Correct me if I'm wrong, but this feels like a long-winded way of saying: if an adversary could control a significant portion of relays without being found out and for a not-insignificant period of time, it could defeat Tor. Is it correct? Probably. Does it justify the "Not secure at all" indictment? No.
The calculator also misleads in another direction, in that it could underestimate the probability of failure by only considering the "takeover" scenario, while I think it is much more likely to be defeated via other OpSec failures.
How Secure is Tor? Not secure at all
51–57 of 57 posts
Re: How Secure is Tor? Not secure at all
#52Earlier quoted context omitted.
The site linked takes a shot at enumerating how unlikely it is. Do you claim it is wrong? If so, what is your calculated chance? To me, TOR is not adequate to protect users targeted by a nation state who are the ones that TOR claims to be created for.
Given that onion sites require six hops and that the Tor team keeps watch for suspicious node behavior, and that there is no “exit node” where you can more closely observe outgoing traffic, onion connections are actually very tough to correlate. It requires a large number of compromised nodes plus cooperation with ISPs and backbone providers, as seen in the arrest of the onion site operator a few years ago. There wer…
https://github.com/Attacks-on-Tor/Attacks-on-Tor
and if you can get the guard and exit node for a clearnet connection and the guard, rendezvous point and exit for the onion service that can be enough.
Re: How Secure is Tor? Not secure at all
#53I wouldn't use Tor or any other anonymous services like SecureDrop without a VPN (preferably multi-hop). Otherwise you're advertising to the world that your IP address uses Tor, and that alone can be a huge reduction in the solution space for your adversary to deanoymize you.
How exactly does someone in China or North Korea go about getting a multi-hop VPN to access Tor?
Re: How Secure is Tor? Not secure at all
#54Earlier quoted context omitted.
Given that onion sites require six hops and that the Tor team keeps watch for suspicious node behavior, and that there is no “exit node” where you can more closely observe outgoing traffic, onion connections are actually very tough to correlate. It requires a large number of compromised nodes plus cooperation with ISPs and backbone providers, as seen in the arrest of the onion site operator a few years ago. There wer…
But you don't need all the hops. You can run a correlation attack (which has been long known): https://github.com/Attacks-on-Tor/Attacks-on-Tor and if you can get the guard and exit node for a clearnet connection and the guard, rendezvous point and exit for the onion service that can be enough.
Come back when you have evidence of real-world attacks and not just FUD against the best current network for anonymity.
Re: How Secure is Tor? Not secure at all
#55Earlier quoted context omitted.
There is a known solution. Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok. However, if a relay refuses to service an onion site directory look up, it will be banned by the Directory Authority. They could allow this today. But they don’t. That’s the simple solution. No surveillance. Not back door. No less privacy for everyone else. edit: This is easy to…
Your assumptions are based on faulty understanding of how tor works.
Specifically, it would be easy to add code to hsdir functionality to deny requests for onion sites that are known to be related to csam. Those sites could be announced by the DAs as part of the consensus file, for example. The Tor Project currently lets exit nodes filter by IP address as long as they announce that in their config; this new functionality is of the same kind in the abstract. This change would not be a backdoor. It’s not going to weaken the privacy of anyone using Tor.
The current setup is an extremist position that children who have been abused are not deserving of privacy. It’s a position that all information deserves to be free even if that information is very clearly harmful to others and has no positive benefit to society. One can have that opinion but you won’t find many (outside of this thread) that agree.
Re: How Secure is Tor? Not secure at all
#56Earlier quoted context omitted.
But you don't need all the hops. You can run a correlation attack (which has been long known): https://github.com/Attacks-on-Tor/Attacks-on-Tor and if you can get the guard and exit node for a clearnet connection and the guard, rendezvous point and exit for the onion service that can be enough.
You ignored a substantial portion of the reply. “That can be enough”... yet it has not been. It’s actually very difficult to perform correlation attacks in a complex network, especially if the user is generating decoy traffic or passing along relay traffic, and even moreso if the end server is highly active as well. It takes an enormous amount of resources to even determine that someone may be connecting to a specifi…
But I don’t think we disagree. My view is that TOR is inadequate against a nation state attack because for some of these attacks it is easier to do mass de-anonymization and hope you get some particular user or set of users you are interested in. The resources to do this are small for something the scale of an intelligence agency, but excessively large for some local police department.
I’m not sure why you appear so hostile to citing attacks that are well-known and already part of the public threat model.
Re: How Secure is Tor? Not secure at all
#57Earlier quoted context omitted.
You ignored a substantial portion of the reply. “That can be enough”... yet it has not been. It’s actually very difficult to perform correlation attacks in a complex network, especially if the user is generating decoy traffic or passing along relay traffic, and even moreso if the end server is highly active as well. It takes an enormous amount of resources to even determine that someone may be connecting to a specifi…
> So unless you’re hunting down someone selling enriched uranium, major abuse content producers/hosters, or something of that scale, putting in all that investment to gain a fuzzy data point that likely isn’t even useful in an enforcement context is just not worth the tradeoff. But I don’t think we disagree. My view is that TOR is inadequate against a nation state attack because for some of these attacks it is easier…
There just aren’t that many people who are both legitimate and likely targets of such an attack. And since the most likely actor to be able to afford such an attack (USG) also has practical uses for Tor, IMHO it would be unlikely to do anything that actually threatens the network. I could be misremembering, but I believe the one big successful deanonymization attack was in Europe, not the US, and the approach used there would not have worked to locate an occasional end user of a busy server.
I am not really interested in debating this further. Feel free to respond of course, but it’s obvious to me (and hopefully everyone else) that you have an axe to grind against Tor.