Live data from Hacker News

Things You Should Know About Tor

eff.org

81–90 of 115 posts

Re: Things You Should Know About Tor

#81

Things I've used Tor for: - Accessing BBC Liveplayer as if I'm in England (using lots of normally discouraged add-ons and defined exit-nodes) - Bypassing paywalls (possibly still criminal?) - Bypassing censorship (which is what it really is) on organizational wifi networks (in Canadian hospitals). The funniest block was to ginger.io, a big data smartphone data analysis play (but blocked by an over-aggressive filter f…

:( on the bbc one. There are plenty of free proxies that you could use that wouldn't waste the tor network bandwith for something that doesn't really need 100% anonymity.

Re: Things You Should Know About Tor

#82
post #74

"4. No One in the US Has Been Prosecuted For Running a Tor Relay" That's a bit of a misleading statement. I'll agree that there haven't been any people prosecuted because they ran a TOR relay directly but there has been at least one case where they prosecuted or at least harassed a guy on child pornography charges because he was running a TOR exit node and saw the activity coming from his IP. Perhaps that wasn't in t…

Note it says 'in the US' because they have been prosecuted successfully in Austria.

https://rdns.im/court-official-statement-part-1

Re: Things You Should Know About Tor

#83
post #63

Earlier quoted context omitted.

But only exit nodes are the problem here. Traffic between nodes is encrypted anyway. If the encryption is sound (and there is no reason to assume the contrary), they may collect as much as they want. There is anyway no guarantee at all, that non-TOR traffic doesn't cross borders. And you can't assume that any three letter agency acts within the (intended) legal boundaries. To be safe, only end-to-end encryption helps…

My worry is that by using Tor at all you become a target for active monitoring, even if the content and destination of your Tor communication can't be decrypted.

Which is why it is important that many people use it. I don't think it is a viable strategy to MITM everyone (at least it will not go undetected), if that is what you assume being a target for active monitoring. Or to send agents to every house. If we are forcing them to do that, we have won.

Re: Things You Should Know About Tor

#84

Earlier quoted context omitted.

I hope you realize you just described the entire Internet. Which is the ultimate irony of complaining about the security of tor: you're trusting someone else to forward your packets. Yes, yes they can modify the traffic to and from your host, and yes, yes they can monitor everything you're doing. The difference with the non-tor Internet is that it's far far easier to do that.

You're absolutely correct in that it is a trust issue. However, when Comcast forwards my packets they have both a profit incentive to not go stealing my all of my credit card info (their customers would quickly take their business elsewhere) and a legal incentive (they're a known entity inside the US - someone's going to court). With Tor, I'm putting all of my trust in someone likely on the other side of the globe wh…

Again, the same can be said of non-tor traffic.

How many people keep track of the route their packets take? (Dare I say none?) How many third parties will it pass thru? (Many). How many of them can trusted to not monitor you (this is why ssl and even ssh was invented), how many have adequate security controls to prevent data theft (again this also why ssl and other tools were invented), how many can be trusted to not forward your data to a hostile government, etc.

It's the same problem, trust. And since when was the internet considered a trusted network? Calling out Tor for inherent trust issues with the path is ironic, neither the internet nor tor is a trusted network. Tors solving a different problem: monitoring. Both have the same problem which neither solves: tampering, but other technologies do (ssh, TLS, etc.)

In both cases, you shouldn't trust a third party (or an intruder into that third parties network) to either not modify your packets or to respect your privacy. At least tor helps with the later, the former isn't solved by blindly trusting an ISP or assuming your entire route is trusted (NSA anyone?).

Trust no untrusted network. At least tor is Upfront about this.

Re: Things You Should Know About Tor

#85

Earlier quoted context omitted.

You're absolutely correct in that it is a trust issue. However, when Comcast forwards my packets they have both a profit incentive to not go stealing my all of my credit card info (their customers would quickly take their business elsewhere) and a legal incentive (they're a known entity inside the US - someone's going to court). With Tor, I'm putting all of my trust in someone likely on the other side of the globe wh…

...Comcast...their customers would quickly take their business elsewhere... This isn't always possible for Comcast customers.

Or many customers in the US. For most consumers you have one choice of broadband provider due to local government monopoly grants. It's either comcast, or verizon or another big telco/cable company, but rarely is there a second equivalent option.

Re: Things You Should Know About Tor

#86
I have a very strong suspicion that Tor is completely compromised, and that's actually how they caught Ross Ulbricht (Silk Road). All the stuff about his previous posting, etc, is tenuous and circumstantial-- it seems totally feasible that it is parallel construction.

The "Tor Sucks" document is from 2012. It talks about the GCHQ running Tor nodes. What could have happened in the years since?

https://metrics.torproject.org/network.html

What many people don't realize is that Tor has only ~5000 exit nodes and ~3000 relays. If you control 50% of the nodes, Tor is essentially compromised. Half is ~4000 servers.

Seems like a lot for an individual person, right? Just a rough estimate, at $40/month for a cheap linode VPS, 4000 nodes would cost $160k/month.

But that's _nothing_ for a nation-state. $160k/month isn't even a rounding error. And that's all it costs to _completely_ compromise Tor.

These nation states don't want anyone to know they compromised Tor, so they won't waste it on little fish. They'll save it for real terrorists and major criminal actors like Ulbricht. But if they compromised Tor, they're certainly recording _all_ that activity somewhere. It's sitting in archived storage ready to be mined if necessary.

Re: Things You Should Know About Tor

#87
post #80

Earlier quoted context omitted.

That's why I mention sslstrip (check out the presentation - it's scary) and overall lack of SSL on the internet. To provide some anecdata, my browser window currently has 8 tabs open right now. Those that support HTTPS: news.ycombinator.com; twitter.com; www.torproject.org Those that don't: cryptome.org (!); zzaper.co.uk (the Vim tips article from a few days ago); forbes.com; vimeo.com; nytimes.com End-to-end encrypt…

What is the use to an exit node in knowing that someone is reading cryptome zzaper forbes vimeo and nytimes? Presumably you are not going to transfer any identifying info to these sites.

Tracking cookies used across various services are known to be used by the NSA to identify users.

Re: Things You Should Know About Tor

#88
post #55
post #45

How did the feds locate freedom hosting? How did the feds take down silk road? The "tor stinks" slide was over a year old when these events occurred. A lot can change in a year.

I specifically addressed this in the article. The feds located freedom hosting by using an exploit in Firefox which was able to deanonymize users. I don't know enough about the silk road case, but it seems probable that traffic correlation was used in that case. I agree that things can change in a year, but the essential point that Tor is not cryptographically broken is still true, IMO.

Tor is not cryptographically broken, I agree. But see my post above about the number of nodes-- it is trivial for any nation-state to spend a small bit of money to completely compromise Tor.

Re: Things You Should Know About Tor

#89
post #80

Earlier quoted context omitted.

What is the use to an exit node in knowing that someone is reading cryptome zzaper forbes vimeo and nytimes? Presumably you are not going to transfer any identifying info to these sites.

Tracking cookies used across various services are known to be used by the NSA to identify users.

If you're using the same browser for Tor and non-Tor traffic (and therefore the same cookies) then You Are Doing It Wrong.

Re: Things You Should Know About Tor

#90
post #80

Earlier quoted context omitted.

What is the use to an exit node in knowing that someone is reading cryptome zzaper forbes vimeo and nytimes? Presumably you are not going to transfer any identifying info to these sites.

Tracking cookies used across various services are known to be used by the NSA to identify users.

That's why the Tor Browser clears cookies on close. But you are free to disable them entirely.
Post reply on HN