What Fraud Examiners Need to Know About Tor
Jan 01, 0001
Jan 01, 0001
Tor is software designed to provide users with anonymity and security in some online communications.
Security, Anonymity and Cybercrime
By Jacob Parks, J.D., CFE
November 2014
When criminals use online tools to commit fraud, the investigation often involves looking for whatever digital traces they might have left behind. One of the most important clues in these searches is the Internet Protocol (IP) address. Through subpoenas to service providers, both law enforcement and private parties might be able to match a user’s IP address to an account holder, which can be used as evidence to identify the perpetrator.
However, because of tools like Tor, these clues are not always useful. If IP addresses are the fingerprints of the Internet, then Tor is a pair of gloves. It is a neutral device that can be used for good and evil, and fraud examiners should be aware of its potential effect in investigations.
Like the Layers of an Onion
Tor is software designed to provide users with anonymity and security in some online communications. It also allows them to access certain websites and services on the Deep Web. The U.S. Naval Research Laboratory developed the core concept behind Tor for government agents to send communications anonymously and securely. Later, a group of researchers (with the Navy’s permission) created the Tor Project, which provided free and openly accessible software for private parties and other government agencies to enhance the anonymity and security of their communications. The term Tor derives from the acronym of “the onion router,” which metaphorically compares the layers of an onion to the way in which the network provides layers of encryption to communications.
Users download the Tor Browser, which has basic functions similar to other Internet browsers. It works by sending a user’s online communications, such as a text-based message or a website request, through a network of volunteered computers around the world. Individuals and organizations donate the use of their computers to serve as message “relays.” However, the messages have multiple layers of encryption, making it so that the first relay that receives the message knows the sender’s IP address, but does not know the encrypted contents of the message. The first relay also knows to pass the message on to a second particular relay.
The second relay peels back another layer of encryption before passing the message on to the next relay, which peels back another layer, passes it on and so on. This process occurs several times, and the relays in this stage each only know from whom they received the encrypted message and where to send it next. Eventually, the message reaches the “exit relay,” in which the content of the message is decrypted. The exit relay forwards the message to the original sender’s intended recipient. The only IP address the recipient can see is that of the exit relay. If the recipient wishes to establish an active connection with the sender, then communications travel in reverse through the Tor network, with a similar encryption process.
The result is that, theoretically, no relays in the system (or potential eavesdroppers) know both the content of the message and the original sender. Meanwhile, the recipient knows the content of the message, but does not know the IP address of the original sender. However, users must keep in mind that the exit relay can view the message, so usernames, passwords and other sensitive data will be viewable to that relay (and potentially other parties such as law enforcement and Internet service providers) unless HTTPS is used. The Electronic Frontier Foundation provides a graphic to illustrate the security differences in using Tor, HTTPS, both or neither.
Uses of Tor
There are several methods for trying to remain anonymous online, but Tor is one of the most popular because it offers the security and speed that some other tools lack. In a leaked report obtained by The Guardian from Edward Snowden, the U.S. National Security Agency (NSA) characterized Tor as “the king of high-secure, low-latency Internet anonymity.” The documents also included descriptions of various ways that the NSA has tried to defeat the anonymity and security aspects of Tor, but concluded that the network’s integrity remains largely intact.
Given its anonymous properties, Tor is attractive to cybercriminals. Hidden service providers that operate through sites that are only accessible by using Tor are notorious for providing illegal goods and services. These sites are recognizable by their .onion addresses. One of the most popular Tor hidden services was the first Silk Road, which was commonly described as the “eBay of drugs” before it was shut down (I say first because there has since been at least one copycat of the Silk Road). It is not just illegal substances that are available through Tor hidden services, but also malicious malware and hacking tools that can be used by fraudsters.
However, using Tor is not illegal and it actually has many benefits from an anti-fraud perspective, including:
Allowing anonymous research of sensitive data
Undercover operations that involve online criminal networks
Communicating as a whistleblower with a greater degree of anonymity
Reducing the risk of identity theft when using online services
Reducing the likelihood of eavesdropping by malicious parties and data breaches during online communications
Providing hidden services that allow for secure channels of communication
Circumventing censorship by oppressive governments
Researching data that is only available at specific parts of the Deep Web
Notable Issues
While Tor is generally considered a strong privacy and security option, it does have limitations and is prone to user error. For instance, misconfiguring the browser can result in a loss of anonymity and vulnerability to eavesdroppers. However, this sword cuts both ways. Recalling the Silk Road investigation, the FBI was able to exploit a flaw in the server’s Tor configurations, leading to a leaked IP address. With that data, they quickly determined that the server was located in Iceland. The Tor Project offers guidance that can help users install and properly configure the Tor Browser.
Another common mistake that criminals make is to inadvertently leave hints about their identity when using hidden services, such as through messages, pictures and other clues that can be linked to the person’s actual identity. For instance, a perpetrator might get careless and create a username on a website that is identical to an email login that he created in the past when he was not using IP-masking tools. Crumbs of evidence like that can lead to a more targeted investigation and possibly a positive identification.
Fraud examiners who deal with cybercrime should be familiar with how Tor works and how it might affect an investigation. While it can be an obstacle for identifying perpetrators, it also proves useful in many investigations and other anti-fraud activities.