Share

Flaws found in privacy-protecting software

San Francisco - Researchers have found a flaw that could expose the identities of people using a privacy-oriented operating system touted by Edward Snowden, just two days after widely used anonymity service Tor acknowledged a similar problem.

The most recent finding concerns a complex, heavily encrypted networking program called the Invisible Internet Project, or I2P. Used to send messages and run websites anonymously, I2P ships along with the specialised operating system "Tails", which former US spy contractor Snowden used to communicate with journalists in secret.

Though a core purpose of I2P is to obscure the Internet Protocol addresses of its roughly 30 000 users, anyone who visits a booby-trapped website could have their true address revealed, making it likely that their name could be exposed as well, according to researchers at Exodus Intelligence.

"People shouldn't trust something wholeheartedly just because Snowden says," said Exodus vice president Aaron Portnoy. "Generally, we assume the things we can find, others can find."

Tails launches from a DVD or USB stick and is designed to maintain privacy even when a computer or network has been hacked.

Vulnerable

Much more than I2P, Tails relies on Tor, the better-known anonymity system that it uses for all software connections to the internet.

But leaks in the past year have shown that Tor is also a major target for the US National Security Agency and others, and researchers at Carnegie Mellon University said they could have identified hundreds of thousands of Tor users.

Those researchers planned to detail their technique in August at the security conference Black Hat. After Tor developers complained to Carnegie Mellon, the university told Black Hat to cancel the talk.

Tor programmer Roger Dingledine conceded that the researchers had found a flaw, and he said his team was now working to fix it before any public disclosure exposes dissidents and other types of users on Tor to greater risk of attack.

The I2P flaw will likewise be fixed. A spokesperson for the I2P project said the group of developers was still analysing the Exodus report.

Tails did not respond to an e-mail seeking comment. It was not clear how many Tails users would have been vulnerable without Exodus' co-operation, since the I2P application does not launch automatically when the operating system is opened.

Exodus is one of a dozen or more companies known to sell secret security flaws to intelligence agencies, law enforcement and other customers in a controversial marketplace.

Government client

But in this case, Exodus alerted I2P and Tails to the problem and said it would not divulge the details to customers until the problem has been fixed. Portnoy declined to say what the company would do if a government client asked him to find a similar flaw in the future.

The Tails and Tor episodes show that no anonymity system is failsafe, Portnoy said, and those in jeopardy should focus on compartmentalising their efforts so that a single breach would not expose everything about them.

"Tor works for most purposes, but a determined adversary will always find a way," he said.

In one such high-stakes case, the FBI used a flaw in a Firefox web browser that came bundled with Tor to identify a man suspected of hosting child pornography, according to Irish media reports.

Leaked NSA documents show that the NSA logged the IP addresses of many Tor users and may have scanned e-mails for users living outside of the US and its four closest intelligence allies, German media reported.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.20
-0.0%
Rand - Pound
23.87
-0.7%
Rand - Euro
20.47
-0.1%
Rand - Aus dollar
12.39
-0.1%
Rand - Yen
0.12
-0.0%
Platinum
921.50
-1.0%
Palladium
1,018.50
+0.3%
Gold
2,314.74
-0.5%
Silver
27.00
-0.7%
Brent Crude
87.00
-0.3%
Top 40
67,983
+0.7%
All Share
73,918
+0.5%
Resource 10
59,585
-2.2%
Industrial 25
102,749
+1.7%
Financial 15
15,852
+1.5%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders