Post
Topic
Board Development & Technical Discussion
Re: Is someone monitoring large parts of the network? (evidence+firwall rules)
by
ABISprotocol
on 13/03/2015, 22:03:53 UTC
On the TOR point specifically, numerous studies have been done that have revealed problems involving the use of TOR and bitcoin in combination, leading to vulnerabilities that have not yet been mitigated.
Your comment is confused and misleading.

The "problems" reported initially is that an attacker can DOS attack to cause IPv4 nodes to block nodes behind Tor. This is true, but we were always aware of that and implemented hidden service bitcoin nodes as a tool to improve that. The paper was revised to also point out that you could concurrently DOS attack hidden service nodes-- which is generally true with or without tor, but there are not as many HS nodes.

The end result of all that though is just a DOS attack. Maybe if an attack happened, which isn't currently happening, you might have problems getting a new connection after starting your software.  This is completely safe, it might be irritating but your privacy would not be compromised unless you took the affirmative (and obviously foolish) action of disabling Tor support in your wallet.

None of this is a reason to not use Tor-- it's a reason, among _many_, that Tor doesn't solve all possible problems but you lose nothing by using it.  It's harmful to the community for you to promote otherwise.

Actually, I use TOR myself.  I just disagree that we should blindly use TOR with bitcoin or suggest that users do the same thing without warning people of the possible consequences.

See in my remarks on github where I suggested one possible option:

"Appropriate warnings for users who are using OpenBazaar (which incorporates bitcoin use) with Tor should be something like this: "Warning: Proceed at your own risk," or, "Warning: Use of Tor and Bitcoin together may result in additional attack vectors that could compromise your privacy. Do you wish to proceed?"

This is not a slam on OB either because I use OpenBazaar.  I simply think it is ridiculous to not warn people of possible risks.