Lazycoder

11Sep/064

Whoops, careful when you join the TOR network.

Germany: Crackdown on TOR-node operators

The public prosecutor’s office of Konstanz raided computing centres of seven providers in Germany,
seizing ten servers because of the proliferation of child pornography.
Nothing new, things like that happen all the time, the juicy detail is
that some of the servers were merely running a copy of the TOR, a software to anonymize the usage of the internet to protect your privacy.

Those servers were most probably configured to be TOR Exit-Nodes, so
their IP-addresses might have shown up in the server logfiles of the
child-porn servers in question. One could argue that this is an attempt
to frigthen german TOR-node operators, but I’d just keep calm for the
moment. I guess that the attorney of state is just after logfiles, they
knew that those servers were operating as TOR-nodes. If you IP-address
pops up in a child-porn case surely your IP looks interesting to the
police.

A while ago, I suggested using TOR to securely browse the web. A few people around the web suggested that this could be risky. It could mean your IP address shows up in a log file somewhere associated with some illegal operation. It looks like that’s what is happening in Germany right now. While this kind of thing is probably defensible, it means more money for lawyers. I’d recommend AGAINST using the TOR software right now. I think your best bet for secure browsing is tunneling your web traffic over SSH to a private proxy server, one you or your friends control.

Update: Take note of the two comments associated with this post. It appears to be safe to use TOR to browse the web as TOR is not enabled to act as a server by default upon startup. It has also been noted that they German police were not cracking down on TOR servers just because they were TOR servers, but as surmised by myself and others that the TOR servers IP address showed up in some logs during a child porn investigation.

Filed under: General Leave a comment
  • http://itnomad.wordpress.com/ Alexander Janssen

    Your up to a misconception here. If you, as a user, use TOR, your IP does not show up in the logfiles of the server you want to connect to but the last TOR-server in the chain.
    As long as you don’t run a TOR-server which also acts as a TOR exit-node you are safe.
    This is what TOR is about.

    Example:
    You TOR-Entry-Node TOR-MIX-Node TOR-MIX-Node TOR-Exit-Node Destination

    Only the IP-address of the TOR-Exit-Node shows up in the logfiles of the destination host.

    So, it is perfectly safe (from a naive point of view) to use TOR as a user. Running a TOR-server which offers the service to other people is an entirely different story.

    If you still have questions, drop me a line. Hope that helps!
    Alexander.

  • http://tor.eff.org Shava Nerad

    Last week, a few Tor exit-node servers were seized by the German police in a massive sting against child pornography. From our friends on the ground in Germany, we hear that dozens and dozens of machines may have been seized.

    So far as we know only six of those were Tor servers. We have heard from the server operators. None of them has been charged.

    This is not a “crackdown” on Tor, as has been widely reported. We expect and hope that the volunteer Tor server operators in Germany will get their equipment back after this has blown over, and there will be no action against Tor.

    Please contact me for more information.

    Shava Nerad
    executive director
    The Tor Project
    shava -at- freehaven -dot- net

  • Scott

    Alexander and Shava:

    Thank you for your comments. I’ll append my post.

  • fake rolex watches

    As the business grows, rolex replicas has also jumped into an international brand. It is worth mentioning that,replica rolex watches is the ancestor of today’s brand-oriented, in order to protect the quality and brand name will be printed on their products, the history of fashion in the world, is the first one first.rolex replica watches, fake rolexfake rolex watches .fake omega watches
    replica omega watches
    tag heuer replica watches
    tag heuer watches.http://www.erowatch.com