[tor-talk] FBI cracked Tor security
Jon Tullett
jon.tullett at gmail.com
Thu Jul 14 07:38:01 UTC 2016
On 14 July 2016 at 08:37, Mirimir <mirimir at riseup.net> wrote:
> On 07/14/2016 12:23 AM, Jon Tullett wrote:
>> Having pwned the server, a malware component is then injected to
>> visiting computers. Ie: when the criminal visits the infected
>> site, his PC is infected (over that encrypted, secure, etc)
>> connection. Now infected, his PC will be under the control of the
>> FBI, and the investigation will proceed from there. As soon as it's
>> connected to the regular internet, that connection will be traced,
>> but that connection is not necessary - data on the PC can be
>> exfiltrated by the feds over Tor and used to identify the user.
>
> Tor Project ought to inform users about this risk, and recommend
> countermeasures. It's not like this is new. I see nothing at
> <https://www.torproject.org/download/download.html.en#warning>.
I agree - a warning of the dangers of visiting infected onion sites
could be useful (even though the problem is not specifically a Tor
one). There's the risk of feature creep - security is a big space and
it isn't really Tor's job to educate people on every risk online.
Perhaps a clarification that just as TBB is not all you need to
maintain privacy, it's also not all you need to stay secure, with a
pointer to some external tips?
For onion site operators, there's this:
https://www.torproject.org/docs/tor-hidden-service.html.en
Which does include this: 'Hidden services operators need to practice
proper operational security and system administration to maintain
security. For some security suggestions please make sure you read over
Riseup's "Tor hidden services best practices" document.'
Which in turn links here:
https://help.riseup.net/en/security/network-security/tor/onionservices-best-practices
That's more specifically about Tor config though - it could usefully
include pointers on basic webserver opsec too, though again it may be
out of scope to say much more than "bad people may attack your web
server, onion or not. Educate yourself on keeping it secure".
-J
More information about the tor-talk
mailing list