Share

Tor warns users: Government might have hacked us

Boston - Tor, the prominent system for protecting internet privacy, said on Wednesday many of its users trying to reach hidden sites might have been identified by government-funded researchers.

In a note on the non-profit’s website, Tor Project leader Roger Dingledine said the service had identified computers on its network that had been quietly altering Tor traffic for five months in an attempt to unmask users connecting to what are known as "hidden services".

Dingledine said it was "likely" the attacking computers, which were removed on July 4, were operated on behalf of two researchers at the Software Engineering Institute, which is housed at Carnegie-Mellon University, but funded mainly by the US Department of Defence.

The pair had been scheduled to speak on identifying Tor users at the Black Hat security conference in August. After Tor developers complained to Carnegie-Mellon, officials there said the research had not been cleared and cancelled the talk.

Previous reports on the research had already raised alarms among privacy activists. Dingledine went further, warning on Wednesday that "users who operated or accessed hidden services from early February through 4 July should assume they were affected."

Hidden services

Those navigating to ordinary websites should be in the clear.

It remains uncertain how much data the researchers were able to collect and what will happen to that information, which would be of interest to intelligence agencies and law enforcement.

Hidden services include underground drug sites such as the shuttered Silk Road, as well as privacy-conscious outfits such as SecureDrop, which is designed to safely connect whistle blowers with media outlets.

Dingledine said the physical locations where the hidden services were housed could have been exposed, although probably not the content on them that was viewed by a visitor.

"Unfortunately, I cannot comment," said lead Software Engineering Institute researcher Alexander Volynkin.

Institute spokesperson Richard Lynch declined to comment, while the FBI had no immediate response to questions about whether it would seek the data.

Defence Department spokesperson Valerie Henderson said she did not know if officials there would have the right to raw research from the Institute.

"You have to know what organisation and which individuals inside the Department of Defence might have set this one up," Henderson said.

Even if there is an overarching guideline about access to unpublished research, “the general rule may not apply”, she added.

Tor is an anonymity tool designed to protect the identity of Internet users by routing traffic through multiple nodes around the world. It is used by human rights activists, criminals and others looking to evade surveillance.

Dingledine advised users to upgrade to the latest version of its software, which addresses the vulnerability that was exploited. He cautioned that attempts to break Tor were likely to continue.

Leaked National Security Agency documents show the NSA has logged the IP addresses of many Tor users and might have scanned emails for users living outside of the United States and its four closest intelligence allies, the UK, Canada, Australia and New Zealand, media in Germany reported this month.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.07
+0.5%
Rand - Pound
23.60
+1.0%
Rand - Euro
20.32
+0.3%
Rand - Aus dollar
12.24
+0.5%
Rand - Yen
0.12
+0.4%
Platinum
943.20
-0.8%
Palladium
1,035.50
+0.6%
Gold
2,388.72
+0.4%
Silver
28.63
+1.4%
Brent Crude
87.11
-0.2%
Top 40
67,314
+0.2%
All Share
73,364
+0.1%
Resource 10
63,285
-0.0%
Industrial 25
98,701
+0.3%
Financial 15
15,499
+0.1%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders