6 ms·
Honest question: What would be the use case for Tor, as is compromised[1] and painfully slow (judging from my personal experience, using it in the US and Asia,
by masterof0 5y ago
Honest question: What would be the use case for Tor, as is compromised[1] and painfully slow (judging from my personal experience, using it in the US and Asia, across the years). Is there any occasion where it will be better to use Tor than your self-hosted VPN?
1- https://restoreprivacy.com/tor/ https://restoreprivacy.com/tor/
- ziddoap 5y agoA point-by-point look of your source is a bit much for these comments (and they raise some great points that I either agree with or can't thoroughly rebut), but there's some interesting things in there that make me question the poster. They exclaim against being accused of spreading FUD, but use extremely emotional language and talk in absolutes when the reality is much less clear. For example, they say "2017 court case proves FBI can de-anonymize Tor users", but immediately handwave the how away, because it's classified. Well then, that's not really a strong proof of Tor being compromised -- there are several ways the FBI could de-anonymize Tor users that have nothing to do with Tor itself (people being compromised by javascript, people posting pictures with metadata, people linking back to real-life accounts, people inadvertently posting identifiable information, people posting quasi-identifiable information that is correlated over time, people downloading XYZ that has a beacon in it, etc.) I also can't help but wonder, if Tor is so thoroughly compromised and just a glowstick, why would the author finish with: >For those who still want to access the Tor network, doing so through a reliable VPN service will add an extra layer of protection while hiding your real IP address. If it's compromised to the core, a glowstick for LEA, enables the US government to "do spooky stuff", why bother giving a half-ass endorsement at the end of a hit piece?
- danuker 5y agoVPNs are great at centralizing paper trails, whether the VPNs themselves keep logs, or the ISPs.
- unethical_ban 5y ago"For those who still want to access the Tor network, doing so through a reliable VPN service will add an extra layer of protection while hiding your real IP address." You Tor to your VPN, you don't VPN to Tor.
- ziddoap 5y agoIt is unclear to me if you meant to reply to me or someone else, because this is wholly unrelated to the criticisms I raised against the author of the source in the parent's post. However, I will say, using Tor to access your VPN strips away much of the benefit of using Tor, to the point that you might as well just use a VPN (sans Tor). I suppose if you want a single-circuit Tor connection that appears to be a static non-Tor IP address, sure. But blindly recommending one way or the other without knowing someone's use case, threat analysis, and risk tolerance is foolish.
- edmcnulty101 5y agoIt's one added layer of protection. Combine Tor with a VPN. If your life is on the line with your content the more layers of protection the better.
- ipaddr 5y agoWhy not tor over tor then?
- bigwavedave 5y ago"You're very clever, young man, very clever- but it's tortles all the way down!"
- edmcnulty101 5y agoBecause apparently people are saying the gov't has control over exit nodes and are able to identify traffic with enough effort. Adding a VPN is another system that obfuscates and is not controlled by the same entity.
- beardog 5y agoTor+VPN has various trade offs and is not good for everyone. Generally i would say most people would not benefit from it. https://matt.traudt.xyz/posts/vpn-tor-not-mRikAa4h/ https://matt.traudt.xyz/posts/vpn-tor-not-mRikAa4h/
- beardog 5y agoIt comes down to statistics. Using a VPN you are using 1 entity, so all a state actor needs to do is view that one entity's traffic. This may be time consuming and legally challenging if the entity is trustworthy and has servers spread across the globe, but there is still only 1 point that they need to monitor - I suspect many VPN service users are not randomly switching servers. You said "self hosted" VPN which if you are doing that at home it provides no anonymity (which i'm assuming is the point of the comment since the context is Tor). If you host it at a server you are anonymously renting (good luck doing that without opsec failure), it is still only your traffic there, you have no benefit of blending in with others. With Tor, you can be assured that your attacker needs to monitor more than some % of the network (which can be done either by running nodes themselves or having a wide view of netflow data). Alphabet soup agencies are capable of this, but these attacks are expensive and non-trivial which is why historically the FBI and such use browser exploits the most. You shouldn't rely on Tor alone to protect your life if your adversary is highly skilled or funded, but chalking it up to a VPN is completely discounting the benefit gained from a larger anonymity set in the world's biggest onion routing network.
- masterof0 5y agoThank you.
- foxfluff 5y agoWow there's so much FUD, hyperbole, and rigged language there. "Interesting" exchanges alright. They go ahead and make FBI and backdoors bold to shock the reader but conveniently rest of the context is left out. The actual context being Roger giving a talk about Tor at one of these conferences where you also have government entities voice their (guess guess) desire for backdooring and wiretapping the internet (while tech people from the industry aren't convinced). The same shit you see discussed openly in the public all the time anyway, probably just with more pleading from the FBI because it's so hard to solve crime without industry's help. Nothing unusual here. The wording of this fudpiece sounds like it's trying to implicate the Tor developer in planting backdoors for the FBI, which is not at all what the exchange is about if you read the context. "Tor privately tips off the federal government to security vulnerabilities before alerting the public" is also complete FUD. I'm so glad I read the whole stack of FOIA'd documents before this text. The context here is that BBG (Broadcasting Board of Governors) is using Tor to circumvent censorship in places like Iran, China, Saudi Arabia, and Russia. Alright you can call that a propaganda arm of the US government if you're so willing, but anyway, Tor is one of the tools they rely on. They need Tor to circumvent censorship, so they need to address vulnerabilities in Tor that make it easy to censor. This "vulnerability" isn't one that FBI uses to catch a drug dealer or a hacker, it's a vulnerability that makes it easy to fingerprint and block Tor traffic. Now Tor's use has historically been quite easy to detect and block (see e.g. this FAQ entry from 2008 [1]) and fixing that has been a long road, I don't know where exactly they stand today. The "vulnerability" is just one among many and the possibility of fingerprinting TLS has been mentioned in the FAQ. It's not the kind of vulnerability you would have to scream and alert the public to (they should've already been aware that it is possible identify and block Tor traffic). Rather, it's something they should quietly research and figure out a solution to and hopefully stay ahead of the game w.r.t. regimes that may attempt to block Tor. Discussing the draft proposal for fixing this TLS fingerprint vuln with the people who they are working together with to keep Tor useful in Iran etc. is exactly what the Tor project ought to do! The fact that these people happen to be employed by the U.S. Government doesn't seem particularly relevant. But suuure, "privately tipping off the feds to a vuln while keeping the public in the dark" is a nice way to twist it. Here's the thing, there are issues with Tor, there are issues with anything because there is no technical solution to perfect anonymity. I would not bet my life on Tor. But knowing what it's good for and what its limits are, Tor is a very useful tool, and IMHO it can only get better if it gets more users and more relays. I would always recommend being vigilant and looking out for bugs, backdoors, and other sketchy stuff, but this fud piece just doing a disservice against itself with all the hyperbole. It sounds more like they've got an axe to grind. [1] https://web.archive.org/web/20080415073019/https://wiki.torproject.org/noreply/TheOnionRouter/TorFAQ#head-0005ffb666bb6de9a5badc70d770841f94bf80ea https://web.archive.org/web/20080415073019/https://wiki.torp... > The original Tor design was easy to block if the attacker controls Alice's connection to the Tor network --- by blocking the directory authorities, by blocking all the relay IP addresses in the directory, or by filtering based on the fingerprint of the Tor TLS handshake. Some government-level firewalls could easily launch this type of attack, which would make the whole Tor network no longer usable for the people behind the firewalls. Sect. 7.1: > Note that all your local ISP can observe now is that you are communicating with Tor nodes. Similarly, servers in the Internet just see that they are being contacted by Tor nodes See also the linked DRAFT "Design of a blocking-resistant anonymity system" https://web.archive.org/web/20080322054926/http://www.torproject.org/svn/trunk/doc/design-paper/blocking.html https://web.archive.org/web/20080322054926/http://www.torpro...