For example, they say "2017 court case proves FBI can de-anonymize Tor users", but immediately handwave the how away, because it's classified. Well then, that's not really a strong proof of Tor being compromised -- there are several ways the FBI could de-anonymize Tor users that have nothing to do with Tor itself (people being compromised by javascript, people posting pictures with metadata, people linking back to real-life accounts, people inadvertently posting identifiable information, people posting quasi-identifiable information that is correlated over time, people downloading XYZ that has a beacon in it, etc.)
I also can't help but wonder, if Tor is so thoroughly compromised and just a glowstick, why would the author finish with:
>For those who still want to access the Tor network, doing so through a reliable VPN service will add an extra layer of protection while hiding your real IP address.
If it's compromised to the core, a glowstick for LEA, enables the US government to "do spooky stuff", why bother giving a half-ass endorsement at the end of a hit piece?
You Tor to your VPN, you don't VPN to Tor.
However, I will say, using Tor to access your VPN strips away much of the benefit of using Tor, to the point that you might as well just use a VPN (sans Tor). I suppose if you want a single-circuit Tor connection that appears to be a static non-Tor IP address, sure. But blindly recommending one way or the other without knowing someone's use case, threat analysis, and risk tolerance is foolish.
With Tor, you can be assured that your attacker needs to monitor more than some % of the network (which can be done either by running nodes themselves or having a wide view of netflow data). Alphabet soup agencies are capable of this, but these attacks are expensive and non-trivial which is why historically the FBI and such use browser exploits the most. You shouldn't rely on Tor alone to protect your life if your adversary is highly skilled or funded, but chalking it up to a VPN is completely discounting the benefit gained from a larger anonymity set in the world's biggest onion routing network.
Combine Tor with a VPN.
If your life is on the line with your content the more layers of protection the better.
Adding a VPN is another system that obfuscates and is not controlled by the same entity.
They go ahead and make FBI and backdoors bold to shock the reader but conveniently rest of the context is left out. The actual context being Roger giving a talk about Tor at one of these conferences where you also have government entities voice their (guess guess) desire for backdooring and wiretapping the internet (while tech people from the industry aren't convinced). The same shit you see discussed openly in the public all the time anyway, probably just with more pleading from the FBI because it's so hard to solve crime without industry's help. Nothing unusual here. The wording of this fudpiece sounds like it's trying to implicate the Tor developer in planting backdoors for the FBI, which is not at all what the exchange is about if you read the context.
"Tor privately tips off the federal government to security vulnerabilities before alerting the public" is also complete FUD. I'm so glad I read the whole stack of FOIA'd documents before this text.
The context here is that BBG (Broadcasting Board of Governors) is using Tor to circumvent censorship in places like Iran, China, Saudi Arabia, and Russia. Alright you can call that a propaganda arm of the US government if you're so willing, but anyway, Tor is one of the tools they rely on. They need Tor to circumvent censorship, so they need to address vulnerabilities in Tor that make it easy to censor.
This "vulnerability" isn't one that FBI uses to catch a drug dealer or a hacker, it's a vulnerability that makes it easy to fingerprint and block Tor traffic. Now Tor's use has historically been quite easy to detect and block (see e.g. this FAQ entry from 2008 [1]) and fixing that has been a long road, I don't know where exactly they stand today. The "vulnerability" is just one among many and the possibility of fingerprinting TLS has been mentioned in the FAQ. It's not the kind of vulnerability you would have to scream and alert the public to (they should've already been aware that it is possible identify and block Tor traffic). Rather, it's something they should quietly research and figure out a solution to and hopefully stay ahead of the game w.r.t. regimes that may attempt to block Tor.
Discussing the draft proposal for fixing this TLS fingerprint vuln with the people who they are working together with to keep Tor useful in Iran etc. is exactly what the Tor project ought to do! The fact that these people happen to be employed by the U.S. Government doesn't seem particularly relevant. But suuure, "privately tipping off the feds to a vuln while keeping the public in the dark" is a nice way to twist it.
Here's the thing, there are issues with Tor, there are issues with anything because there is no technical solution to perfect anonymity. I would not bet my life on Tor. But knowing what it's good for and what its limits are, Tor is a very useful tool, and IMHO it can only get better if it gets more users and more relays. I would always recommend being vigilant and looking out for bugs, backdoors, and other sketchy stuff, but this fud piece just doing a disservice against itself with all the hyperbole. It sounds more like they've got an axe to grind.
[1] https://web.archive.org/web/20080415073019/https://wiki.torp...
> The original Tor design was easy to block if the attacker controls Alice's connection to the Tor network --- by blocking the directory authorities, by blocking all the relay IP addresses in the directory, or by filtering based on the fingerprint of the Tor TLS handshake. Some government-level firewalls could easily launch this type of attack, which would make the whole Tor network no longer usable for the people behind the firewalls.
Sect. 7.1:
> Note that all your local ISP can observe now is that you are communicating with Tor nodes. Similarly, servers in the Internet just see that they are being contacted by Tor nodes
See also the linked DRAFT "Design of a blocking-resistant anonymity system" https://web.archive.org/web/20080322054926/http://www.torpro...