Is Tor still safe to use?
blog.torproject.org
blog.torproject.org
I want to find a certain kind of person so I look for people that access a specific hidden service or clearnet url.
Surely eventually I'm going to get a hit where all three nodes in the circuit are my nodes that are logging everything? It will take a long time, and I can't target a specific person, but eventually I can find someone who has all three bounces through tor nodes I control, no?
Hiring people on something like fiverr could take care of most of the manual part.
My point is that if I could do it, a nation state cracking down on dissidents could likely do it too.
Iran really is not the first country that should come to anyone's mind given how far it is from home.
It’s the most popular so it gets the most attention: from academics, criminals, law enforcement, journalists, …
So latency issues permitting, you would expect the default number of relays to increase over time to accommodate increases in attacker sophistication. I don't think many would mind waiting for a page to load for a minute if it increased privacy by 100x or 1000x.
Or if you were arguing for increasing the number of relays in a circuit, that doesn’t increase security. It’s like one of the OG tor research papers deciding on 3. Bad guy just needs the first and the last. Middle irrelevant.
Because of timing attacks? There are ways to mitigate timing attacks if you are patient (but I think clearnet webservers are not very patient and my drop your connection)
And yeah mitigation gets you into a huge body of research that’s inconclusive on practical usability. Eg so much overhead that it’s too slow and 10 people can use a 1000 relay network and still get just 1 Mbps goodput each. Contrived example.
People need to actually be able to use the network, and the more people the better for the individual.
There’s minor things tor does, but more should somehow be done. Somehow…
The reason that there are so few relays and exit nodes is that everyone that runs an exit node believes, for very good reason, that they'll be opening themselves up to subpoenas and arrest for operating one. You know who never has to worry about getting arrested? Surveillance agencies tasked with running exit nodes.
Consider the two classes of relay and exit operators:
1. People who operate relays and exit nodes long term, spending money to do so with no possibility or expectation of receiving money in return, and opening themselves up to legal liability for doing so, whose only tangible benefit comes from the gratification of contributing to an anonymous online network
2. Government agencies who operate relays and exit nodes long term, spending government allocated money to operate servers, with no material risk to the agencies and whose tangible benefit comes from deanonymizing anonymous users. Crucially, the agencies are specifically tasked with deanonymizing these users.
Now, I guess the question is whether or not you think the people in group 1 have more members and more material resources than the agencies in group 2. Do you believe that there are more people willing to spend money to run the risk of having equipment seized and arrest for no gain other than philosophical gratification than there are government computers running cost and risk free, deanonymizing traffic (which is their job to do)?
...while being practical.
One could argue that there is i2p. But i2p is slow, a little bit harder to use, and from what I can remember, doesn't allow you to easily browse the clearnet (regular websites).
One should be able to make these quite reasonable determinations about how easy it’d be to capture and identify Tor traffic without a bunch of whataboutism and “it’s still really good though, ok!” replies which seek to unjustifiably minimise valid concerns because one feels the need to…go on and bat for the project that they feel some association with, or something.
The self-congratulatory cultiness of it only makes me quite suspicious of those making these comments, and if anything further dissuades me from ever committing any time or resources to the project.
It sounds reasonable to anyone who hasn't read the papers, to anyone that has these comments are so wrong that you can't even start explaining what's going wrong without a papers worth of explanation that the people don't read.
If you're looking for static assets, why would you need to see the whole chain? Wouldn't a connection to a known website (page) have a similar fingerprint even if you wrap it in 3 layers of encryption? Does Tor coalesce HTTP queries or something to avoid having someone fingerprint connections based on the number of HTTP requests and the relative latency of each request?
I've always assumed that, if a global adversary attack works, you'd only need to watch one side if you're looking for connections to known static content.
I don't know much beyond the high level idea of how Tor works, so I could be totally wrong.
Eventually the guard has to send the whole payload to me, right? Wouldn't that look similar every time if there's no obfuscation?
seems like it would also be challenging to hold up in actual legal proceedings
Yeah, basically, but I was thinking that if you're analyzing a pattern going to the client, all you'd need is any point between the guard and the client (ie: an ISP).
If I was browsing one of those sites for an hour and you were my guard, do you think you could make a good guess which site I'm visiting?
I'm asking why that concept doesn't scale up. Why wouldn't it work with machine learning tools that are used to detect anomalous patterns in corporate networks if you reverse them to detect expected patterns.
My understanding (that may be totally wrong) is that there is some padding added to requests so as to not be able to correlate exact packet sizes.
Not really. I'm thinking more along the lines of a total page load. I probably don't understand it well enough, but consider something like connecting to facebook.com. It takes 46 HTTP requests.
Say (this is made up) 35 of those are async and contain 2MB of data total, the 36th is consistently a slow blocking request, 37-42 are synchronous requests of 17KB, 4KB, 10KB, 23KB, 2KB, 7KB, and 43-46 are async (after 42) sending back 100KB total.
If that synchronous block ends up being 6 synchronous TCP connections, I feel like that's a pretty distinct pattern if there isn't a lot of padding, especially if you can combine it with a rule that says it needs to be preceded by a burst of about 35 connections that transfer 2MB in total and succeeded by a burst of 4 connections that transfer 100KB combined.
I've always assumed there's the potential to fingerprint connections like that, regardless of whether or not they're encrypted. For regular HTTPS traffic, if you built a visual of the above for a few different sites, you could probably make a good guess which one people are visiting just by looking at it.
Dynamic content getting mixed in might be enough obfuscation, but for things like hidden services I think you'd be better off if everything got coalesced and chunked into a uniform size so that all guards and relays see is a stream of (ex:) 100KB blocks. Then you could let the side building the circuit demand an arbitrary amount of padding from each relay.
Again, I probably just don't understand how it works, so don't read too much into my reply.
The word "eventually" is doing a lot of heavy lifting here. Let's say you actually manage to add 1000 servers to the tor network somehow without getting detected. The network currently sits at just under 8000 nodes. For simplicity, lets also ignore that there are different types of nodes and geographical considerations and instead just ask what is the probability that someone randomly chooses three nodes that you own. The answer is less than 0.14%. If that someone decided to use 4 nodes to be extra-safe, that number goes down to 0.015%. And it decreases exponentially for every additional relay he adds. Combine this with the fact that tor nodes are actively monitored and regularly vetted for malicious behaviour[1], and these attacks become increasingly difficult. Could someone like the NSA with limitless resources do it? Quite probably, sure. But could you or any other random guy do it? Almost certainly not.
[1] https://gitlab.torproject.org/tpo/network-health/team/-/wiki...
Edit: For all the cynics and doomsayers here, consider this: Tor has been around for a long time, but there has never been an uptick in arrests that could be correlated to cracking the core anonymity service. If you look closely at the actual high profile cases where people got busted despite using tor, these people always made other mistakes that led authorities to them.
Yes, this is obviously the sort of adversary we would be discussing.
> , lets also ignore that there are different types of nodes
causing your number to be an underestimate
> The answer is less than 0.14%.
So almost certainly thousands of people
OP explicitly asked about himself, not some government organisation.
>causing your number to be an underestimate
Not necessarily. It might even be an overestimate if the attacker fails to supply enough nodes of the right kind.
>So almost certainly thousands of people
We're talking about a targeted attack. Of course the statistics game works better when you don't target specific people and just fish randomly. But there are probably more cost effective methods as well.
From OP: " I can't target a specific person, but eventually I can find someone who has all three bounces through tor nodes I control, no"
> Not necessarily. It might even be an overestimate if the attacker fails to supply enough nodes of the right kind.
Assuming they match the existing distribution of nodes, they will only have better results.
Is this per circuit? So if someone switches circuits every X hours, the chance of being caught after a year is actually quite high?
And even catching 0.14% of pedophiles would probably be worth it to the FBI or whatever, nevermind Iran catching dissidents or whatever.
My point is that is seems very cheap to do this (I as a random staff engineer could do it myself) and catch some people. A nation state could easily catch a much higher percentage if they increased the number of logging nodes slowly and carefully and deliberately did things like use many isps and update the servers gradually etc.
There's 1000 red marbles added to a jar with 8000 blue marbles (9000 total). Take three marbles from the jar randomly, one at a time. The odds of getting three red marbles is ~0.14%. That's all.
Tor nodes are not randomly picked marbles. The Tor network is not a jar.
A lot of "hacker" mentality projects involve putting a tremendous amount of effort into something with questionable utility.
People climb mountains because they're there.
>Let's say I as a private individual
Pay people on Fiverr to set them up for you at different ISPs so that all the setup information is different. You can use crypto to pay if you want anonimity (this is actually the main reason I used to use bitcoin - I'd pay ISPs in Iceland to run TOR exit nodes for me without linking them to my identity).
This isn't a difficult problem. A single individual with a good job could do it.
And sure, each connection only has a very small chance of being found, but aggregate it over a year or two and you could catch half of the users of a site if they connected with a new circuit one time per day.
I honestly can't see why a nation state or two hasn't already done this.
With insignificant data caps. To get the data needed I believe you're looking at a couple hundred a month, to start.
Not speaking to the effectiveness of the detection (it's hard!), but there's information available, for example:
https://blog.torproject.org/malicious-relays-health-tor-netw...
https://gitlab.torproject.org/tpo/network-health/team/-/wiki...
https://gitlab.torproject.org/tpo/network-health/team/-/wiki...
They don't have plausible evidence to subpoena the guard node if a middle node only sees encrypted traffic. They would also need to control the exit nodes which communicate with the target's host or they simply control the host as a honeypot.
Ad hominem: your username spells out MIB, Men in Black, surely you are joking.
All Tor hosts use a small set of "guard" nodes as their first hops, because it's considered that directly connecting to a compromised node immediately reveals your IP address, in most cases. Using a small set of first hops reduces the probability that at least one of them is compromised. In older versions of Tor, the middle node is completely random, which means sometimes it is compromised. The German government is thought to have used statistical methods to identify when their compromised node was the middle node, and log the address of the node before it - the guard node. Then, they used legal methods to sniff the traffic on the guard node to find the server's IP address.
In newer versions of Tor, this is more difficult because onion servers use two layers of guard nodes - they use a small infrequently-rotated set of entry guard nodes, and a larger more-frequently-rotated set of middle guard nodes, and the third is still random.
They’re financed by the US Government after all…
Also, according to their latest blog post on their finances, while it is true they have money from the US Government, that was only ~50% of their income (I think that was 2023). For the FUD part of that comment, see the "U.S. Government Support" section of https://blog.torproject.org/transparency-openness-and-our-20...
And if you trust the NSA can’t overcome correlation in the presence of “padding defenses”, then sure: TOR is secure.
That is to say, if I started an onion server on one side of the world, then connected to it from somewhere else, my connection to it would be anonymous and encrypted to any external entity.
Uses a dataset created from aggregation of logs from all nodes in a simulated Tor environment to train a model that can identify the onion server's IP based on fingerprints created from that model.
>We ran the modified Tor software in the Shadow simulation environment to obtain a large amount of circuits for analysis. Shadow is a discrete-event network simulator developed specifically for Tor network simulation experiments and can run Tor software directly. Therefore, Shadow follows all logic related to Tor circuits. In the simulation environment provided by Shadow, we can build servers, clients, directory authorities, onion services and relays, and can control all nodes. Therefore, we can get circuit data in Shadow without the real Tor network.
This is: a) Not a real world example b) Not an example of interception of unencrypted traffic between a client and an onion site c) Not de-anonymization of a client
This: https://www.usenix.org/system/files/raid2019-iacovazzi.pdf
Is super interesting, it's a real world example of using collusion of an entry node that inserts "watermarked" data to identify an onion service.
It does not: a) Intercept or break encryption between client and onion service b) De-anonymize a client
This: https://www.ndss-symposium.org/ndss-paper/flow-correlation-a...
Is the same data watermarking scheme to use entry collusion to identify onion services.
None of your examples show that a connection to an onion server is insecure insofar as data integrity or client anonymity is concerned.
If you're not worried about a fairly well-resourced government agency uncovering whatever network activity you believe needs to be anonymized, why would you be using Tor at all?
They'll just employ parallel construction to avoid exposure.
Because your ex-spouse wants to murder you.
Because you just escaped Scientology, or another cult.
Because you're a criminal. The NSA doesn't handle that.
Because you're a journalist talking to sources in the industry you're investigating.
Using victims' devices and communications in order to locate, and then harass, trap, or attack them, is commonplace for stalkers.
And of those people, how many people have ever even heard of Tor, let alone know how to use it?
Stalkers want to make it impossible to live a normal life. They try to make it impossible to go to work or school, to use phones, email, messaging services, etc. Already knew my contact info, and got new ones by asking mutual friends. Called the the landline and cell and work phone and hung up or heavy-breathed into the phone hundreds of times a day. Telco won't help with this or admit who's doing it w/o a subpoena, which I couldn't realistically get. They tried to get various online accounts, including employer provided, to be flooded/brigaded/spamed/banned.
You don't have to be a leet haxor to do social engineering, sim swapping, and other crying on the phone to customer service type of attacks on other people's accounts. You just have to be pissed off and risk tolerant.
Not saying tor is a good-fit solution to these problems, just saying that "Because your ex-spouse wants to murder you", and also you have a day-to-day practical necessity to find a secure, hard to block way to communicate on, or access, the internet is not actually an exotic problem.
I'm glad we agree!
Knowing that there's one thing they can't get to you on is huge peace of mind. Not needing to think about your stalker, because there's no way for them to hunt you there.
I concede that tor is probably not a useful tool in general for these people. I meant to point out only that one needn't be paranoid to fear one's spouse.
Those are situations that people deal with, but suggesting they use Tor is not going to help them. (Apart from some very specific situations)
Heck - FBI is allowed to do the same damn thing with the data they're given by the NSA. Y'know, the whole "backdoor search loophole" which amounts to laundering authorities across agencies to get access to data they wouldn't otherwise be permitted to have.
Because you want to avoid creepy targeted ads.
Because you live in a country that blocks many legitimate websites.
Because you are looking for information about abortion and live in countries like Iran or US
Using those same network-health dashboards as DDoS target lists, to temporarily degrade/shut down the whole network except for your own nodes.
Also, big nodes route more Tor circuits each. Costs more to run them, and they intentionally don't function as exit nodes (to avoid the "obvious" attack) — but just having a bunch of these big nodes in the network handling only middle hops, biases the rest of the network away from handling middle hops, toward handling end hops. Which means that if you then run a ton of tiny nodes...
Yeah, the stated reason is always something else. But this just reminds me of "parallel construction" - what if they were found in on way and then (to hide the source) the claim was that they were found in another way?
It baffles me that Tor Browser doesn't provide an easy way to blacklist relays in those countries.
[0] Here, you can do the math yourself: https://metrics.torproject.org/rs.html#aggregate/all
[1] https://en.wikipedia.org/wiki/Five_Eyes#Fourteen_Eyes
> Edit: For all the cynics and doomsayers here, consider this: Tor has been around for a long time, but there has never been an uptick in arrests that could be correlated to cracking the core anonymity service. If you look closely at the actual high profile cases where people got busted despite using tor, these people always made other mistakes that led authorities to them.
Maybe someone, somewhere, has decided that allowing petty criminals to get away with their crimes is worth maintaining the illusion that Tor is truly private.
It's also worth noting that it's significantly easier to find the mistakes someone has made that could lead to their identity if you already know their identity.
It provides a channel for operatives to exfiltrate data out of non-NATO countries very easily.
Slight correction: The US benefits from TOR being private to _everyone but the US_
In fact, A major power wins by creating a mote just big enough that only they can cross.
you don't have to be a major power to do such stunts.
everybody and their uncle are already doing it. look into your life to see the truth of this.
I'm not convinced this is the case. For example China's gfw has been very effective at blocking TOR traffic, and any TOR connection in other countries is like announcing to the government that you are suspicious.
Furthermore, the great firewall is quite advanced, they use machine learning techniques to detect patterns, so even if it is TLS on port 443, they may be able to detect it after they have gathered enough traffic. There are workarounds of course, but it is not as simple as just using a TLS tunnel.
The parent said “non-NATO countries”… there are 162 of those that are not China.
(It’s also a little silly to specify “non-NATO” since U.S. intelligence services have to exfiltrate data from NATO countries too…)
To get data out of China, the U.S. undoubtedly has special systems, which are worth the special investment because it’s China.
I bet western spies spend more time on China than some micro island in the middle of the ocean. Same for Chinese spies probably focus on USA first.
Also realistically probably everyone spies everyone and they spy on those micro islands too. But priorities are clear...
I assume that they're connecting multiple times with the CIA - it's not just a one and done drop. That's trivial to look at - if you see someone connecting repeatedly to an IP address that doesn't associate with any known website/service and you see them do it consistently then that's suspicious.
Maybe if the IP addresses rotated it wouldn't be as noticeable, but if you're going over the clearnet then you can't disguise the IP address you're connecting to (short of proxies but then you're giving up the IP address of the proxies).
> the US Navy
Tor was made for spies. But you know what's really bad for spies? If accessing a certain IP/protocol/behavior reliably reveal your spy status.For Tor to be effective for hiding spies it has to be used by the public. Even if it's only nefarious actors (say spies + drug dealers + terrorists) it adds noise that the adversary needs to sort through.
What I fucking hate about many of these conspiracies is how silly it is once you ever work with or for any government entities. You can't get two police agencies in neighboring cities to communicate with one another. The bureaucrats are fucking slow as shit and egotistical as fuck.
It's important to remember that the government and even a single agency (like the NSA) is just as chaotic, disconnected, and full of competing entities as any big tech company has (if not worse). Yeah, most of the NSA is focused offense, but there's groups working on defense. Those groups are 100% at odds. This is true for the 18 intelligence agencies. They have different objectives and many times they are at odds with one another and you bet each one wants to be getting credit for anything.
The US involvement should warrant suspicion and with any technology like Tor you should always be paranoid. But it's not proof. Because guess what, the US wants people in other countries to use high levels of encryption to hide from their authoritarian governments while the US can promote democracy movements and help put a friendly leader into a position of power. AT THE SAME TIME they also want to spy on their own people (and there are plenty of people in the gov that don't want this). Inconsistency is the default because it's a bunch of different people with different objectives. So the US gov both wants Tor to be secure and broken at the same time.
And yet even as early as 2003 they were taking a copy of every single bit that ran over the AT&T backbone (https://en.wikipedia.org/wiki/Room_641A). It's amazing how effective these "chaotic, disconnected, and full of competing entities" can be. We're entirely dependent on whistleblowers willing to risk their lives and freedom to learn about what they're doing to us.
Now things like SCI are things; but there are ways to handle that too. It's more a slowing force than a stopper.
Like human rights activists, journalists and dissidents in totalitarian countries.
Because of its origins, access to the identities of users on the TOR network—even if they could be de-anonymized—would likely be extremely restricted, compartmentalized, and classified. This would make it much more difficult for such information to be used in law enforcement proceedings. Perhaps that, rather than a technical limitation, is the reason most high-profile arrests related to TOR involve criminals making some other mistake, rather than the security of the network itself being compromised.
Additionally, it’s interesting to speculate that some of the secure private defense and intelligence networks—parallel or classified world internets—could themselves be implemented as possibly enhanced forms of TOR. It would make sense that nation-states, through shell companies and other disguises, might run and control many seemingly innocuous machines acting as secure relays in these parallel networks. While I have no data to back this up, it seems logical, given that TOR was originally created by the DoD and then open-sourced.
Why wouldn’t they keep something that works, build on it, and enhance it as a means to secure their own global communications?
i have to say that i love that phrase, it is peak propaganda that just works.
We even have a presidential candidate that spouts similar propaganda that she is going to “Save Democracy”! Yeah right, save it by subverting it at every possible point. First she was appointed into the VP role, then her party skipped holding a primary election, then she was installed into the candidacy. None of those 3 easy steps to power even vaguely resembles a Democracy.
If those 3 succinct points aren’t enough, here’s a few more succinctly in one sentence: Members of her party have tried to deplatform her opposition, cancel her opposition, remove her opposition from the ballot, expropriate over $450 million dollars from her opposition (NY Kleptocracy), jail her opposition, and even assassinate her opposition twice! In all cases to deny and deprive the ability of voters to have a choice in the upcoming election. If her opposition is so bad as her party propaganda wants you to think, won’t that show in the general election? Why does half of America vote the other way? What have they seen that you haven’t?
intentional pause
There could be unlimited reasons why one of our candidates is not about “Saving Democracy” or how that slogan is just propaganda. I’ll give 4 more numbered reasons why:
1) She represents a party that is opposed to Voter ID requirements at polls, which would keep people from voting twice, pretty much like a Bitcoin double-spend attack. Her party’s establishment claims voter ID laws are a problem because they think their voting base is so stupid they couldn’t pass a drivers license test on any number of attempts; let alone figure out how to obtain another form of photo ID. Many in her voting base find that stance pretty offensive and rightfully so. Opponents will assert they couldn’t win a fair and free election if they tried to. Both sides aside, How are voter ID laws a partisan issue? They are just common sense!
There’s a reason their party tries to “get out the vote” every year: low-information-voters are their bread and butter. How many people actually have the time to think critically about these issues? I think America would be a better place if less low-information voter chose to vote and if more voters knew that it’s okay to leave choices on the ballot blank.
2) One of her long standing border policies has been keeping the borders open so that illegals can flood the cities and further dilute the voting power of the constituency base. This leads to more apportionment in the House of Representatives because under the current law, illegals are counted too. This perverse incentive dilutes the vote of the American people and the constituency.
3) Flooding American with illegals is very unpopular with the vast majority of America. If that was put to a vote with the American people, it simply wouldn’t continue. Most people are in support of legal immigration not illegal and unvetted immigration because we want the good talent and beautiful women to cross the border, not whomever can find a gap in the fence. I said beautiful women for your benefit. You’re welcome :)
4) Her third claim to fame is she won’t be going around to very many of the 3-letter agencies (if any) and saying “You’re fired!”. A bureaucracy’s favorite leader is a puppet. They get to control her rather than her getting to control them. When left unchecked, we have power-creep. When we have a bunch of bureaucrats running the government, it subverts the will of the people because we voted for the president, not the unelected bureaucrats who tell her and the current president what to say. Some people joke that the vast number of 3-letter agencies are the 4th branch of government. Some people want all of the power but are afraid of public speaking and don’t want to stand up in front of a podium to explain their case to the American People and appear online. Some simply can’t make a reasonable argument for one point or another... I can and I’m doing that now.
Spreading Democracy is possibly becoming a euphemism for spreading Bureaucracy. Bureaucracy is like taking the DMV and scaling it all the way up to the size of government. Thankfully due to the Chevron doctrine court case, the power of the bureaucracy has been reduced and we can appreciate the effect checks and balances have to save our system of government, which most scholars agree is a Democratic Republic.
Instead of the word Bureaucracy, her presidential opponent uses a more specific term to describe it. He popularized the term “Deep State” from fringe usage to mainstream usage. The term Deep State usually refers to a subset of the 3-letter agencies known as the intelligence community or the intelligence agencies. One of many possible citations is the Joe Rogan podcast episode #2138 with Tucker Carlson, which, although long, is jam packed full of secrets.
Both men talking in that episode have interviewed and have had public (and presumably private) conversations with an enormous and significant quantity and variety of people. They’re also among the best in the world at “active listening” which some people just simply can’t do. That causes interviewees to open up and spill the beans, which is where real journalism & interviewing is.
My most memorable takeaway from that episode is:
“The second point that’s obviously true is that weak people, which is a synonym for bad people, come together for strength and safety. They act as one. The hive mind is specific to a certain group of people: bad people. And that good people don't tend to come together, but they're coming together now.” and “It’s weak men and weak women who are instruments of evil. The weaker, the more evil that leader will be.” I’ll paraphrase: “Men and women without a backbone or spine are the most dangerous because they’re the most corruptible to do what’s wrong against what’s right. Sometimes we take it for granted that strong people wouldn’t do bad things because it compromised their morals or ethics. Like bad sportsmanship.”
I say all this at the risk of potentially not being able to leave Canada or the UK for 18 years if one of my layover flights ever stopped there, despite being a USA citizen in the USA. I also potentially risk being added to the target list of the next virus or bioweapon that leaks out of a lab like the Wuhan institute of Virology. We only found out what was happening there because the orange man wanted to cut all free money to China and someone reviewing the spending line items found we were funding the Wuhan Institute of Virology. Apparently we still are and it’s been allegedly upgraded from BSL 2 to BSL 4 lab. It’s just one of many labs. Like nukes, bioweapons produce plenty of collateral damage. Unlike nukes, they’re deniable assets. Bioweapons are freaking scary. You get to learn how easy it is to wipe essentially all human life off the face of the earth in the popular educational simulation game Plague Inc with various plagues.
In 1969, Bioweapons labs in Fort Detrick and Plum Island boasted to the President that they had the capacity to kill every American in America for 29 cents per life. That year President Richard Nixon surprised everyone and did one of the greatest things of his career, which is he went to Fort Detrick, then he announced the closure and termination of the U.S. Bioweapons programs. He saw that bioweapons were a poor man’s nuclear bomb. Then the Patriot Act was signed which according to Robert F Kennedy Jr had a hidden charter that while not retracting Nixon’s charter to close bioweapons progress, gave immunity to any federal official that violates those laws and who develops bioweapons and researches them. As you know, vaccine research and Gain of Function research are on a similar track so you can say you’re doing vaccine research when actually doing Gain of Function studies for bioweapons like most later evidence for COVID-19 shows. That information was suppressed because they didn’t want everyone to get all up in arms with China. Unfortunately, Gain of Function research is still continuing and being funded by tax payer dollars, no less.
I know what I’m saying is risky but the freedom of speech in my country is a right, not a privilege.
Last, my summary and disclaimer:
Vote for who you think is right based on the knowledge you know. I have a large appetite for knowledge but I don’t know everything. You may know something I don’t. I believe we all have a good head on our shoulders and can make good decisions with sufficient truthful information to make those decisions. If that information is sequestered, kept hidden, or censored, then democracy is subverted. Is that politician here to “Save Democracy” as some of her low-information potential voters say or are those just words of propaganda? Above I gave 4 more numbered points in support of why that’s just more propaganda but my motive is to inform, not to persuade.
The lesson here being; if you forget the point of keeping your government around (for the U S., preserving Liberties, and asserting the supremacy of those rights over the legitimacy of any act of Government trying to curtail them), and conflate the government with the end itself, you create and perpetuate an inhuman monster capable of manufacturing the conditions for manifesting atrocity on scales that would make the despots of the past blush for how unambitious they ultimately were in comparison. For there is literally no stopping something once you've managed to elide the meaning of our most sacred values across generational boundaries from meaning one thing, to something completely different. As an example, from the work of Art in question: Freedom being taken to mean "you are Free to decide how you support the regime", but not whether you should be supporting the regime at all.
I assure you, if winning takes you in that direction, you're barking entirely up the wrong tree.
Do you think the EFF was in on it, duped, or just thought multiple competing interests could be served?
I haven’t looked closely and I wasn’t there at the time so it makes it hard to say for sure but let’s speculate. I think the people involved in EFF are most likely slightly cynical, savvypolitical maneuverers themselve who, like you said realize the utility of multiple not necessarily overlapping objectives, where all involved parties could derive some benefits.
Certainly not an implausible situation that you lay out
I have no doubt that the government doesn't want to demonstrate how weak Tor is to the public, but it's also got to be dead simple to find those kinds of "other mistakes" they can use when they've identified the person they're looking for and can monitor whatever they do.
I’m not saying TOR is weak, nor that the reason for its concealment is to project a false sense of government strength.
What I am saying—and what you seem to have misunderstood—is that the TOR network is most likely used, precisely because of its strength, for highly sensitive clandestine operations. This results in blanket classification of all involved identities, making them inaccessible to law enforcement. Law enforcement likely understands this, which is why they don’t pursue it—knowing it’s a dead end. Instead, they rely on side-channel effects or mistakes made by criminals.
To my mind, this explains the public information we see.
Now that I’ve clarified, what do you think?
Tor seems to be a poster child of the "Nobody But Us"[1] principle the NSA likes so much: it's strong when used by American spooks, but weak when used against them. If a country developed body armor that's impervious to all rounds except their own special alloy rounds, their use and promotion of that armor is not evidence of its utter robustness.
I don't doubt a lot of darknet busts involve a lot of parallel construction - the intelligence community doesn't have to give detailed logs; summaries are enough (IP addresses, dates and times). This is before considering that the FBI is involved in both (counter) intelligence and law environment.
What do you mean by parallel constructions? Is that where LE discovers evidence through extralegal means, then needs to rebuild the narrative through a legally valid chain? Could be, but then again there's probably a lot of TOR identities that are completely out of reach for LE, leaving them with only legal construction. Wouldn't you say?
I sometimes wonder about something, too: you know those "small" cases with huge human cost, like missing child, or murder in a backwoods area? I always imagine that classified capabilities could be used to solve them. The fact they are not, is painful, and I think must be "moral trauma" for LE/IC people involved. Even more so that they can't talk to anyone about it except their organizational therapists if then.
This is what I believe. If they do have a way to track people, it wouldn't be worth blowing their cover for small stuff that wasn't a ridiculously huge national security threat that they could afford to throw away 20+ years of work for.
In fact there have been court cases that were thrown out because the government refused to reveal how their information was obtained... I think that usually means they're hiding it on purpose for a bigger cause. I also wouldn't be surprised if multiple SSL CAs are secretly compromised for the same reason.
If it was effective, would there have been a down tick in arrests at some point?
Or if the arrest rate stayed the same, would that suggest it never “worked” to begin with?
It’s like the movie trope of the detective who finds out the truth via some questionable means which isn’t admissible in court. When you know the truth you can push harder and call every bluff until you get admissible evidence.
You calculated the probability that a specific person randomly chooses three nodes of the 1,000.
But that's not the scenario you're responding to.
>> I can't target a specific person, but eventually I can find someone who has all three bounces through tor nodes I control
Tor estimates that 2.5 million people use the network per day.
Let's assume that in a month, 10 million people use it.
Let's also assume that 80% of monthly users are not committing crimes, while the 20% who are criminals make an average of four Tor connections per month.
With those assumptions we could expect a malicious operator who controls 1,000 nodes could capture the sessions of 10,940 criminals in a given month.
Spending less than fifty cents per suspect is less than trivial.
Let’s say to do that, and now you have found 10k people accessing pirate bay in countries where it is blocked.
Also you captured someone who lives in Siberia and watches illegal porn, now what?
Many of these will not be actionable, like not criminals you would have interest in.
100,000 activists who haven't been caught yet switch to Tor for anonymity.
For $60,000, the regime monitors Tor for a year, identifies 6,500 activists, and marches them off to the camps.
And by discrediting Tor the regime pushes the other 93,500 activists even farther underground, constraining their ability to recruit, limiting their ability to coordinate with each other, and reducing what they can publish about what's happening to their country.
To what audience? It isn't quite what you're getting at in your post but this is worth saying: graffiti, zines, contact with journalists, radio operations like pirate radio, all of it is much more established and less uncertain in risk profile than being online. Crucially it may also be more effective.
What does that mean? The way I understand it you would be getting traffic correlations -- which means an IP that requested traffic from another IP and got that traffic back in a certain time period. What does that tell you, exactly, about the criminal? If you aren't looking for a specific person, how would you even know they are doing crimes?
The billionaire owner of the site supports the strongman leader and provides IP addresses for those who post wrongthink on his platform.
Now the regime can link social media activity of anonymous activists to their real IP addresses, devices and locations.
2/ Police can use parallel construction. Although, given enough time (in theory) parallel construction is eventually exposed.
Parallel construction has existed for decades. It's even in "The Wire". It has never been tested in court, probably because it is nearly impossible to discover outside of being the agents that implement it.
Parallel construction wasn't tested, but the means of them catching criminals this way was tested in court.
[0] - https://www.gps.gov/news/2012/01/supremecourt/
[1] - if the device got power from the vehicle, it would be considered "break and entering" and thus would require a warrant.
During WW2, the British cracked the German codes. They would create pretexts for "discovering" where German ships would be, so that the Germans wouldn't suspect that they cracked their codes.
It's impossible for us to know if the US government have cracked Tor, because the world would look identical to us whether they had or hadn't. If the only evidence they have is via Tor, and the individual is a small fry, they will prefer they get away with it rather than let people know that Tor has been cracked.
I just assume the NSA are spending their budgets on something, although maybe it is stuff like side channel attacks.
The NSA sharing data with the DEA becomes a "routine traffic stop" that finds the drugs. The court would not allow the NSA evidence or anything found as a result, but through parallel construction, the officer lies in court that it was a "routine stop", and judicial review never occurs.
Says who? The intelligent community entity that busted them? If they're using a tool to discover X or Y they're not to let anyone know that.
For example, I live in the NYC area. A couple of times per year there's a drug bust on the New Jersey Turnpike of a car headed to NYC. The story is always a "random" police stop ends up in a drug bust.
Random? My arse. Of the thousands of cars on the NJTP the cops just happened to pick the one loaded with drugs? A couple times a year? I don't buy it. But what are they going to say? They have someone on the inside that tipped them off? That's not going to happen.
The intelligence community doesn't deal in truth and facts. It deals in misinformation and that the ends justify the means. What they're doing and what they say they're doing are unlikely the same.
They'll just make something up for publicity if they don't get something useful.
Assuming tor always was or became broken and is exploitable by law enforcement, authorities would try to maintain a false believe of tor's integrity so as to crack high profile cases for as long as possible.
Within this scenario, it is plausible to assume that authorities can decipher and discover information that can be used as the official pretextual charge / minor reason ("they made the mistake to use their public email address on the dark net forum") in order to not spill the beans on the actual means (here, tor being broken).
> Tor has been around for a long time, but there has never been an uptick in arrests that could be correlated to cracking the core anonymity service.
If I were an intelligence agency that had "cracked" tor -- I'd probably make sure nobody would notice I had access, so I could keep eavesdropping. Not do anything that could expose my access.
It certainly could be happening. Nothing is 100%. Nothing. Just a fact. Tor is probably pretty good at what it does.
(and keep in mind, for what we're talking about in this kind of attack, all I get access to is network contacts, not the actual messages, right?)
I'd call tor broken against any adversary with a little technical skill and willingness to spend $5000.
I'm 80% sure Tor is designed as a US supported project to focus those needing anonymity into a service only governments with global security apparatus (who can grab a good chunk of internet traffic) can access.
I had the impression, with onion services they are a thing of the past.
Seemed like onion services were created to solve the security issues that exit nodes bring, so I assumed people stopped using them and started running onion services instead.
If most Tor users ran exit nodes and most people used Tor, it would effectively make internet traffic anonymous. But without those network effects, it is vulnerable by design to deanonymization attacks by state actors.
This also means the expiry time is usually tied to however long a Tor exit node stays on the DNSBL + 3 or so days (depends on how long the software is configured, but 3 days is typically the assumed default for IPs that tend to get mixed up with automated spam, of which Tor is also a massive purveyor.)
People that have such a sophisticated and resourced team actively hunting them down, likely know about it, and are using many additional layers of security on top of TOR. Even just for personal use out of curiosity to "see what the darkweb is," I used 1-2 additional methods on top of TOR.
Curious: what did you do and what were you hoping to mitigate?
Also since you aren't targetting specific people, rather specific interests, it'd be easier to setup an irresistible site serving content of the vice of interest. It can even be a thin wrapper on existing sites. Do you only need to control entry nodes in that case? You'll return user-identifying data in headers or steganographically encoded in images and since you control the entry node you can decrypt it. It doesn't work for a normal (unaffiliated) entry node but since your entry node is in collusion with the server I think this works.
If you want basic anonymity while researching someone powerful or accessing information, it's extremely unlikely anyone is going to go the lengths people are bringing up here as a way to compromise Tor. The intersection of expertise, funding and time required is too great for such a low value target.
If you're an international terrorist leader wanted in multiple countries, a prolific criminal, or enemy #1 of an authoritarian state though? Those who can go to those lengths absolutely will go to those lengths.
Doesn't a solid VPN service also satisfy this exact need? Tor seems to occupy a narrow niche in which you have to care much more about privacy than the average person, but not at a nation state level. I think that is how it got associated with that 2nd tier of internet crime like buying drugs on the dark web or sharing CSAM. The truly sophisticated internet criminals probably know better and the people who only really care about anonymizing themselves are probably doing something simpler.
Finding a solid one is the hard part. With tor, you kind of know what you are buying. The risks are in the open. With VPN maybe the operator is selling your data to advertizers. Maybe they are keeping logs. You kind of have to just trust them and have no way to verify.
Take for example, John Draper who discovered in the 60's that a Captain Crunch whistle toy could be used to make free phone calls on the telephone systems. Or the discovery of Side Channel attacks by an engineer at Bell Telephone company who noticed that a Bell Telephone model 131-B2 would produce distinct spikes for each key pressed on the oscilloscope across the room. Therefore not requiring nation station level expense to break the encryption used by Navy and Army's encryption systems. Or during the Afghan war, the US was deploying armored vehicles that they assumed would provide good protection, and would be expensive to attack by the enemy. Turned out they could make IEDs from inverted copper cheaply and within locals kitchens. That proved very successful. Or the kid who discovered he could bypass the mint screensaver by smashing random keys on the keyboard (https://github.com/linuxmint/cinnamon-screensaver/issues/354). The list of these types of cheap attacks are throughout history.
I ran a bunch of nodes for a couple years and that's optimistic by perhaps an order of magnitude. No $5 a month VPS provides enough bandwidth to sustain the monthly traffic of a Tor node, and nodes need to be continuously online and serving traffic for about 2-3 months[1] before they will be promoted to guard relays. Throttling traffic to stay in your bandwidth allocation will just get you marked as a slow node and limit the number of connections you get. Sustaining just 1 Mbps will blow your monthly transfer allocation on the cheap tiers of both Digital Ocean or Linode.
Russia, china and usa all dont like each other much so are probably not sharing notes (in theory).
Basically, a variation of the prisoner's dilemma.
Also, those nukes we have pointed at each other are a pretty healthy hint.
"The simplest explanation is usually the best one."
Conspiracy theories are a logical reasoning black hole.
I personally feel it's generally best to avoid the mental Spaghettification.
They are neighbors with some overlapping interests and sort of similar goals if you squint. It wasn't very long ago that they were killing each other over border conflicts and annexed territory.
China right now is just using Russia for cheap energy, they don't actually care about the health of the state.
If that's how geopolitics worked China would still be an American ally, vice versa. But alliances can change. Once an enemy always an enemy isn't a thing.
>they don't actually care about the health of the state
That's true but it's not a requirement for Xi to care about Russia. In fact I'm very sure he doesn't care about the Chinese people either. Russia needs China and the CCP uses Russia, not just for cheap energy but for fighting a war that many Westerners haven't even realized that it has begun already. Russia and China have a common enemy, that enemy is NATO.
1: A good video explaining history & status quo: https://www.youtube.com/watch?v=XHMa-Ba-2Mo
The attacker could try to create a handful of accounts on hundreds of platforms in as many countries as possible, assuming one verify that the platforms accepts tor and do not share underlying providers and data centers. The cost would then be the average price of said providers, which is going to be a fair bit more than the cheapest providers out there. Managing and spreading them out is also going to cost a lot of man hours. Also the secops need to be fairly on the point and need to be maintained quite strictly across all the providers.
https://www.schneier.com/blog/archives/2024/09/remotely-expl...
Still, I think your point is excellent. The sort of group interested in tracking someone(s) over Tor certainly might have the capability to do so despite the difficulty.
Was the operation against Hezbollah funded by a private individual? Otherwise I'm not sure the relevance of your statement to the comment that started this thread.
That said, any bandwidth anyone wants to contribute to mitigate such attacks is always appreciated, even if it's more useful for performance reasons in practice. ;)
It's individuals
Sometimes I set it up as a bridge (hidden entry node) instead.
I ask because I know of stories of law enforcement sending inquiries to owners of, say, exit nodes requiring certain information about given traffic. I don't know if this happens for middle-nodes (or whatever they're called).
Moreover, are there any issues with associating a node to, you know, your name and billing information?
I don't know much about this, and although I could look it up, I think that my questions - and your respective answers or those of others - might do some public service of information sharing here.
You can buy a vps with xmr if you're worried about privacy from law enforcement.
ctrl-f for web hosting
https://www.serverhunter.com/#query=stock%3A%28in_stock+OR+u...
Either they are grossly negligent/incompetent (IMO unlikely given the extent of their research), or they knew it was intercepted on purpose (either by law enforcement, the provider itself or one of their upstreams) and intentionally aren't saying so. They could also be withholding or lying about any number of things, including the exact response from the hosting providers.
I am kind of shocked because I really got positive feedback of hetzner from what I heard from people.
I need to post about this on r/vps and hear about people's opinion.
Edit: there's a youtuber called "Mental Outlaw" that published a while ago some videos about setting up and operating TOR nodes. He sometimes gives inaccurate information regarding more theoretical topics, so I don't follow him much. But I think he can be trusted for this practical topics.
It would be impossible to create daily content if you weren't just rehashing, or taking, information from somewhere. Again, not defending it at all, just saying it's probably a very common thing. Like how some crappy news articles are just a bunch of reddit comments, like that qualifies as news.
Make a channel
Find popular reddit/social media post
Use AI tools for text to speech
Use AI tools to generate pictures
Stitch it all together
Post on channel.
I haven't watched this particular channel so maybe it's obviously shady, but I'm curious: why is this conceptually a crappy thing to do?
I mean, if you take the IP of others and redistribute it verbatim then I definitely see the ethical issue. So if the claim is that he's reading peoples' comments or posts verbatim without credit then yeah that's crappy. Don't get me wrong.
But if all we're talking about is "mining" websites like HN for topics and then creating original content that covers those topics in a different format for a different audience... where's the issue?
A few years ago I was feeling pretty burned out in the tech industry and created a tongue in cheek "luddite" channel called TechPhobe where I took an overly pessimistic view of the industry. At the time Elizabeth Holmes was on trial and a lot my videos involved me reading ArsTechnica articles on the subject (credited) while offering my personal opinions on the matter. While not successful, those videos got more views than anything else I ever created. Was that a crappy thing to do? I didn't think so at the time and I don't think so now.
I didn't stick with the channel because I realized pretty quickly that if I'm dealing with burnout the last thing I should be doing in my spare time is focusing on tech content lol
Plagiarism, generally. I really enjoyed the semi-recent hbomberguy video on why it matters, and a later response (from another channel) on "The Somerset Scale of Plagiarism" for a more rigorous explanation of what the different kinds of "content reuse" can be. Those are generally where my current model of plagiarism comes from.
A specific concern would be the inaccurate telling of information that isn't understood. A video saying, "Here I will summarize this HN thread," is perfectly ok, and a good thing. A video saying, "Here I will tell you how $thing works," should be well researched and cited. Doesn't matter if the content's entirely from an HN thread for from 40 different SEO farms, it's low-quality content and it's wasting everyone's time at best, and probably actively misinforming people. (Because how true and complete is information gleaned from HN comments anyway?)
If your threat model is actually three letter agencies coming after you specifically... that's an entirely different problem not (just) solved by software.
The support teams always understood once I explained it was a tor exit node. I co-operated with the Cloud provider and added any IP-address that requested it to my list of exempt addresses.
But they don't have to. It could also be against their ToS, and many other providers would not have been ok with it. Accounts and domains have been taken away for much less.
Apparently in germany they caught a pedo like that. Watching certain nodes and the sizes of files that are sent between them to identify the admin of a pedophile image sharing forum. Took them 1 1/2 years to identify the specific person, but they got him.
Considering this I would imagine it's pretty safe for the average user since they have to specifically target you for a long time, however it seems like with enough effort it's possible to identify someone even without Clearnet slip-ups like it was the case with Silkroad.
Once they have your address they will just storm your house and catch you on the computer, then you are done for.
Circuits are temporary but the traffic is not scattered across the network to make MITM fingerprinting of request/payload sizes/timestamps impossible.
A typical MITM like the FBI surveillance van next door can identify you by observing the network packets and by _when_ they were requested and by _how large_ the payloads were. There was a famous court case where this was enough evidence to identify a user of an onion service, without the FBI having access to the Wi-Fi of the user. But they had access to the exit node logs that were encrypted, the pcap logs to the onion service from that exit node, and the encrypted Wi-Fi packets of the user.
(Also TLS lower than 1.3 and SNI related problems are relevant here, because DNS TTL 0 effectively makes everyone's privacy compromised, shame on you if you set a DNS TTL to 0)
My point is that with more randomized hops across the network and across ASNs it would be less likely that a threat actor can control both guard and exit nodes.
(Assuming that they parse RIR datasets to map organizations across ASNs, which the datasets already provide)
There's a lot of tools available that can fingerprint different applications pretty well these days. For example, Firefox and TOR Browser can be fingerprinted because of their custom network library that's OS independent.
It gets worse if you use a DSL2 connection with scaling because that will uniquely make your packets fingerprintable because they have a specific MTU size that's dependent of the length of the cable from modem to the next main hub. Same for cable internet, because the frequencies and spectrums that are used are also unique.
(I'm clarifying this, because an FBI van not having access to your Wi-Fi still has access to the cable on the street when there's a warrant for surveillance / wire tapping issued)
[1] https://github.com/NikolaiT/zardaxt (detects entropies of TCP headers and matches them with applications)
[2] https://github.com/Nisitay/pyp0f (detects the OS)
[3] https://github.com/ValdikSS/p0f-mtu (detects the VPN provider)
And of course for a state-level actor, they can afford a couple orders of magnitude more spend prob too.
The primary purpose of tor is for their own use, which is why they have developed and funded it. So the underlying principle is secure, but they’ll definitely be paying for enough of the nodes to compromise it for you.
And more info here: https://lists.torproject.org/pipermail/tor-relays/2024-Septe...
Edit: The NDR alleges a timing attack (no further explanation) that allows "to identify so-called ‘entry servers’" Very little information is actually available on the nature of the attack. The NDR claims this method has already lead to an arrest.
e.g.
Port 873 (native rsync) bulk traffic, low priority
Port 3128 (squid mitm ssl-bump proxy) high priorityHowever, some things, like Tor, can make your use of the Internet safer.
If all you’re doing is arguing that Tor shouldn’t be used because it isn’t/was never “safe”, then you might as well not use the Internet at all.
When people say they're distrustful of Tor (for various reasons) to the extent they refuse to use it, they seldom suggest alternative tools/measures that provide anywhere near the level of safety offered by Tor.
Functional security means understanding your risks, and using privacy tools is a risk - in the sense that it does single you out in the current environment.
Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough.
Just saying "everyone should use these tools!" is not actually a counter-argument. It's a fine long term goal, but it's not addressing the real risk that some folks might be in.
Pigs have significantly higher density than birds and lack wings. Getting them to fly under their own power would be quite a challenge. By contrast, installing Tor Browser is actually pretty easy.
> Your actual communications can be secure, but that doesn't stop a bad actor/government from picking you up and beating you with a wrench until you talk - if they get suspicious enough.
In general this is not what happens in e.g. the United States. The act of installing or using Tor doesn't in and of itself cause anyone to beat you with a wrench. Try it. Visit HN using Tor Browser. No one comes in the night to put a bag over your head.
> Just saying "everyone should use these tools!" is not actually a counter-argument. It's a fine long term goal, but it's not addressing the real risk that some folks might be in.
If you live in an authoritarian country and actively oppose the government, you are already doing something that will get you punished if you're caught and then the question is, which is more likely to get you caught? Tor has several measures to reduce the probability that you're detected. Private entry guards, pluggable transports, etc. You might still get caught, but these things reduce the probability, whereas if you openly oppose the government without using any privacy technology, you're much easier to catch. Using it in this case is pretty clearly to your advantage.
If you live in a country that has a modicum of respect for fundamental rights like privacy and due process, then you can use Tor when you're not breaking any laws and are just trying to avoid being tracked across the internet by Google and Facebook, because using Tor isn't in itself illegal. And doing this not only benefits you, it benefits the people in the first group who need it even more than you do, because it makes them stand out less.
So who are the people who shouldn't be using it?
HN used to often not create new user accounts when connecting from Tor.
Twitter doesn't let a new user account to pass the prove you're human AI challenge. It says it passes but then shows an error message that there was a technical issue.
By using Tor I'm cut off from Twitter. Twitter is my social media of choice. By using Tor I'm cut off from social media.
The reason tor traffic is often denied is because it's hard to block or track "the same" tor use, and some people used to abuse this to perform actions that the platform does not want.
You cannot really have true privacy, and also have moderation of content.
Consider this: just like fraud, the ideal amount of it in any purportedly liberal civilization is non-zero, because the freedom from which is derived the opportunity to engage in the behavior is more important than perfect attribution, detectability, and prosecubility of it.
People don't realize that when you set goals of zero'ing out these sorts of things, you're throwing the baby out with the bathwater.
My statement is pretty clear - using a privacy tool can single you out. Am I afraid of that in the US? Nope, not really.
Would I be afraid of that in, say, Iran? North Korea? Russia? Israel? China? Probably.
> If you live in an authoritarian country and actively oppose the government, you are already doing something that will get you punished if you're caught and then the question is, which is more likely to get you caught? Tor has several measures to reduce the probability that you're detected. Private entry guards, pluggable transports, etc. You might still get caught, but these things reduce the probability, whereas if you openly oppose the government without using any privacy technology, you're much easier to catch. Using it in this case is pretty clearly to your advantage.
You know a clear way to avoid this risk entirely? Don't trust your communications to a public network. Is TOR better than posting directly online? probably. Is TOR still a risk? Obviously yes. Understanding your risks is important, and simply saying "Use it anyways" is not an appropriate answer. Like... at all.
Which does imply that the "singles you out" argument doesn't really apply to anyone who is in the US or any country with a non-authoritarian government.
> Would I be afraid of that in, say, Iran? North Korea? Russia? Israel? China? Probably.
But in those cases your problem is the alternative. If you don't use Tor then you're trapped between the oppressive option of self-censorship or the even more dangerous option of not censoring yourself while also not using any privacy technology.
Moreover, the more people use it the less using it singles anyone out, and the more people contribute to making it harder to detect etc. See also Hofstadter's theory of superrationality.
> You know a clear way to avoid this risk entirely? Don't trust your communications to a public network.
"Just build your own internet" is frequently not a realistic proposal.
> But in those cases your problem is the alternative. If you don't use Tor then you're trapped between the oppressive option of self-censorship or the even more dangerous option of not censoring yourself while also not using any privacy technology.
Don't use online communication. Period. Talk to people face to face.
> "Just build your own internet" is frequently not a realistic proposal.
Don't use online communication. Period. Talk to people face to face.
> Which does imply that the "singles you out" argument doesn't really apply to anyone who is in the US or any country with a non-authoritarian government.
Not my damn point. And you well know it, you just don't want to concede a breath of air to the idea that you might be wrong...
> Moreover, the more people use it the less using it singles anyone out, and the more people contribute to making it harder to detect etc. See also Hofstadter's theory of superrationality.
Fallacy is fallacy. Dreaming of a utopia does not make it so, and expecting the average person to take this stance just isn't a realistic expectation. Noble goal. Shit thing to risk your personal safety on.
---
And that's the point. I advocate for these tools, I use them I when I think they're appropriate. Failing to be able to consider a possible downside isn't a "good" thing. It doesn't make the argument for these tools stronger... it makes it hard to evaluate your risk, and personally - makes me think you're actively undermining real efforts for security.
So if your actual stance is "Use these tools even though I understand it compromises your personal safety - I don't care because blah blah blah"... then I don't have enough respect for you to continue the conversation. You are only acting for you, and that's shitty.
I also use tor in my work in order to get a third-party perspective on a website, or when inspecting suspicious links.
You don't do something, once, and then are good to go forever. Banks don't just put cash in a safe and forget about it; they have audits, security guards, cameras, threat intelligence profiling criminal gangs, etc.
For instance, for buying drugs, the ordering isn't the risky bit. Receiving it in the mail is. Even if tor was magically "100% safe" the crime overall wouldn't be. The point of using tor is not to eliminate all risk, it's just to decouple payment from reception. I had my drugs intercepted by customs once, but they couldn't prove I ordered them, so they dropped the case. I'm sure it might've been possible for them to prove it if they spent a lot of resources trying to trace crypto transfers and so on, but police only do that if the fish is big enough because they're resource constrained.
Tor is just another tool criminals can use to reduce risk. It's not perfect, but for most things it's the best thing available.
An analog crime I think about is the murders in Moscow, Idaho. The criminal did take some careful measures like wearing gloves but he left a knife sheath behind that contained DNA evidence. Everything else they had on him was circumstantial, he owned a similar car to what police thought they saw on people's doorbell cameras and his phone went offline during the time of the murders and also pinged a tower close to the crime scene hours afterwards. Police found a partial genealogy match to his DNA which I'm sure they compared to similar car owners and cell tower records. If he hadn't left the sheath behind, wore something like a Tyvek suit, and simply left his phone at home, the suspect pool would have likely been too large. His careful measures (turning off his phone, making multiple passes in his car) likely contributed to police focusing on him once the DNA proved a link.
Nope. Not even that is 100% safe because you can be falsely convicted of a crime you never even committed. Many privacy tools reduce that risk as well, because you're less likely to be convicted by e.g. a lazy prosecutor willing to take things out of context if you provide them with less source material to trawl through.
If you weren't actually buying drugs online then there shouldn't be any evidence that you were (or the cops planted it and then we're back to it not really mattering whether you have Tor installed). And then what are they charging you with that would even make it to a jury instead of being dismissed by the judge for lack of evidence?
If Tor was ubiquitous obviously not, but its very niche, and looking at a chart of use, its pretty much only used for drugs and CP. There are privacy use cases, but just like using crypto as a currency and not a speculative gambling investment, its in the small minority of uses.
Why did you do multiple searches for std::vector? Are you worried about sharing needles? You also read an article about caffeine, which is often used as a cutting agent. You've been participating in internet discussions about using Tor, which the prosecutor argues is only used for CP and drugs.
> If Tor was ubiquitous obviously not, but its very niche, and looking at a chart of use, its pretty much only used for drugs and CP.
Nobody really knows what Tor is used for, by design. But the media likes to rile people up, and "Tor used by privacy activists to read Facebook" isn't a headline that does that.
It's all too easy to lie with statistics. For example, some people have looked at which hidden services are most often looked up. That's not going to tell you about real usage, because bots do lookups at a much faster rate than real people, and government agencies run automated crawlers. Then you get statistics that say a significant percentage of the lookups are for CP and drugs, but not what percentage of those lookups were made by law enforcement running crawlers 24/7 specifically looking for CP and drugs.
Here's another example:
https://www.sciencealert.com/only-a-small-fraction-of-the-da...
> "In countries coded as 'free', the percentage of users visiting Onion/Hidden Services as a proportion of total daily Tor use is nearly twice as much or ~7.8 percent."
> In other words, people living in liberal democracies are more likely to exploit the dark web for malicious purposes, whereas users living under repressive regimes in non-democratic countries might be more likely to use Tor to circumvent local censorship restrictions and access free information on the internet.
Tor is used to bypass censorship. This use case happens more often in countries where there is censorship, and less often in countries where there isn't, because obviously. Reaching from there to "people living in liberal democracies are more likely to exploit the dark web for malicious purposes" is ridiculous. A higher ratio of B to A because of a smaller need for A does not imply a greater occurrence of B.
That's so exceptionally unlikely as to be something you can discount as a possibility, providing you don't actually commit crimes.
As opposed to... people who undergo illegal activities with the intention to BE caught???
SSL/TLS was introduced for POP3/IMAP, but I don't think that was bad.
Email to this day is unencrypted at rest and completely transparent to whomever is running your mail server. You don't think Google runs GMail out of the goodness of their heart do you?
I think the Middle East gave us a very clear example of how state actors may target channels in unexpected ways.
Exactly, and this same form of spurious argument came up in an hn post yesterday about cavity prevention, centering on an argument that a new advance in cavity treatment "cannot guarantee" to end cavities forever. [0]
I feel as though I've never been fooled by these arguments, although surely I have different types of weaknesses that are unique to me. But it seems to stand out as a form of argument that somehow has persuasive power among intelligent types whom I would never expect to fall for other forms of obviously fallacious arguments.
It's entirely appropriate to pursue a defense in depth strategy while questioning any particular layer.
Crowdsource making tracking useless?
How is a timestamped chain of communication between persons interested in a particular topic "garbage"?
How applicable do people think this information is now 9-10 years later?
DEF CON 22 - Adrian Crenshaw- Dropping Docs on Darknets: How People Got Caught https://www.youtube.com/watch?v=eQ2OZKitRwc
Not that I think the Fed's would blow their cover to hunt down people buying drugs but still seems stupid to trust.
If “deanonymize” strictly means perform a timing attack using info you have from the beginning and end of the circuit, then by definition you’re correct.
But if you visit an identifying set of websites and/or ignore TLS errors or … they can still deanonymize you.
Ignoring TLS errors might mean you’re ignoring the fact your exit relay is MitM attacking you.
Edit: Never does, exit nodes are not part of the circuit, thanks to commenter below.
Completely.
Exits aren’t a part of the circuit. Ever.
The list of all relays is public knowledge by design. There’s contact information attached to relays. The big operators are known individuals and organizations. They contribute. Interact.
Which ones are actually the governments doing bad things against their citizens? It’s hard to tell? Then why do you make such claims?
Relays that observably do bad things are removed from the network all the time. Are those ones the government? Tor seemingly has a reasonable handle on the situation if that’s the case.
If the fed is doing correlation attacks, why would they run relays at all? “Just” tap the IXPs near major hubs of relays. Or heck, get data from the taps you already had. Silent and more widespread.
Pushing people away from tor potentially makes it even easier to deanonymize them, depending on the adversary model assumed.
Beyond a principled stance re communications, I can’t think of a reason to use it. If you’re planning to resist some regime that controls telecom infrastructure, the fact that you’re using it is both uncommon and notable.
I know because I work there. AMA (edit: about tor. Because people say a lot about it without actually knowing much. But now I should put my phone down so… too late!)
To protect our most sensitive communications and vulnerable communities , Tor usage should be normalized so it is common and not notable.
I got to travel to Canada, Mexico, and Europe (from the US) for tor meetings and privacy-enhancing technology conferences.
More or less every single cell that goes through the tor network today is prioritized and scheduled by the cell scheduler I wrote.
Edit: I finally found it![0] I had to go to Donate, Donation FAQ, "Can I donate my time?" , "Learn more about joining the Tor community.", and then "Relay Operations" -> "Grow the Tor network" at the bottom right. I would really hope there's a more direct path than this...
https://community.torproject.org/relay/
Thanks for considering to run a relay.
For your AMA, if you want: How's the job? What keeps you working there? How's patriotism these days?
At least for the teams I have been on and my view of leadership, there is very little political talk.
But patriotism isn’t politics… lol. The higher you get the more “hoo rah America!” is a part of the motivational speech or report or whatever. Down here in the streets it’s just another job. Pride in the country isn’t much of a driver. At least for me.
These two statements make little sense together. It was originally developed by the Navy. Okay. So why would they design it from the get-go with such a fatal flaw that would risk their own adversaries gathering "actionable intelligence" from it?
I'd like to stress if we're talking about the Navy's involvement, then you're questioning the design of the whole thing from the very beginning, not just the current implementation.
Thanks for pointing this out. Seems obvious in retrospect but I don't really recall seeing a lot of evidence for this despite seeing the claim quite commonly. That said, the use of "rarely" makes me wonder what evidence has been presented in such rare instances. Just curious. (Of course it's also fine if the phrasing was just communication style.)
The point is if you cannot assure anonymity with 100% certainty, you are simply setting people up.
i had thought the tor browser ships with noscript preinstalled.
Given that a lot of law enforcement doesn't even bother with the low hanging crimes, the chance of them prosecuting anyone using Tor is extremely low unless you get big enough or go far enough to warrant the attention.
I always assumed if you were doing things where your threat model included governments trying to kill you that Tor wouldn't be all that useful even if it was secure.
But at planetary scale would Tor scale in an environmentally friendly way?
So in many cases it's really a case of "we want a monopoly on secrecy".
Which should be a massive red flag for everyone, from left to right, from liberal to conservative, from anarchist to communist and so on. But somehow isn't picked up by any of these. I presume because they all believe somehow they either won't be targeted or will be exempt?
In most nations it's widely accept that the state has a monopoly on violence (usually through the police force), and it's not clear to me what a good alternative to that would be.
I also want my government to have a monopoly on taxation, I don't want any private company or gang to be able to just collect taxes from me, without any repercussion.
As for secrets? We probably have to distinguish a bit between secrets/data at rest vs. secrets/data in transit. I could well imagine that a good balance between security and privacy could require some tradeoffs when it comes to data in transit.
Because we all have them, need them, and because a society cannot function without them - there are many books and papers written about the "nothing to hide fallacy". We all really need some privacy. How much, is a different question, though. So in this discussion: maybe we don't need the level of "TOR by default for everyone", IDK.
But the things that do inspire confidence:
Tor is updated against vulnerabilities pre-emptively, years before the vulnerability is known to be leveraged
Tor Project happens to be investigating the attack vector of the specific tor client, which is years outdated
They should have just said “we fixed that vulnerability in 2022”
with a separate article about the old software
While it has been fixed for years it was not a case of using old software from what I am reading.
I don't want them to try to sell me something. If they were making bold claims as you suggest I would be more concerned.
There is a risk that the network is compromised at any moment and cannot be relied upon, except for your own personal risk tolerance on the activity you are interested in.
What do we want Tor for except as a hope that Russian citizens might be able to get to the BBC site?
I am asking honestly - and would prefer not to be told my own government is on the verge of a mass pogrum so we had better take precautions.
If everything is SSL secured, then we don't have to explain why any specific thing is SSL secured. The same reason can be applied to use of TOR.
Even for top level comments, HN’s algorithm for ranking is pretty useful for assigning “worth”
Ordering by score DESC only gives you relative point information, not absolute. Theres additional signal if the top comment has 100 points vs only having 3 (and the bottom post also having 100 vs 1).
"Yeah but Y Combinator made a decision that makes it harder for me to auto-generate spam."
We've come to accept (as a normal mainstream thing) end to end encryption in several popular messaging apps (which seems to be largely thanks to WhatsApp?), but the same idea applied to web browsing is still considered fringe for some reason. That distinction seems arbitrary to me, like just a cultural thing?
It might be a UX thing though. WhatsApp is pleasant. Trying to use the internet normally over Tor is horrendous (mostly thanks to Cloudflare either blocking you outright, or sending you to captcha hell).
I think everyone wants “privacy by default”, they just don’t make the connection between this hypothetical and real life. In real life you’re still spied but nobody confronts you directly.
I mean he probably could hear it, and I hope no one on HN who heard their neighbour would bring it up on the street !
We do not have secrecy. We have privacy which is merely the politeness of our neighbours (which is of course a social construct of behaviour).
The internet has given new spaces that have not yet had the time for us to learn such behaviours. What will help us is making the internet more like our daily lives. No anonymity, etc.
But people somehow think the internet should be different - it’s not and it’s better - if we think our lives should be more free then politics is the pave for that not the router.
The internet is different. There are trade offs to privacy just like the real world, but it is not physical. Encryption exists. It protects real people from real governments that feature oppressive regimes. It protects them _now_, not in some distant future where N protests, elections or uprises have toppled all government entities that abuse their power. This seems to be a lofty ideal that we should all trust each other, our governments, our isps, our web services.
I think the crucial part is choice. You are welcome to blog every wikipedia article you visit, or live stream every activity you partake in over Twitch. But this is not a requirement to use the internet.
Also a lot of people wouldn’t appreciate their neighbor talking (or even hearing) about them having sex.
Using Tor this way doesn’t anonymize me—on Facebook at least, I’m logged in under my own account—but it limits the profile Meta builds on me to the union of what it directly observes on Facebook and what it can purchase through data brokers. Ever since I started doing this, I’ve noticed a huge drop in relevance in my Facebook ads, so apparently it’s working. When the ads become suddenly relevant again (which has happened a few times), it exposes an information leak: usually a credit card purchase that Meta must have obtained from either my bank or the shop vendor and tied to my identity.
Using a VPN could theoretically provide the same benefit, but in practice Facebook tended to temporarily lock my account when using a VPN and Reddit blocks VPN traffic completely. So I stick to the onion services, which are run by the websites themselves and so are less likely to be treated as malicious traffic.
If you use these platforms, I recommend bookmarking their onion sites in Tor Browser and using it as your primary interface to them for a while. Then, if you don’t find it too inconvenient, start blocking the non‐onion versions of the sites on your network.
https://old.reddittorjg6rue252oqsxryoxengawnmo46qy4kyii5wtqn...
https://www.facebookwkhpilnemxj7asaniu7vnjjbiltxjqhye3mhbshg...
(P.S.: You shouldn’t trust the links I just posted; I could have posted fake ones! I recommend double‐checking against https://github.com/alecmuffett/real-world-onion-sites which links to proofs of onion site ownership under their usual domain names.)
Also, it's just Tor – not 'TOR'.
>Note: even though it originally came from an acronym, Tor is not spelled "TOR". Only the first letter is capitalized. In fact, we can usually spot people who haven't read any of our website (and have instead learned everything they know about Tor from news articles) by the fact that they spell it wrong.
Couldn’t a national security organization just modify a node to route traffic to other nodes it controls instead of uncontrolled nodes?
The client controls path selection, and each hop is verified using its encryption keys.
The client encrypts traffic to each node on its selected path in turn. If the traffic doesn't reach every desired node in order the traffic can't be decrypted.
Assume if the will is strong and the resources are strong you will be eventually identified. If your not worth it then your not worth it.
become not worth it
https://direct.mit.edu/books/oa-monograph/5761/TorFrom-the-D...
He got caught not by the FBI breaking Tor, but just by network analysis of university network traffic logs showing a very narrow list of on-campus people using Tor at the time the threat was communicated. He quickly confessed when interviewed.
https://www.washingtonpost.com/blogs/the-switch/files/2013/1...
Just another factor to consider when using Tor - who's network you're on.
As always there are caveats that he goes into regarding how to assert the right and all that but the major thrust is if the police want to talk to you for any reason, just don't. Lots of great stories, too.
You are under no legal obligation to assist police in their investigations. Give only the information you are legally required to (varies by state and whether it's a consensual encounter, detainment, arrest, etc.), and no more. If you're arrested say you want an attorney and you will not answer questions until they arrive.
The hidden service targeted[0] had completely ceased to exist by April 2021, so that time range makes sense.
[0]: https://www.ndr.de/fernsehen/sendungen/panorama/aktuell/Inve...
>A guard discovery attack allows attackers to determine the guard relay of a Tor client. The hidden service protocol provides an attack vector for a guard discovery attack since anyone can force an HS to construct a 3-hop circuit to a relay, and repeat this process until one of the adversary's middle relays eventually ends up chosen in a circuit. These attacks are also possible to perform against clients, by causing an application to make repeated connections to multiple unique onion services.
Some specific state actors operate TOR entry and exit routers and can perform analysis which is different to others who just have access to the infra beneath TOR and can infer things from traffic analysis somewhat differently.
I have never been in a situation where my life and liberty depended on a decision about a mechanism like TOR. I can believe it is contextually safe for some people and also believe it's a giant red flag to a lead pipe and locked room for others.
https://support.torproject.org/about/why-is-it-called-tor/
>Note: even though it originally came from an acronym, Tor is not spelled "TOR". Only the first letter is capitalized. In fact, we can usually spot people who haven't read any of our website (and have instead learned everything they know about Tor from news articles) by the fact that they spell it wrong.
...We are writing this blog post in response to an investigative news story looking into the de-anonymization of an Onion Service used by a Tor user using an old version of the long-retired application Ricochet by way of a targeted law-enforcement attack.
...From the limited information The Tor Project has, we believe that one user of the long-retired application Ricochet was fully de-anonymized through a guard discovery attack. This was possible, at the time, because the user was using a version of the software that neither had Vanguards-lite, nor the vanguards addon, which were introduced to protect users from this type of attack. This protection exists in Ricochet-Refresh, a maintained fork of the long-retired project Ricochet, since version 3.0.12 released in June of 2022.
So my answer to your sincere question: no reason to believe it is safe, no.
Tor's development team aren't on the payroll of the US gov't, and their funding comes from many sources.
If having received funding from a government agency is enough to earn your distrust, you'd quickly become a paranoid schizophrenic.
That's not serious. From the Tor official blog:
> U.S. Government (53.5% of total revenue)
> Individual Donations (28.5% of total revenue)
> Non-U.S. Governments (7.5% of total revenue)
> Foundations (6.4% of total revenue)
> Corporations (3.4% of total revenue)
> Other (0.6% of total revenue)
https://blog.torproject.org/transparency-openness-and-our-20...
(Funnily, Signal also received major funding from US government sources but very few people seem to question that when lauding Signal.)
And I cannot name an organization I would trust to tell me the truth if doing so will jeopardize its funding.
No, don't be silly, that's ridiculous! It was the Navy.
(This has been a partial repost of a comment written four years ago: <https://news.ycombinator.com/item?id=23572778>)
If you are an enemy of the United States you probably aren’t but that’s a high bar
But there is also an element of resources. Even if you're sowing distrust in, say, the Comorian government, I don't think they have the resources to go after you unless you are truly destabilizing and not just annoying.
I will be waiting patiently for people to admit that they do very illegal things over Tor.
The Guardian: https://www.guardian2zotagl6tmjucg3lrhxdk4dw3lhbqnkvvkywawy3...
New York Times: https://www.nytimesn7cgmftshazwhfgzm37qxb44r64ytbb2dj3x62d2l...
BBC: https://www.bbcweb3hytmzhn5d532owbu6oqadra5z3ar726vq5kgwwn6a...
The fact that adversaries need to rely on zero-days, or people running massively outdated and unsupported software, strongly suggests the network is safe and robust.
No.
If anyone tries to convince you Tor is not safe, ask yourself: cui bono?
After the core team disbanded there was a full security audit which uncovered some very minor issues.
People never really trusted Veracrypt though. Quite interesting how that turned out.
Can you expand on this? It was my understanding that Veracrypt is the new de-facto standard.
Veracrypt is a curiousity, not beloved the way truecrypt was.
I’d love to see hard numbers for this, just my outside impression.
In fact, when trying to find old forums that I was part of during that era, I failed; and found only this: https://discuss.privacyguides.net/t/why-people-still-believe...
I was stating facts about the ecosystem. People didn't trust it at the time.
I never said there was a definite reason for that distrust.
Where modern research effort goes is into protecting against "they HAD your physical machine and they gave it back to you" or "they got your machine while it was on/running" - these are much more difficult problems to solve, and are where TEE, TPM, Secure Boot, memory encryption, DMA hardening, etc. come into play.
In fact it's pretty much the only difference between Home and Professional editions of Windows these days, so I'd price it as the difference between the two (about $60).
At the time I was talking about, Bitlocker drive encryption on Windows 7 required either Enterprise or Ultimate, and for a 2-5 person office with no domain and a couple laptops they wanted encrypted outside the office Truecrypt was a perfectly viable option.
The only thing I see is seeing which IP addresses are using Tor, when, and how much traffic exchanged, but mostly it will be a bunch of reused residential IPs? If you know who you are looking for anyway better to work with their ISP?
With the exit nodes, you know which IP addresses are being looked up. You might get an exit node IP when investigating a crime say. Raid that person, but can you find anything more?
This isn't an argument, but a question.
https://www.schneier.com/blog/archives/2013/10/how_the_nsa_a... https://blog.torproject.org/yes-we-know-about-guardian-artic...
You might be thinking of DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT).
There's also DNSCurve.
From what I remember, only DoT uses ECH
https://media.ccc.de/v/chaoscolloquium-1-dns-privacy-securit...
You can easily test this: dig @8.8.8.8 https pq.cloudflareresearch.com
Cloudflare is a US-based company that does MITM attacks on all traffic of the websites that it protects. It's part of how their DDoS mitigation works.
Many people still use large US-based mail providers such as Outlook or Gmail.
Many large services use AWS, GCP or Azure. Perhaps there are ways for the NSA to access customers' virtual storage or MITM attack traffic between app backends and the load balancer where TLS is not used.
Of course, in principle, a cloud provider could tap in anywhere you're using their services – ELB (load balancer), S3, etc. I presume they could even provide backdoors into EC2 instances if they were willing to take the reputational risk. But even if you assume the NSA or whoever is able to tap into internal network links within a data center, that alone wouldn't necessarily accomplish much (depending on the target).
There's also significant aggregation of traffic at handfuls of service providers amongst service categories, all generally HTTP(s) type services too ... Mail, CDN, Video, Voice, Chat, Social, etc. Each of these are still likely to employ Load Balancing & WAF.
Most WAF/Load Balancing providers have documentation about when/where to perform decrypt in your architecture.
How many Cloudflare sites are just using the Cloudflare wildcard cert?
From there, plenty of 3 letter agency space to start whiteboarding how they might continue to evolve their attack chain.
A nationwide invisible firewall, with man in the middle decryption and permanent storage of all unencrypted data. All run by the major backbones and ISPs.
How would that work?
In a way it is the perfect solution from a Govt perspective. Other countries have systems at this scale and larger. China for example.
Safer or unsafer than ISP or VPN, is the question.
(I presume safe means private here)
https://www.urbandictionary.com/define.php?term=scare+quotes
this is a helpful answer, downvoting it would be extremely bad form
There definitely are legit use cases for it and in an ideal world, I think all traffic should go over onion routing by default to protect them.
But in reality today besides a handful of idealists (like me some years ago), and legitimate users, like protestors under oppressive regimes - I would assume the biggest group with a concrete interest to hide would be indeed pedophiles and other dark net members and therefore use it.
Tor is a privacy tool. Much of what we do in our lives is on the internet, and privacy is important. Tor helps people enjoy privacy in a medium that they are increasingly dependant on.
The regular internet aka clearnet has far more malicious activity and traffic.
I have no data, just assumptions.
Immoral is as subjective as it gets and is therefore an awful yardstick.
Does Tor Browser Bundle currently ship with Ublock Origin installed and on by default?
I'm concerned with what let's call Gorhill's Web-- that is, the experience glued together by gorhill's Ublock Origin that is viewed by the vast majority of HN commenters on a day to day basis.
What you're describing is the Web-based Wasteland that is experienced by the vast majority of non-technical users who view the web without an ad blocker.
Encouraging Wasteland users to use TBB may well be an overall improvement for them. But there are more and more popular parts of the web that are practically unusable without an ad blocker-- e.g., fake download buttons, myriad other ad-based shenanigans, multiple ads squeezed into short pieces youtube content that ruins the music, etc. And there's an older segment of the population who at I cannot in good conscience move away from Gorhill's Web.
If Tor uptake somehow spikes to the point that some services can no longer get away with discriminating against exit nodes, then great! But in the meantime, I and many others have solid reasons for encouraging more and more Ublock Origin use among a wide variety of users.
And as you point out, there are technical reasons why the ad blocker lists are at odds with TBB design goals. Thus, I find the top poster's "cui bono" comment low effort and unhelpful.
Edit: clarification
It could be for insidious reasons, or because the speaker legitimately believes it. "If anyone tries to convince you you shouldn't use Rot13 as an encryption scheme, ask yourself- cui bono?" Silly example, but the point is, just about *everything* could be explained equally by either evil lies or honest warnings.
You look for the person who will benefit, and uhh...uhh you know, uhh, you know, you'll uhh, uhh. Well, you know what I'm trying to say.
- VI Lenin
Use Tor with extreme caution.
Source? People repeat this claim and nobody every provides evidence.
Sometimes I wonder wtf y'all are doing with such crazy security expectations and paranoia.
The ability to maintain privacy and anonymity is not for today, it's for tomorrow.
Really it's a good thing that the "global adversary" is - almost certainly - keeping tabs on Tor traffic and tracking down who is responsible for the worst abuses within this network.
Why, in your view, is this akin to Stalinism? It's just standard police work adapted for modern technologies, not an indication of totalitarian governance.
There was a gentleman named Edward Snowden who worked at a law enforcement agency called the National Security Agency, or the NSA for short. They operate in the United States of America.
The United States of America is a democracy, and has an agreed upon system in which the populace has a say about the rules their society must follow. These are called laws. American people and institutions are expected to follow these laws.
Pc is referencing the leader of a regime called the USSR. The USSR did not practice democracy, and it's agencies did not have to abide by the laws of the USSR.
The reason American law enforcement agencies are being compared to Stalinist (USSR) ones is because the aforementioned gentlemen Edward Snowden proved that, not unlike the USSR, American LEAs do not follow their countries laws either.
Does that make sense? I'm happy to clarify further, knowledge is power and I seek to empower those around me (y)
It's unfortunate that many people, such as yourself, have been taken in by his story and don't see the bigger picture.
Also, gathering metadata on Tor usage to break anonymity is not actually against any law. It'll be done within the legal framework that permits collection and analysis of intelligence data.
2. Tor allows reception of unsolicited TCP/IPv4 traffic if you are behind a NAT you can't open ports for, because your connection to the network is initiated on your side. This is nice, especially with increasing prevalence of CGNAT.
3. Something my niece stated when I talked to her about it, who I disagree with: Many countries have a notion of upstanding citizen enforced by well funded and maintained violence-monopoly actors (R) that are not equivalent to what the majority of citizens actually do (S). R minus S is T - the tolerance gap. Things that allow T to exist include lack of will to prosecute, general social acceptance of things that were not acceptable years ago, etc. All things that are quite mutable. If your activities fall into T, privacy-enforcement tech benefits you if R and S might change in the future.
FWIW I am firmly in the "if you have nothing to hide you have nothing to fear" camp and I looked at her funny when she said this. Maybe she is a criminal or just crazy, idk.
Really?
End-to-end encryption technologies (of which TOR is one) help prevent entire categories of attacks which would otherwise be available to all of those groups, to use against you and others.