2 ms·
Onion services are incapable of resisting a determined government-scale attacker. Just filter Tor traffic to random groups of users for like 10 seconds, find on
by Iv 7y ago
Onion services are incapable of resisting a determined government-scale attacker. Just filter Tor traffic to random groups of users for like 10 seconds, find one such groups that prevents the target onion service from being routed. Bissect until you locate a precise node.
IMO, Tor is to be used to escape censorship as a reader or host services anonymously in not tech-savvy governments (which are becoming increasingly rare).
In the end, Tor only buys 10 to 20 years of freedom until governments figure out what to outlaw and filter. Censorship is a political problem, technical solutions provide a temporary hotfix, but the political problem has to be solved at one point.
- Ajedi32 7y ago> Just filter Tor traffic to random groups of users for like 10 seconds, find one such groups that prevents the target onion service from being routed. Bissect until you locate a precise node. That only works if you have the ability to filter out Tor traffic in the first place. (In which case, why not just preemptively block all Tor traffic in your country? Problem solved.) But Tor has systems in place designed specifically to prevent that sort of blocking by disguising Tor traffic as other, more common traffic types (like HTTP). There's also no guarantee that the Tor service in question is running on a host that's under your government's control. Cloud hosting is pretty common these days.
- Iv 7y agoYes, you can ban Tor altogether and be done with the whole thing. It is doable and there is no technical workaround for it. The scenario I am proposing is actually worse: you use the feeling of anonymity Tor proposes to uncover opponents. Yes, my tactic proposes you have a backdoor into all of ISP's infrastructure. I don't see that as a crazy requirement for most countries, even democracies. Disguising Tor traffic does not work well, and China has deployed several years ago already a tech that recognizes weird streams. Yes, you could be cloud hosting from outside the country. In the case of China though, that's likely to not work as most encrypted traffic crossing the border gets dropped (I guess unless it is HTTPS from a whitelisted source )