Live data from Hacker News

How Secure is Tor? Not secure at all

csam-bib.github.io

21–30 of 57 posts

Re: How Secure is Tor? Not secure at all

#21

Earlier quoted context omitted.

Maybe because there isn't a known solution? CSAM is still distributed on the clearnet too... why isn't there a "solution" for that too? So far the only solutions people seem to have come up with is mass surveillance, and that's not an option.

There is a known solution. Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok. However, if a relay refuses to service an onion site directory look up, it will be banned by the Directory Authority. They could allow this today. But they don’t. That’s the simple solution. No surveillance. Not back door. No less privacy for everyone else. edit: This is easy to…

Exit nodes are not used for onion services. From https://onionservices.torproject.org/technology/properties/:

> For the Tor network, Onion Services can alleviate the load on exit nodes, since it's connections don't need to reach the exits.

Also:

> Directory Authority.

"These authorities are operated by trusted organizations or individuals with a strong commitment to the principles of privacy, security, and network neutrality."

Emphasis on neutrality... it's not the job of network operators to police the sites people can and can't access, this is exactly why many people use Tor in the first place.

> They could allow this today. But they don’t.

Speaking for onion services... no, they cannot, because the entire design of the tor network prevents this in the first place. No relay in the circuit knows the final destination because it is encrypted multiple times (like an onion) and each hop can only see where it needs to go next, not what the destination is.

Re: How Secure is Tor? Not secure at all

#22
Clickbait title is usually a good indicator of clickbait content.

I see in the comments that the author is an academic, my cursory look of the site makes me disappointed to see such weak rigor applied here. This looks like a hit piece dressed up to sound scary. Not going to waste my time further on its claims when on the surface its given me this impression. Strikes me as yelling and not listening type of personality.

Re: How Secure is Tor? Not secure at all

#23

Earlier quoted context omitted.

There is a known solution. Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok. However, if a relay refuses to service an onion site directory look up, it will be banned by the Directory Authority. They could allow this today. But they don’t. That’s the simple solution. No surveillance. Not back door. No less privacy for everyone else. edit: This is easy to…

Exit nodes are not used for onion services. From https://onionservices.torproject.org/technology/properties/ : > For the Tor network, Onion Services can alleviate the load on exit nodes, since it's connections don't need to reach the exits. Also: > Directory Authority. "These authorities are operated by trusted organizations or individuals with a strong commitment to the principles of privacy, security, and network n…

I think the point is that exit node operators can filter traffic they don’t want to support. Guard and middle nodes are not given the same choice; they apparently must support all traffic or get booted. Why can’t other nodes have freedom to decide how they want to participate?

Re: How Secure is Tor? Not secure at all

#24
post #7

"As C3P will tell you: CSAM distribution on Tor onion services is not inevitable." Lol, are we using the regular internet as an example of preventing all CSAM? We've known for years that owning enough nodes results in the compromise of privacy and that it's likely the NSA has achieved this. Although there is some question around how that plays out if adversaries like China are also competing for similar node share pe…

There is no question about that. The site makes use of current statistics from the Tor Project.

As a percent of onion services, what does it work out to, a few percent? And how much of that is dedicated abuse sites versus general adult sites?

Re: How Secure is Tor? Not secure at all

#25
post #19

Earlier quoted context omitted.

The math and the code is all there. I’d love to have a discussion about what the real value is. Further, why hasn’t the Tor Project provided this calculation? Why hasn’t anyone? I think it’s necessary.

The assumption is the adversary controls x of N nodes. When x=N the probability of discovering the onion service IP is 1. But the adversary can not achieve this situation as he only controls the additional nodes. The existing nodes still stay in the network, they do not disappear. The ratio is not x/N but x/(x+N). The formula is wrong and it all falls apart.

You can adjust the code on the page easily (it’s open source javascript) to determine the question you are after, which is a valid one: if an adversary starts today and adds x nodes to the existing network, what is their success rate?

BUT the author asked a different (but valid) question: assuming the adversary controls x out of N existing nodes, what is the success rate? I am unclear: is the assertion that everyone’s relay is honest today? From a privacy standpoint, that’s not a great assumption.

Re: How Secure is Tor? Not secure at all

#26

Earlier quoted context omitted.

Exit nodes are not used for onion services. From https://onionservices.torproject.org/technology/properties/ : > For the Tor network, Onion Services can alleviate the load on exit nodes, since it's connections don't need to reach the exits. Also: > Directory Authority. "These authorities are operated by trusted organizations or individuals with a strong commitment to the principles of privacy, security, and network n…

I think the point is that exit node operators can filter traffic they don’t want to support. Guard and middle nodes are not given the same choice; they apparently must support all traffic or get booted. Why can’t other nodes have freedom to decide how they want to participate?

> Why can’t other nodes have freedom to decide how they want to participate?

Because the network was explicitly designed to not allow this... otherwise it becomes subject to censorship, which is one of the main goals they try to prevent.

The (onion) address itself is never transmitted in plaintext through the Tor network... when you access an onion site, your Tor client encrypts the traffic multiple times, literally like an onion. No relay in the circuit knows the final destination.

Re: How Secure is Tor? Not secure at all

#27

Earlier quoted context omitted.

There is no question about that. The site makes use of current statistics from the Tor Project.

As a percent of onion services, what does it work out to, a few percent? And how much of that is dedicated abuse sites versus general adult sites?

Your question made me curious so I tried to see what information about onion sites is available. It’s hard to measure onions sites by design, but

https://99firms.com/research/tor-stats

Says there seem to be about 65k onion sites.

This site:

https://protectchildren.ca/en/press-and-media/blog/2025/tor-...

Has some varying numbers depending on the observation time, but in final month listed saw 30k sites that had they identified as having CSAM.

I’m not sure how accurate either number is or if they are directly comparable but that would be a 50% of all onion sites ballpark.

Not sure how to measure general sites vs dedicated abuse sites.

Re: How Secure is Tor? Not secure at all

#28

Earlier quoted context omitted.

I think the point is that exit node operators can filter traffic they don’t want to support. Guard and middle nodes are not given the same choice; they apparently must support all traffic or get booted. Why can’t other nodes have freedom to decide how they want to participate?

> Why can’t other nodes have freedom to decide how they want to participate? Because the network was explicitly designed to not allow this... otherwise it becomes subject to censorship, which is one of the main goals they try to prevent. The (onion) address itself is never transmitted in plaintext through the Tor network... when you access an onion site, your Tor client encrypts the traffic multiple times, literally…

It is absolutely a design decision. I don’t understand though how allowing exit nodes to filter (by port and IP) doesn’t permit censorship but allowing internal nodes to not complete connections to onion sites does. I do understand that early nodes on the path are unaware of what the traffic but it seems pretty straightforward to allow nodes to not become rendezvous points for onion sites.

Re: How Secure is Tor? Not secure at all

#29

Earlier quoted context omitted.

Maybe because there isn't a known solution? CSAM is still distributed on the clearnet too... why isn't there a "solution" for that too? So far the only solutions people seem to have come up with is mass surveillance, and that's not an option.

There is a known solution. Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok. However, if a relay refuses to service an onion site directory look up, it will be banned by the Directory Authority. They could allow this today. But they don’t. That’s the simple solution. No surveillance. Not back door. No less privacy for everyone else. edit: This is easy to…

Your assumptions are based on faulty understanding of how tor works.

Re: How Secure is Tor? Not secure at all

#30
I wouldn't use Tor or any other anonymous services like SecureDrop without a VPN (preferably multi-hop). Otherwise you're advertising to the world that your IP address uses Tor, and that alone can be a huge reduction in the solution space for your adversary to deanoymize you.
Post reply on HN