For example, an Austrian man was arrested in 2011 for running an exit node and charged with being an accomplice to crimes that were carried out over Tor using his exit node. He was ultimately found not guilty, but a law was passed as a result that effectively makes it illegal to run a Tor exit in Austria. [0]
Meanwhile, in the US no one has ever been arrested simply for running a Tor exit node (at least to my knowledge). Anecdotal information suggests that the most difficult thing is finding someone to host the node (many cloud VPS providers, for example, will not) if you don't host it yourself. A Reddit commentator and operator of Tor exits suggests that running Tor exits is protected under U.S. law, although I'm not sure if this has been tested in court [1].
I think Mozilla should take the (relatively small, due to their presence in the U.S.) risk of running Tor exit nodes. They could even turn it into a project of its own, to explore the common problems and develop some best practices for running Tor exits. I could imagine this being a fruitful collaboration with the EFF, for example!
[0] https://www.techdirt.com/articles/20140701/18013327753/tor-n... [1] http://www.reddit.com/r/IAmA/comments/20243q/iaman_operator_...
"Charging a corporation, however, does not mean that individual directors, officers, employees, or shareholders should not also be charged. Prosecution of a corporation is not a substitute for the prosecution of criminally culpable individuals within or without the corporation"
from http://www.justice.gov/criminal/fraud/documents/reports/1999...
on the other hand it may be a good feature if implemented correctly. for example, sites explicitly saying they allow tor exit connections would be a good start.
„You can host 20 TB child porn with us on some encrypted hdds“
The judge argues that this is more than just providing infrastructure, it is advertising illegal content / behavior. So this case is not representative for evaluating the risk of running a tor exit node.
http://futurezone.at/netzpolitik/strafe-fuer-tor-betreiber-g...
Even under that assumption, what is the FBI's motivation for doing this supposed to be? They can obviously only do this for Tor nodes within their jurisdiction, but that's where they want them to be because it's easier to capture their traffic. It's not like exit node operators have any actual connection to the crimes the government may be investigating. The main thrust of the other Tor article on the front page[1] is that the primary source of criminality on Tor is hidden services that don't use exit nodes.
Do you think Amazon gets raided? Do you know how many exit nodes are in AWS? My guess is lots because I know 2 people who have them and I don't know a lot of people.
... in someone else's data center.
Never, ever in your own home. If you are raided ALL your computers and ancillaries will be seized.
And the criticism of anecdotal evidence is that it may not be a representative sample. So what is the actual percentage of Tor exit node operators who have been incarcerated for it in the US then? Is it not 0%?
fbi will probably send one agent to pick up the server in the data center, and 20 others will be picking you up at your credit card billing address.
It's also worth noting that there are a large set of tips and guidelines to follow for exit relay operators: https://trac.torproject.org/projects/tor/wiki//doc/TorExitGu...
Did you hear of Lavabit?
Do you know they can force Amazon to handle access to all your running instances and you simple will never be informed?
https://www.torproject.org/eff/tor-legal-faq.html.en
which was written by my colleagues at EFF. (It doesn't mention particular legal theories that may help exit node operators, though I think CDA §230 and DMCA §512 might be among the laws you're thinking of that have historically protected ISPs, since ISPs have resisted being classified as common carriers in the U.S.)
"Should I run an exit relay from my home?
No. If law enforcement becomes interested in traffic from your exit relay, it's possible that officers will seize your computer. For that reason, it's best not to run your exit relay in your home or using your home Internet connection."