Skip to content

Comment on Is Tor Safe? Think Again.

Comments

Security can succeed by making an attack economically or logistically impractical. You have to consider when using any such system:

1. What would it cost the adversary to pull off a successful attack to reveal your identity? Would it be worth it to the attacker to do so?

2. Are there easier, more obvious targets?

I would say it's a possible useful tool of increasing that cost for a potential adversary above their threshold of resources and motivation.

If I'm wrong, tell me where I posted this from, and I'll go hide in the woods.

Naturally depends on who you're trying to hide from.

This article seems to have been written from the point of view of "the CIA are watching me", not "I don't want someone to hack my facebook profile".

And based on that logic, you have to assume that the CIA (or whatever agency) won't chose who to spy on based on who will cost them the least money.

The CIA won't choose to spend $1billion+ to spy on a single person unless they are really important.

Most of the things he mentions are very cheap to pull off, though. Proxy honeypots, sniffing ISP internet connections, querying IPs, email surveillance -- the infrastructure is already in place they just have to type some commands. Cost: $0.

On the other hand, actions that require actually sending men in suits and vans filled surveillance equipment can be costly. If they're doing that, you know you're in big trouble.

Most of the things he mentions are very cheap to pull off, though. Proxy honeypots, sniffing ISP internet connections, querying IPs, email surveillance -- the infrastructure is already in place they just have to type some commands. Cost: $0.

I'm sorry but I have to jump in here - you're writing off an awful lost of resources under the banner of "they just have to type some commands."

I'm sorry you had to take that literal, I was just figuratively speaking.

My point is that it is the human part of surveillance that is costly. For everything that can be collected automatically with systems already in place (even though placing those systems could have been very expensive), the threshold to use it is very low. When the information is collected and processed, what rests is only database queries. "automatic surveillance" is (comparatively) cheap.

In contrast, "expensive surveillance" is placing monitoring equipment in a house, parking some fan sneakily around the block to listen in, and such. It's labour and resource intensive.

the infrastructure is already in place they just have to type some commands. Cost: $0.

[citation needed]

I don't think that budget needs to be publicly declared. It's just rubber-stamped by some senate committee (IIRC), and the numbers are never released.

So effectively, yes, it's free for the people who do it.

If you can't point to budget appropriation, then at least point to some kind of reference to "they just sit and enter few commands and spy on you". There are definitely sophisticated surveillance programs out there, but notion that they track everything is just too tinfoil for me, sorry.

He didn't say they track everything, he said the marginal cost to track any particular thing is near zero.

How much was the war in Afghanistan just to get Osama Bin Laden?

War is extremely profitable for those who on one the receiving end of the costs.

I highly recommend reading http://jontaplin.com/the-cost-of-empire/ , get the PDF if the images are not loading.

If it was really only about getting Osama Bin Laden, then we would probably have him by now. It was really about attacking a group (Al Qaeda, Taliban) and looking strong in the face of 9/11 by striking back at someone (anyone).

Yes, yes, a thousand times yes.

Adversaries are limited by their budget. When it comes to security, the you should assume that any security protocol can be beaten by a sophisticated and well-funded adversary. There are too many points of failure, and human ingenuity is too powerful, for any security scheme to be impenetrable. Next you should wonder, how expensive would it be to break in? If you can make it too expensive for an adversary to break your security protocol, they will not break it.

One other important thing to consider here is that ideologically motivated adversaries (like governments) will have a different idea of what is "too expensive" than adversaries motivated purely by profit (like carders). If you're trying to avoid an ideologically motivated adversary with billions of dollars at their disposal, you have to be capable of thinking outside of the box.

I can see that demotivating your casual attacker, however if somebody like the CIA or NSA has decided they want to spy on you specifically, the cost of doing so is probably not going to stop them.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.