Deploying Tor Relays
blog.mozilla.org
blog.mozilla.org
Even under that assumption, what is the FBI's motivation for doing this supposed to be? They can obviously only do this for Tor nodes within their jurisdiction, but that's where they want them to be because it's easier to capture their traffic. It's not like exit node operators have any actual connection to the crimes the government may be investigating. The main thrust of the other Tor article on the front page[1] is that the primary source of criminality on Tor is hidden services that don't use exit nodes.
Do you think Amazon gets raided? Do you know how many exit nodes are in AWS? My guess is lots because I know 2 people who have them and I don't know a lot of people.
... in someone else's data center.
Never, ever in your own home. If you are raided ALL your computers and ancillaries will be seized.
And the criticism of anecdotal evidence is that it may not be a representative sample. So what is the actual percentage of Tor exit node operators who have been incarcerated for it in the US then? Is it not 0%?
fbi will probably send one agent to pick up the server in the data center, and 20 others will be picking you up at your credit card billing address.
It's also worth noting that there are a large set of tips and guidelines to follow for exit relay operators: https://trac.torproject.org/projects/tor/wiki//doc/TorExitGu...
Did you hear of Lavabit?
Do you know they can force Amazon to handle access to all your running instances and you simple will never be informed?
https://www.torproject.org/eff/tor-legal-faq.html.en
which was written by my colleagues at EFF. (It doesn't mention particular legal theories that may help exit node operators, though I think CDA §230 and DMCA §512 might be among the laws you're thinking of that have historically protected ISPs, since ISPs have resisted being classified as common carriers in the U.S.)
"Should I run an exit relay from my home?
No. If law enforcement becomes interested in traffic from your exit relay, it's possible that officers will seize your computer. For that reason, it's best not to run your exit relay in your home or using your home Internet connection."
For example, an Austrian man was arrested in 2011 for running an exit node and charged with being an accomplice to crimes that were carried out over Tor using his exit node. He was ultimately found not guilty, but a law was passed as a result that effectively makes it illegal to run a Tor exit in Austria. [0]
Meanwhile, in the US no one has ever been arrested simply for running a Tor exit node (at least to my knowledge). Anecdotal information suggests that the most difficult thing is finding someone to host the node (many cloud VPS providers, for example, will not) if you don't host it yourself. A Reddit commentator and operator of Tor exits suggests that running Tor exits is protected under U.S. law, although I'm not sure if this has been tested in court [1].
I think Mozilla should take the (relatively small, due to their presence in the U.S.) risk of running Tor exit nodes. They could even turn it into a project of its own, to explore the common problems and develop some best practices for running Tor exits. I could imagine this being a fruitful collaboration with the EFF, for example!
[0] https://www.techdirt.com/articles/20140701/18013327753/tor-n... [1] http://www.reddit.com/r/IAmA/comments/20243q/iaman_operator_...
"Charging a corporation, however, does not mean that individual directors, officers, employees, or shareholders should not also be charged. Prosecution of a corporation is not a substitute for the prosecution of criminally culpable individuals within or without the corporation"
from http://www.justice.gov/criminal/fraud/documents/reports/1999...
on the other hand it may be a good feature if implemented correctly. for example, sites explicitly saying they allow tor exit connections would be a good start.
„You can host 20 TB child porn with us on some encrypted hdds“
The judge argues that this is more than just providing infrastructure, it is advertising illegal content / behavior. So this case is not representative for evaluating the risk of running a tor exit node.
http://futurezone.at/netzpolitik/strafe-fuer-tor-betreiber-g...
If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project.
Is Mozilla planning to set up a hidden service for mozilla.org? I didn't see anything mentioned. The more sites that support hidden services, the less need for exit nodes (which are arguably one of the least secure parts of Tor.)
I run three relays right now. I agree that it's pretty easy to setup, especially on Ubuntu, but the documentation could really use improvement. It makes it sound much harder to setup than it actually is.
To anyone who is thinking of running a relay, here are the basic steps:
1. Add the Tor repo to your package manager [1]
2. Install Tor
3. Edit the config file to set a name, your contact info, bandwidth limit, and exit policy. This is all pretty well documented in the config file.
4. Start Tor (eg `sudo service tor start`)
If you want to run an exit node you should read the Tor docs about the topic and decide which ports to open.[2][3]
1: https://www.torproject.org/download/download-unix.html.en
2: https://trac.torproject.org/projects/tor/wiki//doc/TorExitGu...
3: https://blog.torproject.org/blog/tips-running-exit-node-mini...
I also quite like Tor Arm if you are running a relay, for an nice eye-candy dashboard: https://www.torproject.org/projects/arm.html.en
Also, keep in mind that relay IPs, and perhaps even subnets, may show up on various blacklists. Other services (perhaps those of other hosting customers) may be affected.
Have you got an example of that? I know a few relays intimately and I've never seen this.
Edit: Here's one example, posted by Zack Weinberg on the tor-relays list.[0]
CMU network operations has decided to move the Tor exit node that my
group operates (tor-exit.cylab.cmu.edu) to an isolated subnet in order
to minimize consequences for the rest of the campus network. For
instance, apparently there have been several cases where third parties
blacklisted the entire CMU IP space in response to malicious traffic
from the exit node. This is currently scheduled to happen Tuesday (Nov.
4). The new IP address will be 204.194.29.4.
[0] https://lists.torproject.org/pipermail/tor-relays/2014-Novem...I've seen a few references to these supposed problems with running a relay nodes lately, but the poster never replies with any information where this have actually happened. This behaviour is new. It wouldn't surprise me if it's coordinated, considering what else we've seen lately.
However, it's my impression that there is a surplus of entry and middle nodes, and a serious shortage of exit nodes, especially fast ones. Also, I've read that the geographic diversity of exit nodes is inadequate. I base these comments on discussions on the tor-talk and tor-relays lists, and from posts on the Tor Project blog.
TorServers.net has also been mentioned already.
kudos to mozilla for getting involved!
Also all of this is from memory, but I hope none of it is wrong. Feel free to correct me if so.
In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...
It seems easier than the alternative of selling the hardware on ebay.
Obviously apples and oranges, but between this and Facebook's Tor Hidden Service we're starting to see adoption of real privacy tools among major companies.
> privacy
My point was that a Tor Hidden Service provides anonymity to users in countries whose _links_ to Facebook's servers are policed.
It appears content was also censored at the request of the Saudi government.
Facebook really wants your activity to be based on your real identity, and making associations between you and other people.
Facebook shouldn't be used as a tool for organizing political rallies if there is concern for privacy. Connecting to FB via Tor does not isolate you from much.
Can't be avoided these days.
> The Internet is a global public resource that must remain open and accessible.
> Individuals’ security and privacy on the Internet are fundamental and must not be treated as optional.
> We will [...] use the Mozilla assets (intellectual property such as copyrights and trademarks, infrastructure, funds, and reputation) to keep the Internet an open platform [and] promote the Mozilla Manifesto principles in public discourse and within the Internet industry.
[1]: https://blog.mozilla.org/blog/2012/01/17/mozilla-to-join-tom...
[2]: http://arstechnica.com/tech-policy/2014/05/mozilla-offers-fc...
[3]: http://www.cnet.com/news/growing-pressure-in-congress-to-fix...
So it's like, they don't just represent themselves anymore, and an arrest will be a political tool to smash everything into corporate/government control.