3 ms·
> Now this depends on whether the NSA runs Tor exits or not and I cannot answer this question. If running Tor exit nodes is what is necessary for the NSA to sn
by lambda 13y ago
> Now this depends on whether the NSA runs Tor exits or not and I cannot answer this question.
If running Tor exit nodes is what is necessary for the NSA to snoop on traffic, why wouldn't they do so?
If your security depends on "well, the NSA isn't going to run a service they need to snoop on your traffic", you're doing it wrong.
> I think FWIW, given what it does and what we need, there is no better solution so I think we might as well stick to it than trusting some proprietary software.
That's not really the choice. It's a question of where your priorities lie.
I don't think our biggest threats to privacy are in the NSA monitoring merely who we connect to. For some users, it's a substantial threat; for instance, for protesters in Iran, it may be a big problem, and for them Tor is invaluable (especially since it's unlikely that the Iranian government has the same resources to attack Tor that the NSA does).
Instead, our biggest (technical, as opposed to political or social) threats to privacy lie in a few places:
1) Email. Email has all kinds of problems (it's not verifiable, no good identity management, spam, and it's unencrypted in transit in many of its hops).
2) Google, Facebook, Yahoo, Twitter, etc. Big, closed services, that lock you in, and provide centralized places for monitoring. For many people in my social circles, Facebook is their primary means of online communication.
3) Web tracking: cookies and other web de-anonymization techniques
4) Unencrypted HTTP
5) Identity on the web. Almost every account you create requires an email address, which can trivially be used by the NSA to correlate data between accounts. Anonymous email services can be used to fight this, but managing databases of email addresses, usernames, and passwords to preserve anonymity is beyond most people's capabilities. The solutions to this are mostly to use one of the big services for login, which of course down't solve the anonymity problem at all.
6) The phone system. Telecoms have demonstrated repeatedly that they're more than willing to hand your data over without a court order. Tech companies at least act embarrassed about it in public; phone companies just lobby for retroactive immunity to keep themselves safe from their customers.
There may be more that I'm not thinking of, but those are some of the biggest.
Tor does very little to protect you from these kinds of threats. All it protects you from is someone monitoring who you are connecting to; but if most of the traffic they are interested in is to Google or Facebook, they don't need to attack it by monitoring your connection, they can just get the data straight from the endpoint.
I think that the biggest things we need, to preserve privacy, are replacements for many of the above problems, that even our grandmothers can use. Sure, a few privacy conscious geeks, a few Iranian protesters, some online griefers, some drug dealers, and some pedophiles can take advantage of Tor. It provides a useful service for some, but a fairly small portion, of people.
Getting ubiquitous encryption, better key management and identity management, a return to federated or peer-to-peer services rather than a few large centralized players, and getting all of that widely deployed and usable by your grandparents, are what we want to really improve privacy and security.