Skip to content

Comment on Tor best practicesparent

Comments

Tor is far from perfect. Even if Tor does everything it's meant to. People can still compare when you're using your internet on Tor and when you doing activities online (on Tor). What this person is saying does make sense.

"using your internet on Tor" and "doing online activities (on Tor)" sound like the same thing to me.

But this whole article sounds to me like the author's expecting people to only ever use Tor when they want to hide something. What we should be doing is encouraging everyone to use Tor all the time for everything, delays be damned. That totally obliterates any correlative analysis.

This only stops the simple correlative analysis. You could probably still do correlative packet timing attacks(correlating the sent/recieve time of packets from you and from the server) , and active attacks(by adding some data to your/server packet at the ISP and watching this packet flow across the network).

Ya the anonymity sometimes isn't because I'm doing anything illegal. I've been considering setting up Tor on my firewall/router and starting to funnel connections to google, bing, facebook and things like that through it. Probably eventually funnel all http and https through it.

Any unencrypted traffic you funnel through Tor can trivially be intercepted and logged by an exit node.

People can still compare when you're using your internet on Tor and when you doing activities online (on Tor)

Ok, so what is the threat model in this case? (really want to understand)

Logs subpoenaed from your ISP show that you were using Tor between 3:10 and 5:23 PM on 02/05/2012.

Logs from forensic analysis of a breakin to EvilCorp show that the attacker came in from Tor and was downloading secret data from 3:10 to 5:23 PM on the same day.

Not enough to prove anything, but there's definitely some circumstantial evidence there.

But if you use Tor for all of your day-to-day browsing, in strict contrast with the OP's recommendation, then there's not such a glaring correlation.

You've still got the spike in network activity, and if you're running a relay, you've still got the spike in outgoing activity minus incoming activity.

Yes, but the local and remote activity can't be connected. Were somebody to connect and disconnect from Tor in the time surrounding an attack, you could; but you couldn't say that a Tor user is a culprit of an attack that went over the Tor network because they were using the Internet at the time. Perhaps they're just using Facebook or HN as they do many times each day.

Um, yes it can be connected. You have a graph that looks like /\_/-\_ of bandwidth differential on one machine and you have the graph that looks like /\_/-\_ of bandwidth used on the targeted machine. Case closed. The occasional connection to Facebook isn't going to obfuscate that.

OTOH, you can also run a Tor node and your ISP wouldn't be able to see anything (other than you running a Tor node). For added security, run a Tor Exit Node and your ISP wouldn't be able to determine when you stop using the regular internet, either.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.