C3Subtitles: 31c3: Tor: Hidden Services and Deanonymisation

Tor: Hidden Services and Deanonymisation

If you suspend your transcription on amara.org, please add a timestamp below to indicate how far you progressed! This will help others to resume your work!

Please do not press “publish” on amara.org to save your progress, use “save draft” instead. Only press “publish” when you're done with quality control.

Video duration
This talk presents the results from what we believe to be one of the largest studies into Tor Hidden Services (The Darknet) to date.

There is no public list of onion addresses available; instead, over a period of 6 months, we ran a large number of Tor relays to infiltrate the Distributed Hash Table which Hidden Services publish to. From this, we were able to collect the list of Tor onion addresses AND the number of requests for each site (e.g. loosely analogous to the number of visitors).

We then used a custom web crawler to crawl all the hidden services and pull a large set of information from each. From this, in this talk, we present a the information we found, from the list of the top onion addresses by content type and by popularity to estimates on size and turnover. We will also present what the largest proportion of Tor Hidden Service traffic is (it isn't pretty, and it's not drugs/silk road!).

Finally, I will explain the main classes of attacks useful for deanonymising the Hidden Services and Tor users. Sadly, it's easier than the Tor user-base at large think and thus far, there have been no patches or fixes for these attacks and there isn't likely to be because they exploit fundamental weaknesses in the way Tor works.

Talk ID
Saal 2
5:15 p.m.
Security & Hacking
Type of
Dr Gareth Owen

Talk & Speaker speed statistics

Very rough underestimation:
189.5 wpm
1036.2 spm
192.7 wpm
1051.3 spm
100.0% Checking done100.0%
0.0% Syncing done0.0%
0.0% Transcribing done0.0%
0.0% Nothing done yet0.0%

Talk & Speaker speed statistics with word clouds

Whole talk:
189.5 wpm
1036.2 spm
Dr Gareth Owen:
192.7 wpm
1051.3 spm