Hacker News new | ask | show | jobs
Heartbleed and TOR in practice (digitalassurance.com)
14 points by bdpuk 4441 days ago
2 comments

Combined with rumors that the NSA knew about Heartbleed, this makes me wonder if they actually were involved in outing Silk Road. As far as I know, we still haven't seen any indication on how the FBI managed to find and image the Silk Road server.
I dont think heartbleed was necessary to crack Silk Road server - after all its just another php server, those arent really known for being air-tight.

Especially the programmer who basically copypasted stuff from stackoverflow.

I saw a study showing it is possible to deanonymize a hidden service by doing traffic analysis for several months.
I would be shocked if they weren't involved in outing Silk Road, in some sort of multiagency effort. It's not clear NSA couldn't de-anonymize specific TOR services if they wanted to even before we knew about Heartbleed though.
i was going to say the same thing :)
After all the NSA leaks and then Heartbleed, being anonymous anywhere really seems like a pipe dream to me.
Large-scale traffic analysis (dragnet surveillance) + hacking into exit nodes already made compromising TOR users technically feasible before the heartbleed exploit.

The whole cypherpunk/online anonymity movement which spawned TOR was largely predicated on nation states acting legally. But when they can secretly hack into every router, fiber cable, and gateway endpoint without any question of legality then anonymity and privacy online is no longer an option for anyone, even the most technically-proficient.