Wednesday, September 12, 2007

Another Way Around Tor

Tor works well as an anonymizer but shouldn't be relied upon for encryption, according to a security researcher who collected e-mails from the Russian and Indian embassies. Both used Tor for handling their diplomatic e-mail but didn't encrypt the traffic when it entered or left Tor.

The Swedish researcher, Dan Egerstad, got into Tor by setting up his node on a peer-to-peer network used by the embassies. Egerstad was able to grab user names and passwords for around 100 embassies in August.

I've reported on Tor security issues in previous posts.

Friday, March 02, 2007

More About Tor Vulnerabilities

Back in November, I had a post about Tor being cracked. Tor is a proxy server meant to hide a user's identity and IP address on the web.

Computer World ran an article today about some American researchers who cracked Tor again. Tor's executive director, Shava Nerad, replied that they haven't any such attacks in the wild and that this was an academic exercise.

Wednesday, November 08, 2006

Tor Cracked And Global Sites About Privacy

There was an interesting paper from FortConsult about breaching Tor to find out user IP addresses. That sort of defeats the whole purpose of Tor. The paper, Practical Onion Hacking, came out on Packet Storm in October.

I added two more sites to my web site about Internet privacy, censorship and filtering. The two sites, Privacy International and OpenNet Initiative, monitor privacy, censorship and Internet filtering issues around the world. They caught my attention because of their global focus.

Links to the two sites can be accessed from my home page by clicking on Privacy in the left-hand navigation on the home page and then clicking on the link in the page that appears.

Thursday, May 27, 2010

A Guide to Google Privacy

This is an interesting guide to securely using Google from Computerworld. The so-called "smart paranoid's" guide can be basically boiled down to two general protections.

The first protection is a series of tips for cleaning up your Google history and other trails left while logged into your Google account, for example, to read your Gmail or use any of the growing range of Google applications.

I know what you're thinking. So, why not just log out of your Google account when browsing? That sounds pretty obvious. Won't that protect you from Big Brother Google? Not exactly. Even if you're searching without a saddle, Google can track your whereabouts with the usual suspects: IP address, browser settings and User-Agent settings, all sent by default over the Web.

The suggestions, in this case, are to use any of the commonly known proxies, such as Tor, or similar tools referenced in the article. Another suggestion is to use the private browsing features on Internet Explorer or Chrome, for example, and remove all cookies and caches after browsing.

Along the same lines, a sneaky phishing attack using the multiple tabs on browsers -- which the major browsers now, such as IF, Firefox and Chrome. This attack works behind the curtains while a user is browsing. The phisher changes the web site under an open tab, without changing the tab title, which redirects the user after the come back to the tab from another tab. Network World revealed a fix for what they called the "tabnapping" attack.

And, then Google just unveiled its brand new encrypted search feature.

Thursday, October 16, 2008

Autumn 2008 Edition of 2600 on Newstands

It seemed a bit early, but I happened to see the latest issue of 2600 on the newstand this week, and snapped it up, as I do every three months.

As always, there's some good stuff in here. There are articles about Tor, cyberwar, Google Analytics, Blackhat SEO, pen testing and USB forensics.

Tuesday, January 29, 2008

Anonymous May Not Be Anonymous

Russ Cooper of Microsoft Certified Professional Magazine Online had an interesting item yesterday about a paper on covert channels.

The paper by Steven Murdoch of the University of Cambridge explains how anonymizing software, like Tor, isn't always secure. In fact, the covert channels are often not encrypted and can be watched by cybervoyeurs.

The full text of the paper is 140 pages.