News: 1597212847

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

This is node joke. Tor battles to fend off swarm of Bitcoin-stealing evil exit relays making up about 25% of outgoing capacity at its height

(2020/08/12)


The Tor Project has confirmed someone, or some group, is in control of a large number of Bitcoin-snaffling exit nodes in its anonymizing network, and it's battling to boot them off.

One observer reckons more than 23 per cent of the entire Tor network’s exit capacity was under the command of one miscreant, or one group of miscreants, at one point in May, with the end goal being the theft of people's cryptocurrency.

Tor works by randomly routing your connections through a [1]network of nodes spread across the world. When you use the open-source Tor software to connect to a public website, the connection is relayed between a few nodes and out to the site via one of many exit nodes. All the site sees is a connection from that particular exit node, and can't trace you back to the IP address you used to enter the Tor network, and thus you're kept anonymous. The network is maintained in an ad-hoc manner, with nodes joining and leaving.

Crucially, whoever is running an exit node [2]can access the traffic flowing through it. Thus it is wise to ensure your connections to websites and other services are wrapped in additional encryption, such as HTTPS or SSH, so that exit node operators cannot snoop on you and alter any information you send over the internet. (Connections are encapsulated in layers of encryption as they are routed through the Tor network.)

It's one thing to be mindful of a rogue exit node operator eavesdropping on you, it's another thing when someone successfully adds a large number of exit nodes to Tor, all under their control, because it means some kind of elaborate campaign is underway to undermine Tor's security.

In this case, it appears someone or some group is adding malicious exit nodes that perform a form of SSL stripping to eavesdrop on visitors to cryptocurrency websites – specifically, Bitcoin mixer services. If any Bitcoin wallet addresses are spotted in the passing unprotected traffic, the addresses are rewritten on the fly so as to funnel transactions into the miscreants' coffers, thus stealing victims' digital money.

Tor soups up onion sites with bountiful browser bump: No more tears trying to find the secure sites you want [3]READ MORE

The exit nodes take advantage of the fact that when you type in a URL like theregister.com in your browser, it typically tries to connect first to the dotcom using non-encrypted HTTP, only to be redirected by the website's server on port 80 to the safer and encrypted HTTPS service on port 443. The malicious exit nodes intercept some of these insecure HTTP requests to prevent them being upgraded to HTTPS-encrypted connections, and tamper with the unprotected data in transit, namely any Bitcoin wallet addresses.

Yes, there are plugins like HTTPS Everywhere that force browsers to use encryption, but not everyone uses them, or they disable them after a while because the extensions complain too much when they can't establish a connection to non-HTTPS pages. And there are things like HSTS Preloading that can thwart this kind of attack, but not every website owner uses it. Thus, some folks using Tor may end up running unencrypted traffic through one of these bad nodes to a crypto-dosh mixer, and have their Bitcoins swiped.

This is all according to Nusenu, a developer who has been monitor the health of the Tor network for years. They [4]revealed this month that, earlier in 2020, "roughly about one out of four connections leaving the Tor network were going through exit relays controlled by a single attacker."

Whoever is behind the spy nodes is determined and persistent, we're told. Even though the malicious group was detected at the end of May with more than 23 per cent of the network's exit capacity, and removed from the Tor network's directories, they returned in June with about 22 per cent, were discovered and banned again, only to return a few days later with about 20 per cent. Nusenu noted:

This also shows us how fast the malicious entity recovered from a single removal event and that we didn’t detect all of them at the same time. It took them less than 30 days to recover after a removal and reach 22 per cent exit probability again (starting at 4 per cent). It also gives us an idea that they apparently will not back off after getting discovered once. In fact they appear to plan ahead for detection and removal and setup new relays preemptively to avoid a complete halt of their operations.

"So far 2020 is probably the worst year in terms of malicious Tor exit relay activity since I started monitoring it about five years ago," Nusenu added. "As far as I know this is the first time we uncovered a malicious actor running more than 23 per cent of the entire Tor network’s exit capacity. Since Tor clients usually use many Tor exit relays over time the chance to use a malicious exit relay increases over time."

Ongoing war

The Tor Project confirmed to us it has been trying for months to get the bad actor off its network, including banning the malicious nodes in May and June only to see the surveillance menace return. We're told the Tor team is hampered right now due to being short-staffed. Back [5]in April , the project had to drop 13 people, about a third of its staff, due to funding shortfalls amid the coronavirus pandemic and economic downturn. That means there's not enough people monitoring the anonymizing mesh for wrongdoers.

"We still have contributors watching the network and reporting malicious relays to be rejected by our directory authorities, but they cannot do this full time," a Tor Project spokesperson told The Register . "Our goal is to recover our funds to be able to get that Network Health team back in shape."

While the Tor Project said it is trying to mitigate the malicious operation, including considering disabling HTTP connections, it also has a more permanent solution in the works, once its thinly stretched staff is able to finalize the defense mechanism, which seeks to minimize the use of exit nodes that aren't trusted. That hopefully ought to take care of exit relays appearing out of nowhere that later turn out to be malicious.

"We also have a design proposal for how to improve the situation in a more fundamental way, by limiting the total influence from relays we don't 'know' to some fraction of the network," the spokesperson said. "Then we would be able to say that by definition we trust at least 50 per cent (or 75 per cent, or whatever threshold we pick) of the network."

In the meantime, use HTTPS Everywhere, be mindful of HTTPS downgrade attacks, and keep your internet traffic encrypted as it exits the Tor network. ®

Get our [6]Tech Resources



[1] https://2019.www.torproject.org/about/overview.html.en#thesolution

[2] https://2019.www.torproject.org/docs/faq.html.en#CanExitNodesEavesdrop

[3] https://www.theregister.com/2020/06/03/tor_browser_upgrade/

[4] https://medium.com/@nusenu/how-malicious-tor-relays-are-exploiting-users-in-2020-part-i-1097575c0cac

[5] https://www.theregister.com/2020/04/20/security_roundup_190420/

[6] https://whitepapers.theregister.com/

I continue to be surprised

Hubert Cumberdale

at just how many websites are still not using encryption. There really is no excuse these days. I've recently installed HTTPS Everywhere on FF, and I've disabled all HTTP traffic. I'll be interested to see if the internet is still broadly usable.

Re: I continue to be surprised

Symon

It'll be more usable, because it'll block the bit of the internets that you didn't want anyway.

p.s. Privacy Badger, Ghostery, etc. etc.

Too stupid to care?

Claptrap314

I'm seriously having a problem understanding that this is real. In order for this attack to succeed, we need someone who

1) Uses bitcoin.

2) Uses Tor.

3) Uses a bitcoin mixer service.

4) Does NOT use https to access the bitcoin mixer service via Tor.

Isn't that like just one guy? What am I missing?

Also, if you're already using Tor, why on earth would you suddenly care about speed over blind trust in the exit node for that final hop?

Re: Too stupid to care?

Wellyboot

Yes, strikes me as a exploiting the skiddies who think TOR sound cool and don't implement any actual transport security beyond default.

TOR isn't about 'secure routing' it's 'anonymous routing'. Pick your protocols with care.

Re: Too stupid to care?

Anonymous Coward

4) Does NOT use https to access the bitcoin mixer service via Tor.

No, it relies on someone typing mybitcoinesite.com into the browser and it usually 'upgrades' the connection to https. Therefore they think they are always using https. However on this exit node the upgrade doesn't happen and the connection remains insecure.

Most people don't specify the protocol when they type an address any more.

Smaller fleas to bite 'em

Anonymous Coward

Well, I can't find anybody with a lightly-colored hat that has anything good to say about [1]Bitcoin mixers , so this is probably one variety of crims being relieved of their boodle by another, which, I'd hazard to guess, given their persistence, is of the just-south-of-China variety. That said, breaking T O R is B A D.

[1] https://en.wikipedia.org/wiki/Cryptocurrency_tumbler

Re: Smaller fleas to bite 'em

Wellyboot

It's not breaking TOR, just exploiting a fairly small (as per Claptrap ^) set of user activities running over it.

If you're using Tor...

DrXym

You should really be using Tor Browser. It DOES have HTTPS Everywhere and NoScript enabled plus other protections enabled in the browser. I'm sure it doesn't prevent some malicious activity by exit nodes but it sounds like it will block what is going on above.

"What if" is a trademark of Hewlett Packard, so stop using it in your
sentences without permission, or risk being sued.