When Free Software Communities Unite: Tails, Tor, and the Fight for Privacy
Watch on YouTubeVideo summary
The presentation introduces Tor as a global, volunteer-driven free software project dedicated to protecting privacy by hiding not just the content of communications but also the metadata, such as who is talking to whom. Unlike standard encryption which only secures data contents, Tor addresses the critical need for anonymity against various adversaries, including local network eavesdroppers, state-level surveillance agencies like the NSA, and website operators trying to identify visitors. The core design involves routing traffic through multiple relays rather than a single point of failure, ensuring that no single entity can reconstruct the entire path of communication. This approach, known as "privacy by construction," creates an anonymity set where users appear identical to external observers, effectively neutralizing threats from censorship and surveillance while providing reachability for individuals in restricted regions.
Building upon this network foundation, Tails is presented as a portable, amnesic operating system designed specifically for high-stakes scenarios involving activists, journalists, and victims of domestic violence. Based on Debian, Tails allows users to boot directly from a USB stick, ensuring that no traces of activity remain after shutdown, which is crucial when physical devices might be seized by authorities. The project has recently merged with the Tor Project to streamline organizational efforts, allowing the team to focus more intensely on their core mission while leveraging larger resources for fundraising and human rights advocacy. This consolidation also enhances the ability to respond rapidly to censorship events globally, as the combined teams can coordinate strategies to bypass aggressive blocking techniques employed by various governments.
Recent developments highlight a shift toward meeting users where they are, particularly in the mobile sector, with ongoing efforts to improve Tor Browser functionality on Android and develop new tools like Connect Assist for automatic configuration in censored environments. The project has also introduced advanced anti-censorship mechanisms such as Snowflake and WebTunnel to bypass network blockades, alongside improvements in bridge distribution to prevent enumeration by adversaries. Furthermore, the team is addressing critical user needs regarding data integrity and communication by implementing real-time error detection for USB storage, automated repair features, and plans to support major mobile messaging apps like Signal within Tails, ensuring that users can maintain secure communications even when their primary devices are compromised or under surveillance.
The speaker concludes by emphasizing the importance of community support through running relays, donating, or installing browser add-ons to help expand the network's capacity and resilience. While acknowledging legal risks associated with operating exit nodes in certain jurisdictions, the presentation highlights the existence of legal aid networks and open-source transparency as safeguards against abuse. Ultimately, the talk underscores that while funding sources may vary, the work remains transparent and audited by a global community of researchers who constantly test and strengthen the system against attacks. The merging of Tails and Tor represents a strategic evolution to better serve millions of people worldwide who rely on these tools for safety, free speech, and access to uncensored information in an increasingly hostile digital landscape.
Read the full video transcript
Hello everyone.
Welcome to the next session in DebConf
2025.
And now I'm excited to introduce Inti,
who will tell us about Tails for and the
fight for privacy. Please welcome him
warmly.
Inti, the stage is yours.
>> Okay. Hi everybody. Is the microphone
working?
Sounds like it. Excellent. I'm Inti. I'm
on the Tails team at Tor, and I've been
a Debian member since 2011. It's been a
while.
How many people here have used Tor the
browser or Tails?
Oh my god. All right. Cool.
Awesome.
So, I will start by telling a little bit
for those who didn't raise their hands
previously about Tor, what Tor is.
Uh after which I will tell a bit about
what Tails is, and then I will explain
some
things that happened in the last few
years at Tails and Tor.
Tor is a free software
a free [clears throat] software project
uh which produces a bunch of software
all under free software licenses. It's a
nonprofit organization.
It's also a global community of
volunteers and supporters. For example,
the thousands of relays that make the
Tor network are all run by volunteers
all around the world.
This community is also made of
researchers who work in many
universities across the world and
finding ways to attack Tor and finding
ways to make Tor resist these attacks
better.
>> [sighs and gasps]
>> Here's what the problem that Tor is
trying to solve. So, we have Alice here
who's trying to reach some Bob, which
can be a website, for example.
And let's consider what the attacker do
between Alice and Bob.
Uh the attacker can be listening uh next
to Alice, for example, in their local
network, like a Wi-Fi hotspot or the
university or their home.
Uh in case they are facing an adversary
inside their own home, which is an
unfortunate that's uncommon.
They can be listening somewhere along
the way, which can be like a
NSA or an ISP, and so on, listening
various places of the internet, as we
know happens.
Or they can be listening next to Bob,
like, for example, they can be the
website operator or they can be like the
New York Times trying to figure out who
their
this visitors are, for example.
That's basically the the set of threat
model we're trying to address.
One thing I want to get rid of right now
that encryption is not sufficient to
address these problems. Encryption only
protects the contents. But it does not
protect who's talking to whom. It's not
It doesn't protect who is visiting which
website. Okay?
So, if, for example, you're running
something like a leak platform, a
whistleblower platform, encryption is
not enough. Uh it's going to hide what
is being leaked to you. It's not going
to hide who is leaking stuff to you,
which arguably in this context is
probably the most important thing you
want to hide.
So, we don't want to hide the contents
only. We also want to protect metadata.
That is the social graph, who is talking
to whom, who is visiting what.
Metadata is pretty important these days.
Few years ago, a creepy guy at the NSA
or said this to I think the US Congress
or something like that, we kill people
based on metadata.
That's pretty important.
So, we work we
we work on what we call
or when we talk with researcher on
anonymity.
In practice,
in the real world, we rarely talk about
anonymity. They rarely care about
anonymity.
In practice, it depends who you're
talking to. If you're talking to private
citizens, like my my my grandmother, I'm
not saying I work on anonymity software.
I'm saying I work on privacy software.
Everybody feels they need privacy
potentially as private citizens.
Anonymity, I am not quite sure.
If you're talking to businesses, we're
telling them we're working on network
security. They don't really care about
privacy. It doesn't make money. But,
they do care about network security. We
provide that as well.
If we're talking to governments, uh
we're I mean, they don't really want
anonymity. Privacy, oh my god, no way,
thank you.
But, they do want traffic analysis
resistant networks.
We do that as well.
So, the And if you're talking to human
rights activists,
>> [clears throat]
>> they care about privacy. They care about
also reachability, which means if you're
in Russia and you want to connect to
this website, this press media website
in Europe, you might be blocked
probably.
And
in that case, Tor provides reachability.
It allows allows people in Russia or in
Iran or in France to reach a censored
website.
So,
that's one of the interesting things we
store is that it brings all these people
together. It brings all these people
together in what we call an anonymity
set, which is from the point of view of
an external observer,
they all look the same.
So, that's interesting from a, let's
say, analyzing potential attacks. That's
interesting to all bring all these
people together. It protects them all
better.
It's also interesting in terms of
strategy,
uh because it means all these people who
would otherwise potentially be
adversaries or not super aligned
uh
they actually at the end of the day all
have some common interest in having Tor
working.
Uh that's not the case for everybody.
That's not the case all over the world.
Governments in many places try to block
Tor as best as they can.
Uh
but not always. I mean, it's constant
struggle. It's a constant negotiation as
many things in this world. And
if Tor was only about one of these use
cases
the other three use cases potentially
would
try to fight it.
This is less the case thanks to this
design.
So, this is a threat model. How do we
How do we implement something that
addresses this threat model?
The simplest design is to route the
traffic through one single relay
between Bob and Alice. So, Bob goes
through a relay to connect to Alice.
That's what most VPN commercial VPN
providers
give
or sell you, depends.
It works pretty well. It's fast. That's
the main benefit. Actually, that's the
only benefit.
So, one potential problem arises if this
relay is evil. That is, if it obeys
government orders to provide data about
these users and stuff like that. So,
this relay obviously by design is in a
place where it can monitor everything
that everybody is doing.
It's worth noting that because let's
assume you trust this relay.
That's fine. Maybe you have a you're
using a friendly provider. You like
them. You trust them. They're not going
to do bad stuff intentionally at least.
They might be forced to, but at least
they're not going to do bad stuff
intentionally.
Problem is this even if they are honest,
even they are friends
Uh
that's not sufficient because this with
this design
uh anybody who's listening around the
relay network
with timing analysis can match who's
connecting to what.
So, that's a pretty simple attack and
against many kinds of adversaries these
days,
that's super cheap. That's almost free.
So, this super simple design is not
enough in many cases.
For the Tor design, is to route the
traffic through several relays, let's
say three in total,
and to distribute the trust so that no
single relay has all the information.
One relay knows who's connecting to Tor.
One relay knows that someone using Tor
is connecting to this website.
But no single relay knows the entire
story.
We call this
>> [clears throat]
>> as the the presumption was privacy by
promise, which is
the VPN provider promises you to be your
friend or to whatever is written in the
contract.
With our design, with the Tor design,
we call this
privacy by design or privacy by
construction. That is the the way the
system is built gives you some
guarantees.
Okay. But the unfortunately, that's not
sufficient because that's just the
lowest level of the network. Basically,
you at this level you're connecting
you're hiding IP addresses.
The thing is in these network packets
that we're sending, even if you hide the
network address,
there's still stuff we put inside these
network packets that can
leak information about us that we might
not want to leak. That can make us
uh
unique.
And as long as soon as you're unique,
even if you use Tor, you're traceable.
You can tell that oh, it's the same
person who's looking at this that who
was looking at that the other day and so
on.
All this happens in the application
layer like in phones, JavaScript,
uh various configurations of your
browser, of your computer. So, uh Tor we
build other software, not just Tor, not
just the not just the the network, but
as well we provide the Tor browser,
which addresses for the web
the higher level, the applications level
problem.
So, we need both.
Uh
this is not the same as private browsing
mode.
Private browsing mode in most in
browsers doesn't try to address this
problem. It just
>> [sighs and gasps]
>> doesn't do much really.
Uh it just
leaves less traces on the hard drive
than otherwise, but that's about it.
From a network adversary perspective for
the threat model that we just
considered, it does nothing at all.
Unfortunately, the way the way it's
exposed to users
uh is extremely misleading
and studies have shown that many people,
many users
don't understand correctly what it
actually does and what security it's
providing.
That's a little bit scary.
So, this is Tor.
I'll now switch to Tails.
So, as I just said, protecting
protecting things at the network layer
is always not not always sufficient.
Pretty often you also want to protect
data at the applications layer and for
the web we have Tor browser.
Which works in Windows, Mac, Android.
Uh
thing is nowadays we can do lots of
things on the web, but not everything.
Some things still happen in in the
internet uh of the web browser, believe
it or not, on it. And for that, we have
Tails. So, what is Tails?
Tails is a portable operating system
that protects against surveillance and
censorship.
You can download Tails for free.
It's free software. Independent security
researchers can verify what we're doing,
verify our work.
And Tails has been based on Debian since
the beginning.
Tails uses the Tor network to protect
your privacy online and help you avoid
censorship.
You can shut down the computer and start
on your Tails USB stick instead of
starting on Windows, Mac OS, or Linux.
And when you shut down the computer,
Tails leaves no traces of what you've
you've been doing on the computer.
That's what we call amnesia. It's an
amnesic operating system by default. Not
always, we'll go through that later.
And it's a digital security toolbox,
that is. It includes a selection of
applications that are all preconfigured
uh to
have safe defaults, basically. So, they
uh allow working on sensitive documents
and stuff like that, and communicate
securely.
So, who's using Tails?
So, activists use Tails to hide their
identities, avoid censorship,
communicate uh
securely, and uh reach websites they
would otherwise not be able to reach.
That's ex- Well, in particular,
important when part of your threat model
is uh people breaking your door and
getting all computer equipment and
analyzing what's on the hard drive. That
this sort of stuff can help.
Journalists and their sources use Tails
to to publish sensitive information,
access internet from unsafe places,
and isolate their work from super
sensitive work from more day-to-day work
they're doing. Like some journalists
have like one USB stick per
big story, which is super sensitive.
So that it doesn't leave on their Mac
OS, it doesn't leave on their usual
computer and stuff.
So
it's particularly important to protect
their sources who might need special
care in many cases.
Like if they want to stay alive, for
example.
And domestic violence survivors use
Tails to escape surveillance at home,
often to prepare their escape later on.
And you can use Tails whenever you need
extra privacy in this digital world.
You don't have to use it every day. You
might not need it today. You might need
it in 5 years. It will be there
when you need it.
Tails was born
a long time ago, 2009 or something.
That's a while.
Uh and the last talk we had at DebConf
first in Heidelberg in 2015. So it's
been 10 years ago and we're still
around.
Pretty good.
Thank you very much. Um 10 years later,
fast forward. Um in recent years we
realized that Tails has outgrown its
existing structure.
Uh there was way too much organizational
overhead on a small team. For example,
you had developers doing fundraising
work, designers doing accounting work,
and so on.
That was
a little bit complicated to manage. It
was also difficult to grow the team
because how do you hire a new software
developer saying, "Oh, by the way, you
Do you have management skills? And what
about graphic design? And what about
accounting?" That makes it a bit hard to
write a job description and to find the
right people to join the team. So that's
just an example of the sort of
challenges we had to face.
Um so after a year of discussion and
planning
uh Uh, we merged with we joined forces
with the Tor Project in September 204
24.
So, Tails is now part of the Tor
Project. It's now a Tor Project just
like Tor Browser.
What does that mean exactly?
Primarily, thanks to Tor's larger
structure, the Tails team, which I'm
part of, can now focus better on our
core mission, which is maintaining and
improving the Tails operating system.
We also have uh
more
better fundraising and organization
capacity. There are people whose job it
is to do fundraising, people whose job
it is to do HR, and so on.
So, I don't have to do this anymore. I'm
very glad. I was not very good at it.
The priorities of the Tails project
remain unchanged. That's always what
they say when there's a merger. Well, we
are 1 year later and still the case, so
I'm confident.
Uh,
and there's some improvements like uh
are basically better equipped to reach
more people who need Tails. There's been
training about Tails in a bunch of
places on around the world by the Tor
outreach community team, which we
wouldn't have had been able to do
before.
We are also better equipped to react to
censorship events. Uh, it's quite
interesting since now we put together
all these teams, uh we can figure out
where it's the best place to solve the
problem. Like when uh let's say when
China is starting to block obfs4 bridges
more aggressively. Forget the silly
name.
Uh, a couple months ago, we couldn't
figure out if we solve this on the Tor
bridges bridge distribution side, if we
solve this in Tails, if we solve it
elsewhere. Because we are all on the
same team, we can work together.
As a consequence, we are better equipped
to protect people from surveillance and
censorship.
I want to to
give a bit of thank you to Debian here.
So, uh
not just from Tails, also from Tor.
>> [snorts]
>> So,
Tor in many ways is built on top of
Debian.
Uh
the infrastructure at Tor is
mostly or even only, correct me if I'm
wrong, where is he? Anyway, uh he is he
is running about 100 hosts running
Debian.
Tails is based on Debian.
Even some obscure infrastructure bits
from Debian are used in the Tor project
around LDAP and stuff like that. You
don't want to know the details. So,
so thank you.
Uh in a way, um Tails is often the it's
also a gateway to Debian and free
software.
Uh it's often the first opportunity for
folks to start using Linux and Debian
for the first time.
Uh
because before that they were just using
Windows or Mac OS. And one day they have
a special need and they try Tails and
oh, seems it's quite nice. And maybe
they want something similar but
more adequate to their day-to-day usage
and they end up using Debian or Ubuntu
or whatever.
Similarly for contributors, uh quite a
few people starting contributing to
Debian or other free software projects
as part or as a consequence of their
involvement in Tails.
A bunch of people became Debian
developers along the way starting from
the Tails point point of view.
Many of them are still involved in free
software
in free software somewhere or not
involved in Tails anymore. That's
perfectly fine.
We contribute tiny bit back to Debian,
not as much as we used to, probably not
as much as we would like to, admittedly.
We are maintaining a parmo. I
I puppet server is maintained by Tor
staff.
Hey, thank you, Jerome.
And we are maintaining a bunch of more
packages.
So, this is Tails, this is Tor, and this
is the merge that happened.
And now give a few a few ideas of what
happened recently in Tor and in Tails.
So, one thing Tor has been doing is was
has been to uh reach people where they
are.
And
one place is one place where they are is
mobile. Uh
many people nowadays don't have access
to a full-size computer. Their main
computer fits in their pocket.
So, one big thing that Tor has been
working on in the last quite a few years
now has been to make Tor and in
particular Tor Browser usable on mobile.
It's an ongoing effort. The Tor Browser
works there. The main change recently is
that connect assist work on Android.
Connect assist is the thing that helps
users get out basically what sort of
configuration they need to reach the Tor
network depending on where they are
basically.
So, if you're in Iran, it's going to
route you for something called
snowflake. If you're in Russia, it will
go and suggest you use obfs4 and so on.
It's a very easy
thing and it will basically by default
suggest you the right thing.
So, before it was only on the desktop
and then Android was more complicated.
Now, we bought this together.
Tails is part of this whole story to
address find people where they are with
their different needs.
And we are working on a beta VPN which
will allow routing arbitrary
applications on a mobile for Tor.
Yes, I said 10 minutes ago that it was
often not sufficient. Correct. Uh it
depends what you're trying to do and
what what you're trying to achieve. Uh
in many cases uh
people just want reachability.
And if they all they want is
reachability, like being able to use
this app,
that's might be enough. So,
again, that's
Tor trying to have a comprehensive
approach to this and trying to
find people where they are.
We've been working a lot on our what we
call our anti-censorship tools. In the
context of Tor, censorship means uh
access to the Tor network and blockade
blocking access to the Tor network.
So, we've been working on different ways
to bypass in Tor blockage. With
WebTunnel, uh Snowflake has been
improved and works now with latest
Chrome.
Look like it's a pretty cool thing. I
will
introduce it later.
You can help.
And we introduce our disease, which is a
better bridge distribution mechanism,
which will
uh help us distribute
uh better ways to access Tor to people
who are blocked with different means and
try to fight censors who try to block
this and like enumerate all the bridges.
For example, a year or two ago, uh
I think Russia tried to to to enumerate
all the bridges of a certain kind and
they did it using the way we were
distributing these bridges using
Telegram.
And basically, the bridge saw a bunch of
new Telegram accounts and started to ask
new bridges.
And then we realized that they were all
new accounts. So, we thought, "Oh,
actually, these old accounts, they get
these bridges. New accounts, they get
those bridges." So, in the end, they
were able to enumerate only a tiny part
of the bridges.
So, that's the sort of thing that our
disease helps us do.
One one change the Tor network has had
since forever is
uh
performance. Um
so, in order to maintain a stable and
healthy Tor network, we need to
effectively effectively leverage network
data.
There's all these thousands of relays
providing network capacity. We used to
use it as best as we can.
While preserving the uh the privacy and
anonymity promises we have.
Sometimes there's a friction between
these two goals. It's not just route
everything through the fastest servers.
That would defeat the goal. You still
have to distribute a little bit.
So, to do that uh one way that we've
been working on last couple years has
been bandwidth scanners. So, they they
basically measure the bandwidth
available from relays.
And then this data is used to inform how
to build the path for different relays
that your connections take to the Tor
network.
The goal is to optimize the distribution
and ultimately to boost boost browsing
speed and reliability.
Another thing that Tor has been up to is
less technical and maybe less sexy, but
still pretty important.
It's about maturing as an organization
and increasing our independence.
So, Tor has been maturing as an
organization in many ways. Uh it's been
let's say
getting better at adulting the
organization.
Uh doing the sort of things that maybe
most many people in this room don't like
to do, but which is very much needed to
run an organization with a few dozen
people.
Or a few thousand.
>> [snorts]
>> Just saying.
Um this has been important as well on
the funding side. Uh we've worked a lot
on diversifying our
sources of income.
Uh
to by aligning with a new set of funders
globally, with individual giving, with
international grants, not just US,
partnerships with uh companies who share
some values with us.
So, I'm happy to report that in a few
years the share of US government funding
in our budget has gone down from roughly
50% to roughly 20%.
That's
more necessary than ever.
That's more necessary than ever.
It puts puts Tails in a strong position
to continue providing its services to
the millions of people who need Tails
and all.
So, yeah. That's we let's say the
these last 6 months or 10 months have
been a little bit less stressful at all
than in many similar non-profit
organizations.
Not to say everything is perfect.
I'll now switch to things that happened
in Tails recently. I'll just zoom on one
big category of problem that we've been
working on, mostly to to illustrate the
sort of approach we've been having.
Uh
cuz I think it's more important than
listing a list of features or list of
technical things.
Um so, as I said previously,
>> [snorts]
>> Tails by default will forget everything
you do when you shut down the computer,
but
we also have a feature which we call
personal storage in which optionally you
can actually have space on your USB
stick, which is encrypted, where you can
store files and configuration for the
software.
So, when I was saying that like
journalists can use a one USB stick with
Tails for one story, another one for
another story, that's this feature
they're using.
So, journ- journalists, activists, human
rights defenders use Tails as a safe
work environment to store sensitive
material on their Tails USB stick.
But, listening to our users
taught us it's too easy to lose this
important data.
How so?
How to lose data?
Hardware fails.
USB sticks I have failed pretty bad.
Humans make mistakes. Not you, but the
other ones.
Most users don't have backups.
It's hard to recover corrupted data,
like
and software has bugs.
Worse, not everybody is equally
impacted.
Cheaper USB sticks tend to fail earlier.
Without access to tech education, it's
easier to make mistakes that corrupt
data.
To make backups, one needs spare times,
more hardware, and education.
And data recovery requires advanced
skills.
So, to sum up,
the risk of losing data mirrors and
amplifies other inequalities.
Tails cannot directly solve all these
other inequalities,
but we can help our users protect their
data. So, we've been working on that.
Our approach has been to detect errors
before it's hard to recover,
like we basically are scanning logs in
real time to find I/O errors and report
them to the user graphically to let them
to suggest them
to do something before it gets too bad,
these sort of things.
Uh we help the user diagnose and backup
before it's too late.
When we can, when it's safe, we try to
automatically repair, like file system,
uh partition tables, these sort [snorts]
of things.
It's pretty tough to find the right
balance between trying harder, even if
it's unsafe, or not, but we think we've
tried found a decently good balance.
And we we cannot we provide
documentation so the user can go through
the steps themselves manually, taking
responsibility for this
recovery operations.
We have also designed a backup feature
for the personal storage.
In the future, we want to warn the user
when they take action which can
lead to data loss, like unplugging the
USB stick to shut down the computer.
Which is is a cool Tails feature.
It in an emergency, you unplug the USB
stick, it shuts down
and erases the memory. The thing is,
when you have data on the USB stick,
then you can lose data if you do that.
And once we find funding for this, we
will implement a new design for backups.
Future plans.
>> [snorts]
>> So, safeguarding the users,
the data that users stores in Tails is
important, but humans are also social
animals and they also need to
communicate with each other.
Again, we started by listening to our
users.
So, nowadays people use smartphones to
communicate.
Like it or not.
And mobile messaging apps are the
easiest way to protect these
communications.
But at the moment, Tails does not
support many of the largest mobile
messaging apps, if you exclude XMPP, but
that's not where you're going to find
most communities.
>> [snorts]
>> So, we listened to the needs of our
users. We went for a year or two
process. We did a bunch of interviews.
We interviewed researchers who work on
high-stakes investigations.
We interviewed digital security
trainers. They were interesting because
often they have aggregate data and they
talk to dozens or hundreds of people and
they tell us, "Okay, most of them need
that." That's very important to us than
1.0.5.
We talked to environmental activists, to
organizations that create safe
whistleblowing platforms,
and journalists.
So, what we learned is that yes, there
is a need to have this app supported in
Tails. There is a need to be able to use
these apps in Tails to communicate with
other people who use the same protocols,
the same apps.
Uh so, these people need to as part of
the work they're doing in Tails to
communicate with other people
who only use their phones.
So,
these Tails users need to find their
peers, their communication peers where
they are.
Uh they starting a conversation by,
"Hey, can you please install this app so
we can talk?"
is not always ideal. Sometimes sometimes
it's the right thing to do. I mean,
encouraging people to use Signal and not
some crappy stuff always good. But,
putting this as a stumbling block to
even have the conversation can be a
little tough.
They need Tails as a platform or secure
that possibly potentially infected
phone. So, there lots of stuff on their
phone they might want to use Tails for
more safer for more sensitive
communication.
And they need to isolate Yeah.
Finally, in some cases the portability
of the USB stick is critical in conflict
or disaster situation. We've heard of
people who have a Tails USB stick around
around the neck or in their pocket. And
if they have to leave in an emergency
because war, disaster, earthquake, you
name it,
uh it's easier to have this than a
full-size computer.
>> [snorts]
>> We identified which apps we wanted to
support. Uh so, this user research
effort told us that Signal by far is the
more important app to include.
Cool. However, it's not a
one-size-fits-all situations. There's a
number a number of uh
places, use cases, situations where it's
not the right tool or it's not the best
tool.
So, we to support these diverse needs,
we want to support other messaging apps
as well.
We are seeking funding for this project
and we'll try.
And that's about it. So, to
wrap this up,
uh you things you can do to help uh
people uh connect to the internet in a
safer manner with Tor.
You can keep the bandwidth great.
So, thank you in advance for that.
That's
That's a good thing to do. You can run a
slow flag proxy. It's a it's a an add-on
you can add to your to your Chrome or
Firefox and it will help people connect
to the Tor network. You just have to add
install an add-on an add-on. That's it.
You can become a relay operator.
You can donate if you have more money
than time. That's okay as well. We
accept all sorts of social constructs
called money, including
cryptocurrencies. We are non-profit.
Thanks in advance. Your contribution,
including to Debian, helps make Tor
tools faster, more stable, and enables
millions of people to safely access the
internet.
Thank you.
We have five or six minutes for
questions.
>> Yeah, they have five minutes for uh for
questions. Thanks a lot for your talk
and for your work on this very important
tools like Tails, Tor, and other tools.
I think it's now very also important for
people who are living in places in the
world where you are not freely
free to speak and to safe to to make the
safe online.
So, thanks.
Um yeah, we have some questions.
>> And we only have five minutes, but I'm
here all weekend. I'm not going
anywhere. So, if if your question
doesn't fit here right now, grab me
somewhere. We'll have a discussion.
>> I'm not sure this is Oh, there we go.
Um so, my understanding, which may be
wrong, is there is some slight legal
risk from being a relay operator or
something like that. Does Tor have
resources if I'm approached by law
enforcement? And you know, like, how
does that work?
>> So, the main legal risk in most
countries, if you're an exit node, which
is your
in a place of the network where your
traffic is going to exit the Tor network
and reach its final destination.
Basically, you'll be the one connecting
to this resource. So, in some places,
there's a risk that these actions, the
action taken by Tor users, are
attributed to you.
Uh
it's optional. You don't have to be an
exit node to be part of the Tor network.
Many people, maybe even most people,
uh run
uh Tor relays, which are not exit nodes,
for this very reason.
Uh
the Tor Project itself doesn't provide
these sort of resources. However, in
various countries, there are nonprofits
or
uh as I organizations that
bring people together who want to run uh
Tor relays and exit nodes and pool
resources, including legal ones. So, if
and when the risk
uh the the problem happens, uh
there's a lawyer who's ready to support
you
and who knows what you're talking about.
>> Maybe uh yeah, just as a complement and
answer, there is documentation uh that
gathers uh data um
that uh explains um
uh that provides information about for
example which
ISPs and cloud providers,
how they react to users running Tor
relays, if an exit nodes are even
allowed by the user terms and things
like that. So that's one research that's
that's provided by the Tor project. And
as well, there are meetups of
Tor relay
operators that are organized by the Tor
project on a regular basis, which are
spaces where
relay operators can
ask questions and support each other.
And
and give advice. And and yeah, there's
of course all the online resources. We
have a Tor forum where Tor relay
operators are encouraged to
share their experiences and mailing
lists of course and and and IRC channels
and all the usual communication
channels.
>> Okay.
>> Thank you. Any more questions?
>> Oh, sorry.
Thank you
for the information you gave. So
>> Eat the mic.
>> Okay.
Just
>> Eat the mic.
>> Ah.
>> It's an ice cream. It's not a mic.
>> Okay.
What I know, the Tor itself, the relays
are
caught by DPI in Iran.
So that's not a case which I can use.
It's It's Last months I'm really
concerned about that. I'm trying
different VPNs.
None of them works.
And
I seen the Tails, the other product you
said, and the problem there I seen 50%.
uh
supported by US government. So,
I'm not sure how to trust that part. So,
wherever there's a government, there's a
problem also with the protection of your
data.
Uh
it would be nice. I would try to
go ahead with the tour myself to get the
first uh gateway to see how does that
work or even at all.
It was just information I had I wanted
to share, so or maybe later get a
solution for that.
>> There are many parts to your question.
Uh
regarding DPI, uh yeah, I mean
various ways to connect to Tor are more
or less
I mean, usually
I mean, usually it's a black copter.
I don't know.
Uh
Can we We kind of out of time?
>> 1 minute.
>> Okay. Yeah. Uh
yeah, DPI is a big topic. Uh some ways
to connect to Tor go through bypass DPI
very easily. DPI also is not There's bad
DPI, there's better, higher quality DPI.
So, it's it's a very broad term. About
this US government funding, yes, we take
money from those places. Some places we
like more or less.
Uh we try our best to use this money to
make the world a better place. Uh all
our work is transparent and open source.
Uh there's
an immense amount of research uh
in universities by security researchers
trying to attack Tor.
It's basically, if you want to do this
sort of work on this in this area and
have your paper
been published and stuff, well, Tor is a
pretty good target because it's the
biggest search network, it's the most
well-known.
So,
personally, I would first uh uh
network actor even it gets US government
money
much more than a small thing that has
been audited by three and a half people
10 years ago.
Uh just thanks to this exposure we have
to audits and to ongoing security work.
But, you do you.
Safety is a personal thing.
>> Yeah. Thanks again for your work and uh
we hope to see you in the next Demco
Debcoms with updates to the projects
which you are
driving.
Yeah, and
thank you again and I I would ask the
auditorium to thank also.