Quantcast
Viewing latest article 1
Browse Latest Browse All 2

Answer by davidgo for Why do people discourage using Tor with a VPN?

I believe your premise is wrong. In the logical case of using TOR over a VPN (ie connect a VPN, then connect to TOR through the VPN) -

https://support.torproject.org/faq/faq-5/ links to https://gitlab.torproject.org/legacy/trac/-/wikis/doc/TorPlusVPN (ie its authorative) which has a lot more nuance and states (bolding mine):

You can very well decrease your anonymity by using VPN/SSH in addition to Tor. (Proxies are covered in an extra chapter below.) If you know what you are doing you can increase anonymity, security and privacy.

Most VPN/SSH provider log, there is a money trail, if you can't pay really anonymously. (An adversary is always going to probe the weakest link first...). A VPN/SSH acts either as a permanent entry or as a permanent exit node. This can introduce new risks while solving others.

Who's your adversary? Against a global adversary with unlimited resources more hops make passive attacks (slightly) harder but active attacks easier as you are providing more attack surface and send out more data that can be used. Against colluding Tor nodes you are safer, against blackhat hackers who target Tor client code you are safer (especially if Tor and VPN run on two different systems). If the VPN/SSH server is adversary controlled you weaken the protection provided by Tor. If the server is trustworthy you can increase the anonymity and/or privacy (depending on set up) provided by Tor.VPN/SSH can also be used to circumvent Tor censorship (on your end by the ISP or on the service end by blocking known tor exits).

In other words the risks change, but it could be beneficial if you know what you are doing - I guess the question is do you trust your VPN or the TOR entry nodes more, and how well do you understand what VPN's, TOR and your routing stack does?

Apparently, it is possible to run a VPN over TOR - this would not be a good idea in most cases - because this would slow down your connection while quite possibly bringing more scrutiny to your traffic and giving you very little - if any benefit from using Tor. There are a few niche cases this might be useful to get around firewalls, but by-and-large is a bad idea.


Viewing latest article 1
Browse Latest Browse All 2

Trending Articles