"The Tor Project’s mission is to advance human rights and freedoms." - I might be completely barking up the wrong tree here, but I thought the TOR mission was to allow spies to access the network and hide among all the other non-spy users.

It was and still is funded mostly by the US Naval Research Laboratory. And considering most of the nodes are hosted on American cloud infra, if those companies share with the US Govt in real-time what is connecting in and out then the entire chain can be figured out much of the time without any kind of timing attacks. The regular person using it doesn't get as much of the privacy benefits, but the charade is making it seem like they do.

I know lots of people really believe in TOR - fair play to them. I just know it in my bones it's not as it seems.

From what I recall, talking to one of the Tor founders about this, Tor was created with overseas US military personnel in mind. E.g. A soldier’s location could be compromised through foreign ISPs if they accessed sites like .mil domains directly. Tor was a way of preventing this problem. There were other use cases but this one stood out for me and it was one of the initial ones considered.

Pretty on point with what I'm saying. I remember when Tor first launched and it was definitely framed at the time as for human rights. I absolutely believed all of that for years.

You yourself spoke with the founder about this?

The development of onion routing funded by the NRL had a bunch of use cases including the one I mentioned. By the time Tor (The Onion Router) launched, and definitely by the time the Tor Project came along, more general use cases and human rights were a significant part of it.

I did have the chance to attend a talk by one of the cofounders and have a conversation with him afterwards. This was at a math conference a little over a decade ago.

Meh, and yet anyone can run a relay or onion service in a few clicks.

It's the best tool regular people have for privacy without a doubt.

>The regular person using it doesn't get as much of the privacy benefits, but the charade is making it seem like they do.

Just false.

If your model is simply to avoid corporate surveillance and tracking its a fantastic defense.

If your trying to go up against nation states, it never claimed to protect you from that.

'Meh, and yet anyone can run a relay or onion service in a few clicks.' - of course.

'Just false.'

It depends where you are from. The US constitution is supposed to prevent spying on American citizens, but anyone outside of the USA is fair game. Most of the global population is not in the USA (like me).

'If your model is simply to avoid corporate surveillance and tracking its a fantastic defense.' - I host an onion service exactly for that reason, not for my own privacy but to let customers have that with us if they want.

'If your trying to go up against nation states, it never claimed to protect you from that.' - I disagree, it will protect an American spy a treat.

That's a lot of allegations.

> the TOR mission was to allow spies to access the network and hide among all the other non-spy users

Tor is pretty clear about what their mission is, it's at the bottom of the Tor Project homepage https://www.torproject.org: "To advance human rights and freedoms by creating and deploying free and open source anonymity and privacy technologies, supporting their unrestricted availability and use, and furthering their scientific and popular understanding."

Claiming anything else is useless conspiracy thinking without evidence.

> It was and still is funded mostly by the US Naval Research Laboratory

The original idea came from the US Naval Research Laboratory, yes (as a way to mask the origin of messages to hide the command boat in a fleet), but the funding statement is patently false. In 2024, the majority of their government funding ($2.1M out of $2.5) came from the U.S. State Department Bureau of Democracy, Human Rights, and Labor, with the rest of the government money coming from even more innocuous sources. You can find this information on p41 of their IRS form: https://www.torproject.org/static/findoc/2023-2024-TheTorPro... also accessible from their Reports page at https://www.torproject.org/about/reports/

They also clarified that in this more readable post: https://forum.torproject.org/t/transparency-openness-and-our...

Certainly, you can speculate about the motivations of the U.S. State Department Bureau of Democracy, Human Rights, and Labor and whether that's a front for more undercover objectives, but that front lines up pretty well with the US's (former?) foreign policy of undermining (unfriendly) dictatorial regimes, and Occam's Razor applies.

Ultimately though, the tools that Tor provides can absolutely be abused by bad actors, and ever since Silk Road, I've become convinced that the Tor network is overrun by a wretched hive of scum and villainy, where those morally defensible activities are utterly outnumbered by the criminal ones.

"Claiming anything else is useless conspiracy thinking without evidence."

Using the word "conspiracy" in this conversation about TOR is wild to me.

In a post-Snowden world, it surprises me how anyone wouldn't give reasonable doubt to the THE most interesting and juicy tool linked to the US military post-2001. The tool that people think hides what they are doing and hides who they are.

If there's one thing I know, it's that the US would never in a million years leave a data source untapped or a new NIST crypto standard untampered. Their fingers are in every pie.

> I thought the TOR mission was to allow spies to access the network and hide among all the other non-spy users.

Both things can be true... the original need for the network necessitated the mission of the foundation itself... you can't have a global network that only spies use, or you're not blending in, so you have to make it about a public good that many civilians will also use.

Other systems like I2P, SimpleX, Tribler, Datura etc. take additional steps to mitigate such kinds of Sybil attacks that people talk about against Tor, and new methods are being worked on all the time.

Splitting up your traffic across multiple nodes/circuits/etc. as well as persistent dummy/decoy traffic are some methods I've seen discussed recently.

> if those companies share with the US Govt in real-time

IMO This is a colossal "if" and not something we can realistically determine besides saying "we know it happens sometimes, but certainly not all or even most of the time."

Everyone's threat model is different, and hiding from state-level actors is generally 1. much too complicated to succeed at, and 2. you're probably not that special in the first place that you'd actually be targeted. The privacy community is bursting at the seams with all manner of tinfoil-hat wearers and wild conspiracy theorists that think some dark boogeyman is out to get them.

I'd also like to see a source that proves "most of the nodes are hosted on American cloud infra."

I'd also like to see a source that proves "most of the nodes are hosted on American cloud infra."

I will make a correction. What I should have said is that out of the top 10 networks hosting relays or exit nodes, that close to half have an American presence and that the vast majority 80-90% of relays and exit nodes are spread out within 14 eyes countries - you can see it yourself when you look at the network. When was the last time you looked at where it was connected to and did not see a flag within either 5 eyes, 9 eyes or 14 eyes countries? While that maybe isn't the proof you want, it sure is a meaty coincidence and another reason on top of who funds it and what its purpose is for.

How secure is SimpleX? I saw a lot of tinfoil hat people on Reddit claiming that it's the next coming of Signal.