news.volyx.in

Is Tor still safe to use? (blog.torproject.org)

809 points by Sami_Lehtinen · 689 days ago · 561 comments on HN

Article summary

The Tor Project has responded to claims of a de-anonymization attack on the Tor network, stating that the attack was likely due to a user using an old version of the Ricochet application that lacked protection against guard discovery attacks. The Tor Project emphasizes that Tor is still safe to use and that the network is healthy, with over 2,000 exit nodes available. The project encourages users to keep their software up to date and to contribute to the network's diversity by running their own relays. The Tor Project is continuing to investigate the attack and will provide updates as more information becomes available.

Main themes

  • Tor network security
  • De-anonymization attacks
  • Network health and diversity
  • User safety and best practices
  • Surveillance and censorship

What commenters say

  • The Tor Project's response to the de-anonymization attack is not confidence-inspiring due to the lack of clear information about the attack and the project's limited access to relevant documents.
  • Using a VPN with padded and rate-limited packets could potentially mitigate timing attacks on the Tor network.
  • The vulnerability exploited in the attack has been fixed in newer versions of the Tor software, but the fact that the attack was possible in the first place raises concerns about the network's security.
  • The best way to attack Tor is not through technical means, but by convincing people not to use it, highlighting the importance of trust and confidence in the network.
  • The use of alternative anonymization networks, such as I2P, may not be a viable solution due to their own security limitations and similarities to Tor.
  • Physical access to a machine can compromise its security, regardless of the encryption or anonymization methods used, emphasizing the importance of physical security.
  • The NSA's surveillance capabilities, such as XKeyscore, may have been replaced by new methods that can still compromise online privacy, despite the widespread adoption of TLS.
  • Cloudflare's role in mitigating DDoS attacks and providing security services to websites may also make it a valuable target for surveillance and data collection.