project's own efforts or something else), it would be at best a placebo.
of course; but that's not tor's threat model anyhow. Nevermind the scenario of being mostly taken over; it also obviously falls to traffic analysis by a global passive observer.
In other words, its not gonna protect you from the NSA, ever, nor was it meant to. It might have a fightning chance against the FBI though. Actually it was surprising how in Snowden's files, the NSA was having trouble reliably deanonymizing targeted tor users.
Secure against what or who? Nothing is completely secure.
Your browser isn't secure, and most Tor users are using browsers over it to visit websites. All an attacker has ever needed to do is compromise your browser.
This is why you should use Tor only with a series of VMs, one with internet and tor access to act as a router and the other which can only access the router vm. This lowers the attack surface to just that of Tor's proxy interface and your VM isolation. A physical implementation of this could be done for increased security.
TAILS is not designed to be run in a VM. You can do it but it's not recommended. Whonix on the other hand is designed with VMs in mind. Qubes running Whonix isn't a half bad solution, though a live CD of TAILS is probably best becuause your system will have relatively few traits that can be uniquely profiled to you. https://panopticlick.eff.org
I would not trust Tor (by itself) to hide from the Government but I would trust it if I wanted to hide my IP address from a particular website, for example.
If all you're concerned with is keeping basic information out of the hands of comparatively low-resource adversaries (such as hiding your IP address from single website and its authors/owners) there are low-cost and comparatively simple solutions. For examples, a decent VPN or visit to Starbucks costs <$10. (And there are also free proxies, within limits.)
I thought the whole point of Tor was that it would work against highly capable or motivated adversaries?
I'm just saying that if I was trying to hide data from the government, I would be much more paranoid (in some cases it might be a good idea to use a device not owned by you on somebody's else network, for example)... but in cases where you are facing a low-resource adversary, I would not bother with a non-free VPN when you can have Tor for free which have the potential to be better then a VPN.
Surely, if you're paranoid about hiding data from the government, it should be easy enough to handle by using a secondhand diskless laptop with a USB live distro with no RW filesystem, and then wardriving for people running WEP or WPS on their wifis? Especially WPS is still common and can be cracked quite quickly. With one of those big-patch-antenna USB wifi cards that go for $40 on ebay, you can use an AP from several hundred yards easily.
Why not just point that big patch at a busy coffee shop? There are lots of open wifi spots out there.
Honestly, if you are doing things so naughty (which I don't advocate) that you are worried about state adversaries using lots of resources to track you down, you probably need a level of OpSec that you are not likely to achieve without being supported by another state level espionage agency. But at the very least you should be disguising yourself (in such a way that you still blend in), you should not be accessing an AP within a few hundred miles of where you actually live, you should probably not be driving your personal vehicle anywhere near the AP you log into (instead, using public transport paid with cash and then sitting on a park bench near the AP), you should probably be using a computer you purchased second hand from a thrift store with cash at least 6 months ago, you should probably wear gloves, you should probably dispose of the computer in a public dumpster in a different town than you accessed the AP. Hell, you probably shouldn't even download TAILS from an IP you control, I have no doubt every Tor Bundle and TAILS and WHONIX download is logged for cross referencing. Even with all of that, I honestly doubt that in the current climate a normal, highly careful person could remain anonymous if they were targeted by a major western intelligence agency like the NSA or the GCHQ.
I think you're right about the extreme level of opsec required, but with that level of opsec I think it would be feasible to avoid being targeted by the intelligence agency in the first place. Which is the key to survival.
Obviously this means you are doing something illegal but undetected, like spying for the Russians or Chinese in the West, spying for the West in Russia or China, etc.
OTOH, if you are doing something like exposing human rights violations in China/Russia/Iran/etc. where, by its very nature, the results of your (in that place) illegal activity are published, you are far more likely to be targeted.
> diskless laptop with a USB live distro with no RW filesystem
Which distro? One known problem is that browsers still transmit their location. If the network and the laptop are hundreds of yards distant, that's an instant red flag. Once that problem is corrected, there may be unknown problems to deal with.
TAILS. And unless you are using GPS, which would be a silly thing to do on a device you were using to achieve maximum anonymity, your laptop has no idea precisely where you are.
Nearly a year-and-a-half after CMU canceled a Black Hat presentation, hints were dropped that CMU's Tor-related efforts may not have been for research purposes only. An anonymous tipster claimed the FBI had paid CMU $1 million to unmask Tor users. A quasi-confirmation popped up during the DOJ's prosecution of Brian Ferrell, who was allegedly assisting Blake Benthall in running Silk Road 2.0. Ferrell and Benthall were both swept up in the wake of a Tor-related FBI raid known as "Operation Onymous," which began a few months after the hastily-cancelled Black Hat talk.
Included in the information handed over to Farrell's legal representative was the following:
On October 13, 2015, the government provided defense counsel a letter indicating that Mr. Farrell’s involvement with Silk Road 2.0 was identified based on information obtained by a “university-based research institute” that operated its own computers on the anonymous network used by Silk Road 2.0.
[1] https://www.techdirt.com/articles/20160225/07295633707/silk-...