[00:06.630 --> 00:07.030] Hi. [00:07.630 --> 00:08.910] I'm going to start talking now. [00:10.490 --> 00:24.050] My name is Nick Mathewson, and I... for those of you who just saw Lens talk about what anonymity systems are, what they have been, and what they're becoming, I'm going to talk about how to break them. [00:24.530 --> 00:29.470] Now, why am I talking about this, given that I spend most of my time trying to make them and keeping them working? [00:29.470 --> 00:48.490] Well, largely because the people who are trying to break them now don't... aren't the sort of cool people who attend these conferences, who learn how to break things, maybe, you know, play an innocent prank or two with the things they've broken, and then tell everyone else how to do it so that whatever problems there were can go get fixed. [00:48.490 --> 01:01.190] They're people who are very selfish with their knowledge and use it to do nefarious things like track down human rights activists and other things that just don't make my job of making these things secure simpler. [01:01.530 --> 01:08.490] So, I'm hoping that by getting people interested in this topic, I'll get people who will help me out interested in the topic. [01:09.970 --> 01:16.610] As Len said, I'm involved with the Mixed Minion Type 3 project, and I'm also one of the developers on Tor, the onion router. [01:19.370 --> 01:24.330] So, I'm going to talk to you a little bit about attacks that I know, and I'll take questions at the end. [01:25.970 --> 01:29.170] I'm going to start out by telling you a little bit about anonymity networks. [01:29.510 --> 01:33.290] Most of that is going to be stuff that Len covered, so I'll gloss over it pretty fast. [01:34.190 --> 01:42.710] Then I'll talk about some attacks that should be dead long ago, because we've known how to defeat most of them since David Chom wrote his first Mixed Nets paper in 1981. [01:43.530 --> 01:53.970] But because there's a sort of really regrettable divide between the hacker community, which is full of geniuses, and the research community, which is full of geniuses. [01:53.970 --> 02:04.110] And both of whom are convinced that the other side has nothing to teach them, that it's really only recently that people started going to each other's conferences. [02:05.090 --> 02:06.850] Then I'll talk about traffic analysis. [02:07.030 --> 02:11.150] I'm going to start out by talking about the hard version, which I call traffic analysis for telcos. [02:11.470 --> 02:18.210] Or it also works well as traffic analysis for this lovable gentleman glaring at you from behind me. [02:19.130 --> 02:24.370] Then I'll talk about ways... These attacks are going to be a little outside of the price range of any of you. [02:24.690 --> 02:30.470] Unless you happen to work for three-letter government agencies, you know who you are, and you know who you are on tape. [02:31.990 --> 02:44.190] But I'll talk about ways that you can simplify them, speed them up, and try to collect more data, more usably faster, in order to attack those pesky people revealing the secrets of your UFO cult. [02:45.230 --> 02:47.650] Then I'll talk about outside the box stuff. [02:48.210 --> 02:52.910] Because traffic analysis is really attacking anonymity networks at their strongest point. [02:53.290 --> 02:55.490] They're designed to be traffic analysis resistant. [02:56.290 --> 02:57.630] Why do things the hard way? [02:58.290 --> 03:04.950] Finally, I'll talk about how we think we might defend against some of these things, and which of these things we've got no clue how to beat. [03:06.630 --> 03:10.730] Hopefully it's just the hard ones we don't know how to beat, but see whether you believe me or not. [03:12.130 --> 03:20.590] I'm not going to talk about steganographic systems, that is systems that would hide not only what you're saying, but the fact that you're using the system at all. [03:21.210 --> 03:24.130] Not only who you're saying stuff to, but the fact you're using the system at all. [03:24.590 --> 03:30.190] I'm not going to talk about supposedly systems that are supposed to give you plausible deniability only. [03:30.570 --> 03:33.970] That is, everyone knows it's you, but they can't prove it. [03:33.970 --> 03:39.550] And I'm not going to talk about snake oil anonymity systems that are based on wishful thinking. [03:39.710 --> 03:42.190] That is, I didn't write my name on it, so it's anonymous. [03:42.670 --> 03:47.490] No one's going to bother to fingerprint me, so I'm anonymous. [03:48.170 --> 03:53.090] No one was looking at that open proxy I used to send that mail, so I'm probably anonymous. [03:54.110 --> 03:56.050] So, how do anonymity networks work? [03:56.790 --> 03:59.990] Well, how many people were not at Len's talk? [04:01.050 --> 04:03.370] Okay, a good number, so I'll cover this. [04:03.710 --> 04:23.550] From a black box point of view, there's a bunch of people called Alice, and they want to send messages to people or use websites or whatever, and I'll call those people they're sending to you or the websites they're using Bob, and they want this picture to be the only picture that you, [04:23.650 --> 04:24.470] the attacker, can see. [04:24.650 --> 04:30.830] You see, okay, a bunch of Alice's, maybe there's 10,000 instead of five, are sending some messages. [04:31.150 --> 04:35.150] And a bunch of Bob's, maybe there's 10,000 instead of four, are getting messages. [04:35.810 --> 04:42.150] And I don't know who, which Alice is sending to which Bob, and what am I going to do? [04:42.690 --> 04:44.050] So, how does this work? [04:46.070 --> 04:49.670] You've got a bunch of servers that make up the network. [04:50.710 --> 04:57.070] Each Alice, when she's going to send a message to a chosen Bob, chooses a path through the servers in the network. [04:57.210 --> 05:02.250] There's way more servers than that, the paths are longer, the connections are more complicated, there's more messages. [05:02.590 --> 05:03.590] This is a simplification. [05:04.850 --> 05:17.750] And each Alice, after she picks her path of servers, takes her message and does a layered encryption with the public keys of the servers along her path. [05:18.210 --> 05:23.030] She tells each one in the public key encrypted part of it which server to use next. [05:23.610 --> 05:26.850] So, the first server says, ah, I got a message from Alice. [05:28.170 --> 05:32.510] Unwraps the public key crypto, says, okay, I'm supposed to send this to server 99. [05:33.370 --> 05:36.890] And it holds onto it for a little while to hide the timing connection. [05:37.770 --> 05:42.250] And it reorders it with a bunch of other messages from other Alice's and other servers. [05:42.810 --> 05:44.470] And then it sends it off to server 99. [05:44.750 --> 05:53.830] Server 999 gets it, unwraps another layer, says, ah, this is going to server 84, and so on and so on until the last one says, ah, this is going to Bob 12 and sends it to one of the Bobs. [05:55.090 --> 06:06.690] And, um, if this all works, then all of the Alice's are plausible senders for any given message that goes to any Bob. [06:08.650 --> 06:11.450] Now, suppose we're attacking this thing. [06:12.210 --> 06:13.570] What might we want to do? [06:13.830 --> 06:17.710] Because there's not only different attackers in terms of what their capabilities are, they have different goals as well. [06:17.930 --> 06:24.030] We might want to know, who wrote this nasty message criticizing my country's government? [06:24.430 --> 06:28.530] We might want to know, did the same person write these two messages? [06:29.450 --> 06:40.390] We might want to know, who's talking to some particular Alice that we think is up to no good, that we want to catch with something embarrassing so we can blackmail her? [06:41.130 --> 06:49.630] We might just be really snoopy, nosy people who want to know who's talking with whom in general because we like to keep an eye out on things. [06:50.250 --> 06:55.910] We might have no interest in who's talking to who or who's saying what, but we just want the people who say things we don't like to shut up. [06:58.170 --> 07:00.530] And, you know, for a lot of people, that's what they're out to do. [07:01.110 --> 07:09.830] Um, one possible axis along which attacker goals can vary is, when you're trying to find things out, is do you want probability or certainty? [07:09.830 --> 07:11.150] How much certainty do you need? [07:11.710 --> 07:18.150] Um, do you need to know who did it, you know, with scientific certainty? [07:18.290 --> 07:22.570] Or are you okay saying, well, it was one of those three guys over there, I'll shoot them all. [07:23.530 --> 07:26.130] Um, are you bound by rules of evidence? [07:26.870 --> 07:42.010] If you're the FBI and assuming for the moment that the Constitution applies, assuming, um, then you can't just go do illegal wiretaps on people for no good reason. [07:42.990 --> 07:46.570] You need to get permission before you go snooping on people. [07:46.930 --> 07:48.350] So you need to follow the rules of evidence. [07:48.570 --> 07:51.690] On the other hand, if you're an intelligence agency, you can get away with a lot more. [07:53.150 --> 07:55.690] So, Len has already talked about this a little bit. [07:55.870 --> 08:05.930] I'm going to be breaking my talk into attacks on the two major flavors of anonymity networks, because the threat models against them are very different. [08:06.270 --> 08:29.250] There's high latency mix nets, originally proposed by David Chom in 1981, then redone later by the developers of the Cypherpunk or Type 1 remailer, um, improved by Mix Master, then there's Mix Minion, um, which is still in Alpha Beta or Alpha Beta as the Nintendo at the previous talk called it, [08:29.850 --> 08:38.970] um, Babel, which is a design that was built but never really deployed, and lots of other really nifty things you can read papers about that nobody ever built but are cool to read papers about. [08:39.750 --> 08:55.330] These things, messages go in, and they take anywhere from half an hour to a couple hours to come out depending on a lot of things, and because of that, they can hide the connection between incoming and outgoing messages better, but they're not really suitable for playing Quake with your friends, [08:55.530 --> 08:58.750] um, unless you like Quake by mail. [08:59.510 --> 09:17.010] Um, then there are low latency networks like Freedom, may Freedom never die, it's dead, Tor, the onion router, the Java non-proxy, also known as JAP, um, by some folks at University of Dresden in Germany, and many other systems that have been proposed, [09:17.350 --> 09:18.470] some built, some not. [09:20.150 --> 09:27.010] So now the historical attacks, which aren't, which are, I call, put historical in quotes because they should be historical, but people still use this stuff. [09:27.950 --> 09:32.650] Against the cypherpunk remailers, Len's talked some about this, but he's promised that I would talk more about it, so I will. [09:33.250 --> 09:36.050] Um, one of the easiest things is replay attacks. [09:36.950 --> 09:43.490] Cypherpunk messages don't, cypherpunk remailers don't check to see whether they've seen the same message before necessarily. [09:44.010 --> 09:49.150] So, if you, if Alice sends a message and you want to see, say, who's that message going to? [09:49.990 --> 10:02.910] If you're an attacker with, uh, who can, you know, mess with packets on the wire, who can even eavesdrop, you take that message and you send that same message 50 times and you see who gets 50 copies of the same message. [10:03.510 --> 10:05.270] That person is probably the recipient. [10:06.190 --> 10:18.130] And you can do similar attacks if you can get a hold of one of Alice's reply blocks, which is a, um, basically an encrypted path to get messages back to Alice without knowing who Alice is. [10:18.650 --> 10:20.990] There's also size correlation attacks. [10:21.590 --> 10:31.430] Um, there are some countermeasures against, um, replay attacks implemented in cypherpunk, but not all cypherpunk remailers support them and they don't really work. [10:32.010 --> 10:34.310] Um, so, okay, there's also size correlation attacks. [10:34.730 --> 10:41.170] You might notice that, you know, say, this was, a megabyte message went into this remailer. [10:41.370 --> 10:44.630] A 20k message went into this remailer. [10:44.990 --> 10:47.970] A one meg minus a couple bytes came out. [10:48.470 --> 10:50.210] A 20k minus a couple bytes came out. [10:51.930 --> 10:58.410] Probably those, you can tell that the one meg goes with the one meg, the 20k goes with the 20k. [10:59.590 --> 11:06.590] Another thing about cypherpunk is it has lots of features and it uses PGP as its encryption format. [11:07.010 --> 11:08.430] And PGP has lots of features. [11:08.550 --> 11:13.490] Now, features sound good, except that you realize that we are a wonderful, diverse species. [11:13.850 --> 11:17.330] And as wonderful, diverse people, we make lots of different decisions. [11:17.650 --> 11:21.510] And the decisions I love and the decisions you love mean that we look different. [11:21.510 --> 11:24.450] So when we're providing cover for each other, this works against us. [11:24.910 --> 11:26.590] So there's many versions of PGP. [11:26.830 --> 11:46.570] And, you know, and while we're trying to hide each other in the system, while we're all trying to look like the same Alice, the fact that you're using PGP version two, and I'm using PGP version six, or you like triple DES for your cypher, RSA... Oh, no, [11:46.650 --> 11:47.450] no, the remailer uses the key. [11:47.570 --> 12:02.590] You like triple DES, you like bzip, and you like SHA-1, and I like MD5, and I like AES, and I like no compression at all, means that our messages won't provide any cover for each other. [12:03.030 --> 12:11.750] And worse yet, if I choose a really unpopular version of PGP, I might be the only guy sending messages through the Cypherpunk network with that version of PGP. [12:11.830 --> 12:13.510] So I think the whole Cypherpunk network is hiding me. [12:13.810 --> 12:16.190] But really, I'm naked. [12:17.910 --> 12:21.510] And Cypherpunk itself has many features to make the situation even worse. [12:21.990 --> 12:23.850] Then there's fancy blending attacks. [12:24.430 --> 12:26.790] And there's all kinds of neat variations on these. [12:26.890 --> 12:39.030] One of the the simplest is, if you are an active attacker, if you own some of the network, and you want to trace one net message as it goes through a remailer, just block all the other messages that are going into that Cypherpunk remailer for a while. [12:39.810 --> 12:43.430] And just let that one through and see what message comes out. [12:44.210 --> 12:48.650] Also, these remailers don't change their keys at all, or if they do, very slowly. [12:49.070 --> 13:05.190] So if a message goes through and you want to break the key that was used to encrypt that message, you've got years, possibly, to break into that server, break the operator's kneecaps, break them down with bribery, whatever, and many more. [13:06.070 --> 13:12.670] Now, against one-hop proxies, which are weak, as Len said, just watch the one-hop proxy. [13:12.970 --> 13:16.350] Own the router, or, you know, own the proxy. [13:16.830 --> 13:17.910] Better yet, you know. [13:18.150 --> 13:21.830] But if you're just watching it, you see, okay, somebody connects, connection goes out. [13:22.030 --> 13:23.370] A few bytes in, a few bytes out. [13:23.450 --> 13:26.790] There's a trivial timing correlation between in and out if you're watching the proxy. [13:27.550 --> 13:34.830] Or if the proxy actually stores any information itself, then just attack the proxy and get the information. [13:36.150 --> 13:37.710] Legally, et cetera, et cetera. [13:38.430 --> 13:41.250] And Len talked about what happened to Penet a bit for a while. [13:41.810 --> 13:48.350] Right now, the only systems that people seem to be paying money for, though, are one-hop proxies, which is the only reason I'm mentioning them here. [13:49.150 --> 13:53.470] Now, what should our friend on the red background do in order to do this? [13:53.590 --> 14:01.590] And the reason I'm talking about Big Brother is not because I really want to help him out, but because these attacks are easier to understand than low-budget versions. [14:02.510 --> 14:05.030] Now, what am I assuming the attacker can do here? [14:05.630 --> 14:09.310] I'm assuming that they can break into many of the servers on the network. [14:10.110 --> 14:17.950] I'm assuming that they can start up servers on their own and say, hello, I am a student at a German technical college and I am very interested in helping people be anonymous. [14:18.210 --> 14:19.310] Please use my server. [14:20.290 --> 14:22.570] And, you know, under many different false identities. [14:23.130 --> 14:30.510] And I'm assuming that they can eavesdrop on pretty much all of the Internet, or most of the Internet, or just a good chunk of the Internet. [14:31.910 --> 14:34.910] Now, we have to do some cost-benefit analysis here. [14:35.770 --> 14:43.450] This stuff, going against the network is only a good idea if the intelligence agency doesn't have a lot of specific suspects. [14:44.710 --> 14:56.430] If they're after you in particular, if they want to know what you're doing in particular, it's probably easier to eavesdrop upon you personally, or bug your keyboard personally, or kidnap you personally. [14:57.450 --> 15:03.130] This stuff would only ever get used, I imagine, they don't tell me what they're up to. [15:03.290 --> 15:08.790] I imagine, if they don't have enough resources to target all of the users individually. [15:10.210 --> 15:19.970] On the other hand, if you are nefarious and devious enough to compromise a major telco, then this is you. [15:20.170 --> 15:21.690] You can run a lot of servers. [15:21.730 --> 15:24.190] You can probably compromise more servers than just the telco. [15:24.590 --> 15:26.490] And you can watch a good chunk of the network. [15:27.730 --> 15:29.750] So, against low latency systems, what do you do? [15:29.950 --> 15:31.690] You watch both ends and you win. [15:32.710 --> 15:34.410] Timing correlation works great. [15:34.790 --> 15:49.850] You know, once again, and combined with volume correlation, that is how much comes in, how much goes out, you can pretty well link a web requester to the website that they're going to, assuming that you can see both ends. [15:50.890 --> 16:11.810] So, you can say, okay, um, this guy, um, went, um, something about the size of an HTTP request, something about the size of an HTTP request, and in between the two, he got a small thing about this many bytes, and after the second one, he got a much larger file. [16:12.010 --> 16:12.470] Okay. [16:12.650 --> 16:24.410] Now, this website over here, 500 milliseconds after the request, got an HTTP request, and then immediately replied with something about the same size as what the first guy got back. [16:24.670 --> 16:34.350] And you correlate like that, and assuming that he hits a second page on that website, and a third page, and a fourth page, if you're watching both ends, you can win. [16:34.870 --> 16:37.510] And worse yet, you might not even need both ends. [16:38.090 --> 16:53.630] Suppose you already know what images are on CNN.com, how big they are, um, how, say, various popular web browsers respond to getting the page after they've received the first K of the page, the second K, the third K. [16:54.190 --> 16:58.650] And you can build a fingerprint of what CNN.com looks like when you fetch it. [16:58.830 --> 17:02.790] You don't even need to be looking at CNN.com to see that somebody's seeing the main page. [17:03.930 --> 17:05.030] What about padding? [17:05.490 --> 17:14.950] Couldn't we just have Atlas, who we're trying to protect, just always send a full, let's say, 10K into the network every second? [17:15.530 --> 17:22.550] And that way, her channel to her would look the same no matter what was going on. [17:23.210 --> 17:27.110] This would work if you could do it and you could afford it. [17:27.330 --> 17:33.590] There have been lots of neat theory designs, but nothing like this has actually been deployed. [17:34.350 --> 17:37.290] Um, and there's a couple of reasons why it hasn't been deployed. [17:37.610 --> 17:54.950] First off, at the infrastructure, yeah, you can afford a constant bandwidth fairly easily at consumer prices these days, but the infrastructure to support a whole bunch of people always connecting the same amount, always connecting at the same volume that they'll always use ever, [17:55.210 --> 17:57.770] is not proven economical. [17:58.590 --> 18:01.790] Um, Zero Knowledge systems tried it briefly. [18:02.250 --> 18:04.750] I, I, Len says for a day. [18:05.030 --> 18:08.790] Um, and it proved to be too expensive, I've heard. [18:09.350 --> 18:20.510] And another problem with this approach is that if you own one of the routers and Alice connects through you, even if she's giving you a perfect padded stream, you can introduce hiccups into that stream. [18:21.070 --> 18:26.550] And, um, all of a sudden Alice's is no longer sending it a constant rate. [18:27.090 --> 18:32.750] And you can see, ah, are there any requests on the other end that come out with little hiccups in them that match the hiccups I've added. [18:33.630 --> 18:35.130] So, this works for Big Brother. [18:36.090 --> 18:38.190] Now, what do we do against high latency systems? [18:39.010 --> 18:40.470] I'll admit, these are hard. [18:40.670 --> 18:42.250] Big Brother has to work a little bit here. [18:43.010 --> 18:46.270] Um, these are, this is pretty good tech for being fairly anonymous. [18:46.990 --> 18:56.330] The best traffic analysis thing that we know of against these is long-term statistical timing correlation, otherwise known as intersection attacks. [18:56.510 --> 18:59.030] Now, this can only works for long-term patterns. [18:59.490 --> 19:02.050] Alice has to be talking to somebody for a long while. [19:02.410 --> 19:08.470] Bruce Wayne has to be sending messages signed Batman for years, or at least for a few dozen messages, depending. [19:09.110 --> 19:10.970] And it can take lots of traffic to succeed. [19:11.270 --> 19:16.210] The critical factor here is, maybe if Alice is lucky, it takes too much traffic. [19:16.570 --> 19:20.930] Too much being more than she sends, too much being more than her lifetime. [19:21.310 --> 19:26.030] Too much being, she doesn't talk to the same people anymore after too much passes. [19:27.190 --> 19:35.310] Um, now, recent research, in the last few years, people have only started to, like, try to write papers on, well, what's the best way to do this, and how long does it take? [19:36.050 --> 19:41.850] The research I like the best, full disclosure, I wrote, I wrote one of these papers, so I may be biased here. [19:42.210 --> 19:45.750] But, the most promising approach, I think, right now, is called statistical disclosure. [19:46.250 --> 19:50.310] And the basic idea is, you watch the network for a long time, you watch who sends, and who receives when. [19:50.970 --> 19:52.790] And you note, you pick some target Alice. [19:53.610 --> 20:00.250] And you notice, okay, when Alice is sending, how many messages do people tend to receive on average? [20:00.510 --> 20:03.470] How many messages does each person, whoever receives, tend to get on average? [20:03.950 --> 20:10.910] And then you see, okay, when Alice isn't sending, how many messages does everyone tend to get on average? [20:10.910 --> 20:24.790] And, you know, you get two big columns and then you use subtraction to notice that there are some people who get more messages when Alice is sending than when she isn't sending. [20:25.330 --> 20:31.330] Now, as you might imagine, this can take a really long time for you to get for these differences to become apparent. [20:32.170 --> 20:35.350] So... and how long this takes depends on a bunch of factors. [20:36.130 --> 20:40.090] So I'm going to talk to you a little bit about what the results are here. [20:40.390 --> 20:48.570] But before I do, I'm going to mention that in order to analyze this stuff, I'm going to be showing you results from some simulations. [20:48.830 --> 20:50.850] But all models are oversimplified. [20:51.010 --> 20:56.970] And these oversimplifications may make what I'm about to tell you inaccurate to a greater or lesser degree. [20:57.150 --> 21:01.150] So don't go staking your life on anything that I'm about to say. [21:01.150 --> 21:01.170] Okay. [21:02.010 --> 21:05.710] So we analyzed this attack on a simulated network. [21:06.310 --> 21:13.130] And the biggest thing that slowed down the attack was having more variance in how long messages were delayed. [21:13.470 --> 21:16.470] That is, if every message is delayed exactly an hour, that sucks. [21:16.750 --> 21:29.010] But if a message might come out in a longer interval of time, then you have to say, well, okay, then the effect of each individual message is less visible. [21:29.790 --> 21:47.750] So the results we got were when messages, when message latency variance is low, then if you send lots of traffic at once, you lose fairly quickly, like on the order of 100 rounds, where a round is maybe half an hour. [21:48.290 --> 21:50.610] So that's like two days. [21:50.890 --> 21:56.490] On the other hand, if you send messages infrequently, then you last longer. [21:56.670 --> 22:00.550] If you want to know more detail about this stuff, I can tell you where the paper is and where you can read it. [22:00.770 --> 22:08.050] On the other hand, if message delay variance is much higher, then everyone gets more protection. [22:08.990 --> 22:12.490] Even mid-traffic guys still lose more slowly. [22:13.130 --> 22:20.250] But low and high traffic people get more protection when there's more variance in when their messages might come out. [22:20.650 --> 22:36.230] So that's a key fact to keep in mind when I'm going to be talking about the other attacks, which we'll talk about among other things, how you can try to force people to use more insecure networks. [22:36.670 --> 22:40.810] So what if Alice paths on a high latency network and we're big brother? [22:41.330 --> 22:42.810] Well, nobody's perfect. [22:42.950 --> 22:49.170] If Alice always sends the same amount, then she wins again still, except for the hiccup thing. [22:49.350 --> 22:51.710] On the other hand, everyone's computer is down sometimes. [22:52.490 --> 22:55.710] Everyone has their cable company inexplicably shut them off on occasion. [22:56.310 --> 23:01.350] So let's assume Alice is only 99% online sending traffic. [23:01.870 --> 23:07.650] Well, she's doing pretty well if she's on a very high variance network, which is the line on top. [23:07.910 --> 23:15.710] It takes more than a million rounds, which is like more than 50 years at a half an hour round to get Alice then. [23:16.250 --> 23:23.750] On the other hand, she's doing slightly better, but still breakable if she's on a low variance network. [23:23.950 --> 23:27.110] So padding can help sometimes if you're online enough. [23:29.290 --> 23:31.690] So that's all well and good for big brother. [23:31.970 --> 23:41.550] But what can we do if we've only got, you know, oh, the resources of a UFO cult or, you know, a couple spare weekends. [23:42.010 --> 23:46.030] And we want to attack the most secure anonymity networks in the world. [23:47.030 --> 23:49.130] Well, first thing, you don't need to be global. [23:49.690 --> 23:50.210] Basic idea. [23:50.390 --> 23:51.910] Like, this last attack was statistical. [23:52.430 --> 23:57.870] And if you've taken a statistics course or you know little stats, you know, you don't need to see everything to do statistics. [23:58.110 --> 23:58.750] You can sample. [23:59.110 --> 24:00.450] So you run two servers. [24:00.770 --> 24:02.430] You pretend to be two different people. [24:02.830 --> 24:10.630] And you'll get, assuming there's n servers, you will see one over n squared of the traffic both entering and leaving through you. [24:11.150 --> 24:13.190] And that's a sample. [24:13.330 --> 24:14.790] Well, is that a good enough sample? [24:16.170 --> 24:19.310] Not always if there are enough other servers besides you. [24:19.870 --> 24:23.970] This is a simulation for an attacker who only sees part of the network. [24:26.210 --> 24:37.390] And the attacker doesn't really start to get slowed... doesn't start to succeed until they see about 0.2 or 0.3 of the traffic on the network at all. [24:37.490 --> 24:46.210] Which means, to see 20% of the traffic on the network both entering and leaving, you need to be watching or owning 40% of the servers. [24:47.810 --> 24:58.690] Which... it's unclear that you could pretend... that you could take over that much of the network without anyone noticing, hey, these guys all talk alike and act alike. [24:59.030 --> 25:04.190] Or without noticing, hey, all of a sudden there's twice as many servers as there used to be in the last week. [25:05.330 --> 25:08.970] So... and if you're not an intel agency, it might be hard for you to do that without getting caught. [25:09.190 --> 25:10.250] So, what can you do? [25:10.690 --> 25:11.730] We need more data. [25:12.790 --> 25:16.510] How can we get more traffic to go through... let's say we got a few nodes now. [25:16.750 --> 25:19.750] How can we get people to send more traffic through our nodes? [25:20.210 --> 25:21.530] Well, we can run more servers. [25:22.670 --> 25:23.670] That's good for a start. [25:23.910 --> 25:25.510] And we can compromise more servers. [25:26.350 --> 25:31.770] There's a lot of people running servers who show up, do it for a while, go away. [25:31.830 --> 25:36.150] I mean, is anyone checking whether or not, you know, their boxes are secure? [25:36.310 --> 25:38.170] There's some remailers running on Windows. [25:38.410 --> 25:39.510] Are they fully patched? [25:39.590 --> 25:40.230] Who knows? [25:41.830 --> 25:45.810] Another fun thing to do is, well, we talked how the client picks a path. [25:45.930 --> 25:47.350] How does the client pick the path? [25:47.530 --> 25:50.410] They pick it from among the servers they know about. [25:50.410 --> 25:52.190] How do they come to know about servers? [25:52.410 --> 25:54.210] They download a directory of servers. [25:55.230 --> 26:02.970] Let's run our own directory and tell people it's a better directory than the other directory because we're smarter than they are and we love anonymity more than they do. [26:03.310 --> 26:07.850] And let's recommend the servers that we control or own or compromise more than the other ones. [26:07.890 --> 26:12.490] That should be able to get us a few more percentages for those people who we fool. [26:13.170 --> 26:17.910] In fact, we could maybe DOS the servers that we don't control and make them look bad. [26:17.910 --> 26:21.710] So the honest directories will say, hey, those guys, they don't seem to run so good. [26:21.810 --> 26:22.830] They're down some time. [26:23.130 --> 26:24.090] Maybe you should use this guy. [26:24.150 --> 26:25.470] He doesn't get DOSed so much. [26:28.450 --> 26:33.450] And the servers that are running honest directories, well, they're trying to check how reliable you are. [26:34.290 --> 26:42.470] Well, right now, the way they do that, it's sometimes possible to differentiate their reliability probes from real traffic. [26:43.010 --> 26:53.330] Well, if you're a dishonest server, you'd better treat those reliability probes as special precious cargo to be given priority over everything else, which you can drop whenever you like. [26:53.550 --> 26:57.910] And then you'll look better than everyone else who has to do a good job to try to deliver everything. [26:58.970 --> 27:04.810] Another neat way to see more of the traffic, well, they choose a random entry and a random exit. [27:04.930 --> 27:06.790] Clients choose random entry and exit. [27:08.230 --> 27:12.050] But what if you were running a special service that no one else was? [27:12.690 --> 27:14.790] Yeah, this won't fool everybody, but this will fool people. [27:15.550 --> 27:25.970] Um, this has been tried with some success against, excuse me, there are people doing this now and no one can prove whether they're doing it with dishonest intent or not. [27:26.190 --> 27:35.810] But write a closed-source special service that only you can run, say it's amazing, it's wonderful, it's more anonymous than anything else, and you can only get it when you exit from my remailer. [27:36.430 --> 27:44.970] Now instead of people, of you see the traffic whenever people choose one of your remailers for entry and exit, they only, those are the people who like your exit service. [27:45.930 --> 27:50.410] Um, you'll see their traffic whenever they choose one of the other ones you control as your, as their entry. [27:50.730 --> 27:52.670] So you'll see a larger service for them. [27:53.470 --> 27:59.550] Um, you don't beat all the people, but the ones who do you use you, you beat more thoroughly. [28:00.290 --> 28:12.370] Another approach is try to split the anonymity network, fork your own software, get the operators to hate each other, start feuds, start fights, get them to split, get people, some people to like these guys, some people to like that guys. [28:13.190 --> 28:28.050] And, against a smaller network, yeah, some people won't use your server anymore because you've been a dick for so long, but the ones who use you and the other people who are you And the people who like you more than the other guys, it's a smaller network now, [28:28.110 --> 28:29.010] so you get more of the traffic. [28:30.270 --> 28:33.350] Now, how can you get more data from the traffic that you do see? [28:33.790 --> 28:48.830] Well, if there's any disagreement in users among their chosen preferences, among where they get their directory information, you can exploit that to try to make users not look like each other anymore, and feed that into your statistical attacks. [28:49.330 --> 29:06.090] So, for instance, if there's two directories and one of them says that this is a good server and that's a bad server, and one of them says they're both good servers, then any user who uses the server that one thinks is bad isn't using the directory that thinks that server is bad. [29:07.730 --> 29:11.110] So, you know, if you know what directory a user is using, that helps you. [29:11.190 --> 29:18.110] But even if you don't know, you can split off the traffic that's using that server from the rest of the traffic for the purposes of your analysis. [29:18.110 --> 29:20.790] Also, you can try to classify exiting messages. [29:22.110 --> 29:29.310] Split all the messages written in Persian off from the messages written in English. [29:30.110 --> 29:34.730] Split the ones about astrophysics off from the ones about psychology. [29:35.810 --> 29:40.250] Split the ones signed Batman off from the ones signed Superman. [29:40.450 --> 29:42.910] It's basic stuff. [29:43.750 --> 29:51.950] Another neat trick you can do is, and this also has happened against the current MixMaster and Cypherpunk networks, break your server. [29:52.190 --> 30:03.530] Now, this is counterintuitive, but if you're a little bit broken, like say you censor messages as they go out, some directory servers will say, you weren't providing a real exit server. [30:03.830 --> 30:07.530] Some will say, no, that's real or they're not maintained and they don't care or whatever. [30:07.530 --> 30:15.830] That way, some users will use you as an exit, and some won't based on what directory they use, and you've partitioned users again. [30:16.350 --> 30:19.750] Another fun thing to do is change your keys and options and name all the time. [30:20.450 --> 30:21.670] This also has happened. [30:22.190 --> 30:30.750] And when you do that, you can tell when someone found out about you based on what they call you, what they think your key is, and what they think you can do. [30:32.410 --> 30:38.950] So, these are all sneaky moves that I don't know if they're malicious, but they're happening. [30:39.390 --> 30:45.150] So, and you know, if we're determined to be little brother here, then we might want to get in line with that. [30:46.070 --> 30:48.530] Another fun thing to do is to try to make traffic less confusing. [30:48.730 --> 30:54.370] Like, the more traffic there is on the network, the more cover there is for the traffic that we care about. [30:54.550 --> 30:56.610] So, let's try to get people not to use the network. [30:56.790 --> 30:57.570] Let's smear it. [30:57.690 --> 30:59.730] Let's do defamation campaigns. [31:00.330 --> 31:11.850] Let's use the network to do things that people won't like, so we can start flame wars saying that anonymity is for jerks and trolls and terrorists and bad people. [31:12.070 --> 31:19.570] To try to, you know, make people not want to be anonymous, and then the people who really need to be anonymous don't have that many people to hide them on. [31:22.850 --> 31:28.070] So, for the last section of attacks, I'm going to talk about how can we maybe think outside the box? [31:28.170 --> 31:35.590] What are some ways to attack anonymity networks that don't go against their strong suit, which is resisting traffic analysis, but they go around them? [31:35.590 --> 31:37.610] We can think of some pretty easy ones here. [31:37.710 --> 31:43.250] For instance, you know, break into the box, find a buffer overflow in the software. [31:43.410 --> 31:44.270] It's just software. [31:44.450 --> 31:56.090] I mean, there are some pretty good programmers writing pretty good software in this area, but there have been bugs in the past, and there may well be bugs in the future that people haven't found out about. [31:56.890 --> 31:58.110] And there's some other things. [31:58.250 --> 32:04.990] Like, there's a neat technique called stylometry, also known as literary forensics. [32:05.190 --> 32:10.150] And basically, the idea is you want to identify when two texts are written by the same author. [32:10.710 --> 32:29.410] Now, this is sometimes a pseudoscience used to prove that Elvis really wrote all of Shakespeare's plays, but it's becoming pretty well established on a more statistical basis, taking techniques from AI, taking techniques from machine learning, and so on. [32:29.550 --> 32:35.870] And it's been used to make pretty convincing arguments about disputed Federalist papers, miscellaneous bloggers. [32:36.670 --> 32:40.150] There's this one Oz book that was attributed to L. [32:40.270 --> 32:43.870] Frank Baum, but probably wasn't written by him, but nobody could prove who it was written by. [32:45.130 --> 32:50.270] Some Sherlock Holmes stories that some people were written by Conan Doyle, but weren't, and so on. [32:52.330 --> 33:02.850] And there have been a few papers about this before taking a more scientific approach to it, but it's really taken off as a field in computer science in the last decade or so, and I think we'll be seeing a lot more out about it. [33:02.930 --> 33:04.190] Now, how do you do this? [33:05.110 --> 33:09.110] It turns out, you might think, okay, I might want to look at punctuation, I might want to look at spelling. [33:09.110 --> 33:16.130] Wow, you can't spell the word approximate, or, you know, you use really funny line breaks. [33:16.330 --> 33:29.210] But the ones that have actually gotten the most research and seem to work the most reliably from people who write well are relative frequency of common function words like of, for, but, if, the. [33:29.870 --> 33:35.370] It seems that most of the benefit is looking at the 30 most common, although I've seen people look at 50 most, 100 most. [33:36.470 --> 33:39.850] Restrict only to function words, go for non-function words that are also common. [33:41.070 --> 33:48.310] Then you use techniques like principal component analysis, or you can use different machine learning or statistical techniques. [33:48.670 --> 34:05.110] And if you're interested here, I can tell you some papers afterwards you might want to read, but I don't have time to do all the statistics during this talk, to identify which features for your set are most useful in classifying authors, and then start clustering messages that are by the same author. [34:05.330 --> 34:07.970] Now, have you been posting to USENET? [34:08.590 --> 34:10.250] Have you been posting to USENET regularly? [34:10.790 --> 34:28.610] If so, there's a large corpus of training messages that someone can use to identify your writing style and learn it fairly well, and then possibly identify large-ish, like thousand word plus maybe, chunks of text for whether they're likelier to be by you, [34:28.750 --> 34:30.510] or by somebody else they might suspect. [34:31.030 --> 34:38.770] And there's a paper about that in particular where they tried this out and got fairly good results in linking USENET posters. [34:39.030 --> 34:44.890] I don't know if anyone's tried to use this to out old anonymous posters to the cypherpunks list or not, but it would be neat to know. [34:45.450 --> 34:53.270] Now, something also you realize about is most of the high-profile stylometry you read about isn't automated. [34:53.570 --> 35:05.570] And, you know, probably if you really want to find out who wrote what and you're a government and you're really curious about something in particular, you don't use principle component analysis. [35:05.870 --> 35:07.110] You ask around. [35:07.230 --> 35:07.970] You publish what they wrote. [35:08.030 --> 35:11.210] And you say, hey, who likes to talk about this stuff? [35:15.450 --> 35:16.570] And, yeah. [35:17.950 --> 35:19.970] Thanks for being dumb, you murderous bastard. [35:21.650 --> 35:23.010] Now, legal attacks. [35:23.750 --> 35:36.150] You might try to sue remailers to get them to turn over their keys, to get them to shut down, to say, you were used to send a threatening message to me, and bad stuff happening. [35:36.290 --> 35:40.890] But this is mainly useful to harass the network and try to shut people down on it. [35:41.190 --> 35:51.130] It's less useful against good, well-written and well-run remailers because they don't keep logs so they can't tell you after the fact where the message came from. [35:52.010 --> 36:04.230] And, also, it's kind of counterproductive because after you've sued a bunch of people and won sometimes and lost sometimes, the world now knows what jurisdictions you can't win in and what remailers won't give up to you. [36:04.230 --> 36:15.130] For instance, we now know several countries in which remops successfully defeated legal cases from the Church of Scientology to get them to do one thing or another. [36:15.570 --> 36:22.110] And we know some remops who folded under pressure and we now... [36:22.110 --> 36:28.390] and now, thanks to their lawsuits, the world knows which... [36:28.390 --> 36:30.830] you know, where they can't win their lawsuits. [36:31.470 --> 36:47.830] On the other hand, if you can do a legal attack that comes along with a gag order so people don't know whether or not someone has buckled or withstood you or who you've tried to attack, then that's a different matter for legal attacks and you might get better results. [36:49.690 --> 36:51.630] And then there's social engineering. [36:52.790 --> 36:54.470] This wouldn't be hope without social engineering. [36:54.650 --> 36:57.050] Here are some fun things you can say to anonymous people. [36:58.050 --> 36:59.530] You're a brilliant person. [36:59.530 --> 37:03.270] You've come up with the most wonderful anti-government ideas I've ever heard. [37:03.490 --> 37:04.950] I love your manifesto. [37:05.410 --> 37:06.630] Can we meet sometime? [37:07.310 --> 37:08.370] I bet you're cute. [37:10.310 --> 37:11.730] Here's another fun thing you can say. [37:12.230 --> 37:17.250] These new allegedly high-security reply blocks that MixMinion uses are a real pain. [37:17.470 --> 37:18.850] I can't figure them out. [37:19.270 --> 37:21.610] Could you please send me a cypherpunk reply block? [37:21.710 --> 37:23.610] They say it's less secure, but I don't believe that. [37:23.770 --> 37:25.470] And I just can't figure out this new system. [37:25.470 --> 37:26.770] Come on, please. [37:28.230 --> 37:29.590] Here's another fun thing you can say. [37:30.730 --> 37:31.750] MixMaster is insecure. [37:32.130 --> 37:34.210] I have ironclad proof that I can't tell you. [37:34.650 --> 37:36.650] Insert a three-page nonsensical flame. [37:37.110 --> 37:38.850] Use this webpage on the other hand. [37:39.050 --> 37:40.010] It's completely secure. [37:40.990 --> 37:45.910] You can't fool all the people all of the time, but you know, you'll fool some people some of the time. [37:45.910 --> 37:48.490] And there are people who go around saying this stuff. [37:48.630 --> 37:54.630] I don't know whether they're merely misguided or deliberately trying to do something bad. [37:54.990 --> 37:58.530] And then there are the standard meatspace attacks that I don't need to go into. [37:58.970 --> 38:17.030] I only want to let any nefarious people who may be watching this in the audience or on tape know that if you want to do things to force me to introduce vulnerabilities into code that I write, I prefer to be seduced rather than having my kneecaps broken. [38:19.050 --> 38:19.990] Just a request. [38:20.990 --> 38:22.650] So what can we do about all this stuff? [38:23.390 --> 38:24.570] Well, don't be dumb. [38:24.810 --> 38:26.510] First off, don't use the broken systems. [38:26.630 --> 38:34.850] If a system has a known attack that's better than end-to-end traffic analysis, then don't use it and a lot of the easier attacks go away. [38:35.710 --> 38:38.710] Now, against traffic analysis for high latency networks, what can we do? [38:38.930 --> 38:41.610] Well, if you really care about... [38:41.610 --> 38:43.470] if you think Big Brother is out... [38:43.470 --> 38:51.710] would be interested in what you're doing, but you think they're not interested enough to be already bugging your house, then limit the volume you send. [38:52.090 --> 38:54.810] You know, you send a couple messages, you're probably okay. [38:55.570 --> 38:57.570] Use networks with highly variable latency. [38:58.970 --> 39:02.030] Padding helps some, but it has to be disciplined padding. [39:02.150 --> 39:07.010] It has to be, you know, I send one message every day whether I have a message to send or not. [39:07.210 --> 39:11.890] It can't be, I'm going to be wild and wacky and send messages when the fancy strikes me. [39:12.310 --> 39:15.350] We simulated that, too, and it just doesn't help much. [39:16.590 --> 39:18.170] You can check the paper for more info. [39:18.430 --> 39:19.390] Don't be spiky. [39:19.530 --> 39:21.430] Don't send big spikes of messages. [39:21.650 --> 39:28.310] If you want to send 10 messages and stay anonymous, you're probably safer sending them one a day than sending a big spike all at once. [39:29.190 --> 39:42.410] Now, against traffic analysis for low latency systems, one thing to do is if you think you're against a limited attacker, well, in the long run, if you keep choosing different entries and exits, eventually you'll choose an entry and an exit that that attacker knows. [39:42.810 --> 39:51.130] But if you hold your entry fixed, unless you've already chosen an entry that that attacker knows, then that attacker can't see you enter. [39:51.430 --> 39:54.490] Only works against limited attackers, but it's kind of promising. [39:55.950 --> 40:01.330] Caching on the last node has been proposed, and it might help some, but no one has proven it. [40:01.530 --> 40:10.450] The idea being that, you know, if not all web requests actually results in a request to a website, because the network itself is caching. [40:10.890 --> 40:14.310] That might help, but there's no analysis proving it does. [40:14.730 --> 40:19.370] So another thing you might try to do is try to smooth out protocols a little bit. [40:21.370 --> 40:28.410] This is very hand wavy, but no one's really proven any ideas that would work other than on the back of the envelope level. [40:28.410 --> 40:35.450] The Holy Grail would be an economical, workable, long distance, constant volume padding system. [40:37.470 --> 40:43.090] People keep proposing these, and they don't get built mostly for economic reasons. [40:43.930 --> 40:56.930] If you think you have a way to make one economical, write it up in enough detail so that, you know, you really are committing to one design, and you can actually analyze your design, and, you know, tell me about it. [40:57.030 --> 41:03.210] Because this would really make you the most important person in anonymity research. [41:05.410 --> 41:13.850] Now, against traffic analysis in general, well, lots of these attacks depend on watching both ends. [41:13.850 --> 41:16.110] So try to enter and exit in different places. [41:16.570 --> 41:18.070] Maybe different countries, you know. [41:18.470 --> 41:27.750] Don't enter and exit in the same country, or else, you know, someone who's eavesdropping all of that country's ISPs can probably see you both enter and exit. [41:28.070 --> 41:32.390] Also choose different ASs, that is Internet routing zones. [41:33.350 --> 41:37.230] Try to choose some of your paths that don't all pass through the same backbone ISP. [41:37.850 --> 41:59.350] You know, try to enter and exit different, through different OSs, so that if somebody, you know, is exploiting an unknown OpenBSD vulnerability, but doesn't have any unknown Linux vulnerabilities, or vice versa, then hopefully they won't be able to beat all of the remailers along your path. [41:59.490 --> 42:03.870] And there's a paper about these techniques by a couple of guys that hope should come out sooner. [42:04.290 --> 42:08.290] Another thing you can do that should help some, is run your own remailer. [42:08.450 --> 42:27.310] And this is a good thing anyway to do to help save the world, but if you're running your own remailer in your house, then, well, gosh, it's a lot harder to eavesdrop connections between you and your entry remailer, and a lot harder for attackers to find out what you're doing. [42:27.870 --> 42:29.970] Now, what do you do against attacks on the directory server? [42:30.610 --> 42:38.410] The Mixed Minion design includes, and it's not yet implemented, I'm working real hard on it, support for synchronized confederated directories. [42:38.510 --> 42:48.210] That's basically a bunch of cooperating directories decide that in the interests of the users, they will agree on who's a good server, on which servers there are, and which of them are reliable. [42:48.510 --> 42:50.670] And that way everyone sees the same view of the network. [42:51.950 --> 42:53.470] And you can also try to... [42:53.470 --> 43:09.390] Some people have proposed social network techniques to try to limit multiple identity attacks, like saying, I know him, he's a real guy, he knows her, she's real, and, you know, and hopefully the people within a few levels of you are all gonna be real people, [43:09.590 --> 43:13.690] and not like, you know, one kid with a zombie network in Romania. [43:15.250 --> 43:23.070] But there are some hard issues here, because if everyone has a different view of who's real, the network isn't secure, so it's not quite the same as say, PGP web of trust. [43:23.950 --> 43:27.810] Now against legal attacks, I am not a lawyer, this is not legal advice. [43:29.670 --> 43:30.870] Jurisdictional diversity helps. [43:31.210 --> 43:39.770] You know, the, you know, worst comes to worst, say, remailers become illegal in the U.S., and they'll have to turn over their keys or go to jail. [43:40.150 --> 43:42.210] You know, well, there's still Holland. [43:42.210 --> 43:44.770] Right now there's some jurisdictional diversity in the network. [43:45.110 --> 43:51.810] About a third of current mixed master remailers are in the U.S., about a third are in Germany, and the other third are scattered throughout the world. [43:52.510 --> 43:56.090] Maybe make your path choice jurisdictionally aware, you know, don't enter or exit in the same jurisdiction. [43:56.650 --> 44:00.310] And, well, they can only make you turn over what you've got. [44:00.790 --> 44:05.070] So, except in England, Britain, which has some screwed up laws there. [44:05.290 --> 44:08.250] But, they can't make you in general turn over what you don't have. [44:08.410 --> 44:10.450] So, do not keep logs yourself. [44:11.710 --> 44:13.850] And, don't use servers that keep logs. [44:13.970 --> 44:21.750] This should kind of be a duh thing, but there are some servers out there that probably say, I keep logs because it's smart, and I'm better because of that. [44:22.550 --> 44:25.790] Now, against stylometry, could you try to deliberately change your writing style? [44:26.550 --> 44:34.030] No one's done any experiments here, but the stuff that people are looking at in these techniques, those common function words, are not really things you constantly choose. [44:34.390 --> 44:39.850] So, you know, deliberately misspelling things, or trying to type in a phony French accent, may not help you. [44:44.360 --> 44:47.460] Let's do some research later on, about whether alcohol helps. [44:49.560 --> 45:00.860] Something else people have proposed, is to try to run stylometry yourself, against your own writing, until, and change stuff around randomly, until you don't look like yourself anymore, and then send it off. [45:02.160 --> 45:03.920] It's so crazy, it just might work. [45:04.660 --> 45:07.860] But, nobody's tried it, nobody's researched it, don't count on it. [45:11.160 --> 45:15.060] No one has tried, whether or not that works, against principle component analysis techniques. [45:15.400 --> 45:16.560] That would be a fun research paper. [45:16.680 --> 45:17.900] Talk to me if you'd like to co-write it. [45:18.680 --> 45:29.460] Proving that you could beat stylometry, as it's known today, would really, get stylometry researchers interested in this stuff, and, would drag a whole bunch of other people into remailers, and it would be great fun. [45:30.100 --> 45:30.900] Against social attacks. [45:31.080 --> 45:32.760] Well, number one, educate people. [45:32.920 --> 45:37.020] You can't make everyone smart, but you can make people not fall for standard tricks. [45:37.160 --> 45:42.760] You know, just like you can tell everyone that, the penis pump you hear about on the Internet, is not really going to work. [45:43.000 --> 45:48.040] The gentleman in Nigeria, does not in fact, have a hundred million dollars, that he needs your help laundering. [45:48.460 --> 45:49.340] You know, education may help. [45:49.780 --> 45:54.560] Another thing is to build clients, so you know, it's harder for users to shoot themselves in the foot. [45:54.660 --> 45:59.820] That is, there shouldn't be any option switches, where one of the options means, don't be anonymous. [46:00.820 --> 46:02.420] Unless it's labeled as such. [46:03.380 --> 46:12.300] And, you know, also minimize opportunity for users to make decisions that don't do them any good, but make them look less like each other. [46:13.080 --> 46:14.720] So, I'm going to take questions now. [46:15.020 --> 46:23.320] If you're interested in reading on the research side of this, there's a website that tries to collect anonymity papers, going back to CHOM through the present. [46:23.860 --> 46:30.740] And, full disclosure, I don't maintain the list, but I maintain the software that maintains the list. [46:31.140 --> 46:32.540] So, yeah. [46:32.900 --> 46:33.400] Questions? [46:34.640 --> 46:35.140] Jokes? [46:40.740 --> 46:42.020] Wait for the mic or just shut it out. [46:46.420 --> 46:48.940] What's the special service that was being offered on exit? [46:49.500 --> 46:52.460] Well, let's see. [46:52.620 --> 46:53.500] There have been several. [46:53.680 --> 46:54.480] What's a... [46:54.480 --> 46:55.300] Is Len here? [46:56.740 --> 46:58.740] Ah, Len, Len for a smoke or something. [46:59.040 --> 46:59.180] Okay. [46:59.520 --> 47:09.340] One, one fun one is, that, that almost no one offers is, being able to set the from address as you post to USENET to whatever you want. [47:09.340 --> 47:14.300] which, has its uses, but, comparatively few people offer it. [47:14.920 --> 47:18.400] So, all the traffic that wants to set their from address on USENET filters right to them. [47:19.960 --> 47:28.060] another more wacky one, um, was, someone was going to, I, I don't, I don't even see how this works. [47:28.120 --> 47:33.820] This was more to drive most people away, so that you could just, so in theory, if this person were evil, you could distinguish. [47:34.080 --> 47:40.280] He wrote software where he picked some words as randomly offensive, and censored them out of any message that was going to USENET. [47:40.660 --> 47:44.000] And, and he picked really weird words, like some were just people's names he didn't like. [47:44.500 --> 47:47.440] So, and, this was pretty weird. [47:47.920 --> 47:50.760] And I, I, I can list more examples after, after the talk. [47:51.960 --> 47:52.400] Yo. [48:12.140 --> 48:13.520] Yeah, I, I, I, I get your question. [48:13.620 --> 48:31.040] So the question is, um, um, great, this is, you know, we all like to think about how Big Brother can, can watch you better, but, we want to be Big Brother against the spammers, and figure out where they're coming from, so, we can go, do things up to the full extent of the law, [48:31.160 --> 48:34.540] but no more, because, we're good people, right? [48:34.660 --> 48:44.360] But, first off, the thing to remember is, spammers aren't really using anonymity networks, because, they don't need, really strong anonymity. [48:44.440 --> 48:47.400] In fact, they don't want the kind of full anonymity that's going to offer. [48:47.460 --> 48:51.340] Ultimately, remember, they're trying to get rich, they need a way to receive payment. [48:51.340 --> 48:53.580] So, number one, attack them through their payment service. [48:54.320 --> 49:04.840] Second, they're, a lot of spam you get today is either through people with cooperative ISPs, or through people with large zombie networks, or people with large lists of open relays. [49:05.920 --> 49:10.220] So, those are, in effect, one-hop, or no-hop proxies. [49:10.780 --> 49:28.040] So, if you were in a part of the world, where many machines got compromised and used as zombie networks, if you had a good way to eavesdrop on a few of those machines, or you were to put out a honey pot, or you were to go, this is purely theoretical, of course, [49:28.840 --> 49:32.460] some people are comfortable endorsing system penetration of machines you don't own on camera. [49:34.160 --> 49:34.480] Yeah. [49:35.400 --> 49:41.560] But, purely theoretically, if you were to go break some of these zombie machines, you'd find out in one-hop, you know, where was this traffic coming from? [49:41.740 --> 49:44.600] And, you'd be on your way to find out where the spammers were coming from. [49:48.690 --> 49:54.950] One of the interesting things about this as a problem is that, is that, you get more secure as more people are using it. [49:55.070 --> 49:56.870] So, there's a very big social component to it. [49:56.950 --> 50:03.870] I'm wondering if, you have any sort of numbers roughly or specifically about, how many people are using them? [50:03.970 --> 50:07.630] How many people you might expect, say in five or ten years, could be using these systems? [50:08.190 --> 50:08.750] Yes, yes. [50:08.850 --> 50:11.090] And, how you would get more people to use them? [50:11.550 --> 50:12.910] How you get more people to use them? [50:13.190 --> 50:17.940] Well, if I could do whatever I liked, the way I would get more people to use them... [50:17.940 --> 50:27.580] Okay, so first off, one important thing about the question, that I want to elaborate, is not only, is that, it is important that more people use these things to get anonymity. [50:28.080 --> 50:30.720] And, you know, this is generally called network effects in technology. [50:30.880 --> 50:34.160] That is, your telephone becomes more valuable the more people you can call with it. [50:35.880 --> 50:38.340] And, anonymity depends on network effects. [50:38.480 --> 50:47.800] Like, it's not like PGP, where, if you and I are the only two people in the world with PGP, then, we are, you know, we can still encrypt, and you can't tell what we're saying. [50:47.920 --> 50:52.700] But, if you and I are the only two people with Mix Minion, well, anything sent with Mix Minion came from you or me. [50:53.000 --> 50:55.180] And, even though you can't tell which, you can still shoot us both. [50:55.600 --> 50:57.860] But, so how do you get more users to hide better? [50:58.140 --> 51:00.800] First off, you don't, you need users that hide you. [51:01.080 --> 51:05.100] But, it's okay if these users aren't terribly, clever about staying anonymous themselves. [51:05.260 --> 51:06.540] Like, it's okay if like, they screw up. [51:06.620 --> 51:08.480] It's okay if they're running insecure operating systems. [51:09.000 --> 51:14.760] They can still hide you, if you write the software so that, they act the same as other people from the network's point of view. [51:15.220 --> 51:19.480] So, number one, better GUI clients, more of them. [51:19.680 --> 51:25.000] In fact, better yet, make good plugins for the, mail programs people already use. [51:25.600 --> 51:33.300] Like, you know, if this came bundled with Microsoft Office, and, you'd have so many people sending cover traffic purely by accident. [51:34.560 --> 51:37.960] More people than, have ever used the network up till now. [51:38.560 --> 51:43.900] So, yeah, better adoption, better usability, you know, an intermediate step. [51:44.520 --> 51:50.120] Like, you know, get, get more, mail programs that people use today to support it. [51:50.300 --> 51:51.920] Get more education about why it's easy. [51:52.520 --> 51:53.280] Make it cooler. [51:53.500 --> 51:54.380] You know, get more kids to use it. [51:54.440 --> 51:58.680] Like, of the early PGP adopters, a lot of them were people with genuine need for PGP. [51:58.820 --> 52:03.260] And a lot of them were people who, just like playing secret agent, and playing with cool codes. [52:03.260 --> 52:07.780] And, you know, and they, they didn't help the other PGP people get more encryption. [52:08.280 --> 52:12.060] But, if they're using anonymity networks, they help the people who really need it stay more anonymous. [52:13.540 --> 52:14.680] Um, there's... [52:15.060 --> 52:17.840] Um, how many, um, nodes are on a typical mixed network? [52:18.200 --> 52:23.440] And, um, how many hops does it usually take for a message to reach its destination? [52:24.180 --> 52:29.020] Um, well, of a typical mixed network, what you gotta understand is right now there's two. [52:29.720 --> 52:32.280] So, it, it, so it's hard to generalize from examples of two. [52:32.820 --> 52:37.600] Um, there's about fix, there's about 50 on, Mix Master, Cypherpunk. [52:37.820 --> 52:40.180] Most servers run both protocols that run those. [52:40.400 --> 52:42.760] There's about 39 right now running Mix Minion. [52:42.760 --> 52:46.440] Um, and, those numbers need to go up. [52:47.260 --> 52:53.640] Now, as for how many hops people usually choose, that's, that's selected by the people who send messages. [52:54.100 --> 52:59.840] And, their key factors seem to be these days that, on Mix Master, Cypherpunk, there's some stuff that's unreliable. [53:00.060 --> 53:06.480] So, you know, if, so you don't want to send it through too many servers, because too many servers, too many places that might drop your message by mistake. [53:06.720 --> 53:09.720] So, I think people choose, usually choose around four or five there. [53:10.480 --> 53:13.340] Mix Minion is getting reliable delivery, to pass longer than that. [53:13.440 --> 53:15.380] So, I think people, might start choosing longer. [53:15.580 --> 53:19.600] In low latency networks, for various technical reasons, it doesn't make sense to choose more than three. [53:20.260 --> 53:24.000] Because, the end to end attacks work so well, the more servers don't, talk to you. [53:24.060 --> 53:27.940] And if you find that an interesting point, I can, bore you to tears about it afterwards. [53:29.340 --> 53:37.000] Um, I was, I was wondering, you talked earlier about the little brother attacks, you know, we're using long-term statistical analysis. [53:37.360 --> 53:37.440] Yeah. [53:38.020 --> 53:41.920] How practical is it, that those actually work? [53:42.100 --> 53:43.620] How practical is it, that those actually... [53:43.620 --> 53:47.720] Because it's, it sounded like, whereas theoretically, it's a threat model. [53:48.480 --> 53:48.640] Okay. [53:48.700 --> 53:49.720] It's not enough for threat. [53:50.120 --> 54:06.420] If you can see, about 20% of the traffic, as it enters or exits, under the simulations, that I did, which, you know, again, remember all, all simulations are, somewhere between wild guesses, and, asking your psychic friend. [54:07.080 --> 54:12.060] But, um, so if you can see about 20%, then, then you might win. [54:12.180 --> 54:21.240] Now, I bet you there's people, at this conference, who can, you know, right now there's 50 servers on, the MixMaster network. [54:21.800 --> 54:29.860] If you could get, you know, another, you know, if you could get 20 or 30 of them, you'd win. [54:30.320 --> 54:43.360] If you could get, like, a dozen servers up, that people didn't link together as you, and, you got them to be particularly popular, like, you know, twice as popular, you could win. [54:43.500 --> 54:45.200] So I, I think it's something we ought to be worried about. [54:45.540 --> 54:55.800] But then, people in my field tend to be especially paranoid, and, in fact, there's economic incentive for us to be more paranoid than each other, because people trust us the more paranoid we seem to be. [54:56.420 --> 55:00.300] So, I'm likely to over exaggerate the effectiveness of any attack. [55:03.260 --> 55:03.420] yeah. [55:04.080 --> 55:05.580] Um, yes? [55:15.600 --> 55:15.960] Okay, [55:20.680 --> 55:24.920] so the question is, whose responsibility is it, the users or, or the networks? [55:25.060 --> 55:31.040] Well, if you're running the network, or you're, you're building a network, presumably you're doing it because you want people to be anonymous. [55:31.500 --> 55:35.660] So, you should put as much defense into the network as you possibly can. [55:36.640 --> 55:41.500] On the other hand, if you want to be anonymous, you, you, should put in a reasonable effort yourself. [55:41.700 --> 55:55.980] But, you know, in the end, um, you know, these systems should be anonymous enough that my grandmother can use them to whistleblow against the AARP without having AARP death squads come against her. [55:57.240 --> 56:01.360] Replace AARP with a more realistic organization that my, my grandmother might not like. [56:01.560 --> 56:04.440] And, nothing against grandmothers, mine is not computer literate. [56:04.760 --> 56:08.900] So, we can't ask too much of the user in general. [56:09.340 --> 56:17.920] It's great when they can do more, but, um, I'm not a, I'm, I'm better at building software than I am at education. [56:18.080 --> 56:21.980] I try to do education and things like this, but, ultimately, I think this offer should do as much as it can. [56:22.420 --> 56:25.420] And, is that the, I'm almost done signal, or is that the, I'm done signal? [56:27.160 --> 56:28.260] I got like two minutes left. [56:28.340 --> 56:29.200] Let's do quick questions. [56:29.280 --> 56:30.600] If you've got long questions, ask them after. [56:31.240 --> 56:34.460] How much bandwidth do I need to effectively run a remailer at home? [56:35.020 --> 56:38.500] Um, right now, you can run a mixed menu node on a cable modem. [56:41.320 --> 56:42.660] How about DSL speeds? [56:43.400 --> 56:46.340] DSL speeds, um, I don't know, talk to me after. [56:46.440 --> 56:47.200] Let's try and find out. [56:47.700 --> 56:51.180] Worst case, we, we, doesn't work out and you turn it off after a week. [56:52.440 --> 56:55.860] Um, there's, all, all of the good ones right now support bandwidth choking. [56:56.060 --> 56:58.180] So, you can use as, as much or as little bandwidth as you want. [56:58.940 --> 57:01.140] And, Tor, the other router, also supports that. [57:02.320 --> 57:03.200] Uh, anybody else? [57:03.940 --> 57:04.560] Uh, yeah. [57:04.840 --> 57:13.800] Uh, can you talk some more about, um, low latency, um, anonymity networks? [57:14.280 --> 57:18.200] Specifically, anything available for, uh, surfing, uh, the web anonymously? [57:18.400 --> 57:19.500] Surfing the web anonymously. [57:19.640 --> 57:24.360] Full disclosure, I'm a developer on the system, but we're developing something called Tor right now. [57:24.640 --> 57:36.120] It's not good enough to keep the NSA from finding out that you're Googling for, um, you know, for, I don't know, Metallica MP3s. [57:36.360 --> 57:48.300] But, if you wanna keep people at HOPE from, from sniffing your password as you browse, or, from easily figuring out where you're going, then it's probably good enough for you. [57:48.380 --> 57:53.020] And if you're interested in, in stopping, porn sites from getting your IP, it's also probably good enough for you. [57:53.660 --> 58:00.320] Um, also for those applications, a lot of commercial stuff like, anonymizer.com may or may not be good enough for you. [58:00.320 --> 58:02.560] I have no affiliation with anonymizer.com. [58:02.700 --> 58:03.980] And, I'm out of time. [58:04.260 --> 58:06.100] And, if you wanna talk, let's talk later. [58:06.400 --> 58:07.000] Thanks everybody.