Live data from Hacker News

How Secure is Tor? Not secure at all

csam-bib.github.io

31–40 of 57 posts

Re: How Secure is Tor? Not secure at all

#31
post #19

Earlier quoted context omitted.

The assumption is the adversary controls x of N nodes. When x=N the probability of discovering the onion service IP is 1. But the adversary can not achieve this situation as he only controls the additional nodes. The existing nodes still stay in the network, they do not disappear. The ratio is not x/N but x/(x+N). The formula is wrong and it all falls apart.

You can adjust the code on the page easily (it’s open source javascript) to determine the question you are after, which is a valid one: if an adversary starts today and adds x nodes to the existing network, what is their success rate? BUT the author asked a different (but valid) question: assuming the adversary controls x out of N existing nodes, what is the success rate? I am unclear: is the assertion that everyone’…

No, the author is presenting an idea that $25 a month can buy you a node. That fits adding a new node to the network, not taking over an existing node.

Re: How Secure is Tor? Not secure at all

#32

Earlier quoted context omitted.

> Why can’t other nodes have freedom to decide how they want to participate? Because the network was explicitly designed to not allow this... otherwise it becomes subject to censorship, which is one of the main goals they try to prevent. The (onion) address itself is never transmitted in plaintext through the Tor network... when you access an onion site, your Tor client encrypts the traffic multiple times, literally…

It is absolutely a design decision. I don’t understand though how allowing exit nodes to filter (by port and IP) doesn’t permit censorship but allowing internal nodes to not complete connections to onion sites does. I do understand that early nodes on the path are unaware of what the traffic but it seems pretty straightforward to allow nodes to not become rendezvous points for onion sites.

You are welcome to fork Tor and create a version that uses this approach, but good luck getting people to use it.

Conversely, even if the official project implemented an onion blacklist, a fork would quickly appear to remove it. And node operators would likely prefer that one.

Anyone with any sense understands that introducing a node blacklist creates the capability to expand the use of that blacklist in the interest of political and/or military censorship. The Tor project, Tor devs, and node operators are adamantly opposed to any such censorship capabilities. Therefore it will not happen, period.

Re: How Secure is Tor? Not secure at all

#33
post #6

I'm not here to defend Tor But the calculator states that if the investigating party has $150,000 a month budget for all targets they have a 100% certainty of getting your IP address... obviously this is false, so what else has the author claimed that is also not true?

Pretty much everything claimed on this site is false or grossly misleading.

Not only is it misleading, but given how it’s presented, it’s clearly FUD in the interest of the author’s pet cause (campaigning against Tor use due to a perceived association with CSAM).

Re: How Secure is Tor? Not secure at all

#34

Earlier quoted context omitted.

As a percent of onion services, what does it work out to, a few percent? And how much of that is dedicated abuse sites versus general adult sites?

Your question made me curious so I tried to see what information about onion sites is available. It’s hard to measure onions sites by design, but https://99firms.com/research/tor-stats Says there seem to be about 65k onion sites. This site: https://protectchildren.ca/en/press-and-media/blog/2025/tor-... Has some varying numbers depending on the observation time, but in final month listed saw 30k sites that had they i…

Looks like the tor metrics site says ~900k onion sites?

https://metrics.torproject.org/hidserv-dir-v3-onions-seen.ht...

Re: How Secure is Tor? Not secure at all

#35

Earlier quoted context omitted.

Maybe because there isn't a known solution? CSAM is still distributed on the clearnet too... why isn't there a "solution" for that too? So far the only solutions people seem to have come up with is mass surveillance, and that's not an option.

There is a known solution. Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok. However, if a relay refuses to service an onion site directory look up, it will be banned by the Directory Authority. They could allow this today. But they don’t. That’s the simple solution. No surveillance. Not back door. No less privacy for everyone else. edit: This is easy to…

>Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok.

That's simply not true. Exit operators who intentionally block websites are flagged as bad relays.

https://community.torproject.org/policies/relays/expectation... https://gitlab.torproject.org/tpo/network-health/team/-/wiki...

Re: How Secure is Tor? Not secure at all

#36

If an adversary is spending tens or hundreds of thousands of dollars to find you, that's a lift that most threat actors won't be able to do. Especially if they have to host a significant number of exit nodes for a lengthy period, which often means serving unlawful content which is very awkward for law enforcement. It's definitely better than regular browsing for security, but it's not perfect.

It’s a drop in the bucket for state actors who might want to find TORs target user base of dissidents, whistleblowers, and journalists.

It’s extremely unlikely that they would be able to find an end user (not an onion site operator, a user) with good opsec who connects occasionally, such as a journalist uploading a few documents to a secure onion drop. All existing known attacks were against onion site operators running for long periods from a static location (still took a lot of resources and time to track them down) or end users with poor opsec/infosec.

The whole thing reads as scaremongering FUD to prevent people from using Tor, with further FUD tacked on to make people think that using it might be illegal somehow. Tor is actually great for personal infrastructure (no need for domain names or a static IP), limited anonymity, and censorship resistance.

Re: How Secure is Tor? Not secure at all

#37

Earlier quoted context omitted.

It is absolutely a design decision. I don’t understand though how allowing exit nodes to filter (by port and IP) doesn’t permit censorship but allowing internal nodes to not complete connections to onion sites does. I do understand that early nodes on the path are unaware of what the traffic but it seems pretty straightforward to allow nodes to not become rendezvous points for onion sites.

You are welcome to fork Tor and create a version that uses this approach, but good luck getting people to use it. Conversely, even if the official project implemented an onion blacklist, a fork would quickly appear to remove it. And node operators would likely prefer that one. Anyone with any sense understands that introducing a node blacklist creates the capability to expand the use of that blacklist in the interest…

That’s not at all what I proposed. Not even close.

Edit: on second look I can see how you could think it was. I’m just proposing that if you run a node you be allowed to not become a rendezvous point for onion sites.

Re: How Secure is Tor? Not secure at all

#38

Earlier quoted context omitted.

It’s a drop in the bucket for state actors who might want to find TORs target user base of dissidents, whistleblowers, and journalists.

It’s extremely unlikely that they would be able to find an end user (not an onion site operator, a user) with good opsec who connects occasionally, such as a journalist uploading a few documents to a secure onion drop. All existing known attacks were against onion site operators running for long periods from a static location (still took a lot of resources and time to track them down) or end users with poor opsec/inf…

The site linked takes a shot at enumerating how unlikely it is. Do you claim it is wrong? If so, what is your calculated chance?

To me, TOR is not adequate to protect users targeted by a nation state who are the ones that TOR claims to be created for.

Re: How Secure is Tor? Not secure at all

#39

Earlier quoted context omitted.

Pretty much everything claimed on this site is false or grossly misleading.

Not only is it misleading, but given how it’s presented, it’s clearly FUD in the interest of the author’s pet cause (campaigning against Tor use due to a perceived association with CSAM).

Tor isn't without its weaknesses, but this author is simultaneously claiming child predators are successfully evading law enforcement despite their identity only coming at the relatively low price of ~$150k.

Re: How Secure is Tor? Not secure at all

#40

Earlier quoted context omitted.

Your question made me curious so I tried to see what information about onion sites is available. It’s hard to measure onions sites by design, but https://99firms.com/research/tor-stats Says there seem to be about 65k onion sites. This site: https://protectchildren.ca/en/press-and-media/blog/2025/tor-... Has some varying numbers depending on the observation time, but in final month listed saw 30k sites that had they i…

Looks like the tor metrics site says ~900k onion sites? https://metrics.torproject.org/hidserv-dir-v3-onions-seen.ht...

In reality there are fewer than 1000 "real" hidden services (see https://rnsaffn.com/zg4/ for HTTP response dumps) and an ocean of short-lived temporary spam onions, most of them pornography.
Post reply on HN