Live data from Hacker News

Is Tor still safe to use?

blog.torproject.org

241–250 of 602 posts

Re: Is Tor still safe to use?

#241

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

75% [0] of all Tor nodes are hosted within 14 Eyes [1] countries, so it would actually be quite trivial for the NSA to de-anonymize a Tor user. It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries. [0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all [1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes > Edit: For all the cynics…

> petty criminals to get away with their crimes

Like human rights activists, journalists and dissidents in totalitarian countries.

Re: Is Tor still safe to use?

#242
post #222

Earlier quoted context omitted.

>This could cost less than $5000 for a month I ran a bunch of nodes for a couple years and that's optimistic by perhaps an order of magnitude. No $5 a month VPS provides enough bandwidth to sustain the monthly traffic of a Tor node, and nodes need to be continuously online and serving traffic for about 2-3 months[1] before they will be promoted to guard relays. Throttling traffic to stay in your bandwidth allocation…

Still easily within the budget of the US, Russia, China, Israel, etc. I wouldn't be surprised if a majority of nodes are ran by intelligence agencies.

In fact, you should assume they are. This doesn't imply the network doesn't have utility for a given actor.

Re: Is Tor still safe to use?

#243

Remember the Harvard student that emailed in a bomb threat via Tor to get out of a final exam in 2013? He got caught not by the FBI breaking Tor, but just by network analysis of university network traffic logs showing a very narrow list of on-campus people using Tor at the time the threat was communicated. He quickly confessed when interviewed. https://www.washingtonpost.com/blogs/the-switch/files/2013/1... Just anot…

If he simply didn’t confess, they likely could not have proven it was him - but yes, it is best to avoid suspicion altogether.

Re: Is Tor still safe to use?

#244

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

> what is the probability that someone randomly chooses three nodes that you own. The answer is less than 0.14%. You calculated the probability that a specific person randomly chooses three nodes of the 1,000. But that's not the scenario you're responding to. >> I can't target a specific person, but eventually I can find someone who has all three bounces through tor nodes I control Tor estimates that 2.5 million peop…

> could capture the sessions of 10,940 criminals in a given month

Let’s say to do that, and now you have found 10k people accessing pirate bay in countries where it is blocked.

Also you captured someone who lives in Siberia and watches illegal porn, now what?

Many of these will not be actionable, like not criminals you would have interest in.

Re: Is Tor still safe to use?

#245
post #236

Earlier quoted context omitted.

Using Tor, like all security and privacy tools, must be balanced against what it is being used for. We will always live in a world of limited resources for policing, and systems of privacy work by increasing the difficulty and cost to deanonymize someone. They don't have to be perfect, they just have to be expensive. If you want basic anonymity while researching someone powerful or accessing information, it's extreme…

>If you want basic anonymity while researching someone powerful or accessing information, it's extremely unlikely anyone is going to go the lengths people are bringing up here as a way to compromise Tor. The intersection of expertise, funding and time required is too great for such a low value target. Doesn't a solid VPN service also satisfy this exact need? Tor seems to occupy a narrow niche in which you have to car…

> Doesn't a solid VPN

Finding a solid one is the hard part. With tor, you kind of know what you are buying. The risks are in the open. With VPN maybe the operator is selling your data to advertizers. Maybe they are keeping logs. You kind of have to just trust them and have no way to verify.

Re: Is Tor still safe to use?

#246
post #38

Earlier quoted context omitted.

Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. I know ISPs, especially national ISPs like AT&T (see: titanpointe - 33 thomas st, nyc) would feed data to NSA since traffic at the time was mostly via http (rather than https). I suppose the unencrypted dns queries are still useful (although DNSSEC is supposed to defend against snooping/deep packet inspection)

>Wonder what has replaced “Xkeyscore” given the wide adoption of TLS. Cloudflare is a US-based company that does MITM attacks on all traffic of the websites that it protects. It's part of how their DDoS mitigation works. Many people still use large US-based mail providers such as Outlook or Gmail. Many large services use AWS, GCP or Azure. Perhaps there are ways for the NSA to access customers' virtual storage or MIT…

Load Balancing && WAF or CDN enablement usually suggests at least a decrypt step or two in the HTTP(s) chain. WAF for layer7 payload inspection, or the default wildcard cert'ing your Cloudflare site for instance.

There's also significant aggregation of traffic at handfuls of service providers amongst service categories, all generally HTTP(s) type services too ... Mail, CDN, Video, Voice, Chat, Social, etc. Each of these are still likely to employ Load Balancing & WAF.

Most WAF/Load Balancing providers have documentation about when/where to perform decrypt in your architecture.

How many Cloudflare sites are just using the Cloudflare wildcard cert?

From there, plenty of 3 letter agency space to start whiteboarding how they might continue to evolve their attack chain.

Re: Is Tor still safe to use?

#247

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

If someone would do the thing-to-be-detected (e.g. accessing CSAM) every day, then that 0.14% probability of detection turns out to be 40% for a single year (0.9986^365) or 64% over two years, so even that would deanonymize the majority of such people over time.

That is why in tor it picks a specific guard node and sticks with it. To prevent this kind of attack where you change nodes until you hit a bad one.

Re: Is Tor still safe to use?

#248

Earlier quoted context omitted.

>Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geogra…

> what is the probability that someone randomly chooses three nodes that you own. The answer is less than 0.14%. You calculated the probability that a specific person randomly chooses three nodes of the 1,000. But that's not the scenario you're responding to. >> I can't target a specific person, but eventually I can find someone who has all three bounces through tor nodes I control Tor estimates that 2.5 million peop…

> could capture the sessions of 10,940 criminals

What does that mean? The way I understand it you would be getting traffic correlations -- which means an IP that requested traffic from another IP and got that traffic back in a certain time period. What does that tell you, exactly, about the criminal? If you aren't looking for a specific person, how would you even know they are doing crimes?

Re: Is Tor still safe to use?

#249
post #236

Earlier quoted context omitted.

>If you want basic anonymity while researching someone powerful or accessing information, it's extremely unlikely anyone is going to go the lengths people are bringing up here as a way to compromise Tor. The intersection of expertise, funding and time required is too great for such a low value target. Doesn't a solid VPN service also satisfy this exact need? Tor seems to occupy a narrow niche in which you have to car…

> Doesn't a solid VPN Finding a solid one is the hard part. With tor, you kind of know what you are buying. The risks are in the open. With VPN maybe the operator is selling your data to advertizers. Maybe they are keeping logs. You kind of have to just trust them and have no way to verify.

This hypothetical was about "a low value target" looking for "basic anonymity". Just get Mullvad and assume the entire company wasn't a 15 year long con set up to better target ads at you specifically.

Re: Is Tor still safe to use?

#250
post #151

Earlier quoted context omitted.

The skilled labor to set that all up, especially in a way that TOR won't notice and shut you down will be worth much much more than $5k. People that have such a sophisticated and resourced team actively hunting them down, likely know about it, and are using many additional layers of security on top of TOR. Even just for personal use out of curiosity to "see what the darkweb is," I used 1-2 additional methods on top o…

> used 1-2 additional methods on top of TOR Curious: what did you do and what were you hoping to mitigate?

Just playing around, not mitigating anything. I think it would be poor practice to share my ideas/techniques- think of your own! Contrary to popular philosophy- obscurity is a powerful security method. People still rob houses with expensive locks… nobody robs secret underground bunkers.
Post reply on HN