Live data from Hacker News

Is Tor still safe to use?

blog.torproject.org

221–230 of 602 posts

Re: Is Tor still safe to use?

#222

Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…

>This could cost less than $5000 for a month

I ran a bunch of nodes for a couple years and that's optimistic by perhaps an order of magnitude. No $5 a month VPS provides enough bandwidth to sustain the monthly traffic of a Tor node, and nodes need to be continuously online and serving traffic for about 2-3 months[1] before they will be promoted to guard relays. Throttling traffic to stay in your bandwidth allocation will just get you marked as a slow node and limit the number of connections you get. Sustaining just 1 Mbps will blow your monthly transfer allocation on the cheap tiers of both Digital Ocean or Linode.

[1] https://blog.torproject.org/lifecycle-of-a-new-relay/

Re: Is Tor still safe to use?

#223

Earlier quoted context omitted.

I think you just unintentionally highlighted the need for the tor project and outreach to inform people about it.

Not to make too much light of a morbid topic but the idea of someone having a murderous yet tech-savvy ex who has methodically installed all sorts of elaborate digital surveillance measures in their former spouse's personal tech stack in service of premeditated homicide, sitting in a dark room somewhere, howling in anger upon realizing his murder plan has (somehow...?) been thwarted by said former spouse unexpectedly…

It's like a series of onions!

Re: Is Tor still safe to use?

#224

Earlier quoted context omitted.

You don’t need all the middle nodes. Just the entry and exit, and enough data to do packet timing analysis to correlate them. It’s in fact shockingly easy for a well provisioned actor to trace tor traffic, and this is something the TOR project openly admits. They’re financed by the US Government after all…

Tor does have padding defenses to protect against that. Also, according to their latest blog post on their finances, while it is true they have money from the US Government, that was only ~50% of their income (I think that was 2023). For the FUD part of that comment, see the "U.S. Government Support" section of https://blog.torproject.org/transparency-openness-and-our-20...

“Only half” is hilarious. Thanks for that.

And if you trust the NSA can’t overcome correlation in the presence of “padding defenses”, then sure: TOR is secure.

Re: Is Tor still safe to use?

#225

Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…

You didn't think someone would notice if the Tor network has 1000 new nodes setup similarly? Or, I suppose, if you find enough heterogenous people and pay them to log their nodes, you're not going to get noticed?

Re: Is Tor still safe to use?

#226
post #38

Earlier quoted context omitted.

Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. I know ISPs, especially national ISPs like AT&T (see: titanpointe - 33 thomas st, nyc) would feed data to NSA since traffic at the time was mostly via http (rather than https). I suppose the unencrypted dns queries are still useful (although DNSSEC is supposed to defend against snooping/deep packet inspection)

>Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. Cloudflare is a US-based company that does MITM attacks on all traffic of the websites that it protects. It's part of how their DDoS mitigation works. Many people still use large US-based mail providers such as Outlook or Gmail. Many large services use AWS, GCP or Azure. Perhaps there are ways for the NSA to access customers' virtual storage or MIT…

Often the connection between the load balancer and app backend also uses TLS. I've operated a large / complex service on AWS and all internal communications at each level were encrypted.

Of course, in principle, a cloud provider could tap in anywhere you're using their services – ELB (load balancer), S3, etc. I presume they could even provide backdoors into EC2 instances if they were willing to take the reputational risk. But even if you assume the NSA or whoever is able to tap into internal network links within a data center, that alone wouldn't necessarily accomplish much (depending on the target).

Re: Is Tor still safe to use?

#227

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

> Edit: For all the cynics and doomsayers here, consider this: Tor has been around for a long time, but there has never been an uptick in arrests that could be correlated to cracking the core anonymity service. If you look closely at the actual high profile cases where people got busted despite using tor, these people always made other mistakes that led authorities to them. During WW2, the British cracked the German…

These pretexts for "discovering" are a "bedrock principle" in law enforcement called parallel construction.

The NSA sharing data with the DEA becomes a "routine traffic stop" that finds the drugs. The court would not allow the NSA evidence or anything found as a result, but through parallel construction, the officer lies in court that it was a "routine stop", and judicial review never occurs.

Re: Is Tor still safe to use?

#228

It's safe if you ain't a pedo or terrorist. Sometimes I wonder wtf y'all are doing with such crazy security expectations and paranoia.

The implication of the right to privacy being unnecessary because you have nothing to hide is akin to declaring the right to free speech unnecessary because you have nothing to say. The ability to maintain privacy and anonymity is not for today, it's for tomorrow.

Where do I say it's unnecessary?

Re: Is Tor still safe to use?

#229
post #210

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

1/ if a user sends 10,000 requests, you're saying 14 of them might see 3 compromised nodes? 2/ Police can use parallel construction. Although, given enough time (in theory) parallel construction is eventually exposed.

> given enough time (in theory) parallel construction is eventually exposed.

Parallel construction has existed for decades. It's even in "The Wire". It has never been tested in court, probably because it is nearly impossible to discover outside of being the agents that implement it.

Re: Is Tor still safe to use?

#230

Remember the Harvard student that emailed in a bomb threat via Tor to get out of a final exam in 2013? He got caught not by the FBI breaking Tor, but just by network analysis of university network traffic logs showing a very narrow list of on-campus people using Tor at the time the threat was communicated. He quickly confessed when interviewed. https://www.washingtonpost.com/blogs/the-switch/files/2013/1... Just anot…

I recall this situation well as it interrupted an exam of mine. iirc, it was the MAC address of his machine being known/registered to the Campus network that nailed him.
Post reply on HN