Critical Analysis of Tor's Security Claims and Limitations
By
emeryberger
An everything bagel for the brain. Substantive, layered, well-seasoned.
Summary
This article critically analyzes the security claims made by the Tor Project, arguing that their assertion of protecting users from 'anyone monitoring your browsing' is misleading. The author provides a risk calculator that estimates the probability of Tor's failure based on an adversary's financial resources, suggesting that Tor's effectiveness is directly proportional to the monetary capabilities of potential attackers.
Key quotes
· 3 pulledDon't misinterpret this claim. It's not true that Tor protects you against 'anyone monitoring your browsing'
if you estimate your adversary's resources in dollars, I'll estimated the probability that Tor will fail to protect you
The first step in determining if Tor is secure is to ask yourself, How much money does my adversary have?
You might also wanna read
New browser-based side-channel attack uses SSD activity analysis to spy on users
Researchers have discovered a new browser-based side-channel attack that can spy on users by analyzing SSD (Solid State Drive) activity thro
arstechnica.com·2d agoResearchers Demonstrate How Inaudible Audio Commands in Podcasts and Videos Can Hijack AI Voice Assistants
Researchers have demonstrated a new cybersecurity threat where hackers can embed inaudible sounds into podcasts, YouTube videos, or other au
Security researcher claims BitLocker bypass vulnerability may be intentional Microsoft backdoor
A security researcher known as Nightmare-Eclipse has discovered and released YellowKey, a vulnerability that allegedly bypasses Microsoft's
Research Reveals 287 Chrome Extensions Spy on 37 Million Users Through Data Collection
A 2025 investigation reveals that 287 Chrome extensions with 37 million users are secretly spying on users by collecting and exfiltrating br
New FROST Technique Enables Browser-Based SSD Tracking of Website Visitors
A new browser-based tracking technique called FROST (Fingerprinting Remotely Using OPFS-based SSD Timing) allows websites to spy on visitors
Phishing Campaign Targets Signal Users by Stealing Backup Recovery Keys
A new wave of phishing attacks is targeting Signal users by impersonating the app's support team. Hackers send messages inside Signal claimi
cybersecuritynews.com·5h ago