Live data from Hacker News

Things You Should Know About Tor

eff.org

11–20 of 115 posts

Re: Things You Should Know About Tor

#11
post #8

Earlier quoted context omitted.

A passive observer that is as big as NSA/GCHQ etc. can correlate traffic to de-anonomise some traffic, some very small amount of the time. It is extremely unlikely that a single ISP would ever have enough information to do that though.

Even the NSA has to deal with the base rate fallacy. You can't just magically "correlate" traffic.

It is hard, perhaps, but a good attack for the NSA would be to run many of the exit nodes.

The intelligence gathered this way would be very valuable, as the traffic on the TOR network is has a much higher intelligence value. This is because it is used by those trying to hide something, something which the NSA may like to know.

Re: Things You Should Know About Tor

#12
post #11
post #8

Earlier quoted context omitted.

Even the NSA has to deal with the base rate fallacy. You can't just magically "correlate" traffic.

It is hard, perhaps, but a good attack for the NSA would be to run many of the exit nodes. The intelligence gathered this way would be very valuable, as the traffic on the TOR network is has a much higher intelligence value. This is because it is used by those trying to hide something, something which the NSA may like to know.

> This is because it is used by those trying to hide something, something which the NSA may like to know.

Sounds like a great reason for more people to use Tor!

Re: Things You Should Know About Tor

#13
post #11
post #8

Earlier quoted context omitted.

Even the NSA has to deal with the base rate fallacy. You can't just magically "correlate" traffic.

It is hard, perhaps, but a good attack for the NSA would be to run many of the exit nodes. The intelligence gathered this way would be very valuable, as the traffic on the TOR network is has a much higher intelligence value. This is because it is used by those trying to hide something, something which the NSA may like to know.

Have you considered contributing to organizations that make sure no single entity controls too many exits:

https://lists.torproject.org/pipermail/tor-relays/2013-Septe...

https://www.torservers.net/

Re: Things You Should Know About Tor

#14
post #9
post #5

Earlier quoted context omitted.

http://dl.acm.org/citation.cfm?id=2516651 Full article is at : http://web.elastic.org/~fche/mirrors/www.jya.com/2013/09/tor... And i've read other work that talks about using machine leanring to create realistic attacks, and another by a guy that even deanonimized some anonymous remailers. And let's not forget most implemented protocols like tls have bugs. A somewhat pessimistic view would probably say that the only…

Or even better, the full paper: http://cryptome.org/2013/08/tor-users-routed.pdf And from 2009: https://blog.torproject.org/blog/one-cell-enough > The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up. B…

[deleted]

Re: Things You Should Know About Tor

#15
post #11
post #8

Earlier quoted context omitted.

Even the NSA has to deal with the base rate fallacy. You can't just magically "correlate" traffic.

It is hard, perhaps, but a good attack for the NSA would be to run many of the exit nodes. The intelligence gathered this way would be very valuable, as the traffic on the TOR network is has a much higher intelligence value. This is because it is used by those trying to hide something, something which the NSA may like to know.

> It is hard, perhaps, but a good attack for the NSA would be to run many of the exit nodes.

It definitely doesn't control most of the exit bandwidth, unless the TorServers and blutmagie guys have been conning us for maybe a decade now.

>TOR network

Tor, not TOR.

>This is because it is used by those trying to hide something, something which the NSA may like to know.

This is a rather strong statement about the average Tor user.

Re: Things You Should Know About Tor

#16
"It is also important to remember that if you log into services like Google and Facebook over Tor, you will be sacrificing your anonymity to those services."

It is important to note that both Google and FB can track you on 3rd party websites through things like "Like" button. Consider disabling 3rd party cookies completely or using plugins like Ghostery.

Re: Things You Should Know About Tor

#17

Things I've used Tor for: - Accessing BBC Liveplayer as if I'm in England (using lots of normally discouraged add-ons and defined exit-nodes) - Bypassing paywalls (possibly still criminal?) - Bypassing censorship (which is what it really is) on organizational wifi networks (in Canadian hospitals). The funniest block was to ginger.io, a big data smartphone data analysis play (but blocked by an over-aggressive filter f…

I use Tor hidden services to punch through NATs (mostly for SSH); it's also useful in that only you can access the service (since only you know its address), so a hidden service + random port is a cheap "port knocking" implementation.

I've also used Tor to debug firewalls. It's a good way of saying "put me in a random spot on the Internet."

Outside of that, I use Tor for whatever I can: downloading RSS feeds, instant messaging, downloading email, mostly. There's no reason not to have Tor on these things because they're all either batched or tolerant of bad latency, and it destroys a little bit of my personal information that would otherwise leak.

Re: Things You Should Know About Tor

#18

Things I've used Tor for: - Accessing BBC Liveplayer as if I'm in England (using lots of normally discouraged add-ons and defined exit-nodes) - Bypassing paywalls (possibly still criminal?) - Bypassing censorship (which is what it really is) on organizational wifi networks (in Canadian hospitals). The funniest block was to ginger.io, a big data smartphone data analysis play (but blocked by an over-aggressive filter f…

[deleted]
Post reply on HN