[tor-dev] Building better pluggable transports (Google Summer of Code)

Tom Ritter tom at ritter.vg
Tue May 28 19:04:53 UTC 2013


On 28 May 2013 14:51, adrelanos <adrelanos at riseup.net> wrote:

> How good are SSH connections with hiding what's inside?
>
> Website fingerprinting has demonstrated, that SSH connections may hide
> communication contents, but which website was visited, could be guessed
> with a fairly good results.
>
> Tor isn't a website, but if SSH leaks which website has been visited
> even when using a SSH tunnel, will it also leak the fact, that someone
> is using Tor through a SSH tunnel?


I think that if we make the adversary upgrade from probing and byte
matching (e.g. look for specific ciphersuites) to statistical protocol
modeling, especially with a small time investment on our part, we have won
a battle.  Development effort isn't free.

You probably can detect Tor traffic inside of SSH with some probability X
after some amount of traffic Y.  But what X, what Y, and how much effort on
behalf of the adversary will it take?  I don't know, but I do think we
should work to move the fight beyond something as simple as byte matching.

-tom
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.torproject.org/pipermail/tor-dev/attachments/20130528/3a74fc01/attachment.html>


More information about the tor-dev mailing list