4 ms·
Couldn't you circumvent this by using a VPN to access TOR? It would obfuscate the entry point.
by CommentCard 9y ago
Couldn't you circumvent this by using a VPN to access TOR? It would obfuscate the entry point.
- nomel 9y agoIf you have an anonymous VPN, then what's the need for tor?
- freeflight 9y agoRedundancy, why use only one lock when you could use three different ones? That, of course, assumes that none of the locks come with a vulnerability which would allow an attacker to bypass all the locks at once.
- posterboy 9y ago> redundancy I always rot13 twice for good measure, too.
- kakarot 9y agoWouldn't your traffic then be compromised at the VPN level, opening you to snooping from your provider? Or do I not understand something about how TOR encrypts its requests?
- sillysaurus3 9y agoThis is correct. It's important to remember that everyone is just very, very bad at opsec. The ones who aren't usually don't comment. It's very hard and you spend most nights worrying the police will kick your door in. Not too worthwhile. Those who are serious should learn from the Whonix wiki. It's hard to find a more stellar source of unbiased and comprehensive information. They have pros and cons of both VPN to Tor and Tor to VPN, but that's like 2% of the overall concerns you have to worry about.
- CommentCard 9y agoHow is adding additional layers of security bad when there is a specific attack against one of the layers of security (timing attack via controlled TOR nodes) that a VPN-to-Tor would disrupt? If this method is dependent on knowing the latency going in and out of the network, adding VPNs that have varying latencies would seem to defeat this on the surface. I'm posing the question, as I don't see an answer in the article. Nobody gets better at opsec if flawed methodologies aren't picked apart in detail. I'm surprised I was downvoted, but I don't comment here frequently and maybe didn't pose the question in enough detail. This is usually how I was accessing Tor based on the assumption that most of the exit nodes are compromised.
- sillysaurus3 9y agoAgain: Go read. I gave you a reliable reference. I'd recommend spending all weekend reading the wiki and thinking carefully about the issues. Even if you don't use the information directly, it will give you some wonderful insights into the belly of the underworld.
- kakarot 9y agoI experimented with the Whonix setup while I was running a Qubes workstation and I was extremely impressed with the architecture. I also read through their wiki and was quite impressed at thorough explanations of the TOR network and opsec in general. I've also read through the actual TOR docs but most of it didn't stick. I see it as more of a reference. The only reason I ever left Qubes was because Xen still has not implemented a workaround for GPU passthrough with consumer NVIDIA cards like KVM does. I need this for gaming. I now run a KVM system with separate VMs for each domain similarly to Qubes, but the moment GPU passthrough functionality is addressed by Xen I'm moving back. The KVM experience is quite subpar, for example it is lacking a secure copy-paste between domains and forces me to type out my passwords from my password manager VM when I need them.
- CommentCard 9y agoI'm basing this on the assumption that your VPN is in a non-Eyes nation. I'm not sure why I was downvoted for posing this question, it seems like this is a valid way to obfuscate a potential timing attack if you have VPN servers with varying latencies.
- kakarot 9y agoDoesn't matter. It's simply not secure and any illusion of safety you may have using such a setup is just that, an illusion.