Live data from Hacker News

Is Tor still safe to use?

blog.torproject.org

421–430 of 602 posts

Re: Is Tor still safe to use?

#421

No. It is not. More than 1/3 of the Tor servers are run by US Federal Govt as does other members of the Five Eyes. Israel has a large number as well. Cases are built backwards or in parallel that are from the fruit of the poisonous tree. If you don't know what that term means, look it up. Use Tor with extreme caution.

[deleted]

Re: Is Tor still safe to use?

#422
post #222

Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…

>This could cost less than $5000 for a month I ran a bunch of nodes for a couple years and that's optimistic by perhaps an order of magnitude. No $5 a month VPS provides enough bandwidth to sustain the monthly traffic of a Tor node, and nodes need to be continuously online and serving traffic for about 2-3 months[1] before they will be promoted to guard relays. Throttling traffic to stay in your bandwidth allocation…

[deleted]

Re: Is Tor still safe to use?

#423
post #415

Here is an awesome DefCon talk about this topic from the perspective of a darknet vendor. It's amazing: https://youtu.be/01oeaBb85Xc

Nice presentation. Ironically the ?si= parameter is for tracking. You should remove it.

Re: Is Tor still safe to use?

#424
post #405
post #347

Earlier quoted context omitted.

I never operated a TOR node, but as far as I know and heard from other sources, TOR realays don't get much attention from law enforcement, it any attention at all. Which makes sense: all they're doing is getting encrypted traffic in and giving encrypted traffic out. It would hard for them to link a relay node to a specific connection, and even if they do, you can't help them in any way: even you as the node operator…

Just a quick note on the Youtube channel you mention: I follow his videos for a while and it seems to me, that he's half a shill. My impression is, that he re-models popular HN threads into Youtube videos. Just watch the latest video on the MrBeast topic and you'll basically get the same info as all the popular 'root' comments (was on HN front page last week). Not the first time I noticed a suspicious connection.

It would be funny if he makes a new video about TOR and ends up mentioning your comment :D

Re: Is Tor still safe to use?

#425

Earlier quoted context omitted.

The issue that TOR has is that it's a layered routing concept that won't respect ASN based spreading/scattering of traffic. Circuits are temporary but the traffic is not scattered across the network to make MITM fingerprinting of request/payload sizes/timestamps impossible. A typical MITM like the FBI surveillance van next door can identify you by observing the network packets and by _when_ they were requested and by…

Would an Ethernet cable plugged into your ISP router defend against the above mentioned surveillance (i.e., no WiFi snooping)? Or did the FBI PCAP at the ISP?

The problem is also that different network stack implementations have different MTU values and different TCP headers.

There's a lot of tools available that can fingerprint different applications pretty well these days. For example, Firefox and TOR Browser can be fingerprinted because of their custom network library that's OS independent.

It gets worse if you use a DSL2 connection with scaling because that will uniquely make your packets fingerprintable because they have a specific MTU size that's dependent of the length of the cable from modem to the next main hub. Same for cable internet, because the frequencies and spectrums that are used are also unique.

(I'm clarifying this, because an FBI van not having access to your Wi-Fi still has access to the cable on the street when there's a warrant for surveillance / wire tapping issued)

[1] https://github.com/NikolaiT/zardaxt (detects entropies of TCP headers and matches them with applications)

[2] https://github.com/Nisitay/pyp0f (detects the OS)

[3] https://github.com/ValdikSS/p0f-mtu (detects the VPN provider)

Re: Is Tor still safe to use?

#426
post #402

From what little I've heard, de-anonymization of Tor users is largely done by targeting their devices with zero-day exploits. That is still a valid method, I wouldn't trust Tor personally, but I'm with the Tor project that there is no credible evidence of a large scale de-anonymization attack.

Why wouldn't you trust Tor? Do you mean you wouldn't trust it at all, or wouldn't trust it completely?

I mean at all, but I don't have any reasons worth mentioning here, that I'm willing to defend on a public site.

Re: Is Tor still safe to use?

#427
post #423
post #415

Here is an awesome DefCon talk about this topic from the perspective of a darknet vendor. It's amazing: https://youtu.be/01oeaBb85Xc

Nice presentation. Ironically the ?si= parameter is for tracking. You should remove it.

Is it sad that when someone else gives me a video with an si parameter or similar, I keep it on when passing it forward, in my eyes, this feeds garbage to their backend.

Re: Is Tor still safe to use?

#428
post #407
post #264

Earlier quoted context omitted.

Now to add additional problems. 1000 tor nodes on a single platform would be very noticeable and geographically limited. Platforms also have different weight attached to them in the consensus, which adds further time requirements before a node is promoted. The developers do not want a single platform provider to be able to observe a large portion of all the traffic, so there are counter measures. The attacker could t…

Pagers and the next day handheld radios exploded on their users! This can be done.

I think the news about that particular counter example is too recent to be easily understood.

https://www.schneier.com/blog/archives/2024/09/remotely-expl...

Still, I think your point is excellent. The sort of group interested in tracking someone(s) over Tor certainly might have the capability to do so despite the difficulty.

Re: Is Tor still safe to use?

#429

Earlier quoted context omitted.

Specifically what I chose US (allies implied), China, and Russia. These should be three competing factions.

Russia and China are allies. And I'm not sure if Beijing would even be interested in spying on TOR users since it's blocked so thoroughly it's basically unusable for Chinese residents.

China is for sure interested in spying on people in the US. I'm not sure if TOR users are of special interest though.

Re: Is Tor still safe to use?

#430
post #423

Earlier quoted context omitted.

Nice presentation. Ironically the ?si= parameter is for tracking. You should remove it.

Is it sad that when someone else gives me a video with an si parameter or similar, I keep it on when passing it forward, in my eyes, this feeds garbage to their backend.

New tool idea: a si parameter tracking "mixer"?

Crowdsource making tracking useless?

Post reply on HN