Oh boy. The first line of any blog post on how to create a Tor Exit Node should be: DON'T.
If you really want to, first do a metric shitload of legal and commercial prep work, including picking a specific ISP for the exit node, registering an LLC or equivalent to be the legal entity that owns the exit node, and all sorts of steps that mean when the inevitable deluge of traffic from hackers, bittorrenters and so on come through your exit node, you're at least somewhat insulated from the blowback you'll get. Prepare for answering legal queries about your exit node being your full time job.
Read https://blog.torproject.org/tips-running-exit-node/ first, and note that even that post is 8 years old.
If you merely want there to be more Tor exit nodes in the world, I recommend you donate to an existing operator of them, like https://torservers.net/ -- if you read their blog, https://torservers.net/blog/ , you'll see the latest entries (also from 8 years ago) are about seized servers and arrested operators.
If you want to donate your ISP bandwidth for improving the Tor network, do it by running a guard relay or middle relay, that is relatively straightforward.
I don't really agree with this entirely. Yes, you can be paranoid and only run them when you're absolutely sure there won't be any trouble. Alternatively, we can run so many and the police can learn that nothing happens from raiding one, and then there won't be any legal trouble. Also, you aren't living if you aren't taking risks.
Bit overblown? I have ran many over the years. Another option is don't have a legal presence in the US. Many of these issues disappear. Many US companies will rent you hardware and when there is an issue move on.
That's an intense reaction. Do you have experience doing it?
I got in huge trouble hosting one of these when I was a kid.
I saw some call-to-arms post that got me excited for the free internet and set it up on my parents' residential service.
You can imagine the fallout. No permanent damage though.
Well? Tell us the story. What happened?
I ran an exit node about 15y ago on a free IP. After a few weeks, I found malware files (not deployed) on the desktop. They reappeared after deletion a few times. I concluded the experiment and wiped the system.
Some time later I tried running a middle relay (VM non-persistent live distro) but Dan List (then) didn't differentiate between between exit and other node types and my public IP kept getting blacklisted. I eventually gave up.
There are still blacklists that don't differentiate. They'll even list it as "verified malicious activity originating from the host", and security products that gather all IP blacklist services and take them at face value will block your IP.
Wow....
> I’ll go with Ubuntu 14.04 (Trusty)
This is extremely old. I am aware that the Tor project tries to keeps their defaults sane for any use, but someone has checked that the configuration here is still valid for this use?
Also, running tor as a root is bad idea, I don't think the client allows you to anymore (or at least warns you)
> This is extremely old. I am aware that the Tor project tries to keeps their defaults sane for any use, but someone has checked that the configuration here is still valid for this use?
Article was published in 2015. Seems 14.04 was the LTS, as the time of writing.
So let me ask this: How hard is it to create a temporary exit node that is basically a rasberry pi with a sim card or wifi connection say from a cafe, or any other public wifi, ans are online for say na hour or two? If we had enough of these scattered around, would it matter?
> So let me ask this: How hard is it to create a temporary exit node that is basically a rasberry pi with a sim card or wifi connection say from a cafe, or any other public wifi, ans are online for say na hour or two?
It's not hard at all.
> If we had enough of these scattered around, would it matter?
No. Your relays won't be trusted with significant amounts of traffic until they've been up for a few weeks.
The last time I looked into it, exit nodes have a long “ramp up” period of many days. If this is still true, you’re not going to be serving much purpose with a collection of transient nodes.
How is that trust anchored? To public IPs or to public keys?
It's not trust, it's uptime. Tor trusts only the directory authorities, not any nodes. A node that is going up and down won't be used much. They can be used as middle nodes, since those are ephemeral.
If it's IP, it will be the incoming IP, not outgoing. You might want a stable central node that routes outgoing traffic to the currently active transient edge node.
You can't move a fingerprint's IP without bringing it down, anyway, because the directory consensus is cached for a while and your node will look down to other nodes until they get the latest one.
I wonder, according to law, what are the outcomes of maintaining an exit node, apart from having, I quote, _balls of steel_
According to law, in most places, it's legal. The legal problems people are worried about are not being charged and convicted, they are everything that happens before the conviction. Police can raid your home, take all your electronics and shoot your dog - sometimes. Other times they go, oh that's a tor exit mode, we won't get anything from that.
depends on the jurisdiction
in the us, entirely legal. you may get law enforcement knocking on your door with questions, from time to time.
best to do it as part of a non profit or other organization, and being open about running a node, so that law enforcement/etc knows what they're dealing with
> you may get law enforcement knocking on your door with questions
If you host an exit node on your home internet connection, the daily thing you will struggle with is not law enforcement, but rather the fact that your public IP will be blocked by most big websites to the point that simply browsing the web will become a pain.
Then whoever did this experiment will likely shut down the node and reset their router to pull a new IP, which could be reassigned in short order, thereby causing trouble for an innocent neighbor.
Use a VPN on your router to avoid this issue.
> best to do it as part of a non profit or other organization
I've always thought that universities would be a great safe haven for exit nodes, probably managed by a student club but using campus's infra (with their fully informed permission and support, of course).
I think this would make them less likely to be shut down by the police because a university would lend them more credibility as a civic-driven research project rather than some random person running "shady" stuff, as most people unfortunately assume.
Here in Mexico there's very few Tor nodes running at all, but some of the longest running (non exit, TIL) nodes are run by UNAM [1], which is the biggest university.
That being said, I studied in a different university and I didn't have the confidence or knowledge to propose anything similar, so I've no idea of how effective would such a project be or how hard would it be to run.
[1] https://metrics.torproject.org/rs.html#search/country:mx
They are. In general, having a big and respected institution to hide behind does wonders for avoiding suspicion. It would have to be formally approved by whoever is responsible for these things at the university - you couldn't just plug it into a random port (well you could but you might get Aaron Swartzed).
I note that Linode will still let you run exit nodes on their infra (though they may ask you to respond to specific complaints to reduce the exit policy).
stupid questions for a guy with no idea about TOR
- how is it better than a VPN
- how is it untraceable
- what makes you think you dont get tagged by 3 letter agencies when are you trying to download it for the first time?
> how is it better than a VPN
There isn’t one centralized entity with your email address and credit card information on file that can pass it on wittingly or otherwise to interested parties.
> how is it untraceable
It’s not. It tries to be by routing your connection through a random set of relays + exit node (each peeling back one layer of encryption, like an onion), but it hinges on the assumption that those nodes aren’t all operated by the same entity. If the network is dominated by a bad actor (at one point the FBI had a large fraction), your route can land entirely on their nodes, and they can associate the original request with the decrypted request at the exit node. Of course you’re still protected by regular internet security, plus the browsers often take additional measures to make tracing harder, but it’s definitely not a guarantee.
> what makes you think you dont get tagged by 3 letter agencies […]
You absolutely do, lots of mainstream media coverage about this.
thank you very much, my biggest concern is i want to be learn how to use tor and how it works and fiddle with it and what not but the 3rd point is my major concern. i dont want to get tagged for someone that is just experimenting with it
Using tor doesn't hurt. They probably know which people have used tor at least once in their lives, but it's so many people it's useless information. All it really shows is that the people on the list know their way around a computer.
I'm even using it right now, to post this comment!
Half the websites on the internet will block you while you're using it though.
>harrased by ISP
Or the FBI setting you up and jail you for 3 years
https://rockenhaus.com/
Not to fear monger, in fact, the more people run exit node the harder it will be to go after individuals.