Live data from Hacker News

Is Tor still safe to use?

blog.torproject.org

481–490 of 602 posts

Re: Is Tor still safe to use?

#481
post #434

Earlier quoted context omitted.

Most governments value their law enforcement obligations and/or desire for surveillance more strongly than an Internet that is protected from spying, so good luck with that.

Ironically, most of these same sectors in the same governments have strong need to be protected from spying themselves. So in many cases it's really a case of "we want a monopoly on secrecy". Which should be a massive red flag for everyone, from left to right, from liberal to conservative, from anarchist to communist and so on. But somehow isn't picked up by any of these. I presume because they all believe somehow th…

I don't see government monopolies as immediate red flags.

In most nations it's widely accept that the state has a monopoly on violence (usually through the police force), and it's not clear to me what a good alternative to that would be.

I also want my government to have a monopoly on taxation, I don't want any private company or gang to be able to just collect taxes from me, without any repercussion.

As for secrets? We probably have to distinguish a bit between secrets/data at rest vs. secrets/data in transit. I could well imagine that a good balance between security and privacy could require some tradeoffs when it comes to data in transit.

Re: Is Tor still safe to use?

#482

Earlier quoted context omitted.

If it’s that expensive to run Tor nodes, who is actually paying for them? I’ve heard individuals getting doors kicked in for participating in the network, so it’s not individuals. Corporates too wouldn’t want this type of burden… so is it really just spy-vs-spy

> I’ve heard individuals getting doors kicked in for participating in the network, so it’s not individuals. It's individuals

Unless something has changed, one of the issues with Tor is that it tries to send traffic through servers that have the most bandwidth which are pretty much certain to be servers owned by the state a lot of the time because a random person's residential cable modem is going to be a lot less capable.

Re: Is Tor still safe to use?

#483

As knowledgeable users of the Internet in 2024, we would do well to assume that nothing is 100% “safe” (I.e. there’s no such thing as perfect security/privacy). However, some things, like Tor, can make your use of the Internet safer . If all you’re doing is arguing that Tor shouldn’t be used because it isn’t/was never “safe”, then you might as well not use the Internet at all.

But that's half the point. If someone has an intention to undergo some illegal activities with full intention not to be caught, only 100% "safe" solution works for them. Normally we talk about risk tolerance, but this particular use case is a bit special.

The only 100% safe method is to not do the illegal activity at all. There's always a risk/rewards analysis to be performed when committing any act that could have negative consequences whether you're playing the stock market or doing credit card fraud. For any major criminal that gets caught, you can usually read the arrest affidavit which offers a pretty interesting look into how the criminal was caught despite the careful measures they took. The one for DPR is interesting to read and shows how despite taking careful measures, DPR left a trail of breadcrumbs that investigators used to track him down. His use of Tor was pretty solid (assuming the whole affidavit isn't complete parallel construction fiction) but it was everything else he did outside of it that got him in the end. There's another story of a university student that sent threats to his school to get out of an exam or something through anonymous emails over Tor. They only caught him because he was the only person using Tor on the school network at the time the email was sent. If he was off campus, he may have remained anonymous.

An analog crime I think about is the murders in Moscow, Idaho. The criminal did take some careful measures like wearing gloves but he left a knife sheath behind that contained DNA evidence. Everything else they had on him was circumstantial, he owned a similar car to what police thought they saw on people's doorbell cameras and his phone went offline during the time of the murders and also pinged a tower close to the crime scene hours afterwards. Police found a partial genealogy match to his DNA which I'm sure they compared to similar car owners and cell tower records. If he hadn't left the sheath behind, wore something like a Tyvek suit, and simply left his phone at home, the suspect pool would have likely been too large. His careful measures (turning off his phone, making multiple passes in his car) likely contributed to police focusing on him once the DNA proved a link.

Re: Is Tor still safe to use?

#484

Earlier quoted context omitted.

75% [0] of all Tor nodes are hosted within 14 Eyes [1] countries, so it would actually be quite trivial for the NSA to de-anonymize a Tor user. It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries. [0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all [1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes > Edit: For all the cynics…

The original purpose of TOR was to provide agents and handlers with a means of secure communication, allowing them to organize subversive or espionage activities. It was created by the Department of Defense to propagate their interests and spread democracy around the world using these secure capabilities. Given this context, it's not unreasonable to assume that TOR is still being used in a similar manner today. Becau…

> Perhaps that, rather than a technical limitation, is the reason most high-profile arrests related to TOR involve criminals making some other mistake, rather than the security of the network itself being compromised.

I have no doubt that the government doesn't want to demonstrate how weak Tor is to the public, but it's also got to be dead simple to find those kinds of "other mistakes" they can use when they've identified the person they're looking for and can monitor whatever they do.

Re: Is Tor still safe to use?

#485
post #267

Earlier quoted context omitted.

I think the threat model is that the majority are not run by cooperating malicious parties. Russia, china and usa all dont like each other much so are probably not sharing notes (in theory).

Or perhaps they _are_ sharing notes about tor users with each other, as part of a global club of intelligence agencies (a sort of new world order) who would rather not be overthrown. How are we to know?

Occam's Razor definitely applies here.

"The simplest explanation is usually the best one."

Conspiracy theories are a logical reasoning black hole.

I personally feel it's generally best to avoid the mental Spaghettification.

Re: Is Tor still safe to use?

#486

Earlier quoted context omitted.

Its important to realize that TOR is primarily funded and controlled by the US Navy. The US benefits from the TOR being private. It provides a channel for operatives to exfiltrate data out of non-NATO countries very easily.

> the US Navy Tor was made for spies. But you know what's really bad for spies? If accessing a certain IP/protocol/behavior reliably reveal your spy status. For Tor to be effective for hiding spies it has to be used by the public. Even if it's only nefarious actors (say spies + drug dealers + terrorists) it adds noise that the adversary needs to sort through. What I fucking hate about many of these conspiracies is ho…

> It's important to remember that the government and even a single agency (like the NSA) is just as chaotic, disconnected, and full of competing entities as any big tech company has (if not worse).

And yet even as early as 2003 they were taking a copy of every single bit that ran over the AT&T backbone (https://en.wikipedia.org/wiki/Room_641A). It's amazing how effective these "chaotic, disconnected, and full of competing entities" can be. We're entirely dependent on whistleblowers willing to risk their lives and freedom to learn about what they're doing to us.

Re: Is Tor still safe to use?

#487

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

75% [0] of all Tor nodes are hosted within 14 Eyes [1] countries, so it would actually be quite trivial for the NSA to de-anonymize a Tor user. It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries. [0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all [1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes > Edit: For all the cynics…

> Maybe someone, somewhere, has decided that allowing petty criminals to get away with their crimes is worth maintaining the illusion that Tor is truly private.

This is what I believe. If they do have a way to track people, it wouldn't be worth blowing their cover for small stuff that wasn't a ridiculously huge national security threat that they could afford to throw away 20+ years of work for.

In fact there have been court cases that were thrown out because the government refused to reveal how their information was obtained... I think that usually means they're hiding it on purpose for a bigger cause. I also wouldn't be surprised if multiple SSL CAs are secretly compromised for the same reason.

Re: Is Tor still safe to use?

#488

Earlier quoted context omitted.

75% [0] of all Tor nodes are hosted within 14 Eyes [1] countries, so it would actually be quite trivial for the NSA to de-anonymize a Tor user. It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries. [0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all [1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes > Edit: For all the cynics…

Its important to realize that TOR is primarily funded and controlled by the US Navy. The US benefits from the TOR being private. It provides a channel for operatives to exfiltrate data out of non-NATO countries very easily.

You know what else was funded by the US government? Computers, the Internet and GPS. Also Signal (via OTF funded by Congress).

Re: Is Tor still safe to use?

#489

Earlier quoted context omitted.

That is why in tor it picks a specific guard node and sticks with it. To prevent this kind of attack where you change nodes until you hit a bad one.

The attack Germany is thought to have actually used was to flood the network with middle nodes and wait until the victim connects to their middle node. Then, it knows the guard node's IP. Then, it went to an ISP and got logs for everyone who connected to that IP.

technicly this is the only comment in this chain that is relevant to the featured article, but it's technicly so incomplete that it's almost wrong, I can tell from having read the thread and knowing next to nothing else about how TOR works.

They don't have plausible evidence to subpoena the guard node if a middle node only sees encrypted traffic. They would also need to control the exit nodes which communicate with the target's host or they simply control the host as a honeypot.

Re: Is Tor still safe to use?

#490

Earlier quoted context omitted.

The original purpose of TOR was to provide agents and handlers with a means of secure communication, allowing them to organize subversive or espionage activities. It was created by the Department of Defense to propagate their interests and spread democracy around the world using these secure capabilities. Given this context, it's not unreasonable to assume that TOR is still being used in a similar manner today. Becau…

> Perhaps that, rather than a technical limitation, is the reason most high-profile arrests related to TOR involve criminals making some other mistake, rather than the security of the network itself being compromised. I have no doubt that the government doesn't want to demonstrate how weak Tor is to the public, but it's also got to be dead simple to find those kinds of "other mistakes" they can use when they've ident…

What you’re claiming is not necessarily correct, but it’s an avenue of interesting speculation. Nevertheless, let’s clarify a few of your possible misunderstandings or points of confusion:

I’m not saying TOR is weak, nor that the reason for its concealment is to project a false sense of government strength.

What I am saying—and what you seem to have misunderstood—is that the TOR network is most likely used, precisely because of its strength, for highly sensitive clandestine operations. This results in blanket classification of all involved identities, making them inaccessible to law enforcement. Law enforcement likely understands this, which is why they don’t pursue it—knowing it’s a dead end. Instead, they rely on side-channel effects or mistakes made by criminals.

To my mind, this explains the public information we see.

Now that I’ve clarified, what do you think?

Post reply on HN