<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Committee to Protect Bloggers &#187; Tor</title>
	<link>http://committeetoprotectbloggers.org</link>
	<description>Free speech for bloggers worldwide</description>
	<pubDate>Thu, 20 Nov 2008 03:42:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>
	<language>en</language>
			<item>
		<title>Tor Hacker&#8217;s House Raided in Sweden</title>
		<link>http://committeetoprotectbloggers.org/2007/11/14/tor-hackers-house-raided-in-sweden/</link>
		<comments>http://committeetoprotectbloggers.org/2007/11/14/tor-hackers-house-raided-in-sweden/#comments</comments>
		<pubDate>Thu, 15 Nov 2007 02:54:38 +0000</pubDate>
		<dc:creator>Curt</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://committeetoprotectbloggers.org/2007/11/14/tor-hackers-house-raided-in-sweden/</guid>
		<description><![CDATA[According to a post on Wired&#8217;s Threat Level blog, by Kim Zetter, Dan Egerstad, of DEranged Security, who had previously &#8220;obtained log-in and password information for 1,000 e-mail accounts belonging to foreign embassies, corporations and human rights organizations, had his house raided on Monday by Swedish officials, who took him in for questioning.&#8221;
Egerstad illustrated how [...]]]></description>
			<content:encoded><![CDATA[<p>According to a post on Wired&#8217;s <a href="http://blog.wired.com/27bstroke6/2007/11/swedish-researc.html">Threat Level</a> blog, by Kim Zetter, <a href="http://committeetoprotectbloggers.org/2007/09/11/tor-is-no-guarantee/">Dan Egerstad</a>, of DEranged Security, who had previously &#8220;obtained log-in and password information for 1,000 e-mail accounts belonging to foreign embassies, corporations and human rights organizations, had his house raided on Monday by Swedish officials, who took him in for questioning.&#8221;</p>
<p>Egerstad illustrated how the Tor onion-routing system (that sends an Internet content request through a series of servers to make pursuit difficult) is no outright guarantee of information safety by capturing and publishing this information. </p>
<blockquote><p>
As Egerstad and I discussed the problem in August, we both came to the conclusion that the embassy employees were likely not using Tor nor even knew what Tor was. Instead, we suspected that the traffic he sniffed belonged to someone who had hacked the accounts and was eavesdropping on them via the Tor network. As the hacked data passed through Egerstad&#8217;s Tor exit nodes, he was able to read it as well.</p>
<p>So who was responsible for hacking the accounts? The likely suspect &#8212; given that most of the accounts Egerstad uncovered belonged to embassies, foreign and defense ministry officials, legislators and human rights groups &#8212; was a government or intelligence agency. I attempted to contact several of the account holders in August to ask them whether they used Tor or knew that their accounts had been compromised but never received a response from any of them.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://committeetoprotectbloggers.org/2007/11/14/tor-hackers-house-raided-in-sweden/feed/</wfw:commentRss>
		</item>
		<item>
		<title>German Tor Administrator Arrested</title>
		<link>http://committeetoprotectbloggers.org/2007/09/17/german-tor-administrator-arrested/</link>
		<comments>http://committeetoprotectbloggers.org/2007/09/17/german-tor-administrator-arrested/#comments</comments>
		<pubDate>Mon, 17 Sep 2007 01:05:53 +0000</pubDate>
		<dc:creator>Curt</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://committeetoprotectbloggers.org/2007/09/17/german-tor-administrator-arrested/</guid>
		<description><![CDATA[
On Sunday, July 29, German Tor onion router operator Alexander Janssen was arrested by the German police. A bomb threat against police on a German forum had run through Janssen&#8217;s Tor node and the police traced his IP address. he attempted to explain that Tor was a system distributed on computers around the world that [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://tor.eff.org/" title="Tor"><img src="http://farm2.static.flickr.com/1141/1393657895_642f86ce4a_o.png" width="193" height="79" alt="Tor" /></a></p>
<p>On Sunday, July 29, German Tor onion router operator Alexander Janssen was arrested by the German police. A bomb threat against police on a German forum had run through Janssen&#8217;s Tor node and the police traced his IP address. he attempted to explain that Tor was a system distributed on computers around the world that allowed people in, say, repressive countries to both gain access to forbidden materials (like sex education or the Encyclopedia Britannica) and to send messages and post on websites without the Internet police in those countries finding you. The cops were not in a listening mood. </p>
<p>He was released not long after, with an apology but waited to <a href="http://itnomad.wordpress.com/2007/09/16/tor-madness-reloaded/">tell the world about it on his blog</a> until the charges were <a href="http://www.cnet.com/surveillance-state/8300-13739_1-46.html?tag=bc">officially dropped</a>.</p>
<p>Tor can be abused as well as used and police forces in theoretically non-repressive countries need to get some night-classes under their belts to avoid arresting people like Janssen, while really miscreants walk free.</p>
]]></content:encoded>
			<wfw:commentRss>http://committeetoprotectbloggers.org/2007/09/17/german-tor-administrator-arrested/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Tor is No Guarantee</title>
		<link>http://committeetoprotectbloggers.org/2007/09/11/tor-is-no-guarantee/</link>
		<comments>http://committeetoprotectbloggers.org/2007/09/11/tor-is-no-guarantee/#comments</comments>
		<pubDate>Tue, 11 Sep 2007 16:53:45 +0000</pubDate>
		<dc:creator>Curt</dc:creator>
		
		<category><![CDATA[Tor]]></category>

		<category><![CDATA[Circumvention]]></category>

		<guid isPermaLink="false">http://committeetoprotectbloggers.org/2007/09/11/tor-is-no-guarantee/</guid>
		<description><![CDATA[Dan Egerstad of DEranged Security found supposedly secret government information by &#8220;sniffing&#8221; info from Tor nodes around the world. In a post entitled DEranged Security gives you 100 passwords to Governments &#038; Embassies, Egerstand published the information he found as, according to him, a corrective to the complacency surrounding Internet security. 
Here is everything you [...]]]></description>
			<content:encoded><![CDATA[<p>Dan Egerstad of DEranged Security found supposedly secret government information by &#8220;sniffing&#8221; info from <a href="http://tor.eff.org/">Tor</a> nodes around the world. In a post entitled <a href="http://www.derangedsecurity.com/deranged-gives-you-100-passwords-to-governments-embassies/">DEranged Security gives you 100 passwords to Governments &#038; Embassies</a>, Egerstand published the information he found as, according to him, a corrective to the complacency surrounding Internet security. </p>
<blockquote><p>Here is everything you need to read classified email and fuck up some serious International business. Hopefully this will put light on the security problems that are never talked about and get at least this fixed with a speed that you never seen your government work before. As a Swedish citizen I can’t give this information to anyone without getting into trouble, so instead I’m giving it to everyone.</p></blockquote>
<p>Egerstad <a href="http://www.derangedsecurity.com/where-did-we-go/">subsequently claimed</a> that the United States shut down his site. (Egerstad&#8217;s in Sweden.) Later, he explained what he did and how. If you&#8217;re capable of following it, you are far more technically adept than I. </p>
<blockquote><p>Five ToR exit nodes, at different locations in the world, equipped with our own packet-sniffer focused entirely on POP3 and IMAP traffic using a keyword-filter looking for words like “gov, government, embassy, military, war, terrorism, passport, visa” as well as domains belonging to governments. This was all set up after a small experiment looking into how many users encrypt their mail where one mail caught my eye and got me started thinking doing a large scale test. Each user is not only giving away his/her passwords but also every mail they read or download together with all other traffic such as web and instant messaging.</p>
<p>Did you get it? These governments told their users to use ToR, a software that sends all your traffic through not one but three other servers that you know absolutely nothing about. Yes, two are getting encrypted traffic but that last exit node is not. There are hundreds of thousands ToR-users but finding these kinds of accounts was… hmm… chocking! The person who wrote the security policy on these accounts should reconsider changing profession, start cleaning toilets! These administrators are responsible for giving away their own countries secrets to foreigners. I can’t call it a mistake, this is pure stupidity and not forgivable!</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://committeetoprotectbloggers.org/2007/09/11/tor-is-no-guarantee/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
