Skip to content

Comment on Congestion Control Arrives in Tor 0.4.7-stableparent

Comments

People arrested for their darknet activities have always had OPSEC failures that out them like reusing known email addresses or usernames.

Being deanonymised during normal Tor browsing is extremely difficult and I'd challenge you to post cases where Tor itself lead to it.

Just curious: does Tor have anything against timing analysis by an actor with state-level resources? My impression is it's extremely hard to defend against in general, and it's employed by governments against both .onion servers and users browsing the clearnet (although I don't have concrete evidence). AFAIK some sites in .onion get DDoSed on and off routinely, possibly to locate the origin of the server.

There has been plenty of work on how to de-anonymize Tor users over the years, e.g., see https://www.cs.princeton.edu/~jrex/papers/usenixsec15.pdf.

There's no doubt in my mind that state actors have been putting similar techniques to use.

There has been plenty of work on how to de-anonymize Tor users over the years, e.g., see https://www.cs.princeton.edu/~jrex/papers/usenixsec15.pdf.

But that's not what gp asked.

Has the work you linked to been shown to lead to the successful deanonymization of a normal user during normal Tor browsing? It's a simple yes or no question. I don't follow tor news like I used to but I'm willing to bet a months-worth of salary that the answer is still no.

Unless the NSA, FBI, or whoever comes out and says oh we broke Tor, I don't see how you could ever get a definite answer to that question. And I don't really see that happening.

Or it could leaked, on accident or by a whistleblower. But that's pretty uncommon.

True, but it'd be difficult to both make arrests based on info learned from having broken Tor, and keep it secret that they'd broken Tor. It's possible by obscuring how they got information (e.g. via parallel construction), but difficult to do at scale.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.