15 ms·
Running a Tor Exit Node for Fun and E-mails
- techsupporter 10y agoI really want to like running a Tor exit node but I'm tired of my IP address being blacklisted to hell and back "just because Tor exit node." (To say nothing of affecting my neighbors since many of those lists take out the /24 because they can't see that I only have a /27.) I don't mind dealing with e-mailed complaints but I do mind having my e-mail and other outbound connections arbitrarily blown to smithereens. His take on it is interesting since I hadn't considered putting my money proverbially where my mouth is and signing up for an inexpensive but standalone service elsewhere. I'll probably give this a whirl.
- arkadiyt 10y agoIt's pretty much the only way to do it - even running a relay node on your home network gets you blacklisted (which is frustrating since absolutely zero malicious traffic originates from your IP). In addition to the reasons you mentioned, some people have had surprise 6am home visits from law enforcement for running exit nodes (though it was heartening to read that the author has not had any bad encounters with LE).
- techsupporter 10y ago> even running a relay node on your home network gets you blacklisted Yeah, that was a fun week when I naively stood up a Tor not-an-exit relay on my home Internet connection and 40% of the Internet turned into "go away" or "enter CAPTCHA to proceed" madness. > some people have had surprise 6am home visits from law enforcement for running exit nodes Oh, right. And I even live in Seattle[0] so best not to do that. 0 - http://www.thestranger.com/slog/2016/03/30/23885710/police-go-on-fishing-expedition-search-the-home-of-seattle-privacy-activists-who-maintain-tor-network http://www.thestranger.com/slog/2016/03/30/23885710/police-g...
- DaKnOb 10y agoThere are some providers who "buy" their blacklists from other companies that specialize in that. They essentially get a list of X IP Addresses / Subnets and they blindly block them. Providers compete to generate the "largest blocklist" with "the most bad guys", and therefore end up adding any IP Address they can find. Tor has been used by criminals at least once, therefore any address related to it must be bad, right?
- pricechild 10y agoNeustar is one of those providers and they obviously don't want to talk to anyone. I'm not sure who Amazon Video uses, but they also block relays, not just exit nodes.
- sporkenfang 10y agoCDN's tend to block Tor. A lot of the Web is stood up behind one CDN or another. Cloudflare is the one that sticks out to me. But then again, a lot of people do use Tor to do stupid shit like DDoS or run C&C for botnets. So my thought is you probably ran into CDN's of various ilk, likely wasn't your ISP. For the record, a fair number of large public universities run Tor relays and exits (my lab ran four relays and an exit when I was a grad student), and they seem to be doing okay; we were kind of our "own ISP" but what that really means is you lease everything from the local ISP and get to provision a large sub-block of "their" addresses as you see fit, which in our case was Comcast. I think we had a grand total of one DMCA complaint and no other issues. But it didn't hurt we did have a law school to call on if anything went south (which it didn't).
- nbraud 10y ago> But then again, a lot of people do use Tor to do stupid shit like DDoS or run C&C for botnets. Misinformed at best: you wouldn't want to DDoS anything over Tor, because 1) the nature of the protocol means that the target receives less data than you are sending; 2) any botnet worth worrying over has much more bandwidth available than Tor's exit bandwidth. Regarding botnet C&C, the picture is more complicated but 1) there has been a very high-profile case of a botnet using Tor to hide it's C&C activities; “surprisingly”, it's very easy to spot when a significant amount of all Tor clients are bots (i.e. the anonymity set is much too small to hide the botnet); 2) those do not tend to be hosted on behind CDNs. > But it didn't hurt we did have a law school to call on if anything went south (which it didn't). That's /very/ true: I would strongly urge anybody who considers running exit nodes to do this within a framework/organization where they can get legal assistance if it is ever needed.
- chimeracoder 10y ago> even running a relay node on your home network gets you blacklisted (which is frustrating since absolutely zero malicious traffic originates from your IP) Are you sure about this? How would anybody even know if you're running a relay - those aren't published anywhere. Unless your ISP is doing DPI, in which case running a relay and being a Tor user would look the same to them.
- mook 10y agoI've seen this (running a non-exit relay), though in my experience it's been a tiny fraction of sites rather than a majority. I don't get the CAPTCHA prompts for CloudFlare (unless I'm actually browsing via tor, not just my own IP address). Sites like https://atlas.torproject.org/ https://atlas.torproject.org/ will list (exit and non-exit) relays.
- dest 10y agohttps://torstatus.blutmagie.de/ https://torstatus.blutmagie.de/
- praptak 10y agoHow are relays not published anywhere? A very basic property of onion routing is that the client chooses the relays. Even if they are not technically "published", they certainly are public.
- anc84 10y agoCorrect! The list of relays (both exit and non-exit) is public. There are several tools with web frontends available as well. There are also relays that are not publically advertised but available by special requests if someone needs a "secret" entry point to the network, they are the so-called bridges,
- throwaway12346 10y ago(Comment made from a throwaway account, because I can't be bothered with the potential for future hassle from possible employers over it) > In addition to the reasons you mentioned, some people have had surprise 6am home visits from law enforcement for running exit nodes. As someone who has had one of those surprise 6am home visits, I can attest to it being something you Do Not Want, especially from inexperienced British police officers who don't really understand what Tor is. To their credit they were incredibly professional about the whole thing, but it still resulted in every device in my home capable of storing data being seized, and six month's of social services asserting that I couldn't be alone with my then one year old son while those devices were inspected by police investigators. (And social services really weren't at all professional about the process - their representative as good as told my wife to leave me because I was almost certainly guilty). You then get the additional problem that "I'm being investigated by police because they think I'm a paedophile" isn't something you can easily talk to people about without conclusions being jumped to, and potentially making things even worse. In summary, don't run a Tor exit node from your home internet connection in the UK unless you really want to see what the inside of a police cell is like, or fancy several months of intense stress in your life. You may think this is just scaremongering, and it won't happen to you, but that was precisely the attitude that resulted in me writing this.
- Freak_NL 10y agoMan that sucks, especially the social services part. Did everything work out in the end? > […] in the UK Or anywhere else for that matter, unless you are absolutely sure about the legality of the matter and how law enforcement will respond. I am under the impression that only corporations and institutions should run Tor exit nodes.
- throwaway12346 10y agoYeah, it all worked out fine eventually, apart from me still being a little bit jumpy if someone knocks the door in the morning when I'm not expecting it.
- 10y ago
- driverdan 10y agoIt's safe to run relays at home but not exits.
- pricechild 10y agoIt depends what you mean by "safe". Various organisations will deny their services to you just for running a relay, despite the fact that no proxied traffic will exit your network and connect to them. I hope that it is incompetence, it's often unsurprisingly difficult to contact anyone who's able to deal with the issue. Amazon Video is a high profile example.
- paulddraper 10y agoHow do these various organizations know you are running a relay?
- pricechild 10y agoDue to the nature of the tor network, relays aren't a secret. They need to be public so clients can independently choose which to use. You then get people who operate lists of all relays e.g. https://www.dan.me.uk/tornodes https://www.dan.me.uk/tornodes There's probably a good reason for using a "full" list, but I can't think of one off the top of my head. That site at least offers both and just about explains the difference.
- driverdan 10y agoI've been running relays at home for over a year. The only sites I have trouble with are Monoprice and Apple Support Forums. I don't have any trouble watching Amazon videos.
- DominoTree 10y agoIt's much more fun to run an exit node and inspect the traffic using tools like the dsniff suite and Suricata. Back in the day, 90% of the traffic I would see was just people trying to brute force Hotmail accounts via POP3, but occasionally I'd sniff the credentials for an IRC-based C2 for a botnet, and I'd log in and wreck the thing.
- DaKnOb 10y agoWell, it's fun to do this and learn from that, however in an exit node it's not something I'd want to do. People use Tor to surf the web anonymously (mostly) and have some privacy. There are certainly exit nodes that do this, and it has been proven by blog posts in the past, however the more nodes that don't engage in such activities, the better for the network overall.
- nxzero 10y agoWould it be possible for Tor to detect sniffing by seeding the traffic with poison pills that ratted out anyone doing this in bulk?
- dogma1138 10y agoNot really you can always mirror the wan/uplink port and do the capture on another box so even some time based / performance analysis won't show anything.
- dkopi 10y agoPort mirroring means you can only be a passive eavesdropper. Attacks like SSL mitm wouldn't work because you actually have to intercept and modify the traffic
- dogma1138 10y agoSSL MITM still won't work unless you want it to be very noticeable or you have very substantial resources. Port mirroring is enough to capture SSL traffic and to break weak SSL keys or if you have compromised the key of the destination services (w/ some caveats like no forward secrecy etc.) And it doesn't prevents you from executing MITM attacks from upstream or just doing specific MITM attacks from within the TOR exit node later on. But overall there is nothing you can do to ensure that your TOR exit node, your VPN gateway or even your ISP isn't reading your traffic other than to use encrypted tunnels everywhere and even then you are for the most part only moving the problem upstream.
- tehlike 10y agoI wonder if there is some nonprofit where donations would go to increasing exit nodes in Tor. Sounds like a fun thing to do. i'd certainly put some, and get matching probably.
- iancarroll 10y agohttps://torservers.net https://torservers.net :)
- tehlike 10y agoVery good pointer - thanks. i will be supporting them, i was having fun with relay nodes before (and ran one for a couple weeks).
- mcherm 10y agoI don't wish to deal with the headaches involved in running a Tor exit node (despite this article's claim that the headaches are less than one might expect). I wonder if there is a way to contribute money to help those who ARE willing to invest the effort to run these nodes?
- DaKnOb 10y agoLike some other comments, you can find people who run tor relays and accept donations (TorServers being my personal choice), however, very few are willing to run exit nodes.
- nbraud 10y agoYes: a number of non-profits exist, who operate high-bandwidth Tor exit nodes. In Europe and North America, many of them partnered with the German TorServers.net: https://www.torservers.net/partners.html https://www.torservers.net/partners.html There are several reasons one might want to setup a non-profit for this: - we can pool resources (money, but also technical expertise, availability to reply to abuse mails, access to legal expertise ...); - it gives you greater (but still not great) media visibility for advocacy/outreach and running donation campaigns; - it puts you on better footing if/when contacted by law enforcement agencies; - it makes it easier to find networks that aren't heavily represented in the Tor network yet, and are willing to host exit nodes. Full disclaimer: I am on the board of directors and sysadmin team of Nos oignons [NO], a French non-profit that operates Tor exit nodes. [NO]: https://nos-oignons.net https://nos-oignons.net
- 10y ago
- Scarbutt 10y agoWhy does torproject.org make it so hard to find tor standalone?
- mintplant 10y agoBecause most users should be encouraged to just use the Tor Browser Bundle rather than, say, trying to make Tor work with their existing browser. torproject.org -> Download Tor -> View All Downloads -> [Your Platform] -> Expert Bundle
- daxelrod 10y agoThere are tons of ways that unmodified software will deanonymize you. For example, WebRTC and Flash can leak your true IP from your browser. Fingerprinting attacks are possible with lots of network-enabled software.
- setheron 10y agoIf its that cheap and the bandwidth is limited by the exit nodes, why don't we just spin up 1000 exit nodes ? I'd like to use Tor more if it was a bit speedier.
- nxzero 10y agoMakes me wonder if Tor had an automated way to spin up servers and outsource admin if more servers would be around.
- DaKnOb 10y agoWell, you can contribute, and it will only cost you about 5$ / month! Tor, by design, has some latency issues, and can also have exit node bottlenecks. I think people only run intermediate relays because of a "myth" that you'll get raided at 4 am if you run one. It has happened in the past to some operators, however, in this blog, I wanted to show that it's not always that way.
- nbraud 10y agoWell, one single person running 1000 exit nodes would be potentially armful. Same for 1000 exit nodes running on the same network. That's why it's not very practical to simply write a deployment script for some major cloud provider and let people run with it. (Also, bandwidth tends to be expensive there) However, if you mean for 1000 HN denizens to start operating their own exit nodes, then by all means go for it :) (Be aware, though, that some people can get quite obnoxious, regardless of the actual legality of running an exit node.) PS: As already mentioned in this thread, for the sake of full disclosure, I run a non-profit that runs exit nodes.
- ashitlerferad 10y agoTor relies on various kinds of diversity to protect anonymity. Your proposal probably reduces diversity in terms of sysadmin, hoster, network and jurisdiction.
- lucb1e 10y agoI interpret his message differently, namely the "we" I see as referring to the community as a whole. It's not that dirt-cheap that any individual could host 1000 servers anyway, even at only $5 a month that would be $60k a year, which I doubt many individuals are going to not care about.
- Grollicus 10y ago5€ / Month for 50MB/s? No way thats fair to the other customers..
- dx034 10y agoIf the provider accepts it for 8 months without even sending a warning, I don't see a problem.
- UVB-76 10y agoThe only reason they won't have cancelled the service is because they haven't done proper customer profitability analysis. There is absolutely no way a customer running a Tor exit node with ~50Mbps traffic 24/7 on a €4,90pm server is sustainable.
- deleted 10y ago[deleted]
- humpdinger 10y agoA lot of small providers offer truly "unmetered" bandwidth packages at low cost because for whatever reason they have contractually overprovisioned their bandwidth. They lose nothing by giving away unused bandwidth they have already paid for. Once they attract enough business to consume that bandwidth these deals go away.
- deleted 10y ago[deleted]
- hrunt 10y agoThe article keeps making reference to the types of users on the Tor network: > The majority of Tor traffic is legitimate users accessing the web anonymously, through insecure networks like Public WiFi, etc. > Finally, just like with everything else, we have malicious users. [...] That last, tiny portion of users is the primary reason people don't run more Exit Nodes. > Despite malicious users being the minority of Tor users, as an absolute number, there are many of them. Where are the facts that form the basis of these statements? I've seen studies about geographic and network demographics, and there was the disputed study about how much Tor traffic was related to child-porn, but has someone done a study on how many users are engaging in abusive behavior through Tor exit nodes? Regardless of the number of users, a better question may what percentage of the traffic is abusive? It doesn't matter if a minority of the users are abusive if the majority of the traffic is abusive. Tor administrator's tendency to dismiss abusive conducted through their exit nodes as "that's just the way it is to protect anonymity" reminds me of Twitter's early lack of action against abusive verbal attacks on its service. Tor's anonymity is analogous to Twitter's free speech, but in both cases, abuse of those freedoms defines the need for some practical protections in order to maintain them.
- ryanlol 10y agoTor really sucks for sending abusive traffic, it's slow and blacklisted by everyone (IME mostly due to problematic users, rather than "hacking" and such). Luminati for example offers a much better service, as do the hundreds of thousands of routers offering unauthenticated SSH tunneling around the world. Way better speeds, and no blacklists. > Tor's anonymity is analogous to Twitter's free speech, but in both cases, abuse of those freedoms defines the need for some practical protections in order to maintain them. This sounds worryingly like a call to weaken Tor, I really hope it's not.
- deleted 10y ago[deleted]
- fatman13gg 10y agoI remembered an article on motherboard about a guy's house raided by FBI for running an exit node. Now that article rendered a 404. Not sure if publicly claiming to run an exit node is safe.
- kiallmacinnes 10y agoSince no one else seems to have mentioned it, am I the only one who noticed this? > ... as well as tcp/179, which is used by BGP, and I wanted to avoid the exploitation of a particular vulnerability in KeyWeb ;-) That sounds... Dangerous. Did KeyWeb allow all customers to inject BGP routes? View full BGP tables? Something else?
- jayess 10y agoYou can run an exit node that only allows port 80 and 443 traffic. A lot safer and a lot less bandwidth usage. I ran a server for a couple of years and not once got a complaint.
- nbraud 10y agoThe Reduced Exit Policy goes in that direction: https://trac.torproject.org/projects/tor/wiki/doc/ReducedExitPolicy https://trac.torproject.org/projects/tor/wiki/doc/ReducedExi... It's basically a documented exit policy (i.e. the configuration stating which outbound traffic you accept to carry) that aims to minimize the potential for abuse while still allowing useful things.
- micro_softy 10y agoApologies for being stupid but this does not make sense to me: while [ true ];do ssh user@62.141.55.117; sleep 0.1; done Is this the same as writing: while test true; do ...; done Then this would also work: while [ false ]; do ...; done But if the plan is to use the keyboard e.g. INT to stop this loop, why test anything? One could just write: while :; do ...; done
- jordigh 10y ago`test` is the oldest and most portable syntax, "[" is a POSIX synonym which is either a shell built-in (e.g. in bash) or a command i.e. /usr/bin/[ . You are correct that the author seems to misunderstand what "[" and "test" do, probably by failed analogy with C syntax. In the case of "test foo" for any string "foo", "test" will be evaluating a non-empty expression which is always true.
- INTPenis 10y agoThere's always something to remark on other peoples use of bash, I often find. For example I'd rather just do while command; do sleep 0.1; done. Or simply install autossh.
- yuubi 10y agoFor a vaguely similar use case (repeat till host is up) I once wrote until ssh ...; do sleep 5; done which stops looping once a connection succeeds.
- micro_softy 10y agowhile :;do ssh ... && break; sleep 5; done
- yuubi 10y agoWhy? That reminds me of the while(1) { if (condition) break; ... } stuff I've seen too much of and can't explain, instead of just while(!condition) { ... }.
- jordigh 10y agoHasn't Tor failed to meet its goal so far? With only 900 exit nodes, it's totally feasible to block them all, which is exactly what China has done. If Tor isn't usable for hopping over the GFW, it hasn't yet fulfilled its true potential, has it?
- AgentME 10y agoHiding the fact that you're using Tor isn't one of the main goals of Tor.
- jordigh 10y ago"Tor provides a gateway to the free Internet, bypassing most mediums of censorship that may be imposed by someone, like for example oppressive regimes." People sure seem to believe that getting around censorship is one of the main goals, though.
- AgentME 10y agoTor does have private bridges into the network that you can request access to, which is their solution to this issue.
- adamfisk 10y agoIt's not a matter of hiding the fact that you're using Tor, it's a matter of whether it bypasses censors or not. There's a big difference between those two. Even if a censor is able to detect that an individual node is running Tor, that doesn't mean they can globally detect all nodes and then block them. Tor's user numbers in China in particular are very low simply because it's just straight blocked. Private bridges and pluggable transports can get around that, but they're just not used at scale because that's just too challenging for ordinary users.
- witty_username 10y agoThere are bridges that can be used to connect to the Tor network.
- 10y ago
- tmikaeld 10y agoWe where a keyweb customer for years, using it for email and crm for many clients. When we asked to add corporate VPN to make it more secure and reduce abuse, they didn't allow it in their dFlat bandwidth terms. So now they accept Tor exit nodes but not corporate VPN? Just... Wow.. Talk about priorities.
- pilif 10y ago>I was never contacted by any law enforcement agency Not yet. Good luck trying to prove to law enforcement that it wasn't you downloading child porn. And even if they believe you, the can still arrest you as accessory. See https://www.techdirt.com/articles/20140701/18013327753/tor-nodes-declared-illegal-austria.shtml https://www.techdirt.com/articles/20140701/18013327753/tor-n... No. Until judges start seeing Tor node operators as ISPs, this is way too much hassle.
- panic 10y agoIt's important to mention that that conviction was made in Austria. No one in the US has been prosecuted for running an exit node.
- mrswag 10y agoAssuming you pay for your hosting in whatevercoins and only connect to it over TOR, you aren't at risk, right?
- icebraining 10y agoIf you bought your coins in a traceable way, I wouldn't bet on that.
- nbraud 10y agoThe guy was convicted for literally saying in a public chat room “if you want to host child porn, you can do it on a Tor onion service”, IIRC. That's very much not them getting convicted for running a Tor exit node.
- mirimir 10y ago> The next, and probably last, thing is the CPU. It is not very important, but it's good to have more cores, especially for higher speed relays. As far as I know, tor daemon is still single-threaded. With multiple cores, you can run multiple tor daemons. But then there's a maximum of two instances per IP.
- datenwolf 10y agoRegarding the saturation of free socket ports. I see that KeyWeb gives you 2 IP addresses per vServer (and IPv6 enabled, which I assume means a whole /64). Wouldn't it have been easier to configure Tor to bind to only a single IPv4 address and use the other one for administrative login? As far as I understand the Linux network stack, port exhaustion happens on a per-address base. So even if Tor (or anything else) exhausts all the connection ports for one address you should still be able to get back in via the other address.
- doozler 10y agoI would be really interested in setting up an exit node and doing my part to help people with privacy and other issues get access to an open internet. Where would be the best place to start? I'm afraid that I'm not quite as technically advanced as the Author of the article so setting up the auto email responders and such would be difficult - can you just ignore the emails?
- DaKnOb 10y agoHey, it's the Author here.. You don't have to be very technical with that.. There are plenty of tutorials, some are "official" in the Tor Project website, and some not. Unfortunately you have to reply to these e-mails otherwise they may follow up or see that you never reply and follow other means of contacting you. Truth be told, I don't know. I've just read some info on their website.
- qwertyuiop0987 10y agoI guess my question is ...what exactly makes Tor any different than a bulletproof hosting provider? They could not care less about the abusive traffic they route, and when you confront them on dealing with that abusive traffic they just turn around and say "nothing we can do, it's anonymous by design." No wonder they are blocked all over the place -- they want the best of both worlds: anonymity without any of the consequences of dealing with the abuses of their platform. Doesn't work that way guys. Clean up your network or you get what you deserve -- which is to be blocked, or forced to prove you're not malicious. Cry me a river if you need to jump through some hoops ...it's the price that hipster should pay so that he can use Tor just to feel cool while he's at a coffee shop in SF. The hipsters who complain on Twitter are not the actual journalists or activists who should be using Tor.