4 ms·
It was in the article you posted at the end. /shrug. If your threat model includes state actors, then Tor's current shortcomings are non-trivial and should be
by bpchaps 9y ago
It was in the article you posted at the end.
/shrug. If your threat model includes state actors, then Tor's current shortcomings are non-trivial and should be treated as such.
- jerheinze 9y agoOh, well here's what he was talking about, > The Harvard kid who was the only Tor user on Harvard’s network at the time that he sent his bomb threat. > The Freedom Hosting and Silk Road hacks (problems with the web apps that were hosted as Tor hidden services, not with Tor itself). > Exit node sniffing (an issue with people using plaintext protocols on the internet; people are just as vulnerable when using airport wifi, though perhaps they’re less likely to have an attacker on their network than to be using a malicious exit node). As you can see those are problems that Tor can't solve. Micah wasn't talking about some inherent flaws in Tor's design. > If your threat model includes state actors, then Tor's current shortcomings are non-trivial and should be treated as such. Doesn't change the fact that Tor is the best low-latency anonymity system currently and using it is better than not.
- deleted 9y ago[deleted]
- bpchaps 9y agoHere is what Tor claims to solve on its download page [0]: "The Tor software protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody watching your Internet connection from learning what sites you visit, it prevents the sites you visit from learning your physical location, and it lets you access sites which are blocked." That statement is not exactly true in the case of that Harvard kid. A sysadmin and their logs is still "watching", and in this case eventually found out which site through news channels ;). That's not to say that I think Tor isn't great nor that it shouldn't be used. My complaint is that it gets represented to general non-technical crowds as solving more problems than it actually does. [0] https://www.torproject.org/projects/torbrowser.html.en https://www.torproject.org/projects/torbrowser.html.en
- jerheinze 9y ago> That statement is not exactly true in the case of that Harvard kid. A sysadmin and their logs is still "watching", and in this case eventually found out which site through news channels ;). That's why bridges and pluggable transports exist and let you obfuscate your Tor traffic to look like something else, see: https://tb-manual.torproject.org/en-US/circumvention.html https://tb-manual.torproject.org/en-US/circumvention.html > That's not to say that I think Tor isn't great nor that it shouldn't be used. My complaint is that it gets represented to general non-technical crowds as solving more problems than it actually does. Well they do provide warnings https://www.torproject.org/download/download.html.en#warning https://www.torproject.org/download/download.html.en#warning among them is the one which is related to the Harvard teen "Use bridges and/or find company: Tor tries to prevent attackers from learning what destination websites you connect to. However, by default, it does not prevent somebody watching your Internet traffic from learning that you're using Tor. If this matters to you, you can reduce this risk by configuring Tor to use a Tor bridge relay rather than connecting directly to the public Tor network. Ultimately the best protection is a social approach: the more Tor users there are near you and the more diverse their interests, the less dangerous it will be that you are one of them. Convince other people to use Tor, too! "