3 ms·
Nothing new, and I'm pretty sure these sorts of attacks have been possible and used ever since it's founding. TOR ultimately works like any old relay system; i
by noirscape 2y ago
Nothing new, and I'm pretty sure these sorts of attacks have been possible and used ever since it's founding.
TOR ultimately works like any old relay system; if you control enough nodes, you can effectively decloak people if they happen to connect to only your nodes. Nodes are assigned for connection based on a trust value so all a Nation state would have to do is host enough nodes (relay+exit) and they'd be able to decloak a connection. This kinda inherently gives TOR decloaking abilities to entities with the most infrastructure, which at that scale basically will only be nation states.
TOR works well enough for privacy when your adversaries aren't well-funded state actors. (ie. It's probably enough to mask your traffic if you use TOR to access resources to get out of an abusive relationship or need to circumvent cult-level inspection of your personal interests by religious schools. Most dictatorships also don't really have the resources to mount this sort of attack - it's probably just the US and some European countries.) That rule kinda also goes for VPNs in general however.
- deleted 2y ago[deleted]
- shavanerad 2y agoThere are thousands of relays run by altruistic volunteers. Unless your opsec sucks (i.e. you configure Tor to favor performance and not swap circuits every ten minutes) the opportunity to correlate by malicious nodes is small. Also, these nodes operated by bad actors are constantly identified and excluded.