Live data from Hacker News

Tor: From the Dark Web to the Future of Privacy

direct.mit.edu

71–80 of 100 posts

Re: Tor: From the Dark Web to the Future of Privacy

#71
post #59

Earlier quoted context omitted.

> What are the incentives for running a node? It costs my ISP resources but I pay a flat rate. That would have value to me.

if enough customers of the ISP do this, they will no longer charge a flat rate. It's just that some people manage to consume resources that other customers don't atm.

My ISP situation is olipolistic (and perhaps a colluding duopoly once you distill it down enough).

I’m confident it’s not an efficient market and they’re charging what the market can bare, not a tight markup over their actual costs.

Re: Tor: From the Dark Web to the Future of Privacy

#72
post #66

Earlier quoted context omitted.

The scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.

Controlling a large fraction of tor nodes is possible, but there is a large cost associated with it. Tor has a reputation system when it comes to nodes, and in order to gain a large fraction of tor nodes you need to continuously have a presence for a long period of time. Having such long term presence also risk gaining visibility and become detected, and require good and consistent secops. As the network expands this…

Wouldn't the long term cost of doing that be amortized over all the potential targets it would help provide information on? Seems like it would be a valuable capability to maintain in the long term. Hundreds or even thousands of tor nodes would likely be a minor fraction of the budget of whichever state actor cared about doing that.

Re: Tor: From the Dark Web to the Future of Privacy

#73

Earlier quoted context omitted.

The scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.

"don't become an enemy of the state" is my go-to security posture

I mean, the upstream question we're discussing is whether tor is appropriate if your threat model includes state actors.

Re: Tor: From the Dark Web to the Future of Privacy

#74

I don't think much of this writing style. What's the tor attack surface? Are all the tor boxes on the internet backdoored by the NSA? Is tor a honeypot or is tor not a honeypot? As far as I can tell tor was designed by spooks to allow remote agents operating in foreign countries a means to communicate with headquarters without being traced. It was never designed to allow two entities to communicate anonymously. The m…

There was a guy in a dorm who thought he was anonymous using tor on the schools website. They caught him because it turns out he was the only one using tor. In some ways it is a honeypot.

Which story is this? I've heard a few famous stories of people getting caught using Tor, but none that were like this.

Re: Tor: From the Dark Web to the Future of Privacy

#75
post #27

Earlier quoted context omitted.

Governments dont have authority outside of their borders. They cannot force foreign ISP to give over the same information. Therefore they could only mirror nodes on IP addresses issued to companies in their country.

Governments will just get other governments to let them tap their fiber.

Right, like China and Russia are going to let USA tap their fibre?

Re: Tor: From the Dark Web to the Future of Privacy

#76
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

(with the understanding that I'm only speaking for what I found, not for the Tor project or the relay community) Most of the people I spoke to saw themselves as providing a service - they wanted to help do something to bring a particular kind of future Internet about and found it rewarding to be a part of that. A number of them found the act of running a relay interesting and fun in itself - something they could get…

> from hunting down bad relays actively

If there is a mechanism to block , let’s say, CSAM, then the same mechanism can be used to block dissident political speech, no?

Re: Tor: From the Dark Web to the Future of Privacy

#77

Earlier quoted context omitted.

There was a guy in a dorm who thought he was anonymous using tor on the schools website. They caught him because it turns out he was the only one using tor. In some ways it is a honeypot.

Which story is this? I've heard a few famous stories of people getting caught using Tor, but none that were like this.

https://www.thecrimson.com/article/2013/12/17/student-charge...

Re: Tor: From the Dark Web to the Future of Privacy

#78

Earlier quoted context omitted.

(with the understanding that I'm only speaking for what I found, not for the Tor project or the relay community) Most of the people I spoke to saw themselves as providing a service - they wanted to help do something to bring a particular kind of future Internet about and found it rewarding to be a part of that. A number of them found the act of running a relay interesting and fun in itself - something they could get…

> from hunting down bad relays actively If there is a mechanism to block , let’s say, CSAM, then the same mechanism can be used to block dissident political speech, no?

AFAIK there is no mechanism for content blocking. The "bad relays" are relays that deanonymize, store, delay, or in any other way hamper user's traffic.

Re: Tor: From the Dark Web to the Future of Privacy

#79
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

> What are the incentives for running a node? It costs my ISP resources but I pay a flat rate. That would have value to me.

Don't most ISPs have a bandwidth cap?
Post reply on HN