I am concerned about statements like this:
Unless you cite your sources and explain to me in technical terms how you think that Tor is being used by the NSA as a honeypot this is not a reasonable statement to make.
Tor DOES receive a large amount of funding by the US government. Tor DOES work on active projects with the military.
Because intelligence agencies have a very strong incentive to ensure that there is a widely-available tool used by lots of people to anonymize traffic.
Because a traffic anonymizer that is exclusively used by intelligence agencies is a dead giveaway that the only people using it are fucking feds and spies.
So here's my problem: Tor is the absolute easiest way for people with the lowest level of technical skill to attain some kind of IP anonymization online.
It isn't perfect, and the system isn't invulnerable to attacks, and there are legitimate reasons to be concerned about the ways that traffic can be monitored.
There HAS been evidence of Tor reporting vulnerabilities to the FBI before they report it to general users. There HAVE been problems with people using the network getting fingerprinted and tracked.
But a lot of complaints about Tor's use by the government look like this:
While Syverson indicated that some of the security issues identified by this research have been addressed in recent Tor versions, the findings only added to a growing list of other research and anecdotal evidence showing Tor’s not as safe as its boosters want you to think — especially when pitted against determined intelligence agencies.
Case-in-point: In December 2013, a 20-year-old Harvard panicked overachiever named Edlo Kim learned just how little protection Tor offered for would be terrorists.
To avoid taking a final exam he wasn’t prepared for, Kim hit up on the idea of sending in a fake bomb threat. То cover his tracks, he used Tor, supposedly the best anonymity service the web had to offer. But it did little mask his identity from a determined Uncle Sam. A joint investigation, which involved the FBI, the Secret Service and local police, was able to track the fake bomb threat right back to Kim — in less than 24 hours.
As the FBI complaint explained, “Harvard University was able to determine that, in the several hours leading up to the receipt of the e-mail messages described above, ELDO KIM accessed TOR using Harvard’s wireless network.” All that Tor did was make the cops jump a few extra steps. But it wasn’t hard, nothing that a bit of manpower with full legal authority to access network records couldn’t solve. It helped that Harvard’s network logging all metadata access on the network — sorta like the NSA.
Did you catch that? Someone sent a bomb threat via Tor over a wireless network that logged all user metadata and this author is suggesting that's a problem with *Tor.*
Here's more from the same article:
In 2013, they took down Freedom Hosting, which was accused of being a massive child porn hosting operation — but not before taking control of its servers and intercepting all of its communication with customers. The FBI did the same thing that same year with the online drug superstore Silkroad, which also ran its services in the Tor cloud. Although, rookie mistakes helped FBI unmask the identity of Dred Pirate Roberts, it is still a mystery how they were able to totally take over and control, and even copy, a server run in the Tor cloud — something that is supposed to be impossible.
Back in 2007, a Swedish hacker/researcher named Dan Egerstad showed that just by running a Tor node, he could siphon and read all the unencrypted traffic that went through his chunk of the Tor network. He was able to access logins and passwords to accounts of NGOs, companies, and the embassies of India and Iran. Egerstad thought at first that embassy staff were just being careless with their info, but quickly realized that he had actually stumbled on a hack/surveillance operation in which Tor was being used to covertly access these accounts.
Uh. This guy's primary method of attacking Tor seems to be pointing out that Tor doesn't encrypt traffic and so people get caught using it when their traffic is unencrypted.
That is a LOT of the criticism that you see about Tor.
Yeah. It's not a VPN. It's a traffic anonymizer.
Tor isn't an NSA honeypot that is snooping on your traffic. Tor is a decent anonymizing tool that is run by an open source project and largely funded by the US government because they can't do their gray man hide in plain sight bullshit if they're the only one walking around.
Here's Luckygreen, an oldschool cypherpunk and crypto activist, talking about Tor as it was being conceived of in 1997:
At the FC'97 rump session, Paul Syverson from NRL presented a paper titled "Onion Routing". The description of the system sounds very much like Wei Dai's PipeNet. However, the development team seems to be unaware of PipeNet and the discussions about it that we had in the past.
NLR has currently five machines implementing the protocol. Connection setup time is claimed to be 500 ms. They are looking for volunteers to run "Onion Routers". It appears the US military wants to access websites without giving away the fact that they are accessing the sites and is looking to us to provide the cover traffic. What a fortunate situation.
And here's some more from him on the topic:
>What do you think of the "onion routing" approach from the group at Naval Postgraduate? How would compare it to this newest proposal?
Neither one of them is any good in its present form. The folks at the FC'97 rump session got to watch Jim and myself poke truck sized holes into the NRL design within seconds of them ending their presentation. :-)
Here was a US military research lab presenting a system they thought would give them a way to surf the Net anonymously by using the public for cover traffic. [Let me just spell out here that I believe that the people from NRL and Cypherpunks are on the same side on this issue. Their concern is COMSEC, not SIGINT.]
If you don't know what that last sentence in brackets means, let me explain it:
Comsec is communications security; sigint is signals intelligence. Comsec means keeping your own comms secure; signals intelligence is deriving intelligence from intercepted signals.
The NSA/CIA/FBI/US Navy are all interested in making sure that Tor is alive and well and running but it is largely so that they can send their own messages on a well-supported, widely used tool. This is widely and openly discussed in emails between developers and intelligence agencies and it is being reframed as "the NSA is using this tool to spy on you."
Again, Tor is not perfect. It does not encrypt your traffic and it is possible - with a significant amount of effort, time, and expense - to exploit the Tor network to eliminate anonymization.
But unless you can articulate how to deanonymize Tor traffic *separate from the now-six-and-eight-year-old attacks in 2014 and 2016* I can't take you seriously when you talk about how Tor isn't a useful tool and/or is some kind of honeypot or data gathering scheme.
It is either a fundamental or wilful misunderstanding of how this technology works and what it is meant to do to act as though it's useless to use Tor because Tor is *also* used by the military and CIA.
Tor is one of the better tools out there to anonymize your IP address. It is vital to OSINT researchers, hackers, activists, and whistleblowers. Telling people NOT to use this tool while not providing a better solution with instructions on how to use it is the kind of misinformation that ruins people's lives.
I will agree that it's equally harmful to pretend that Tor is perfectly protective, and you should not walk away from this conversation thinking that you can just log in to Tor and have perfectly anonymous traffic (just like you can't believe that your traffic is secret if you use a VPN) but every time I bring up Tor there are ostensible leftists in the comments saying "throw out one of our best tools because the NSA likes it" and that's like saying "don't use the internet because it was developed by DARPA and the FBI uses it and monitors it." These statements are technically true, but the risk associated with these facts doesn't outweigh the benefits of using the tools, it just means you need to be careful with how you handle them.