4 ms·
Running your own guard is stupid unless you open it for the world to use. If you're the only person using the guard, then the guard offers you zero anonymity.
by hackerfactor1 7y ago
Running your own guard is stupid unless you open it for the world to use.
If you're the only person using the guard, then the guard offers you zero anonymity.
And if lots of people use your guard, then make sure it doesn't violate your ISP's terms of service. (Most ISPs have a clause about residential customers not running public services.) Also, have a plan in place for when (not if) you receive legal notices about copyright infringement, child porn distribution, and other acts that could be criminal in your country/city.
- bureaucrat 7y agoActually it's not like you think. It's OK to use guards for yourself because 1) there are thousands of non-public guards(bridges) 2) you choose the path to the rendezvous point 3) middle nodes don't know the type of the traffic Also there are a few things wrong with your article. And the rendezvous point must be in this list (because you shouldn't have a private rendezvous node). This is not true. The spec does not specify that. Usually Choopa LLC -- a cloud provider that is regularly used by hostile actors. Choopa LLC is not regularly used by hostile actors. You can't say that citing one report. However, the relay, rendezvous, and exit nodes must be publicly known so that lots of Tor traffic will use them. Not true with rendezvous points.
- xb95 7y agoI work on infrastructure at Discord. Our voice and video infrastructure gets attacked quite frequently and we have pretty good tracking about which ASNs the traffic is coming from as part of our mitigation processes. Anyway, Choopa is a common source of DDoS in our reports, so I can corroborate the OP's comment to some degree. They aren't the largest we see, but they're in the top 10 sources for us.
- az656 7y agoAs someone who also has similar visibility, I can also vouch for the fact that Choopa has a very lax and unenforced abuse policy.
- lima 7y agoAs someone who used to work for a company that hosted large-scale gaming infrastructure, I can confirm that Choopa was a common source of DDoS. DigitalOcean, too, and lots of eyeball providers. Any provider who allows credit card payments has issues with outbound attacks, and some are better at responding quickly than others. It got so bad we ended up building and deploying our own line-rate packet processing engine at our network edge to be able to deal with the weird UDP protocols gaming uses. How much spoofed traffic do you see nowadays?
- mirimir 7y agoAs long as you're anonymous enough about it, I don't see why running your own [private bridge] is any less anonymous than using an unpublished bridge, or a snowflake proxy. An adversary with lots of intercepts could certainly figure it out. But otherwise, how would anyone know? And at least, it protects you from malicious guards. Also, your point about violating a residential ISP's ToS is troubling. Because nobody in their right mind ought to be running any sort of Tor relay from home. It's a ~sure way to get your IP address on many blocklists. And about getting notices, that only happens for exit relays. Not for guards and middle relays. Edit: Actually, I meant running your own unpublished bridge, not guard. In the bridge torrc: ExitRelay 0 BridgeRelay 1 BridgeDistribution none PublishServerDescriptor 0 And in the client torrc: UseBridges 1 UpdateBridgesFromAuthority 0 Bridge [transport] IP:ORPort [fingerprint]
- marshray 7y agoIf you have a way to run a server anonymously, then you could just use that instead of Tor.
- mirimir 7y agoTor protects the server. Paying and managing is separate. And yes, also uses Tor, plus nested VPN chains.
- hackerfactor1 7y agoFirst: If you're going to do that, then why bother with Tor? Just get a couple of private cloud boxes and make your own VPN. (You'll be just as secure. Which isn't as secure as Tor, but it's better than nothing.) Second: "An adversary with lots of intercepts could certainly figure it out." Exactly. If you use Tor properly, then nationstates with virtually infinite resources can't figure it out. (That's why some countries block Tor; if you can't crack it, then block it.) But if you run your own guard, relay, rendezvous, or exit node -- and you're the only person who uses it -- then an adversary with lots of intercepts could certainly figure out who you are.
- 7y ago
- 3xblah 7y ago"Tor exit node block Operators of Internet sites have the ability to prevent traffic from Tor exit nodes or to offer reduced functionality for Tor users. ... The BBC blocks the IP addresses of all known Tor guards and exit nodes from its iPlayer service, although relays and bridges are not blocked.^[110] 110. https://www.bbc.co.uk/iplayer/help/questions/playback-issues/outside-uk-message" https://www.bbc.co.uk/iplayer/help/questions/playback-issues... The above is from the Wikipedia page for Tor. If the guard IP was "unpublished", then would that be a way to access sites like BBC iPlayer in spite of their blacklisting known guard IPs. Perhaps in the BBC case some users were trying to use Tor as a "poor man's VPN" to get a free UK IP address.
- mirimir 7y agoHuh? Sites like the BBC don't see guards, or middle relays, just exit relays. However, Tor relays are exits only if their torrc has this: ExitRelay 1 Otherwise, to start, they're just middle relays. It takes a while to earn the guard flag. But eventually, some relays could fill all three roles: guard, middle, and exit. As far as I know, bridges are the only Tor relays that can be unpublished.