The online anonymity network Tor is a high-priority target for the National Security Agency. The work of attacking Tor is done by the NSA's application vulnerabilities branch, which is part of the systems intelligence directorate, or SID. The majority of NSA employees work in SID, which is tasked with collecting data from communications systems around the world.. According to a top-secret NSA presentation provided by the whistleblower Edward Snowden, one successful technique the NSA has developed involves exploiting the Tor browser bundle, a collection of programs designed to make it easy for people to install and use the software. The trick identifies Tor users on the Internet and then executes an attack against their Firefox web browser. The link for this article located at Schneier on Security is no longer available. . Discover the methods employed by the NSA to track Tor users through sophisticated exploitation strategies and maneuvers aimed at undermining privacy.. Tor Exploitation, Online Privacy, NSA Attacks, Firefox Vulnerabilities. . LinuxSecurity.com Team
The Tor Project has become a vital mechanism for privacy advocates, human rights activists, journalists and others in sensitive positions to evade online censorship and persecution. And while the governments interested in limiting user access to the Internet and controlling content have had some recent success in preventing the use of the anonymity network, Tor members have been working on new methods for circumventing those restrictions.. In a talk at the USENIX LEET workshop here Tuesday, Nick Mathewson of the Tor Project discussed the group's recent challenges in responding to suppression efforts by governments in Egypt, China and elsewhere. What the Tor members have learned in these recent incidents is that while governments are becoming more up front about their willingness to shut off Internet access altogether or censor content, users are also becoming more resourceful. However, while Tor offers users a high level of anonymity and privacy when used correctly, there are a number of ways that its protections can be circumvented both intentionally and unintentionally. The link for this article located at ThreatPost is no longer available. . In a talk at the USENIX LEET workshop here Tuesday, Nick Mathewson of the Tor Project discussed the . project, become, vital, mechanism, privacy, advocates, human, rights, activists, journali. . LinuxSecurity.com Team
On October 4th one of our readers sent in a very worrying analysis of what appeared to be "traffic modification" (in his words) on the part of the Tor network. The Tor ("The Onion Router") network is an anonymizing peer-to-peer network of routers on the Internet which uses various techniques to bounce traffic around the Internet in such a way that traffic analysis becomes difficult if not impossible to perform. Tor is a perfect example of a dual-use technology: it can be used to avoid government-imposed Internet censorship or to protect the identity of a corporate whistleblower but at the same time it is sadly ideal for various nefarious uses. . The link for this article located at Sans.org is no longer available. . The Tor network offers online anonymity but has vulnerabilities such as reliance on volunteer relays, potential traffic monitoring, and user exposure risks that necessitate caution. Anonymity Network, Traffic Analysis, Privacy Technology, Tor Network Security. . Benjamin D. Thomas
Get the latest Linux and open source security news straight to your inbox.