7 ms·
How Secure is Tor? Not secure at all
- emeryberger 1y agoThe Tor Project web site makes a bold claim to its users: "Tor Browser prevents someone watching your connection from knowing what websites you visit. All anyone monitoring your browsing habits can see is that you're using Tor." Don't misinterpret this claim. It's not true that Tor protects you against "anyone monitoring your browsing". On this web page, I provide you with the critical information missing from the Tor Project's website: if you estimate your adversary's resources in dollars, I'll estimated the probability that Tor will fail to protect you. (web site by Brian Levine, Professor at UMass Amherst <https://www.cics.umass.edu/about/directory/brian-levine https://www.cics.umass.edu/about/directory/brian-levine> and director of Rescue Lab <https://www.rescue-lab.org/ https://www.rescue-lab.org/>)
- ranger_danger 1y ago> Why has the Tor Project created a network used extensively for child sexual abuse Hottest take of the week right there. Why do they seem to imply that Tor was somehow created explicitly with this purpose in mind? That's like saying only criminals use the Internet, just because it can be used to commit crimes. I think they are taking Tor's words and applying it to a much broader scope than they originally intended. > Tor Browser prevents someone watching your connection from knowing what websites you visit. If someone is watching only your connection as it exits your local ISP and nothing else, then yes, this is in fact true. It's just not articulated that plainly. But if the author actually went as far as they are trying to, they might as well tell people to just give up because there's a chance your attacker already controls the destination server you're talking to in the first place. If you're going to the trouble of trying to calculate the chances that nodes in the middle are compromised, why not include the destination itself too? > The small set of people that centrally control Tor software and centrally manage the Tor network have the power to act to stop this abuse without lessening their (weak) protections. Source: trust me bro > The world's standards for encrypting data are so secure that no one has enough money or time to brute force their way into properly encrypted data, not even governments. They are better off waiting for a scientific breakthrough that may never come. This completely disregards the possibility that any one of a number of root CAs aren't already compromised or cannot be coerced by your attacker. If you're going to claim tor is insecure, you might as well go all the way and say it's pointless to use anything at all, ever.
- deleted 1y ago[deleted]
- nickdurfe 1y ago> Why has the US created a highway system used extensively for causing death?
- ranger_danger 1y agoReminds me of https://0x0.st/XJZT.jpg https://0x0.st/XJZT.jpg
- bnl_umass 1y agoMy apologies. I don’t believe that was their intent to create a network for csam. But after decades of it being used extensively for csam, why would they take no corrective action?
- ranger_danger 1y agoMaybe because there isn't a known solution? CSAM is still distributed on the clearnet too... why isn't there a "solution" for that too? So far the only solutions people seem to have come up with is mass surveillance, and that's not an option.
- bnl_umass 1y agoThere is a known solution. Did you know that the Tor Project allows exit nodes to filter based on the clear internet IP. So filtering is ok. However, if a relay refuses to service an onion site directory look up, it will be banned by the Directory Authority. They could allow this today. But they don’t. That’s the simple solution. No surveillance. Not back door. No less privacy for everyone else. edit: This is easy to confirm. I’m not asking anyone to trust me.
- ranger_danger 1y agoExit nodes are not used for onion services. From https://onionservices.torproject.org/technology/properties/ https://onionservices.torproject.org/technology/properties/: > For the Tor network, Onion Services can alleviate the load on exit nodes, since it's connections don't need to reach the exits. Also: > Directory Authority. "These authorities are operated by trusted organizations or individuals with a strong commitment to the principles of privacy, security, and network neutrality." Emphasis on neutrality... it's not the job of network operators to police the sites people can and can't access, this is exactly why many people use Tor in the first place. > They could allow this today. But they don’t. Speaking for onion services... no, they cannot, because the entire design of the tor network prevents this in the first place. No relay in the circuit knows the final destination because it is encrypted multiple times (like an onion) and each hop can only see where it needs to go next, not what the destination is.
- leakycap 1y agoI'm not here to defend Tor But the calculator states that if the investigating party has $150,000 a month budget for all targets they have a 100% certainty of getting your IP address... obviously this is false, so what else has the author claimed that is also not true?
- saithound 1y agoPretty much everything claimed on this site is false or grossly misleading.
- bnl_umass 1y agoReally? Tell me why.
- saithound 1y agoThe primary claims of the site, both made without any evidence (presumably by you), are that 1. Tor is primarily used to distribute CSAM, 2. a single organization with a budget of $150k could deanonymize every Tor user simultaneously. Since pretty much every firat world law enforcement organization can cough up this amount in spare budget, either - at least one of the claims above is false; or - there's a global conspiracy involving every major law enforcement organization in the planet being taken over by pedos. In fact, both claims (you?) made without evidence are simply false. Having published calculations for the second claim is like having published calculations for "the Sun went supernova yesterday". The conclusion is blatantly wrong, so the calculations have a mistake, and an intellectually honest author would double check them, find that mistake, then retract the claim (or would not have made it in the first place).
- bnl_umass 1y ago1. I said “extensively” used for csam. What’s my source/evidence for that claim? This list of peer reviewed papers, cases, and government reports: https://csam-bib.github.io https://csam-bib.github.io. 2. My site shows a mathematical model of security that Tor provides in terms of its design for relays alone. I say on the site I’m not including staff and other costs. In fact bringing someone to court is a further cost. My point in making the site is to quantify solely the costs that the design brings to the table. You can then compare that design to some other anonymous system. Or compare it to a doublespend attack on bitcoin or to brute force decryption. That’s important for users. Unlike the Tor Project, I’m being transparent by showing assumptions, the math, and the code. Do you have a better model? Great, then publish it. I’m trying to start a formal conversation. The Tor Project should be relying on science, and not strong assertions, to ensure its security. And while there are costs to, say, bring someone to court for csam, do you believe all adversaries are going to do that? That’s why it’s not part of the costs I model. Finally, to be more clear, Onion Services in particular are the problem when it comes to CSAM (and ransomeware). Tor Browser is not the issue when it comes to CSAM.
- giantg2 1y ago"As C3P will tell you: CSAM distribution on Tor onion services is not inevitable." Lol, are we using the regular internet as an example of preventing all CSAM? We've known for years that owning enough nodes results in the compromise of privacy and that it's likely the NSA has achieved this. Although there is some question around how that plays out if adversaries like China are also competing for similar node share percentage.
- bnl_umass 1y agoThere is no question about that. The site makes use of current statistics from the Tor Project.
- datadrivenangel 1y agoAs a percent of onion services, what does it work out to, a few percent? And how much of that is dedicated abuse sites versus general adult sites?
- neutered_knot 1y agoYour question made me curious so I tried to see what information about onion sites is available. It’s hard to measure onions sites by design, but https://99firms.com/research/tor-stats https://99firms.com/research/tor-stats Says there seem to be about 65k onion sites. This site: https://protectchildren.ca/en/press-and-media/blog/2025/tor-backgrounder https://protectchildren.ca/en/press-and-media/blog/2025/tor-... Has some varying numbers depending on the observation time, but in final month listed saw 30k sites that had they identified as having CSAM. I’m not sure how accurate either number is or if they are directly comparable but that would be a 50% of all onion sites ballpark. Not sure how to measure general sites vs dedicated abuse sites.
- datadrivenangel 1y agoLooks like the tor metrics site says ~900k onion sites? https://metrics.torproject.org/hidserv-dir-v3-onions-seen.html https://metrics.torproject.org/hidserv-dir-v3-onions-seen.ht...
- datadrivenangel 1y agoIf an adversary is spending tens or hundreds of thousands of dollars to find you, that's a lift that most threat actors won't be able to do. Especially if they have to host a significant number of exit nodes for a lengthy period, which often means serving unlawful content which is very awkward for law enforcement. It's definitely better than regular browsing for security, but it's not perfect.
- _alternator_ 1y agoUnfortunately, the money isn't just to find "you". You rent arbitrary exit nodes, and if you spend ~$30k / month, you'll be able to deanonimize >50% of users using Tor each month.
- neutered_knot 1y agoIt’s a drop in the bucket for state actors who might want to find TORs target user base of dissidents, whistleblowers, and journalists.
- iamnothere 1y agoIt’s extremely unlikely that they would be able to find an end user (not an onion site operator, a user) with good opsec who connects occasionally, such as a journalist uploading a few documents to a secure onion drop. All existing known attacks were against onion site operators running for long periods from a static location (still took a lot of resources and time to track them down) or end users with poor opsec/infosec. The whole thing reads as scaremongering FUD to prevent people from using Tor, with further FUD tacked on to make people think that using it might be illegal somehow. Tor is actually great for personal infrastructure (no need for domain names or a static IP), limited anonymity, and censorship resistance.
- neutered_knot 1y agoThe site linked takes a shot at enumerating how unlikely it is. Do you claim it is wrong? If so, what is your calculated chance? To me, TOR is not adequate to protect users targeted by a nation state who are the ones that TOR claims to be created for.
- superfishy 1y ago"The small set of people that centrally control Tor software and centrally manage the Tor network have the power to act to stop this abuse without lessening their (weak) protections." That the author has received funding from the DOJ makes me wonder what their proposed solution is.
- basedrum 1y agoClickbait title is usually a good indicator of clickbait content. I see in the comments that the author is an academic, my cursory look of the site makes me disappointed to see such weak rigor applied here. This looks like a hit piece dressed up to sound scary. Not going to waste my time further on its claims when on the surface its given me this impression. Strikes me as yelling and not listening type of personality.
- roncesvalles 1y agoI wouldn't use Tor or any other anonymous services like SecureDrop without a VPN (preferably multi-hop). Otherwise you're advertising to the world that your IP address uses Tor, and that alone can be a huge reduction in the solution space for your adversary to deanoymize you.
- IAmBroom 1y agoI agree, but we are both first-world privileged. How exactly does someone in China or North Korea go about getting a multi-hop VPN to access Tor?
- Gathering6678 1y agoCorrect me if I'm wrong, but this feels like a long-winded way of saying: if an adversary could control a significant portion of relays without being found out and for a not-insignificant period of time, it could defeat Tor. Is it correct? Probably. Does it justify the "Not secure at all" indictment? No.
- Gathering6678 1y agoThe calculator also misleads in another direction, in that it could underestimate the probability of failure by only considering the "takeover" scenario, while I think it is much more likely to be defeated via other OpSec failures.
- bnl_umass 1y agoThe “conclusions” section of the site makes this same point.
- bnl_umass 1y agoThe website actually states “not very secure at all”. This hacker news submission changed the title.