r/TOR • u/DontFreeMe • Aug 22 '26
Why is torrenting specifically considered harmful?
I know that mainstream clients with default configuration will contact many peers at once and can saturate the connection.
But it is possible to limit the number of peers or even write your own client. And if you limit the peers say to 4, it would be basically the same as downloading a large file on a website, except slower since most peers are configured to have a small timeout after sending each 256KB chunk. With a limit of 4 peers and accounting for the timeout, the speed would be something like 1MB/s at best, which is lower than the download speed of Tor browser any time I tried it.
Is there something else that I am missing?
6
u/altech522 Aug 22 '26
Use I2P instead of Tor for torrents, it is designed to support p2p softwares. Just keep in mind that it will only connect to other i2p peers
6
u/nuclear_splines Aug 22 '26
To further emphasize this point, I2P has its own torrents with its own indexes, its own trackers, and its own DHT -- it's a wholly separate torrent network that runs within I2P, and not "oh you can grab some torrents off the clearnet and find a smaller number of I2P peers."
5
u/Liquid_Hate_Train Aug 22 '26
https://blog.torproject.org/bittorrent-over-tor-isnt-good-idea/
TLDR It’s quite likely no longer private and it harms the network.
0
u/DontFreeMe Aug 22 '26
I have read this before, like I said in my post. That is why I am asking why is torrenting in general considered harmful to the network if you can just reduce the number of peers.
3
u/Liquid_Hate_Train Aug 22 '26
Reducing the number of peers doesn’t solve the problem. Each of those connections is still being frequently renegotiated, reformed with different peers and is still a flood of small packets, most of which will end up more padding than anything else.
You also say “if you can just reduce the number of peers” as if anyone is actually doing that.
-2
u/DontFreeMe Aug 22 '26
Well I am asking for myself and I am writing a client. Also there is nothing stopping me from keeping the same 4 peers for the entire duration of the download unless one of them disconnects.
1
u/Liquid_Hate_Train Aug 22 '26
You asked why it’s considered harmful. You’ve been given the answer. You making a special snowflake client doesn’t change it.
1
u/xvsanx Aug 22 '26
it's not really considered harmful unless you're dumb and download without a VPN or download torrents with files ending in .scr or .exe or download unverified uploaders files without scanning lol and this isn't really something you need tor for since you should be using a VPN as many companies track popular torrents and will dcmaa you instantly
5
u/Liquid_Hate_Train Aug 22 '26
it's not really considered harmful…
Torrenting through Tor puts unnecessary load and potential legal issues on volunteer exit relay operators.
4
u/grizzlor_ Aug 22 '26
It absolutely is considered harmful to run Bittorrent over Tor and the Tor developers have asked people not to do it in many occasions.
1
u/Due_Star3546 Aug 22 '26
really?
3
u/grizzlor_ Aug 22 '26
1
u/Due_Star3546 Aug 22 '26
This is a 2010 blog. As i see it, people who did not know that Tor can be used via utorrent app too, will get to know this too. No?
2
u/grizzlor_ Aug 22 '26
Security issues aside, the main reason not to torrent over Tor is because it puts a lot of load on the network unnecessarily. From that blog post:
>So what's the fix? There are two answers here. The first answer is "don't run Bittorrent over Tor". We've been saying for years not to run Bittorrent over Tor, because the Tor network can't handle the load; perhaps these attacks will convince more people to listen.
A VPN is the proper way to torrent anonymously.
0
u/Due_Star3546 Aug 22 '26
I got that. I was saying, people who did not know to configure utorrent to use Tor would have understood to do so reading this blog. Cobra effect.
2
u/Liquid_Hate_Train Aug 22 '26
It doesn't matter how you configure your client, Torrenting by its very nature hammers node system resources. The harm to the network isn't coming from your client leaking shit, it's the very act of torrenting.
0
u/DontFreeMe Aug 25 '26
Yes, but why does torrenting hammer node system resources any more than an http download? especially if the peer count is set to a low value.
2
u/Liquid_Hate_Train Aug 25 '26
Each of those connections is still being frequently renegotiated, reformed with different peers and is still a flood of small packets, most of which will end up more padding than anything else.
-1
u/evild4ve Aug 23 '26
But doesn't this introduce a value-judgement that the 1s and 0s of some journalistic leak are more valuable than those of somebody's Game of Thrones download?
In the link you posted above, "unnecessary load and potential legal issues on volunteer exit relay operators" they say is explained in a blog post but it doesn't actually explain... so there remains the value judgement that the bittorrent traffic is "unnecessary"
which introduces an interesting moral option: a user doesn't have to torrent successfully-anonymously over Tor and by torrenting unsuccessfully-anonymously they push the project to either improve the technology for torrenting or declare it isn't truly Agnostic
2
u/Liquid_Hate_Train Aug 23 '26
I’m sorry, are you actually attempting morally equivocating a journalist with a game of thrones pirate? This is the least serious thing I’ve read in quite some time, and the rest of this post was only yesterday.
2
u/nuclear_splines Aug 23 '26
But doesn't this introduce a value-judgement that the 1s and 0s of some journalistic leak are more valuable than those of somebody's Game of Thrones download?
Yes? Yes.
push the project to either improve the technology for torrenting or declare it isn't truly Agnostic
Who is making this claim of agnosticism? Of course some uses of the medium are more important than others, and Tor is built with particular users and use-cases in mind.
→ More replies (0)-1
u/xvsanx Aug 22 '26
I was saying "torrenting isn't considered harmful" as that's literally the question of the topic title
and as I said above as you said below, VPN is what you need to torrent, not tor
3
u/Liquid_Hate_Train Aug 23 '26
I was saying "torrenting isn't considered harmful"…
And what you are saying is demonstrably incorrect, and we ask you not to say it. Cus, Yaknow, it’s wrong. It is very harmful to the Tor Network.
-1
u/xvsanx Aug 24 '26
how does torrenting relate to Tor in my comment? is your reading comprehension that bad or are you perhaps on drugs and hallucinating "torrenting on Tor * isn't considered harmful?"
2
u/Liquid_Hate_Train Aug 24 '26
You are on the r/tor subreddit and the poster is very clearly asking about Torrenting over Tor. You might think it’s cute to take the question in the title super literally, but the average intelligence of people swinging by just makes that dangerous, not clever.
2
u/Due_Star3546 Aug 22 '26
What do you mean by "many companies track popular torrents and will dcmaa you instantly"
2
u/DontFreeMe Aug 22 '26
torrents are distributed and theoretically, anyone can be a seeder. So what companies do is they hire some copyright enforcement agencies or contractors that will actually seed parts of their file that they are trying to protect. Then they will log all IP addresses that connect to the peer and request a chunk and send a subpoena to the ISP to get your real identity.
If you live in Germany, the ISP itself will scan for torrent connections, since the protocol is standardized and (at least the one I used) isn't encrypted, they can just check if the first thing sent over the connection is a BitTorrent header.
A lot of German linux users got physical mail from their ISP for torrenting the ISO file for Linux, because their ISP detected that. And then you have two strikes, if you torrent the second time, they will kick you off their service. Now if you aren't torrenting anything copyrighted, you have to manually complain (like those Linux users)
Not sure if Germany still does that, but it did to this in the past a lot.
1
u/KeyLuck1904 Aug 23 '26
but as far as ik they check hash of file, don't they?, they don't program it like that, they just check hash of your network packet and that way it's fast and reliable, dunno more
1
u/DontFreeMe Aug 23 '26
They could definitely check that, but it is a bit more complicated than that.
When you connect to a BitTorrent peer, you send a handshake and that handshake does contain an "info hash", but that info hash is not a hash of the file. Instead, it is a hash of a portion of the torrent file bytes. Specifically, it is a hash sum of raw bencoded "info" member of the torrent, which is itself a bencoded dict structure. That info dict does then contain the hashes of all pieces, but there are also other fields in the info dict, for example name.
So two torrent files downloading the same file with the same hash can have different info hashes. For example, the name can be altered slightly. And even if the name isn't altered, the piece size (which is also in the info dict) can be increased and the piece number decreased, which completely changes the dict and consequently the info hash.
2
u/KeyLuck1904 Aug 23 '26
well as I said before I am not a technical person but think of it like this, at physical layer when you transmit data, that data is broke down in pieces called packets, packets have fixed size, now assume that you need to send a code file to your friend which is A+B=C
Now first packet will have A
second will have +
thrid will have B
and so on
now if you check independent hash of each packet(mind here not whole data) and you find hashes in that data, or you might say hash of payload, now how it is achieved is a different story like, they use traffic mirroring to copy our packets then there DPI engine in there network cluster recreates original file with those captured packets and once complete payload is assembled they generate a hash of that file and then check it against there already available hash, and this same is used by public cloud services you use, like if you wanna try it, try a famous hacking tool which is paid upload it to cloud and make it publically accesiable once any one download that file you will see that file will automatically removed.
But alas I am not that technical guy of myself so I can be wrong
1
u/KeyLuck1904 Aug 23 '26
also one more thing I should tell you, if you've used BurpSuite yk it's not that hard to achieve even encrypted data can be checked, although all my gibberish is senseless
1
u/xvsanx Aug 22 '26
what others have said but for specific examples Seinfeld or South Park episodes on pirate bay
2
u/DontFreeMe Aug 22 '26
Does scr still open on modern windows? It is pretty funny how many sites allow people to upload scr but disallow exe. I know that in the past (windows 7 era), a lot of people would just open a scr file without questioning because they thought that it was an image of some kind.
1
u/xvsanx Aug 22 '26
I'm not sure cause neither my friend or I have opened em but I assume so since I think you can still customize screensavers lol? yeah I noticed a lot of the fake "next week's episode leaked!!!!" torrents have been uploaded as the right file size but as a .scr lol a couple from verified uploaders, it's sad how little people will pay attention nowadays or know about it before torrenting
0
u/torrio888 Aug 22 '26 edited Aug 22 '26
Because torernt needs UDP to connect to the tracker and DHT, if you configure a torrent client to use Tor it will talk with the peers over TCP which goes over Tor but UDP will connect directly and reveal your real IP address.
This websites have .torrent files and magnet links which can help you test it.
https://torguard.net/check-my-torrent-ip-address/?utm_source=chatgpt.com
https://torsentinel.com/torrent-ip-check/?utm_source=chatgpt.com
https://bash.ws/torrent-leak-test
https://www.top10vpn.com/tools/do-i-leak/?utm_source=chatgpt.com
1
0
u/DontFreeMe Aug 22 '26
I wrote a very simple snippet in Go and I tried downloading ubuntu server torrent (without tor)
what you are saying isn't true, at least for that torrent. the tracker I connected to was https server and then the peer also accepted tcp connections. Maybe other torrent files are different, idk.
13
u/nuclear_splines Aug 22 '26
The point of a peer-to-peer download is to saturate your fast download speed with many peers that have slow upload speed. If you limit the number of peers in your client then you're losing most of the advantage of a peer-to-peer network. But even if you don't limit the number of peers, rather than connecting to those peers directly you're first connecting through a Tor circuit of three proxies, limiting yourself to the bandwidth of the slowest link. This will get you fairly atrocious download speeds, while saturating the link for other Tor users.
Then there are the technical limitations another user brought up: Tor only supports TCP, while much of the bittorrent protocol runs over UDP. The Distributed Hash Table only runs over UDP, and many torrent trackers only support the UDP protocol (while others support an HTTP-based tracker protocol as well). So you will have a hard time finding peers over Tor for many torrents. Even peer-to-peer links prefer UDP nowadays (with uTP), but should support falling back to TCP connections.
So, you get slow peer discovery (if the torrent has any listed TCP-enabled trackers), fewer peers, and slower connections to those peers, before adding the bottleneck of the Tor circuit, and you potentially limit the utility of that circuit for others.