Tor Challenge
eff.org
eff.org
We will be presenting our research at the HotPETS privacy workshop in Amsterdam in July [1]. Here's a link to the paper if you're interested (I'm Miles). [2] Keep in mind it's an early draft.
[1] http://petsymposium.org/2014/hotpets.php
[2] https://docs.google.com/file/d/0B7r4osQgWVqKTHdxTlowUVpsVmJR...
My email is in the paper, but it's miles.richardson@yale.edu
This will be a challenge: the number of people willing and able to run TOR relays is quite small, and the subcategory of those interested in a (new) cryptocurrency is even smaller.
Reaching critical mass for the currency to be interesting is going to be hard.
Try looking at it from the miners' perspective. The pitch isn't "buy our coin, and use this guide to help yourself install the dependencies needed to run our beta software." Instead, its "get paid coins, all you have to do is leave the relayCoin bandwidth-miner running while you sleep."
In the future, proof-of-bandwidth / proof-of-relay "coin" incentives on next-gen layer 3 protocols will bootstrap the transition to a global, p2p wireless mesh network (wireless at the edges and sparse areas, the big pipes and backhauls will still be fiber). It will look something like "leave this wifiMeshCoin nodeBox attached to your cable modem. It will open an unlocked wifi hotspot for anyone nearby. some people will get free access through a metered guest connection, and you might earn a little coin. But if you get lucky and your nodeBox can form a bridge connection to somebody else's nodeBox at a different ISP, that bridge relay will earn a lot of coin. Another option is to invest $2k to get a 4G/5G cellular micro-tower from NextGen Labs, one of those could earn you $500/mo in relayPower if there are enough unlocked CDMA phones in your area. You can resell the unlocked phones as well."
It's still going to be a challenge, but that makes a more manageable one :)
Tor really needs some more relays. With this it could be more interesting to companies as a business model.
One thing I could be worried about is abuse - could a scriptkiddie deploy a botnet and earn TorCoins with this, like it's done with bitcoin miners (although not that effective any more).
With Bitcoin and others, we've seen malware created that turns compromised PCs and devices (routers, DVRs, etc.) into "zombie miners". If this becomes popular, I can certainly envision malware that instead turns these compromised devices into "zombie relays" in an attempt to benefit $hacker. Have you considered this (I'm sure you probably thought about it at some point) and/or do you have any ideas of ways to discourage (or punish) that behavior?
I am all about having more Tor relays out there but, well, legitimate ones.
How important is it to discourage a specific kind of zombie, rather than the infection itself?
So, transferring data among each other wouldn't get them any coin from outside their own circle...
I would however add a little spice to the incentive by having some kind of raffle on top of the t-shirt and sticker, just to get some more traction.
"Run a tor relay for a year, your chance to get a free free laptop!"
I understand many people would enter the raffle just for the laptop, but if they do run their TOR relay for a year to get it, what's the problem?
Of course, it might not be well perceived or even legal in some jurisdictions.
EDIT: This being the EFF, making the winning laptop a Gluglug would make so much sense it hurts. Then you could say "free free" laptop, too :) https://www.fsf.org/news/gluglug-x60-laptop-now-certified-to...
EDIT2: Typoes. Duh!
The FSF is also a "supporter" of this project so the Gluglug X60 would be very fitting as a "grand prize". I first joined both the FSF and the EFF about a decade ago and I would be quite happy to have my membership dollars going towards something like that. Hell, if EFF/FSF/Tor did a fundraiser just for something like this, I would throw in some money specifically earmarked for the purchase of these prizes.
Side note: anyone know where I can get one of those Tor stickers? :-)
[1]: https://blog.torproject.org/blog/trip-report-tor-trainings-d...
See also these two independent reports, one written, one an audio recording of a presentation, by a Dutch activist I happened across:
- http://raided4tor.cryto.net/ [text]
- https://archive.org/details/OHM2013-Partyvan [audio]
EDIT: To sum up, the activist advises that activism is not something to be taken lightly, and there is a real cost to being targeted by law enforcement. I know relays are different to exits, but it's not encouraging when you want to assist!
Also, Dutch police has never actually raided a private domicile where there was an exit relay.
One advantage to running an exit relay from your home is that there is a lot of garbage traffic coming from your address, which I really like because it hides me a little bit more.
Last time I looked at the tor documentation (maybe half a year ago?) there seemed to be no way to run an IPv6-only tor node.
Has that changed? Is IPv6 support being worked on?
> There is currently no way of running an IPv6 only relay
which makes it unusable for my application.
Tor has some sane defaults, so you don't need to edit much. I've started running a relay (no exit) node for the challenge, and this is what I'm using:
ORPort 9001
Nickname RelayName
RelayBandwidthRate 6000 KB
RelayBandwidthBurst 10000 KB
AccountingMax 500 GB
AccountingStart month 1 00:00
ExitPolicy reject *:*
RelayBandWidthRate and Burst control how much bandwidth the tor daemon is allowed to use (average and burst obviously), AccountingMax is how much bandwidth the daemon is allowed to use over a given period, and AccountingStart definite that period (in my config a period is a month, and it start at midnight of the first day).Also, once you start it, give it an hour or so to appear in the tor swarm. As long as you have "Self-testing indicates your ORPort is reachable from the outside. Excellent. Publishing server descriptor." in your logs, you should be fine and only have to wait.
Please consider the following... It's better for the Tor network to don't have a limit on the bandwidth and let the relay just hibernate when it reachs the 500 GB. If you are able to do this, please give it a try.
Again, thank you!
As they say, flawed crypto is worse than no crypto at all.
Perhaps someone should start a fundraiser for an audit of Tor. I would certainly toss a few dollars into the jar for that myself and I suspect sufficient funds could be raised pretty easily.
The point is not that Tor relays are anonymous, but the traffic going through the Tor network is anonymized by bouncing between relays.
Anybody run the numbers (and are there legal repercussions?) on the cost of running a relay at 1MB/s on AWS for a year?
>The Tor Cloud images have been configured to use no more than 40 GB of bandwidth out per month. We have estimated that customers who do not qualify for the free usage tier will pay up to $20 a month for an instance located in us-east-1 (Virginia).
>Customers who qualify for the free usage tier, but who run bridges that use more than 15 GB of bandwidth out per month, will pay up to $3 per month for an instance located in us-east-1 (Virginia).
Nickname whateveryouwant ORPort 9001 BandwidthRate 200 KB BandwidthBurst 500 KB ExitPolicy reject :
Just make sure port 9001 allows TCP traffic in, and is forwarded from whatever world facing device you have.
You can also get the TOR software bundle for Mac: https://www.torproject.org/download/download-easy.html.en#ma...
That includes vidalia, which is a configuration utility that lets you run a relay. It supports UPnP, so you can avoid even needing to port forward with a supported router.
Are you taking part in ResetTheNet? Here's the original thread on the topic: https://news.ycombinator.com/item?id=7399298
AFAIK I couldn't do this with TOR, my ISP don't allow it.
Honeypot. Potentially inadvertent honeypot, but honeypot.
(AFAIK it was originally deployed by USA as a way to secure their field agents comms. )
There's no problem, really. The points you mention arise when you run an 'exit node'.
The challenge FAQ [1] even has two points addressing this:
> Is it a good idea to let others know that I'm running an exit relay? Yes. Be as transparent as possible about the fact that you're running an exit relay...
> Should I tell my ISP that I'm running an exit relay? Yes. Make sure you have a Tor-friendly ISP that knows you're running an exit relay...
You're varying the "if you've got nothing to hide" argument. You would want to be secretive because spy agencies quite definitely ARE interested in who's running nodes, as if they know who runs the nodes, and where they are, shutting the thing down becomes possible.
This is how they think. Strategic opportunity. Not what they can do with the data today, but what they could use it for tomorrow. What opportunities they might lose if they didn't have it.
This is therefore how you need to think too, and why I think that volunteering this information is a bad idea.
The reason for publicizing that you’re running a relay is that it reduces the probability of being falsely accused of doing illegal things that someone else was using your exit relay for, and it makes it easier for you to recover any confiscated computers. If you publicize your running of a relay in advance, then the prosecutor might see that fact and not bother prosecuting you, knowing that you were not the origin of the illegal traffic.