HomeSecurityGoogle may remove anonymity from Tor connections!

Google may remove anonymity from Tor connections!

A team of scientists has found a new attack method that in the hands of some adversaries can be used to deanonymize Tor traffic by monitoring traffic going to a Tor relay and HTTP and DNS traffic coming out of a Tor exit node.

Called DefecTor , this new attack is an improved version of what security and privacy experts call a “Tor correlation attack.

Google may remove anonymity from Tor connections!

Tor correlation attacks have been studied and explained in detail in the past. In short, such attacks mean that a global adversary in a position to monitor large chunks of Internet is able to see when a user initiates a Tor connection and, using various clues, correlate their incoming connection with an outgoing stream of packets. The adversary can guess with varying degrees of accuracy the website that the user is accessing via Tor.

A team of researchers from Swedish and American universities say that initial research into these types of deanonymization attempts was done using correlation attacks and focused only on encrypted traffic entering the Tor network and HTTP traffic leaving an exit node.

They say the initial research has completely ignored a second set of outbound traffic, involving DNS queries. They say DNS queries can prove very useful in improving the guesswork that comes with Tor correlation attacks.

This attack is possible because the Tor Browser, which allows Tor users to access websites through the Tor network, concatenates HTTP and DNS traffic, encrypts it, passes it through the Tor network, and then resolves the DNS query at the exit node level, sending the HTTP traffic to its destination.

“We find that there are adversaries that can launch DefecTor attacks,” the researchers write in their paper. “For example, Google observes nearly 40% of all DNS queries coming out of the Tor network.”

While Google has shown no interest in de-anonymizing or sabotaging the Tor network, the research shows that it could do so if it wanted to.

The Tor threat model involves global adversaries representing ASs (Autonomous Systems – Autonomous Systems – or ISPs) run by repressive regimes. These third-party entities can gain more than enough information about known dissidents and their activities by launching DefecTor attacks.

“Given this more powerful fingerprinting method, we have shown that the threat of DefecTor attacks against the Tor network is clear and present,” the researchers say. “Tor relay operators should take steps to ensure that the network maintains more diversity in how exit relays manage DNS domains.”

Technical details about the DefecTor attack are available on the website . The actual research paper, called "The Effect of DNS on Tor's Anonymity", can be downloaded here or here and includes some recommendations for mitigating DefecTor correlation attacks.

deanonymization-scheme

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS