Live data from Hacker News

Things You Should Know About Tor

eff.org

111–115 of 115 posts

Re: Things You Should Know About Tor

#111
post #13
post #11

Earlier quoted context omitted.

It is hard, perhaps, but a good attack for the NSA would be to run many of the exit nodes. The intelligence gathered this way would be very valuable, as the traffic on the TOR network is has a much higher intelligence value. This is because it is used by those trying to hide something, something which the NSA may like to know.

Have you considered contributing to organizations that make sure no single entity controls too many exits: https://lists.torproject.org/pipermail/tor-relays/2013-Septe... https://www.torservers.net/

If I wanted to support the NSA, I'm sure I'd do volunteer work for those organizations -- and if I ran an intelligence agency, I'm sure I'd recruit assets off university campuses across the globe. Just saying.

Re: Things You Should Know About Tor

#112

Earlier quoted context omitted.

You don't address my specific point; namely that it is not only possible but relatively inexpensive for any nation-state to compromise users' anonymity on Tor en masse not by cracking its cryptography but by running >50% of the nodes themselves.

a bit of a pedantic note: If you want to control 50% of the servers by adding servers, you actually have to double the total server count... ie, 8k servers now, if you want to control 50% you have to add 8k of your own servers for 16k total servers ...

Indeed, but my proposition is that they already did that, some time ago. It's just such a small amount of money that it seems unlikely that they _didn't_ do this.

Re: Things You Should Know About Tor

#114

I have a very strong suspicion that Tor is completely compromised, and that's actually how they caught Ross Ulbricht (Silk Road). All the stuff about his previous posting, etc, is tenuous and circumstantial-- it seems totally feasible that it is parallel construction. The "Tor Sucks" document is from 2012. It talks about the GCHQ running Tor nodes. What could have happened in the years since? https://metrics.torproje…

> All the stuff about his previous posting, etc, is tenuous and circumstantial-- it seems totally feasible that it is parallel construction.

I've done similar things in the past (trying to find a user's real identity, when that user has taken active steps to stop anyone finding out - before you ask, tracking scammers, not doxxing innocents) and to me it sounded totally plausible. He made exactly the same kind of mistakes many of the people I've tracked down did, and they found him the same way I would have gone about it.

Re: Things You Should Know About Tor

#115
post #17

Earlier quoted context omitted.

I use Tor hidden services to punch through NATs (mostly for SSH); it's also useful in that only you can access the service (since only you know its address), so a hidden service + random port is a cheap "port knocking" implementation. I've also used Tor to debug firewalls. It's a good way of saying "put me in a random spot on the Internet." Outside of that, I use Tor for whatever I can: downloading RSS feeds, instant…

Latency is a problem for me. Maybe for some users, who already have very slow internet, or who live in areas with more TOR relays, it is not so noticeable, but for me the speed difference is about 10 times. Mostly not because TOR would be unbearably slow (it is not slower than regular internet 8 years ago), but because regular internet is very fast where I live.

I mean, you'll notice my strategy is to never torify anything where I'd have to actually wait for it. Except IM, which is small enough that it doesn't matter, anything I've torified is downloaded in the background anyway.
Post reply on HN