usenix conference policies
Security Audit of Safeplug "Tor in a Box"
Anne Edmundson, Anna Kornfeld Simpson, Joshua A. Kroll, and Edward W. Felten, Princeton University
We present the first public third-party security audit of Pogoplug’s Safeplug device, which markets “complete security and anonymity online” by using Tor technology to protect users’ IP addresses. We examine the hardware, software, and network behavior of the Safeplug device, as well as the user experience in comparison to other forms of web browsing. Although the Safeplug appears to use Tor as advertised, users may still be identified in ways they may not expect. Furthermore, an engineering vulnerability in how the Safeplug accepts settings changes would allow an adversary internal or external to a user’s home network to silently disable Tor or modify other Safeplug settings, which completely invalidates the security claims of the device. Beyond this problem, the user experience challenges of this type of device make it inferior to the existing gold standard for anonymous browsing: the Tor Browser Bundle.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Anne Edmundson and Anna Kornfeld Simpson and Joshua A. Kroll and Edward W. Felten},
title = {Security Audit of Safeplug "Tor in a Box"},
booktitle = {4th USENIX Workshop on Free and Open Communications on the Internet (FOCI 14)},
year = {2014},
address = {San Diego, CA},
url = {https://www.usenix.org/conference/foci14/workshop-program/presentation/edmundson},
publisher = {USENIX Association},
month = aug
}
connect with us