Live data from Hacker News

Is Tor still safe to use?

blog.torproject.org

311–320 of 602 posts

Re: Is Tor still safe to use?

#311

Earlier quoted context omitted.

Still easily within the budget of the US, Russia, China, Israel, etc. I wouldn't be surprised if a majority of nodes are ran by intelligence agencies.

The interesting thing is, the more agencies that run relays, the more they interfere with each other. So having something like US, Russia, and China a each running 25% of the network reduces the chances of any one getting all three relays.

This would help negate that interference. https://en.wikipedia.org/wiki/Five_Eyes

Re: Is Tor still safe to use?

#312

Earlier quoted context omitted.

Because you're an enemy of the Iranian, Saudi, North Korean, etc. gov't. Because your ex-spouse wants to murder you. Because you just escaped Scientology, or another cult. Because you're a criminal. The NSA doesn't handle that. Because you're a journalist talking to sources in the industry you're investigating.

Those second and third points are pretty laughably paranoid-fantasy reasons to use Tor—even if one found oneself in either situation.

tor-browser comes with other privacy-boosting features, beyond its method of talking to the network. That might make a difference too, if someone is likely to look at your browser history etc.

Re: Is Tor still safe to use?

#313
post #210

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

1/ if a user sends 10,000 requests, you're saying 14 of them might see 3 compromised nodes? 2/ Police can use parallel construction. Although, given enough time (in theory) parallel construction is eventually exposed.

1/ tor-browser by default sticks to the same circuit for one origin for the session, so that'd have to be 10,000 separate sites or 10,000 separate sessions.

Re: Is Tor still safe to use?

#314

Earlier quoted context omitted.

Onion sites do not utilize an exit node.

There is a node that delivers your packet to the target server, is there not?

If the server is on the Tor network, an onion server, then it is encrypted end to end and no traffic or identity is exposed to either the onion server or any intermediary.

That is to say, if I started an onion server on one side of the world, then connected to it from somewhere else, my connection to it would be anonymous and encrypted to any external entity.

Re: Is Tor still safe to use?

#315
post #38

Earlier quoted context omitted.

Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. I know ISPs, especially national ISPs like AT&T (see: titanpointe - 33 thomas st, nyc) would feed data to NSA since traffic at the time was mostly via http (rather than https). I suppose the unencrypted dns queries are still useful (although DNSSEC is supposed to defend against snooping/deep packet inspection)

>> Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. A nationwide invisible firewall, with man in the middle decryption and permanent storage of all unencrypted data. All run by the major backbones and ISPs.

> man in the middle decryption

How would that work?

Re: Is Tor still safe to use?

#316

Earlier quoted context omitted.

> It provides a channel for operatives to exfiltrate data out of non-NATO countries very easily. I'm not convinced this is the case. For example China's gfw has been very effective at blocking TOR traffic, and any TOR connection in other countries is like announcing to the government that you are suspicious.

How do they see TOR traffic in a TLS tunnel?

If you can find TOR nodes, so can the Chinese government. They can then just block these addresses.

Furthermore, the great firewall is quite advanced, they use machine learning techniques to detect patterns, so even if it is TLS on port 443, they may be able to detect it after they have gathered enough traffic. There are workarounds of course, but it is not as simple as just using a TLS tunnel.

Re: Is Tor still safe to use?

#317

Earlier quoted context omitted.

>> Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. A nationwide invisible firewall, with man in the middle decryption and permanent storage of all unencrypted data. All run by the major backbones and ISPs.

> man in the middle decryption How would that work?

Start an NSA cutout called Cloudflare. Configure sites to use an SSL/TLS connection to Cloudflare, then a separate SSL/TLS connection from Cloudflare to your actual machine. Then have the marketing team call it "Strict" encryption. Make it free so everyone uses it.

Re: Is Tor still safe to use?

#318

Earlier quoted context omitted.

75% [0] of all Tor nodes are hosted within 14 Eyes [1] countries, so it would actually be quite trivial for the NSA to de-anonymize a Tor user. It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries. [0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all [1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes > Edit: For all the cynics…

Its important to realize that TOR is primarily funded and controlled by the US Navy. The US benefits from the TOR being private. It provides a channel for operatives to exfiltrate data out of non-NATO countries very easily.

  > the US Navy
Tor was made for spies. But you know what's really bad for spies? If accessing a certain IP/protocol/behavior reliably reveal your spy status.

For Tor to be effective for hiding spies it has to be used by the public. Even if it's only nefarious actors (say spies + drug dealers + terrorists) it adds noise that the adversary needs to sort through.

What I fucking hate about many of these conspiracies is how silly it is once you ever work with or for any government entities. You can't get two police agencies in neighboring cities to communicate with one another. The bureaucrats are fucking slow as shit and egotistical as fuck.

It's important to remember that the government and even a single agency (like the NSA) is just as chaotic, disconnected, and full of competing entities as any big tech company has (if not worse). Yeah, most of the NSA is focused offense, but there's groups working on defense. Those groups are 100% at odds. This is true for the 18 intelligence agencies. They have different objectives and many times they are at odds with one another and you bet each one wants to be getting credit for anything.

The US involvement should warrant suspicion and with any technology like Tor you should always be paranoid. But it's not proof. Because guess what, the US wants people in other countries to use high levels of encryption to hide from their authoritarian governments while the US can promote democracy movements and help put a friendly leader into a position of power. AT THE SAME TIME they also want to spy on their own people (and there are plenty of people in the gov that don't want this). Inconsistency is the default because it's a bunch of different people with different objectives. So the US gov both wants Tor to be secure and broken at the same time.

Re: Is Tor still safe to use?

#319

Earlier quoted context omitted.

The interesting thing is, the more agencies that run relays, the more they interfere with each other. So having something like US, Russia, and China a each running 25% of the network reduces the chances of any one getting all three relays.

This would help negate that interference. https://en.wikipedia.org/wiki/Five_Eyes

Specifically what I chose US (allies implied), China, and Russia. These should be three competing factions.

Re: Is Tor still safe to use?

#320

Earlier quoted context omitted.

I started a tor relay on a spare vps about a month ago and it got guard status around 2-3 weeks in, so that info seems to be out of date.

Pardon my ignorance, but I thought it fruitful to ask: Are there any issues that can arise by doing this on a VPS? I ask because I know of stories of law enforcement sending inquiries to owners of, say, exit nodes requiring certain information about given traffic. I don't know if this happens for middle-nodes (or whatever they're called). Moreover, are there any issues with associating a node to, you know, your name…

I'm not an exit node.

You can buy a vps with xmr if you're worried about privacy from law enforcement.

Post reply on HN