Bitcoin Forum
May 13, 2024, 11:54:57 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Has bitcoin tor been patched to stop attack ?  (Read 495 times)
somedude5 (OP)
Newbie
*
Offline Offline

Activity: 6
Merit: 2


View Profile
March 20, 2016, 10:17:16 AM
 #1

Hi,

There is/was a problem when using tor in the bitcoin client.
The article is here : http://www.coindesk.com/bitcoin-tor-anonymity-can-busted-2500-month/

What basiclly happens is that an atacker sets up some tor nodes and then closes down some nodes you
are using, so you start using the attackers nodes. He can then start to do some kind of man in the middle attack.
Also it is easy to identify who a particular person is.

I was wondering if this problem has been patched.

Regards,
1715644497
Hero Member
*
Offline Offline

Posts: 1715644497

View Profile Personal Message (Offline)

Ignore
1715644497
Reply with quote  #2

1715644497
Report to moderator
1715644497
Hero Member
*
Offline Offline

Posts: 1715644497

View Profile Personal Message (Offline)

Ignore
1715644497
Reply with quote  #2

1715644497
Report to moderator
1715644497
Hero Member
*
Offline Offline

Posts: 1715644497

View Profile Personal Message (Offline)

Ignore
1715644497
Reply with quote  #2

1715644497
Report to moderator
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
European Central Bank
Legendary
*
Offline Offline

Activity: 1288
Merit: 1087



View Profile
March 20, 2016, 02:00:39 PM
 #2

First I heard of it. There's probably a few exploits out there waiting to be uncovered. If it's really bad then we'll see an emergency scramble from everyone.
unamis76
Legendary
*
Offline Offline

Activity: 1512
Merit: 1009


View Profile
March 20, 2016, 02:23:24 PM
 #3

I don't think there's anything to fix here really, the issue is inherent to Tor usage, I think. It most likely can only be prevented, not fixed, but correct me if I'm wrong Smiley
SanaButt
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
March 20, 2016, 02:38:07 PM
 #4

Hi,

There is/was a problem when using tor in the bitcoin client.
The article is here : http://www.coindesk.com/bitcoin-tor-anonymity-can-busted-2500-month/

What basiclly happens is that an atacker sets up some tor nodes and then closes down some nodes you
are using, so you start using the attackers nodes. He can then start to do some kind of man in the middle attack.
Also it is easy to identify who a particular person is.

I was wondering if this problem has been patched.

Regards,


I think this is related to hardware wallets and not online wallets ?
and its uses denial of service attack (DoS) .

▲▼▲▼▲▼▲▼  No.1 Bitcoin Binary Options and Double Dice  ▲▼▲▼▲▼▲▼
████████████████████████████████  sec◔nds trade  ████████████████████████████████
↑↓ Instant Bets ↑↓ Flexible 1~1440 minutes Expiry time ↑↓ Highest Reward 190% ↑↓ 16 Assets [btc, forex, gold, 1% edge double dice] ↑↓
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
March 20, 2016, 03:53:12 PM
 #5

-snip-
I think this is related to hardware wallets and not online wallets ?
and its uses denial of service attack (DoS) .

No, this has nothing to do with hard wallets, its about network nodes like e.g. bitcoin core. The exploit is using the bitcoin internal DoS protection to ban all Tor exit nodes for the bitcoin node in question to force it on the clearnet or out of the network.

This would only work though if you use Tor as proxy to connect to the clearnet and not if you are connected to other nodes that function as hidden service. The lattest version allows you to distinguish between the two types of connections and as such I would argue that this was indeed patched (in a sense).

Im not really here, its just your imagination.
somedude5 (OP)
Newbie
*
Offline Offline

Activity: 6
Merit: 2


View Profile
March 20, 2016, 07:35:07 PM
 #6

-snip-
I think this is related to hardware wallets and not online wallets ?
and its uses denial of service attack (DoS) .

No, this has nothing to do with hard wallets, its about network nodes like e.g. bitcoin core. The exploit is using the bitcoin internal DoS protection to ban all Tor exit nodes for the bitcoin node in question to force it on the clearnet or out of the network.

This would only work though if you use Tor as proxy to connect to the clearnet and not if you are connected to other nodes that function as hidden service. The lattest version allows you to distinguish between the two types of connections and as such I would argue that this was indeed patched (in a sense).

Thank you very much for your understanding and serious reply of the subject.
I am new to the whole bitcoin world. And i was wondering what exactly  do you mean by "other nodes that function as hidden service"?

If i would have the computer running bitcoin getting physical internet form another box that is routed completely through tor, does that qualifies as hidden service ?
Or do i have to run a  tor node myself and connect it through that node in order to be safe from attackers ?

or and can i configure this using the following option described in the software help  :

--start code output of help bitcoin client --
  -listenonion
       Automatically create Tor hidden service (default: 1)
--end code output of help bitcoin client --
( i would really like to know what exactly this option does, i do not understand it completely )

I am very great full for any help regarding this security issue !
calkob
Hero Member
*****
Offline Offline

Activity: 1092
Merit: 520


View Profile
March 20, 2016, 08:10:53 PM
 #7

What would be the reason for using the tor network for a bitcoin node? i am always abit weary when using tor anyway never mind in regards to my bitcoin
shorena
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1520


No I dont escrow anymore.


View Profile WWW
March 20, 2016, 08:46:58 PM
 #8

@somedude5

-snip-
Thank you very much for your understanding and serious reply of the subject.
I am new to the whole bitcoin world. And i was wondering what exactly  do you mean by "other nodes that function as hidden service"?

Well you can access a site through Tor (e.g. http://blockchain.info/ ) or use a hidden service (e.g. https://blockchainbdgpzk.onion/ ) to visit the same site within the Tor network. Same for bitcoin nodes. They can use Tor to reach other bitcoin nodes with a clear net IP (e.g. https://en.bitcoin.it/wiki/Fallback_Nodes#IPv4_Nodes ) or Tor nodes ( https://en.bitcoin.it/wiki/Fallback_Nodes#Tor_nodes )

If i would have the computer running bitcoin getting physical internet form another box that is routed completely through tor, does that qualifies as hidden service ?

Maybe. The question is not whether you have set up Tor or not, but whether you have a target within Tor (aka hidden service) or outside of the Tor network (everything else).

Or do i have to run a  tor node myself and connect it through that node in order to be safe from attackers ?

or and can i configure this using the following option described in the software help  :

--start code output of help bitcoin client --
  -listenonion
       Automatically create Tor hidden service (default: 1)
--end code output of help bitcoin client --
( i would really like to know what exactly this option does, i do not understand it completely )

I am very great full for any help regarding this security issue !

You can configure bitcoin core to use Tor to connect to other nodes outside of Tor or you can set it up in a way to only allow connections to other nodes that are within the Tor network.

On how to do it, I suggest this thread -> https://bitcointalk.org/index.php?topic=1374919.0 as I have yet to find the time to do it myself.



@calkob

What would be the reason for using the tor network for a bitcoin node? i am always abit weary when using tor anyway never mind in regards to my bitcoin

Same reason for using Tor for anything else. Anonymity. Bitcoin addresses and transactions can not easily be linked to an IP address, but its possible. If you are running bitcoin core as a hidden service and only connect to other nodes within the Tor network there is no IP that could be matched. There are also mobile wallets like Mycelium that support Tor.

Im not really here, its just your imagination.
Bitcoinpro
Legendary
*
Offline Offline

Activity: 1344
Merit: 1000



View Profile
March 20, 2016, 09:06:09 PM
 #9

Bitcoin has never been annonymous,

this is similiar to random numbers,

they just dont exist, infact for you

to pick a random number in your own

head is plain stupid it will always be a

low number, your idea of random is

a trick played by your own cerebal

cortex

WWW.FACEBOOK.COM

CRYPTOCURRENCY CENTRAL BANK

LTC: LP7bcFENVL9vdmUVea1M6FMyjSmUfsMVYf
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!