From Newsgroup: alt.privacy
GabX wrote:
Lately I've started seeing omnimix users again boasting of having modified the tor.exe, the executable present in omnimix, with a patch that goes beyond the three hops recommended by torproject.
This is the position of the torproject
https://support.torproject.org/about-tor/using-and-sharing/circuit-length/
They only try to protect their network from heavier load, which
with nowadays network bandwidths no longer has to be feared.
This is an article (in Italian) that I wrote about it. >https://virebent.art/blog/tor-extended-hops-risks.html
This article is for informational purposes only.
| Critical Analysis
|
| The Paradox of Extended Hops
|
| In anonymity networks, "more" isn't always "better." Understanding the
| statistical risks of non-standard Tor circuits.
|
| Intuition suggests that a longer path is more secure. However, in
| cryptography and distributed networks, anonymity stems not just from
| encryption but from the *anonymity set*rCothe ability to blend into the
| crowd.
|
| Technical Risk Analysis
|
| 1. Behavioral Fingerprinting
|
| Modifying the number of hops moves you from the standard anonymity set
| (99.9% of users) into a statistical niche. A network observer can
| identify you simply by noting the anomalous latency involved in circuit
| construction.
Apart from circuit length there are a lot of factors influencing
circuit construction timing, many of them much more relevant.
|
| 2. Attack Surface Expansion
|
| Each added node represents a potential point of compromise. In a 3-node
| circuit, the probability of an adversary controlling both the Entry and
| Exit nodes is X. In a 6-node circuit, you increase the likelihood of
| including malicious nodes.
The risk of an adversary controlling the entry and exit node
remains the same. Intermediaries are only capable of disrupting
the chain.
|
| 3. Circuit Failure Cascade
|
| Circuit stability is determined by the product of each node's stability.
| The more hops you add, the more likely a node is to "drop," forcing the
| client to rebuild the circuit and creating new timing patterns.
Which won't help an adversary in any way.
|
| 4. Timing Analysis
|
| Long circuits possess unique latency "signatures." A global adversary
| can correlate traffic much more easily if your round-trip time (RTT)
| consistently deviates from the network average.
That's about a global adversary, who controls multiple server
connections for a longer period of time. OTOH with Tor we have
Hidden Services, which also increase round-trip time in an
unpredictable way.
Nevertheless such correlation and timing analysis attacks are the
reason why no realtime data transmission method can provide true
anonymity, which is why OmniMix uses Tor just to deliver encrypted
packets to their respective entry remailers, where the true
anonymization process then takes place. And that's why potential
users of your webmailer snake oil service should als rethink their
choice of sending clear text messages (!) through Tor.
|
| Probability of hitting a compromised node: 3 Hops vs. 6 Hops
| +100% Exposure Risk
|
| Based on a network simulation with 10% adversary nodes.
It results in a broken circuit, whihc then gets rebuilt. So what?
|
| The Malicious Node Paradox
|
| Adding hops in the "middle" of the circuit does not protect against
| end-to-end (Entry-Exit) correlation attacks. If an adversary controls
| the first and last nodes, the length of the intermediate chain is
| irrelevant: anonymity is already compromised.
With 3-hop chains it's a tiny additional step to have the complete
chain compromised and you're toast. No need of performing any
lengthy correlation tests, a bargain for an adversary.
|
| Conclusions
|
| For most users, including those using NNTP or SMTP services, the Tor
| Project's standard 3-hop configuration remains the safest choice. True
| security lies not in the length of the chain, but in the ability to
| remain indistinguishable from millions of other users.
No, finally it's time for the Tor development team to increase
circuit length to reduce the risk of all your hops being held by a
single entity, which is the fundamental problem here.
--- Synchronet 3.22a-Linux NewsLink 1.2