2. Using hidden services obviates the problem of exit nodes.
The upside is that no government would admit to having this capability, so your only worries are extrajudicial measures (e.g. the US does plenty of extrajudicial killings of middle easterners with its drone program) and parallel construction.
Now running ordinary Tor node is not dangerous. It does not consume a lot of resources (I'm running node on 256 MB OpenBSD VPS) and hosters don't care at all. It takes few minutes to install and set it up.
So there's absolutely no reason for people not to run Tor node on every server they have access to. And I'm sure that many people do. So I doubt that government control majority of Tor nodes.
If you operate a server, consider installing Tor node. It does no harm, it consumes as much of bandwidth as you will configure and you probably have a lot of unused resources anyway.
Uh,
This was the whole premise of Carnivore... installed in room 641A
https://en.wikipedia.org/wiki/Room_641A
(Btw - this is the room that Twitter was originally routed through...)
Basically I take the defeatest stance at this point...
There is NO privacy or anon. It doesnt exist any longer.
THIS is what I would guess a state entitiy would be training an AI to do as a function...
Within 30 minutes of my public IP changing, CloudFlare would get wind of it again and then it'd be back to hitting a captcha for 75% of all of my own NOR tor traffic with the same origin IP as a TOR exit node. This among myriad other misadventures resulted in me shutting it off after ~6 months.
There is at lest one: list of tor relays IP addresses is public. Some mail servers use this list as an additional source for RBLs (probably people, who are not familiar with tor don't know the difference between exit nodes and relays and bun all just in case). So it is not a good idea to share mail server IP with a tor relay.
Even in the richest parts (relevant because they love forbidding things) of the EU you can find hosters that accept tor exit nodes. As for it being dangerous, that is kind of a spurious argument. Why do you think it is dangerous? Do you know because you tried, or do you "know" because you heard someone tell you it was?
>The upside is that no government would admit to having this capability
Probably because it's very improbable that they have the capability to do so.
Suppose the NSA has a project to deanonymize TOR, so they set up TOR nodes. To be less conspicuous (TOR node ips are monitored for geographic distribution) they set up small clusters in various locations, one of them an apartment in Amsterdam. The FSB manages to get a double agent that installs software in those nodes to send the same information to Russia. India finds a 0-day exploit and installs their own data-extraction on those nodes as well. Since it's an undercover installation in Amsterdam usual US government rules don't apply and the ISP used uses Huawei networking equipment, giving China a way to listen in as well. Meanwhile the ISP itself is run by Mossad agents specifically to extract dutch traffic for Israeli analysis, and they struck gold with this NSA op choosing them because they are cheap and have no data cap. The ISP routes the traffic to the internet backbone, where most of it will pass through a GCHQ facility on the British coast.
That's 6 different agencies using the same pair of nodes to deanonymize TOR users, without any deliberate data sharing.
I have read that research. It works great in a controlled environment without the parallel requests of modern browsers, where packages all arrive in order, and where a high rate of false positives are acceptable. Outside of a lab settings the research gets much more muddy and more speculative that it maybe can be used, but I have yet to see an actually experiment that demonstrate it.
ASD
CSE
GCHQ
GCSB
NSA
FVEY
(I'm seriously considering getting some of those made as tshirts...)only one of FVEY is a US IC org. See also Nine Eyes and Fourteen Eyes.
If Tor was made for intelligence (agencies), why would anyone ever use it? Makes no sense.
I’m not suggesting that the code of Tor is compromised, as it has been under the control of others for years. I am suggesting that military/intelligence interests have been associated with the network from the beginning and no doubt have significant presence in terms of infrastructure, etc.
A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes or who can execute unmasking attacks by traffic shaping or monitoring if they control enough relays.
For the most part any country which can perform intelligence collection out of its embassy will have sufficient budget and and technical capacity to develop their own secure means of phoning home.
Also for highly sensitive material a diplomatic pouch is still the most secure means of transport as it never leaves your sight and is never inspected and if you do get intercepted then destroying physical media is much easier than securing network traffic to the same level of assurance.
The CIA has it's own onion service: ciadotgov4sjwlzihbbgxnqg3xiyrg7so2r2o3lt5wz5ypk4sxyjstad.onion
Tor was developed by the US naval research lab, it was opened up because an anonymity network only spooks use isn't anonymous.
Smart intelligence agencies are not going to reinvent the wheel (or in this case, the onion router).
>A properly configured commercial or open source VPN is considerably more reliable and secure than ToR since you have no idea who is listening on the exit nodes
If traffic is encrypted this does not matter. (HTTPS also provides integrity checking to show messages were not modified in transit)
Also, traffic to onion services does not exit the Tor network - there is no "exit node"
>Also for highly sensitive material a diplomatic pouch is still the most secure means of transport as it never leaves your sight and is never inspected and if you do get intercepted then destroying physical media is much easier than securing network traffic to the same level of assurance.
They may use diplomatic pouches for especially sensitive information, but the need for low latency communication is strong. What's more likely is that one time pad codes for said communications are sent via pouch, and the communication itself then goes over Tor or some other channel.
(Also it's my understanding Tor uses the exit node's DNS server)
If I needed to design a secure system that didn't need to be anonymous I'd just have it send a HD full of random in a diplomatic pouch & ensure that the packets are sent with encrypted 0s if there isn't anything to say.
And that's only if you think that there isn't a safe pubic key protocol.
Bitcoin's security model relies on public key encryption & there is an extremely large bounty on breaking it. There doesn't seem to be evidence of it being broken yet.
I don't know how much the longer .onions affects generation time - anyone?
For the longer v3 .onions you'll want a different tool, this page mentions some and makes some estimates for finding increasing lengths of characters: https://www.jamieweb.net/blog/onionv3-vanity-address/
(unless you are thinking about high level things, like "lots of traffic" -> "something going on", but tor won't help with that either)
But is an embassy always only "phoning home"?
(and for really secure stuff you will want a channel with constant rate, constant size packets, as others said)
(Though certainly things like packet timing, packet size, etc. might make more thorough analyses harder to escape…)
1. Alice and Bob set up their OTP
2. Alice randomly generates a new OTP
3. Alice encrypts the new OTP with the original OTP and sends the ciphertext to Bob
4. Bob decrypts... the new OTP
5. Alice and Bob burn the original OTP
6. Now Alice and Bob have a copy of the new OTP
I mean, it's pointless. But I don't see how it isn't secure.
jancsika is right in the sense that this is possible, but meaningless. The reason for that is that in OTP, you use your key ("pad") for every transmission, in 1-to-1 ratio to amount of data being transmitted. And you can only use your key once (hence "one time pad")
So let's say you brought 1000 MB of OTP keys to embassy in diplomatic mail, you can use it to send up to 1000 MB of encrypted data, and then you have to get a new one. If you are low on OTP keys, and you use it to send a new one, you'll have to spend 100 MB of "old" OTP keys to get 100 MB of "new" OTP keys -- entirely pointless process, as amount of unused key data won't change.
The Department of Defense is probably one the largest and most sophisticated telecoms in the world. Cannot have dependencies on local infrastructure in countries you are bombing.
[0] https://en.wikipedia.org/wiki/Defense_Information_System_Net...
How much it does so might be, and what it talks certainly is, but that's easily fixed by getting a line with dedicated bandwidth, running an encrypted connection (VPN or something custom) over it, and padding the traffic to ensure the bandwidth usage is constant (if you have a 100 Mbit line and 10 Mbit of traffic, you send 90 Mbit of padding).
The keys for the VPN get delivered via diplomatic courier.