Tor Project Mulls How Feds Took Down Hidden Websites

HughPickens.com writes: Jeremy Kirk writes at PC World that in the aftermath of U.S. and European law enforcement shutting down more than 400 websites (including Silk Road 2.0) which used technology that hides their true IP addresses, Tor users are asking: How did they locate the hidden services? “The first and most obvious explanation is that the operators of these hidden services failed to use adequate operational security, ” writes Andrew Lewman, the Tor project’s executive director. For example, there are reports of one of the websites being infiltrated by undercover agents and one affidavit states various operational security errors.” Another explanation is exploitation of common web bugs like SQL injections or RFIs (remote file inclusions). Many of those websites were likely quickly-coded e-shops with a big attack surface. Exploitable bugs in web applications are a common problem says Lewman adding that there are also ways to link transactions and deanonymize Bitcoin clients even if they use Tor. “Maybe the seized hidden services were running Bitcoin clients themselves and were victims of similar attacks.” However the number of takedowns and the fact that Tor relays were seized could also mean that the Tor network was attacked to reveal the location of those hidden services. “Over the past few years, researchers have discovered various attacks on the Tor network. We’ve implemented some defenses against these attacks (PDF), but these defenses do not solve all known issues and there may even be attacks unknown to us.” Another possible Tor attack vector could be the Guard Discovery attack. The guard node is the only node in the whole network that knows the actual IP address of the hidden service so if the attacker manages to compromise the guard node or somehow obtain access to it, she can launch a traffic confirmation attack to learn the identity of the hidden service. “We’ve been discussing various solutions to the guard discovery attack for the past many months but it’s not an easy problem to fix properly. Help and feedback on the proposed designs is appreciated.” According to Lewman, the task of hiding the location of low-latency web services is a very hard problem and we still don’t know how to do it correctly. It seems that there are various issues that none of the current anonymous publishing designs have really solved. “In a way, it’s even surprising that hidden services have survived so far. The attention they have received is minimal compared to their social value and compared to the size and determination of their adversaries.” Read more of this story at Slashdot.

Read the original:
Tor Project Mulls How Feds Took Down Hidden Websites

Mozilla Updates Firefox With Forget Button, DuckDuckGo Search, and Ads

Krystalo writes: In addition to the debut of the Firefox Developer Edition, Mozilla today announced new features for its main Firefox browser. The company is launching a new Forget button in Firefox to help keep your browsing history private, adding DuckDuckGo as a search option, and rolling out its directory tiles advertising experiment. Read more of this story at Slashdot.

Read More:
Mozilla Updates Firefox With Forget Button, DuckDuckGo Search, and Ads

Multi-Process Comes To Firefox Nightly, 64-bit Firefox For Windows ‘Soon’

An anonymous reader writes with word that the Mozilla project has made two announcements that should make hardcore Firefox users very happy. The first is that multi-process support is landing in Firefox Nightly, and the second is that 64-bit Firefox is finally coming to Windows. The features are a big deal on their own, but together they show Mozilla’s commitment to the desktop version of Firefox as they both improve performance and security. The news is part of a slew of unveilings from the company on the browser’s 10th anniversary — including new Firefox features and the debut of Firefox Developer Edition. Read more of this story at Slashdot.

Read this article:
Multi-Process Comes To Firefox Nightly, 64-bit Firefox For Windows ‘Soon’

One in four self-made American billionaires dropped out of college

Bloomberg crunched the numbers on “self-made” billionaires in the U.S. and found that about a quarter of them were college dropouts . Ten of America’s 43 self-made billionaires dropped out. One, Harold Hamm , never even attended college. Read more…

Originally posted here:
One in four self-made American billionaires dropped out of college

Google Voice Gets Native MMS Support, Brings Verizon Into the Fold

MMS support has always been a sore spot for Google Voice, but it looks like the long journey is finally over. Today, Google announced that not only has Verizon joined the club, but MMS can now be sent natively. Read more…

Read More:
Google Voice Gets Native MMS Support, Brings Verizon Into the Fold

Google’s Spending $1 Billion on an Old NASA Hangar, No One Knows Why

Planetary Ventures LLC, a Google shell company, just signed a very expensive lease on a very large building and airfield in Silicon Valley. The lease in question will cost the search giant $1.16 billion over the term of 60 years. The building and airfield in question is the Moffett Field, where Google’s founders have been landing their private jets for years. Read more…

Visit link:
Google’s Spending $1 Billion on an Old NASA Hangar, No One Knows Why

AT&T’s Killing Its In-Flight WiFi Plans

In-flight WiFi is great (because Snapchat on planes!) but also terrible (because paying $12 for two hours of dial-up era internet), something that AT&T was planning to change by offering its own in-flight WiFi. Sadly, AT&T just announced that it’s nuking that idea. Read more…

Excerpt from:
AT&T’s Killing Its In-Flight WiFi Plans