<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: TOR is&#160;hiring</title>
	<atom:link href="http://boingboing.net/2012/04/20/tor-is-hiring.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2012/04/20/tor-is-hiring.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Sat, 25 May 2013 07:36:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Ant</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1402218</link>
		<dc:creator>Ant</dc:creator>
		<pubDate>Sun, 22 Apr 2012 18:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1402218</guid>
		<description>I thought this was about SW:TOR!</description>
		<content:encoded><![CDATA[<p>I thought this was about SW:TOR!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oasisob1</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401904</link>
		<dc:creator>oasisob1</dc:creator>
		<pubDate>Sun, 22 Apr 2012 02:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401904</guid>
		<description>Wasn&#039;t a paper already published proving that a sufficient number of TOR nodes owned by any one entity was enough to identify all the end users, or at the very least, end users of interest? </description>
		<content:encoded><![CDATA[<p>Wasn&#8217;t a paper already published proving that a sufficient number of TOR nodes owned by any one entity was enough to identify all the end users, or at the very least, end users of interest? </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MarcVader</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401835</link>
		<dc:creator>MarcVader</dc:creator>
		<pubDate>Sun, 22 Apr 2012 01:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401835</guid>
		<description> Instead of going to bed I read your comments twice and all I can say right now is: Your dystopia beats my dystopia. You make a frighteningly good point about pre-existing backdoors, peppered with evidence of non-average understanding of implementation details. Thank you. And now I really need to sleep. </description>
		<content:encoded><![CDATA[<p> Instead of going to bed I read your comments twice and all I can say right now is: Your dystopia beats my dystopia. You make a frighteningly good point about pre-existing backdoors, peppered with evidence of non-average understanding of implementation details. Thank you. And now I really need to sleep. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bardfinn</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401769</link>
		<dc:creator>bardfinn</dc:creator>
		<pubDate>Sat, 21 Apr 2012 23:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401769</guid>
		<description>Apologies for the grammar deficiencies — My son just discovered that bouncing off Daddy is hi-larious. </description>
		<content:encoded><![CDATA[<p>Apologies for the grammar deficiencies — My son just discovered that bouncing off Daddy is hi-larious. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bardfinn</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401752</link>
		<dc:creator>bardfinn</dc:creator>
		<pubDate>Sat, 21 Apr 2012 22:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401752</guid>
		<description>That creates a serious hurdle to creating a secure implementation of TOR that widespread users, technically inclined or not, will feel comfortable in using. The Windows OS will complain that the software being installed isn&#039;t signed (as far as it cares). It&#039;ll do that twice, spooking casual users -- that is, if it even allows the installation of unsigned code that runs in &quot;kernel mode/ring 0&quot;, and/or the user knows how to shut that off. For technically inclined users, they&#039;ll have to download the binaries on a secure platform, fingerprint and verify signatures there, copy the binaries to the Windows machine, occasionally audit the image in memory by inducing a core dump and verifying it isn&#039;t compromised, and praying that Windows doesn&#039;t come packaged with a bit of code that specially recognises TOR and inserts a trampoline into the memory image to tamper with it on the fly.
The problems with using an untrusted and untrustable computing platform.</description>
		<content:encoded><![CDATA[<p>That creates a serious hurdle to creating a secure implementation of TOR that widespread users, technically inclined or not, will feel comfortable in using. The Windows OS will complain that the software being installed isn&#8217;t signed (as far as it cares). It&#8217;ll do that twice, spooking casual users &#8212; that is, if it even allows the installation of unsigned code that runs in &#8220;kernel mode/ring 0&#8243;, and/or the user knows how to shut that off. For technically inclined users, they&#8217;ll have to download the binaries on a secure platform, fingerprint and verify signatures there, copy the binaries to the Windows machine, occasionally audit the image in memory by inducing a core dump and verifying it isn&#8217;t compromised, and praying that Windows doesn&#8217;t come packaged with a bit of code that specially recognises TOR and inserts a trampoline into the memory image to tamper with it on the fly.<br />
The problems with using an untrusted and untrustable computing platform.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bardfinn</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401751</link>
		<dc:creator>bardfinn</dc:creator>
		<pubDate>Sat, 21 Apr 2012 22:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401751</guid>
		<description>In tl;dr:

The US government doesn&#039;t want to install any software backdoors. They gave up trying that in Clinton&#039;s administration. They just want to know whether any backdoors they might already be using are discovered, or are compromised.
If they wanted to find weaknesses in a released implementation, they can do that while circumventing any need for direct access to TOR&#039;s team. 

Any useful implementation of TOR on the Windows platform would need to bypass the Windows encryption API altogether, because of _NSAKEY — there&#039;s zero cryptographic trust in Windows&#039; architecture. It would need to be signed independently of Windows&#039; architecture. That will require any Windows implementation to have a low-level cryptography interface that differs in structure and method from, say, a *NIX implementation, where the trustedness of the OS&#039; APIs can be verified, independently, and don&#039;t contain a known backdoor for which no one is practically or legally accountable.</description>
		<content:encoded><![CDATA[<p>In tl;dr:</p>
<p>The US government doesn&#8217;t want to install any software backdoors. They gave up trying that in Clinton&#8217;s administration. They just want to know whether any backdoors they might already be using are discovered, or are compromised.<br />
If they wanted to find weaknesses in a released implementation, they can do that while circumventing any need for direct access to TOR&#8217;s team. </p>
<p>Any useful implementation of TOR on the Windows platform would need to bypass the Windows encryption API altogether, because of _NSAKEY — there&#8217;s zero cryptographic trust in Windows&#8217; architecture. It would need to be signed independently of Windows&#8217; architecture. That will require any Windows implementation to have a low-level cryptography interface that differs in structure and method from, say, a *NIX implementation, where the trustedness of the OS&#8217; APIs can be verified, independently, and don&#8217;t contain a known backdoor for which no one is practically or legally accountable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bardfinn</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401748</link>
		<dc:creator>bardfinn</dc:creator>
		<pubDate>Sat, 21 Apr 2012 22:11:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401748</guid>
		<description>Presumably, as their core demographic is tech-savvy privacy-conscious open-source aficionadoes, there would (will be) a large contingency of people who would be (will be) compiling the source code with all types of compiler directives on all platforms and then further fuzzing the results.
So, if there&#039;s an inside position here for the us government, it would likely be in discovering whether anyone on this team discovers any existing backdoor systems.

Given that the us government has an electrical engineering group dedicated to manufacturing and certifying backdoor-free hardware for us government use, then it&#039;s also quite likely that they&#039;re not hoping the TOR team is going to stumble across a backdoor system the USG doesn&#039;t already know is in existence. 
If the US govt has a hand in the TOR team, it would be to find out whether someone on the TOR team, while developing a software-based surveillance-avoidance system, finds evidence of an existing hardware-based surveillance system. 
The USG wouldn&#039;t be looking to find anyone&#039;s surveillance system or place one, through TOR. They&#039;d be looking to find out if one that is already in place had been discovered, and what intel they could use to prevent that information from being spread.</description>
		<content:encoded><![CDATA[<p>Presumably, as their core demographic is tech-savvy privacy-conscious open-source aficionadoes, there would (will be) a large contingency of people who would be (will be) compiling the source code with all types of compiler directives on all platforms and then further fuzzing the results.<br />
So, if there&#8217;s an inside position here for the us government, it would likely be in discovering whether anyone on this team discovers any existing backdoor systems.</p>
<p>Given that the us government has an electrical engineering group dedicated to manufacturing and certifying backdoor-free hardware for us government use, then it&#8217;s also quite likely that they&#8217;re not hoping the TOR team is going to stumble across a backdoor system the USG doesn&#8217;t already know is in existence.<br />
If the US govt has a hand in the TOR team, it would be to find out whether someone on the TOR team, while developing a software-based surveillance-avoidance system, finds evidence of an existing hardware-based surveillance system.<br />
The USG wouldn&#8217;t be looking to find anyone&#8217;s surveillance system or place one, through TOR. They&#8217;d be looking to find out if one that is already in place had been discovered, and what intel they could use to prevent that information from being spread.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MarcVader</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401499</link>
		<dc:creator>MarcVader</dc:creator>
		<pubDate>Sat, 21 Apr 2012 09:40:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401499</guid>
		<description>If I were in the intelligence business I would make it a very high priority to get one of my guys hired for this position!
First objective: infiltration and information gathering over a long time period. Second objective: I can haz backdoor, yes?</description>
		<content:encoded><![CDATA[<p>If I were in the intelligence business I would make it a very high priority to get one of my guys hired for this position!<br />
First objective: infiltration and information gathering over a long time period. Second objective: I can haz backdoor, yes?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SedanChair</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401446</link>
		<dc:creator>SedanChair</dc:creator>
		<pubDate>Sat, 21 Apr 2012 04:53:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401446</guid>
		<description>Just so</description>
		<content:encoded><![CDATA[<p>Just so</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antinous / Moderator</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401437</link>
		<dc:creator>Antinous / Moderator</dc:creator>
		<pubDate>Sat, 21 Apr 2012 04:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401437</guid>
		<description>Oxymoronically?</description>
		<content:encoded><![CDATA[<p>Oxymoronically?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SedanChair</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401431</link>
		<dc:creator>SedanChair</dc:creator>
		<pubDate>Sat, 21 Apr 2012 04:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401431</guid>
		<description>Probably not, but I know how intelligence agencies work in 2012...</description>
		<content:encoded><![CDATA[<p>Probably not, but I know how intelligence agencies work in 2012&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jacklaughing</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401429</link>
		<dc:creator>jacklaughing</dc:creator>
		<pubDate>Sat, 21 Apr 2012 04:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401429</guid>
		<description>You *really* don&#039;t know how the technology world works in 2012, do ya?</description>
		<content:encoded><![CDATA[<p>You *really* don&#8217;t know how the technology world works in 2012, do ya?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SedanChair</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401422</link>
		<dc:creator>SedanChair</dc:creator>
		<pubDate>Sat, 21 Apr 2012 03:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401422</guid>
		<description>White person hired=&quot;technology job&quot;
Brown person with funny name hired=&quot;aiding and abetting terrorism&quot;</description>
		<content:encoded><![CDATA[<p>White person hired=&#8221;technology job&#8221;<br />
Brown person with funny name hired=&#8221;aiding and abetting terrorism&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oasisob1</title>
		<link>http://boingboing.net/2012/04/20/tor-is-hiring.html#comment-1401367</link>
		<dc:creator>oasisob1</dc:creator>
		<pubDate>Sat, 21 Apr 2012 01:13:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=155750#comment-1401367</guid>
		<description>Oh, man! I thought you meant TOR Books. Dang.</description>
		<content:encoded><![CDATA[<p>Oh, man! I thought you meant TOR Books. Dang.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
