Live data from Hacker News

Deploying Tor Relays

blog.mozilla.org

71–80 of 91 posts

Re: Deploying Tor Relays

#71
post #68
post #63

Earlier quoted context omitted.

It's good practice to discuss plans with your hosting provider, so that you and they both know what to expect. Stealth doesn't cut it, especially if there's real money at risk. Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.

> keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists Have you got an example of that? I know a few relays intimately and I've never seen this.

I recall seeing this on tor-talk or tor-relays within the past year or so. Someone started running an exit, and their hosting provider nuked their account, claiming that other customers were being affected by bans. I'll see if I can find it.

Edit: Here's one example, posted by Zack Weinberg on the tor-relays list.[0]

    CMU network operations has decided to move the Tor exit node that my
    group operates (tor-exit.cylab.cmu.edu) to an isolated subnet in order
    to minimize consequences for the rest of the campus network. For
    instance, apparently there have been several cases where third parties
    blacklisted the entire CMU IP space in response to malicious traffic
    from the exit node.  This is currently scheduled to happen Tuesday (Nov.
    4). The new IP address will be 204.194.29.4.
[0] https://lists.torproject.org/pipermail/tor-relays/2014-Novem...

Re: Deploying Tor Relays

#72
post #56

Earlier quoted context omitted.

> It is plenty safe to run exit nodes ... in someone else's data center. Never, ever in your own home. If you are raided ALL your computers and ancillaries will be seized.

you can be raided just the same. fbi will probably send one agent to pick up the server in the data center, and 20 others will be picking you up at your credit card billing address.

That's why you want to rent your server as anonymously as possible. It's also why most hosting providers don't like anonymous customers. And those that are cool with it often charge more.

Re: Deploying Tor Relays

#73
post #49

> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2 Xeon L5640, 2 1Gbps NIC) In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...

That's a five year old server. That's worthlessly depreciated in just about any organization.

Re: Deploying Tor Relays

#74

Earlier quoted context omitted.

Its much easier to raid a big company because they have a clear physical prescence and a strong interest to focus on their core buisness. For example, some people in the company may defend their tor node, but managers will look to the interests of the company as a whole, concluding that the loss of dozens of jobs is not worth risking over something that is not a core competancy.

It seems like you're arguing from a pure realpolitik perspective. The FBI is going to raid your Tor node because they know it will make your boss unhappy. Even under that assumption, what is the FBI's motivation for doing this supposed to be? They can obviously only do this for Tor nodes within their jurisdiction, but that's where they want them to be because it's easier to capture their traffic. It's not like exit n…

Indeed, but this perspective comes from the large number of people that make up an enterprise and the interwoven net of responsibility. One person can choose to fight for liberty and risk ruin, but its much harder to justify risking the other hundred people in your company.

Re: Deploying Tor Relays

#75
post #49

> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2 Xeon L5640, 2 1Gbps NIC) In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...

Are there tax advantages of donating old equipment to certain good causes?

It seems easier than the alternative of selling the hardware on ebay.

Re: Deploying Tor Relays

#76
post #55

Earlier quoted context omitted.

Part of the problem of running an exit node is that it's unclear how "safe" it actually is, and as a result there is a lot of rumor and paranoia. Every country has different laws that affect the legal status of an exit node operator. For example, an Austrian man was arrested in 2011 for running an exit node and charged with being an accomplice to crimes that were carried out over Tor using his exit node. He was ultim…

tor exit is effectively a proxy. nobody should run an open proxy. that's just common sense. on the other hand it may be a good feature if implemented correctly. for example, sites explicitly saying they allow tor exit connections would be a good start.

Tor is effectively an open proxy (or set of them).

Re: Deploying Tor Relays

#77
post #71
post #68

Earlier quoted context omitted.

> keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists Have you got an example of that? I know a few relays intimately and I've never seen this.

I recall seeing this on tor-talk or tor-relays within the past year or so. Someone started running an exit, and their hosting provider nuked their account, claiming that other customers were being affected by bans. I'll see if I can find it. Edit: Here's one example, posted by Zack Weinberg on the tor-relays list.[0] CMU network operations has decided to move the Tor exit node that my group operates (tor-exit.cylab.c…

Note that a tor exit node is quite different from a relay.

Re: Deploying Tor Relays

#78
post #63

Earlier quoted context omitted.

> If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. I run three relays right now. I agree that it's pretty easy to setup, especially on Ubuntu, but the documentation could really use improvement. It makes it sound much harder to setup than it actually is. To anyone who is thinking of running a relay, here are the basic st…

It's good practice to discuss plans with your hosting provider, so that you and they both know what to expect. Stealth doesn't cut it, especially if there's real money at risk. Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.

This primarily applies to exits, not relays. Relays only work within the Tor network and never know exactly what they're relaying.

Re: Deploying Tor Relays

#79
post #20
post #3

I hope they are going to be deploying exit nodes as well. It's not very safe to run an exit node but I doubt the FBI will be raiding Mozilla and other big companies for them if this practice continues.

It is plenty safe to run exit nodes. If your host complains, there is even form letters to send. The government knows that seizing an exit node will not help them in anyway (one can go online immediately.) Do you think Amazon gets raided? Do you know how many exit nodes are in AWS? My guess is lots because I know 2 people who have them and I don't know a lot of people.

Ummm, yes. Amazon just got raided yesterday: http://www.bbc.com/news/technology-31000904

Re: Deploying Tor Relays

#80
post #42

Earlier quoted context omitted.

Would it help if an ISP ran a couple of exit nodes plugged into core routers?

It's actually better if 1000 different people each run a 40Mbps exit node than if one ISP runs a single 40Gbps one. You don't want to centralize control over the exit nodes because it increases the chance that party could control every node in a circuit.

If they're only running exit nodes, they're not going to control every node in a circuit.
Post reply on HN