Tor says it’s “still safe” amid reports of police deanonymizing users

Share:

The Tor Project is attempting to assure users that the network is still safe after a recent investigative report warned that law enforcement from Germany and other countries are working together to deanonymize users through timing attacks.

The team behind the specialized web browser claims that adequate protections are in place for those using the latest versions of its tools, noting that timing analysis is a known technique for which effective mitigations exist.

Busting “Boystown” through Tor

Tor is a privacy tool and web browser that anonymizes your identity by bouncing your internet traffic through several computers (nodes) worldwide, making it difficult to trace where your traffic came from.

Read More

Due to its privacy assurances, it is commonly used by activists and journalists when communicating with sources and to bypass censorship in countries with oppressive governments. While the project has a long list of legitimate uses, due to its anonymity, it is also used by cybercriminals to host illegal marketplaces and to evade law enforcement.

An investigative report by the German portal Panorama, supported by the Chaos Computer Club (CCC), says court documents revealed that law enforcement agencies use timing analysis attacks through a large number of Tor nodes they operated to identify and arrest the operators of the child abuse platform “Boystown.”

A Tor timing attack is a method used to deanonymize users without exploiting any flaws in the software, but rather by observing the timing of data entering and leaving the network.

If the attacker controls some of the Tor nodes or is monitoring the entry and exit points, they can compare the timing of when data enters and leaves the network, and if they match, they can trace the traffic back to a particular person.

“The documents related to the information provided strongly suggest that law enforcement agencies have repeated and successfully carried out timing analysis attacks against selected gate users for several years to deanonymize them,” stated CCC’s Matthias Marx.

Panorama highlights the ever-worsening problem of large portions of the Tor network’s servers being controlled by a small number of entities, creating an environment that makes these timing attacks more feasible.

The report also mentions that one of the identified users was using an outdated version of Ricochet, an anonymous instant messaging app that relies on the Tor network to create private communication channels.

That older Ricochet version, which does not include Vanguard protections, is vulnerable to ‘guard discovery attacks,’ which allow the unmasking of the user’s entry node (guard).

Tor’s response

The Tor Project expressed frustration for not being provided access to the court documents that would enable them to analyze and validate security-related assumptions.

However, the organization still published a statement to reassure users based on what information they had.

The Tor Project statement highlights that the described attacks occurred between 2019 and 2021, but the network has significantly increased since then, making timing attacks much harder to pull out now.

Additionally, extensive work to flag and remove bad relays has taken place in the past years, and efforts to put a break on centralization yielded tangible results.

Concerning Ricochet, Tor notes that the version used by the deanonymized user was retired in June 2022 and has been replaced by the next-gen Ricochet-Refresh, which features Vanguards-lite protections against timing and guard discovery attacks.

Finally, Tor acknowledges the pressing issue of relays diversity, calling volunteers to help and highlighting various initiatives they launched recently to introduce more bandwidth and variety on the network.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:39 pm, Jun 22, 2025
weather icon 20°C
L: 18° | H: 20°
scattered clouds
Humidity: 67 %
Pressure: 1011 mb
Wind: 14 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 48%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
18° | 20°°C 0.66 mm 66% 14 mph 77 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
13° | 24°°C 0.2 mm 20% 14 mph 81 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 11 mph 88 % 1014 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
17° | 25°°C 1 mm 100% 15 mph 84 % 1018 mb 0 mm/h
Fri Jun 27 10:00 pm
weather icon
15° | 28°°C 0 mm 0% 15 mph 70 % 1020 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 13 mph 70 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 18°°C 0.66 mm 66% 14 mph 77 % 1011 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0.2 mm 20% 13 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 am
weather icon
18° | 18°°C 0 mm 0% 13 mph 45 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
20° | 20°°C 0 mm 0% 13 mph 32 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
23° | 23°°C 0 mm 0% 14 mph 30 % 1014 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
21° | 21°°C 0 mm 0% 14 mph 40 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 17°°C 0 mm 0% 11 mph 55 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€86,125.25
-2.17%
Ethereum(ETH)
€1,894.27
-4.57%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.71
-3.62%
Solana(SOL)
€112.06
-2.98%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.128026
-3.39%
Shiba Inu(SHIB)
€0.000009
-3.77%
Pepe(PEPE)
€0.000008
-5.73%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top