Live data from Hacker News

Tor: From the Dark Web to the Future of Privacy

direct.mit.edu

11–20 of 100 posts

Re: Tor: From the Dark Web to the Future of Privacy

#11
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

> What are the incentives for running a node?

It costs my ISP resources but I pay a flat rate. That would have value to me.

Re: Tor: From the Dark Web to the Future of Privacy

#12
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

There are no incentives for running a Tor node except altruism and the perhaps nebulous claim that by doing so you will be making the network better. There is nothing stopping a state actor controlling a large percentage of nodes thus increasing the likelihood that your anonymous communications are nothing of the sort.

Aren't there ways to filter out untrusted nodes?

(Edit: I say this, but in reality I also think it's pretty safe to assume most are government controlled)

Re: Tor: From the Dark Web to the Future of Privacy

#13
post #5

Earlier quoted context omitted.

What are your thoughts on the integrity of the network against state actors?

I assume that TOR is vulnerable to the 51% attack? If so I would imagine that state actors have the ability to spin up a million containers each hosting a node and easily take control (or at least be able to start tracing connection from entry to exit node). However Im sure this would be immediately obvious (unless they have been slowly doing this since the begining of TOR)

IIRC there is at least one known case where a moderately major criminal was let go rather than the government disclosing how they got the evidence on him. The assumption has been that they had a way of compromising TOR that they didn't want to reveal.

Re: Tor: From the Dark Web to the Future of Privacy

#14
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

Nothing at all stops that, and there's scarce incentive for independent node operators. Indeed, it is commonly surmised that many node operators have a hidden incentive: they're explicitly trying to control enough nodes to deanonymize traffic because they are law enforcement agencies.

Re: Tor: From the Dark Web to the Future of Privacy

#16
It seems, at the beginning of the 90s there were a lot of expectations in regard to DC-nets, considered to be a way better alternative to remailers of the time [1]. At least that's my impression after reading Tim May's FAQ (The Cyphernomicon) [2]. Any progress on this front?

[1]: https://en.wikipedia.org/wiki/Anonymous_remailer

[2]: https://hackmd.io/@jmsjsph/TheCyphernomicon

Re: Tor: From the Dark Web to the Future of Privacy

#17
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

People can do things altruistically - there doesn't always need to be a bitcoin-style monetary incentive. Lots of people run exit nodes because they believe in privacy and freedom of information. That said, you're absolutely right about large entities being able to control a large number of nodes, which is why a great number of nodes are controlled by governments trying to do so and also prevent foreign adversaries f…

> Lots of people run exit nodes because they believe in privacy and freedom of information.

I used to do that. But I've ultimately decided that the prospect of fighting accusations of abuse or crimes committed through my network wasn't that enticing. Proponents will try to downplay the risks by using vague ideological nonsense like "don't worry, an IP doesn't legally represent a person ;)" which, even if true, won't prevent a rather unpleasant ordeal.

Running a relay is likely fairly low-risk and still a good thing for the network, though.

Re: Tor: From the Dark Web to the Future of Privacy

#18
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

(with the understanding that I'm only speaking for what I found, not for the Tor project or the relay community)

Most of the people I spoke to saw themselves as providing a service - they wanted to help do something to bring a particular kind of future Internet about and found it rewarding to be a part of that. A number of them found the act of running a relay interesting and fun in itself - something they could get better at. Plus, membership of the relay community itself (especially now) is a kind of shared experience of community - and that's attractive to people in itself.

In terms of malicious actors, Tor does a lot to avoid this, from hunting down bad relays actively, monitoring the network as best as it can, continuously developing the algorithms which select routes through the network, and other mechanisms, like forcing relays to operate for a while before they get trusted with a lot of connections.

Re: Tor: From the Dark Web to the Future of Privacy

#19
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

There are no incentives. I'm pretty sure the vast majority does it for altruistic reasons. At least all those I've met. Many run relays with spare resources they pay for anyway. Others rent a cheap VPS to run a relay. $10 gives you a surprisingly large amount of bandwidth if you avoid the cloud like the plague.

Governments have other possibilities. Why should they run a relay if they can force the ISP to mirror the traffic of all relays to them?

Re: Tor: From the Dark Web to the Future of Privacy

#20

Cheers for this, I'm the author - AMA! :) A big motivation in writing the book was to feature the voices of the people we often don't hear from in the Tor community (which is why there's a whole chapter on the people who run the relays).

What are your thoughts on the integrity of the network against state actors?

There's a lot in the book about this - it depends what you mean. Tor has a lot of social and technical design elements that try as best they can to minimise this risk. It would be pretty hard for intelligence services to compromise the Tor organisation in ways that meant they were deploying malicious code, for example. Plus, the way it's grown over the years has also given them some protections.

In terms of deanonymising people through surveillance (for example, by spying on the whole Internet and tracing you through the Tor network), Tor explicitly doesn't protect you against this. The decision was made early on - they switched all the high-security design elements to 'off' to make the network faster. They calculated that a hyper-secure network that was so slow no-one used it was less secure - i.e. made less privacy exist in the real world - than one that was less secure but used by millions, because that would give you a huge crowd of people to hide in. This gets really complicated - because you also want lots of different kinds of people using the network, so they can't tell if you're a drug dealer, an activist, a spy etc. just because you're using Tor.

Individual bits of major intelligence organisations can probably deanonymise you at some times, and not at others. The real question is if they can do so in a way that's dangerous to you in a sustained way, and if it's actually useful for them to do this. Usually, it's easier to do this through simpler mechanisms (bribing your friends, putting a camera in your bedroom, figuring out who you are etc.) than compromising the Tor network. Some security services absolutely will be researching and developing ways to deanonymise larrge numbers of Tor users at a given time - but in general, the budget for this is going to be quite high on a per-user basis (so you'd have to be a prime target for it to be worth it), and a lot of the complexity of the Internet geography makes this quite hard itself.

Ultimately, for any given high value target, there are usually easier ways to get them than through breaking Tor. In almost every case, a person will make a basic OPSEC error long before mass-scale traffic analysis gets them.

Post reply on HN