Was Tor ever safe to use? I don't think so.
The fact that adversaries need to rely on zero-days, or people running massively outdated and unsupported software, strongly suggests the network is safe and robust.
401–410 of 602 posts
Was Tor ever safe to use? I don't think so.
The fact that adversaries need to rely on zero-days, or people running massively outdated and unsupported software, strongly suggests the network is safe and robust.
From what little I've heard, de-anonymization of Tor users is largely done by targeting their devices with zero-day exploits. That is still a valid method, I wouldn't trust Tor personally, but I'm with the Tor project that there is no credible evidence of a large scale de-anonymization attack.
Earlier quoted context omitted.
No! The client controls path selection, and each hop is verified using its encryption keys.
You're saying that if you modify the tor software, other clients will be able to tell before connecting to you? And you can't trick them into sending to a bad node?
Old Ricochet used onion v2, that has stopped working long ago as far as I know, or I am missing something
You are right. The lack of details or time window when this happened make it difficult to know what the actual compromise was, or if it is still something that can be used. However, if they compromised a Ricochet user, then this attack was a long time ago, and from what Tor's blog says that client didn't have the defenses that would have prevented the attack they think it is. Without the actual details, it seems like…
The hidden service targeted[0] had completely ceased to exist by April 2021, so that time range makes sense.
[0]: https://www.ndr.de/fernsehen/sendungen/panorama/aktuell/Inve...
Earlier quoted context omitted.
Pardon my ignorance, but I thought it fruitful to ask: Are there any issues that can arise by doing this on a VPS? I ask because I know of stories of law enforcement sending inquiries to owners of, say, exit nodes requiring certain information about given traffic. I don't know if this happens for middle-nodes (or whatever they're called). Moreover, are there any issues with associating a node to, you know, your name…
I never operated a TOR node, but as far as I know and heard from other sources, TOR realays don't get much attention from law enforcement, it any attention at all. Which makes sense: all they're doing is getting encrypted traffic in and giving encrypted traffic out. It would hard for them to link a relay node to a specific connection, and even if they do, you can't help them in any way: even you as the node operator…
Earlier quoted context omitted.
I think you just unintentionally highlighted the need for the tor project and outreach to inform people about it.
Not to make too much light of a morbid topic but the idea of someone having a murderous yet tech-savvy ex who has methodically installed all sorts of elaborate digital surveillance measures in their former spouse's personal tech stack in service of premeditated homicide, sitting in a dark room somewhere, howling in anger upon realizing his murder plan has (somehow...?) been thwarted by said former spouse unexpectedly…
Knowing that there's one thing they can't get to you on is huge peace of mind. Not needing to think about your stalker, because there's no way for them to hunt you there.
Earlier quoted context omitted.
>This could cost less than $5000 for a month I ran a bunch of nodes for a couple years and that's optimistic by perhaps an order of magnitude. No $5 a month VPS provides enough bandwidth to sustain the monthly traffic of a Tor node, and nodes need to be continuously online and serving traffic for about 2-3 months[1] before they will be promoted to guard relays. Throttling traffic to stay in your bandwidth allocation…
Now to add additional problems. 1000 tor nodes on a single platform would be very noticeable and geographically limited. Platforms also have different weight attached to them in the consensus, which adds further time requirements before a node is promoted. The developers do not want a single platform provider to be able to observe a large portion of all the traffic, so there are counter measures. The attacker could t…
TOR critics like Len Sassaman said the same years ago, with traffic analysis it is possible to detect where the source is coming from. https://en.wikipedia.org/wiki/Len_Sassaman
Also, it's just Tor – not 'TOR'.
>Note: even though it originally came from an acronym, Tor is not spelled "TOR". Only the first letter is capitalized. In fact, we can usually spot people who haven't read any of our website (and have instead learned everything they know about Tor from news articles) by the fact that they spell it wrong.