4 ms·
There's a lot in the book about this - it depends what you mean. Tor has a lot of social and technical design elements that try as best they can to minimise thi
by susan_segfault 2y ago
There's a lot in the book about this - it depends what you mean. Tor has a lot of social and technical design elements that try as best they can to minimise this risk. It would be pretty hard for intelligence services to compromise the Tor organisation in ways that meant they were deploying malicious code, for example. Plus, the way it's grown over the years has also given them some protections.
In terms of deanonymising people through surveillance (for example, by spying on the whole Internet and tracing you through the Tor network), Tor explicitly doesn't protect you against this. The decision was made early on - they switched all the high-security design elements to 'off' to make the network faster. They calculated that a hyper-secure network that was so slow no-one used it was less secure - i.e. made less privacy exist in the real world - than one that was less secure but used by millions, because that would give you a huge crowd of people to hide in. This gets really complicated - because you also want lots of different kinds of people using the network, so they can't tell if you're a drug dealer, an activist, a spy etc. just because you're using Tor.
Individual bits of major intelligence organisations can probably deanonymise you at some times, and not at others. The real question is if they can do so in a way that's dangerous to you in a sustained way, and if it's actually useful for them to do this. Usually, it's easier to do this through simpler mechanisms (bribing your friends, putting a camera in your bedroom, figuring out who you are etc.) than compromising the Tor network. Some security services absolutely will be researching and developing ways to deanonymise larrge numbers of Tor users at a given time - but in general, the budget for this is going to be quite high on a per-user basis (so you'd have to be a prime target for it to be worth it), and a lot of the complexity of the Internet geography makes this quite hard itself.
Ultimately, for any given high value target, there are usually easier ways to get them than through breaking Tor. In almost every case, a person will make a basic OPSEC error long before mass-scale traffic analysis gets them.
- htrp 2y agoThe rubber hose cyptography xocd comes to mind https://xkcd.com/538/ https://xkcd.com/538/
- generalizations 2y agoThe scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.
- jazzyjackson 2y ago"don't become an enemy of the state" is my go-to security posture
- geraldhh 2y agosame, though there are ppl that become so by chance or occupation
- generalizations 2y agoI mean, the upstream question we're discussing is whether tor is appropriate if your threat model includes state actors.
- barbariangrunge 2y agoWhat about whistleblowers?
- llmblockchain 2y ago"don't become an enemy of any state" which is a little trickier.
- belorn 2y agoControlling a large fraction of tor nodes is possible, but there is a large cost associated with it. Tor has a reputation system when it comes to nodes, and in order to gain a large fraction of tor nodes you need to continuously have a presence for a long period of time. Having such long term presence also risk gaining visibility and become detected, and require good and consistent secops. As the network expands this also mean the attacker need to expand in equal rate. It is a assumed vulnerability of the network. The biggest question is if any state actor would consider it economical to do it compared to alternative methods. Personally I suspect that it is actually cheaper to have visibility into the entire internet, since that method bring value beyond tor and you do not need major secops to pull it off.
- deleted 2y ago[deleted]
- keepamovin 2y agoOne gap seems to be provision of HTTPS for onions. LetsEncrypt should really get on this. Aligns well with their mission right?