"The Tor Project’s mission is to advance human rights and freedoms." - I might be completely barking up the wrong tree here, but I thought the TOR mission was to allow spies to access the network and hide among all the other non-spy users.
It was and still is funded mostly by the US Naval Research Laboratory. And considering most of the nodes are hosted on American cloud infra, if those companies share with the US Govt in real-time what is connecting in and out then the entire chain can be figured out much of the time without any kind of timing attacks. The regular person using it doesn't get as much of the privacy benefits, but the charade is making it seem like they do.
I know lots of people really believe in TOR - fair play to them. I just know it in my bones it's not as it seems.
Meh, and yet anyone can run a relay or onion service in a few clicks.
It's the best tool regular people have for privacy without a doubt.
>The regular person using it doesn't get as much of the privacy benefits, but the charade is making it seem like they do.
Just false.
If your model is simply to avoid corporate surveillance and tracking its a fantastic defense.
If your trying to go up against nation states, it never claimed to protect you from that.
That's a lot of allegations.
> the TOR mission was to allow spies to access the network and hide among all the other non-spy users
Tor is pretty clear about what their mission is, it's at the bottom of the Tor Project homepage https://www.torproject.org: "To advance human rights and freedoms by creating and deploying free and open source anonymity and privacy technologies, supporting their unrestricted availability and use, and furthering their scientific and popular understanding."
Claiming anything else is useless conspiracy thinking without evidence.
> It was and still is funded mostly by the US Naval Research Laboratory
The original idea came from the US Naval Research Laboratory, yes (as a way to mask the origin of messages to hide the command boat in a fleet), but the funding statement is patently false. In 2024, the majority of their government funding ($2.1M out of $2.5) came from the U.S. State Department Bureau of Democracy, Human Rights, and Labor, with the rest of the government money coming from even more innocuous sources. You can find this information on p41 of their IRS form: https://www.torproject.org/static/findoc/2023-2024-TheTorPro... also accessible from their Reports page at https://www.torproject.org/about/reports/
They also clarified that in this more readable post: https://forum.torproject.org/t/transparency-openness-and-our...
Certainly, you can speculate about the motivations of the U.S. State Department Bureau of Democracy, Human Rights, and Labor and whether that's a front for more undercover objectives, but that front lines up pretty well with the US's (former?) foreign policy of undermining (unfriendly) dictatorial regimes, and Occam's Razor applies.
Ultimately though, the tools that Tor provides can absolutely be abused by bad actors, and ever since Silk Road, I've become convinced that the Tor network is overrun by a wretched hive of scum and villainy, where those morally defensible activities are utterly outnumbered by the criminal ones.
> I thought the TOR mission was to allow spies to access the network and hide among all the other non-spy users.
Both things can be true... the original need for the network necessitated the mission of the foundation itself... you can't have a global network that only spies use, or you're not blending in, so you have to make it about a public good that many civilians will also use.
Other systems like I2P, SimpleX, Tribler, Datura etc. take additional steps to mitigate such kinds of Sybil attacks that people talk about against Tor, and new methods are being worked on all the time.
Splitting up your traffic across multiple nodes/circuits/etc. as well as persistent dummy/decoy traffic are some methods I've seen discussed recently.
> if those companies share with the US Govt in real-time
IMO This is a colossal "if" and not something we can realistically determine besides saying "we know it happens sometimes, but certainly not all or even most of the time."
Everyone's threat model is different, and hiding from state-level actors is generally 1. much too complicated to succeed at, and 2. you're probably not that special in the first place that you'd actually be targeted. The privacy community is bursting at the seams with all manner of tinfoil-hat wearers and wild conspiracy theorists that think some dark boogeyman is out to get them.
I'd also like to see a source that proves "most of the nodes are hosted on American cloud infra."
From what I recall, talking to one of the Tor founders about this, Tor was created with overseas US military personnel in mind. E.g. A soldier’s location could be compromised through foreign ISPs if they accessed sites like .mil domains directly. Tor was a way of preventing this problem. There were other use cases but this one stood out for me and it was one of the initial ones considered.