Examples:
[1]: https://www.ibtimes.co.uk/fbi-crack-tor-catch-1500-visitors-...
Examples:
[1]: https://www.ibtimes.co.uk/fbi-crack-tor-catch-1500-visitors-...
After all, if you suspect the feds control a lot of tor nodes you probably also suspect they’ve infiltrated or outright own the major VPNs; that they’ve got special access to the major cloud providers, and that they’ve got backdoors in things like TPMs and remote management agents.
Of course Tor has its problems - exit nodes with trash IP reputations, unreliable hidden services, evil exit nodes and suchlike. So it’s certainly not perfect.
By who? It's an important question for someone taking this advice.
One drawback of Tor is that it attracts attention to you.
So the whole fabric of the Internet itself is one giant spy machine, in effect. That sounds like is like it's straight out of dystopian fiction, but no, it's for real.
https://www.vice.com/en/article/jg84yy/data-brokers-netflow-...
Obviously, this doesn't scale for something like social media. But metadata regarding one-on-one conversations using something like Signal could be effectively obscured.
The fundamental nature of the Internet itself permits this behavior to go unchecked, there is no way for a user to know what is happening behind the scenes with certainty. We send out our private information (search queries, etc.) into this giant black box we have no control over. That's the crux of it.
That was not the case with radio or satellite TV, the ability to determine what people were listening to or watching on a mass scale was nearly impossible due to the laws of physics. As the system was completely receive-only.
It is safe to assume Israel and US are actively using them as honeypots, especially they were mostly acquired - not built - by Kape.
Define "secure." Secure from what attackers, in what threat model, with what resources devoted to the attack, etc.
There are several categories of attack against Tor, and several ways to mitigate them, depending on who you are and what you use Tor for.
For a typical end user of Tor, the main one to worry about is "browser beaconing" style attacks - where a compromised onion website causes the browser to beacon out, on the clearnet, with something that links the browser's request on the clearnet to the browser's activity on the onion network. If you just use a regular browser proxied to Tor, this is a rather high risk, as browsers leak all sorts of things (I believe WebRTC was a common way of doing it for a while). The solution here is Whonix - a multi-VM setup in which your workstation (with a stripped down browser) is only connected to a Torification VM that routes all inbound traffic over Tor. So, if the browser tries to beacon out, it doesn't matter. Pop open a command shell and use ping, it still goes out through Tor. Etc. I consider this a reasonable way to use Tor, and any lesser construct is probably a dumb idea unless you're using it for things like sysadmin where beaconing out doesn't matter. Of note, Qubes supports the Whonix configuration as a first party sort of setup, and can route all your traffic through Tor, should you care.
There's also the risk of traffic correlation for end users, but I don't have a sense for the scale of this risk - I wouldn't leave long running connections over Tor, but I don't know if it matters for "casual use."
If you're hosting hidden services, the "guardian nodes" that know your identity are a risk, and given how many nodes seem to be run by three letter agencies, you'll want to deeply understand Tor and how to protect your services if you're going to host something - I believe you can limit guardian nodes to those you trust (and run yourself, perhaps?), but that changes some of the risk equations in ways I don't fully understand how to reason about (not running hidden services that matter - my blog has an .onion address, but it's literally just the same content as the clearnet version).
And then, we get into the problem that "computers in general" could be argued very convincingly to be "not in the slightest bit secure against a high level adversary," which is another can of worms...
Nitpick, but since there's no way to send ICMP traffic through a SOCKS proxy, using ping from whonix workstation is impossible (i.e. it won't work). But any other kind of beaconing (DNS leak, curl to a clearnet website) will be properly torified.
For example, take a look at I2P, which has been around almost as long as Tor. It has a lot in common with Tor, but has some key differences that may be appealing to some people. I2P nodes are capable of implementing something like an exit node (often called an "outproxy"), but there's no distinction between peers in I2P that designates one as an exit node. The project is more oriented towards hidden services, implementing its internal network, than it is in anonymizing connections to the clearweb. I think it's great that Tor exists, but I wish more people would consider I2P or at least simultaneously hosting their hidden services on both Tor and I2P. And if you really don't like running a Java runtime, Purple I2P exists and is written in C++.
There are also other networks like GNUnet, which slightly predates Tor, which is mostly file-sharing oriented, but with the goal of anonymity. It can do other things too but, from what I can tell, the project never gained much favor anywhere. Nevertheless, it still exists and is being worked on.
And I can't forget Freenet, or what's not referred to as "Hyphanet". I'll just call it Freenet for now because a lot of people still remember it. Freenet's focus is not only on anonymity but providing a distributed data store that is censorship resistant. This at least in part solves the issue of having to be online all the time in order to host a hidden service. It's been a long time since I've used Freenet, but supposedly the community is very good at discouraging crime and other unsavory elements. I haven't used the new iteration called Hyphanet.
All of these projects have significant differences from Tor, and some of these differences are seen by some as fixing significant flaws present in the Tor protocol that Tor can't reconcile. I2P's design of having no peer distinctions, in my opinion, is a vastly superior model for both security and plausible deniability. Its routing protocol also makes DDoS attacks a greater challenge. Having a primitive yet effective implementation of human-readable hostnames is also nice.
All of these projects are available for people to use today.
Tor does have two upsides. The first is that it has a larger community. The second is that it has the Tor Browser, which I2P does not have an equivalent to, although the Tor Browser can be adapted to use I2P.
Running Tor nodes is pocket change for intelligence agencies, and a major legal risk for volunteers. It's virtually guaranteed that the US intelligence agencies own the majority of the network between them. If they were in an arms race with foreign intelligence agencies, the number of Tor nodes would be exploding.
It's just that the NSA won't lend its shiniest toys to the FBI just to bust some CP websites. The lives of children aren't worth the risk of exposing and losing a zero-day exploit.
I'm unconvinced by this argument. First of all, why US intelligence agencies and not let's say Czech intelligence agencies? Or, more likely, nobody owns the majority of the network and nobody wants an arms race?
"U.S. Department of State Bureau of Democracy, Human Rights, and Labor The Bureau of Democracy, Human Rights and Labor leads the U.S. efforts to promote democracy, protect human rights and international religious freedom, and advance labor rights globally."
"DARPA's Resilient Anonymous Communication for Everyone (RACE) program researches technologies for a distributed messaging system that can: a) exist completely within a given network, b) provide confidentiality, integrity, and availability of messaging"
Both of those seem to align with Tor's goals of privacy and confidentiality.
It strikes me as cognitive dissonance that someone would simultaneously distrust the USG for obvious reasons (TFA is about Snowden), yet also think they are a perfectly noble arbiter of "secure communications", and look the other way when copious evidence suggests that the USG has means to compromise said "secure communications".
It's a very roundabout way of arguing "if you have nothing to hide, you have nothing to fear". TOR is a fine product if you aren't doing anything that the USG would realistically prosecute you for.
Occam's Razor says that TOR is primarily a tool of the USG for enabling intelligence & influence operations, particularly those involving low-level assets without clearances (e.g. color revolutions), and the stuff about "consumer privacy" is an unreliable side effect.