Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy technology
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 3rd, 2009, 01:12 AM
danielspencer2 danielspencer2 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 39
Question Ideas to encrypt TOR entry and exit nodes

We all know with TOR that the weak points are that the initial connection to a TOR entry node is not anonymous, and that TOR exit nodes are unencrypted so the exit node operator can view all the traffic.

I was brainstorming for days and i cannot think of a solution to this problem so I would like to ask if anyone here knows how TOR could encrypt exit and entry nodes?
  #2  
Old June 3rd, 2009, 03:37 AM
JokersWild JokersWild is offline
Infrequent Poster
 
Join Date: Nov 2008
Posts: 23
Default Re: Ideas to encrypt TOR entry and exit nodes

In theory at least, here's how Tor works:

Tor is designed to disassociate the content of your traffic from your IP address.

Thus: A Tor entry can know your originating IP address, but only knows it is passing an encrypted chunk of data along to another Tor node. The entry node does not know the ultimate destination of your traffic.

The Tor exit node can know the contents of your traffic, but only knows it has received an encrypted chunk of data from another Tor node.
  #3  
Old June 3rd, 2009, 04:48 AM
danielspencer2 danielspencer2 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 39
Default Re: Ideas to encrypt TOR entry and exit nodes

but there is a way for authorities to trace the original ip address to it's source if a person examined the exit node logs then went backwards until they reached the entry node right?

Quote:
Originally Posted by JokersWild
In theory at least, here's how Tor works:

Tor is designed to disassociate the content of your traffic from your IP address.

Thus: A Tor entry can know your originating IP address, but only knows it is passing an encrypted chunk of data along to another Tor node. The entry node does not know the ultimate destination of your traffic.

The Tor exit node can know the contents of your traffic, but only knows it has received an encrypted chunk of data from another Tor node.
  #4  
Old June 3rd, 2009, 09:23 AM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

Tor nodes are not "allowed" to keep logs. If they find out you keep logs or do injecting, they put you in a "badnode" list. So presumably, if every link in your circuit (3) kept logs they could find out who you are.

However, that doesn't really matter. It is easier to find out who you are than by asking nodes for logs. Aug 1, deanonymizer will be released, and will unmask virtually all tor users as an example of the results of poor implementation.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #5  
Old June 3rd, 2009, 10:36 AM
caspian's Avatar
caspian caspian is offline
Very Frequent Poster
 
Join Date: Jun 2007
Location: Oz
Posts: 1,806
Default Re: Ideas to encrypt TOR entry and exit nodes

God that will be a spooky thought for a lot of people, I would think. I even read about some international government agencies being exposed once, just as an experient.....and that was a long time ago.
__________________
A Billion for a Billion

http://www.wfp.org/1billion
  #6  
Old June 3rd, 2009, 10:41 PM
danielspencer2 danielspencer2 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 39
Default Re: Ideas to encrypt TOR entry and exit nodes

will deanonymizer unmask people using tor thats included in xb browser?

Quote:
Originally Posted by SteveTX
Tor nodes are not "allowed" to keep logs. If they find out you keep logs or do injecting, they put you in a "badnode" list. So presumably, if every link in your circuit (3) kept logs they could find out who you are.

However, that doesn't really matter. It is easier to find out who you are than by asking nodes for logs. Aug 1, deanonymizer will be released, and will unmask virtually all tor users as an example of the results of poor implementation.
  #7  
Old June 4th, 2009, 08:27 AM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

It won't defeat the new xB Browser we release by Aug 1.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #8  
Old June 4th, 2009, 10:46 AM
danielspencer2 danielspencer2 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 39
Default Re: Ideas to encrypt TOR entry and exit nodes

So if i use the current xb browser to be anonymous on june 10th, are you saying when the deanonymizer is released that it would be able to find some info about me? Or does deanonymizer work in real-time so if a person has a tor exit node and they ran deanonymizer could they see my real ip?

Quote:
Originally Posted by SteveTX
It won't defeat the new xB Browser we release by Aug 1.
  #9  
Old June 4th, 2009, 11:18 AM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

They are independent projects. I don't know if DeAnonymizer will currently work against the legacy xB Browser but our bug finders are terribly clever. Our replacement xB Browser will be very modern and defeat nearly every possible attack including those by DeAnonymizer (because of superior implementation and leakproofing).

DeAnonymizer does run in real time. So any Tor exit node or wordpress blog will be able to deanonymize you with our plugins, or you can visit deanonymizer and test yourself directly. There will be great wailing and gnashing of teeth.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #10  
Old June 4th, 2009, 03:04 PM
snowdrift snowdrift is offline
Frequent Poster
 
Join Date: Sep 2007
Posts: 394
Wink Re: Ideas to encrypt TOR entry and exit nodes

Quote:
Originally Posted by SteveTX
There will be great wailing and gnashing of teeth.

Be careful, Steve. Your deep South fundamentalist Baptist roots are showing! ;-)
  #11  
Old June 4th, 2009, 03:29 PM
caspian's Avatar
caspian caspian is offline
Very Frequent Poster
 
Join Date: Jun 2007
Location: Oz
Posts: 1,806
Default Re: Ideas to encrypt TOR entry and exit nodes

Could I have a side order of locusts to go with that?
__________________
A Billion for a Billion

http://www.wfp.org/1billion
  #12  
Old June 4th, 2009, 04:34 PM
arran's Avatar
arran arran is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 1,091
Default Re: Ideas to encrypt TOR entry and exit nodes

Do you have to use xB Browser for xerobank ? or can you use firefox for xerobank services?

what are the benefits of using xB Browser Versus Firefox with, Cache disabled, No script, Global cookies blocked, adds ons disabled, history disabled, Java disabled and referrer disabled ?
__________________
Win7 64bit Ultimate
Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt |
FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar
  #13  
Old June 4th, 2009, 05:21 PM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

No, you don't have to use xB Browser for XeroBank. XeroBank is a full VPN, meaning all your existing programs, browser, applications, games, etc are fully anonymized and encrypted through the XeroBank network. However, you can continue to use the xB Browser in addition to XeroBank's anonymous service to help you avoid phishing and evil websites, but it isn't required for anonymity if you already have xB VPN running.

xB Browser is significantly more complicated than any setup you can do with firefox. In addition to all those simple plugins, It is preconfigured to block all mime types, to disable hidden and rogue plugins, has external profile management, search and destroy flash cookies, profile protection to prevent users from compromising their own anonymity, awareness of firewalls and networking, threat model management for both VPN and Tor access, built-in tor and VPN process management, and lots more.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #14  
Old June 4th, 2009, 06:44 PM
arran's Avatar
arran arran is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 1,091
Default Re: Ideas to encrypt TOR entry and exit nodes

how do you get the trial to work? what pin number do I enter here?

Why isn't there a separate down load for the browser?
Attached Images
 
__________________
Win7 64bit Ultimate
Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt |
FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar
  #15  
Old June 4th, 2009, 07:02 PM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

Just enter in your access account number you were emailed. It won't ask you for a PIN if you entered it in correctly. Why would there be a separate download for the browser? It's all contained in the single installer.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #16  
Old June 4th, 2009, 08:07 PM
kareldjag's Avatar
kareldjag kareldjag is offline
Frequent Poster
 
Join Date: Nov 2004
Location: Feet in France, Mind in the World
Posts: 517
Default Re: Ideas to encrypt TOR entry and exit nodes

hi,

In fact there is a way to harden Tor, and i am really wondering why StevTX has not talked about it before...maybe that he was not aware of it, that makes me doubt of his level of expertise, or maybe he has censored himself for interest conflicts reasons...bad points in both cases...
With OnionCat it is possible to build VPN connections on Tor hidden services.
OnionCat has been presented at the begining of the year at the Chaos Computer Club Congress:
http://events.ccc.de/congress/2008/F...s/2828.en.html
http://www.cypherpunk.at/onioncat/

OnionCat hardens Tor agaisnt a few issues (http://events.ccc.de/congress/2008/F...s/2977.en.html ) like DNS leaks ( https://wiki.torproject.org/noreply/...AQ#SOCKSAndDNS ) for instance.
As i i use a cable ISP with a fixe IP i sometimes use Tor, and i guess that services like Xerobank will be more and more used in France after the HADOPI law:
http://www.edri.org/edri-gram/number...-strikes-voted
Except for those who want a fast surf, and then downloads, paid anonimity services like Xerobank are not necessary: i trust more Tor than Xerobank, and who knows? what proves that this last one is not a trojan of the NSA?

Of course, as for anyone who takes seriously into consideration its privacy, OnionCat is for those who begin FIRST by forgetting Windows...
And of course, an hardened Tor configuration only protects internet activities, and since crime has any relation and echo in real world, there is therefore many ways to catch those who have illegal things to hide...

rgds
__________________
Independent vision of Security (Security? Yeah But Well: http://www.ouaismaisbon.ch/ )
Fight child crime: http://www.circamp.eu/ http://www.virtualglobaltaskforce.com/
  #17  
Old June 4th, 2009, 08:15 PM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

You should read what the user asked before you start making ad hominem attacks. This isn't a question of hardening tor, or tor hidden services. If we were talking about hardening tor, i would suggest JanusVM or TorVM, which were both developed by two folks, one of whom is on the XeroBank team, and which was developed a 1+ years later than XeroBank's xB Machine VM which runs on both Tor and XeroBank, which is 2+ years before OnionCat. You've been enlightened, enjoy.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #18  
Old June 4th, 2009, 08:26 PM
kareldjag's Avatar
kareldjag kareldjag is offline
Frequent Poster
 
Join Date: Nov 2004
Location: Feet in France, Mind in the World
Posts: 517
Default Re: Ideas to encrypt TOR entry and exit nodes

Funny... a Xerobank self advertising reply to a Xerobank anti marketing post...i could not expect more from SteveTX.
Sorry but i am quite boring with SteveTX spam advertising campaigns on this board, especially for a stinking business.
i just wanted to tell it by ABC.
__________________
Independent vision of Security (Security? Yeah But Well: http://www.ouaismaisbon.ch/ )
Fight child crime: http://www.circamp.eu/ http://www.virtualglobaltaskforce.com/
  #19  
Old June 4th, 2009, 08:54 PM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

If I could keep users from asking these questions on wilders and send it to xb forum, I would. The fact is that someone asked, i gave them the exact answer, no more no less. You walk in, talk trash and have an off topic post about hidden services which neither addresses the original topic or the current thread. If you just wanted to be acrimonious, you didn't need a pretense about onioncat.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #20  
Old June 5th, 2009, 12:30 AM
danielspencer2 danielspencer2 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 39
Default Re: Ideas to encrypt TOR entry and exit nodes

so why hasn't tor included OnionCat inside it or developed their own OnionCat?

Quote:
Originally Posted by kareldjag
hi,

In fact there is a way to harden Tor, and i am really wondering why StevTX has not talked about it before...maybe that he was not aware of it, that makes me doubt of his level of expertise, or maybe he has censored himself for interest conflicts reasons...bad points in both cases...
With OnionCat it is possible to build VPN connections on Tor hidden services.
OnionCat has been presented at the begining of the year at the Chaos Computer Club Congress:
http://events.ccc.de/congress/2008/F...s/2828.en.html
http://www.cypherpunk.at/onioncat/

OnionCat hardens Tor agaisnt a few issues (http://events.ccc.de/congress/2008/F...s/2977.en.html ) like DNS leaks ( https://wiki.torproject.org/noreply/...AQ#SOCKSAndDNS ) for instance.
As i i use a cable ISP with a fixe IP i sometimes use Tor, and i guess that services like Xerobank will be more and more used in France after the HADOPI law:
http://www.edri.org/edri-gram/number...-strikes-voted
Except for those who want a fast surf, and then downloads, paid anonimity services like Xerobank are not necessary: i trust more Tor than Xerobank, and who knows? what proves that this last one is not a trojan of the NSA?

Of course, as for anyone who takes seriously into consideration its privacy, OnionCat is for those who begin FIRST by forgetting Windows...
And of course, an hardened Tor configuration only protects internet activities, and since crime has any relation and echo in real world, there is therefore many ways to catch those who have illegal things to hide...

rgds
  #21  
Old June 5th, 2009, 12:34 AM
danielspencer2 danielspencer2 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 39
Default Re: Ideas to encrypt TOR entry and exit nodes

So just to confirm, here is a scenario:

1)Person using current version of xb browser makes an anonymous comment in a wordpress blog today. Currently blog owner will not be able to trace the original ip address the comment came from.

2)When deanonymizer is released later this year, the blog owner can use deanonymizer to trace the original ip address of the comment that was made a few months ago?

Is this scenario true or false?

Quote:
Originally Posted by SteveTX
They are independent projects. I don't know if DeAnonymizer will currently work against the legacy xB Browser but our bug finders are terribly clever. Our replacement xB Browser will be very modern and defeat nearly every possible attack including those by DeAnonymizer (because of superior implementation and leakproofing).

DeAnonymizer does run in real time. So any Tor exit node or wordpress blog will be able to deanonymize you with our plugins, or you can visit deanonymizer and test yourself directly. There will be great wailing and gnashing of teeth.
  #22  
Old June 5th, 2009, 09:15 AM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

DeAnonymizer will only work if the blog owner used it to scan the commentor while the commentor was on his website.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #23  
Old June 5th, 2009, 04:46 PM
arran's Avatar
arran arran is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 1,091
Default Re: Ideas to encrypt TOR entry and exit nodes

Quote:
Originally Posted by SteveTX
DeAnonymizer will only work if the blog owner used it to scan the commentor while the commentor was on his website.

If that's the case then it would be very difficult to use DeAnonymizer. Because
after the Blog page has been downloaded to your browser isn't the Connection broken? The only time there is a physical connection is when your browser is loading a page which is only for what 1 or 2 seconds?
__________________
Win7 64bit Ultimate
Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt |
FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar
  #24  
Old June 5th, 2009, 04:52 PM
SteveTX's Avatar
SteveTX SteveTX is offline
Very Frequent Poster
 
Join Date: Mar 2007
Location: TX
Posts: 1,641
Default Re: Ideas to encrypt TOR entry and exit nodes

Yes and no. The blog plugin has a mode where it can be set to start scanning using a hidden iframe that will stay open across the site regardless of navigation, or can start scanning while the user is writing a comment (to keep out spammers).

It will quickly do an IP scan for network detection (instant) and can ban based on proxy detection, then it loads up about 25 proxy-breaking tests which take a half second to 3 seconds or so to complete each but can be run concurrently.

The point is not to be some evil tool but to demonstrate to everyone that they aren't as anonymous as they are being led to believe. This will change the game and put nearly all "anonymity" (privacy) services and networks to shame.
__________________
The Deep Packet Inspection in Act I will be used for domestic surveillance in Act II. | Ye shall know the truth, and the truth shall make you mad. ~Aldous Huxley
Never duplicated, frequently impersonated (on Usenet) | PGP Fingerprint: 4A83 2DB4 E8E5 46D9 59A1 3A3D D88F D7B7 BB67 8C30
  #25  
Old June 5th, 2009, 05:32 PM
arran's Avatar
arran arran is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 1,091
Default Re: Ideas to encrypt TOR entry and exit nodes

Quote:
Originally Posted by SteveTX
Yes and no. The blog plugin has a mode where it can be set to start scanning using a hidden iframe that will stay open across the site regardless of navigation, or can start scanning while the user is writing a comment (to keep out spammers).


FF no script blocks IFrame. would this prevent it?
__________________
Win7 64bit Ultimate
Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt |
FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar
 

Wilders Security Forums > Privacy Related Topics > privacy technology « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:00 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums