One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?
Tor: From the Dark Web to the Future of Privacy
61–70 of 100 posts
Re: Tor: From the Dark Web to the Future of Privacy
#62Earlier quoted context omitted.
What are your thoughts on the integrity of the network against state actors?
There's a lot in the book about this - it depends what you mean. Tor has a lot of social and technical design elements that try as best they can to minimise this risk. It would be pretty hard for intelligence services to compromise the Tor organisation in ways that meant they were deploying malicious code, for example. Plus, the way it's grown over the years has also given them some protections. In terms of deanonymi…
Re: Tor: From the Dark Web to the Future of Privacy
#63Earlier quoted context omitted.
There are no incentives for running a Tor node except altruism and the perhaps nebulous claim that by doing so you will be making the network better. There is nothing stopping a state actor controlling a large percentage of nodes thus increasing the likelihood that your anonymous communications are nothing of the sort.
But warring state actors competing with each other on that offers me some protection.
After all, the field agents probably meet once or twice a year at some math/CS conference in France anyway.
Re: Tor: From the Dark Web to the Future of Privacy
#64One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?
It's also a bit like picking up trash when you're out for a walk, it's just a nice and proper thing to do to make society a better place to live in.
Re: Tor: From the Dark Web to the Future of Privacy
#65Earlier quoted context omitted.
But warring state actors competing with each other on that offers me some protection.
Assuming they compete. If I were a state entity with a vested interest to compromise tor, I would cooperate with peers to that end, enemies or not. It is in every state's interest to have protocols in place for conditional cooperation with hostile states. At the agency or team level, these protocols can be quite effective. After all, the field agents probably meet once or twice a year at some math/CS conference in Fr…
Re: Tor: From the Dark Web to the Future of Privacy
#66Earlier quoted context omitted.
There's a lot in the book about this - it depends what you mean. Tor has a lot of social and technical design elements that try as best they can to minimise this risk. It would be pretty hard for intelligence services to compromise the Tor organisation in ways that meant they were deploying malicious code, for example. Plus, the way it's grown over the years has also given them some protections. In terms of deanonymi…
The scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.
It is a assumed vulnerability of the network. The biggest question is if any state actor would consider it economical to do it compared to alternative methods. Personally I suspect that it is actually cheaper to have visibility into the entire internet, since that method bring value beyond tor and you do not need major secops to pull it off.
Re: Tor: From the Dark Web to the Future of Privacy
#67Earlier quoted context omitted.
Assuming they compete. If I were a state entity with a vested interest to compromise tor, I would cooperate with peers to that end, enemies or not. It is in every state's interest to have protocols in place for conditional cooperation with hostile states. At the agency or team level, these protocols can be quite effective. After all, the field agents probably meet once or twice a year at some math/CS conference in Fr…
And this is why governmental privacy is unethical... All should be open to peer review. For the people, and for the world.
These administrators can then launder the information to their respective agencies by means of any number of play-pretend activities you can write up for the transparency committee. The agency doesn't even need to (officially) know.
Re: Tor: From the Dark Web to the Future of Privacy
#68Earlier quoted context omitted.
Couldn't running an exit node be a cover for other activity? One that provides a reasonable doubt as to whether it was the operator or some other actor who did something unsavory from an IP address?
I thought there was a classic statement from the Tor developers that you shouldn't do this, but the closest that I found on the site is the part about not running an exit node from home (as it might make law enforcement more interested in seizing your home computer). This question https://support.torproject.org/relay-operators/#relay-operat... also seems to imply that it might be useful to run a node to provide cover…
It might be a good idea in a prosecution to raise reasonable doubt. Few people are willing to play punching bag for the police to find out. Also the general technical skill of the average cop and prosecutor is quite low.
Re: Tor: From the Dark Web to the Future of Privacy
#69Earlier quoted context omitted.
There are no incentives. I'm pretty sure the vast majority does it for altruistic reasons. At least all those I've met. Many run relays with spare resources they pay for anyway. Others rent a cheap VPS to run a relay. $10 gives you a surprisingly large amount of bandwidth if you avoid the cloud like the plague. Governments have other possibilities. Why should they run a relay if they can force the ISP to mirror the t…
Governments dont have authority outside of their borders. They cannot force foreign ISP to give over the same information. Therefore they could only mirror nodes on IP addresses issued to companies in their country.
Re: Tor: From the Dark Web to the Future of Privacy
#70I don't think much of this writing style. What's the tor attack surface? Are all the tor boxes on the internet backdoored by the NSA? Is tor a honeypot or is tor not a honeypot? As far as I can tell tor was designed by spooks to allow remote agents operating in foreign countries a means to communicate with headquarters without being traced. It was never designed to allow two entities to communicate anonymously. The m…