3 ms·
Using a VPN to connect to Tor can decrease anonymity. The Tor wiki has a whole page about the topic https://gitlab.torproject.org/legacy/trac/-/wikis/doc/TorPlu
by bluesttuesday 4y ago
Using a VPN to connect to Tor can decrease anonymity. The Tor wiki has a whole page about the topic https://gitlab.torproject.org/legacy/trac/-/wikis/doc/TorPlusVPN https://gitlab.torproject.org/legacy/trac/-/wikis/doc/TorPlu...
- sterlind 4y agothe scenario I'm describing is "You -> VPN/SSH -> Tor" and your link says it's a fine idea.
- anonym29 4y agoJust keep in mind that your VPN/SSH provider now has the same visibility your ISP did.
- INeedMoreRam 4y agoUsing a reputable VPN who claims no logs is much better than an ISP who gladly hands over logs.
- anonym29 4y agoUsing a reputable VPN who claims no logs still places immense trust in that VPN provider. If you're a journalist or political dissident, it's possible your life is resting on that trust. Alternatively, You -> ISP -> Tor -> VPN and paying with Monero obtained over Tor without ever having disclosed your ID or any revealing info means: • Your ISP knows who you are, but not what you're doing (no anonymity, yes privacy). The connection to tor establishes privacy from ISP. • Your Tor exit node sees you're connecting to a VPN, but does not know who you are, or what you're doing (yes anonymity, yes privacy). The routing of Tor establishes anonymity, but not privacy from the exit node. The connection to the VPN establishes privacy from the exit node. • Your VPN provider knows a bit about what you're doing, but not who you are (yes anonymity, less privacy) This offers additional protection if your VPN provider is compromised / lying about logging (you have no way to verify at any given moment, only that they weren't in past incidents that have gone to court, but this is no guarantee they can't be compelled to start logging your connections). This also offers additional protection if your guard node and exit node are compromised, which is sufficient to deanonymize tor users. What it does not offer protection against is all ISP's involved selling netflow metadata to a single party who uses timing and packet sizes to correlate traffic across all of these connections, like Team Cymru does with their Pure Signal Recon product (formerly called Augury). If that scares you, I'd encourage you to look up what company actually owns and operates torproject's website, and how many contracts they have with governments, too.
- sterlind 4y agoassume there's an xkeyscore query logging Tor connections within the US. that's easy for the NSA to implement, and seems like something they'd do, and would capture all users directly connecting. now, a foreign VPN isn't going to be connected to the xkeyscore dragnet like Comcast would be. I'm sure the NSA's pwned dozens of VPN providers, but beam-splitting all VPN traffic into a colo'd supercomputer isn't going to be stealthy. the best the NSA could do is watch for outbound connections from the VPN to Tor, then match the connection to your ingress using their access inside the VPN's infra. they can't do that in bulk without the VPN company catching on. that's a capability they'll save for going after individuals. just the fact you connected to Tor isn't suspicious enough to be worth risking burning their backdoor, for them. the point is that connecting to Tor via a VPN keeps you out of the dragnets. and all the VPN provider learns is that you're using them as a gateway into Tor.