Andrew Lewman [email protected] August 4, 2010 · Andrew Lewman [email protected] ICCS Tor...

21
ICCS Tor Overview Andrew Lewman [email protected] August 4, 2010 Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 1 / 15

Transcript of Andrew Lewman [email protected] August 4, 2010 · Andrew Lewman [email protected] ICCS Tor...

Page 1: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

ICCS Tor Overview

Andrew [email protected]

August 4, 2010

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 1 / 15

Page 2: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

The Tor Project, Inc.

501(c)(3) non-profit organization dedicated to the research anddevelopment of technologies for online anonymity and privacy

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 2 / 15

Page 3: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

What is Tor?

online anonymity software and network

open source, freely available (3-clause BSD license)

active research environment:Rice, UMN, NSF, NRL, Drexel, Waterloo, Cambridge UK, BambergGermany, Boston U, Harvard, MIT, RPI, GaTech

increasingly diverse toolset:Tor, Torbutton, Tor Browser Bundle, TorVM, Incognito LiveCD, TorWeather, Tor auto-responder, Secure Updater, Orbot, TorFox, Torora,Portable Tor, Tor Check, Arm, Nymble, Tor Control, Tor Wall

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 3 / 15

Page 4: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

What is Tor?

online anonymity software and network

open source, freely available (3-clause BSD license)

active research environment:Rice, UMN, NSF, NRL, Drexel, Waterloo, Cambridge UK, BambergGermany, Boston U, Harvard, MIT, RPI, GaTech

increasingly diverse toolset:Tor, Torbutton, Tor Browser Bundle, TorVM, Incognito LiveCD, TorWeather, Tor auto-responder, Secure Updater, Orbot, TorFox, Torora,Portable Tor, Tor Check, Arm, Nymble, Tor Control, Tor Wall

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 3 / 15

Page 5: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

What is Tor?

online anonymity software and network

open source, freely available (3-clause BSD license)

active research environment:Rice, UMN, NSF, NRL, Drexel, Waterloo, Cambridge UK, BambergGermany, Boston U, Harvard, MIT, RPI, GaTech

increasingly diverse toolset:Tor, Torbutton, Tor Browser Bundle, TorVM, Incognito LiveCD, TorWeather, Tor auto-responder, Secure Updater, Orbot, TorFox, Torora,Portable Tor, Tor Check, Arm, Nymble, Tor Control, Tor Wall

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 3 / 15

Page 6: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

What is Tor?

online anonymity software and network

open source, freely available (3-clause BSD license)

active research environment:Rice, UMN, NSF, NRL, Drexel, Waterloo, Cambridge UK, BambergGermany, Boston U, Harvard, MIT, RPI, GaTech

increasingly diverse toolset:Tor, Torbutton, Tor Browser Bundle, TorVM, Incognito LiveCD, TorWeather, Tor auto-responder, Secure Updater, Orbot, TorFox, Torora,Portable Tor, Tor Check, Arm, Nymble, Tor Control, Tor Wall

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 3 / 15

Page 7: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

estimated 500,000 daily users

]

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 4 / 15

Page 8: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Twitter in Iran: Good.

From http://www.time.com/time/world/article/0,8599,1905125,00.html

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 5 / 15

Page 9: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Twitter in USA: Bad.

from http://gothamist.com/2009/10/05/fbi raids queens home in g20 protes.php

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 6 / 15

Page 10: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Who uses Tor?

Normal people

LawEnforcement

Human RightsActivists

Business Execs

Militaries

Abuse Victims

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 7 / 15

Page 11: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Tor hides communication patterns by relaying data throughvolunteer servers

Tor Node

Tor Node

Tor Node

Tor Node

Tor NodeTor Node

Tor Node

Tor Node

Tor Network

Web server

Tor user

Encrypted tunnel

Unencrypted TCP

Tor Node

Tor Node

Tor Node

Exit node

Entry nodeMiddle node

Diagram: Robert Watson

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 8 / 15

Page 12: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Tor

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 9 / 15

Page 13: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Metrics

Measuring metrics anonymously

NSF grant to find out

Metrics portal:https://www.torproject.org/projects/metrics

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 10 / 15

Page 14: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Tor hidden services allow privacy enhanced hosting ofservices

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 11 / 15

Page 15: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Operating Systems leak info like a sieve

Applications, networkstacks, plugins, oh my....

some call this ”sharing”

Did you know MicrosoftWord and OpenOfficeWriter are browsers?

http:

//www.decloak.net/ isa fine test

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 12 / 15

Page 16: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Operating Systems leak info like a sieve

Applications, networkstacks, plugins, oh my....some call this ”sharing”

Did you know MicrosoftWord and OpenOfficeWriter are browsers?

http:

//www.decloak.net/ isa fine test

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 12 / 15

Page 17: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Operating Systems leak info like a sieve

Applications, networkstacks, plugins, oh my....some call this ”sharing”

Did you know MicrosoftWord and OpenOfficeWriter are browsers?

http:

//www.decloak.net/ isa fine test

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 12 / 15

Page 18: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Operating Systems leak info like a sieve

Applications, networkstacks, plugins, oh my....some call this ”sharing”

Did you know MicrosoftWord and OpenOfficeWriter are browsers?

http:

//www.decloak.net/ isa fine test

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 12 / 15

Page 19: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Mobile Operating Systems

Entirely new set of challenges for something designed to know whereyou are

Orbot: Tor on Android.http://openideals.com/2009/10/22/orbot-proxy/

iphone, maemo, symbian, etc

Tor on Windows CE, http://www.gsmk.de as an example.

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 13 / 15

Page 20: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Next steps

Visit https://www.torproject.org/ for more information, links, andideas.

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 14 / 15

Page 21: Andrew Lewman andrew@torproject.org August 4, 2010 · Andrew Lewman andrew@torproject.org ICCS Tor Overview August 4, 2010 12 / 15 Mobile Operating Systems Entirely new set of challenges

Credits & Thanks

who uses tor?http://www.flickr.com/photos/mattw/2336507468/siz, MattWestervelt, CC-BY-SA.

danger!, http://flickr.com/photos/hmvh/58185411/sizes/o/,hmvh, CC-BY-SA.

500k, http://www.flickr.com/photos/lukaskracic/334850378/sizes/l/,Luka Skracic, used with permission.

Andrew Lewman [email protected] () ICCS Tor Overview August 4, 2010 15 / 15