Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you think the Tor project is working on an important problem, consider running a relay. It's inexpensive, easy to administer, no hassle (if not an exit) and I think the scale is such that a couple thousand additional relays would make a noticeable difference to the network.

You can even have it AWS where it will get automatic updates with almost no effort: https://cloud.torproject.org/

If you want to run it on OS X: https://tor.stackexchange.com/questions/6567/how-do-i-manual...

I think it's pretty cool that you can help enable people to safely bypass censorship/surveillance from across the world.



> You can even have it AWS where it will get automatic updates with almost no effort: https://cloud.torproject.org/

I guess you didn't click on your own link....

> As of May 8, 2015, the Tor Cloud project has been discontinued.


Wow yeah - you're right, I haven't checked in on mine in a while and assumed it was good (just pasted the link).

Thanks for pointing that out.


> no hassle (if not an exit)

Not 100% true, your server's IP will be banned along side the IPs of exit nodes. It seems a lot of blacklists don't bother to make the distinction.

https://www.reddit.com/r/TOR/comments/2abne1/hulu_blocked_af...

https://trac.torproject.org/projects/tor/wiki/org/doc/ListOf...


Good point - I did notice this with Hulu, but haven't seen it elsewhere.


I've been running a relay at home for most of this year. The only site I've had issues accessing is Apple's shitty support forums. No big loss.


My sibling comment points out that Tor Cloud is discontinued anyway, but I have some concerns about running a relay on a cloud provider. If a lot of people do this, it seems like it could pose a risk to Tor users' anonymity.

Tor works by bouncing traffic across a few nodes. In an ideal case, these nodes are run by different people in different countries, so even if a vulnerability in a server or legal action exposes the traffic across a single relay, the other nodes are not accessible to the attacker and the users' anonymity is maintained.

If a large number of people start running nodes on cloud services, then this centralizes the nodes under the control of Amazon or whatever cloud provider. Even if you trust Amazon (there are many use cases where you shouldn't) a vulnerability in their cloud services could expose data from ALL of the nodes running on their cloud. I haven't done any specific analysis on this, but my guess is that if 5% of the nodes in the Tor relay system had their data completely exposed, the nodes would include all the nodes along routes for a significant number of users. Combine this with traffic analysis and other attacks, and even more users could be de-anonymized.

I'm by no means an expert on Tor, so I can't say with confidence whether or not this is a concern. Perhaps someone with more knowledge will weigh in.


One interesting thing I read recently is that, when building a circuit, Tor actively avoids picking more than one relay sharing a common attack vector.

Basically, it will not pick more than one relay with the same family id, router or /16 subnet.

Your point is still valid, since AWS and other big web hosts like OVH obviously have a lot of /16 subnets and distinct router addresses, but it's good to see this was anticipated by the design.


Yeah, that's super interesting.

To be fair, I suspect there is already a similar problem simply due to economics: running a relay costs money, so the vast majority of relays are running in the first world, which correlates well with countries that have extradition treaties with the US, for example.


The node constructs the path it uses. As concentration in one area becomes a concern, those nodes can be identified as Amazon based on IP so clients know not to use more than 1 or 2 nodes there.


If you want to run a tor exit node, you can improve the security by subscribing to a rigorous hygiene process that provides accountability of your security upkeep.

* System Hardening

* Log Monitoring

* Intrusion Prevention

* Write proceses

* Perimeter Control

A compromised tor exit node is no good because all it takes is switching on NetFlow and all those sensitive packets are captured.

http://motherboard.vice.com/read/how-the-nsa-or-anyone-else-...


> safely bypass surveillance from across the world

Is this true, for a global passive adversary? If all of the nodes which route your link go through a friendly IC that shares ToR traffic patterns, I'm pretty sure traffic analysis can disclose where you are browsing or which hidden service you are visiting (or at least where it's hosted).

Does anyone know more about how a ToR link is chosen, whether you can control it, and what some alternatives might be?


From https://svn.torproject.org/svn/projects/design-paper/tor-des...:

    A global passive adversary is the most commonly
    assumed threat when analyzing theoretical anonymity
    designs. But like all practical low-latency systems,
    Tor does not protect against such a strong adversary.


Since the global passive adversary is now a reality (NSA) it seems like Tor is broken by design.


Not everyone is hiding from the NSA.


So ToR is like a shitty free VPN? Who can one be hiding from that a cheap VPN to a jurisdiction of your choice won't solve much better?


No, it's not. It's also not written ToR. I recommend you venture over to their website and start reading the documentation.


Thanks for the correction, I'm not sure why I decided to upper case the R :)

To clarify what I think you meant to refer me to, the Tor client actually chooses the three nodes in the path of a circuit, doesn't use two nodes on the same subnet, nor ones the network classifies as belonging to the same "family" (although I'm having trouble determining what this means in practice).

Given that there is a hard limit of three nodes in a route, I'm still have trouble thinking of an adversary that Tor protects you against that a VPN to a jurisdiction of your choosing doesn't, and a VPN is significantly faster...


It's extremely difficult to do (even for the NSA as the leaks mostly showed). Tor is by far the best option that exists today.


The NSA isn't really global, though. For example, if enough ToR traffic were routed via Asia or South America, I imagine they would not be able to perform much traffic analysis on it.


The NSA is very much global and according to the Snowden leaks tapped into a large number of major internet exchanges and sea cables, including the largest internet exchange of the world (Germany, DECIX[1]) as well as the largest exchange in Asia (Hong Kong, HKIX[3]) and South America (Brazil, BRIX[4]) respectively.

From what we know the NSA has global coverage with google-style indexing[1] since at least 2012, possibly earlier.

[1] https://firstlook.org/theintercept/2014/08/25/icreach-nsa-ci...

[2] http://www.ip-watch.org/2015/04/24/largest-internet-exchange...

[3] http://www.scmp.com/news/hong-kong/article/1269773/hong-kong...

[4] http://www.newyorker.com/news/news-desk/what-the-n-s-a-wants...

[5] http://www.theguardian.com/uk/2013/jun/21/gchq-cables-secret...

[6] https://docs.google.com/spreadsheets/d/1x6aYnGmbQKzZGLUkWC4m...


Thanks for finding all of those sources. That is indeed a vast network of intercepts, however it's not necessarily "global" in the sense that they monitor all communication. If one could choose their Tor link to include enough paths not likely to be monitored by colluding parties, then one could be more certain they are not facing a "global adversary" in the sense that the Tor site means.


however it's not necessarily "global" in the sense that they monitor all communication.

It is very much global in the sense that they monitor all communication.

How about actually reading some of the sources that you were just provided with?


Not literally all communication in the global sense that Tor refers to. For a trivial example, the wifi signal between my computer and my router is not monitored.

Your references seem to talk about major exchanges all over the globe. Practically speaking, because a Tor client can choose the routers for the link it creates, it could choose three routers behind a single major exchange that is monitored (e.g. in Asia or South America), and hence remain anonymous, because the connections between those routers are not monitored.


because the connections between those routers are not monitored

A correlation attack[1] doesn't care about the intermediate routers. It only requires packet dumps from the entry and the exit node. Both of which, with very high probability, route through networks that are monitored by the NSA.

[1] https://blog.torproject.org/blog/traffic-correlation-using-n...


Good point. I wonder how useful that is in practice with the amount of traffic going through the Tor network. It seems to me that the more people use it, the harder it would be to get accurate correlations. That said, I wouldn't be surprised if some clever math can do so more accurately than has been published.


Your client constructs the whole path. You can take whatever route you desire.


Will running a relay decrease the chances of my guard nodes fingerprinting me (because of other people's injected traffic)? Or maybe the relay traffic is completely different and detectable from the the normal Tor usage traffic?


I'm speculating, but I'd suspect that your traffic connects and initially passes through your guard node while traffic passing through your relay is probably going to other nodes in the network (since guard nodes are used for initial connections and as a relay you're already the middle node).

In this case it wouldn't help conceal anything extra from your guard node.

For those who don't know, guard nodes are the nodes you initially connect to. In Tor once established, your first hop is always to the same node - this is because it's assumed some nodes are bad actors and if the first node is randomly selected each time your chance of eventually connecting to a node trying to collect information is high and partial compromise isn't much better than fully compromised.

By selecting and using one guard node for your initial connection it's either a bad actor or not, but if it isn't then you're good to go from then on.

When you run a relay if your relay is fast, stable and online for a while (60 days I think) the Tor network will automatically turn your relay into a guard.


What sort of legal protections does USA have for people running a Tor node?


Generally speaking, running a relay node is considered to be fairly safe and hassle-free.

Running an exit node is more of a hassle, you'll usually be receiving a lot of DMCA notices and a lot of ISPs won't permit running exit nodes from their network.

There has been at least one case outside of the US where an exit node operator was prosecuted and found guilty of aiding in distributing child porn [1].

[1]: https://www.techdirt.com/articles/20140701/18013327753/tor-n...


It's probably legal, but it hasn't yet been tested in courts: https://www.torproject.org/eff/tor-legal-faq.html.en


What sort of legal protections does Canada have for people running a Tor node?


A relay which is not an exit is practically zero risk. The design of the Tor system means you'll be receiving an encrypted packet from one source, unwrapping one layer of encryption, and passing it on to the next relay in the chain, with no knowledge of the original source, final destination, or true packet contents.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: