Just the fact you’re using it automatically makes you interesting and worthy of a closer look.
All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?
Just the fact you’re using it automatically makes you interesting and worthy of a closer look.
All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?
Maybe I'm unique, but my dark net activity is usually pretty tame. The number one reason I use Tor is because browsing onion sites reminds a bit more of how the web used to be in the late 1990s. Lot's of garbage of course, but a lot more serendipitous discovery than the web today.
Because of its anonymous nature Onion sites are inherently resistant to being swallowed whole by advertising. Nobody on the dark web is creating "content marketing", if someone is trying to sell you something it's obvious. You're not the product on the dark web.
I know it's wishful thinking, but I often hope for a parallel web to really thrive on Tor.
Nytimes.Com is an example.
Me too. Wish every blog and web site out there was a hidden service instead. Especially this one.
If it were directly using tor then I'd have to agree that most people wouldn't use it. Only those that are technical enough to understand what's going on and the security aspects. But they wouldn't be using Brave for the Tor functionality, they'd be using Tor Browser.
Basically, using the TOR network as a VPN.
The TOR browser and Brave do the exact same thing, it's just that the TOR browser is configured to not store anything and to make sure it's fingerprint to other sites is as generic as possible (this is also why TOR warns you about changing window size, it un-generalizes that fingerprint). Both ultimately are conveniences because messing with SOCKS proxy settings is rather unfriendly for most users.
If you use a Linux distro, I'd recommend checking out torsocks[1], it's a shared library + a shell script that lets you "onion-ify" any application pretty easily.
[0]: This also means you can connect basically every mainstream browser to TOR if you know the port the SOCKS proxy is running on.
(Still, it's great they have done that.)
Quite a few people involved in crypto send a bit of TOR noise across the wires using that client to do transactions
This is a good point, though. We need more and more things to use it (legitimately) so that the traffic alone isn't as suspect.
It'll always be a little suspect, I suppose, being only visible to exit nodes or whatever
As far as I can tell, the US Intelligence community has never explained it's aims/goals for Tor. The fact that Tor not only attracts the type of traffic that US Intelligence would have a lot of interest in monitoring, but also by design then funnels that traffic through a small number of exit nodes, makes it seem self-explanatory. But I wouldn't want to presume anything.
[0] https://en.wikipedia.org/wiki/Tor_(network)
[1] https://www.documentcloud.org/app?q=%2Bproject%3Athe-tor-fil...
[1] https://www.torproject.org/about/reports/ [2] https://blog.torproject.org/transparency-openness-and-our-20...
> 2,500 pages of correspondence — including strategy and contracts and budgets and status updates — between the Tor Project and its main funder, a Central Intelligence Agency spinoff now known as the Broadcasting Board of Governors (BBG). These files show incredible cooperation between Tor and the regime change wing of the US government.
So the documents acquired via FOIA requests are worth reading, and it's worth discussing why the US Intelligence community has such an active interest in propping up Tor.
(finally I can say that and it may in fact actually be true for once! hahaha)
The federal government isn't in my threat model, and "you can't fight city hall".
Having a bunch of Tor site certs in your MacOS keychain has its own issues, so what is really needed is a way for Tor browsers to accept those certs directly without using the OS trust stores. The current practice of authenticating the remote site by PGP signature would remain more or less the same - you just wouldn’t have exit nodes sniffing traffic.
I’m also convinced that the whole reason Google has pushed TLS so hard isn’t some noble quest to protect people’s privacy and freedom of speech - it’s more to keep people from blocking their advertisements, which isn’t nearly so sexy an argument, but it has brought good benefits for a lot of people.
I've been on the side of advocating for it, but the other side isn't making an obviously ridiculous argument. The onion protocol itself negotiates an end-to-end cryptographic session, authenticated by the onion site's public key, between the onion site and the end user. There's not cleartext traffic sent between a Tor exit node and the onion site or anything!
My argument in favor of TLS to onion sites was that, at least as of onion protocol v2, the cryptographic session was not itself TLS, and its security and threat model hadn't been as extensively reviewed as those of TLS. So it might turn out that there was something suboptimal there that the rendezvous server could then use to perform a sophisticated cryptographic attack.
I don't know if this is still true of onion protocol v3 or if the client-to-onion-site session is now also based on TLS.
https://gitlab.torproject.org/tpo/core/torspec/-/blob/main/r...
I think the main question would be: are there cryptographic attacks that a rendezvous server could do that wouldn't work against TLS?
For connections to the clearnet it was always highly recommended to only use TLS and recent Tor browsers have now finally enabled https only mode that displays a big warning if you try to connect to a http server.
Eg. each client sends out 1000 1 kbyte packets per second to each peer, once per millisecond. Inside each packet, they send the onion encrypted user data. The rest of the packet is filled with rand().
Without that protection, any network attacker can do packet size and timing analysis to unmask nearly any user rather quickly.
If just a single client used this option, their traffic path, all the way to the exit node, would stand out to any network attacker.
CircuitPadding 0|1
If set to 0, Tor will not pad client circuits with additional cover
traffic. Only clients may set this option. This option should be
offered via the UI to mobile users for use where bandwidth may be
expensive. If set to 1, padding will be negotiated as per the
consensus and relay support (unlike ConnectionPadding,
CircuitPadding cannot be force-enabled). (Default: 1)
ReducedCircuitPadding 0|1
If set to 1, Tor will only use circuit padding algorithms that have
low overhead. Only clients may set this option. This option should
be offered via the UI to mobile users for use where bandwidth may
be expensive. (Default: 0)Basically - this option doesn't serve it's intended purpose.
I'm curious as to how it stands out. I can imagine a few things, like an ISP seeing traffic to known TOR intermediary nodes, or maybe analyzing packets to look for some sort of handshake?
> Just the fact you’re using it automatically makes you interesting and worthy of a closer look.
Sort of. But what would looking do? What does looking mean? The traffic is encrypted, they can look all they like. In the US they'll need more than "they connected to TOR" to get a warrant to search your device.
https://www.propublica.org/article/heres-one-way-to-land-on-...
https://www.theverge.com/2013/12/18/5224130/fbi-agents-track...
Why would someone make a legit bomb threat? Isn't the point of the bomb for it to explode?
What if everyone believed that law-abiding citizens should use postcards for their mail? If a nonconformist tried to assert his privacy by using an envelope for his mail, it would draw suspicion. Perhaps the authorities would open his mail to see what he's hiding. Fortunately, we don't live in that kind of world, because everyone protects most of their mail with envelopes. So no one draws suspicion by asserting their privacy with an envelope. There's safety in numbers. Analogously, it would be nice if everyone routinely used encryption for all their email, innocent or not, so that no one drew suspicion by asserting their email privacy with encryption. Think of it as a form of solidarity.
The only solution to this problem that I can see is massive no opt-out adoption until a tipping point is reached.
Some people just want privacy. No need to have an specific "cookie recipe" activity: they would just browse the New York Times, but in full reassurance of anonymity - as they believe is normal.
(And by the way: "«brows[ing] the New York Times»" - as a sequence of actions - is not a neutral activity, but already a profiling one.)
if you're worried, you could use a popular VPN to connect to Tor - using a VPN is less interesting. also, P2P app developers could consider running non-exit nodes in their clients for popular apps. there shouldn't be legal risks unless you're running an exit node, and this adds more noise to the signal of Tor users.
if a Tor user uses your exit node to email a bomb threat or access child porn, it's your source IP that shows up. the FBI should check your IP against the registry of exit node IPs, but if they don't it's still your door getting kicked in.
Alternatively, You -> ISP -> Tor -> VPN and paying with Monero obtained over Tor without ever having disclosed your ID or any revealing info means:
• Your ISP knows who you are, but not what you're doing (no anonymity, yes privacy). The connection to tor establishes privacy from ISP.
• Your Tor exit node sees you're connecting to a VPN, but does not know who you are, or what you're doing (yes anonymity, yes privacy). The routing of Tor establishes anonymity, but not privacy from the exit node. The connection to the VPN establishes privacy from the exit node.
• Your VPN provider knows a bit about what you're doing, but not who you are (yes anonymity, less privacy)
This offers additional protection if your VPN provider is compromised / lying about logging (you have no way to verify at any given moment, only that they weren't in past incidents that have gone to court, but this is no guarantee they can't be compelled to start logging your connections).
This also offers additional protection if your guard node and exit node are compromised, which is sufficient to deanonymize tor users.
What it does not offer protection against is all ISP's involved selling netflow metadata to a single party who uses timing and packet sizes to correlate traffic across all of these connections, like Team Cymru does with their Pure Signal Recon product (formerly called Augury).
If that scares you, I'd encourage you to look up what company actually owns and operates torproject's website, and how many contracts they have with governments, too.
now, a foreign VPN isn't going to be connected to the xkeyscore dragnet like Comcast would be. I'm sure the NSA's pwned dozens of VPN providers, but beam-splitting all VPN traffic into a colo'd supercomputer isn't going to be stealthy. the best the NSA could do is watch for outbound connections from the VPN to Tor, then match the connection to your ingress using their access inside the VPN's infra. they can't do that in bulk without the VPN company catching on. that's a capability they'll save for going after individuals. just the fact you connected to Tor isn't suspicious enough to be worth risking burning their backdoor, for them.
the point is that connecting to Tor via a VPN keeps you out of the dragnets. and all the VPN provider learns is that you're using them as a gateway into Tor.
No, it isn't rare. Plenty of people use Tor for casual browsing without triggering invasive ads and similar. It just works.
Could we convert our "observers" into early customers?