12 ms·
Things You Should Know About Tor
- paletoy 12y agoThis isn't accurate. It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that.
- majke 12y agoThis is not factually correct. If you use tor correctly (https everywhere, don't leak cookies) you can be pretty safe. I'm fairly sure I know what I'm talking about, but feel free to point to some articles and I will try to explain one by one what Tor can and what it can't do. Here, some links on Tor operational security, do read them carefully: - https://www.torproject.org/download/download#warning https://www.torproject.org/download/download#warning - http://cryptome.org/0005/tor-opsec.htm http://cryptome.org/0005/tor-opsec.htm - the server side: https://trac.torproject.org/projects/tor/wiki/doc/OperationalSecurity https://trac.torproject.org/projects/tor/wiki/doc/Operationa...
- paletoy 12y agohttp://dl.acm.org/citation.cfm?id=2516651 http://dl.acm.org/citation.cfm?id=2516651 Full article is at : http://web.elastic.org/~fche/mirrors/www.jya.com/2013/09/tor-users-routed-slides.pdf http://web.elastic.org/~fche/mirrors/www.jya.com/2013/09/tor... And i've read other work that talks about using machine leanring to create realistic attacks, and another by a guy that even deanonimized some anonymous remailers. And let's not forget most implemented protocols like tls have bugs. A somewhat pessimistic view would probably say that the only protection you get is that the nsa doesn't use this capability too often, because it doesn't want to expose it.
- tedks 12y agoAs of the Snowden-leaked documents creation (so at least 2006-2009), the NSA was not, in fact, using that capability at all. Nor was the FBI or DEA in a recent high-profile case against a certain Tor hidden website. Nor were international LEAs going after Freedom Hosting. Also note that the final author on the Users Get Routed paper is Paul Syverson, inventor of onion routing and still an active Tor designer. Academic attacks are pretty common against Tor because Tor is the most serious and therefore most well-studied anonymity system. Most of them aren't feasible in the real world regardless of what the abstracts say.
- majke 12y agoOr even better, the full paper: http://cryptome.org/2013/08/tor-users-routed.pdf http://cryptome.org/2013/08/tor-users-routed.pdf And from 2009: https://blog.torproject.org/blog/one-cell-enough https://blog.torproject.org/blog/one-cell-enough > The Tor design doesn't try to protect against an attacker who can see or measure both traffic going into the Tor network and also traffic coming out of the Tor network. That's because if you can see both flows, some simple statistics let you decide whether they match up. Because we aim to let people browse the web, we can't afford the extra overhead and hours of additional delay that are used in high-latency mix networks like Mixmaster or Mixminion to slow this attack. That's why Tor's security is all about trying to decrease the chances that an adversary will end up in the right positions to see the traffic flows. Well yeah, that sucks. Correlation attacks are a real threat. If an adversary controls both entry and exit, they can correlate. I personally don't think NSA are doing it (yet!) but that's a speculation. I still claim your statement is incorrect: > It doesn't mention that the u.s government can in very high likelihood de-anonimize users , sometimes even without cooperation from foreign governments , and sometimes even ISP's can do that. Correlation attacks are a real threat but if they are "high likelihood" it only depends on your path selection and use case. Rotate your paths, don't use bittorrent, choose entry and exit points wisely. > A somewhat pessimistic view would probably say ... A somewhat optimistic view would say: the tools are there, use them, use them wisely! Using tor is still _so much_ better for anonymity than pretty much anything else.
- deleted 12y ago[deleted]
- A_COMPUTER 12y agoThere are numerous problems with anonymizing remailers none of which have anything to do with Tor whatsoever. The two main problems are that there are not enough nodes (between three and six running at any particular time) and their protocol is overly complicated and implementations are bug-ridden, leading to mistakes that leak information.
- stephen_g 12y agoA passive observer that is as big as NSA/GCHQ etc. can correlate traffic to de-anonomise some traffic, some very small amount of the time. It is extremely unlikely that a single ISP would ever have enough information to do that though.
- majke 12y agoa) http://www.washingtonpost.com/blogs/the-switch/wp/2013/10/04/everything-you-need-to-know-about-the-nsa-and-tor-in-one-faq/ http://www.washingtonpost.com/blogs/the-switch/wp/2013/10/04... > "With manual analysis we can de-anonymize a very small fraction of Tor users." > "We will never be able to de-anonymize all Tor users all the time" b) https://www.schneier.com/blog/archives/2013/10/how_the_nsa_att.html https://www.schneier.com/blog/archives/2013/10/how_the_nsa_a... > Tor is a well-designed and robust anonymity tool, and successfully attacking it is difficult. The NSA attacks we found individually target Tor users by exploiting vulnerabilities in their Firefox browsers, and not the Tor application directly.
- tedks 12y agoEven the NSA has to deal with the base rate fallacy. You can't just magically "correlate" traffic.
- RachelF 12y agoIt is hard, perhaps, but a good attack for the NSA would be to run many of the exit nodes. The intelligence gathered this way would be very valuable, as the traffic on the TOR network is has a much higher intelligence value. This is because it is used by those trying to hide something, something which the NSA may like to know.
- Scoundreller 12y agoThings I've used Tor for: - Accessing BBC Liveplayer as if I'm in England (using lots of normally discouraged add-ons and defined exit-nodes) - Bypassing paywalls (possibly still criminal?) - Bypassing censorship (which is what it really is) on organizational wifi networks (in Canadian hospitals). The funniest block was to ginger.io, a big data smartphone data analysis play (but blocked by an over-aggressive filter for obvious reasons). Does anyone else have some unexpected/interesting use cases?
- tedks 12y agoI use Tor hidden services to punch through NATs (mostly for SSH); it's also useful in that only you can access the service (since only you know its address), so a hidden service + random port is a cheap "port knocking" implementation. I've also used Tor to debug firewalls. It's a good way of saying "put me in a random spot on the Internet." Outside of that, I use Tor for whatever I can: downloading RSS feeds, instant messaging, downloading email, mostly. There's no reason not to have Tor on these things because they're all either batched or tolerant of bad latency, and it destroys a little bit of my personal information that would otherwise leak.
- unsignedint 12y agoI find Hidden Services useful, too. It's a simple way to experiment without an IP address, etc. I use it in a container, works great. https://registry.hub.docker.com/u/hsaito/torbox-hidden/ https://registry.hub.docker.com/u/hsaito/torbox-hidden/
- zaroth 12y agoThe onion addresses of hidden services are not themselves secret. The onion address is in fact well known, published in the directory. It's only your server's IP that a hidden service is hiding. So please, don't treat knowledge of the onion address itself as a secret! You still have to authenticate to your service in some way.
- mct 12y ago
- lsh123 12y ago"It is also important to remember that if you log into services like Google and Facebook over Tor, you will be sacrificing your anonymity to those services." It is important to note that both Google and FB can track you on 3rd party websites through things like "Like" button. Consider disabling 3rd party cookies completely or using plugins like Ghostery.
- deleted 12y ago[deleted]
- spenvo 12y ago> like Ghostery Ghostery is great but lacking in some respects, check out the https://www.eff.org/privacybadger https://www.eff.org/privacybadger project
- lsh123 12y agoI am actually running both of them side-by-side (together with ABP and a few other plugins). So far, I find Ghostery to be blocking more than Privacy Badger does.
- donniezazen 12y agoI have always wondered about that. What if I completely switch all my network traffic to Tor continue using all the services as I currently do? What are the implications involved here?
- thejdude 12y agoI've been browsing the internet for 15 years with 3rd-party cookies disabled. I never had ANY problems with any website - no idea if there would have been more functionality with 3rd-party cookies enabled. But then again, how can functionality depend on THIRD parties? Also activated the setting for my girlfriend years ago, no complaints so far. This feature should really be the default for any browser and any user. Too bad Android Chrome doesn't have such a setting. Too bad for Google I'll use something else instead.
- 12y ago
- frozenport 12y agoIn addition to not being a criminal you might be a government agent working in a hostile country.
- Istof 12y agoalso, you might not be a government agent working in a hostile country (in addition to not being a criminal)
- cottonseed 12y agoI had been meaning to run a Tor relay for a while. The EFF Tor Challenge [0] motivated me to get it done. It was incredibly easy. If you have a VPS with unused bandwidth, please consider taking a few minutes to set up a Tor relay. [0] https://www.eff.org/torchallenge/ https://www.eff.org/torchallenge/
- iamtew 12y agoKeep in mind though when setting this up to take a close look at your exit policy settings, to ensure you only route the traffic you want and where you want it. I span up a relay at home to play around with, but just skimmed over the exit policy settings and ended up running an exit node. Not big deal really, as it was only advertised for about 14 hours before I noticed and disabled it. It was only after a few weeks when my girlfriend was complaining she kept getting messages from websites refusing to show her content on the basis that she was connecting over the Tor network (which she wasn't) that I realised my home IP was blacklisted, and it took a while for me to get a new lease and IP. I'm not telling people to not run exit nodes, but people shouldn't just go and spin up a Tor relay with default settings, because it will by default run as an exit node, and depending on the hosting provider, this may or may not be an issue.
- FedRegister 12y agoAs I recall, best practice for running an exit node at home (if you want to do it) is to have a separate Internet connection for it. That way you keep your traffic separate from the exit node traffic.
- untrothy 12y agoMy distro's tor setup (arch in this case) should default to not being an exit node, relevant default lines in the torrc: ExitPolicy accept *:6660-6667,reject *:* # allow irc ports but no more ExitPolicy accept *:119 # accept nntp as well as default exit policy ExitPolicy reject *:* # no exits allowed Installing via `pacman -S tor` and enabling via `systemctl enable tor.service` doesn't start an exit node / relay but a simple client. Are you using linux, windows or osx?
- csandreasen 12y agoI'm probably going to take some flack for this, but I don't trust Tor. When you access Tor, you're masking your origin IP to the remote address by trusting one of a couple hundred volunteer exit nodes who raised their hands and said "Trust me! You can route all of your internet traffic through me and I promise I won't monitor or inject anything..." I think most Tor users don't have an adequate understanding of the threat model. It doesn't help that the Tor Project has at times upsold the anonymity provided to a ludicrous extent[1] (to be fair, they do address the risk in their FAQ[2]). Is it more likely that that Comcast will MITM me, or some random exit node? I might expect Comcast to maybe inject an ad into an HTTP connection or do some DNS redirect to shoot me an advertisement, but I don't worry about them stealing my credit card or injecting a buffer overflow or something. In fact, they have a profit incentive to not do so. I don't have that guarantee with a random exit node. It might be a generous privacy advocate, or it might be someone who has more nefarious profit incentive in mind[3]. If you're only connecting through Tor just to avoid the NSA, then you have to assume that both a) the NSA is targeting you to begin with, and b) that exit node you're going through isn't controlled by the NSA (or GCHQ/FSB/PLA/etc). sslstrip[4] undermines the prospect of protecting yourself by connecting solely over SSL through Tor. Even then, in my experience more than half of the sites I visit don't support SSL to begin with. The HTTPS Everywhere plugin that EFF provides and is included in the Tor Browser Bundle is implemented backwards - it connects over SSL only when the site matches a whitelist[5] (I use KB SSL Enforcer on Chrome myself). Sorry if this came off as a rant - I just see too many articles like this that prop up Tor as a silver bullet without discussing the risks and establishing an adequate threat model that allows the user to make an informed decision regarding the risks/benefits of using Tor. [1] http://betaboston.com/news/2014/05/07/as-domestic-abuse-goes-digital-shelters-turn-to-counter-surveillance-with-tor/ http://betaboston.com/news/2014/05/07/as-domestic-abuse-goes... [2] https://www.torproject.org/docs/faq.html.en#AttacksOnOnionRouting https://www.torproject.org/docs/faq.html.en#AttacksOnOnionRo... [3] http://threatpost.com/small-number-of-malicious-tor-exit-relays-snooping-on-traffic http://threatpost.com/small-number-of-malicious-tor-exit-rel... [4] https://www.youtube.com/watch?v=ibF36Yyeehw https://www.youtube.com/watch?v=ibF36Yyeehw [5] https://www.eff.org/https-everywhere/faq https://www.eff.org/https-everywhere/faq
- totoroisalive 12y ago
- mschuster91 12y agoTails is not fool-proof when it comes to determining the IP address of a Tor user. A live CD would not have helped any FreedomHosting victim. The only way to do secure TOR is to use a distinct machine (NOT a VM!) as a gateway.
- dublinben 12y ago>A live CD would not have helped any FreedomHosting victim. Yes it would have. That attack relied on both a Windows-specific vulnerability, and accessing the internet without Tor. Neither would have happened to a user of Tails.
- sirdogealot 12y ago>They have been able to compromise certain Tor users in specific situations. Historically this has been done by finding an exploit for the Tor Browser Bundle or by exploiting a user that has misconfigured Tor. I'm not touching TOR until I figure out how they managed to capture Ross Ulbricht. I highly doubt that he had his TOR misconfigured.
- cLeEOGPw 12y agoHe exposed his email address containing his name as a contact email for silkroad business, so he pretty much gave himself in. With that kind of "attention to details", I wouldn't be surprised if he even had misconfigured TOR.
- hendersoon 12y agoNot exactly. He exposed his email address as a contact for bitcoin related development, then used the same username some time later as one of the first people to _discuss_ silk road. It's a tenuous connection at best, but this seemingly minor opsec lapse gave the investigators a hint to follow.
- woniesong 12y agoWould there be consequences in using Tor on HN?
- throwaway2048 12y agoestablished accounts are allowed to use tor on HN. If you make an account over tor, its posts will be killed for two weeks, then it will be a normal account.
- rsync 12y agoTor is currently funded by the US government. Any list of things you should know about tor should include that.
- growupkids 12y agoWhich is a half truth at best, the list of sponsors includes far more than the US government, including non-govt bodies, and 4300 individuals: https://www.torproject.org/about/sponsors.html.en https://www.torproject.org/about/sponsors.html.en
- pekk 12y agoSay what you will about the US government, but you could do worse as far as sinister sponsorship.
- middleclick 12y agoThe protocol and the code is open. It doesn't matter who funds it, but let it be also clear that the US government is one of the funders. Also, the government is not one coherent entity that all of its bodies want to spy on people.
- jonnybgood 12y agoI guess we should also should include that with every Linux kernel release too. The US government has funded a lot of publicly available security technology that you may not even be aware of, even through the NSA (SELinux). It is a good thing the US government supports these things.
- higherpurpose 12y agoI agree Tor isn't as slow as many think. It's just slightly slower. My biggest problem with Tor, though, is having to enable Javascript even for common tasks, like logging in to Reddit, which hopefully they aren't doing on purpose, considering Reddit is known for a site where you can use pseudonyms as much as you want.
- SquareWheel 12y agoHave you tried https://ssl.reddit.com/login https://ssl.reddit.com/login?
- cowbell 12y agoHow did the feds locate freedom hosting? How did the feds take down silk road? The "tor stinks" slide was over a year old when these events occurred. A lot can change in a year.
- AJ007 12y agoNo matter what pipe communication comes through, a machine is not immune to security vulnerabilities and exploits.
- stephen_g 12y agoDidn't the feds take down Silk Road because the owner paid a cop posing as a hitman to kill someone? Also, there is a problem where hidden services can be enumerated by scanning IPs. With IPv4, it is practical for a well connected entity to scan the entire internet and search for hidden services, making it possible to match to IPs. This is only an issue for people running hidden services, not Tor users.
- quasque 12y agoHidden services can't be located in that manner unless the owner has badly misconfigured the service so it's reachable by IP address. A typical configuration would have the service listening on 127.0.0.1 or a private (RFC 1918) network address only, and have Tor connect to that.
- deleted 12y ago[deleted]
- cooperq 12y agoI specifically addressed this in the article. The feds located freedom hosting by using an exploit in Firefox which was able to deanonymize users. I don't know enough about the silk road case, but it seems probable that traffic correlation was used in that case. I agree that things can change in a year, but the essential point that Tor is not cryptographically broken is still true, IMO.
- 12y ago
- runn1ng 12y agoI actually tried to get Tor relay working. It ate all my monthly bandwidth limit within an hour. By simple analysis I found out it's mostly BitTorrent traffic, but I didn't dig very deep so I might be wrong. I would love to run a Tor relay, but I just do not have unlimited bandwidth to do that.
- maest 12y agoIt would seem there is more demand than supply when it comes to Tor relays. If there were a safe, anonymous way to pay for using Tor relays (Torcoin?), then there would be a lot more incentives to have people run relays. That means the speed will be bumped up and at one point there will be an equilibrium between supply and demand. The system might also provide preferential treatment to users who are willing to pay more. Discuss.
- deathcakes 12y agoThere is an option in the config to limit the amount of bandwidth used by the relay. BandwidthRate N bytes|KBytes|MBytes|GBytes In combination with accounting you can limit monthly or daily usage - has to be over 30kb/s to be usable by the network, so may not be feasible, but worth knowing.
- pmorici 12y ago"4. No One in the US Has Been Prosecuted For Running a Tor Relay" That's a bit of a misleading statement. I'll agree that there haven't been any people prosecuted because they ran a TOR relay directly but there has been at least one case where they prosecuted or at least harassed a guy on child pornography charges because he was running a TOR exit node and saw the activity coming from his IP. Perhaps that wasn't in the US but still.
- hackerboos 12y agoNote it says 'in the US' because they have been prosecuted successfully in Austria. https://rdns.im/court-official-statement-part-1 https://rdns.im/court-official-statement-part-1
- hendersoon 12y agoI have a very strong suspicion that Tor is completely compromised, and that's actually how they caught Ross Ulbricht (Silk Road). All the stuff about his previous posting, etc, is tenuous and circumstantial-- it seems totally feasible that it is parallel construction. The "Tor Sucks" document is from 2012. It talks about the GCHQ running Tor nodes. What could have happened in the years since? https://metrics.torproject.org/network.html https://metrics.torproject.org/network.html What many people don't realize is that Tor has only ~5000 exit nodes and ~3000 relays. If you control 50% of the nodes, Tor is essentially compromised. Half is ~4000 servers. Seems like a lot for an individual person, right? Just a rough estimate, at $40/month for a cheap linode VPS, 4000 nodes would cost $160k/month. But that's _nothing_ for a nation-state. $160k/month isn't even a rounding error. And that's all it costs to _completely_ compromise Tor. These nation states don't want anyone to know they compromised Tor, so they won't waste it on little fish. They'll save it for real terrorists and major criminal actors like Ulbricht. But if they compromised Tor, they're certainly recording _all_ that activity somewhere. It's sitting in archived storage ready to be mined if necessary.
- Homunculiheaded 12y agoMy suspicion is essentially the opposite: Tor is secure, but the two high profile arrests (Freedom Hosting and Silk Road) where given priority to make the general public a.) feel that the entire function of Tor is illegal and often repulsive activity b.) that Tor is not safe. The latter part of that theory, that law enforcement agencies intentionally stepped up the resources for both the FH and SR cases in order to intentionally create disgust and distrust of Tor, is of course merely conjecture. Basically I find it an amazing coincidence that the two most notorious parts of the Tor hidden service world where busted very quickly after a huge amount of positive public attention was brought to Tor right after the Snowden leaks. Additionally if you actually look at the details of the FH exploit the FBI unleashed it is fairly useless, but very terrifying when you read just the headline. Legally there seems no useful reason to use such an easy to discover exploit that would have delivered no particularly interesting information. However from the stand point of creating public fear it worked marvelously. If you talk to even technical people that don't understand security and Tor well they often assume that the feds "hacked Tor". Which, in my opinion, is exactly what state actors want people to think. As for the former part of the claim, that Tor is secure, look at the Snowden leaks about the methods that the NSA was thinking about for attacking Tor. Egotistical Giraffe, the attack used on FH, as mentioned was not a particularly useful exploit, and attacks user behavior not the network. Other similar leaks also suggest that neither the NSA nor any other state agency, has the ability to completely compromise Tor. Finally,if you are a state agency and you have completely compromised Tor, you would actually want the general public to think it is safe. It is an amazing advantage to have your adversary think they are on a secure line when they absolutely are not. On the other hand if you haven't (and probably can't) compromised Tor you want the majority of people to think you have so that they disregard one of their best tools for defense. Now of course there is plenty of evidence that federal agencies can perform targeted timing attacks against specific individuals. Tor does not and really cannot guard against this, and this has always been the case and fairly well known. If a state agency is targeting you specifically, I don't think there is anything you can do. However, given the information that is available to us, I do think it's reasonable to assume that Tor is secure from general, large scale, untargeted surveillance.
- zargon 12y agoOne usually sees a list like this presented as debunking myths. The myths are given bold headings that state the opposite of what the author wants to say. This format is so much clearer because they state the position they are taking instead of the opposite of their position.
- nanoscopic 12y agoIt is possible to de-anonymise any Tor user if they have JS enabled and you have passive listeners at their ISP. See http://webcache.googleusercontent.com/search?q=cache:kVKMeKxd2UEJ:www.regimedeath.com/+&cd=1&hl=en&ct=clnk&gl=us http://webcache.googleusercontent.com/search?q=cache:kVKMeKx... The described attack on Tor may not be well known, but at the very least I told the FBI how to do it myself, so they certainly know about it.
- maerF0x0 12y agoIIRC Tails helps you by encouraging you to turn off the JS to avoid the exploit.
- zoobear 12y agoLast I checked google was able to discern my real ip even while behind tor... I used tor for scraping google but now that no longer works