6 ms·
I love Tor, but it's almost suspicious how fast it's become, like I'm wondering who's paying for all this bandwidth. Home, businesses, hotels, you name it, Tor
by hnuser54 7y ago
I love Tor, but it's almost suspicious how fast it's become, like I'm wondering who's paying for all this bandwidth. Home, businesses, hotels, you name it, Tor Browser almost never takes more than 2x as long to load anything on the web as the raw connection does. I admit don't have an understanding of how Tor works mathematically. There are organizations funding Tor exits and relays (torservers.net, Emerald Onion, Tor Project itself) but has anyone added up the bandwidth they provide and compared it to the total?
- arthurcolle 7y agoDon't all those crazy FBI/CMU/(NSA..?) correlation attacks require you to control some majority percentage of the relays and/or exit nodes? It would definitely be interesting to actually come up with some estimates of how much was being spent in aggregate bandwidth costs, say, 7 years ago, and compare it with what is being spent at present, and see if it matches what would be expected with 'normal user growth' although normal user growth for a relatively niche project like this would be pretty hard to quantify.
- throwaway66920 7y agoI wonder if there aren’t multiple us agencies competing for a majority share Unbeknownst to each other, all of them limiting the abilities of the others, all of them making it a better platform for those wishing to remain anonymous
- heavyset_go 7y agoThey're most likely working together.
- arthurcolle 7y agoIn modern times I bet you are right but historically information-sharing wasn't common across the IC (based on my understanding of post-9/11 reality)
- mike_hock 7y agoMore likely US agencies are competing with Russian and Chinese agencies.
- whamlastxmas 7y agoI've seen what I remember to be credible information, possibly leaks via something like Wikileaks, saying that there was a tremendous number of US government owned Tor nodes. To the point that it was likely your traffic wasn't actually anonymous. I wish I could remember where I saw it.
- derefr 7y agoYou can see at least the first half of any Tor circuit, though, and more-often-than-not I get mostly nodes with IPs from European countries. Are those US-Government-owned nodes, that just happen to be in Europe?
- ColanR 7y agoThat would be insanely easy for the US government to set up.
- the-pigeon 7y agoPhysical location is not really relevant to who owns a node. Most countries allow anyone to setup a company and operate servers. Any government organization with a small amount of resources can setup a front company and turn on a server.
- LMYahooTFY 7y agoI also wish you could remember, as my memory is something along the lines of they ran a few nodes on on EC2 for like a few weeks. I'll try to find a source when I'm off mobile.
- codesushi42 7y agoThat doesn't matter unless they operated all nodes in the routing chain.
- schoen 7y agoOperating the entry and exit on a circuit is almost as bad as operating the entry, middle, and exit.
- schoen 7y agoThe Tor Project tells relay operaters to set a value called MyFamily to declare which relays are run by the same person or group, so that Tor users won't use more than one relay in the same path with the same operator. https://2019.www.torproject.org/docs/tor-manual.html.en#MyFamily https://2019.www.torproject.org/docs/tor-manual.html.en#MyFa... Of course, a malicious relay operator that wanted to increase its chances of being used as both the entry and exit nodes in a single path (and thereby easily being able to correlate traffic between its origin and destination) could add a lot of nodes and not own up to their relationship. Some people in the Tor community try to watch for relay-creation behavior that they consider suspicious. A common example is a large number of new relays that appear within a short period of time with similar characteristics and don't declare common ownership. Edit: one of the main tools for this is OrNetRadar, which seems to primarily use the autonomous system number in which the relays are located, as well as the timing of their creation: https://nusenu.github.io/OrNetRadar/ https://nusenu.github.io/OrNetRadar/ In this case, the relays can be given a flag like BadExit by the Tor developers, which will stop any Tor client from selecting those relays as exit nodes in a path. However, a sufficiently malicious attacker could add a lot of network capacity in a way that isn't recognizably associated as belonging to the same entity, for example by adding nodes in different data centers, with different speeds, with different software environments, and not all coming online at the same moment. In that case, there wouldn't be a way to easily infer that these nodes are associated with the same operator. As someone has said elsewhere in this thread, there's still the hope that if different organizations add network capacity with malicious intent, they tend to undermine one another's chances of succeeding, at least as long as they aren't directly colluding (because the basic security goal in Tor is that clients choose paths whose constituent relays don't share information with one another).
- tlrobinson 7y agoDo Tor circuits always use 3 nodes? It seems like it should randomized/configurable (maybe 3 or 4 by default), such that no nodes can know whether they're an entry node or somewhere in the middle.
- schoen 7y ago
- KenanSulayman 7y agoI'm operating three 10Gb Tor exits in a DC in Amsterdam. [1] It seems like a meaningful contribution. I assume the other operators who are not IAs have similar reasons. [1] https://metrics.torproject.org/rs.html#search/family:38A42B8D7C0E6346F4A4821617740AEE86EA885B https://metrics.torproject.org/rs.html#search/family:38A42B8...
- t34543 7y agoPersonally or on behalf of a company? I ran two in the US and folded due to legal pressure.
- KenanSulayman 7y agoPersonally
- input_sh 7y agoIf you don't want legal trouble, don't run exit nodes. I've configured my relay to serve as a middle node. I'm using a provider that's known to be hostile towards Tor relay operators with no repercussions for about two years now.
- bureaucrat 7y agoWhat datacenter do you use? How much does it cost? Did you get any legal troubles?
- Aeolun 7y agoWhy would you get in legal trouble for hosting tor exit nodes? There’s nothing illegal about that is it?
- throwaway-9320 7y agoHosting an exit node is not illegal, but some of the users of that exit node may be doing illegal things.
- 7y ago
- bureaucrat 7y agoI run 3 nodes. They have 1TB traffic cap per month, so they serve 30GB per day per node, and then hibernates. It costs 15$ per month to run. I also use those nodes for personal use, so it’s not that expensive. Also I’ve convinced my company to run nodes with their VPS credit. 6 nodes, 30GB per day per node. It costs them 30$.
- anderspitman 7y agoDigitalOcean?
- bureaucrat 7y agoTor asks not to host on them so no.
- Kiro 7y agoWhy is that?
- walrus01 7y agoa tor exit node is nearly guaranteed to attract a flood of DMCA notices (relevant to digitalocean, since they're in the US), subpoenas, legal threats, national security letters, regular search warrants, and the rare but not unheard of no-knock bust down the doors search warrant.
- mike_hock 7y agoWell, the NSA is funded by taxes, so ... the US taxpayer pays for it.
- robert_foss 7y agoI've run Exit nodes at home and in DCs for the past 10 years. https://metrics.torproject.org/rs.html#details/786926E8C497A6924ED69E23D48B13E92D1E07EE https://metrics.torproject.org/rs.html#details/786926E8C497A...
- bufferoverflow 7y agoHome internet speeds have improved dramatically in the last decade, especially outside of the US. Most of the EU has gigabit available, and in many countries it's crazy cheap.