Tor anonymity compromised by researchers

Tor

Tor has been dealt another blow after researchers found a way to deanonymise certain hidden services with a very high level of accuracy.

First reported by Ars Technica, the researchers from the Massachusetts Institute of Technology and Qatar Computing Research Institute were able to denonymise the sites with an alarming 88% accuracy.

Using the method, malicious actors can carry out an attack by gathering network data from a pre-compiled list of hidden services in advance. Careful analysis of the patterns of packets passing between the hidden service and entry guard it uses to access Tor allows researchers to obtain a unique fingerprint of each one. This can then be later be used to identify the service but the traffic could not be decrypted.

Foreign governments, especially the US, could well be interested in the research considering that the FBI recently seized a Tor-hidden site hosting child pornography and hid there for weeks to allow evidence gathering.

Not successful in the real-world

Tor project leader Roger Dingledine reacted to the article in an email that doubted how successful it would be in a real-world setting. One reason for this is that the entry guard of the hidden service must be controlled by the attacker. Secondly he pointed to research last year that showed researchers routinely exaggerating the risk of website fingerprinting.

Tor's anonymity is one of its biggest selling points as it uses a system of protocols to make sure that no one can trace your IP address and not even your ISP will know the sites you're visiting, which makes the latest claims worrying.

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand