4 ms·
No, you only need to compromise the first node – named the entry guard for that reason [1] – and either the exit node or ideally the endpoint (hidden) service.
by throwaway89201 3y ago
No, you only need to compromise the first node – named the entry guard for that reason [1] – and either the exit node or ideally the endpoint (hidden) service. Deanonymization is then possible by correlating the timing of traffic between those two points, as Tor wants to be low-latency, without randomly delaying traffic.
For this reason not all nodes may be guard nodes, as decided by the directory authorities, and guard nodes are maintained for a longer time by the client to reduce the chance that you pick a compromised guard node because you switch often. This is balanced against the risk that you are unlucky and pick a compromised guard at first (which you then maintain for a longer time).
The exit node is pretty much assumed to be compromised, as it's a role not available to many entities – it requires high bandwidth and much teeth-gritting – and the public internet is intercepted at large anyway.
[1] https://support.torproject.org/about/entry-guards/ https://support.torproject.org/about/entry-guards/