The German police have successfully deanonymized at least four Tor users. It appears they watch known Tor relays and known suspects, and use timing analysis to figure out who is using what relay. T…

The German police have successfully deanonymized at least four Tor users. It appears they watch known Tor relays and known suspects, and use timing analysis to figure out who is using what relay.
Tor has written about this.
Hacker News thread.

Bad post.

A: old news

B: missing important context

C: Most likely partially fabricated by law enforcement according to many experts and the tor project. They didnt execute a full timing attack because they are not capable of doing that.

From the limited information The Tor Project has, we believe that one user of the long-retired application Ricochet was fully de-anonymized through a guard discovery attack. This was possible, at the time, because the user was using a version of the software that neither had Vanguards-lite, nor the vanguards addon, which were introduced to protect users from this type of attack. This protection exists in Ricochet-Refresh, a maintained fork of the long-retired project Ricochet, since version 3.0.12 released in June of 2022.

Thanks for this.

Yeah not sure why OP felt the need to use such a click-bait title.

Maybe OP is part of a law enforcement entity!!

I doubt it. I think OP wanted upvotes and didn’t read carefully. Something like “tor user de-anonymized via retired app” would of been more accurate.

This is another great lesson that even the best privacy tools can’t protect a user from their own bad opsec.

It just sucks as a lot of Lemmy users will just read the title and assume its true and then tell their friends tor is no longer safe.

sunzu2
link
fedilink
17d

German feds cant maintain proper posture against russia so these limp dick cucks need some good PR?

They say not given full access, so post from tor may not full picture.

In interview daniel moßbrucker say that onion v3 was affect 2 time, so not only ricochet.

Source for expert saying it fabricated?

Source for government not capable of timing attack?

Want to read up on more opinion on this.

edit: if daniel moßbrucker trustworthy. might also fabricate story.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.97K Posts
  • 74.6K Comments
  • Modlog