FAQ 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123
  1. The Onion Routing (TOR) Frequently Asked Questions
  2. --------------------------------------------------
  3. 1. General.
  4. 1.1. What is tor?
  5. Tor is an implementation of version 2 of Onion Routing.
  6. Onion Routing is a connection-oriented anonymizing communication
  7. service. Users build a layered block of asymmetric encryptions
  8. (an "onion") which describes a source-routed path through a set of
  9. nodes. Those nodes build a "virtual circuit" through the network, in which
  10. each node knows its predecessor and successor, but no others. Traffic
  11. flowing down the circuit is unwrapped by a symmetric key at each node,
  12. which reveals the downstream node.
  13. Basically tor provides a distributed network of servers ("onion
  14. routers"). Users bounce their tcp streams (web traffic, ftp, ssh, etc)
  15. around the routers, and recipients, observers, and even the routers
  16. themselves have difficulty tracking the source of the stream.
  17. 1.2. Why's it called tor?
  18. Because tor is the onion routing system. I kept telling people I was
  19. working on onion routing, and they said "Neat. Which one?" Even if onion
  20. routing has become a standard household term, this is the actual onion
  21. routing project, started out of the Naval Research Lab.
  22. (Theories about recursive acronyms are ok too.)
  23. 1.3 Is there a backdoor in tor?
  24. Not right now, but if this answer changes we probably won't be allowed
  25. to tell you. You should always check the source (or at least the diffs
  26. since the last release) for suspicious things; and if we don't give you
  27. source, that's a sure sign something funny could be going on.
  28. 2. Compiling and installing.
  29. [Read the README file for now; check back here once we've got packages/etc
  30. for you.]
  31. 3. Running tor.
  32. 3.1. What kind of server should I run?
  33. The same executable ("or") functions as both client and server, depending
  34. on which ports are specified in the configuration file. You can specify:
  35. * APPort: client applications (eg privoxy, Mozilla) can speak socks to
  36. this port.
  37. * OPPort: onion proxies (client onion routers) connect to this port.
  38. * ORPort: other onion routers connect to this port
  39. * DirPort: onion proxies and onion routers speak http to this port, to
  40. pull down a directory of which nodes are currently available.
  41. 3.2. So I can just run a full onion router and join the network?
  42. No. Users should run just an onion proxy (use the 'oprc' config file).
  43. If you start up a full onion router, the rest of the routers in the
  44. system won't recognize you, so they will reject your handshake attempts.
  45. 3.3. How do I join the network then?
  46. If you just want to use the onion routing network, you can run a proxy
  47. and you're all set. If you want to run a router, you must convince
  48. the directory server operators (currently arma@mit.edu) that you're a
  49. trustworthy person. From there, the operators add you to the directory,
  50. which propagates out to the rest of the network. All nodes will know
  51. about you within an hour.
  52. 3.4. I want to run a directory server too.
  53. If you run a very reliable node, you plan to be around for a long time,
  54. and you want to spend some time ensuring that router operators are
  55. people we know and like, we may want you to run a directory server
  56. too. We must manually add you to the 'dirservers' file that's part of
  57. the distribution; users will only know about you when they upgrade to
  58. a new version. Of course, you can always just start up your router as a
  59. directory server too --- but users won't know to ask you for directories,
  60. and more importantly, you'll never learn from the real directory servers
  61. about recently joined routers.
  62. 4. Development.
  63. 4.1. Who's doing this?
  64. 4.2. Can I help?
  65. 4.3. I've got a bug.
  66. 5. Anonymity.
  67. 5.1. So I'm totally anonymous if I use tor?
  68. 5.2. Where can I learn more about anonymity?
  69. 5.3. What attacks remain against onion routing?
  70. tagging: can change bytes in the cells, even through link encryption
  71. end node can give back wrong data, even subtly wrong data.
  72. 6. Comparison to related projects.
  73. 6.1. Onion Routing.
  74. Tor *is* onion routing.
  75. 6.2. Freedom.
  76. 7. Protocol and application support.
  77. 7.1. http? ftp? udp? socks? mozilla?