6 ms·
The talk about de-anonymizing Tor at the BlackHat conference has been removed
- bitexploder 12y agoWild conjecture. Most of the guys on CERT have a security clearance. This talk may have been viewed as crossing streams that he could not cross. He likely had to get the talk approved by whoever manages his clearance to ensure his talk is not leaking secret information. Someone further up the chain may have caught wind and pulled it.
- pekk 12y agoSpeakers drop out all the time. Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues.
- at-fates-hands 12y ago>>> Or maybe someone didn't want to compromise Tor in public until the Tor project had a chance to address the issues. To some degree, isn't this what the Black Hat conference is all about?
- jackweirdy 12y agoSeems to me the public ousting of projects only happens when they refuse to implement a fix, or deny that something's an issue.
- deleted 12y ago[deleted]
- MacsHeadroom 12y agoNo, to some degree BH is about compromising X in public after X has been repeatedly contacted with the necessary details AND given ample time to address the issues. What these "researchers" were doing was just reckless. When it comes to Tor, lives are on the line. This kind of irresponsible disclosure is abhorrent, at best.
- tptacek 12y agoI don't know what BH you've been attending for the last 10 years, but it's not the one I've been going to.
- eat 12y agoNot at all... Black Hat is one of the more commercial, "industry" security conferences out there.
- peterwwillis 12y agoEvery year that some controversial BH talk happens that exposes some company's unpatched security vulnerabilities (or even questions the company's integrity), either the talk is pulled, or the talk materials are literally ripped out of the books or CDROMs given to attendees. As soon as a company gets wind that a talk might catch them with their pants down they threaten to file suit and Black Hat pulls the talk. The Black Hat conference is about promoting the security industry. DEFCON, on the other hand, is about promoting hacker culture. It's a lot more common to see 0-day talks at DEFCON because there's much less industry spotlight [and thus, fewer general business professionals that could get scared by some new attack being announced].
- yalue 12y agoI doubt this removal is anything sinister. Attacks on Tor have been a relatively common theme at many large security conferences. For example, there was a presentation at IEEES&P 2013 on de-anonymizing Tor hidden services (http://www.ieee-security.org/TC/SP2013/papers/4977a080.pdf http://www.ieee-security.org/TC/SP2013/papers/4977a080.pdf). The Tor people are typically pretty open to this stuff. It was most likely removed due to something mundane, like the presenters having issues getting through their organization's bureaucracy.
- dpeck 12y agoMid summer tends to be pullout season for Blackhat and Defcon speakers. A handful happen every year, thats why they have alternates. Sometimes the speakers screwed up and didn't get their material together and they weren't important enough to ignore that. Other times they're threatened by their employer or some external forces. Subway hacking, Padgets RFID (and GSM a few years later IIRC), etc. Theres quite a history of great presentations that have never happened for one reason or another.
- packetlss 12y agoA Black Hat spokeswoman told Reuters that the talk had been canceled at the request of lawyers for Carnegie-Mellon University, where the speakers work as researchers. A CMU spokesman had no immediate comment. Source: http://www.reuters.com/article/2014/07/21/cybercrime-conference-talk-idUSL2N0PW14320140721 http://www.reuters.com/article/2014/07/21/cybercrime-confere...
- lanbird 12y agoThank you for the information packetlss! http://www.qatar.cmu.edu/iliano/svc/meetings/PX/2004-09-21/syverson.pdf http://www.qatar.cmu.edu/iliano/svc/meetings/PX/2004-09-21/s... http://www.cmu.edu/silicon-valley/research/tech-showcase/pdfs/stegotorus.pdf http://www.cmu.edu/silicon-valley/research/tech-showcase/pdf...
- 616c 12y agoInteresting, they did a talk at Education City in Qatar and I had no idea about it? Very disappointed, and surprised they had talks with these kinds of experts on this talk (censorship avoidance is not looked kindly upon there).
- x1798DE 12y agoI have to imagine that this is for some sort of internal bureaucratic reason. I don't see who is in a position to even want to stop this talk - almost certainly not the Tor project itself. The mundane (and thus most likely) answer is that the CMU lawyers wanted to pull it either because they want to sort out some sort of intellectual property first, or they're worried about some sort of liability.
- andor 12y agoI don't see who is in a position to even want to stop this talk A government agency that wants to stay a step ahead of the competition or of its targets?
- 12y ago
- orbifold 12y agoAt this point it is not really a good idea to use Tor anyways, given that you are then automatically targeted by the NSA and at the same time potentially provide cover for covert operations of several countries. What is really needed is political action to limit the capabilities of security agencies to indiscriminantly monitor web traffic.
- Sprint 12y agoOn the opposite, everyone should use it. I love using it for queries I feel embarassed about, like googling for illness symptoms or watching wildlife documentaries.
- gnarbarian 12y agobut then how can amazon.com bombard you with ads for Anal Wart Cream for the next six weeks?
- jessaustin 12y agoAs soon as I learned that companies are people, I suspected Sprint might have something like that.
- cortesoft 12y agoI disagree. The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. No political action is going to stop all such entities in the world from monitoring web traffic, let alone prevent non-government entities from doing so. I am not saying Tor is the answer, but whatever the answer is, it will have to be technical.
- DanBC 12y ago> The only way to prevent security agencies from indiscriminately monitor web traffic is to make it technically impossible. The vast majority of people do not want that Internet. See, for example, the popularity of Facebook. (About 1.2bn users per month). You need technical measures, and law, and effective oversight.
- dan_bk 12y agohttps://news.ycombinator.com/item?id=7998527 https://news.ycombinator.com/item?id=7998527
- wfn 12y agoRoger's response here is probably relevant: https://lists.torproject.org/pipermail/tor-talk/2014-July/033954.html https://lists.torproject.org/pipermail/tor-talk/2014-July/03... Hi folks, Journalists are asking us about the Black Hat talk on attacking Tor that got cancelled. We're still working with CERT to do a coordinated disclosure of the details (hopefully this week), but I figured I should share a few details with you earlier than that. 1) We did not ask Black Hat or CERT to cancel the talk. We did (and still do) have questions for the presenter and for CERT about some aspects of the research, but we had no idea the talk would be pulled before the announcement was made. 2) In response to our questions, we were informally shown some materials. We never received slides or any description of what would be presented in the talk itself beyond what was available on the Black Hat Webpage. 3) We encourage research on the Tor network along with responsible disclosure of all new and interesting attacks. Researchers who have told us about bugs in the past have found us pretty helpful in fixing issues, and generally positive to work with. (imho 2) and 3) is a polite way of saying that this particular talk did not feature much in terms of responsible disclosure. But these are not related to 1).)
- lawnchair_larry 12y agoCoordinated disclosure is the proper term.
- ripb 12y agoA lot of "I don't like your post so I'm downvoting it", Reddit-esque behaviour in this thread.