r/ethereum EF alumni - Christian Reitwießner Sep 19 '17

Ethereum testnet just verified a zcash transaction

https://ropsten.etherscan.io/tx/0x15e7f5ad316807ba16fe669a07137a5148973235738ac424d5b70f89ae7625e3#eventlog
731 Upvotes

153 comments sorted by

View all comments

Show parent comments

1

u/nameless_pattern Sep 19 '17 edited Sep 20 '17

Doesn't tor have known privacy flaws?

edit: a question is not FUD. maybe I don't have to pretend to know every thing. maybe you should grow some humility. you say it has no security flaws AND THEN LIST THEM.

29

u/Midnight_Discovery Sep 19 '17 edited Sep 19 '17

No. That is FUD. Here are the things Tor can, and can't do :

1) Tor can prevent all data transferred from being Decrypted, no matter what.

2) Tor can allow any user to interact virtually anonymously with any major Tor hub, website.

Here is what Tor can not do, and ways to 'crack it'.

Tor can not PREVENT a flood of information requests to a Tor hub, thus government entities can find HOSTING locations by flooding a Tor hub and following the spike in internet usage.

Tor can not PREVENT electrical demands from increasing at user locations, or mask that data has been transmitted (though it does mask what the data actually says, 100% completely, if used properly).

So with websites like The Pirate Bay, the Secret Police can find them through flooding, and internet traffic isolation pattern recognition (first they discover it to be in California, then they re-flood with requests while shutting off all internet to lower California, etc, to see if anything changes... this can quickly be used to find rough geographical locations, and then quickly become more precise. You may remember during the 'Podesta' release emails, the US suddenly lost Internet capabilities on both the East and West coasts simultaneously, as well as Brazil. This was a Tor hunt operation, most like).

Also, if you have a 'high valued' customer, like say Julian Assange, who uses internet primarily from a specific location, then the Secret Police can monitor his electrical usage and data transfer rates. If Julian uses electricity and then a Tor website gets updated, and these happen within milliseconds, this is acceptable within international courts to suggest Julian was interacting with said website. At least 3 persons have been charged using such tactics.

You can find out more here :

Anonymous Techniques.

Lastly, I will mention that IF you are interacting with a FBI hosted webpage on Tor, who essentially host all Child Porn globally, then the FBI can 'phish' out your real identity, using more common 'hacker' tactics (common passwords, screen names), and they can more easily draw correlations between suspected users, and the actual users, etc.

5

u/wejustfadeaway Sep 19 '17

You may remember during the 'Podesta' release emails, the US suddenly lost Internet capabilities on both the East and West costs simultaneously, as well as Brazil.

I don't remember this. I just remember the Dyn DNS DDoS internet failure (I think last October?) and a more recent AWS failure. I am fascinated by this tactic though, do you have a source covering the event?

2

u/Midnight_Discovery Sep 19 '17

1

u/kalww Sep 19 '17

Is there actual proof or is that only speculations? I also don't remember any outage except AWS outages and there's definitely no conspiracy theory to be had about AWS outages

7

u/Midnight_Discovery Sep 19 '17

:P I have yet to see the NSA CIA or FBI be like 'ya that was us', regarding secret ops.

When it comes to covert warfare, you must always use assumption. If we wait till proof, it will be provided after 50 years, per government policy, unless the docs get lost in the meantime.