Live data from Hacker News

Is Tor still safe to use?

blog.torproject.org

171–180 of 602 posts

Re: Is Tor still safe to use?

#172

Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…

You only need to control the entry and exit node - since you know the next and previous hop for all traffic you touch, and default chains are 3 long. With circuits changing every 10 mins, within a few days you would have deanonymized at least some percentage of traffic for nearly every user. I'd call tor broken against any adversary with a little technical skill and willingness to spend $5000. I'm 80% sure Tor is des…

I imagine most exit nodes are likely controlled by the US government and/or its close allies. Who else wants to have their IP address banned from most of the internet and potentially get visits from their country's equivalent of the FBI?

If most Tor users ran exit nodes and most people used Tor, it would effectively make internet traffic anonymous. But without those network effects, it is vulnerable by design to deanonymization attacks by state actors.

Re: Is Tor still safe to use?

#173
post #38

Earlier quoted context omitted.

Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. I know ISPs, especially national ISPs like AT&T (see: titanpointe - 33 thomas st, nyc) would feed data to NSA since traffic at the time was mostly via http (rather than https). I suppose the unencrypted dns queries are still useful (although DNSSEC is supposed to defend against snooping/deep packet inspection)

>Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. Cloudflare is a US-based company that does MITM attacks on all traffic of the websites that it protects. It's part of how their DDoS mitigation works. Many people still use large US-based mail providers such as Outlook or Gmail. Many large services use AWS, GCP or Azure. Perhaps there are ways for the NSA to access customers' virtual storage or MIT…

Worse is how most email providers require SMS confirmation or a secondary email.

Re: Is Tor still safe to use?

#175
post #38

Earlier quoted context omitted.

Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. I know ISPs, especially national ISPs like AT&T (see: titanpointe - 33 thomas st, nyc) would feed data to NSA since traffic at the time was mostly via http (rather than https). I suppose the unencrypted dns queries are still useful (although DNSSEC is supposed to defend against snooping/deep packet inspection)

A lot of pages are now behind CF, hosted on AWS,... It would surprise me if these providers didn't share their data with the 3-letter agencies.

I'd argue any data center of cloudflare is just as valuable to fiber tap, just like the undersea fiber cables.

Re: Is Tor still safe to use?

#176
post #120

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

You know what's easier than waiting around to get really lucky? Using those same network-health dashboards as DDoS target lists, to temporarily degrade/shut down the whole network except for your own nodes. Also, big nodes route more Tor circuits each. Costs more to run them, and they intentionally don't function as exit nodes (to avoid the "obvious" attack) — but just having a bunch of these big nodes in the network…

[deleted]

Re: Is Tor still safe to use?

#177

Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…

It'd be ten times that cost, easily. You have to buy data volume.

Also since you aren't targetting specific people, rather specific interests, it'd be easier to setup an irresistible site serving content of the vice of interest. It can even be a thin wrapper on existing sites. Do you only need to control entry nodes in that case? You'll return user-identifying data in headers or steganographically encoded in images and since you control the entry node you can decrypt it. It doesn't work for a normal (unaffiliated) entry node but since your entry node is in collusion with the server I think this works.

Re: Is Tor still safe to use?

#178

Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

75% [0] of all Tor nodes are hosted within 14 Eyes [1] countries, so it would actually be quite trivial for the NSA to de-anonymize a Tor user.

It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries.

[0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all

[1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes

> Edit: For all the cynics and doomsayers here, consider this: Tor has been around for a long time, but there has never been an uptick in arrests that could be correlated to cracking the core anonymity service. If you look closely at the actual high profile cases where people got busted despite using tor, these people always made other mistakes that led authorities to them.

Maybe someone, somewhere, has decided that allowing petty criminals to get away with their crimes is worth maintaining the illusion that Tor is truly private.

It's also worth noting that it's significantly easier to find the mistakes someone has made that could lead to their identity if you already know their identity.

Re: Is Tor still safe to use?

#179

Earlier quoted context omitted.

My point is that it doesn't require "vast resources". A VPS is $5 a month. A thousand of them would be in the disposable income budget of a single FAANG engineer never mind a nation state. Pay people on Fiverr to set them up for you at different ISPs so that all the setup information is different. You can use crypto to pay if you want anonimity (this is actually the main reason I used to use bitcoin - I'd pay ISPs in…

> A VPS is $5 a month. With insignificant data caps. To get the data needed I believe you're looking at a couple hundred a month, to start.

Running exit nodes is also likely to result in getting booted from most VPS or even bare metal providers, maybe unless you BYOIP.

Re: Is Tor still safe to use?

#180
post #3

For context, here's the NDR report: https://www.ndr.de/fernsehen/sendungen/panorama/aktuell/Inve... And more info here: https://lists.torproject.org/pipermail/tor-relays/2024-Septe... Edit: The NDR alleges a timing attack (no further explanation) that allows "to identify so-called ‘entry servers’" Very little information is actually available on the nature of the attack. The NDR claims this method has already lead to…

This should be the article linked at the top.
Post reply on HN