5 ms·
TOR has been an invaluable tool for me for its ability to circumvent state censorship in an undetectable way. At some point in my career I was involved in some
by giga_chad 5y ago
TOR has been an invaluable tool for me for its ability to circumvent state censorship in an undetectable way.
At some point in my career I was involved in some journalistic reporting in Saudi Arabia; had I used a regular VPN, it could have been easily detected, and in best case defeated, worst case put me in serious legal trouble, which in Saudi Arabia can easily end in corporal punishment and/or death. TOR allowed me to circumvent all that and keep reporting on government official and police force corruption in a safe way, in a country that frankly could use a lot more of this type of journalism.
Thank you, TOR project!
- pfundstein 5y agoTor has long been billed as a tool for journalists to fly under the radar and avoid persecution, but it's great to hear these case studies from the horse's mouth. Thanks to you and other journalists who risk life and limb to report on and within these abusive regimes.
- hellbannedguy 5y agoThat is impressive. People throw around impressive too much, but I couldn't imagine pissing off any official in that country.
- wolverine876 5y agoI don't know the parent or their situation, but if you need similar security I would be very cautious about taking the parent literally. Sorry if I sound like a jerk; it sounds like the parent has taken great risks for the public good, but I don't want people to be hurt: I'm almost certain that Tor use is easily detected; that is what I've always (100%) read from security experts and it makes sense to me: Traffic patterns, packet fingerprints (encryption implementations, size, etc.), and of course all the traffic is going to and from a Tor node, a list of which is available to every Tor user. The attacker may not be able to read the contents or metadata, but they will know you are using Tor. Tor users are a very small population; it's a red flag. The same is true for websites, etc. that you visit: They can easily see that your traffic is coming from a Tor exit node. Also, exit nodes are of course as vulnerable to attack as any other server, and they provide access to the ip addresses you connect with and, when https isn't used or properly implemented, to the contents of the communication. Tor is not a panacea. Also, don't conflate Tor with Tor Browser, which I've read is possibly the worst security choice among browsers - a huge target without the resources to secure itself.
- jchw 5y agoTor on it’s own is definitely not a panacea. However, interested parties should look into Qubes OS. If detection is a huge concern, there is always the potential you could bridge your sensitive traffic in a less obvious manner. I believe you can configure this with a Qubes Whonix setup by selecting the “Tor is dangerous or censored in my area” option. It’s pretty powerful. I haven’t personally tried this as I don’t actually use Qubes except to play around with its neat VM setup.
- pfundstein 5y agoI'm not sure if you're aware but Tor has a specific mode for OP's situation, where it disguises traffic by using standard TLS on standard ports which looks no different to any other HTTPS traffic for example, among other things.
- wolverine876 5y agoWhat mode is that? Also, the traffic still goes to a Tor node. Finally, the Tor Project works very hard, but they are outgunned. Security is significantly a matter of resources. Tor's small team has a hard time competing with well-funded state security actors (who can also buy exploits).
- ivann 5y agoObfsproxy. You can also use bridges, which are unlisted Tor nodes. https://support.torproject.org/censorship/censorship-7/ https://support.torproject.org/censorship/censorship-7/
- smoldesu 5y agoFWIW, Tor is maintained by the US Navy as a means of secure communication. If it's outgunned, it becomes a national security risk.
- schoen 5y agoI think this is an exaggeration. The Tor technology was originally invented by researchers with the U.S. Naval Research Laboratory, who suggested that the system might be useful to Navy personnel among others. While Paul Syverson, one of those researchers, has remained involved with Tor since inventing it, no one from the Navy has ever publicly stated how or to what extent Tor is used by the military operationally. Military researchers invent a lot of cool stuff, much of which theoretically could be useful to the military in some way, but you shouldn't take the military research pedigree as proof that something is necessarily useful for a particular application or threat model today, any more than being invented by people from a famous university means that a technology is good or is the best choice for some application. A better case for the kind of considerations you mention might be found in infosec guidance that government agencies offer to other government agencies and contractors. For example, NSA has recommended that government agencies use AES to protect sensitive data, which doesn't mean that they think it's perfect (or would necessarily tell us if they knew of problems with it), but presumably puts some kind of cap on how bad it can be. I'm not aware of any government infosec authority that has publicly recommended that people inside the government use Tor.
- bouncycastle 5y agoHow is that possible? The fact that you are using Tor is detectable by ISPs just like it is detectable that you are using VPNs. Also, it's sometimes possible to de-anonymize your Tor traffic, and state-level actors would be capable to do so if they wanted. https://www.thesecmaster.com/4-types-of-attacks-on-the-tor-network-to-de-anonymize-tor-users/ https://www.thesecmaster.com/4-types-of-attacks-on-the-tor-n...
- cosentiyes 5y agoTOR bridges aren't publicly listed and support various obfuscation methods: https://tb-manual.torproject.org/bridges/ https://tb-manual.torproject.org/bridges/
- bouncycastle 5y agoLook at the language of that page. All the statements are without certainty, eg it's not "an adversary cannot identify them" but "an adversary cannot identify them easily."
- cosentiyes 5y agoYes, the tor project is very transparent that anonymity is not guaranteed. Bridges and obfuscation tools are simply one possible answer to the "how is [connecting to tor without ISP detection] possible?" question. The linked article tries to imply that Ross Ulbricht's arrest was somehow the result of deanonymized tor traffic, but in reality many (most?) large DNM [1,2] and malware/hacking arrests seem to be the result of poor opsec [3]. [1] https://www.ivpn.net/privacy-guides/online-privacy-through-opsec-and-compartmentalization-part-2/ https://www.ivpn.net/privacy-guides/online-privacy-through-o... [2] https://en.wikipedia.org/wiki/AlphaBay#Seizure_and_shutdown https://en.wikipedia.org/wiki/AlphaBay#Seizure_and_shutdown [3] https://krebsonsecurity.com/category/breadcrumbs/ https://krebsonsecurity.com/category/breadcrumbs/
- bouncycastle 5y agoObfuscation is a cat-and-mouse game and with enough resources, it's always possible to detect. While Tor is OK for privacy from your ISP or the big-tech firms, certainly not for what the OP described. I think recommending Tor as the definite solution for these types of people is irresponsible.
- kingcharles 5y agoIs a VPN illegal in Saudi Arabia? My girlfriend is Qatari and everyone there uses VPNs to access Pornhub etc. She says that while the state censors the Internet it does not criminalize the use of VPNs. It's a confusing issue. (I also undertstand that even if something isn't technically illegal it can bring the heat of LEOs upon you)
- ssalka 5y agoThank you for your efforts, giga_chad
- shp0ngle 5y agoTor is much more easily detected than VPN. Or. Well. It is same easily detected, but you can reasonably say you have VPN "just to watch US netflix" or something like that. You cannot say that about Tor.
- pphysch 5y ago> At some point in my career I was involved in some journalistic reporting in Saudi Arabia Was it a career in the IC?
- IceWreck 5y agoI think its the opposite. Regular VPN protocols, if obfuscated properly can blend in with https traffic. Tor is almost always detectable. You can see someone is using Tor, but not what theyre doing with it.