Torservers.net: Professional Global Tor infrastructure
mailman.stanford.edu
mailman.stanford.edu
I thought Tor was suspected of being compromised, since is was originally developed by ex-government or military types? Is this the case, is Tor actually accepted as secure and free from government interference?
Also, I vaguely remember concerns about things like child porn being handled by exit points. Were the legal or moral concerns resolved? Or are such concerns accepted as being a thin end of the censorship wedge?
This is entirely fine as far as I can tell - the U.S. interest can be explained as two-fold:
First, it could be a genuine wish to fund projects with potential to support freedom of expression in parts of the world they think need it (Secretary of State Clinton has expressed this as a policy at least once).
Second, and I think this is the more important reason, is that the various intelligence arms in the U.S. need Tor for themselves, in order to provide anonymous means of communications for secret agents and other foreign operatives who work in hostile environments. The important thing to realise is that low-latency mixnets absolutely depend on being widely used by many kinds of users for many purposes, so that each user can hide in the crowd. Therefore Tor absolutely needs to be publicly available - if American spies were its only users, they would stick out like sore thumbs and the entire thing would be hilariously pointless.
Tor is of course open source and can be inspected for backdoors and such, and its design continues to be subject to scrutiny and research. If there is a danger involved, it is an attack where the U.S. government controls sufficiently many Tor nodes in order to be able to do traffic analysis efficiently. So far I don't know of any signs of this, and I question if they would want to sabotage a project that has such a useful potential for themselves.
If so, then any government/military/intelligence concerns become irrelevant. Right?
This is a different problem than the original US Navy development.
Your threat analysis should include this fact.
Tor's security is in its design (which is free and open). And thanks to that it does not matter what the original purpose was. Everyone can run a router and thus contribute to the network.
You can find research on remaining issues in https://blog.torproject.org/category/tags/research
The fact that it's very unlikely it was created as part of some conspiracy doesn't mean that it's impossible to compromise a Tor user's anonymity. I'm not an expert but as far as I know the most credible large-scale attack against it is still the one described in this paper: http://wesscholar.wesleyan.edu/cgi/viewcontent.cgi?article=1... . To be successful, it requires controlling a very large proportion of Tor's entry and exit nodes.
Tor, compromised or not, is completely worthless against an attacker who can monitor the entire network, observe both entry and exit nodes, and correlate packets. The NSA wouldn't bother compromising nodes since they presumably already can see all the traffic and a compromised node might expose them.
But fortunately, even if what you're saying was true you're still safe! Endpoint alone can't tell much about the origin of the connection :)
The Tor client tries to take this into account when choosing entry and exit nodes, but it has to consider other threats as well and there's a limit to how well it can do. Remember the adversary only has to get lucky once to discover that you are a member of the Rebel Alliance and a traitor; you have to evade them every time.
Ross Anderson calls this "programming Satan's computer". It's like you have an NFA that always chooses the worst state transition rather than the correct one.