Seyed Masoud Hosseini · Overview · Study log · Weekly summaries · Ideas · Search · Transcript · RSS feed

Computer Security · Lecture 18 of 22 · 1:20:13

Lecture 19: Anonymous Communication (Tor)

19. Anonymous Communication on YouTube

Study guide

What this lecture covers

This is a guest lecture by Nick Mathewson, one of Tor's core developers, given after students read a Tor design paper. It defines anonymity precisely, then walks step by step from "we want Alice to be able to buy socks without being tracked" to the actual design of onion routing, circuits, and relays. It closes with practical problems Tor has faced in production: abuse, hidden services, and real attacks against the network.

It follows directly after the private browsing lecture and extends the same privacy unit into network-level anonymity. After watching, you should be able to define unlinkability and unobservability, explain why a single relay or a small anonymity set doesn't provide real protection, describe how Tor builds and uses circuits, and name some of the concrete attacks and design tradeoffs Tor deals with.

Key ideas

  • Anonymity (technical sense): an observer cannot link a specific user to a specific action, categorically or even probabilistically better than random.
  • Unlinkability: an attacker cannot connect a user's separate actions or pseudonymous activity into one long-term profile.
  • Unobservability: an attacker cannot even tell that a user is active online at all; much harder to achieve than plain anonymity.
  • Anonymity loves company: anonymity systems only protect users well if they have a large, shared user base; small user pools (like old remailer networks) provide little real cover.
  • Onion routing: a message is wrapped in layers of encryption, one per relay, so each relay only knows the hop before and after it, not the full path.
  • Circuits: Tor negotiates a symmetric key with each relay in a path and reuses that path (a circuit) for a session rather than doing expensive public-key crypto per message.
  • Directory consensus: Tor avoids trusting a single directory server or an unverified peer-to-peer list by having multiple hardened authorities vote hourly and sign a consensus list of relays.
  • Traffic correlation: Tor does not hide packet timing and volume; an attacker who sees both ends of a connection can often still correlate them statistically.

Walkthrough

Defining anonymity: unobservability and unlinkability (8:05)

Using an example of Alice buying socks while an eavesdropper Eve watches, the lecture distinguishes plain anonymity (Eve can't tell Alice bought socks, categorically or probabilistically) from unlinkability (Eve can't connect Alice to a long-term pseudonymous profile, like a blog written under a fake name) and unobservability (Eve can't even tell Alice is online). Unobservability is called much harder to build than the other two.

Motivations: why build Tor (11:07)

Mathewson explains Tor grew out of an unfinished research project and a belief that anonymity systems needed a real test bed to make progress, since waiting for research problems to be solved first would have meant waiting indefinitely. He discusses use cases beyond obvious privacy: companies protecting competitive data, researchers avoiding biased geolocation results, law enforcement avoiding tipping off investigation targets, and journalists or ordinary users avoiding harassment. He is direct that Tor is also used for illegal activity, and argues that a security tool unusable by criminals is usually a bad security tool.

Building anonymity step by step: from a single relay to onion routing (17:08)

The lecture builds Tor's design incrementally on the whiteboard. A single relay is not enough, since an eavesdropper can just watch that one machine. Adding many users through one relay helps but still trusts that relay fully. Adding TLS protects the links but the relay still knows both who is asking and what they asked for. The fix is multiple relays, each removing one layer of encryption, so no single relay sees both the source and the destination — classic onion routing, with a warning that timing and volume of traffic are not hidden by this scheme alone, which is why systems like mix networks trade latency for stronger protection (a tradeoff Tor deliberately does not make, since it targets everyday web browsing).

How Tor's circuit protocol works (27:23)

A detailed walkthrough shows Alice negotiating a symmetric key with the first relay via a create cell, then extending the circuit to a second relay via a relay extend cell encrypted so only that next relay can read it. Each relay only knows its own circuit ID and neighbor, not the full path. The lecture explains why Tor carries TCP stream contents rather than raw IP packets (avoiding the need for an IP normalization layer, since different OS TCP stacks are trivially fingerprintable) and why it avoids protocol-specific proxies, since end-to-end encryption from the user's application to the destination means anonymizing transformations must happen in the application, not a proxy.

Node discovery and abuse (46:38)

The lecture traces why Tor settled on multiple hardened directory authorities that vote hourly and sign a consensus, rejecting a hardcoded node list (doesn't scale), a single trusted directory (single point of failure), and unverified peer gossip (vulnerable to route-capture attacks where one relay lies about the network). On abuse, exit policies restricting ports turned out not to stop abuse (any port can carry abusive traffic) but did let more operators volunteer to run limited exits. The deeper problem is that many sites use IP-based blocking against abusive users, and this frequently gets all Tor users banned; blind signatures and anonymous blacklistable credentials are discussed as partial, still-immature fixes.

Hidden services and attacks and defenses (55:46)

Hidden services solve "responder anonymity" — publishing content without revealing the server's location — by having the service build circuits to several relays, register a public key with a directory system, and let clients connect through those relays without ever learning the service's real IP. The lecture also covers real attacks: unencrypted application traffic being the most common attack surface, a traffic-tagging flaw in early integrity checking, memory-exhaustion ("sniper") attacks against relays, and a serious bug where Tor's Diffie-Hellman implementation failed to reject degenerate values like zero, which would let an attacker force a known shared key.

Before you watch

  • Read (or at least skim) the Tor design paper assigned for this lecture; the talk assumes familiarity with it and references specific sections.
  • Review the private browsing lecture's discussion of IP-based identification, since this lecture treats Tor as a complementary layer that addresses IP anonymity but not fingerprinting.

Check your understanding

  1. What is the difference between unlinkability and unobservability, and why is the second one harder to achieve?
  2. Why does "anonymity loves company" mean that a small anonymity network can fail to protect its users even without any flaw in its cryptography?
  3. Walk through why Tor uses layered relays with per-hop encryption instead of a single trusted relay.
  4. Why did Tor reject both a single trusted directory server and unverified peer-to-peer node discovery?
  5. Why is unencrypted application traffic described as the single biggest practical attack on Tor users?

Vocabulary

anonymity (noun)
The state of not being identifiable while doing something.
Tor is designed to give users anonymity online.
eavesdropper (noun)
Someone who secretly listens in on private communication.
An eavesdropper watching the network shouldn't learn who visited what.
unlinkability (noun)
The property that separate actions by the same person cannot be connected together.
Unlinkability prevents building a profile from someone's posts.
unobservability (noun)
The property that an attacker cannot even tell whether someone is active online.
Unobservability is much harder to achieve than plain anonymity.
pseudonymous (adjective)
Using a fake name instead of a real identity.
A pseudonymous blog can still be linked back to its author.
onion routing (noun)
A method of sending data through several relays, each removing one layer of encryption.
Onion routing hides both the source and destination from any single relay.
relay (noun)
A computer that forwards traffic on behalf of others in a network.
Each relay only knows the hop before and after it.
circuit (noun)
A fixed path through several relays used for a session.
Tor builds a circuit and reuses it instead of choosing a new path each time.
layer (encryption) (noun)
One level of encryption wrapped around data, among several.
Each relay peels off one layer of encryption.
test bed (noun)
A system used for experimenting and testing new ideas in practice.
Tor was built as a real-world test bed for anonymity research.
directory authority (noun)
A trusted server that helps decide which relays are valid and safe to use.
Multiple directory authorities vote to build the consensus list.
consensus (network) (noun)
An agreed, shared record produced by combining input from several trusted sources.
Relays sign a consensus list every hour.
single point of failure (noun)
One part of a system whose failure would break the whole system.
A single trusted directory would be a single point of failure.
traffic correlation (noun)
Matching patterns in timing or volume of data to link the two ends of a connection.
Traffic correlation can still de-anonymize a Tor user.
exit policy (noun)
Rules that decide which types of traffic a relay allows to leave the network.
Exit policies restrict which ports a Tor exit relay allows.
hidden service (noun)
A service reachable through Tor without revealing its real server location.
A hidden service hides the server's IP address from visitors.
responder anonymity (noun)
Hiding the identity or location of the party providing a service, not just the requester.
Hidden services provide responder anonymity for the server.
blind signature (noun)
A cryptographic signature given without the signer seeing the actual content being signed.
Blind signatures are proposed as a partial fix for Tor abuse.
route-capture attack (noun)
An attack where a malicious node lies to control which paths traffic takes.
Unverified peer gossip is vulnerable to a route-capture attack.
degenerate value (noun)
A special, edge-case value (like zero) that breaks the normal assumptions of a calculation.
The bug let an attacker send a degenerate value like zero.

From the YouTube description

MIT 6.858 Computer Systems Security, Fall 2014
View the complete course: http://ocw.mit.edu/6-858F14
Instructor: Nick Mathewson

In this lecture, Nick Mathewson delivers a guest lecture on Tor and Anonymous communication.

License: Creative Commons BY-NC-SA
More information at http://ocw.mit.edu/terms
More courses at http://ocw.mit.edu

← Lecture 18: Private Browsing · Lecture 20: Mobile Phone Security →