I ran a bunch of nodes for a couple years and that's optimistic by perhaps an order of magnitude. No $5 a month VPS provides enough bandwidth to sustain the monthly traffic of a Tor node, and nodes need to be continuously online and serving traffic for about 2-3 months[1] before they will be promoted to guard relays. Throttling traffic to stay in your bandwidth allocation will just get you marked as a slow node and limit the number of connections you get. Sustaining just 1 Mbps will blow your monthly transfer allocation on the cheap tiers of both Digital Ocean or Linode.
Now to add additional problems. 1000 tor nodes on a single platform would be very noticeable and geographically limited. Platforms also have different weight attached to them in the consensus, which adds further time requirements before a node is promoted. The developers do not want a single platform provider to be able to observe a large portion of all the traffic, so there are counter measures.
The attacker could try to create a handful of accounts on hundreds of platforms in as many countries as possible, assuming one verify that the platforms accepts tor and do not share underlying providers and data centers. The cost would then be the average price of said providers, which is going to be a fair bit more than the cheapest providers out there. Managing and spreading them out is also going to cost a lot of man hours. Also the secops need to be fairly on the point and need to be maintained quite strictly across all the providers.
Considering multiple world governments have already shown in leaked documents that this is exactly what they do, I personally wouldn't trust my secrets with tor.
Still, I think your point is excellent. The sort of group interested in tracking someone(s) over Tor certainly might have the capability to do so despite the difficulty.
> Let's say I as a private individual fund 1000 tor nodes
Was the operation against Hezbollah funded by a private individual? Otherwise I'm not sure the relevance of your statement to the comment that started this thread.
They say the internet is just someone else's computer. With Tor it's the computer of a person who wants you to think it's not their computer, and also that they aren't paying attention to (or somehow can't see) what you're doing on it.
The interesting thing is, the more agencies that run relays, the more they interfere with each other. So having something like US, Russia, and China a
each running 25% of the network reduces the chances of any one getting all three relays.
I think even Russia and the US still do intelligence sharing on a lot of stuff - and that's before you consider that the US seems to be in everybody's networks anyhow, so non-sharing is probably just sharing with a bit more skullduggery.
I don't think they share on the bulk data. I would highly doubt they routinely cooperate on cyber crimes given Russia's stance on the matter (basically encouraging it).
Russia and China are allies. And I'm not sure if Beijing would even be interested in spying on TOR users since it's blocked so thoroughly it's basically unusable for Chinese residents.
They are neighbors with some overlapping interests and sort of similar goals if you squint. It wasn't very long ago that they were killing each other over border conflicts and annexed territory.
China right now is just using Russia for cheap energy, they don't actually care about the health of the state.
If that's how geopolitics worked China would still be an American ally, vice versa. But alliances can change. Once an enemy always an enemy isn't a thing.
>they don't actually care about the health of the state
That's true but it's not a requirement for Xi to care about Russia. In fact I'm very sure he doesn't care about the Chinese people either. Russia needs China and the CCP uses Russia, not just for cheap energy but for fighting a war that many Westerners haven't even realized that it has begun already. Russia and China have a common enemy, that enemy is NATO.
I get scared reading that wiki page. The fact that the Australians are powerless[1] to stop US operating Pine Gap on their own soil, says something about how important the stuff the NSA & co. is doing there. (Surveillance) Horrors beyond our understanding.
Or perhaps they _are_ sharing notes about tor users with each other, as part of a global club of intelligence agencies (a sort of new world order) who would rather not be overthrown. How are we to know?
Because if they each only have incomplete information, they each wouldn't know whether the information they have is relevant to preventing overthrow of their collective order, or intelligence that is only going to help their geopolitical adversary.
Basically, a variation of the prisoner's dilemma.
Also, those nukes we have pointed at each other are a pretty healthy hint.
Or perhaps someone with secret quantum computing can break all our encryption and has full transparency on all communications on the internet. Perhaps extraterrestrials are eavesdropping on everything I say in my living room, and sharing it with the KGB. How are we to know?
Before 2020 when /r/privacy stimulated conversation that was worthy of good discussion you learned Tor the software made less available nodes accessible with newer deployments, that’s why it got faster. Regardless of how many nodes existed. The routing shifted. Now it’s way faster and there's specifically designated guard nodes seemingly pinged repeatedly out to the same allied nations.
Pardon my ignorance, but I thought it fruitful to ask:
Are there any issues that can arise by doing this on a VPS?
I ask because I know of stories of law enforcement sending inquiries to owners of, say, exit nodes requiring certain information about given traffic. I don't know if this happens for middle-nodes (or whatever they're called).
Moreover, are there any issues with associating a node to, you know, your name and billing information?
I don't know much about this, and although I could look it up, I think that my questions - and your respective answers or those of others - might do some public service of information sharing here.
I never operated a TOR node, but as far as I know and heard from other sources, TOR realays don't get much attention from law enforcement, it any attention at all. Which makes sense: all they're doing is getting encrypted traffic in and giving encrypted traffic out. It would hard for them to link a relay node to a specific connection, and even if they do, you can't help them in any way: even you as the node operator are only able to see encrypted traffic.
Edit: there's a youtuber called "Mental Outlaw" that published a while ago some videos about setting up and operating TOR nodes. He sometimes gives inaccurate information regarding more theoretical topics, so I don't follow him much. But I think he can be trusted for this practical topics.
Just a quick note on the Youtube channel you mention: I follow his videos for a while and it seems to me, that he's half a shill. My impression is, that he re-models popular HN threads into Youtube videos. Just watch the latest video on the MrBeast topic and you'll basically get the same info as all the popular 'root' comments (was on HN front page last week). Not the first time I noticed a suspicious connection.
While that is a crappy thing to do, I bet tons of YouTubers are doing just that. Hell, most political YouTubers just read articles and make stupid comments about them.
It would be impossible to create daily content if you weren't just rehashing, or taking, information from somewhere. Again, not defending it at all, just saying it's probably a very common thing. Like how some crappy news articles are just a bunch of reddit comments, like that qualifies as news.
Agreed. Extra: I'd generally say, that comments on HN are often interesting and insightful (that's why we're here, no?). With the current state of social media, I'd wish for a little more HN flavor. But at least credit your source. The information you provide doesn't get less valuable only because someone else did the work.
I haven't watched this particular channel so maybe it's obviously shady, but I'm curious: why is this conceptually a crappy thing to do?
I mean, if you take the IP of others and redistribute it verbatim then I definitely see the ethical issue. So if the claim is that he's reading peoples' comments or posts verbatim without credit then yeah that's crappy. Don't get me wrong.
But if all we're talking about is "mining" websites like HN for topics and then creating original content that covers those topics in a different format for a different audience... where's the issue?
A few years ago I was feeling pretty burned out in the tech industry and created a tongue in cheek "luddite" channel called TechPhobe where I took an overly pessimistic view of the industry. At the time Elizabeth Holmes was on trial and a lot my videos involved me reading ArsTechnica articles on the subject (credited) while offering my personal opinions on the matter. While not successful, those videos got more views than anything else I ever created. Was that a crappy thing to do? I didn't think so at the time and I don't think so now.
I didn't stick with the channel because I realized pretty quickly that if I'm dealing with burnout the last thing I should be doing in my spare time is focusing on tech content lol
> But if all we're talking about is "mining" websites like HN for topics and then creating original content that covers those topics in a different format for a different audience... where's the issue?
Plagiarism, generally. I really enjoyed the semi-recent hbomberguy video on why it matters, and a later response (from another channel) on "The Somerset Scale of Plagiarism" for a more rigorous explanation of what the different kinds of "content reuse" can be. Those are generally where my current model of plagiarism comes from.
A specific concern would be the inaccurate telling of information that isn't understood. A video saying, "Here I will summarize this HN thread," is perfectly ok, and a good thing. A video saying, "Here I will tell you how $thing works," should be well researched and cited. Doesn't matter if the content's entirely from an HN thread for from 40 different SEO farms, it's low-quality content and it's wasting everyone's time at best, and probably actively misinforming people. (Because how true and complete is information gleaned from HN comments anyway?)
Mental Outlaw definitely doesn't know how to threat model anything. Keeps assuming you'll be targeted specifically, but then tries to evade that with i2p and Tor. Most people aren't going to be specifically targeted though, especially if they keep a low profile (i.e. don't be one of ~50k i2p users, that's sure to be a selector) and especially not for torrenting content illegally (as opposed to illegal content).
If your threat model is actually three letter agencies coming after you specifically... that's an entirely different problem not (just) solved by software.
I ran tor exit nodes on Linode and Digitalocean for years. No real issues, but you will get regular abuse complaints.
The support teams always understood once I explained it was a tor exit node. I co-operated with the Cloud provider and added any IP-address that requested it to my list of exempt addresses.
But they don't have to. It could also be against their ToS, and many other providers would not have been ok with it. Accounts and domains have been taken away for much less.
What's more alarming to me is that they (the jabber operators) seemingly stopped caring about it. Whatever this intercepting proxy did (including from the sound of it, spoofing ACME challenges from their domain to get a certificate) could be illegal and they didn't even attempt to do anything about it, AND they are assuming that continuing to use the service after the attack stopped is somehow safe now.
Either they are grossly negligent/incompetent (IMO unlikely given the extent of their research), or they knew it was intercepted on purpose (either by law enforcement, the provider itself or one of their upstreams) and intentionally aren't saying so. They could also be withholding or lying about any number of things, including the exact response from the hosting providers.
Some do though. I got started a minecraft server the other month that i paid for in xmr. You can go to like a VPS aggregator like serverhunter.com and filter those that allow altcoins as payment
If it’s that expensive to run Tor nodes, who is actually paying for them? I’ve heard individuals getting doors kicked in for participating in the network, so it’s not individuals. Corporates too wouldn’t want this type of burden… so is it really just spy-vs-spy
This is probably strictly true but it smacks to me of 'many people say'. I wonder what % of TOR nodes are run by people with an ideological allegiance for the network vs how many are run by nation-state actors.
I run a non-exit node any time I have the spare resources. I2P too. This means they're on the same popular providers that have too many other nodes, though.
Sometimes I set it up as a bridge (hidden entry node) instead.
Unless something has changed, one of the issues with Tor is that it tries to send traffic through servers that have the most bandwidth which are pretty much certain to be servers owned by the state a lot of the time because a random person's residential cable modem is going to be a lot less capable.
Run by individuals doesn't necessarily mean run on potato hardware. I ran a highly reputable (non-exit) node on a beefy but underutilised dedicated server for at least half a decade.
You don’t technically need separate nodes, just separate IP addresses. Although Tor has some marginal protections against circuits sharing relays with similar IP, so you couldn’t just get a /24 and hope they all get the same circuit.
Not only would you need the node to expose IPs with a wide enough distribution to allow the right path selection, you'd also need to have enough bandwidth available to look like distinct hosts, and ensure any losses in connectivity aren't correlated enough to draw attention (people monitor metrics.torproject.org pretty diligently, and would notice if there was a chunk of bandwidth coming and going in lockstep). At that point, the difference in cost to just actually running legitimately separate hosts is negligible. All empirical evidence points towards the status quo that has existed for most all of Tor's existence: if you want to identify Tor users, there are cheaper ways to do it than dominating the network (and those ways are expensive enough to be outside most people's threat models).
That said, any bandwidth anyone wants to contribute to mitigate such attacks is always appreciated, even if it's more useful for performance reasons in practice. ;)
I ran a bunch of nodes for a couple years and that's optimistic by perhaps an order of magnitude. No $5 a month VPS provides enough bandwidth to sustain the monthly traffic of a Tor node, and nodes need to be continuously online and serving traffic for about 2-3 months[1] before they will be promoted to guard relays. Throttling traffic to stay in your bandwidth allocation will just get you marked as a slow node and limit the number of connections you get. Sustaining just 1 Mbps will blow your monthly transfer allocation on the cheap tiers of both Digital Ocean or Linode.
[1] https://blog.torproject.org/lifecycle-of-a-new-relay/