pwshub.com

German investigators successfully tracked suspects inside the Tor network

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

Tor Uncovered: Tor is an overlay network designed to provide a fully anonymous way to browse the web and exchange messages or data over the internet. The "darknet" is supposed to be free from eavesdropping and surveillance, but resourceful agencies can still breach its many onion-like layers to go and get a suspect's true identity.

German news outlet Tagesschau reports that local law enforcement agencies have successfully targeted, tracked, and arrested four suspects in a single investigation. The outlaws used Tor to hide their identities and activities in managing a ransomware operation and hosting child sex abuse material (CSAM) on their servers.

Investigators identified the suspects using a "timing analysis" attack. The officers directly monitored many Tor nodes over time, looking for a specific connection between the servers hidden within the darknet and local internet connections. The story confirms that law enforcement agencies are actively monitoring web servers hidden in Tor.

Authorities tracked four people in their investigation, eventually taking over the Tor address belonging to a ransomware group. Police redirected its traffic to a new page to prevent users from sharing previously stolen encrypted files. Then, the investigators used timing analysis techniques to uncover the identity of "Andres G," an individual operating a .onion service known as "Boystown" that hosted CSAM.

Successfully uncovering who's behind a darknet service is no easy feat, and authorities haven't revealed significant details about their timing analysis attack. Developers from the Tor Project claim a suspect tracked by German authorities was using an old version of the Tor-based, decentralized instant messaging application Ricochet.

The Tor team said the Ricochet user was "fully de-anonymized" through a guard discovery attack. The outdated Ricochet release didn't protect against timing analysis. Developers addressed this shortcoming in a new application fork (Ricochet-Refresh). This version is fully maintained and offers better privacy for freely chatting (and exchanging files) within the darknet.

The developers claim that users can only access Onion services from within the Tor network, so any discussion about monitoring exit nodes is irrelevant. The network is healthier than ever, with over 2,000 new exit nodes coming online over the past few years. An "exit node" is the last hidden Tor node a user connects to before going on the clearnet, acting as the originator of the communication from an ISP's point of view.

"Like many of you, we are still left with more questions than answers," the Tor programmer said. "But one thing is clear: Tor users can continue to use Tor Browser to access the web securely and anonymously."

Source: techspot.com

Related stories
1 week ago - Outdated software blamed for cracks in the armor The Tor project has insisted its privacy-preserving powers remain potent, countering German reports that user anonymity on its network can be and has been compromised by police.…
1 month ago - sick burns — It's very rare, but lithium-ion batteries in electric vehicles can catch fire. Enlarge /...
1 month ago - BUM BUM BUM — "No deeper meaning," says German navy. The German navy going "full Empire" down the Thames. The...
1 week ago - Jürgen Müller agreed to step down from his role at the end of September German prosecutors have confirmed to The Register that SAP's outgoing CTO is under investigation following allegations of sexual harassment.…
1 month ago - This is despite the German vendor's preferred upgrade path There is an even split for large enterprise customers of SAP ERP systems between on-prem and the public cloud – the German vendor's preferred upgrade path – according to NTT Data,...
Other stories
1 hour ago - Both Apple phones come with upgrades like larger batteries and new cameras but choosing between the iPhone 16 and 16 Pro is still a difficult choice. We're here to help.
1 hour ago - Here's today's NYT Mini Crossword answer. These answers will help you solve New York Times' popular crossword game, Mini Crossword, every day!
3 hours ago - Here's today's Strands answers and hints. These clues will help you solve The New York Times' popular puzzle game, Strands, every day.
3 hours ago - Here's today's Connections answer and hints for groups. These clues will help you solve New York Times' popular puzzle game, Connections, every day!
3 hours ago - Here's today's Wordle answer, plus a look at spoiler-free hints and past solutions. These clues will help you solve New York Times' popular puzzle game, Wordle, every day!