Bitcoin Forum
May 11, 2024, 12:54:31 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: US Govt shares tips on defending against cyberattacks via Tor  (Read 109 times)
Yogee (OP)
Sr. Member
****
Offline Offline

Activity: 1540
Merit: 412



View Profile
July 04, 2020, 01:59:54 PM
Last edit: July 05, 2020, 12:58:42 AM by Yogee
Merited by OgNasty (1)
 #1

Yes, you read that right.

Since cyberattackers use Tor to mask and hide their online identification, CISA (Cybersecurity and Infrastructure Security Agency) and the FBI are teaching private companies measures to detect activities that are malicious and mitigate cyber threats. Measures includes:
Quote
Most restrictive approach: Block all web traffic to and from public Tor entry and exit nodes (does not completely eliminate the threat of malicious actors using Tor for anonymity, as additional Tor network access points, or bridges, are not all listed publicly.)
Less restrictive approach: Tailor monitoring, analysis, and blocking of web traffic to and from public Tor entry and exit nodes: orgs that do not wish to block legitimate traffic to/from Tor entry/exit nodes should consider adopting practices that allow for network monitoring and traffic analysis for traffic from those nodes, and then consider appropriate blocking. This approach can be resource-intensive but will allow greater flexibility and adaptation of defensive. Legitimate usage examples: deployed military or other overseas voters.
Blended approach: Block all Tor traffic to some resources, allow and monitor for others (i.e., intentionally allowing traffic to/from Tor only for specific websites and services where legitimate use may be expected and blocking all Tor traffic to/from non-excepted processes/services). This may require continuous re-evaluation as an entity considers its own risk tolerance associated with different applications. The level of effort to implement this approach is high.

Summary: https://www.bleepingcomputer.com/news/security/us-govt-shares-tips-on-defending-against-cyberattacks-via-tor/
Full report: https://www.us-cert.gov/ncas/alerts/aa20-183a

Educating the public is a good approach by Government agencies I must say.
1715388871
Hero Member
*
Offline Offline

Posts: 1715388871

View Profile Personal Message (Offline)

Ignore
1715388871
Reply with quote  #2

1715388871
Report to moderator
1715388871
Hero Member
*
Offline Offline

Posts: 1715388871

View Profile Personal Message (Offline)

Ignore
1715388871
Reply with quote  #2

1715388871
Report to moderator
1715388871
Hero Member
*
Offline Offline

Posts: 1715388871

View Profile Personal Message (Offline)

Ignore
1715388871
Reply with quote  #2

1715388871
Report to moderator
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715388871
Hero Member
*
Offline Offline

Posts: 1715388871

View Profile Personal Message (Offline)

Ignore
1715388871
Reply with quote  #2

1715388871
Report to moderator
StonerStanley
Sr. Member
****
Offline Offline

Activity: 535
Merit: 267



View Profile
July 04, 2020, 04:16:49 PM
Merited by OgNasty (1), Yogee (1)
 #2

Yes, you read that right.

Since cyberattackers use Tor to mask and hide their online identification, CISA (Cybersecurity and Infrastructure Security Agency) and the FBI recommends that companies consider using Tor for their online activities.

Quote
CISA and the FBI recommend that organizations assess their individual risk of compromise via Tor and take appropriate mitigations to block or closely monitor inbound and outbound traffic from known Tor nodes.

Summary: https://www.bleepingcomputer.com/news/security/us-govt-shares-tips-on-defending-against-cyberattacks-via-tor/
Full report: https://www.us-cert.gov/ncas/alerts/aa20-183a

I am not a security expert but I was still surprised reading this. Government agencies such as the FBI is the least expected to recommend using Tor service. I believe they would rather want to know everything. But educating legitimate companies to increase their online privacy and anonymity via Tor is probably the better way to starve cyber attackers.


I don't read anywhere that they are recommending to companies to consider using Tor for protect their online activities.
They give recommendations to avoid being attacked by an attacker that is using Tor.

It would make no sense for most companies to use Tor, because it would be less secure since the data would transit between servers that could be compromised and that aren't owned by these same companies.
Yogee (OP)
Sr. Member
****
Offline Offline

Activity: 1540
Merit: 412



View Profile
July 05, 2020, 01:02:07 AM
Merited by OgNasty (1)
 #3

My bad. I completely misunderstood the article.

Done rewriting my post. Thanks.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!