Post #3448553
2026-06-28 12:50 UTC
@avuko@infosec.exchange
Problem with TOR is that the US authorities see it as fair game to attack anyone on TOR "cause it's just used by criminals".
Plus, it is not trivial to use. E.g. by default it covers TCP. UDP etc. packages are not automatically routed through it. So one small unintentional mistake (or an intentionally injected JavaScript?) de-anonymizes you.
It's possible to use it safely, yes, but it's not that easy.
PS: I am speaking from experience. I already got the real IP of an attacker using TOR to attack a customer. Also, once one of our pentesters was identified early due to a small TOR mistake.
Replies (1)
-
@avuko@infosec.exchange 2026-06-28 13:51
@13reak@infosec.exchange yeah, something like the OnionShare software to make it simple to set up and use. Maybe becoming a middle relay in the process, adding to the network.