Can NAT traversal be Tor's killer feature? (2014)
gist.github.com
gist.github.com
(And since I set HiddenServiceAuthorizeClient, random people just knowing the address won't be able to connect.)
It works great and I stopped port forwarding my home network while ago...
It would be interesting if somehow Tor could be used only to initiate the NAT traversal, then the direct connection could be used with better performance. (This article feels like it's talking about routing everything through Tor.) If there was an open-source library that managed this well I have a feeling it would be used everywhere.
That's correct. How would you use Tor to initiate the NAT traversal only, and then go direct? Perhaps using it as a way to advertise ports bound upstream from local NAT?
If both parties are behind a NAT, you need a STUN server to help set up UDP hole punching. STUN servers are cheap to run, as it is a stateless UDP protocol. I imagine a single server could handle tens of millions of concurrent users, or more if the STUN client is not aggressive.
There are enough public STUN servers that I think an open source project could ship with a big list of them and it'd be functional. (The two peers don't need to be using the same STUN server.)
There is also pwnat, which uses a neat trick to connect two parties behind a NAT without a third server necessary.
> If there was an open-source library that managed this well I have a feeling it would be used everywhere.
Check out telehash.org for one attempt to make a p2p overlay of the regular Internet as an open source library.
ZeroTier, as mentioned in the link, has all the code necessary to also provide a p2p library. (It's p2p VPN software right now, but I imagine someone could separate out the guts if that hasn't been done already.)
Because of that, I suggest that if you build a project like this, DONATE and/or encourage users to donate to Tor project. It's not like relay traffic is an unlimited resource and Tor already does a lot to support various use cases, but it takes money. Keep that in mind.
The solution of course being for more people to run relays.
BitTorrent is effectively a "relay" when you seed. The anonymity network I2P actually works in a way that you are both the relay and the client by default.
According to Tor, "decent" is 2Mb/sec symmetric, which most any broadband connection can do. I suspect everyone has 2MB/sec lying around. From Tor [1]:
The more people who run relays, the faster the Tor network will be. If you have at least 2 megabits/s for both upload and download, please help out Tor by configuring your Tor to be a relay too.
There are other ways to contribute to the project as well, such as running bridge relays [2]. These are often less-used but are necessary for the network to work well in places where it needs to be used for censorship circumvention.
You can also configure a browser to be a short-lived FlashProxy [3] bridge relay.
Even still, throttling bandwidth in your `torrc` means you can easily run a relay on a droplet or EC2 instance and not cost yourself a lot of money. There is also torservers.net [4] for hosting; they accept donations as well.
[1] https://www.torproject.org/docs/tor-doc-relay.html.en [2] https://www.torproject.org/docs/bridges.html.en [3] https://crypto.stanford.edu/flashproxy/ [4] https://www.torservers.net/
HiddenServiceDir /usr/local/etc/tor/hidden_service/
HiddenServicePort 80 127.0.0.1:8080
Then you just see /usr/local/etc/tor/hidden_service/hostname for your .onion address.The hardest part is setting up your web and application servers, which don't care that they're behind a hidden service.
How would you expect a UI for that to function? I'm asking sincerely.
https://github.com/zerotier/ZeroTierOne
https://github.com/zerotier/ZeroTierSDK
The difference between something like ZeroTier and Tor is a trade-off between meta-data privacy and latency/speed. (Both encrypt the actual payload.)
Efficient connectivity and anonymity are antagonistic goals. You can't provide both since optimization for one of these two goals implies violation of the other.
Tor provides meta-data privacy, but it's impossible to do this without sacrificing a lot of performance. If you allow low latency on a privacy network, latency can be used to triangulate the endpoint. Rule of thumb: latency can never be lower than about 1/2 the time it takes a photon to travel the Earth's diameter. In practice it's higher since you must also account for median router latency. Same goes for high throughput though in that case you need much more detailed intel on the physical network. Rule of thumb here: if throughput is higher than global mean it can be used to rule out and thus narrow down paths in the graph.
ZeroTier provides fast efficient low-latency direct connectivity but to do this requires that it introduce people directly, thus revealing peoples' locations (IP-wise) to each other. This is a hard requirement since the most efficient path is by definition the most direct and therefore de-anonymized (again IP-wise) path. You can't go directly A<>B without A knowing where B is and vice versa.
Edit: I speak a bit theoretically above. In practice a weaker anonymity system could be deployed closer to the last mile to hide people at e.g. city resolution. But AFIAK this is not what Tor does, would probably require either a huge critical mass or last-mile carrier participation or both, and would still have a performance impact.
I suppose it's open-source.