usenix conference policies
Security Audit of Safeplug "Tor in a Box"
Website Maintenance Alert
Due to scheduled maintenance, the USENIX website may not be available on Monday, March 17, from 10:00 am–6:00 pm Pacific Daylight Time (UTC -7). We apologize for the inconvenience and thank you for your patience.
If you would like to register for NSDI '25, SREcon25 Americas, or PEPR '25, please complete your registration before or after this time period.
Anne Edmundson, Anna Kornfeld Simpson, Joshua A. Kroll, and Edward W. Felten, Princeton University
We present the first public third-party security audit of Pogoplug’s Safeplug device, which markets “complete security and anonymity online” by using Tor technology to protect users’ IP addresses. We examine the hardware, software, and network behavior of the Safeplug device, as well as the user experience in comparison to other forms of web browsing. Although the Safeplug appears to use Tor as advertised, users may still be identified in ways they may not expect. Furthermore, an engineering vulnerability in how the Safeplug accepts settings changes would allow an adversary internal or external to a user’s home network to silently disable Tor or modify other Safeplug settings, which completely invalidates the security claims of the device. Beyond this problem, the user experience challenges of this type of device make it inferior to the existing gold standard for anonymous browsing: the Tor Browser Bundle.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Anne Edmundson and Anna Kornfeld Simpson and Joshua A. Kroll and Edward W. Felten},
title = {Security Audit of Safeplug "Tor in a Box"},
booktitle = {4th USENIX Workshop on Free and Open Communications on the Internet (FOCI 14)},
year = {2014},
address = {San Diego, CA},
url = {https://www.usenix.org/conference/foci14/workshop-program/presentation/edmundson},
publisher = {USENIX Association},
month = aug
}
connect with us