Why We Need a Dark(er) Web

77
WHY WE NEED A DARK(ER) WEB JEROEN BAERT – CHECKUP 2017

Transcript of Why We Need a Dark(er) Web

Page 1: Why We Need a Dark(er) Web

WHY WE NEED A DARK(ER) WEBJEROEN BAERT –CHECKUP 2017

Page 2: Why We Need a Dark(er) Web

ABOUT ME

• Engineer – Computer Scientist

• Phd Student (Computer Graphics @ KU Leuven)

• Improv / Stand-up Comedian

• (Belgian Improv League)

• jeroen-baert.be & forceflow.be

• PGP: 30F2 857D 9129 3519

Page 3: Why We Need a Dark(er) Web

MY RESEARCH: GRAPHICS! ALL THE GRAPHICS!

• Out-of-core construction and visualization of Sparse Voxel Octree

structures on modern GPU hardware

Page 4: Why We Need a Dark(er) Web

BAD NEWS EVERYONE

Page 5: Why We Need a Dark(er) Web

TALK OVERVIEW

• Why the internet is broken

• Why a “dark web” is a possible solution

• What you can do

Page 6: Why We Need a Dark(er) Web

THE INTERNET IS BROKEN BECAUSE OF TRACKING

• WWW evolution:

• Open, free source of information

• Ad-infested cesspool

• Websites / apps serve

• Advertisements

• Trackers

Page 7: Why We Need a Dark(er) Web

THE INTERNET IS BROKEN BECAUSE OF TRACKING

• GOAL: Profile & identify you and

your habits

• Over multiple services and websites

• Without knowledge or consent

• Sell information for targeting

purposes

https://boingboing.net/2015/10/05/botwars-vs-ad-tech-the-origin.html

Page 8: Why We Need a Dark(er) Web

TRACKING & CONTENT

• Content is not free

• You pay with your private data

• Content has become delivery method for ads & trackers

• “If you’re not paying, you are the product”

Page 9: Why We Need a Dark(er) Web

TRACKING – FLEMISH NEWS SITES

• Experiment:

• 4 popular news websites (HLN, DM, DS, HNB)

• Load homepage once (in fresh VM every time)

• Register # connections to 3rd-party servers

• Wireshark & Firefox+Lightbeam

Page 10: Why We Need a Dark(er) Web

TRACKING – FLEMISH NEWS SITES

• Results:

• +40 connections to 3rd party trackers/ads

• Often located in other countries

• Little or no info for end user

• Privacy policies: vague/non-existent

Page 11: Why We Need a Dark(er) Web

TRACKING – FLEMISH NEWS SITES

Full report: http://www.forceflow.be/2017/08/02/tracking-be-2017/

Page 12: Why We Need a Dark(er) Web

TRACKING – FLEMISH NEWS SITES

Page 13: Why We Need a Dark(er) Web

TRACKING – FLEMISH NEWS SITES

Page 14: Why We Need a Dark(er) Web

TRACKING – FLEMISH NEWS SITES

• Additional cost:

• Bandwidth (Money)

• Battery

• Time

Page 15: Why We Need a Dark(er) Web

TRACKING – FLEMISH NEWS SITES

• Some trackers on multiple sites

• Track your entire morning routine

• Journalism = Bait

• Not only (these) news sites

Page 16: Why We Need a Dark(er) Web

TRACKING – PEOPLE FARMERS

• Facebook = “People Farmer” (Aral Balkan, 2016)

• Build advertising profile

• Everywhere you see

• Offer functionality (likes, comments, ...)

• In exchange for tracking

• “Behavioral Advertising Tech”

Page 17: Why We Need a Dark(er) Web

TRACKING – PEOPLE FARMERS

https://www.theguardian.com/technology/2017/may/01/facebook-advertising-data-insecure-teens

Page 18: Why We Need a Dark(er) Web

TRACKING – BIG DATA = BIG BUSINESS

• Cambridge Analytica

• Buy/Collect massive amounts of data

• Sources: Social media, web trackers, ...

• Data mining / analysis

• Psychographic profiling

• Political Microtargeting

Page 19: Why We Need a Dark(er) Web

TRACKING – CAMBRIDGE ANALYTICA

• Booming business

• Because of state WWW is in

• No legal framework

• (2018) GDPR?

• Enforcement?

https://www.theguardian.com/technology/2017/may/07/the-great-british-brexit-robbery-hijacked-democracy

Page 20: Why We Need a Dark(er) Web

POLITICAL MICROTARGETING

Adam Curtis – Hypernormalization (2016)

Page 21: Why We Need a Dark(er) Web

AD/TRACKER BLOCKING

• Yes, there are ad/tracker-blockers

• Some good, some bad

• Need some technical skills to use

• Treating symptom, not disease

• Never-ending arms race

• Will not lead to structural change

Page 22: Why We Need a Dark(er) Web

TRACKING - CONCLUSION

Adtech has transformed the WWW, and current technology and

protocols allow easy collection and storage of vast amounts of data

Page 23: Why We Need a Dark(er) Web

TALK OVERVIEW

• Why the internet is broken

• Tracking

• Why a “dark web” is a possible solution

• What you can do

Page 24: Why We Need a Dark(er) Web

INTERNET IS BROKEN BECAUSE OF CENSORSHIP

• Lots of WWW services = centralized

• Easy to filter / censor

• At local / ISP/ nation level

• Techniques

• DNS hijacking

• (Deep) Packet Inspection

• ...

Page 25: Why We Need a Dark(er) Web

CENSORSHIP - TURKEY

• Communication censorship

• Protests 2016: National shutdown of

social media

• Blackholing at ISP level

• Sharing Erdogan cartoons = internet

block

• Similar incidents in Egypt, Iran,...

Page 26: Why We Need a Dark(er) Web

CENSORSHIP - CHINA

• Knowledge censorship

• “Great firewall of China”

• No Wikipedia

• No “Tiananmen Square”

Page 27: Why We Need a Dark(er) Web

CENTRALIZATION – DEMOCRACY RISK

• Catalonia Referendum (2017)

• Raid on registrar .cat

• To censor referendum info

• Forced ISP’s to blacklist essential

vote system IP’s

• Several voting offices disabled

Page 28: Why We Need a Dark(er) Web

CENTRALIZATION – BUSINESS RISK

• October 2016

• Infected IoT devices (Mirai Worm)

• DDoS attack on Dyn.org (DNS provider)

• Twitter, Paypal, Spotify, ... down

Page 29: Why We Need a Dark(er) Web

CENTRALIZATION - SOCIAL MEDIA PLATFORMS

• For a lot of people, WWW = Social media

• A few private companies decide

• What you see

• When you see it

• How long you can see it

• Who you can share it with

• Billion of eggs, handful of baskets

Page 30: Why We Need a Dark(er) Web

TALK OVERVIEW

• Why the internet is broken

• Tracking

• Censorship

• Why a “dark web” is a possible solution

• What you can do

Page 31: Why We Need a Dark(er) Web

THE INTERNET IS BROKEN BY DESIGN

• Not designed with PRIVACY in mind

• Not designed with ANONIMITY in mind

Page 32: Why We Need a Dark(er) Web

PRIVACY & ANONIMITY

• Important for everyone

• Regular users (protect personal life)

• Journalists (sources)

• Whistleblowers (identity)

• Companies (communication & trade secrets)

• ...

Page 33: Why We Need a Dark(er) Web

PRIVACY & ANONIMITY

• Tim Berners-Lee, 2016:

“Sites you visit tell your own intimate story.

Internet history should never be tracked.”

• US Congress, 2016:

ISP’s are allowed to sell your internet history

Page 34: Why We Need a Dark(er) Web

TRACKING - TECHNICAL

• Browsing the internet = leaking information

• HTTP + Javascript make collection easy

• Unique fingerprint:

• IP, location, network

• OS/Browser version, plug-ins, local time

• Screen size, cursor positions, settings

• ...

Page 35: Why We Need a Dark(er) Web

AMIUNIQUE.ORG

Page 36: Why We Need a Dark(er) Web

TALK OVERVIEW

• Why the internet is broken

• Tracking

• Censorship

• Anonimity / Privacy

• Why a “dark web” is a possible solution

• What you can do

Page 37: Why We Need a Dark(er) Web

CONCLUSION

• The internet is a wonderful place

• But by design, makes it easy to track,

censor and identify users

• Need alternative, different network

with better privacy properties

Page 38: Why We Need a Dark(er) Web

ENTER...

THE DARK WEB

Page 39: Why We Need a Dark(er) Web

THE “DARK WEB”

• A lot of misconceptions

• Blame:

• Media

• Politics

• Technical nature

• Confusing terminology

Page 40: Why We Need a Dark(er) Web

THE “DARK WEB”

• Interesting from a privacy & anonimity PoV

• Solution to (some of) our problems?

Page 41: Why We Need a Dark(er) Web

“DARK WEB” VS “NORMAL WEB”

• Traditional explanation:

• Surface web

• Deep web

• Dark web

• Better explanation:

• Dark web is parallel to all

DARKWEB

Page 42: Why We Need a Dark(er) Web

DARK WEB(S)

• No such thing as one dark web

• Alternative networks focused on

privacy/anonimity:

• Tor (The Onion Router)

• I2P Project

• Freenet

• Zeronet

• ...

Page 43: Why We Need a Dark(er) Web

QUESTION

• I have never heard of Tor

• I have heard of Tor

• I know Tor as the thing people use to get around my company firewall

• I buy drugs using Tor

• I am a Tor developer

Page 44: Why We Need a Dark(er) Web

TOR: THE ONION ROUTER

• Most popular & well-known

• Open-Source

• Originally developed by DARPA (US)

• Now: Nonprofit org

• Unrelated to torrents

• Network nodes run by volunteers

• Exit nodes to surface web

Page 45: Why We Need a Dark(er) Web

TOR: NODE TYPES

Page 46: Why We Need a Dark(er) Web

TOR: HOW IT WORKS (1)

Page 47: Why We Need a Dark(er) Web

TOR: HOW IT WORKS (2)

Page 48: Why We Need a Dark(er) Web

TOR: ENCRYPTION

Page 49: Why We Need a Dark(er) Web

TOR: HOW IT WORKS (3)

Page 50: Why We Need a Dark(er) Web

TOR: PROTECTING YOUR ANONIMITY

• Original IP never revealed

• No logs

• Strong encryption

• New circuit for every site

• No cross-site tracking

Page 51: Why We Need a Dark(er) Web

TOR: HIDDEN SERVICES

• Tor Hidden services

• “Rendezvous point”

• “Invisible” hosting

• Only accessible through Tor

Page 52: Why We Need a Dark(er) Web

TOR: HOW IT THWARTS CENSORSHIP

• No way of knowing where hidden service is hosted

• Takedown notice = where to send?

• Everyone can publish : no central authority

• Censorship impossible by design

Page 53: Why We Need a Dark(er) Web

TOR: HOW IT THWARTS CENSORSHIP (2)

• Link to surface web

• Exit nodes in various

countries

• Tor traffic can be disguised

• As Skype call, regular

browsing ...

• Very hard to filter: arms race

Page 54: Why We Need a Dark(er) Web

TOR NETWORK: USERS

Page 55: Why We Need a Dark(er) Web

TOR NETWORK: CURRENT STATUS

Page 56: Why We Need a Dark(er) Web

TOR NETWORK: CURRENT STATUS

Page 57: Why We Need a Dark(er) Web

THE “DARK WEB” IS NOT ILLEGAL

• Using or running an alternative network is not illegal

• You are simply using a different

• communication protocol

• way to exchange information

• way of processing data

• Like you already do for a lot of things!

• E-mail: POP3/IMAP

Page 58: Why We Need a Dark(er) Web

THE “DARK WEB” IS NOT ILLEGAL

• Media get it wrong all the time

Page 59: Why We Need a Dark(er) Web

THE “DARK WEB” IS NOT ILLEGAL

• Professionals get it wrong all the time

Page 60: Why We Need a Dark(er) Web

THE “DARK WEB” AND CRIMINALITY

• Alternative networks are not exclusively

used by criminals

• Technology is inherently neutral

• Lots of useful services:

• Webhosting / blogging platforms

• File storage

• E-mail

• ...

Page 61: Why We Need a Dark(er) Web

THE “DARK WEB” AND CRIMINALITY

• What about ...

• Drugs? Guns? Fake Ids? Terrorist forums? Hitmen?

• Same % of services on surface web

• A lot of scams

• Anonimity + cryptocurrencies

• Hidden web is actually tiny

• 7k – 30k sites = 0.03% of surface web

Page 62: Why We Need a Dark(er) Web

THE “DARK WEB” AND CHILD PORNOGRAPHY

• CP is a problem on every network

• Research by Internet Watch Foundation (2015)

• 31k CP URL’s

• 51 (0.02%) on a Dark Web

• Need to break association Dark Web<->CP

• Without ignoring/minimalizing CP problem

Page 63: Why We Need a Dark(er) Web

IS TOR INFALLIBLE ?

• Nothing is

• Tor Browser exploits

• Get patched quickly

• Malicious nodes

• Network monitoring

• Peer voting

Page 64: Why We Need a Dark(er) Web

IS TOR INFALLIBLE: MARKET BUSTS

• Silk Road, AlphaBay, ...

• Admins got arrested, sites closed

• Tor fail?

• Admin fail:

• Re-using e-mail / passwords

• Paper trail

• Reckless bragging

• Bad service configuration

Page 65: Why We Need a Dark(er) Web

START USING TOR

• Using a Dark Web does not require advanced tech knowledge

• Go to www.torproject.org

• Download the Tor Browser bundle

• Install

• Go!

Page 66: Why We Need a Dark(er) Web

TOR BROWSER BUNDLE

• Custom version of Firefox

• Great browser

• Pre-configured for Tor

• Masked fingerprint

• Scripts blocked by default

• Auto-updater

• HTTPS everywhere

• Safe out-of-the-box

Page 67: Why We Need a Dark(er) Web

TOR ON MOBILE

• Android: Orbot + OrFox

• In Play Store

• VPN for all traffic

• Free

• iOS: Onion browser

• In App Store

• Free

Page 68: Why We Need a Dark(er) Web

MAYBE START USING IT...

• On public networks?

• All the time?

• More users = more diversity = safer network

Page 69: Why We Need a Dark(er) Web

HEY SYSADMINS, LISTEN UP

Page 70: Why We Need a Dark(er) Web

SYSADMINS & TOR

• Don’t block Tor usage on your network

• Don’t block Tor exit nodes

• Mitigate abuse using CAPTCHA

• If you use Cloudflare: explicitly allow Tor

• See Tor abuse FAQ:

https://www.torproject.org/docs/faq-abuse.html.en

Page 71: Why We Need a Dark(er) Web

SYSADMINS & TOR

• Run a TOR node!

• On VPS / dedicated

• You can limit bandwidth / ports

• (only 80 / 443, for example)

• Donate @ torservers.net

Page 72: Why We Need a Dark(er) Web

MEDIA / PRESS

• Offer your site as Hidden Service

• Set up SecureDrop for communication

Page 73: Why We Need a Dark(er) Web

EVERYONE ELSE

• Programmers / Writers /

Educators / Designers / ...

• Development

• Documentation

• Education

• Discussion

• Promotion

• Legal assistance

Page 74: Why We Need a Dark(er) Web

AND YOU...

• Try it!

• Spread the word

• Educate friends, family & colleagues

• Talk to your IT departement

• “Well Actually” when you hear misconceptions

Page 75: Why We Need a Dark(er) Web

IT DOESN’T STOP AT TOR

• Just an example of tech that can help us

• More decentralization needed:

• Mastodon

• Diaspora

• IPFS (Distributed Web)

Page 76: Why We Need a Dark(er) Web

THE INTERNET IS A MIRROR THAT REFLECTS THE SOCIETY WE LIVE IN. IF YOU DON’T LIKE WHAT YOU SEE, DON’T JUST BREAK THE MIRROR.

Vint Cerf, co-inventor WWW

Page 77: Why We Need a Dark(er) Web

THANK YOUQUESTIONS? [email protected] - @JBAERT