Gaetano Zappulla's weblog



Un blog, non tecnico, su tutto quello che mi passa per la testa e voglio che sia pubblico. Queste opinioni e/o segnalazioni non rispecchiano per nulla quelle delle societa' per cui lavoro.

May 11, 2010 2:19 pm
Compromising Tor Anonymity Exploiting P2P Information Leakage

Un lavoro molto interessante:

Privacy of users in P2P networks goes far beyond their current usage and is a fundamental requirement to the adop- tion of P2P protocols for legal usage. In a climate of cold war between these users and anti-piracy groups, more and more users are moving to anonymizing networks in an at- tempt to hide their identity. However, when not designed to protect users information, a P2P protocol would leak in- formation that may compromise the identity of its users. In this paper, we first present three attacks targeting BitTorrent users on top of Tor that reveal their real IP addresses. In a second step, we analyze the Tor usage by BitTorrent users and compare it to its usage outside of Tor. Finally, we depict the risks induced by this de-anonymization and show that users’ privacy violation goes beyond BitTorrent traffic and contaminates other protocols such as HTTP.

Compromising Tor Anonymity Exploiting P2P Information Leakage