Tor was supposed to be an anonymous means of browsing the Internet, but a study by computer science professorSambuddho Chakravarty reveals that 81 percent of those using Tor can be de-anonymized by exploiting a technology in Cisco routers called Netflow. The ploy reveals a user's originating IP address, which is analogous to identifying someone's home address even if he or she uses a P.O. box.
By facilitating anonymity online, Tor enables people around the world to communicate securely and get around firewalls that might block certain sites in their countries. It's also the technology that facilitated the notorious Silk Road (and subsequent iterations), seeing people trade bitcoins for assorted black market paraphernalia through the mail. The nonprofit project enables freedom of the press around the world and, for at least a time, presented a means to mail-order drugs.
The Tor browser works by way of decentralization. Your Web traffic doesn't come directly to you, but instead arrives by way of a number of relays. Each relay makes it increasingly difficult to identify the traffic's ultimate destination, shielding you from being associated with it. The trade-off is one of speed for purported anonymity, but this Netflow exploit is only the latest among a few incidents that seem to be punching holes in the browser's popular conception as a bulletproof security fiend.
"That general understanding is wrong," Kevin Johnson, CEO of independent security consulting firm SecureIdeas,said. "Tor runs on top of a complex series of interconnections between apps and the underlying network. To expect that everything in that system is going to understand and respect it, it becomes very complex."
Consider Web traffic as though it were automobile traffic flowing down a highway. To assume that all Web traffic will follow Tor's anonymizing "rules" is akin to assuming that every car on the highway follows all the traffic regulations, but "as we know by looking at any news report, a number of people have accidents every day," Johnson said. "The exact same thing happens with Tor. Its a highway system with an application that says 'go this way,' and we expect all of our apps to follow those signs."
Johnson says that Cisco's Netflow, which sits at the heart of the exploit that can de-anonymize these Tor users, is comparable to the Department of Transportation's analytics on a given stretch of road. Instead of identifying the types of traffic -- 15 percent motorcycles, 25 percent sedans, 40 percent semi trucks, and so on --Netflow can break down Internet traffic into its various types, say 50 percent email, 35 percent Web traffic, and the remainder being Tor. Chakravarty'stechnique for exploiting Netflow works by injecting a repeating traffic pattern, such as the common HTML files that most Tor users are likely to be accessing, into the connection and then checking the routers flow records to check for a match. If it finds a match, then the user is no longer anonymous.
"When youre looking at those kind of attacks, they're done by government state agencies, usually foreign governments suppressing protesters or tracking dissidents. It's harder to do in America because there's so much other traffic," said Jayson Street, who bears the job title of Infosec Ranger atsecurity assessment firm Pwnie Express.
The takeaway is clear: Tor used by itself is hardly some one-stop shop to ensure anonymity online. "End users dont know how to properly configure it -- they think its a silver bullet," Street said. "They think once they use this tool, they dont have to take other precautions. It's another reminder to users that nothing is 100 percent secure. If you're trying to stay protected online, you have to layer your defenses."
More here:
A Computer Science Professor Found A Way To Identify Most 'Anonymous' Tor Users
- Tor - Official Site - April 26th, 2014 [April 26th, 2014]
- Tor Browser (M-S0FT) - Video - April 26th, 2014 [April 26th, 2014]
- Downloading torrents in utorrent using tor browser - Video - April 27th, 2014 [April 27th, 2014]
- Tor Browser installieren [Tutorial deutsch] - Video - May 1st, 2014 [May 1st, 2014]
- TOR BROWSER KURULUM+KULLANIM - Video - May 1st, 2014 [May 1st, 2014]
- tor browser descargar e instalar - Video - May 1st, 2014 [May 1st, 2014]
- Entering the Deep Web-Deep Web Url link (2014) - Video - May 6th, 2014 [May 6th, 2014]
- Red Onion Tor Browser for iPhone - Video - May 10th, 2014 [May 10th, 2014]
- working referral link to agora hidden market place -new url ( onion site ) - Video - May 12th, 2014 [May 12th, 2014]
- Tor Browser Free Download/Install|Free Latest Version|64/32 bit Windows|2014 - Video - May 18th, 2014 [May 18th, 2014]
- how to install TOR Browser On LINUX - Video - May 18th, 2014 [May 18th, 2014]
- Grams Darknet black market search engine demo - Video - May 18th, 2014 [May 18th, 2014]
- How to Install the New Tor Browser in Kali Linux - Video - May 18th, 2014 [May 18th, 2014]
- How to download and use Tor browser [4K] - Video - May 20th, 2014 [May 20th, 2014]
- Free App Lets the Next Snowden Send Big Files Securely and Anonymously - May 22nd, 2014 [May 22nd, 2014]
- How to get free 7 day trials for XBL works as of May 2014 - Video - May 23rd, 2014 [May 23rd, 2014]
- Free Access to Deep Web (HIdden Wikki)(Tor Browser)-free 2014 - Video - May 27th, 2014 [May 27th, 2014]
- Federal Cybersecurity Director Found Guilty on Child Porn Charges - August 31st, 2014 [August 31st, 2014]
- Cybersecurity official uses Tor but still gets caught with child porn - August 31st, 2014 [August 31st, 2014]
- Softonic - Tor Browser - Download - August 31st, 2014 [August 31st, 2014]
- What is the Tor Browser? - Tor Project: Anonymity Online - August 31st, 2014 [August 31st, 2014]
- Tor Browser - Problem Connecting? - August 31st, 2014 [August 31st, 2014]
- Review: Tor Browser Bundle lets you browse in anonymity ... - August 31st, 2014 [August 31st, 2014]
- Guide to using the Tor Browser Bundle for secure communication - Video - August 31st, 2014 [August 31st, 2014]
- Hack-Bypass Hotspot (Mikrotik) With Tor Browser - Video - September 3rd, 2014 [September 3rd, 2014]
- Using tor-browser on ubuntu 14.04 LTS - Video - September 7th, 2014 [September 7th, 2014]
- Download Tor Browser Bundle 3 6 5 For Win, Mac, Linux - Video - September 8th, 2014 [September 8th, 2014]
- Browse Anonymously, Browse Safely - The App Center - September 11th, 2014 [September 11th, 2014]
- Tor browser NOT SAFE without this quick step - Video - September 12th, 2014 [September 12th, 2014]
- Tor Browser for iOS - Free download and software reviews ... - September 14th, 2014 [September 14th, 2014]
- Comcast Denies It Will Cut Off Customers Who Use Tor, The Web Browser For Criminals (CMCSA) - September 15th, 2014 [September 15th, 2014]
- Comcast calls rumor that it disconnects Tor users wildly inaccurate - September 15th, 2014 [September 15th, 2014]
- Why a thinly sourced, unverified report about Comcast has the Web in an uproar - September 16th, 2014 [September 16th, 2014]
- Drier: Is Comcast really blocking anonymous Internet browser Tor? - September 19th, 2014 [September 19th, 2014]
- Guns, drugs and freedom: the great dark net debate - September 19th, 2014 [September 19th, 2014]
- Download and Install Tor Browser Bundle - Video - September 24th, 2014 [September 24th, 2014]
- install tor browser for kali linux 1.0.9 - Video - September 27th, 2014 [September 27th, 2014]
- TOR Browser: Safe to use 2014? - Yahoo Answers - September 28th, 2014 [September 28th, 2014]
- Alex Jones Interviews Creator of TOR Browser- Infowars September 2014 - Video - September 28th, 2014 [September 28th, 2014]
- Tor Executive Director Hints At Firefox Integration - September 30th, 2014 [September 30th, 2014]
- Dreaming of a Tor Button for Firefox - September 30th, 2014 [September 30th, 2014]
- Install tor browser on kali linux - Video - September 30th, 2014 [September 30th, 2014]
- How to install TOR browser bundle on sparkylinux 32bit - Video - September 30th, 2014 [September 30th, 2014]
- Firefox could be adding built-in Tor support for improved private browsing - October 2nd, 2014 [October 2nd, 2014]
- Tor Browser Bundle: Download & Start - Tutorial deutsch - Video - October 3rd, 2014 [October 3rd, 2014]
- With This Tiny Box, You Can Anonymize Everything You Do Online - October 13th, 2014 [October 13th, 2014]
- Tor Browser Cheat TankPit - Video - October 13th, 2014 [October 13th, 2014]
- Anonabox Promises Total Online Anonymity That's Easy, Open Source, and Cheap - October 14th, 2014 [October 14th, 2014]
- This tiny box anonymises all your online actions - October 14th, 2014 [October 14th, 2014]
- Anonabox promises a portable, streamlined way to use Tor to hide your online tracks - October 14th, 2014 [October 14th, 2014]
- Investors flock to tiny device that promises online anonymity - October 16th, 2014 [October 16th, 2014]
- How to run all your Internet's programs thru Tor Browser - Video - October 16th, 2014 [October 16th, 2014]
- Tails 1.2 : Released with Tor Browser 4.0 - Video - October 20th, 2014 [October 20th, 2014]
- Tor Browser 4.0 is released | The Tor Blog - October 25th, 2014 [October 25th, 2014]
- Access Blocked site using Tor Browser and chrome [2014] - Video - October 27th, 2014 [October 27th, 2014]
- Be Anonymous Online : TOR Browser - Video - October 27th, 2014 [October 27th, 2014]
- Menggunakan TOR Browser - Video - October 29th, 2014 [October 29th, 2014]
- Facebook Just Created a Custom Tor Link and That's Awesome - October 31st, 2014 [October 31st, 2014]
- How to Use Deep Web Using Tor Browser - Video - October 31st, 2014 [October 31st, 2014]
- Setup Tor Browser on Mac OS 10 - Video - October 31st, 2014 [October 31st, 2014]
- Facebook opens up to Tor users with new secure .onion address - November 1st, 2014 [November 1st, 2014]
- How to use the Tor browser and the Open PGP applet - Video - November 1st, 2014 [November 1st, 2014]
- Facebookcorewwwi.onion ( Preview ) - Video - November 2nd, 2014 [November 2nd, 2014]
- How to use Tor for Facebook (Windows, Mac & Linux) - November 4th, 2014 [November 4th, 2014]
- Tor Browser Bundle - Secure your Web surfing - [Free Download] - Video - November 5th, 2014 [November 5th, 2014]
- The Law Scores a Victory Against Dark Net Denizens - November 8th, 2014 [November 8th, 2014]
- Tor Browser New 4 - Video - November 8th, 2014 [November 8th, 2014]
- How to (Install- Enable) Flash Player on Tor Browser - Video - November 9th, 2014 [November 9th, 2014]
- Tor Browser New 2 - Video - November 9th, 2014 [November 9th, 2014]
- Tor Browser New 1 - Video - November 9th, 2014 [November 9th, 2014]
- Developer edition and privacy are Firefoxs 10th birthday present for the world - November 11th, 2014 [November 11th, 2014]
- Easily Install Tor Browser 4.0.1 via PPA in Linux Mint 17 - Video - November 11th, 2014 [November 11th, 2014]
- Better Tor-gether? Mozillla bids to bring anonymous browsing to the masses - November 12th, 2014 [November 12th, 2014]
- How to connect Tor Browser to Country-specific IP Address - Video - November 12th, 2014 [November 12th, 2014]
- Tor Browser-in Yuklenmesi ve qurulmasi. - Video - November 26th, 2014 [November 26th, 2014]
- | | install tor browser on ubuntu 14 04 - Video - November 29th, 2014 [November 29th, 2014]
- Tor Browser 4.5-alpha-1 is released | The Tor Blog - November 29th, 2014 [November 29th, 2014]
- Como instalar o Tor Browser- Navegador da Deep Web/Annimo - Video - December 5th, 2014 [December 5th, 2014]
- [ExpertProf - THT]Tor Browser Kurulumu Ve Onion'a Girilmesi - Video - December 5th, 2014 [December 5th, 2014]
- Tor Browser Bundle 4 0 2 Latest Version Is Available To Download And Update - Video - December 8th, 2014 [December 8th, 2014]