Delivery-Date: Fri, 31 Oct 2014 08:37:56 -0400
Return-Path: <tor-talk-bounces@lists.torproject.org>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on moria.seul.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.9 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_MED,
	RP_MATCHES_RCVD autolearn=ham version=3.3.1
X-Original-To: archiver@seul.org
Delivered-To: archiver@seul.org
Received: from eugeni.torproject.org (eugeni.torproject.org [38.229.72.13])
	(using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by khazad-dum.seul.org (Postfix) with ESMTPS id 344111E01BC;
	Fri, 31 Oct 2014 08:37:55 -0400 (EDT)
Received: from eugeni.torproject.org (localhost [127.0.0.1])
	by eugeni.torproject.org (Postfix) with ESMTP id 3DF1331828;
	Fri, 31 Oct 2014 12:37:51 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1])
 by eugeni.torproject.org (Postfix) with ESMTP id CB3DF3182C
 for <tor-talk@lists.torproject.org>; Fri, 31 Oct 2014 12:37:47 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at eugeni.torproject.org
Received: from eugeni.torproject.org ([127.0.0.1])
 by localhost (eugeni.torproject.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id ijPHKAnVRB9R for <tor-talk@lists.torproject.org>;
 Fri, 31 Oct 2014 12:37:47 +0000 (UTC)
Received: from smtp.mozilla.org (mx2.corp.phx1.mozilla.com [63.245.216.70])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client did not present a certificate)
 by eugeni.torproject.org (Postfix) with ESMTPS id A05AB30CF3
 for <tor-talk@lists.torproject.org>; Fri, 31 Oct 2014 12:37:44 +0000 (UTC)
Received: from Ornithorynque.local (unknown [64.213.97.194])
 (Authenticated sender: dteller@mozilla.com)
 by mx2.mail.corp.phx1.mozilla.com (Postfix) with ESMTPSA id 3B0CFF300D
 for <tor-talk@lists.torproject.org>; Fri, 31 Oct 2014 05:37:40 -0700 (PDT)
Message-ID: <5453828B.2060401@mozilla.com>
Date: Fri, 31 Oct 2014 13:37:31 +0100
From: David Rajchenbach-Teller <dteller@mozilla.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9;
 rv:31.0) Gecko/20100101 Thunderbird/31.2.0
MIME-Version: 1.0
To: tor-talk@lists.torproject.org
References: <20141031122302.GA5554@glue.grepular.com>
In-Reply-To: <20141031122302.GA5554@glue.grepular.com>
Subject: Re: [tor-talk] Facebook brute forcing hidden services
X-BeenThere: tor-talk@lists.torproject.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: tor-talk@lists.torproject.org
List-Id: "all discussion about theory, design,
 and development of Onion Routing" <tor-talk.lists.torproject.org>
List-Unsubscribe: <https://lists.torproject.org/cgi-bin/mailman/options/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=unsubscribe>
List-Archive: <http://lists.torproject.org/pipermail/tor-talk/>
List-Post: <mailto:tor-talk@lists.torproject.org>
List-Help: <mailto:tor-talk-request@lists.torproject.org?subject=help>
List-Subscribe: <https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk>, 
 <mailto:tor-talk-request@lists.torproject.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============9090211535146810818=="
Errors-To: tor-talk-bounces@lists.torproject.org
Sender: "tor-talk" <tor-talk-bounces@lists.torproject.org>

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============9090211535146810818==
Content-Type: multipart/signed; micalg=pgp-sha1;
 protocol="application/pgp-signature";
 boundary="0krDu2jDlfd1AS4NNEJWJdH4XxuHoJp2i"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--0krDu2jDlfd1AS4NNEJWJdH4XxuHoJp2i
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

That article is extremely vague. Can someone explain exactly what
happened for someone like me who has very limited understanding of Tor?

Thanks,
 David

On 31/10/14 13:23, Mike Cardwell wrote:
> https://www.facebook.com/notes/protect-the-graph/making-connections-to-=
facebook-more-secure/1526085754298237
>=20
> So Facebook have managed to brute force a hidden service key for:
>=20
> http://facebookcorewwwi.onion/=20
>=20
> If they have the resources to do that, what's to stop them brute
> forcing a key for any other existing hidden service?
>=20
>=20
>=20


--=20
David Rajchenbach-Teller, PhD
 Performance Team, Mozilla


--0krDu2jDlfd1AS4NNEJWJdH4XxuHoJp2i
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBAgAGBQJUU4KQAAoJED+FkPgNe9W+qrgH/RhTR4Ilva9bt9+U3ei3355q
R8m9AfjcIHt6ynJRdZy9iK5AM0Zb2VBZ5v1kcVw42JDIsBwWZgUuXOFsdB1ZHeFf
o0u4d79JxjAIQCJLxm6fhag/bbCeXVR6XdL3P/F9N6tP1+4x7NwKutGwhty39BSo
Wrm+RmF3XlmiyWFaClRDTL1wA/l1c8ha+mM5Q3MmJv06VWj8icMKkfjEZizl5jA3
ygvYTyEERf2N0kLBlK/r0Krw21OKTb8kzoWxWhO6BnDEvy8ZrmLXyjr73VHyjEF9
XnK3SGnN+FTJnSsIzR5qGbQ52Q7R0ROstMUo49dqGCYwZC1OvX3ECcFogNZz8Y0=
=i1G4
-----END PGP SIGNATURE-----

--0krDu2jDlfd1AS4NNEJWJdH4XxuHoJp2i--

--===============9090211535146810818==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
tor-talk mailing list - tor-talk@lists.torproject.org
To unsubscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk

--===============9090211535146810818==--

