4 ms·
It's not a matter of some backdoor. It's a question of whether the idea is fundamentally sound. You're routing your data through several strangers, who are al
by lambda 13y ago
It's not a matter of some backdoor.
It's a question of whether the idea is fundamentally sound.
You're routing your data through several strangers, who are all volunteers and may be individuals who support anonymity or governments who are trying to break it, relying on them discarding logs in order to preserve your anonymity. Since the data is encrypted, and routed between several nodes, you do have some redundancy in place in case one of the middle nodes is an attacker.
However, there are several problems. The data coming out of the exit nodes is unencrypted. Now, everyone advises you to always encrypt anything that will pass through an exit node, but that's not always possible. Some protocols just don't have widely available encrypted versions (like DNS), or even with encryption, where you are connecting to is leaked, as well as some information in things like the TLS handshake that may be de-anonymizing.
There are also lots of ways that data can leak at your endpoint. For instance, many programs may make DNS queries that don't go through Tor, so what you are looking up may be leaked.
Furthermore, Tor doesn't sent data at a constant bitrate. Someone who can monitor traffic on a large portion of the network can correlate it across points.
Finally, due to the nature of routing traffic between several points, a fairly limited number of exit nodes, and the encryption, Tor is fairly slow. So most people won't really be able to use it on a day to day basis, making mere use of it somewhat suspicious, and likely to subject you to more scrutiny.
None of these are fatal flaws, but they are some fundamental weaknesses, and many of them can't really be fully fixed.
I think that focusing on widespread, end-to-end encryption, rather than anonymity service like Tor, would be more valuable. Yes, you will still be vulnerable to metadata monitoring, which is a problem, but it would help a lot more with the content of your communications.
- thex86 13y ago> It's a question of whether the idea is fundamentally sound. The problems it has are clearly discussed in multiple places -- websites, research papers, etc. I don't think it can be more sound than that. > You're routing your data through several strangers, who are all volunteers and may be individuals who support anonymity or governments who are trying to break it, relying on them discarding logs in order to preserve your anonymity. It doesn't matter. That is the entire idea behind Tor. > However, there are several problems. The data coming out of the exit nodes is unencrypted. There are also lots of ways that data can leak at your endpoint. For instance, many programs may make DNS queries that don't go through Tor, so what you are looking up may be leaked. The TBB already takes care of this. So unless you use some crappy third-party browser, you are safe from these problems because they know about it and they have been fixed. Of course the exit node is not something you can trust. But your argument does not always hold true because TBB ships with HTTPS Everywhere by default. So almost all major websites will automatically use HTTPS and therefore the exit node sniffing your connection is rendered useless. Now if you are sending out your information over plain-HTTP, then yes, you will have it compromised. > Furthermore, Tor doesn't sent data at a constant bitrate. Someone who can monitor traffic on a large portion of the network can correlate it across points. Because Tor is a low-latency network, timing analysis is easy to perform if the entry and the exit node are controlled by the same entity. Now this depends on whether the NSA runs Tor exits or not and I cannot answer this question. > Finally, due to the nature of routing traffic between several points, a fairly limited number of exit nodes, and the encryption, Tor is fairly slow. So most people won't really be able to use it on a day to day basis, making mere use of it somewhat suspicious, and likely to subject you to more scrutiny. Anonymity loves diversity. Tor has a diverse userbase and it is getting better. I do not think it is that slow -- surely we can't expect it to be as fast as your normal internet connection -- but it is not bad either. I think FWIW, given what it does and what we need, there is no better solution so I think we might as well stick to it than trusting some proprietary software.
- lambda 13y ago> Now this depends on whether the NSA runs Tor exits or not and I cannot answer this question. If running Tor exit nodes is what is necessary for the NSA to snoop on traffic, why wouldn't they do so? If your security depends on "well, the NSA isn't going to run a service they need to snoop on your traffic", you're doing it wrong. > I think FWIW, given what it does and what we need, there is no better solution so I think we might as well stick to it than trusting some proprietary software. That's not really the choice. It's a question of where your priorities lie. I don't think our biggest threats to privacy are in the NSA monitoring merely who we connect to. For some users, it's a substantial threat; for instance, for protesters in Iran, it may be a big problem, and for them Tor is invaluable (especially since it's unlikely that the Iranian government has the same resources to attack Tor that the NSA does). Instead, our biggest (technical, as opposed to political or social) threats to privacy lie in a few places: 1) Email. Email has all kinds of problems (it's not verifiable, no good identity management, spam, and it's unencrypted in transit in many of its hops). 2) Google, Facebook, Yahoo, Twitter, etc. Big, closed services, that lock you in, and provide centralized places for monitoring. For many people in my social circles, Facebook is their primary means of online communication. 3) Web tracking: cookies and other web de-anonymization techniques 4) Unencrypted HTTP 5) Identity on the web. Almost every account you create requires an email address, which can trivially be used by the NSA to correlate data between accounts. Anonymous email services can be used to fight this, but managing databases of email addresses, usernames, and passwords to preserve anonymity is beyond most people's capabilities. The solutions to this are mostly to use one of the big services for login, which of course down't solve the anonymity problem at all. 6) The phone system. Telecoms have demonstrated repeatedly that they're more than willing to hand your data over without a court order. Tech companies at least act embarrassed about it in public; phone companies just lobby for retroactive immunity to keep themselves safe from their customers. There may be more that I'm not thinking of, but those are some of the biggest. Tor does very little to protect you from these kinds of threats. All it protects you from is someone monitoring who you are connecting to; but if most of the traffic they are interested in is to Google or Facebook, they don't need to attack it by monitoring your connection, they can just get the data straight from the endpoint. I think that the biggest things we need, to preserve privacy, are replacements for many of the above problems, that even our grandmothers can use. Sure, a few privacy conscious geeks, a few Iranian protesters, some online griefers, some drug dealers, and some pedophiles can take advantage of Tor. It provides a useful service for some, but a fairly small portion, of people. Getting ubiquitous encryption, better key management and identity management, a return to federated or peer-to-peer services rather than a few large centralized players, and getting all of that widely deployed and usable by your grandparents, are what we want to really improve privacy and security.
- Zuider 13y ago>. Some protocols just don't have widely available encrypted versions (like DNS)... DNSCrypt encrypts communication between the user and the OpenDNS servers. http://www.opendns.com/technology/dnscrypt/ http://www.opendns.com/technology/dnscrypt/