Live data from Hacker News

Is Tor still safe to use?

blog.torproject.org

321–330 of 602 posts

Re: Is Tor still safe to use?

#321

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

75% [0] of all Tor nodes are hosted within 14 Eyes [1] countries, so it would actually be quite trivial for the NSA to de-anonymize a Tor user. It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries. [0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all [1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes > Edit: For all the cynics…

TOR as it exists now is a honeypot simple as. Same as that documentary called "Benedict Cumberbniamnatch's Great Work" where they cracked the radio signals of the Frenchmen but they had to let the submarine sink so that they knew that the other guy doesn't know that they knew. NSA uses ROT which is TOR-inspired but takes the techniques and incognito aspects 7 or 8 steps ahead.

Re: Is Tor still safe to use?

#322

Earlier quoted context omitted.

There is a node that delivers your packet to the target server, is there not?

If the server is on the Tor network, an onion server, then it is encrypted end to end and no traffic or identity is exposed to either the onion server or any intermediary. That is to say, if I started an onion server on one side of the world, then connected to it from somewhere else, my connection to it would be anonymous and encrypted to any external entity.

How are you imagining the penultimate node in the chain connects to the target server without knowing anything about them?

Re: Is Tor still safe to use?

#323

Earlier quoted context omitted.

There is a node that delivers your packet to the target server, is there not?

If the server is on the Tor network, an onion server, then it is encrypted end to end and no traffic or identity is exposed to either the onion server or any intermediary. That is to say, if I started an onion server on one side of the world, then connected to it from somewhere else, my connection to it would be anonymous and encrypted to any external entity.

[deleted]

Re: Is Tor still safe to use?

#324

Earlier quoted context omitted.

If the server is on the Tor network, an onion server, then it is encrypted end to end and no traffic or identity is exposed to either the onion server or any intermediary. That is to say, if I started an onion server on one side of the world, then connected to it from somewhere else, my connection to it would be anonymous and encrypted to any external entity.

How are you imagining the penultimate node in the chain connects to the target server without knowing anything about them?

This is well understood public knowledge.

https://community.torproject.org/onion-services/overview/

Re: Is Tor still safe to use?

#325
post #19

Earlier quoted context omitted.

> People never really trusted Veracrypt though Can you expand on this? It was my understanding that Veracrypt is the new de-facto standard.

Bitlocker, LUKS and FileVault are the new standard(s). Veracrypt is a curiousity, not beloved the way truecrypt was. I’d love to see hard numbers for this, just my outside impression. In fact, when trying to find old forums that I was part of during that era, I failed; and found only this: https://discuss.privacyguides.net/t/why-people-still-believe...

This is complete conjecture. Like Truecrypt, Veracrypt is open source, has been audited and has been actively maintained. Could it use another audit? Sure but so could Bitlocker but that isn't happening for even the first time any time soon.

Re: Is Tor still safe to use?

#326
post #38

Earlier quoted context omitted.

After the Snowden revelations regarding FOXACID and QUANTUM going largely undressed in the tor project, people have every right to feel sketched out with using ToR for anything. "We're still helping people" just isn't a good enough argument for most people. https://www.schneier.com/blog/archives/2013/10/how_the_nsa_a... https://blog.torproject.org/yes-we-know-about-guardian-artic...

Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. I know ISPs, especially national ISPs like AT&T (see: titanpointe - 33 thomas st, nyc) would feed data to NSA since traffic at the time was mostly via http (rather than https). I suppose the unencrypted dns queries are still useful (although DNSSEC is supposed to defend against snooping/deep packet inspection)

DNSSEC does NOT protect against snooping.

Re: Is Tor still safe to use?

#327

Earlier quoted context omitted.

> The US benefits from the TOR being private. Slight correction: The US benefits from TOR being private to _everyone but the US_

I’m glad I didn’t have to scroll too far to see your comment. In fact, A major power wins by creating a mote just big enough that only they can cross.

everybody does such shenanigans, bro.

you don't have to be a major power to do such stunts.

everybody and their uncle are already doing it. look into your life to see the truth of this.

Re: Is Tor still safe to use?

#328
I remember Adrian Crenshaw doing a speech at Def Con 22 about how people got busted using Tor. Even then he point out in most of the cases, it was bad OpsSec by the person, and had nothing to do with Tor.

How applicable do people think this information is now 9-10 years later?

DEF CON 22 - Adrian Crenshaw- Dropping Docs on Darknets: How People Got Caught https://www.youtube.com/watch?v=eQ2OZKitRwc

Re: Is Tor still safe to use?

#329

Earlier quoted context omitted.

Pardon my ignorance, but I thought it fruitful to ask: Are there any issues that can arise by doing this on a VPS? I ask because I know of stories of law enforcement sending inquiries to owners of, say, exit nodes requiring certain information about given traffic. I don't know if this happens for middle-nodes (or whatever they're called). Moreover, are there any issues with associating a node to, you know, your name…

I'm not an exit node. You can buy a vps with xmr if you're worried about privacy from law enforcement.

most vps don't support xmr though. any suggestions to whom I can trust (I basically only trust hetzner in vps space)

Re: Is Tor still safe to use?

#330
post #267

Earlier quoted context omitted.

Or perhaps they _are_ sharing notes about tor users with each other, as part of a global club of intelligence agencies (a sort of new world order) who would rather not be overthrown. How are we to know?

Because if they each only have incomplete information, they each wouldn't know whether the information they have is relevant to preventing overthrow of their collective order, or intelligence that is only going to help their geopolitical adversary. Basically, a variation of the prisoner's dilemma. Also, those nukes we have pointed at each other are a pretty healthy hint.

the last sentence really just gave me a chuckle
Post reply on HN