2821
Security / Re: Who on SR orders from their home computer?
« on: May 20, 2012, 03:02 am »I think the point is it's security through obscurity - yes of course someone downloading CP could be traced to your IP address, it actually happened in London to a man I knew but the conversation with the Police lasted less than five minutes :
"I run an Apache Home Server running a Tor exit relay Officer, here take a look. "
"Thank you Sir, have a good day."
The Police understand the implications of running an exit relay as well as we do. It may well be the case that someone does something nefarious via your IP, the point is it won't be possible to single you out for LEO's attentions on that basis.
By way of compromise it's also possible to run a Tor non exit relay....!
V.but also, why would you want to run an exit relay if you ARE doing something illegal, running an EXIT relay increases your chances of being investigated for anything that might have happened from your exit node, so why invite terrorism investigations, child porn investigations, assassination plot investigations etc into your home? if you run an exit relay, anyone could be using Tor for clearnet communications through YOUR exit relay, and that brings unwanted attention, so encrypt your hd, YES, run an exit relay...NO (at least not from a machine that also contains incriminating evidence that could be used against you. the encryption thing was not the point of my post, the exit relay being a stupid choice while doing illegal activity was the point.
Just fyi, security through obscurity is a derogatory term in most security circles. You want to have security through correctness, security in depth, security via strong cryptographic primitives, security by whatever, but security through obscurity is not something to aim for at all. Unless you are Microsoft and don't want to reveal your source code while still pretending that you are increasing security by keeping it secret .
Secondly, running as an exit is bad because you might be raided over it, but running as a relay decreases your anonymity significantly as well and should also be avoided.
if you want to contribute to Tor, buy a VPS and run it as an exit or relay. I would avoid running as an exit or relay on a computer on a network that I use for anything I want to remain anonymized, and I would certainly avoid running an exit if I didn't want to chance being raided over someone elses bullshit. In some cases LE ignore Tor exit IPs entirely because they know they can't trace them and don't want to harass the exit node operator, in other cases they kick in the door and haul your ass off to jail on CP charges and it takes a few days to sort things out plus they keep your PC for a long time for evidence, in some cases people have even been raided by CIA type agencies (not in USA so not actually CIA). Police forces of the world are widely different in their understanding of Tor and their standard procedures, do you want to risk that the police agency that saw your tor exits IP downloading CP + your own local police force have no fucking clue about Tor? If they are not checking Tor exit lists and filtering those off of the lists of IPs they see downloading CP, you will be treated as anyone else who they suspect of downloading CP or sending bomb threats or whatever, and that means you could wake up with a bunch of thugs pointing guns at your face and ripping your house apart.