blog-contributions/opsec/torvsvpns/index.html

168 lines
10 KiB
HTML

<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta name="description" content="">
<meta name="author" content="">
<link rel="shortcut icon" href="../../../../../../assets/img/favicon.png">
<title>The main source of Anonymity: The Tor Network</title>
<!-- Bootstrap core CSS -->
<link href="../../assets/css/bootstrap.css" rel="stylesheet">
<link href="../../assets/css/xt256.css" rel="stylesheet">
<!-- Custom styles for this template -->
<link href="../../assets/css/main.css" rel="stylesheet">
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
<!--[if lt IE 9]>
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
<![endif]-->
</head>
<body>
<!-- Static navbar -->
<div class="navbar navbar-inverse-anon navbar-static-top">
<div class="container">
<div class="navbar-header">
<button type="button" class="navbar-toggle" data-toggle="collapse" data-target=".navbar-collapse">
<span class="icon-bar"></span>
<span class="icon-bar"></span>
<span class="icon-bar"></span>
</button>
<a class="navbar-brand-anon" href="\index.html">The Nihilism Blog</a>
</div>
<div class="navbar-collapse collapse">
<ul class="nav navbar-nav navbar-right">
<li><a href="/about.html">About</a></li>
<li><a href="/blog.html">Categories</a></li>
<li><a href="https://blog.nowhere.moe/donate.html">Donate</a></li>
<li><a href="/contact.html">Contact</a></li>
</ul>
</div><!--/.nav-collapse -->
</div>
</div>
<!-- +++++ Posts Lists +++++ -->
<!-- +++++ First Post +++++ -->
<div id="anon2">
<div class="container">
<div class="row">
<div class="col-lg-8 col-lg-offset-2">
<a href="../index.html">Previous Page</a></br></br><p><img src="../../assets/img/user.png" width="50px" height="50px"> <ba>nihilist@mainpc - 2024-04-30</ba></p>
<h1>The main source of Anonymity: The Tor Network </h1>
</div>
</div><!-- /row -->
</div> <!-- /container -->
</div><!-- /grey -->
<!-- +++++ Second Post +++++ -->
<div id="anon3">
<div class="container">
<div class="row">
<div class="col-lg-8 col-lg-offset-2">
<h2><b>Why aren't VPNs enough?</b></h2>
<pre><code class="nim">
Privacy Analogy:
Alice is talking to Bob, but Jack can hear their conversation, they have no privacy.
Alice is talking to Bob, behind closed doors. Jack can't hear their conversation, they now have privacy.
</pre></code>
<p>As explained <a href="../asp/index.html">previously</a>, Privacy is about excluding someone from being able to spy on what you're doing, the <b>whole marketing point for VPNs is to provide privacy for your internet usage, from your internet service provider (ISP)</b> </p>
<img src="1.png" class="imgRz">
<p>By default, you are using your computer from home, from your home connection which is provided by your Internet Service Provider (ISP), and you are using it to access services remotely. <b>In that scenario, your ISP is able to see (to spy on) what you're doing with your internet connection.</b> From there, the entire VPN industry emerged.</p>
<img src="2.png" class="imgRz">
<p>A VPN provider is a centralised entity (see our previous <a href="../governments/index.html">explanation</a> on why these are highly likely to be used as a spying proxy for the governments), they offer you to connect to their infrastructure <b>in order to offer you privacy from your ISP.</b></p>
<p>However when you do that, the VPN provider becomes your ISP, <b>The VPN provider becomes the one who is able to spy on your internet traffic, instead of your ISP.</b></p>
<p>By connecting to a VPN you are moving your trust from your ISP to the VPN provider, <b>but since both your ISP and your VPN provider are centralised entities, you can be damn sure they are spying on what you're doing.</b></p>
<p>Moving your trust from a centralised entity to another is not going to protect you against targeted surveillance. <b>It won't protect you from being reported to the authorities either if you do something illegal.</b></p>
<p><u>DISCLAIMER ON VPNs:</u> Keep in mind that if you choose to use a VPN anyway, you must conduct a strict VPN selection, see <a href="https://www.privacyguides.org/en/vpn/">Privacy Guides' Recommendations</a> on that topic, out of which i recommend <a href="https://kycnot.me/service/Mullvad">Mullvad</a> because they accept Monero without any KYC.</p>
</div>
</div><!-- /row -->
</div> <!-- /container -->
</div><!-- /white -->
<div id="anon2">
<div class="container">
<div class="row">
<div class="col-lg-8 col-lg-offset-2">
<h2><b>Tor Network: the main source of Anonymity</b></h2> </br> </br>
<pre><code class="nim">
Anonymity Analogy:
Jack sees that Alice is talking to Someone. But Jack can't make out who that person is.
Until Jack can figure out who that Someone is, that someone is Anonymous.
</pre></code>
<p>So we can't trust our ISP, nor VPNs alone, what can we trust then ? </p>
<p>That situation is what started the <a href="https://torproject.org">Tor Project</a>. Tor is above all an open source routing protocol, that aims to not only encrypt traffic (like what VPNs do) <b>but the aim is also to obscure where connections come from, and where they go</b>. </p>
<p>It aims to blend all of the users together, to make everyone look the same to prevent any identity correlation. (that is also why you shouldn't edit your tor browser configs, as it will make you stand out as an unique user. <p>
<img src="4.png" class="imgRz">
<p>We have the following scenario: you don't want your internet service provider to know what you're doing, <b>but you also don't want the end services like google youtube or duckduckgo to know that you are accessing their service.</b> in other words, you want to remain Anonymous while browsing the web, and Tor provides that for you.</p>
<img src="5.png" class="imgRz">
<P>Tor is unique as it is the anonymity network that received the most donations, studies and patches, but also due to it's popularity there's alot of nodes ran by anyone (individuals, companies, and potentially also governments), the decentralised aspect is vital there, because <b>by using Tor, you are trusting 3 random entities, in 3 different countries</b></p>
<p>It takes all 3 nodes used by your tor circuit (<b>in 3 different legislations if they are in 3 different countries</b>) to actually be malicious and to record connections to be able to successfully deanonymize you. While at the same time, the Tor protocol does not log any connection by default.</p>
<p>For more details you can see the repartition of tor nodes per <a hrEF="Https://metrics.torproject.org/bubbles.html#country">country</a>, or per <a href="https://metrics.torproject.org/bubbles.html#as">ISP</a> on metrics.torproject.org</p>
<img src="6.png" class="imgRz">
<p>Keep in mind that it is still possible for you to get deanonymized sometimes if you're unlucky to have all 3 nodes ran by the same entity. So <b>it is not perfect</b>, but it is definitely many times more trustworthy than having to trust a centralised entity providing you with a VPN connection. </p>
<p>As we have discussed <a href="../anonymityexplained/index.html">previously</a>, sometimes Anonymity is the difference-maker between Life and Death, especially for Journalism in censorship-heavy countries, Tor's main attraction is that <b>De-anonymization attacks are made to be as expensive as possible</b>, even for state-actors.</p>
<p>Some people argue that Tor can't be trusted, but as we have discussed <a href="govfear">previously</a>, Governments need to be able to know what happened (lack of Privacy), and once they know what happened, they need to know who did it (lack of Anonymity), <b>in order to enforce their laws.</b> When that is the case, <a href="https://status.nowhere.moe/status/darknet">how come is there still so many illegal marketplaces with years of uptime on the Tor network</a> ? One thing is for sure, these marketplaces are very high on international authorities' priority list. If they are still there after all this time, It must be because the Tor network is protecting them from being discovered by the authorities isn't it ?</p>
<p>Even though i don't recommend to use Tor for any illegal purposes, the fact that these marketplaces have remained in activity for such a long time are a clear testament to the resiliency of the Tor network.</p>
</div>
</div><!-- /row -->
</div> <!-- /container -->
</div><!-- /white -->
<!-- +++++ Footer Section +++++ -->
<div id="anonb">
<div class="container">
<div class="row">
<div class="col-lg-4">
<h4>Nihilism</h4>
<p>
Until there is Nothing left.</p></br></br><p>Creative Commons Zero: <a href="../../../../opsec/runtheblog/index.html">No Rights Reserved</a></br><img src="\CC0.png">
</p>
</div><!-- /col-lg-4 -->
<div class="col-lg-4">
<h4>My Links</h4>
<p>
<a target="_blank" rel="noopener noreferrer" href="http://blog.nowhere.moe/rss/feed.xml">RSS Feed</a><br/><a target="_blank" rel="noopener noreferrer" href="https://simplex.chat/contact#/?v=2-7&smp=smp%3A%2F%2FL5jrGV2L_Bb20Oj0aE4Gn-m5AHet9XdpYDotiqpcpGc%3D%40nowhere.moe%2FH4g7zPbitSLV5tDQ51Yz-R6RgOkMEeCc%23%2F%3Fv%3D1-3%26dh%3DMCowBQYDK2VuAyEAkts5T5AMxHGrZCCg12aeKxWcpXaxbB_XqjrXmcFYlDQ%253D&data=%7B%22type%22%3A%22group%22%2C%22groupLinkId%22%3A%22c3Y-iDaoDCFm6RhptSDOaw%3D%3D%22%7D">SimpleX Chat</a><br/>
</p>
</div><!-- /col-lg-4 -->
<div class="col-lg-4">
<h4>About nihilist</h4>
<p style="word-wrap: break-word;"><u>Donate XMR:</u> 8AUYjhQeG3D5aodJDtqG499N5jXXM71gYKD8LgSsFB9BUV1o7muLv3DXHoydRTK4SZaaUBq4EAUqpZHLrX2VZLH71Jrd9k8</p></br><p><u>Contact:</u> nihilist@contact.nowhere.moe (<a href="https://nowhere.moe/nihilist.pubkey">PGP</a>)</p>
</div><!-- /col-lg-4 -->
</div>
</div>
</div>
<!-- Bootstrap core JavaScript
================================================== -->
<!-- Placed at the end of the document so the pages load faster -->
</body>
</html>