Tor Browser Security Audit
blog.torproject.org
blog.torproject.org
Apologies for not bothering to research this question in advance.
It absolutely is. This is known and explicitely called out in Tor's design:
> A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic […]
What gives people, especially in the west, the confidence to use it at all, given all of the fusion centers and likelihood of parallel construction? Perhaps this is a rhetorical question...
Of course, if I were the KGB, or MI-6, or the Chinese State Security Ministry, or the DGSI, etc., then I would be doing the same thing.
Assuming that's true (and it may not be), I'm curious how much security would be compromised with many different adversaries instead of just one adversary.
Can anyone shed some light on this for me?
It's also why it's still available and hasn't been challenged in law. Every tor node and exit is in a list, it has to be. If govs wanted to, they can make it illegal and start raiding. They love raids. They don't because that harms their intelligence ops.
Tor Browser is 100% open source, so pull up git and run blame if you want to determine the reasoning for a decision.
It just limits snooping to actors with the time and resources to do it on a large enough scale to capture what they are looking for.
What percentage of exit nodes are run by spy agencies and other snoops? Does anyone really know?
Most of them. The cost to operate top-bandwidth nodes are estimated at least five figures per month. Thankfully the Tor design spec explicitely calls out government panopticons as being squarely outside the threat model. So, adjust your infosec policy accordingly.
[0] https://metrics.torproject.org/rs.html#search/family:C466C9A...
[1] https://nusenu.github.io/OrNetStats/#exit-families (tuxli.org)
[2] https://nusenu.medium.com/is-kax17-performing-de-anonymizati...
> https://metrics.torproject.org/rs.html#search/bauruine
> 1113 bauruine@mail.ru 0.01
You're off by a factor of 350.
I already have. You can get the same or better "privacy" using public wifi with a random MAC address.