Sinisterly
Tor Vulnerability - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Computers (https://sinister.li/Forum-Computers)
+--- Forum: Networking (https://sinister.li/Forum-Networking)
+---- Forum: Anonymity (https://sinister.li/Forum-Anonymity)
+---- Thread: Tor Vulnerability (/Thread-Tor-Vulnerability)



Tor Vulnerability - lady_godiva - 08-09-2013

First of all this is not a tutorial. As it was requested i post this link which explains a congestion attack to identify the first node (user who wants to stay anonymous) in a tor circuit. I Apologize i cannot write about it in details but i am very busy, so i provide the link below :

Code:
http://freehaven.net/anonbib/papers/congestion-longpaths.pdf
  • Please notice that this is a research paper so it's not an easy reading however it fully explains the problem.
  • For those who wander what's the solution : Tor project has implemented bridges which hides most relays making this congestion attack not feasible. Another possible solution is to customize the path length (if i'm not mistaken 8 hops is the maximum). Tor default is 3 so when you estabilish a circuit by default it will be 3 hops long.
  • Making longer paths, 4 + hops, will make congestion attack infeasible as tor switches circuits every 10 minutes and experimental results showed that it is not feasible to identify the hops in 10 mins.

  • Notice however that increasing the circuit length will very probably cause a slow down in network speed for obvious reasons.



Tor Vulnerability - lady_godiva - 08-09-2013

First of all this is not a tutorial. As it was requested i post this link which explains a congestion attack to identify the first node (user who wants to stay anonymous) in a tor circuit. I Apologize i cannot write about it in details but i am very busy, so i provide the link below :

Code:
http://freehaven.net/anonbib/papers/congestion-longpaths.pdf
  • Please notice that this is a research paper so it's not an easy reading however it fully explains the problem.
  • For those who wander what's the solution : Tor project has implemented bridges which hides most relays making this congestion attack not feasible. Another possible solution is to customize the path length (if i'm not mistaken 8 hops is the maximum). Tor default is 3 so when you estabilish a circuit by default it will be 3 hops long.
  • Making longer paths, 4 + hops, will make congestion attack infeasible as tor switches circuits every 10 minutes and experimental results showed that it is not feasible to identify the hops in 10 mins.

  • Notice however that increasing the circuit length will very probably cause a slow down in network speed for obvious reasons.



RE: Tor Vulnerability - chmod - 08-09-2013

Was waiting for this I don't have time to read the information in the link right now but will be bookmarking it for later


RE: Tor Vulnerability - chmod - 08-09-2013

Was waiting for this I don't have time to read the information in the link right now but will be bookmarking it for later


RE: Tor Vulnerability - lady_godiva - 08-09-2013

It is a good idea to take enough time to read it, despite that, even if i could not write it myself explaining it in an easier way, just write here if there's something not clear


RE: Tor Vulnerability - lady_godiva - 08-09-2013

It is a good idea to take enough time to read it, despite that, even if i could not write it myself explaining it in an easier way, just write here if there's something not clear


RE: Tor Vulnerability - Anunnaki - 09-04-2013

How do you make Tor go through 4 networks instead of the normal 3?


RE: Tor Vulnerability - lady_godiva - 09-12-2013

My knowledge about it might be a little outdated but i think this can be done in 2 ways :

1) edit the torrc file, which is tor configuration file, to suit your needs

2) Give a look at

Code:
https://thesprawl.org/projects/tor-autocircuit/