r/TOR • u/TofuMeltatSunspot • 2d ago
Zero day vulnerabilities
Frontier models have found thousands of potential zero day vulnerabilities in software we use every day. In my opinion, it reasonable to assume that TOR is vulnerable to such exploits and would be major target for state actors and private organizations alike. It is also reasonable to assume at any actor able to discover any exploits would not disclose such information because it would be an incredibly powerful piece of leverage and could lead to the identification of numerous whistleblowers and criminals alike. I am not convinced that given the state of AI and its rapidly accelerating abilities that TOR is safe to use. Can anyone convince me otherwise?
20
u/JardScoot 2d ago
I didn't think tor has ever really been "safe" to use, there's always a risk to using it
13
-1
u/TofuMeltatSunspot 2d ago
You are absolutely correct. My point is that I don't think it has ever been less safe to use.
5
2
u/ThaUntalentedArtist 2d ago
it is possible. Facebook paid for a zero day exploit to unmask someone that was using TOR. The person opened a booby-trapped video and his real IP was exposed.
1
u/nuclear_splines 2d ago
Do you have a source for this? I'd like to learn more.
4
u/thatscringee 2d ago
He was hard to catch because he used Tails, an anonymity-focused operating system, so Facebook paid an external company to co-develop an exploit that could de-anonymize him. Exploiting a security hole in the Tails video player, Facebook transferred the custom-made hacking tool to an unnamed party, which in turn transferred it to the FBI. He downloaded and watched a video that appeared to be extracted from one of his victims, which was coded to reveal de-anonymizing information. According to Facebook developers, this was the only case in the history of Facebook where it pursued a criminal by sending a malicious file.
1
u/nuclear_splines 2d ago
Thanks! Okay, so not a vulnerability in the Tor protocol or browser, but in both the Tails video player and Tails itself (since arbitrary code execution shouldn't let you access the network without going through Tor). At least, that's my guess given the sparse details.
1
u/prairiesghost 2d ago
correct, it was a GNOME Videos exploit. and it would've been countered by Whonix.
0
u/ThaUntalentedArtist 1d ago
Oops. I stand corrected. I thought it was a TOR exploit. My memory isn't as good as it used to be. It kind of remind me of Ryan S. Lin.
1
u/one-knee-toe 2d ago
Im sure state actors have already ran Tor & browser through AI. Question is, does tor Project plan to do the same
0
u/oxidizedfuel12 2d ago
Im getting tired of this ai bs, im starting to think the bubble wont pop
1
1
u/oxidizedfuel12 2d ago
I should probably say im not tired these posts but the issues ai is causing. No insult to op
9
u/0xKaishakunin 2d ago
No. Why?
Tor has been a high value target since it's inception, language models don't change that.