Live data from Hacker News

Things You Should Know About Tor

eff.org

71–80 of 115 posts

Re: Things You Should Know About Tor

#71

I'm probably going to take some flack for this, but I don't trust Tor. When you access Tor, you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes who raised their hands and said "Trust me! You can route all of your internet traffic through me and I promise I won't monitor or inject anything..." I think most Tor users don't have an adequate understanding of the th…

>you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes

No! When using Tor, you are not trusting any single node, and that's the whole point. The exit node does not know your IP or anything else about you, and the other nodes do not know what server you're communicating with. And you should never send any personal information over Tor, such as your credit card, because the end server would be able to identify you and steal that information (and why would you trust the end server? The idea is not to trust anyone when using Tor.)

Re: Things You Should Know About Tor

#72

Earlier quoted context omitted.

I hope you realize you just described the entire Internet. Which is the ultimate irony of complaining about the security of tor: you're trusting someone else to forward your packets. Yes, yes they can modify the traffic to and from your host, and yes, yes they can monitor everything you're doing. The difference with the non-tor Internet is that it's far far easier to do that.

You're absolutely correct in that it is a trust issue. However, when Comcast forwards my packets they have both a profit incentive to not go stealing my all of my credit card info (their customers would quickly take their business elsewhere) and a legal incentive (they're a known entity inside the US - someone's going to court). With Tor, I'm putting all of my trust in someone likely on the other side of the globe wh…

What's the point of using Tor to access your bank's website though? I don't think that is a normal use case at all because there's no point using an anonymity network for that, because your bank probably knows who you are. Exactly the same as with credit cards.

If you're going to pay for something over Tor, it should probably be with a prepaid credit card (or bitcoin). And if you're buying something anonymously then you know you're taking a risk.

Same as with email accounts or any other account. It doesn't make sense to use any account through Tor that you've used outside it, as it could already be identifying information.

Re: Things You Should Know About Tor

#73
post #16

"It is also important to remember that if you log into services like Google and Facebook over Tor, you will be sacrificing your anonymity to those services." It is important to note that both Google and FB can track you on 3rd party websites through things like "Like" button. Consider disabling 3rd party cookies completely or using plugins like Ghostery.

I've been browsing the internet for 15 years with 3rd-party cookies disabled. I never had ANY problems with any website - no idea if there would have been more functionality with 3rd-party cookies enabled. But then again, how can functionality depend on THIRD parties? Also activated the setting for my girlfriend years ago, no complaints so far. This feature should really be the default for any browser and any user. T…

Do things like Disqus work?

Re: Things You Should Know About Tor

#74
"4. No One in the US Has Been Prosecuted For Running a Tor Relay"

That's a bit of a misleading statement. I'll agree that there haven't been any people prosecuted because they ran a TOR relay directly but there has been at least one case where they prosecuted or at least harassed a guy on child pornography charges because he was running a TOR exit node and saw the activity coming from his IP. Perhaps that wasn't in the US but still.

Re: Things You Should Know About Tor

#75
post #63

Earlier quoted context omitted.

This is incorrect and dangerously misleading. The NSA collects data that crosses the US border. An internet user in America is more likely to have their data cross a border if they use TOR. In this respect, TOR makes your data more likely to be collected unless you have reason to believe you're already being monitored anyway.

But only exit nodes are the problem here. Traffic between nodes is encrypted anyway. If the encryption is sound (and there is no reason to assume the contrary), they may collect as much as they want. There is anyway no guarantee at all, that non-TOR traffic doesn't cross borders. And you can't assume that any three letter agency acts within the (intended) legal boundaries. To be safe, only end-to-end encryption helps…

My worry is that by using Tor at all you become a target for active monitoring, even if the content and destination of your Tor communication can't be decrypted.

Re: Things You Should Know About Tor

#76
post #52

I'm probably going to take some flack for this, but I don't trust Tor. When you access Tor, you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes who raised their hands and said "Trust me! You can route all of your internet traffic through me and I promise I won't monitor or inject anything..." I think most Tor users don't have an adequate understanding of the th…

Lets address your concern by talking about security and probability for each of those issues. Credit card thieves in Comcast vs in TOR. Given the number of employees who has remote access to customers routers (ie support), sysadmins that has remote server access, and personale who has physical access to switching equipment, whats the risk that one of those people has a criminal record? This will always be non-zero, a…

[deleted]

Re: Things You Should Know About Tor

#77
post #61

I actually tried to get Tor relay working. It ate all my monthly bandwidth limit within an hour . By simple analysis I found out it's mostly BitTorrent traffic, but I didn't dig very deep so I might be wrong. I would love to run a Tor relay, but I just do not have unlimited bandwidth to do that.

There is an option in the config to limit the amount of bandwidth used by the relay.

BandwidthRate N bytes|KBytes|MBytes|GBytes

In combination with accounting you can limit monthly or daily usage - has to be over 30kb/s to be usable by the network, so may not be feasible, but worth knowing.

Re: Things You Should Know About Tor

#78
post #52

I'm probably going to take some flack for this, but I don't trust Tor. When you access Tor, you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes who raised their hands and said "Trust me! You can route all of your internet traffic through me and I promise I won't monitor or inject anything..." I think most Tor users don't have an adequate understanding of the th…

Lets address your concern by talking about security and probability for each of those issues. Credit card thieves in Comcast vs in TOR. Given the number of employees who has remote access to customers routers (ie support), sysadmins that has remote server access, and personale who has physical access to switching equipment, whats the risk that one of those people has a criminal record? This will always be non-zero, a…

You can test Comcast in the same way that you can test a Tor exit node - the technique is exactly the same. The threat of a rogue network admin is similar to that of a rogue waitress stealing credit card info - significant criminal liability if caught. To top that, people in a position to carry out such an attack are generally easily identifiable by their employers if there is a criminal investigation. The same can't be said for the administrator of a Tor node in a foreign country.

The NSA threat relies on the assumption that they are targeting you specifically; the risk with a rogue exit node is that you are exposing yourself to an adversary that doesn't care who their victim - i.e. most criminals. My issue with Tor advocacy is that it's attempting to mitigate the risk of a perceived adversary by exposing users to a much more realistic threat. My spouse and I have both had our credit cards stolen before, but I've never had any reason to believe that I've been targeted by the NSA.

There is a definite tradeoff with regards to the whitelist/blacklist model, but ultimately both solutions are really just patching over inherent flaws in SSL trust model. I wasn't clear in earlier post - my issue is not necessarily with the HTTPS Everywhere model, but rather the perception that it gives the user pervasive end-to-end encryption and solves the issue of rogue exit nodes.

Re: Things You Should Know About Tor

#79

Earlier quoted context omitted.

I hope you realize you just described the entire Internet. Which is the ultimate irony of complaining about the security of tor: you're trusting someone else to forward your packets. Yes, yes they can modify the traffic to and from your host, and yes, yes they can monitor everything you're doing. The difference with the non-tor Internet is that it's far far easier to do that.

You're absolutely correct in that it is a trust issue. However, when Comcast forwards my packets they have both a profit incentive to not go stealing my all of my credit card info (their customers would quickly take their business elsewhere) and a legal incentive (they're a known entity inside the US - someone's going to court). With Tor, I'm putting all of my trust in someone likely on the other side of the globe wh…

...Comcast...their customers would quickly take their business elsewhere...

This isn't always possible for Comcast customers.

Re: Things You Should Know About Tor

#80
post #29

Earlier quoted context omitted.

Sure, but this is why pretty much every resource on Tor stresses the importance of end-to-end encryption for sensitive or identifying info.

That's why I mention sslstrip (check out the presentation - it's scary) and overall lack of SSL on the internet. To provide some anecdata, my browser window currently has 8 tabs open right now. Those that support HTTPS: news.ycombinator.com; twitter.com; www.torproject.org Those that don't: cryptome.org (!); zzaper.co.uk (the Vim tips article from a few days ago); forbes.com; vimeo.com; nytimes.com End-to-end encrypt…

What is the use to an exit node in knowing that someone is reading cryptome zzaper forbes vimeo and nytimes? Presumably you are not going to transfer any identifying info to these sites.
Post reply on HN