Scientists have unveiled a high-speed network that users can go online anonymously and that mass surveillance will be available. The network is called HORNET ( pdf ), which stands for High Speed Onion Routing at the Network Layer. Because the running at the network layer, there are, according to the scientists, all kinds of applications are possible. To protect the privacy of users is made use of symmetric cryptography. It does this in a way that HORNET nodes, the computers where the network consists of, can process at a rate of 93GB / s traffic.
At present, there are already several solutions for Internet users to protect their anonymity on the Web, such as the Tor network, which has over 2 million users a day. The speed of the Tor network can not be perfect. According to scientists, is well suited for Tor anonymous communication, but its scalability and network performance problems. The more people Tor to use, the more nodes are to be added in order to maintain the speed of the network.
The scientists therefore looked for a solution that did scalable. In doing so HORNET agreements with Tor (The Onion Router).They both use onion routing, where traffic runs on multiple nodes to protect the identity of users. In the case of HORNET have to store the nodes in the middle of the network, less information about the connection, so that they can exchange traffic faster in theory. For the time being, however, the only paper in which the scientists describe the new anonymity network.
An American starter has developed a solution that can find stolen corporate data on the Dark Web. The Dark Web is the name for websites and services through anonymity networks like Tor and I2P are accessible. It regularly happens that compromised or stolen corporate data at market places and forums for cyber criminals appear on the Tor network.
Terbium Labs, founded by two researchers from the Johns Hopkins University, proposes that these data are very fast on both the accessible Internet as the Dark Web can find, so the compromised company can be alerted in question. In this way, a leak can be found within seconds or minutes rather than months, as claimed by the investigators.
To do this, first a "digital fingerprint" made the important business files and data. Then there is the Dark Web and Internet for these prints. According to him, would have the company in this way in just 30.000 seconds stolen credit cards and 6,000 compromised email addresses find you.
After years of having participated in a Google initiative where students were paid to the development of open source software, have the Tor Project, known from the Tor anonymizing network, and the American civil rights movement EFF now decided to launch an initiative in which students from all over the world are paid for the further development of the Tor privacy tools.
From 2007 to the Tor Project participated last year in the Google Summer of Code . Google paid for several months, students who wanted to contribute to open source software projects. So the students could gain practical experience, while the open source projects could benefit from the extra programming power. The size of the Google initiative has been adjusted, allowing Gate and the EFF not participate this year.
It was then decided to start his own initiative, called Tor Summer of Privacy . Students from all over the world, also from the Netherlands can apply for one of the available spots. For every student is a grant of $ 5,000 available. The idea is that students, under the supervision of a mentor, existing Tor privacy tools or develop their own ideas to improve the software.Registration is possible until April 17th. On 25 May, the Summer of Privacy start to finish then on 1 September.
Every day, hundreds of thousands of people using the Tor network to protect their online identity and privacy. Yet there is still much confusion about how the Tor network and the importance of online anonymity. Therefore, the Tor Project has several informative flyers ( pdf ) made for police and citizens explaining the operation of the Tor network and the importance of anonymous internet.
Through the Tor network users can hide their IP address such as "hidden" visit websites that are only accessible through the Tor network. In recent months, several of these sites by the authorities off the air. The most Tor users are ordinary citizens who want to keep control over their privacy, so the Tor Project has announced in the flyer for police and investigative services.
The network is also used by journalists, activists and people in countries with totalitarian regimes or internet censorship. It is also handy for police and undercover operations. So use investigative services also the Tor network for their research."Because of the identity and location of hiding researchers Tor can be a valuable tool for successful online undercover operations," so let the flyer.
There is created a flyer for citizens showing the importance of anonymous Internet and online freedom is explained. According to the Tor Project is anonymity under fire as never before, allowing the ability to share free information on the Internet is undermined. "Countries monitors on each other and their citizens, block websites, watching the contents of traffic and reduce important world news." Organizations that deal with internet freedom can also order the flyers.
The Tor network not only provides users the ability to hide their IP address, even turning and visiting hidden sites and services is possible. And it is this feature of Tor developers who now want to bring wider attention.
Through the hidden sites and services, on the Tor network if hidden services identified, people can share information anonymously and safely. So bloggers, activists, journalists and organizations under other totalitarian regimes use it.Newspapers like the Washington Post and Human Rights organizations like Amnesty International use them again to receive leaked information. "The potential of hidden services is huge and much still needs to be explored there," said Tor developers.They want to make the technology therefore accessible to a larger audience.
The Tor developers look for hidden services namely an important role when it comes to the future of secure communication.To realize this, the uses of hidden services will have to be increased, there must be mobile support for mobile applications and will eventually also the number of people that have to grow hidden services used. At this time, approximately 4% of the Tor-traffic originating from hidden services. To determine where the emphasis will be launched a crowd funding campaign on.
While looking for the Tor Project ideas for hidden services to crowd funded. Meanwhile, there are three ideas conceived, including an information for administrators of hidden services and hidden services where anonymity is paramount but speed.In this case, the hidden service will not care about their own anonymity, but that visitors anonymously and securely connect through the Tor network. It involves, for example initiatives of Facebook and Reddit to also be active in the Tor network.Other ideas via this page to reach out to.
Almost 97% of the traffic that will generate Tor users to 'normal' websites over the internet anyone can visit, according to research from the Tor Project. Tor is a software that allows users not only to hide their IP address, but also makes it possible to visit Tor sites that are only accessible through the Tor network.These are the so-called "hidden services".
The Tor Project wanted to know how many of the Tor traffic goes to these hidden services. For this was the collaboration of several volunteers to share data from their Tor server. This enabled the Tor Project a small proportion (2% - 5%) of activities in hidden view services. Establish on the basis of current calculations, the researchers found that each day 30,000 hidden services are active. These websites generate every day 400 to 600Mbit per second of traffic, which amounts to about 5 terabytes of data per day.
Furthermore, it appears that is the Tor traffic from Tor users to these hidden services 3.4% of the total Tor traffic. This means that 96.6% of the Tor traffic to "normal" websites is that anyone can access through a browser. Tor came last year regularly negative in the news because Tor would mainly be used for visiting criminal Tor sites. Now it appears that the most traffic to websites is that outside Gate to visit.
The researchers suggest that it is still to preliminary results in that regard are established on the basis of a limited data set, and with a grain would have to be taken. The study was conducted over a period of several months, but the researchers plan to expand further in the future. They want to know how many people visit daily Tor sites and how often people try to visit a hidden service that no longer exists.
"Unfortunately, some of these questions with the current reporting infrastructure are not easy to answer, mostly because the collection in this way can reveal hidden information about specific services, as well as the results of the current system include excess dates." The researchers are also looking at aggregation protocols for statistics that they can use in place of the current system, so they still safe to collect all kinds of statistics.
There are currently going around emails posing as security for Google Chrome, but in reality spread ransomware. The messages would come from the "Google Security Center" and have the subject line "Google Chrome Security". According to the email, the Chrome version of the receiver is potentially vulnerable and outdated.
Instead of an e-mail attachment, the recipient gets instructions to enter a particular search that points to a compromised website and on which the so-called security is offered. The update is in reality a ransomware variant called CTB Locker, which stands for Curve Tor Bitcoin. The ransomware is also known as Citroni.
The malware encrypts all kinds of files on the computer and then prompts the user to pay an amount in bitcoin for decryption, as reported security Malwarebytes. How many people have been kicked in the e-mail is unknown. Users do in the case of Google Chrome namely itself to install updates because the browser on most computers will update automatically.
Researchers have discovered that a Trojan on infected computers used Microsoft Outlook to send infected emails. It is a variant of the Dyre banking Trojan , also known as Dyreza . The malware is specifically designed to steal money from online bank accounts.
The now discovered variant spreads via email attachments posing as faxes or contain a message from an undelivered package and Upatre downloader. This downloader downloads the weather Dyre Trojan on the system, which installs a worm on the computer. The worm uses Microsoft Outlook on the computer to send infected e-mails with Upatre downloader. In addition, the malware does not use the address book of the victim, as it was done by many worms in the past. After the messages are sent, the worm deletes itself again, as reports of anti-virus company Trend Micro.
Researchers have discovered a new variant of a particular ransomware which now specifically aimed at Dutch Internet users. It involves CTB Locker, which stands for Curve Tor Bitcoin, which for the first time in mid-July appeared and encrypts files for ransom.
CTB Locker, called Microsoft Critroni, stands out because of the methodology used. Thus, the ransomware uses the Tor network to communicate with infected computers. Instead of the file to use Tor.exe, as is done by other malware, the maker of CTB Locker has the code of Tor made part of the ransomware code.
Where ransomware also strikes a different path to the encryption used. Most ransomware uses a combination of AES and RSA encryption to encrypt the files of victims. CTB-Locker uses an asymmetric cryptographic protocol known as ECDH (Elliptic Curve Diffie-Hellman). Another new development for the first time at the CoinVault-ransomware was seen is the free decrypt files. Let CoinVault victims one file free decrypt, CTB Locker decrypts free five files.
Bitcoin Address
The ransomware is distributed through hacked WordPress sites. On the websites of malicious code is placed that uses vulnerabilities. However, it is unknown to what vulnerabilities it exactly. In the case, the attack is successful is CTB-Locker placed on the system and will encrypt the ransomware existing files. Security Researcher ' JuK 'of the blog Malware Do not Need Coffee discovered the latest version, which also supports Italian alongside Dutch.
The administrators of the Tor network have removed thousands of fake servers that had been added by the group Lizard Squad. The group claimed earlier this week to sit behind attacks on Xbox Live and the Playstation Network and would now plans have been to attack the Tor network.
In a short time appeared some 3,000 new servers in the Tor network. Thereby Lizard Squad had a considerable share in the network, which came out with the new servers at 10.000 "relays". In theory this is a risk for Tor users, for a party that has a large part of the network owned'd users can unmask. In this case, Tor users were however no danger. The capacity of the new servers was 20 kilobytes per second per server too small.
Tor Network List
The total capacity of the Lizard Squad servers accounted for only 0.27% of the entire Tor network. The servers would become the first three days are not selected as a server for Tor users, let security researcher Nadim Kobeissi opposite The Verge know. Meanwhile, the fake servers are removed, according to the list of Tor servers. On Twitter Kobeissi states that were hosted many of these servers in the Google Cloud. He also suspects that it was thousands of small virtual machines with limited bandwidth.
The FBI has used a component of the popular Metasploit hacking tool to identify Tor users. Metasploit is a tool that penetration testers and security experts test the safety of systems and networks. It is now being developed and managed by security company Rapid7.
Wired reports that the FBI in 2012 set in part of Metasploit to successfully identify different Tor users through Adobe Flash Player. The US investigation department made use of an abandoned Metasploit project called " Decloaking Engine ". It was one in 2006 developed experimental concept where multiple tricks were used to identify users of a service such as Tor anonymity via a specially crafted Web site. In case the Tor user had his installation secure he could not be identified through the website. However, if users made a mistake their real IP address is visible.
Flash Player
One of the tricks was the use of a Flash application. Adobe Flash Player can set up a direct connection to the Internet and thus leak the IP address of the user. A known problem and the Tor Project advises users therefore not to install Flash Player. Finally appeared in 2011, a version of the Tor Browser, the software to access the Tor network, allowing users were better protected and the test site that was set up for the Decloacking Engine almost no users identified more.
However, the FBI used Decloaking Engine as a basis for an operation against child pornography sites on the Tor network. The investigation department had access to several of these sites and then let them run Flash programs in visitors' browsers in order to determine their true IP address. A total of 25 users in the United States were identified and an unknown number elsewhere. According to Wired is to use the first time the FBI spyware-like software to all visitors of a website started in place against certain individuals.
Identification
However, it is unknown whether the FBI standard Decloaking Engine has used or a customized version. HD Moore, the original developer of Metasploit and Decloaking Engine, argues that his release could barely identify Tor users. Only suspects with very old Tor version or who had gone to great lengths to install Flash Player would have been at risk.
In this way, the FBI would only have to suspects with the worst operational security-oriented instead of the worst offenders. A few months later, the FBI provided the weather on Tor users. Then there was an exploit for a known Firefox vulnerability used to determine the IP address and MAC address of Tor users. Again it came to users with poor operational security, as it attacked Firefox leak was already in the latest version of Tor Browser solved .
The makers of a Trojan horse that is specifically designed to steal money from bank accounts have released a new variant that uses I2P to communicate with infected computers. I2P stands for Invisible Internet Project (I2P) and is a network layer allowing application messages safely and pseudo -Anonymous can exchange.
According PhishMe security company that the new variant discovered I2P can be seen as a "secure version of Tor". Thus true DNS destination is standard shielded and it features peer-to-peer features, IP2 each node can act as an exit node. At the Tor network servers must be specifically set as an exit node.
In the case of the Dyre banking Trojan , also known as Dyreza, I2P provides the attackers a separate communication channel which is difficult to analyze and detect. Yet managers are not powerless says analyst Ronnie Tokazowski. Indeed, it is possible to capture I2P on the top-level domain (.i2p) off and thus stop the spread and possibly make IP2 traffic network harmless.
Researchers have discovered a new ransomware variant that uses strong encryption to encrypt files, but because the original file could not be thoroughly erased victims recover their data without having to pay the ransom.
OphionLocker Message
OphionLocker, such as the ransomware by Trojan7Malware is called, spreads via hacked websites and makes use of known vulnerabilities that are not by Internet users are patched to infect their computer. Once active makes ransomware a unique hardware identifier to, based on the serial number of the first hard disk, the serial number of the motherboard and other information.
Asking For Hardware ID - Tor Link
Then it will create a Tor website link to check the specific hardware ID is already encrypted. Hereafter OphionLocker looking for all kinds of files. However it is only for files with file extensions sought in lowercase. A file as photo.jpg will encrypt the ransomware while foto.jpg is about beaten.
Encryption
To encrypt used OphionLocker elliptic-curve encryption (ECC). As far as known, it is only the second ransomware that uses this encryption method. Most ransomware uses a combination of AES and RSA encryption to encrypt the files of victims. Here, the server generates a key pair, RSA public and private, for RSA. The private key remains on the server, while the public key is sent to the ransomware. In OphionLocker is the public key already in the malware. As a result, can also on computers which are not encrypted are files connected to the Internet.
The malware after encryption displays a message indicating the amount of 1 bitcoin is asked, what with the current exchange rate is 290 euros. Victims, however, do not have to pay to get their files, reports the forum Bleeping Computer . The ransomware shows the original of the files not erase the encrypted safe and also allows the volume shadow copies alone. As a result, it is possible to access the files through a program as ShadowExplorer to recover.
Programmers create code and hackers find errors in it and use them. Discovered a hole in the most widespread cryptographic the OpenSSL could potentially lead to data theft almost all Internet users.
Seventh of April came security bulletin CVE-2014-0160, from which it became aware of the continued existence of a critical vulnerability in the cryptographic package OpenSSL.
Found that implementation algorithms TLS and SSL are used today in most versions of OpenSSL properly handle expansion packs Heartbeat (because of what the error was called HeartBleed). This allows hackers to gain remote access to confidential information from RAM active network process outside the buffer.
An error in the system has learned the Finnish-American company Codenomicon, what hastened to inform the world through a special website heartbleed.com. Heart Bleed - is the name given error experts, loosely translated it means "bleeding heart."
Such dramatic name was not chosen randomly. An error was detected in the package heartbeat (heart beat, heart rate) used for fault detection and resource management server cluster. The result was a play on words in the heart of the leak occurred.
Surprisingly, the critical vulnerability did not notice for two years. It affects all versions from 1.0.1 to OpenSSL 1.0.1f inclusive and 1.0.2-beta1.
As a result of that error in them is not checked in the recording of the actual length of SSLv3. This allows you to read without authorization to 64 Kbytes of RAM process on the connected client or server for each request. In many cases this is enough to get the keys, passwords or other sensitive data. Vulnerable versions of OpenSSL cryptographic package from March 2012 are included in many distributions and BSD OS family of almost all branches of the Linux Debian, RedHat and Slackware.
The first error affects servers Apache, nginx, project Tor (via the web server https://www.torproject.org), as well as many websites that use the HTTPS, even if access to them is carried out by VPN.
Unlike all the other "helpers hackers» Heart Bleed intercepts encryption keys - the cornerstone of secure connections, which encrypts the data transmission between servers. By themselves, the captured data is not worth anything, because the same encrypted PIN bank card might look like, «dkgh # k87u». Without the key, which will allow to decipher the code, it's just a set of symbols. But if the key will be in the hands of criminals, then get the raw data for them there is no trouble.
The greatest danger lies in the fact that this hack does not leave absolutely no trace in the case of data theft is not possible to know about this.
It would seem, what's this, because such errors are almost every day. However encryption package OpenSSL - the most widespread in the world. It is used mostly in the Apache web server and nginx. According to research company Netcraft, on these architectures employ about 66% of all sites on the Internet. Thus, only every third site does not represent a potential threat in terms of data theft. Among the endangered sites include such popular services like Twitter, Dropbox, Yahoo!, Steam and others. OpenSSL packages are used to everything else for the operation of e-mail servers and diverse client software.
To determine the degree of risk of error Codenomicon tried to kidnap their own data as it would make professional hackers.
As a result, they managed to make an attack on their own servers, without leaving any traces. Using only a hole in the system, Codenomicon received encryption keys. Using them, experts have collected from servers usernames and passwords, correspondence employees through messengers and email, as well as confidential company records stored on your computer.
Of course, such a dangerous hole could not remain uncovered. As a result, on April 7 was released a new version of OpenSSL, in which the error is no longer present. However, a simple upgrade package is not enough. If criminals have stolen encryption keys, they can use them in the same way as in the previous version, and for security administrators need to get a new security certificates and to generate new keys.
Of course, for large projects should not worry, because the price of their negligence administrators too great. It can be assumed that the relevant work already done on the servers.
In Codenomicon even see the positive side of Heart Bleed: because administrators can not ignore the fact that hole detection, they have to update the system data encryption on their servers. Along with them are likely to be installed, and other updates that have been postponed for a certain period.
While common in the bulletin and news reports officially recommend the following steps:
Install a patched version of OpenSSL 1.0.1g or 1.0.2-beta2 or recompile OpenSSL package with key OPENSSL_NO_HEARTBEATS;
reissue the SSL-certificate;
lures (honeypot), simulating the presence of a vulnerable server package OpenSSL, and check to connect to them.
We recommend that if you do not use in public places WiFi network, then try to put this kind of functionality is temporarily closed. Personal use of computers when not readily allow strangers remote control of their computer to prevent personal information from being stolen. Once the leakage of information to remind consumers to timely remedy, keep relevant evidence, take the initiative to safeguard their rights.