The application is open sourced [1], and it gets a lot of attention from all manner of people, ranging from nation states (both ‘good’ and ‘bad’ guys, depending on what you’re using it for and from where) and activist researchers.
It’s almost certain that some state has an application exploit sitting on a shelf somewhere, which might only be useful in some extremely niche use case, but it’s unlikely that it’s routinely ‘compromised’ in the way that sensationalised media might put it.
What’s more likely is that an exit node has been owned, or is actually operated by some nation state. Even then, you might not even see the actually traffic if it has been re-routed.
The most likely scenario is an OPSEC failure - turns out you need to be very, very good at operations and online hygiene if you want to hide your illicit activities online shocked pikachu.
Comments
The application is open sourced [1], and it gets a lot of attention from all manner of people, ranging from nation states (both ‘good’ and ‘bad’ guys, depending on what you’re using it for and from where) and activist researchers.
It’s almost certain that some state has an application exploit sitting on a shelf somewhere, which might only be useful in some extremely niche use case, but it’s unlikely that it’s routinely ‘compromised’ in the way that sensationalised media might put it.
What’s more likely is that an exit node has been owned, or is actually operated by some nation state. Even then, you might not even see the actually traffic if it has been re-routed.
The most likely scenario is an OPSEC failure - turns out you need to be very, very good at operations and online hygiene if you want to hide your illicit activities online shocked pikachu.
[1] https://gitlab.torproject.org/tpo/core/tor