Earlier quoted context omitted.
only exit nodes get there door kicked in and they are the minority and not needed for the tor network to function
They are pretty essential, without them you can only access onion services.
Is Tor still safe to use?
561–570 of 602 posts
Re: Is Tor still safe to use?
#562Earlier quoted context omitted.
Pardon my ignorance, but I thought it fruitful to ask: Are there any issues that can arise by doing this on a VPS? I ask because I know of stories of law enforcement sending inquiries to owners of, say, exit nodes requiring certain information about given traffic. I don't know if this happens for middle-nodes (or whatever they're called). Moreover, are there any issues with associating a node to, you know, your name…
I never operated a TOR node, but as far as I know and heard from other sources, TOR realays don't get much attention from law enforcement, it any attention at all. Which makes sense: all they're doing is getting encrypted traffic in and giving encrypted traffic out. It would hard for them to link a relay node to a specific connection, and even if they do, you can't help them in any way: even you as the node operator…
If your threat model is actually three letter agencies coming after you specifically... that's an entirely different problem not (just) solved by software.
Re: Is Tor still safe to use?
#563The more privacy the better as far as I'm concerned, but I've never used tor. What are people using tor for? General comms, piracy (mild illegal), other (very illegal), ...?
Besides regular browsing (basically a free VPN), a pretty nice use case of Tor is that some news sites have non-paywalled onion addresses. The Guardian: https://www.guardian2zotagl6tmjucg3lrhxdk4dw3lhbqnkvvkywawy3... New York Times: https://www.nytimesn7cgmftshazwhfgzm37qxb44r64ytbb2dj3x62d2l... BBC: https://www.bbcweb3hytmzhn5d532owbu6oqadra5z3ar726vq5kgwwn6a...
Re: Is Tor still safe to use?
#564I am interested in the “legitimate” uses for tor. I have not kept up with this but I understand it was designed by US Navy to make it hard for oppressive regiemes to track their citizens use of web. What do we want Tor for except as a hope that Russian citizens might be able to get to the BBC site? I am asking honestly - and would prefer not to be told my own government is on the verge of a mass pogrum so we had bett…
How would you feel if a stranger came up to you in the street and said they appreciated the wiki article you were reading last night? I think everyone wants “privacy by default”, they just don’t make the connection between this hypothetical and real life. In real life you’re still spied but nobody confronts you directly.
I mean he probably could hear it, and I hope no one on HN who heard their neighbour would bring it up on the street !
We do not have secrecy. We have privacy which is merely the politeness of our neighbours (which is of course a social construct of behaviour).
The internet has given new spaces that have not yet had the time for us to learn such behaviours. What will help us is making the internet more like our daily lives. No anonymity, etc.
But people somehow think the internet should be different - it’s not and it’s better - if we think our lives should be more free then politics is the pave for that not the router.
Re: Is Tor still safe to use?
#565Re: Is Tor still safe to use?
#566Earlier quoted context omitted.
When you think about countries that have the resources to "pay a thousand different isps in a thousand different ways with a thousand different os versions and tor versions" your first thought was Iran?
My first thought was actually "I could probably do that myself given some motivation" Hiring people on something like fiverr could take care of most of the manual part. My point is that if I could do it, a nation state cracking down on dissidents could likely do it too.
Iran really is not the first country that should come to anyone's mind given how far it is from home.
Re: Is Tor still safe to use?
#567Earlier quoted context omitted.
Servers in the public cloud are a lot easier to do traffic analysis on.
Each server is only used by a single operative though, how do you even find which IP to analyze? The story with Tor and espionage is that if an asset connected to cia website the gov which monitors internet access would know they went to the site. Even if its not a public site they just need to have one operative defect and tell them the site and they can catch all the other operatives who use it. But if everyone con…
I assume that they're connecting multiple times with the CIA - it's not just a one and done drop. That's trivial to look at - if you see someone connecting repeatedly to an IP address that doesn't associate with any known website/service and you see them do it consistently then that's suspicious.
Maybe if the IP addresses rotated it wouldn't be as noticeable, but if you're going over the clearnet then you can't disguise the IP address you're connecting to (short of proxies but then you're giving up the IP address of the proxies).
Re: Is Tor still safe to use?
#568Earlier quoted context omitted.
Each server is only used by a single operative though, how do you even find which IP to analyze? The story with Tor and espionage is that if an asset connected to cia website the gov which monitors internet access would know they went to the site. Even if its not a public site they just need to have one operative defect and tell them the site and they can catch all the other operatives who use it. But if everyone con…
> But if everyone connects to a different IP I dont see how traffic analysis helps you discover you is connecting with the cia. I assume that they're connecting multiple times with the CIA - it's not just a one and done drop. That's trivial to look at - if you see someone connecting repeatedly to an IP address that doesn't associate with any known website/service and you see them do it consistently then that's suspic…
Re: Is Tor still safe to use?
#569Earlier quoted context omitted.
I mean, sure. And while we're at it pigs should fly. Functional security means understanding your risks, and using privacy tools is a risk - in the sense that it does single you out in the current environment. Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough. Just saying "everyone sho…
> I mean, sure. And while we're at it pigs should fly. Pigs have significantly higher density than birds and lack wings. Getting them to fly under their own power would be quite a challenge. By contrast, installing Tor Browser is actually pretty easy. > Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get…
My statement is pretty clear - using a privacy tool can single you out. Am I afraid of that in the US? Nope, not really.
Would I be afraid of that in, say, Iran? North Korea? Russia? Israel? China? Probably.
> If you live in an authoritarian country and actively oppose the government, you are already doing something that will get you punished if you're caught and then the question is, which is more likely to get you caught? Tor has several measures to reduce the probability that you're detected. Private entry guards, pluggable transports, etc. You might still get caught, but these things reduce the probability, whereas if you openly oppose the government without using any privacy technology, you're much easier to catch. Using it in this case is pretty clearly to your advantage.
You know a clear way to avoid this risk entirely? Don't trust your communications to a public network. Is TOR better than posting directly online? probably. Is TOR still a risk? Obviously yes. Understanding your risks is important, and simply saying "Use it anyways" is not an appropriate answer. Like... at all.
Re: Is Tor still safe to use?
#570Earlier quoted context omitted.
The attack Germany is thought to have actually used was to flood the network with middle nodes and wait until the victim connects to their middle node. Then, it knows the guard node's IP. Then, it went to an ISP and got logs for everyone who connected to that IP.
technicly this is the only comment in this chain that is relevant to the featured article, but it's technicly so incomplete that it's almost wrong, I can tell from having read the thread and knowing next to nothing else about how TOR works. They don't have plausible evidence to subpoena the guard node if a middle node only sees encrypted traffic. They would also need to control the exit nodes which communicate with t…