Live data from Hacker News

Is Tor still safe to use?

blog.torproject.org

111–120 of 602 posts

Re: Is Tor still safe to use?

#111

Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

> Could someone like the NSA with limitless resources do it? Quite probably, sure.

If you're not worried about a fairly well-resourced government agency uncovering whatever network activity you believe needs to be anonymized, why would you be using Tor at all?

Re: Is Tor still safe to use?

#112

Earlier quoted context omitted.

Society benefits when people refrain from illegal and immoral activities.

Are you implying that Tor is primarily used for illegal or "immoral" purposes?

I would assume very likely yes?

There definitely are legit use cases for it and in an ideal world, I think all traffic should go over onion routing by default to protect them.

But in reality today besides a handful of idealists (like me some years ago), and legitimate users, like protestors under oppressive regimes - I would assume the biggest group with a concrete interest to hide would be indeed pedophiles and other dark net members and therefore use it.

Re: Is Tor still safe to use?

#113

Earlier quoted context omitted.

If someone would do the thing-to-be-detected (e.g. accessing CSAM) every day, then that 0.14% probability of detection turns out to be 40% for a single year (0.9986^365) or 64% over two years, so even that would deanonymize the majority of such people over time.

That assumes you could run thousands of malicious tor nodes for several years without being detected. Unless you have vast resources and time, this is unlikely.

But given the attack is just logging the cleartext at the ends how are you going to detect that the servers are malicious?

Re: Is Tor still safe to use?

#114

It's safe if you ain't a pedo or terrorist. Sometimes I wonder wtf y'all are doing with such crazy security expectations and paranoia.

The implication of the right to privacy being unnecessary because you have nothing to hide is akin to declaring the right to free speech unnecessary because you have nothing to say. The ability to maintain privacy and anonymity is not for today, it's for tomorrow.

I don't think many people seriously think that terrorists planning attacks to maim and kill people, and pedophiles sharing child sexual abuse imagery with each other, have an absolute right to privacy in such communications, nor that doing so is an example of free speech.

Really it's a good thing that the "global adversary" is - almost certainly - keeping tabs on Tor traffic and tracking down who is responsible for the worst abuses within this network.

Re: Is Tor still safe to use?

#115
post #98

Earlier quoted context omitted.

If you’re advocating for a bigger network… we need more relay operators. Can’t wave a magic wand. There’s like 8000 relays. Haven’t looked in a while. Or if you were arguing for increasing the number of relays in a circuit, that doesn’t increase security. It’s like one of the OG tor research papers deciding on 3. Bad guy just needs the first and the last. Middle irrelevant.

Any idea what consideration keeps the tor team from making the client also act as a relay node by default?

Clients aren’t necessarily good relays. Reachability. Bandwidth. Uptime. I’ll-go-to-prison-if-caught-and-idk-how-to-change-settings-this-needs-to-just-work.

Re: Is Tor still safe to use?

#116

Earlier quoted context omitted.

> Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? If you're looking for static assets, why would you need to see the whole chain? Wouldn't a connection to a known website (page) have a similar fingerprint even if you wrap it in 3 layers of encryption? Does Tor coalesce HTTP queries or something to avoid having someone fingerprint connections base…

If I don't know the whole chain (or I don't use a timing attack with a known guard and exit node) then I don't see how I'd know who sent the packet in the first place. The person in the chain would connect to a random tor guard node, which would connect to another random node which would connect to my evil exit node. My evil exit node would only know which random TOR node the connection came from but that's not enoug…

Say there are only 2 sites on Tor. Site 'A' is plain text and has no pages over 1KB. You know this because it's public and you can go look at it. Site 'B' hosts memes which are mostly .GIFs that are 1MB+. You know this because it's also a public site.

If I was browsing one of those sites for an hour and you were my guard, do you think you could make a good guess which site I'm visiting?

I'm asking why that concept doesn't scale up. Why wouldn't it work with machine learning tools that are used to detect anomalous patterns in corporate networks if you reverse them to detect expected patterns.

Re: Is Tor still safe to use?

#117

Earlier quoted context omitted.

If someone would do the thing-to-be-detected (e.g. accessing CSAM) every day, then that 0.14% probability of detection turns out to be 40% for a single year (0.9986^365) or 64% over two years, so even that would deanonymize the majority of such people over time.

That assumes you could run thousands of malicious tor nodes for several years without being detected. Unless you have vast resources and time, this is unlikely.

What detection? A malicious node is only different from a non-malicious node because all the traffic is being logged. If that's our definition of a malicious node in this case then there is no way to detect one.

Re: Is Tor still safe to use?

#118

Federal agencies operate enough exit nodes to make Tor use risky at best. I have no idea if they have since implemented some feature to prevent this but if not I would stay far away from Tor if you're planning to do illegal things. There's also the risk of trusting service operators to secure any PII you expose on marketplaces. Not that I think the Fed's would blow their cover to hunt down people buying drugs but sti…

Please read the blog post:"It is important to note that Onion Services are only accessible from within the Tor network, which is why the discussion of exit nodes is irrelevant in this case."

Re: Is Tor still safe to use?

#119
post #94

Old Ricochet used onion v2, that has stopped working long ago as far as I know, or I am missing something

You are right. The lack of details or time window when this happened make it difficult to know what the actual compromise was, or if it is still something that can be used. However, if they compromised a Ricochet user, then this attack was a long time ago, and from what Tor's blog says that client didn't have the defenses that would have prevented the attack they think it is. Without the actual details, it seems like this attack was mitigated some time ago and is no longer something that can be done in the same way.

Re: Is Tor still safe to use?

#120

Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

You know what's easier than waiting around to get really lucky?

Using those same network-health dashboards as DDoS target lists, to temporarily degrade/shut down the whole network except for your own nodes.

Also, big nodes route more Tor circuits each. Costs more to run them, and they intentionally don't function as exit nodes (to avoid the "obvious" attack) — but just having a bunch of these big nodes in the network handling only middle hops, biases the rest of the network away from handling middle hops, toward handling end hops. Which means that if you then run a ton of tiny nodes...

Post reply on HN