3 ms·
Its not secure. "Everyone" knows that. Everytime a drug market is taken down or a pedophile ring is busted, the investigators from FBI always claim it was some
by gressquel 9y ago
Its not secure. "Everyone" knows that. Everytime a drug market is taken down or a pedophile ring is busted, the investigators from FBI always claim it was some dubious mistake from the admin whic lead to it. But we all know they have discovered a vulnurability in the TOR protocol but won't disclose it.
Safe browsing guys
//edit: if you want extra security. Launch TOR from a remote desktop. And I am not talking about the ones you buy from known VPN providers like NordicVPN or amazon web services.
- typon 9y ago> But we all know they have discovered a vulnurability in the TOR protocol but won't disclose it. Can you provide evidence for this claim? I'm a huge conspiracy nut, this has me excited.
- nobodyorother 9y agoYou don't need anything that isn't already publicly available: see every security bug reported on the mailing list, and reliable hop tracing via coordinated parties recording traffic (Tor's version of Bitcoin's 51% problem). That said, it's still the most reliable limited-anonymity provider I know of.
- staticassertion 9y agoI guess I'm not everyone. I'd bet that the majority of the 'busts' are due to: a) Infiltrating chats where people are more likely to share sensitive information / trust the people they're talking to b) Poor configurations/ setups on either the client or server (client browser bundle has noscript, but it's not on the strictest settings, js is enabled iirc) c) Exploitation of client or server due to out of date versions, things like that Historically I think it's always fallen into one of these cases - and not just what the FBI etc say publicly but we've seen these exploits ITW. I wouldn't be surprised if the NSA and other agencies have the power to deanonymize TOR users but if it were trivial why is the majority of TOR traffic still going towards illegal content? Last I read (a paper a year ago) TOR is still primarily all about drugs, followed by child pornography (mostly drugs though iirc). If they can track all of these people by breaking TOR completely... why don't they?
- colejohnson66 9y ago^ This. Remember, Silk Road was finally found and taken down because Ross Ulbrich messed up his OpSec on a Stack Overflow question.
- 0xJRS 9y agoThats really interesting, does anyone have a link to an explanation about this?
- colejohnson66 9y agoWow. That was 4 years ago? Here’s a Reddit discussion: https://www.reddit.com/r/webdev/comments/1nln17/the_stackoverflow_question_that_busted_the_silk/ https://www.reddit.com/r/webdev/comments/1nln17/the_stackove... Basically, he posted to stack Overflow using his own name and email address with code that was Silk Road was using. He quickly changed his username, but it was too late.
- jerheinze 9y ago> //edit: if you want extra security. Launch TOR from a remote desktop. And I am not talking about the ones you buy from known VPN providers like NordicVPN or amazon web services. No, if you want extra security use Qubes OS with Whonix (it comes with it by default) for isolating the Tor process in a single VM and the browser in another - thereby prohibiting any leaks, unless an adversary has a VM escape RCE.
- tresp 9y agowhat about Tails?
- jerheinze 9y agoSee this great comparison table: https://www.whonix.org/wiki/Comparison_with_Others#General https://www.whonix.org/wiki/Comparison_with_Others#General Especially this other one: https://www.whonix.org/wiki/Comparison_with_Others#Circumventing_Proxy_Obedience_Design https://www.whonix.org/wiki/Comparison_with_Others#Circumven...
- revmoo 9y agoAll they have to do is ddos the target using a specific traffic pattern and then look on edge routers for it coming through to the server. Doesn't even require DPI. Tor is not secure.
- tresp 9y agolmao, this is complete BS. sure it's not perfect and some nodes get compromised. no nation or three letter agency has cracked tor. prove me wrong
- woodandsteel 9y ago>But we all know they have discovered a vulnurability in the TOR protocol but won't disclose it. Really? Perhaps you could explain how every single one of us found out it is true? Maybe every single one of us has a friend working in the NSA who was willing to tell us, even though he could go to jail for giving away such a secret? Or maybe you are just making things up.