If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?
If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?
Most of the people I spoke to saw themselves as providing a service - they wanted to help do something to bring a particular kind of future Internet about and found it rewarding to be a part of that. A number of them found the act of running a relay interesting and fun in itself - something they could get better at. Plus, membership of the relay community itself (especially now) is a kind of shared experience of community - and that's attractive to people in itself.
In terms of malicious actors, Tor does a lot to avoid this, from hunting down bad relays actively, monitoring the network as best as it can, continuously developing the algorithms which select routes through the network, and other mechanisms, like forcing relays to operate for a while before they get trusted with a lot of connections.
If there is a mechanism to block , let’s say, CSAM, then the same mechanism can be used to block dissident political speech, no?
That said, you're absolutely right about large entities being able to control a large number of nodes, which is why a great number of nodes are controlled by governments trying to do so and also prevent foreign adversaries from being able to.
I used to do that. But I've ultimately decided that the prospect of fighting accusations of abuse or crimes committed through my network wasn't that enticing. Proponents will try to downplay the risks by using vague ideological nonsense like "don't worry, an IP doesn't legally represent a person ;)" which, even if true, won't prevent a rather unpleasant ordeal.
Running a relay is likely fairly low-risk and still a good thing for the network, though.
For a few years Oniontip [1] allowed tipping Tor relay operators with Bitcoin. In my opinion that was a quite nice combination of technologies, as it allowed to anonymously tip operators of a service providing anonymity on the internet.
Also, bitcoin actually was more private back then, because KYC rules were much more lax.
There is nothing stopping a state actor controlling a large percentage of nodes thus increasing the likelihood that your anonymous communications are nothing of the sort.
After all, the field agents probably meet once or twice a year at some math/CS conference in France anyway.
These administrators can then launder the information to their respective agencies by means of any number of play-pretend activities you can write up for the transparency committee. The agency doesn't even need to (officially) know.
(Edit: I say this, but in reality I also think it's pretty safe to assume most are government controlled)
It costs my ISP resources but I pay a flat rate. That would have value to me.
I’m confident it’s not an efficient market and they’re charging what the market can bare, not a tight markup over their actual costs.
Governments have other possibilities. Why should they run a relay if they can force the ISP to mirror the traffic of all relays to them?
You have, conveniently, moved your point back to tor when I pointed out the folly of your statement.
Here, have an example:
https://www.telegraph.co.uk/news/worldnews/asia/japan/104090...
Alt227 has a point but the Tor network is centered around a handful countries where traffic is cheap and there aren't that many huge IXs and Tier 1 ISPs where much of the traffic flows through.
I'm not saying that this is done but it's IMHO more likely than state actors running thousands of relays.
“a state actor has the physical capabilities/resources to perform an attack that determines Alice was speaking to Bob.”
I totally agree. Im just pointing out that we still have layer 5 encryption to protect the contents of our messages. Also at that point, if you’re so important they would just grab a warrant and raid your home.
This question
https://support.torproject.org/relay-operators/#relay-operat...
also seems to imply that it might be useful to run a node to provide cover for your own traffic (though not an exit node in your home), but that it isn't known for sure how useful that is.
I think the core argument against your suggestion is (1) having your devices more likely to be seized is just plain harmful to you; (2) if you're personally doing something that law enforcement cares about, having your devices more likely to be seized increases you risk that they could discover that by seizing those devices; and (3) there may be traffic analysis techniques that law enforcement could use to distinguish between your own traffic and your exit traffic, like trying to correlate inbound Tor circuit activity with exit traffic, and attributing the traffic to you if it couldn't be matched up with an inbound circuit.
It might be a good idea in a prosecution to raise reasonable doubt. Few people are willing to play punching bag for the police to find out. Also the general technical skill of the average cop and prosecutor is quite low.
It's also a bit like picking up trash when you're out for a walk, it's just a nice and proper thing to do to make society a better place to live in.
You are workng for the FBI.