3 ms·
Why would you put TOR behind a VPN? That just increases the surface area for attack.
by noodleman 4y ago
Why would you put TOR behind a VPN? That just increases the surface area for attack.
- TechBro8615 4y agoIt does add another entity who can identify you (your VPN provider), but it doesn't strictly increase the surface area, since it avoids passive surveillance tripwires at your ISP looking for "interesting" traffic like active connections to Tor nodes. Now, if your ISP is monitoring Tor connections, they're probably monitoring VPN connections too. But at this point VPN services like Apple Private Relay are so commonplace that it's not too unusual to route all your traffic through a WireGuard endpoint. So the burden of surveillance shifts to your VPN provider, who may be worse or better than your ISP in terms of keeping logs, respecting privacy and responding to subpoenas. Note that "VPN provider" could refer to any entity who is next in the connection chain after your ISP. That could be some public VPN providers like Cloudflare or Apple Private Relay (which is run by Cloudflare and Akamai). Or, if you host your own VPN, it could be your VPS provider. If your goal is to blend in, you probably want to use the public VPN provider where exit IP addresses are (theoretically) shared between a (limited) number of users at any given time. Whereas a VPN on your own box will have an exit IP that is uniquely attributable to you, making you not only easier to trace, but also easier to hack, through any vulnerabilities you might have introduced when setting up the server.