Live data from Hacker News

Deploying Tor Relays

blog.mozilla.org

81–90 of 91 posts

Re: Deploying Tor Relays

#81
post #63

Earlier quoted context omitted.

It's good practice to discuss plans with your hosting provider, so that you and they both know what to expect. Stealth doesn't cut it, especially if there's real money at risk. Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.

This primarily applies to exits, not relays. Relays only work within the Tor network and never know exactly what they're relaying.

Some sites don't bother distinguishing between relays and exits. They just block non-Tor access from all Tor node IPs.

Re: Deploying Tor Relays

#82
post #80

Earlier quoted context omitted.

It's actually better if 1000 different people each run a 40Mbps exit node than if one ISP runs a single 40Gbps one. You don't want to centralize control over the exit nodes because it increases the chance that party could control every node in a circuit.

If they're only running exit nodes, they're not going to control every node in a circuit.

If you know which nodes they control you can easily avoid using them in the same circuit. But how are you supposed to know that? There is a configuration option to list other nodes you operate for exactly this purpose, but someone staging an attack is obviously not going to use it.

Re: Deploying Tor Relays

#83

They better tell their employees not to buy any drugs or use TOR for illegal stuff, because now they'll be representing the whole TOR project and The Free Web. So it's like, they don't just represent themselves anymore, and an arrest will be a political tool to smash everything into corporate/government control.

What does the word "illegal" encompass here?

Re: Deploying Tor Relays

#84
post #68
post #63

Earlier quoted context omitted.

It's good practice to discuss plans with your hosting provider, so that you and they both know what to expect. Stealth doesn't cut it, especially if there's real money at risk. Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.

> keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists Have you got an example of that? I know a few relays intimately and I've never seen this.

It happened to me when I ran a tor relay (not an exit) on the same ip as a mailserver. There is one rbl that automatically adds you if you do this. Mind you, I've never found a mailprovider using this list (can't remember the name).

Re: Deploying Tor Relays

#85
post #3

I hope they are going to be deploying exit nodes as well. It's not very safe to run an exit node but I doubt the FBI will be raiding Mozilla and other big companies for them if this practice continues.

Part of the problem of running an exit node is that it's unclear how "safe" it actually is, and as a result there is a lot of rumor and paranoia. Every country has different laws that affect the legal status of an exit node operator. For example, an Austrian man was arrested in 2011 for running an exit node and charged with being an accomplice to crimes that were carried out over Tor using his exit node. He was ultim…

The case is Austria was complicated because the court found chat protocols from him:

„You can host 20 TB child porn with us on some encrypted hdds“

The judge argues that this is more than just providing infrastructure, it is advertising illegal content / behavior. So this case is not representative for evaluating the risk of running a tor exit node.

http://futurezone.at/netzpolitik/strafe-fuer-tor-betreiber-g...

Re: Deploying Tor Relays

#86
post #75
post #49

> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2 Xeon L5640, 2 1Gbps NIC) In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...

Are there tax advantages of donating old equipment to certain good causes? It seems easier than the alternative of selling the hardware on ebay.

Yes there is in most jurisdictions. The company can write off the value of the hardware against their taxable profits. However the Mozilla Foundation is a non-profit, so I'm not sure that applies.

Re: Deploying Tor Relays

#87
post #3

I hope they are going to be deploying exit nodes as well. It's not very safe to run an exit node but I doubt the FBI will be raiding Mozilla and other big companies for them if this practice continues.

Part of the problem of running an exit node is that it's unclear how "safe" it actually is, and as a result there is a lot of rumor and paranoia. Every country has different laws that affect the legal status of an exit node operator. For example, an Austrian man was arrested in 2011 for running an exit node and charged with being an accomplice to crimes that were carried out over Tor using his exit node. He was ultim…

Why isn't the EFF already running an exit node to confront the legal ambiguity issue?

Re: Deploying Tor Relays

#88
Is Tor broken? I've heard that its anonymity was proven to be broken, but I'm not sure how reliable my source was. I'm interested in getting involved but hesitant to do so until I have some solid info one way or the other.

Re: Deploying Tor Relays

#89

Is Tor broken? I've heard that its anonymity was proven to be broken, but I'm not sure how reliable my source was. I'm interested in getting involved but hesitant to do so until I have some solid info one way or the other.

There's something like 2k-8k exit nodes, and all that is needed to compromise it is 51% of those. Given that the CIA started tor and the government has significant interest in breaking it, I would find it harder to believe that they didn't have a few thousand computers lying around.

Also all of this is from memory, but I hope none of it is wrong. Feel free to correct me if so.

Re: Deploying Tor Relays

#90
post #71
post #68

Earlier quoted context omitted.

> keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists Have you got an example of that? I know a few relays intimately and I've never seen this.

I recall seeing this on tor-talk or tor-relays within the past year or so. Someone started running an exit, and their hosting provider nuked their account, claiming that other customers were being affected by bans. I'll see if I can find it. Edit: Here's one example, posted by Zack Weinberg on the tor-relays list.[0] CMU network operations has decided to move the Tor exit node that my group operates (tor-exit.cylab.c…

It is quite expected if you run an exit node. However this was in regard to a relay node, which is something else entirely.

I've seen a few references to these supposed problems with running a relay nodes lately, but the poster never replies with any information where this have actually happened. This behaviour is new. It wouldn't surprise me if it's coordinated, considering what else we've seen lately.

Post reply on HN