Fair 'nuff.
Yup yup yup. And a couple more yups.
We agree on a fundamental principal, there is no black and white. In this day and age IP banning is like Han Solo with a blaster when we need a more elegant weapon, but it gets the job done.
BTW, do you happen to have a source for tor and i2p interconnect or routing nodes? Entrance and exit are easy, itâs the stuff in between that is hard to track.
It was pretty funny the first year defcon moved to the Rio, and every ATM and elevator was pwned on day one. Well, funny to me, I was staying somewhere else.
I donât, but Iâm not sure why youâd need it, either? If the node doesnât have an exit policy than it isnât routing traffic outside of Tor (and as a result isnât going to hit BBS).
Letâs just say I have $reasons. But it is God awful hard to trace, unless you bribe ask nicely for netflow or router log data.
and most reasons are Not Nice, even academia has no ethical problems doing attacks research (c.f. CMUâs SEI)
The main reason I track onion routing and crypto currencies isnât because there is anything inherently wrong with them. It is because libraries bundled with malware commonly tunnel via protocols such as tor, and very commonly use computer power in crypto currency pools.
So answering the question, are there tor transit flows on my network, is really a proxy question for, Are there compromised hosts on my network.
Onion routing is neither bad or good. It is just traffic. But I sure as shit want to know if VPCs in my DC are forwarding certain kinds of trafficâcause they should never do that. Being able to answer that question is literally a multi billion dollar issue.
Disturb, disrupt, disengage, disease, dissolve, disavow, dispense, disgrace. Loads of possibilities.
I have a suggestion regarding your visualisation. (And no, I donât want to derail. Thereâs the Peterâs projection thread for that.)
It was crude, linear, and slapdash. I appreciate the link, I suspect this wonât be the last geo infosec dashboard I develop
This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.