Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy technology
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 5th, 2012, 01:17 PM
FuZzY_BuBbLeS FuZzY_BuBbLeS is offline
Infrequent Poster
 
Join Date: Apr 2012
Posts: 4
Question Setting up a Tor hidden service--is this secure?

I want to set up a Tor hidden service (for legitimate, but possibly illegal reasons). I have an old PC that I got from a company Win XP Pro installed. I will be using Ubuntu for the OS and thttpd as the web server software. I have a few questions:

1) Would it be reasonable to install Ubuntu alongside Windows so that I can set up FDE with Truecrypt in Windows? Or should I man up and sort out encrypted LVM etc.?

2) How can I make my server more secure? I mean, Ubuntu is a relatively safe OS, but I feel like if I'm going to be running a hidden service on it then I will need to harden it a bit more.

3) Are there any thttpd-specific configuration changes I should make?
  #2  
Old May 5th, 2012, 02:39 PM
PaulyDefran PaulyDefran is offline
Frequent Poster
 
Join Date: Dec 2011
Posts: 734
Default Re: Setting up a Tor hidden service--is this secure?

No idea about #2 or #3, but for #1, if you don't care that someone could tell that there is encryption, then LUKS it should be. If you want to hide the fact, then a TC Hidden OS option may serve you better. You'll be sacrificing hard drive space for the decoy, and some would question using Windows as the host when anonymity is the goal. Since this Hidden Service is probably going to be up 24/7, realize that the encryption keys will be in memory and one of the first things grabbed during triage on an incident response.

PD
  #3  
Old May 5th, 2012, 06:21 PM
mirimir mirimir is offline
Very Frequent Poster
 
Join Date: Oct 2011
Posts: 1,567
Default Re: Setting up a Tor hidden service--is this secure?

As PaulyDefran said, you'll be hosed if they get the server while it's up. Running from home is OK when you're learning and testing. But, if you have hidden services up 24/7, and they handle sensitive information, you want to be using hosted servers. Specifically, you want bulletproof hosting, and you want to pay for it anonymously. And you SSH to it only through Tor.

For security, you have your servers running in VMs, with Tor on the host machine. That way, even if the server is compromised, is has no Internet access except through Tor. Check the tor-talk archives, and the seedier sections of THW, and you'll find instructions and FAQs.
 

Wilders Security Forums > Privacy Related Topics > privacy technology « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:27 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums