1) It's highly possible that there are federal government agencies with knowledge of encryption and security beyond the current state of the art in academia. There could be deliberate vulnerabilities that even the most highly regarded researchers/academics in the field could not detect.
2) Even if you trust the source, the source can be compromised elsewhere in the toolchain (the compiler could turn safe code into malicious code). Unless you trust every element of your toolchain, you trust nothing (from a mathematical sense -- of course it's much more complicated, and thus less likely, to compromise Tor through its own source code rather than gcc's source code).
That's true, but Tor uses encryption that is common in many other products. Even if it were a privately owned product, it probably would have been implemented in a very similar way.
> Even if you trust the source, the source can be compromised elsewhere in the toolchain (the compiler could turn safe code into malicious code). Unless you trust every element of your toolchain, you trust nothing (from a mathematical sense -- of course it's much more complicated, and thus less likely, to compromise Tor through its own source code rather than gcc's source code).
OP is not talking about whether or not perfect security is possible. They are talking about the possibility of Tor specifically being backdoored, since it originated within and is funded by the U.S. government.
While I agree toolchain compromises are a concern, this particularly famous one of backdooring a compiler has a counter: http://www.dwheeler.com/trusting-trust/
How many users are downloading and compiling source? If you're running a binary you didn't compile, it's really no different than being closed source. (Unless you get the MD5 sig from an independent, trusted third party, and verify yourself)
a). For all the bundles, they are signed by the Tor developer who packages them. The signatures are clearly visible with the downloads.
b). Most importantly:
Tor is moving towards deterministic builds: https://blog.torproject.org/blog/deterministic-builds-part-o...
Different people build the Tor Browser Bundles on Gitian (look it up), and they will have the same hashes. So unless ALL of these people are lying, if their hashes match, you can be convinced that it is the same binary as you would get by compiling it.
That writeup is really fucking cool. You should submit it as its own story!
It goes back to the design of DES - the NSA influenced small design changes in the SBoxes that had implications that only they understood. This gave an advantage, even though the algorithms were completely "open source".
http://en.wikipedia.org/wiki/Data_Encryption_Standard#NSA.27...
In that case, they made the encryption STRONGER. But they certainly showed how that type of influence could happen.
I don't happen to be enough of a conspiracy theorist to believe that they're messing with Tor - there are better ways, especially when a vast majority of the traffic isn't through Tor.