Tor calls for help as its supply of bridges falters
arstechnica.com
arstechnica.com
What are the risks involved in doing this? Both in regards to legal responsibility for traffic, and Amazon ToS.
It's safe to be an entrance into the network, but it can be dangerous to be the exit, as you sometimes get blamed for the traffic.
If you run an exit node on Amazon, you can expect to receive a C&D at some point. I'm not sure if Amazon will intervene. There are some services elsewhere that allow you to pay for the operation of exit nodes in bitcoin.
Tor is essentially just 2 proxies chained together such that the first proxy (the entry node) doesn't know the final destination, the second one (the exit node) doesn't know the source, and the final destination only knows the exit node. If a malicious entity is operating either entry or exit nodes, it still protects your identity as long as you did not expect the exit node to send information that leaks information about yourself. If the same malicious entity or cooperating ones get lucky and operate all of your nodes, then you are unmasked. If you are afraid of this possibility, then you can configure your client to make a circuit of more than 2 nodes.
In order to find out about all of the available public nodes that you can connect to, the client queries a list of hardwired directory servers. Here, you can get this yourself: http://86.59.21.38/tor/status-vote/current/consensus
If you run a public server, your information will be distributed in this list. You can also run a private bridge, which is not shared publicly. You will not be used as an exit node unless you configure your server to allow exit traffic. You can specify this by port ranges, so as to only allow certain traffic. You can see this in the above consensus document in lines that start with "p". "p reject 1-65535" means it is not an exit node.
If you want to help in other ways, you can also run a directory cache that serves consensus information (as in the above link).
I believe this is the default on Ubuntu:
ExitPolicy reject <asterisk>:<asterisk>
(it seems HN filters out the literal asterisks in the above context, so replace <asterisk> with *)
Thanks for the clarification.
https://svn.torproject.org/svn/projects/design-paper/tor-des...
It helps to simplify when explaining to others.
Like I say, I know it is off topic but I can't find anything conclusive to how risky it is?
I want to see what is on there but at the same time I hear of hackers at every corner and child porn. I don't want to encounter either ever.
Is there a safe way of browsing it whilst taking a casual look around?
Risk and safety is hard to talk about, mostly because its hard to quantify it. I could say that the hacker risk is as risky as visiting a private hosted word press blog, through I suspect more blogs has viruses on them that tor pages has.
As for seeing child porn, so long you don't go looking for it, I suspect the risk is low. Any site that allows users to upload images (like forums) or video without pre-reviewing it could have such images. To be sure, turn of images in your browser when visiting such sites.
I don't think I want to know to be honest, there's enough crap after page 2 on Google as it is
- You use the onion url of a page: You will probably not encounter anything you do not want to see (depending on the source of the link).
- You use one of the hidden service search engines. These are NOT provided by TOR but by TOR users, i.e. they are TORs Google/Yahoo (especially old time yahoo with long lists of pages instead of a search). Here the risk is significantly higher: Most of these link lists/search engines have a strict "no censoring" policy, so you will at least risk to get links to such things. I've never had this problem (and I am grateful for that) but the risk exists.
Due to the bandwidth issues, most sites are not going to serve images unless they are a media site of some sort. If you don't want to see animal porn on the WWW, how on earth do you keep your virgin eyes safe? You don't seek it out.
You don't use your own browser for Tor, you use the Tor Browser, unless you're trying not to protect yourself.
The Tor exit node that happens to handle any particular request gets to read the relevant traffic (since it is handling the request to the actual end server on your behalf). So, for instance, if you're logging into some bulletin board via unencrypted http, the Tor exit node handling the login request gets to see your username and password on that bulletin board in cleartext (as can all the other net infrastructure between that exit node and the bboard itself).
In one sense, this doesn't change your risk profile; if you're logging in over unencrypted http directly, you're also at risk of sniffing. However, the risk may be enhanced with Tor; there are persistent rumors of law enforcement and intelligence agencies (and others with darker-colored hats) running exit nodes which deliberately sniff the traffic they're proxying to see if something interesting comes up. It also might be possible for such a hostile exit node to mess with the content of unencrypted traffic, though I've personally heard no rumors of that.
Note that if you're using Tor to proxy encrypted traffic (https), the exit node sees only the encrypted data stream, which is as secure as the encryption you're using --- and the official Tor browser bundle includes the "HTTPS everywhere" Firefox plugin to try to get you to use HTTPS where available.
Additionally, if you're using Tor, anyone monitoring the net segments between you and the entry nodes you hit may be able to tell that you're using it (though they won't be able to tell what you're using it for). If the local secret (or other) police frown on that sort of thing in principle, it could be trouble.
Certainly in the UK, Europe general and probably in the US, your ISP retains a list of all the IP addresses you connect to, and they supply this to the government if they have national security grounds.
At least in the UK, security clearance is grounds to pull your internet records, they say so on public government websites.
I think that in future, if your household connects to known TOR bridge nodes, that might well impact if you can do government work, from IT at your local tax office to army work.
Probably paranoia, but I'm staying away from TOR for this reason. Which is a shame because what some ad networks do is really, really creepy.
And sponsor a node. They are based in SF and accept BTC.
They list their exit node servers here: http://www.torservers.net/exits.html
I'm interested, but still trying to learn more. In particular, are there ways to limit the traffic or prioritize other packets?
(Select Obfs3)
# Start Tor as a bridge.
# Run obfsproxy
# Never send or receive more than 10GB of data per week.
# Running a bridge relay just passes data to and from the Tor network. so it shouldn't expose the operator to abuse complaints.
Sorry. They need to make it way easier to get involved.
Instructions on setting up a service on OpenSuse at http://www.acooke.org/cute/StartingTO0.html (anyone know how to make systemd switch to a different user?)
If TOR wants widespread support, they need to create a simple tutorial with a FAQ that covers all the basic problems when you do a one-click install on Windows. If malware can be written to be easily installed and configured, then it shouldn't throw errors when you do a basic install using their Windows package that you need to Google and diagnose. If a software developer gets pissed off at their installers, what will average users think?
No one needs that, hence the supply is low.
Edit: http://arstechnica.com/tech-policy/2012/11/tor-operator-char...
+-----+
| You |
+-----+
\ <= encrypted _
+----------------+ | T
| Tor Entry Node | | O
+----------------+ | R
\ <= encrypted |
+------------------------+ | N
| Tor Bridge/Relay Nodes | | E
+------------------------+ | T
\ <= encrypted | W
+---------------+ | O
| Tor Exit Node | | R
+---------------+ _| K
unencrypted => \
+----------+
| Internet |
+----------+
The exit node is the only one that the wider Internet sees. All other traffic within the network is encrypted.