10 ms·
The inescapable fact about Tor is that its traffic patterns make you stand out prominently. Just the fact you’re using it automatically makes you interesting a
by optimalsolver 4y ago
The inescapable fact about Tor is that its traffic patterns make you stand out prominently.
Just the fact you’re using it automatically makes you interesting and worthy of a closer look.
All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?
- acapybara 4y agoMaybe this could be a good thing for business development? Could we convert our "observers" into early customers?
- deleted 4y ago[deleted]
- pr337h4m 4y agoThe Brave browser has around 60 million MAUs and has Tor bundled with it, so Tor traffic is unlikely to stand out as much as before.
- thekyle 4y agoI believe the Tor feature of Brave is an optional setting, so I assume only a small fraction of their MAU use it.
- Gigachad 4y agoIt’s not a setting, it’s like their version of an incognito tab. You can right click a link to “open in tor”
- Mistletoe 4y agoWow this is really cool. I need to look into Brave again.
- dhaavi 4y agoAfaik, it does not use Tor from within the browser, but uses a proxy server into Tor. That could have changed though.
- CommitSyn 4y agoIt would certainly make sense from a marketing perspective to claim it's using tor, and then have a tor-proxy service (think onion.cab) use tor for hidden services and also attempt to use tor for clearnet traffic but fail back to regular proxy if it fails. If it were directly using tor then I'd have to agree that most people wouldn't use it. Only those that are technical enough to understand what's going on and the security aspects. But they wouldn't be using Brave for the Tor functionality, they'd be using Tor Browser.
- ffpip 4y agoIt runs a TOR client locally and proxies all connections through that. It does not implement the privacy protections of the TOR browser tho. Basically, using the TOR network as a VPN.
- noirscape 4y agoNot a VPN, TOR just runs as a SOCKS proxy on whatever device you're using[0]. Replacing the actual network stack at OS level was considered but iirc was decided against because it would require admin permissions. The TOR browser and Brave do the exact same thing, it's just that the TOR browser is configured to not store anything and to make sure it's fingerprint to other sites is as generic as possible (this is also why TOR warns you about changing window size, it un-generalizes that fingerprint). Both ultimately are conveniences because messing with SOCKS proxy settings is rather unfriendly for most users. If you use a Linux distro, I'd recommend checking out torsocks[1], it's a shared library + a shell script that lets you "onion-ify" any application pretty easily. [0]: This also means you can connect basically every mainstream browser to TOR if you know the port the SOCKS proxy is running on. [1]: https://man.archlinux.org/man/torsocks.1.en https://man.archlinux.org/man/torsocks.1.en
- yreg 4y agoThey also have private windows without Tor and the users probably found out that Tor takes quite longer and works only half the time compared to the ordinary private window, so I wouldn't get my hopes up that it is adopted massively. (Still, it's great they have done that.)
- metadat 4y agoI don't see this on Android. I also can't seem to locate any related settings.
- bravetraveler 4y agoSimilarly, as do the Trezor wallets. Quite a few people involved in crypto send a bit of TOR noise across the wires using that client to do transactions This is a good point, though. We need more and more things to use it (legitimately) so that the traffic alone isn't as suspect. It'll always be a little suspect, I suppose, being only visible to exit nodes or whatever
- worldsavior 4y agoThis is a wrong conception. Using tor without Tor browser will make you stand out much more, since you're using a different browser. Not talking about non-browsers connections.
- treebeard901 4y agoWhile this is true, it shouldn't make anyone more worthy of a closer look. It's the same argument used to justify mass surveillance. Trying to defend a Constitutional right to privacy, if one exists in your country, does not mean you are automatically trying to hide doing something wrong.
- kube-system 4y agoI didn't take the parent comment to be referring to governments. Most of the internet is made up of private organizations, many of which are interested in the traffic they carry.
- sasattack 4y agoAlso you are providing cover to agents of US intelligence who use it
- sterlind 4y agoiirc IC still mostly uses burner shell companies for IPs, at least for running ops. Tor is fine for innocuous browsing but Tor exit nodes will stick out like a sore thumb in the victim's logs or IDS.
- sterlind 4y agoa closer look maybe, but unless they break Tor they'll only have a close look at your timing traffic. if you're worried, you could use a popular VPN to connect to Tor - using a VPN is less interesting. also, P2P app developers could consider running non-exit nodes in their clients for popular apps. there shouldn't be legal risks unless you're running an exit node, and this adds more noise to the signal of Tor users.
- godelski 4y agoWhy are exit nodes more legally perilous than non-exit nodes?
- sterlind 4y agothey shouldn't be, but there's a practical difference in how often your house gets raided by FBI agents. if a Tor user uses your exit node to email a bomb threat or access child porn, it's your source IP that shows up. the FBI should check your IP against the registry of exit node IPs, but if they don't it's still your door getting kicked in.
- bombcar 4y agoExactly - and I've noticed there aren't very many exit nodes at all, small enough that I can start to recognize them by name.
- HackerNCoder 4y agoYea, there is only about 1000 (actually 1300, I just checked) exits - out of only ~6000 nodes total, the Tor network is actually kinda small.
- godelski 4y agoSo I guess the question is, how would one scale the number of nodes? Isn't that really what's needed then?
- yucky 4y agoThere is also the inescapable fact that Tor was created by US Intelligence, specifically the US Naval Research Lab[0]. And according to FOIA documents it continues to receive a huge chunk of funding & resources from US Intelligence, particularly from the United States Agency for Global Media (formerly the Broadcasting Board of Governors), which supervises our propaganda channels Voice of America and Radio Free Europe/Radio Liberty[1]. As far as I can tell, the US Intelligence community has never explained it's aims/goals for Tor. The fact that Tor not only attracts the type of traffic that US Intelligence would have a lot of interest in monitoring, but also by design then funnels that traffic through a small number of exit nodes, makes it seem self-explanatory. But I wouldn't want to presume anything. [0] https://en.wikipedia.org/wiki/Tor_(network) https://en.wikipedia.org/wiki/Tor_(network) [1] https://www.documentcloud.org/app?q=%2Bproject%3Athe-tor-files-transparenc-37206 https://www.documentcloud.org/app?q=%2Bproject%3Athe-tor-fil...
- HackerNCoder 4y agoYou don't need (outdated) FOIA documents for that... Go to https://www.torproject.org/about/sponsors/ https://www.torproject.org/about/sponsors/ and you will see that they get money from the US government, if you want to know more about how much, go check the IRS 990 forms [1] or check the blog post that explains the 990, it also gives clear percentages on how much comes from where, [2] [1] https://www.torproject.org/about/reports/ https://www.torproject.org/about/reports/ [2] https://blog.torproject.org/transparency-openness-and-our-2020-and-2021-financials/ https://blog.torproject.org/transparency-openness-and-our-20...
- yucky 4y agoThis part appears to be missing from the Tor website: > 2,500 pages of correspondence — including strategy and contracts and budgets and status updates — between the Tor Project and its main funder, a Central Intelligence Agency spinoff now known as the Broadcasting Board of Governors (BBG). These files show incredible cooperation between Tor and the regime change wing of the US government. So the documents acquired via FOIA requests are worth reading, and it's worth discussing why the US Intelligence community has such an active interest in propping up Tor.
- time_to_smile 4y ago> but it’s rarely ever that, is it? Maybe I'm unique, but my dark net activity is usually pretty tame. The number one reason I use Tor is because browsing onion sites reminds a bit more of how the web used to be in the late 1990s. Lot's of garbage of course, but a lot more serendipitous discovery than the web today. Because of its anonymous nature Onion sites are inherently resistant to being swallowed whole by advertising. Nobody on the dark web is creating "content marketing", if someone is trying to sell you something it's obvious. You're not the product on the dark web. I know it's wishful thinking, but I often hope for a parallel web to really thrive on Tor.
- mypastself 4y agoIf I may ask (provided you’re comfortable with disclosing) what kind of content do you find there that’s genuinely interesting?
- shaky-carrousel 4y agoPersonal blogs in my case. I find a similar landscape on Gemini. I really dislike the noise proeuced by ad-sponsored websites.
- mhitza 4y agoWhile not Tor, I browse I2P websites from time to time. tracker2.postman.i2p is a great torrent tracker if I want to easily get access to leaked material I read in the news about. And planet.i2p to see newly "registered" websites. Content on those websites vary, but I've stumbled upon a couple of blogs, ranging from the mundane, to conspiracy theory blogs, which are also fun to read. It really does give you that 90s internet feeling.
- bombcar 4y agoA surprising number of "clarinet" (er clearnet spellcheck) sites have onion sites, if you use Brave and TOR it sometimes shows up a little onion in the right telling you there's an onion version available.
- 4y ago
- anotheraccount9 4y agoSounds like I should use my session for multiple unrelated activities while using Tor, to cover only for one of them (before changing my fingerprint)
- londons_explore 4y agoTor can be made substantially less obvious if you make sure the bitrate and packet timings over each 'hop' of users connections are fixed. Eg. each client sends out 1000 1 kbyte packets per second to each peer, once per millisecond. Inside each packet, they send the onion encrypted user data. The rest of the packet is filled with rand(). Without that protection, any network attacker can do packet size and timing analysis to unmask nearly any user rather quickly.
- yjftsjthsd-h 4y agoIs that individually tunable, or are you suggesting something that the project would have to change in their code?
- londons_explore 4y agoIt would only be effective if at least some proportion of clients used it. If just a single client used this option, their traffic path, all the way to the exit node, would stand out to any network attacker.
- resuresu 4y agoSubmit a pull request then.
- data_maan 4y agoI took class in IT privacy back in the day. Exactly this idea came up. And while it really disables certain kinds of timing based attacks, the problem is it doesn't scale. If everyone did this, it seems the network would be flooded.
- sillystuff 4y agoI'm not sure if only the client does the padding, or if the padding also occurs at intermediate hops, but Tor does randomly pad traffic by default (from manpage of torrc): CircuitPadding 0|1 If set to 0, Tor will not pad client circuits with additional cover traffic. Only clients may set this option. This option should be offered via the UI to mobile users for use where bandwidth may be expensive. If set to 1, padding will be negotiated as per the consensus and relay support (unlike ConnectionPadding, CircuitPadding cannot be force-enabled). (Default: 1) ReducedCircuitPadding 0|1 If set to 1, Tor will only use circuit padding algorithms that have low overhead. Only clients may set this option. This option should be offered via the UI to mobile users for use where bandwidth may be expensive. (Default: 0)
- chefandy 4y agoA colleague at a former academic job was questioned by campus police because he was one of a handful of people on the university network connected to TOR when a bomb threat was submitted (I forget how, though) from an IP address running a TOR exit node. Bomb threats from students were pretty common during exams, so after the cops saw that it was our very privacy conscious dev ops guy they didn't pursue him as a suspect. If the person who did it connected to TOR from the university network to submit a bomb threat to duck an exam, they definitely deserve to get caught. I think that qualifies as "just enough knowledge to be dangerous."
- scrlk 4y agoWas it this incident? https://www.theverge.com/2013/12/18/5224130/fbi-agents-tracked-harvard-bomb-threats-across-tor https://www.theverge.com/2013/12/18/5224130/fbi-agents-track...
- chefandy 4y agoMuch more recent.
- andirk 4y agoSometimes it goes the other way too. In my high school, a handful of kids wore all black every day. They were harmless valley girls/guys if you spoke with them. I figured they _wanted_ to be seen as a threat. Why would someone make a legit bomb threat? Isn't the point of the bomb for it to explode?
- MerelyMortal 4y agoI suppose some people might just want to destroy infrastructure and not kill people directly (give people an opportunity to evacuate).
- Eisenstein 4y agoTwo historical examples: The Weather Underground regularly and the IRA occasionally called in their bombs in advance order to reduce/remove civilian casualties. They tried to give enough time to evacuate an area but not enough time to find and defuse the device.
- shaky-carrousel 4y agoIt is, in my case. All my system updates run over Tor. I do it to generate noise.
- jerheinze 4y agoThis is one of the main reasons why I keep using Tor daily. The more people use Tor for normal browsing, the less interesting it becomes to be a Tor user, the better the anonymity for everyone else.
- INeedMoreRam 4y agoI also use Tor sometimes for the sole purpose of muddying up the waters for investigators.
- Scoundreller 4y agoI use it to get around many paywalls.
- CommitSyn 4y agoSimilarly, I use it to train my internal neural net to better answer Cloudflare CAPTCHAs.
- shaky-carrousel 4y agoQuoting Phil Zimmermann: What if everyone believed that law-abiding citizens should use postcards for their mail? If a nonconformist tried to assert his privacy by using an envelope for his mail, it would draw suspicion. Perhaps the authorities would open his mail to see what he's hiding. Fortunately, we don't live in that kind of world, because everyone protects most of their mail with envelopes. So no one draws suspicion by asserting their privacy with an envelope. There's safety in numbers. Analogously, it would be nice if everyone routinely used encryption for all their email, innocent or not, so that no one drew suspicion by asserting their email privacy with encryption. Think of it as a form of solidarity.
- ashwagary 4y ago
- jerheinze 4y agoYou can use pluggable transports to camouflage your traffic (they're already built into the Tor Browser, e.g. snowflake, obfs4 ...).
- bitL 4y agoEven if you run it over a VPN connection?
- tylersmith 4y agoYes, you just stand out to the VPN provider instead of your ISP. The VPN traffic itself makes you stand out to your ISP but in a different way.
- goodpoint 4y ago> All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it? No, it isn't rare. Plenty of people use Tor for casual browsing without triggering invasive ads and similar. It just works.
- insanitybit 4y ago> The inescapable fact about Tor is that its traffic patterns make you stand out prominently. I'm curious as to how it stands out. I can imagine a few things, like an ISP seeing traffic to known TOR intermediary nodes, or maybe analyzing packets to look for some sort of handshake? > Just the fact you’re using it automatically makes you interesting and worthy of a closer look. Sort of. But what would looking do? What does looking mean? The traffic is encrypted, they can look all they like. In the US they'll need more than "they connected to TOR" to get a warrant to search your device.
- NoThisIsMe 4y agoI don't know if this is true, but I've read that if you plug in the tracking number for a package at USPS.com through Tor, the package will be flagged for inspection.
- metadat 4y agoSource? Because this reeks of urban myth FUD.
- DoItToMe81 4y agoIt's known from leaks that showing an interest in Tor is enough to get you on an NSA list. But this list was so incredibly broad that anyone with an interest in technology was/is probably on it, diminishing its usefulness to actually discriminate anyone. https://www.propublica.org/article/heres-one-way-to-land-on-the-nsas-watch-list https://www.propublica.org/article/heres-one-way-to-land-on-...
- insanitybit 4y agoI mean how do they do it? In terms of the technology/ fingerprinting approach.
- orthecreedence 4y agoI use it when looking up drugs and medical conditions. If the NSA wants to spend their budget connecting me to searches about sumatriptan or plantar fascitis then that's a useful (useful to me, fuck the NSA) waste of their time. If not, then it creates noise for the rest of the network.
- mdp2021 4y ago> if you’re just maintaining a cookie recipe site on the dark web Some people just want privacy. No need to have an specific "cookie recipe" activity: they would just browse the New York Times, but in full reassurance of anonymity - as they believe is normal. (And by the way: "«brows[ing] the New York Times»" - as a sequence of actions - is not a neutral activity, but already a profiling one.)