{"id":203558,"date":"2017-03-21T08:00:58","date_gmt":"2017-03-21T06:00:58","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=203558"},"modified":"2017-03-21T07:45:18","modified_gmt":"2017-03-21T05:45:18","slug":"tor-upgrades-to-protect-user-privacy-and-security","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/203558-tor-upgrades-to-protect-user-privacy-and-security.html","title":{"rendered":"Tor upgrades to protect user privacy and security"},"content":{"rendered":"<p>In the coming months, the Seattle-based nonprofit <a href=\"https:\/\/www.torproject.org\">The Tor Project<\/a> will be making some changes to improve how the Tor network protects users\u2019 privacy and security.<\/p>\n<p>The free network lets users browse the internet anonymously.<\/p>\n<p>For example, using Tor can reduce the risk of being identified when dissidents speak out against their governments, whistleblowers communicate with journalists and victims of domestic abuse seek help. <img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/counter.theconversation.edu.au\/content\/73641\/count.gif?distributor=republish-lightbox-basic\" alt=\"The Conversation\" width=\"1\" height=\"1\" \/><\/p>\n<p>In its most common, and best-known, function, a person using the free <a href=\"https:\/\/www.torproject.org\/download\/download-easy.html.en\">Tor Browser<\/a> \u2013 essentially a privacy-enhanced version of Firefox \u2013 uses the internet mostly normally.<\/p>\n<p>Behind the scenes, the browser and the network handle the web traffic by bouncing the communications through a chain of three randomly chosen computers from all over the world, called \u201crelays.\u201d As of March 2017, the Tor network <a href=\"https:\/\/metrics.torproject.org\/networksize.html?start=2016-12-13&amp;end=2017-03-13\">counts almost 7,000 of these relays<\/a>. The goal of leveraging these relays is to decouple a user\u2019s identity from her activity.<\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Tor.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-203560 size-large\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Tor-640x340.png\" alt=\"Tor\" width=\"640\" height=\"340\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Tor-640x340.png 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Tor-600x318.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Tor.png 754w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>But those users are still, generally speaking, using others\u2019 websites, which can be <a href=\"https:\/\/www.theatlantic.com\/technology\/archive\/2016\/02\/the-research-pirates-of-the-dark-web\/461829\/\">shut down<\/a> or <a href=\"http:\/\/www.bbc.com\/news\/technology-11928899\">pressured into censoring online activity<\/a>.<\/p>\n<p>My own work as a scholar and volunteer member of The Tor Project also looks at the network\u2019s way of allowing people to host websites privately and anonymously, which is where most of the upgrades to the system will come.<\/p>\n<p>Called \u201conion services,\u201d this element of the Tor network makes it possible for a person to run a website (or filesharing site, or chat service or even video calling system) from a dedicated server or even her own computer without exposing where in the world it is.<\/p>\n<p>That makes it much harder for authorities or opponents to take down. <a href=\"https:\/\/gitweb.torproject.org\/torspec.git\/tree\/proposals\/224-rend-spec-ng.txt\">The upcoming changes<\/a> will fix flaws in the system\u2019s original design, and employ modern-day cryptography to make the system future-proof.<\/p>\n<p>They will improve security and anonymity for existing Tor users and perhaps draw additional users who were concerned the prior protections were not enough when communicating and expressing themselves online.<\/p>\n<h3 class=\"my-4\">Understanding onion services<\/h3>\n<p>As of March 2017, an estimated <a href=\"https:\/\/metrics.torproject.org\/hidserv-dir-onions-seen.html?start=2016-12-15&amp;end=2017-03-15\">50,000 onion services<\/a> are operating on the Tor network. Onion services continuously come online and offline, though, so it is difficult to obtain exact numbers.<\/p>\n<p>Their name comes from the fact that, like Tor users, their identities and activities are protected by multiple layers of encryption, like those of an onion.<\/p>\n<p>While <a href=\"https:\/\/doi.org\/10.1109\/ISI.2016.7745452\">criminals are frequently early adopters<\/a> of anonymity technology, as more people use the system, legal and ethical uses become far more common than illegal ones. Many onion services host websites, chat sites and video calling services.<\/p>\n<p>We don\u2019t know all of what they\u2019re doing because The Tor Project <a href=\"https:\/\/www.ipc.on.ca\/wp-content\/uploads\/Resources\/7foundationalprinciples.pdf\">designs privacy into its technology<\/a>, so it does not and cannot keep track. In addition, when new onion services are set up, their very existence is private by default; an operator must choose to broadcast a service\u2019s existence publicly.<\/p>\n<p>Many owners do announce their sites\u2019 existence, however, and the <a href=\"https:\/\/ahmia.fi\">Ahmia search engine<\/a> provides a convenient way to find all publicly known onion services.<\/p>\n<p>They are as diverse as the internet itself, including a <a href=\"http:\/\/3g2upl4pq6kufc4m.onion\">search engine<\/a>, a <a href=\"http:\/\/toristinkirir4xj.onion\">literary journal<\/a> and an <a href=\"http:\/\/n3q7l52nfpm77vnf.onion\">archive of Marxist and related writing<\/a>. <a href=\"https:\/\/facebookcorewwwi.onion\">Facebook<\/a> even has a way for Tor users to <a href=\"https:\/\/www.facebook.com\/notes\/protect-the-graph\/making-connections-to-facebook-more-secure\/1526085754298237\/\">connect directly to its social media service<\/a>.<\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Facebook.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-203564\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Facebook.jpg\" alt=\"Facebook\" width=\"640\" height=\"445\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Facebook.jpg 754w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Facebook-576x400.jpg 576w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2017\/03\/Facebook-619x430.jpg 619w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<h3 class=\"my-4\">Creating an onion site<\/h3>\n<p>When a privacy-conscious user sets up an onion service (either <a href=\"https:\/\/www.torproject.org\/docs\/tor-manual.html.en\">manually<\/a> or with a third-party tool such as <a href=\"https:\/\/onionshare.org\">onionshare<\/a>), people who want to connect to it must use the Tor Browser or other Tor-enabled software; normal browsers such as Chrome and Firefox cannot connect to domains whose names end in \u201c.onion.\u201d<\/p>\n<p>(People who want to peek at onion sites without all of the network\u2019s anonymity protections can visit <a href=\"https:\/\/tor2web.org\">Tor2web<\/a>, which acts as a bridge between the open web and the Tor network.)<\/p>\n<p>Originally, a new onion service was supposed to be known only to its creator, who could choose whether and how to tell others of its existence.<\/p>\n<p>Of course, some, like Facebook, want to spread the word as widely as possible. But not everyone wants to open their Tor site or service to the public, the way search and social media sites do.<\/p>\n<p>However, a design flaw made it possible for an adversary to learn about the creation of a new onion service. This happened because each day, onion services announce their existence to several Tor relays.<\/p>\n<p>As happened in 2014, an <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/carnegie-mellon-university-attacked-tor-was-subpoenaed-by-feds\">attacker could potentially control enough relays<\/a> to keep track of new service registrations and slowly build up a list of onion sites \u2013 both secret and public \u2013 over time.<\/p>\n<p>The same design flaw also made it possible for an attacker to predict what relays a particular service would contact the following day, allowing the adversary to become these very relays, and render the onion service unreachable.<\/p>\n<p>Not only could someone wanting to operate a private, secret onion service be unmasked under certain circumstances, but their site could effectively be taken offline.<\/p>\n<p>The updates to the system <a href=\"https:\/\/gitweb.torproject.org\/torspec.git\/tree\/proposals\/250-commit-reveal-consensus.txt\">fix both of these problems<\/a>. First, the relays each service contacts for its daily check-in will be randomly assigned. And second, the check-in message itself will be encrypted, so a relay can follow its instructions, but the human operator won\u2019t be able to read it.<\/p>\n<h3 class=\"my-4\">Naming domains more securely<\/h3>\n<p>Another form of security causes the names of onion services to be harder to remember. Onion domains are not named like regular websites are: <a href=\"http:\/\/www.facebook.com\">facebook.com<\/a>, <a href=\"http:\/\/www.theconversation.com\">theconversation.com<\/a> and so on.<\/p>\n<p>Instead, their names are derived from randomly generated cryptographic data, and often appear like <a href=\"http:\/\/expyuzz4wqqyqhjn.onion\">expyuzz4wqqyqhjn.onion<\/a>, which is the website of The Tor Project. (It is possible to repeatedly generate onion domains until a user arrives at one that\u2019s a bit easier to recognize. Facebook did that and \u2013 with a combination of luck and raw computational power \u2013 managed to create <a href=\"http:\/\/facebookcorewwwi.onion\">facebookcorewwwi.onion<\/a>.)<\/p>\n<p>Older onion services had names made up of 16 random characters. The new ones will use 56 characters, making their domain names look like this: l5satjgud6gucryazcyvyvhuxhr74u6ygigiuyixe3a6ysis67ororad.onion.<\/p>\n<p>While the exact effects on users\u2019 ability to enter onion services\u2019 addresses haven\u2019t been studied, lengthening their names shouldn\u2019t affect things much. Because onion domain names have always been hard to remember, most users take advantage of the Tor Browser\u2019s bookmarks, or copy and paste domain names into address fields.<\/p>\n<h3 class=\"my-4\">Protecting onion sites<\/h3>\n<p>All this new design makes it significantly harder to discover an onion service whose operator wants it to remain hidden. But what if an adversary still manages to find out about it? The Tor Project has solved that problem by allowing onion services to challenge would-be users to enter a password before using it.<\/p>\n<p>In addition, The Tor Project is updating the cryptography that onion services employ. Older versions of Tor used a <a href=\"https:\/\/people.csail.mit.edu\/rivest\/Rsapaper.pdf\">cryptosystem called RSA<\/a>, which could be broken by calculating the two prime factors of very large numbers.<\/p>\n<p>While RSA is not considered insecure yet, researchers have devised <a href=\"http:\/\/www.ams.org\/notices\/199902\/boneh.pdf\">several attacks<\/a>, so The Tor Project is replacing it with what is called <a href=\"https:\/\/blog.cloudflare.com\/a-relatively-easy-to-understand-primer-on-elliptic-curve-cryptography\/\">elliptic-curve cryptography<\/a>, which uses keys that are shorter, more efficient and understood to be at least as secure.<\/p>\n<p>The developers are also updating other basic elements of the encryption standards used in Tor. The hash function, which Tor uses to derive short and constant-length text strings from arbitrarily long data, will change from the troubled \u2013 and <a href=\"https:\/\/shattered.io\/\">partially broken<\/a> \u2013 SHA-1 to the modern <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2015\/08\/nist-releases-sha-3-cryptographic-hash-standard\">SHA-3<\/a>.<\/p>\n<p>In addition, secret keys for the <a href=\"https:\/\/doi.org\/10.6028\/NIST.FIPS.197\">Advanced Encryption Standard<\/a> cryptosystem will be twice as long as before \u2013 and therefore significantly harder to break. These don\u2019t address specific immediate threats, but protect against future improvements in attacking encryption.<\/p>\n<p>With these improvements to the software that runs Tor, we\u2019re expecting to be able to prevent future attacks and protect Tor users around the world.<\/p>\n<p>However, better anonymity is only one aspect in the bigger picture. More experimentation and research are necessary to make onion services easier to use.<\/p>\n<p><a href=\"https:\/\/theconversation.com\/profiles\/philipp-winter-245128\">Philipp Winter<\/a>, Postdoctoral Research Associate in Computer Science, <em><a href=\"http:\/\/theconversation.com\/institutions\/princeton-university-1357\">Princeton University<\/a><\/em><\/p>\n<p>This article was originally published on <a href=\"http:\/\/theconversation.com\">The Conversation<\/a>. Read the <a href=\"https:\/\/theconversation.com\/tor-upgrades-to-make-anonymous-publishing-safer-73641\">original article<\/a>.<\/p>\n<h3 class=\"my-4\">Now read:\u00a0<a href=\"https:\/\/mybroadband.co.za\/news\/security\/203470-former-it-admin-used-backdoors-to-help-new-employer.html\" rel=\"bookmark\">Former IT admin \u201cused backdoors\u201d to help new employer<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>In the coming months, the Seattle-based nonprofit The Tor Project will be making changes to improve privacy and security. <\/p>\n","protected":false},"author":340972,"featured_media":161684,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[35,2818],"class_list":["post-203558","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-headline","tag-tor"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/203558"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/340972"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=203558"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/203558\/revisions"}],"predecessor-version":[{"id":203562,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/203558\/revisions\/203562"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/161684"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=203558"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=203558"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=203558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}