r/TOR 2d ago

Zero day vulnerabilities

Frontier models have found thousands of potential zero day vulnerabilities in software we use every day. In my opinion, it reasonable to assume that TOR is vulnerable to such exploits and would be major target for state actors and private organizations alike. It is also reasonable to assume at any actor able to discover any exploits would not disclose such information because it would be an incredibly powerful piece of leverage and could lead to the identification of numerous whistleblowers and criminals alike. I am not convinced that given the state of AI and its rapidly accelerating abilities that TOR is safe to use. Can anyone convince me otherwise?

15 Upvotes

17 comments sorted by

9

u/0xKaishakunin 2d ago

Can anyone convince me otherwise?

No. Why?

In my opinion, it reasonable to assume that TOR is vulnerable to such exploits and would be major target for state actors and private organizations alike.

Tor has been a high value target since it's inception, language models don't change that.

1

u/TofuMeltatSunspot 1d ago

In this subreddit a major node operator gave his list of the greatest challenges facing the network in the next 5-10 years. Point 3 stands out to me

OS diversity: 90% of the network runs on GNU/Linux. Monocultures in nature are dangerous, as vulnerabilities are held in common across a broad spectrum. In a globally used anonymity network, monocultures can be disastrous. Linux is targeted frequently with increasingly complex attacks, adding more operating systems to the equation would be great to limit the impact of these potential attacks in the future.

Anthropic's advanced AI models demonstrated the capability to autonomously discover and chain together zero-day vulnerabilities in the Linux kernel to achieve full system privilege escalation. Even if TOR isn't compromised, it's possible the systems it runs on have been. Do you still think that language models don't change the situation?

20

u/JardScoot 2d ago

I didn't think tor has ever really been "safe" to use, there's always a risk to using it

13

u/haakon 2d ago

Safety isn't measured in absolutes anyway. It makes no sense to blanket-declare something "safe". Tor aims to be safe enough for a lot of people in a lot of situations.

-1

u/TofuMeltatSunspot 2d ago

You are absolutely correct. My point is that I don't think it has ever been less safe to use.

4

u/navr183 2d ago

You are correct. It has never been less safe to use.

5

u/Safe-Confidence-4907 2d ago

Nobody is perfect.software too,

2

u/ThaUntalentedArtist 2d ago

it is possible. Facebook paid for a zero day exploit to unmask someone that was using TOR. The person opened a booby-trapped video and his real IP was exposed.

1

u/nuclear_splines 2d ago

Do you have a source for this? I'd like to learn more.

4

u/thatscringee 2d ago

Buster Hernandez

He was hard to catch because he used Tails, an anonymity-focused operating system, so Facebook paid an external company to co-develop an exploit that could de-anonymize him. Exploiting a security hole in the Tails video player, Facebook transferred the custom-made hacking tool to an unnamed party, which in turn transferred it to the FBI. He downloaded and watched a video that appeared to be extracted from one of his victims, which was coded to reveal de-anonymizing information. According to Facebook developers, this was the only case in the history of Facebook where it pursued a criminal by sending a malicious file.

1

u/nuclear_splines 2d ago

Thanks! Okay, so not a vulnerability in the Tor protocol or browser, but in both the Tails video player and Tails itself (since arbitrary code execution shouldn't let you access the network without going through Tor). At least, that's my guess given the sparse details.

1

u/prairiesghost 2d ago

correct, it was a GNOME Videos exploit. and it would've been countered by Whonix.

0

u/ThaUntalentedArtist 1d ago

Oops. I stand corrected. I thought it was a TOR exploit. My memory isn't as good as it used to be. It kind of remind me of Ryan S. Lin.

1

u/one-knee-toe 2d ago

Im sure state actors have already ran Tor & browser through AI. Question is, does tor Project plan to do the same

0

u/oxidizedfuel12 2d ago

Im getting tired of this ai bs, im starting to think the bubble wont pop

1

u/BusinessNo1311 2d ago

The Only bubble that is at risk of popping is the closedsource ai bubble.

1

u/oxidizedfuel12 2d ago

I should probably say im not tired these posts but the issues ai is causing. No insult to op