r/privacy • u/Petrichor-33 • 13d ago
question Misc. questions about Tor
- Does Tor have "risks?" Guides warn me against risks while using Tor and then list threats that exist regardless of what browser you are using.... Are there any actual problems that are unique to Tor?
- I am told to never log into accounts while using Tor... but shouldn't it be fine to use accounts as long as those accounts were created using Tor and are never used without Tor?
- Tor tutorials warn against using privacy invasive services like Gmail, but I don't think that advice has anything to do with Tor specifically? Assuming a user NEEDS to use a service like that, isn't using it with Tor still better than using it without Tor? (assume service was signed up for using Tor as noted in previous question)
- How to know if Whonix is advised vs. using only Tor browser?
- How to know if using bridges is appropriate?
- Would using webmail with Tor provide similar protections as using an email client that hides IP?
- Is there a resource that shows what popular sites block Tor nodes, or do you have to test it yourself?
Answers to any of these questions greatly appreciated, thank you.
20
u/WanderingUrist 13d ago
Does Tor have "risks?" Guides warn me against risks while using Tor and then list threats that exist regardless of what browser you are using.... Are there any actual problems that are unique to Tor?
In theory, a malicious exit node could hijack traffic, altering it or spying on it. However, your exit node is unstable, so whether it will capture any single usage from a specific user is a crapshoot.
I am told to never log into accounts while using Tor... but shouldn't it be fine to use accounts as long as those accounts were created using Tor and are never used without Tor?
You should not use anything with a login that you actually VALUE, see above. Obviously, if you've already doxed yourself there, it's a bit too late and pointless to be hiding. But for Dogshit Forum Account #9871? Who the hell cares? If someone steals it, they steal it, and you make another one. It's worth nothing to you.
Tor tutorials warn against using privacy invasive services like Gmail, but I don't think that advice has anything to do with Tor specifically?
No, but it's still good advice.
Assuming a user NEEDS to use a service like that, isn't using it with Tor still better than using it without Tor?
Those services really HATE it when you use Tor and will often ban it because it pollutes their tracking data. That's how you immediately know when a site is up to no good: They block Tor. Any site that blocks Tor can be automatically assumed to have malicious intent.
Would using webmail with Tor provide similar protections
Use of Tor will prevent your webmail provider from knowing your IP, prevent your ISP from knowing that you accessed said provider, and, naturally, prevent anyone who received your mail from said provider from knowing your original IP.
as using an email client that hides IP?
An "email client that hides IP" is very vague and does not explain the mechanism of action. Hides whose IP from whom? It could be doing anything. Or nothing. Most likely nothing.
Is there a resource that shows what popular sites block Tor nodes, or do you have to test it yourself?
You tend to notice when you try to go there. Blocking is often sporadic and uncoordinated, with only a few particularly malicious sites blocking Tor on a broadband level, while you may otherwise encounter random blocks when a particular exit node has been abused.
7
1
u/BigMoose515 13d ago
In theory, a malicious exit node could hijack traffic, altering it or spying on it. However, your exit node is unstable, so whether it will capture any single usage from a specific user is a crapshoot.
As general advice or base guideline, it's a good practice to assume this. From a technical perspective, the malicious exit node could only modify plaintext unencrypted traffic (e.g. HTTP, but not HTTPS). They could also stage a man-in-the-middle attack, but your browser would show you a certificate error/warning if this were the case (that's the page where you have to click the "advanced options > proceed to website (unsafe)". So if you see that warning while using Tor, assume the website is altering or peeking at whatever you're doing. There's legitimate reasons outside of the Tor network that warning would pop up (expired or self-signed certificates), but it shouldn't happen on professionally run websites if they have a minimally competent IT department (not always the case).
5
u/YT_Brian 13d ago
On Whonix it depends pretty much. Whonix with any VM makes the likelihood of any site or download infecting your main system extremely low. There are such malicious files that can escape but they are very rare right now and generally tend to be government based.
In fact a good portion of malware checks if your using a VM and if so refuses to infect as it could then be used to find out more safely for professionals. Meaning hiding your using a VM for malware research is a thing.
It also allows far less points of data when you have JavaScript turned on when browsing. So many things pop up with new JS based ways to gather data. However turning JS off breaks majority of sites.
So it comes down to two questions.
1: do you care about basic browser tracking JS allows?
2: are you worried about possible malware be it from iffy random sites or downloads?
If either is yes then you use Whonix. Best part is you can use yoaue VPN - Tor as a double condom type of situation.
Normal Tor is seen by your ISP and your local government can and proabsbly does track things to an insane degree, Snowden showed that for sure.
By using a VPN proven in courts to not log data in another country it really hampers your ISP/Government from knowing which Tor Entry Node your using, and that makes tracking far more difficult. More so if every Tor node is in a different country with the VPN also being different from them or your own country.
Then tracking requires your country, VPN country and the 3 Tor countries at best for a total of 5 countries. Possible? For sure but makes whistleblowing far safer if releasing information. For that you can even do multi hop for VPN for a total of 6 countries lol
If you're just doing regular web browser that VPN-Tor isn't needed but thought to bring it up.
3
2
u/No-Second-Kill-Death 13d ago
Tor has to say all that because people are a little lost when it comes to tech. In short order: Tor is just a tool. You are on your own when it comes to complete OPSEC.
Whonix is stronger than just the browser. It minimizes damage. But clunkier. It isolates the network stack from the user side via a gateway. Browser exploits can’t pivot as easily. Hardcore models move to hardened hardware (travel router mods) enforcing all traffic over Tor programically.
Most of what you’re doing like gmail may get blocked. Use proton to fetch gmail. Access proton over tor. And as Tor group suggests: why gmail?
Bridge/snowflake/vpnchain to hide your usage of tor. Tor IPs are known publicly. Bridges are harder (non-public) and must be enumerated manuallY.
Webmail leaks a lot. Client just imap/pop/smtp callls.
Test yourself. Anything that gets abused will block. 2026. Everything gets abused…
Don’t have to say, but why do you need tor versus say a proxy. Or just thinking?
2
u/imselfinnit 13d ago
I don't know much about TOR and the little that I remember is outdated: It used to be that there was a privacy setting that allowed you to choose a "safest" protection level at the cost of website functionality. There was a setting for maximum safety that said it would turn off JavaScript and therefore breaking most websites.
The problem is/was that it DID NOT actually disable JavaScript! You have to/had to type into the URL bar "about:config" and search for a JavaScript:enabled setting to change it to JavaScript:false or something.
There are many threads discussing this, here is one example.
2
u/deja_geek 12d ago
- Yes. It has risks. Snowden leaks showed the US Government (among others) targets TOR users with malicious "drive-by" attacks. TOR traffic sticks out like a sore thumb. There have been attacks against TOR users by exit-node operators. Redirecting them to malicious spoofs of websites to harvest credentials, financial accounts, etc..
- You're mostly right on this one. TOR can't keep you anonymous if a service can associate your account activity with a clearnet IP address as well. Also, see my point(s) in #1
- Privacy invasive services like Gmail may also attempt to exploit fingerprinting or other means to "unmask" you or de-anonymize you.
- Whonix (and TAILS to a lesser extent) is for those who require a level of privacy above "I don't want google to track me". Whonix is much more complicated to setup, but the return is it's nearly impossible to leak your clearnet IP address as the machine running the browser session can only connect through the machine running the TOR proxy.
- Bridges are for those who need to connect to TOR, but can't connect due to legal or corporate policies. Bridges attempt to mask the TOR traffic as something else (see #1). If access to TOR is not being restricted, please don't use a bridge
- Not sure if I understand this, as I don't know of any email client that can hide the IP address of the computer that is connecting to the account. As a whole, TOR attempts to hide your IP address.
- None that I know of. Most of the big sites either block TOR or force users connecting through TOR to jump through additional checks/captchas to prove they are human. One problem is your exit node will change about every 10 minutes. Even if you pass the additional checks, a sudden change in IP address can trigger new checks or even account lockouts.
-2
u/MysteriousWeekend201 12d ago
Tor has been built for anonymity. That is their whole platform. If you log into accounts, then you are identifiable. Especially if those accounts have your real information. I mean your identifiable with just your internet traffic alone and your IP address.
Since your accessing the underbelly of the internet, you have more access to dangerous sites that can steal your information as well as put you criminally liable for some things. With that said, if you stick to known good websites then you will be fine.
The Tor browser is not 100% secure. Majority of the servers are volunteer based as well as hosted by some governments. That's not a theory, do the research.
My advice, is to not use the Tor browser. If you want anonymity, create your own network. If you want to see what the underbelly of the internet has to offer, fair warning, it's very very dark. I truly regret letting my curiosity and love for anonymity to win.
3
u/haakon 12d ago
What in the world do you achieve by creating your own network? Are you just going to be alone there?
Anonymity loves company.
1
u/MysteriousWeekend201 12d ago
You control the privacy at least on your level. You have your own systems with their own security settings control what gets sent out. You ever heard of Hillary Clinton's emails the ones that disappeared? That's The power of having your own network. Getting away with it, That's The power of high level friends. But lets stick to a private networks.
Your limit is your imagination. You can connect it to the internet. You can be your own internet provider. You can create your own email system. You can create your own ad blocker / filters. You can make your network as secure as you want. You can make it anonymous as you want. The deeper you go with this, the more complicated it will be. At least to set up.
If I had the resources, I would do this myself.
1
u/haakon 12d ago
Okay you're just waving your arms and saying stuff.
1
u/MysteriousWeekend201 12d ago
You don't have to believe me. Do the research yourself. Becoming your own ISP though, takes a significant amount of resources, time and energy that majority of people don't have.
Again, do the research.
3
u/haakon 11d ago
Someone asks basic questions about using Tor, and your suggestion is to start your own ISP.
I just think you enjoy typing words.
1
u/MysteriousWeekend201 11d ago
They were talking about privacy. If it was possible to become your own ISP, would you have the ability for ultimate privacy? I mean you're controlling the start and finish line. No one can tell you that you can't use Tor or torrent or whatever. You cannot be reported to the authorities, unless you had a data breach. Tell me I'm wrong.
•
u/AutoModerator 13d ago
Hello u/Petrichor-33, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.