Earlier quoted context omitted.
If they run just the exit node they still can’t de-anonymize you right?
Depends on the content of your traffic. If “deanonymize” strictly means perform a timing attack using info you have from the beginning and end of the circuit, then by definition you’re correct. But if you visit an identifying set of websites and/or ignore TLS errors or … they can still deanonymize you.
Is Tor still safe to use?
211–220 of 602 posts
Re: Is Tor still safe to use?
#212Earlier quoted context omitted.
> A VPS is $5 a month. With insignificant data caps. To get the data needed I believe you're looking at a couple hundred a month, to start.
Running exit nodes is also likely to result in getting booted from most VPS or even bare metal providers, maybe unless you BYOIP.
Re: Is Tor still safe to use?
#213Earlier quoted context omitted.
>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…
> there has never been an uptick in arrests If it was effective, would there have been a down tick in arrests at some point? Or if the arrest rate stayed the same, would that suggest it never “worked” to begin with? It’s like the movie trope of the detective who finds out the truth via some questionable means which isn’t admissible in court. When you know the truth you can push harder and call every bluff until you g…
Re: Is Tor still safe to use?
#214Sincere question. This was created with US government funding. Is there any reason to believe it is safe?
So my answer to your sincere question: no reason to believe it is safe, no.
Re: Is Tor still safe to use?
#215Earlier quoted context omitted.
https://blog.torproject.org/tips-running-exit-node/
Ah, there are people who use Tor to access non-onion services. Got it. Seemed like onion services were created to solve the security issues that exit nodes bring, so I assumed people stopped using them and started running onion services instead.
Re: Is Tor still safe to use?
#216Earlier quoted context omitted.
Depends on the content of your traffic. If “deanonymize” strictly means perform a timing attack using info you have from the beginning and end of the circuit, then by definition you’re correct. But if you visit an identifying set of websites and/or ignore TLS errors or … they can still deanonymize you.
What role do TLS errors play in de-anonymizing onion traffic?
Ignoring TLS errors might mean you’re ignoring the fact your exit relay is MitM attacking you.
Re: Is Tor still safe to use?
#217>A guard discovery attack allows attackers to determine the guard relay of a Tor client. The hidden service protocol provides an attack vector for a guard discovery attack since anyone can force an HS to construct a 3-hop circuit to a relay, and repeat this process until one of the adversary's middle relays eventually ends up chosen in a circuit. These attacks are also possible to perform against clients, by causing an application to make repeated connections to multiple unique onion services.
Re: Is Tor still safe to use?
#218Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…
If you want basic anonymity while researching someone powerful or accessing information, it's extremely unlikely anyone is going to go the lengths people are bringing up here as a way to compromise Tor. The intersection of expertise, funding and time required is too great for such a low value target.
If you're an international terrorist leader wanted in multiple countries, a prolific criminal, or enemy #1 of an authoritarian state though? Those who can go to those lengths absolutely will go to those lengths.
Re: Is Tor still safe to use?
#219Here is what I don't understand: Let's say I as a private individual fund 1000 tor nodes (guard and exit nodes included) and have them all log everything. This could cost less than $5000 for a month, with some time needed to get guard node status. I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url. Surely eventually I'm going to get a hit where all three…
>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…
During WW2, the British cracked the German codes. They would create pretexts for "discovering" where German ships would be, so that the Germans wouldn't suspect that they cracked their codes.
It's impossible for us to know if the US government have cracked Tor, because the world would look identical to us whether they had or hadn't. If the only evidence they have is via Tor, and the individual is a small fry, they will prefer they get away with it rather than let people know that Tor has been cracked.
I just assume the NSA are spending their budgets on something, although maybe it is stuff like side channel attacks.
Re: Is Tor still safe to use?
#220Earlier quoted context omitted.
No? Any modern disk encryption system with a strong passphrase (basically, anything but default-BitLocker) is very effective against "they have your physical machine and it's off" for any known, current adversary. And, the basic cryptography in use is common, robust, and proven enough that this is probably true even if your tinfoil hat is balled quite tightly. Where modern research effort goes is into protecting agai…
Disagree. If one has physical access to your machine, they also have physical access to you. Practically everyone is vulnerable to rubber hose cryptanalysis.