You yourself spoke with the founder about this?
I did have the chance to attend a talk by one of the cofounders and have a conversation with him afterwards. This was at a math conference a little over a decade ago.
It's the best tool regular people have for privacy without a doubt.
>The regular person using it doesn't get as much of the privacy benefits, but the charade is making it seem like they do.
Just false.
If your model is simply to avoid corporate surveillance and tracking its a fantastic defense.
If your trying to go up against nation states, it never claimed to protect you from that.
'Just false.'
It depends where you are from. The US constitution is supposed to prevent spying on American citizens, but anyone outside of the USA is fair game. Most of the global population is not in the USA (like me).
'If your model is simply to avoid corporate surveillance and tracking its a fantastic defense.' - I host an onion service exactly for that reason, not for my own privacy but to let customers have that with us if they want.
'If your trying to go up against nation states, it never claimed to protect you from that.' - I disagree, it will protect an American spy a treat.
> the TOR mission was to allow spies to access the network and hide among all the other non-spy users
Tor is pretty clear about what their mission is, it's at the bottom of the Tor Project homepage https://www.torproject.org: "To advance human rights and freedoms by creating and deploying free and open source anonymity and privacy technologies, supporting their unrestricted availability and use, and furthering their scientific and popular understanding."
Claiming anything else is useless conspiracy thinking without evidence.
> It was and still is funded mostly by the US Naval Research Laboratory
The original idea came from the US Naval Research Laboratory, yes (as a way to mask the origin of messages to hide the command boat in a fleet), but the funding statement is patently false. In 2024, the majority of their government funding ($2.1M out of $2.5) came from the U.S. State Department Bureau of Democracy, Human Rights, and Labor, with the rest of the government money coming from even more innocuous sources. You can find this information on p41 of their IRS form: https://www.torproject.org/static/findoc/2023-2024-TheTorPro... also accessible from their Reports page at https://www.torproject.org/about/reports/
They also clarified that in this more readable post: https://forum.torproject.org/t/transparency-openness-and-our...
Certainly, you can speculate about the motivations of the U.S. State Department Bureau of Democracy, Human Rights, and Labor and whether that's a front for more undercover objectives, but that front lines up pretty well with the US's (former?) foreign policy of undermining (unfriendly) dictatorial regimes, and Occam's Razor applies.
Ultimately though, the tools that Tor provides can absolutely be abused by bad actors, and ever since Silk Road, I've become convinced that the Tor network is overrun by a wretched hive of scum and villainy, where those morally defensible activities are utterly outnumbered by the criminal ones.
Using the word "conspiracy" in this conversation about TOR is wild to me.
In a post-Snowden world, it surprises me how anyone wouldn't give reasonable doubt to the THE most interesting and juicy tool linked to the US military post-2001. The tool that people think hides what they are doing and hides who they are.
If there's one thing I know, it's that the US would never in a million years leave a data source untapped or a new NIST crypto standard untampered. Their fingers are in every pie.
Both things can be true... the original need for the network necessitated the mission of the foundation itself... you can't have a global network that only spies use, or you're not blending in, so you have to make it about a public good that many civilians will also use.
Other systems like I2P, SimpleX, Tribler, Datura etc. take additional steps to mitigate such kinds of Sybil attacks that people talk about against Tor, and new methods are being worked on all the time.
Splitting up your traffic across multiple nodes/circuits/etc. as well as persistent dummy/decoy traffic are some methods I've seen discussed recently.
> if those companies share with the US Govt in real-time
IMO This is a colossal "if" and not something we can realistically determine besides saying "we know it happens sometimes, but certainly not all or even most of the time."
Everyone's threat model is different, and hiding from state-level actors is generally 1. much too complicated to succeed at, and 2. you're probably not that special in the first place that you'd actually be targeted. The privacy community is bursting at the seams with all manner of tinfoil-hat wearers and wild conspiracy theorists that think some dark boogeyman is out to get them.
I'd also like to see a source that proves "most of the nodes are hosted on American cloud infra."
I will make a correction. What I should have said is that out of the top 10 networks hosting relays or exit nodes, that close to half have an American presence and that the vast majority 80-90% of relays and exit nodes are spread out within 14 eyes countries - you can see it yourself when you look at the network. When was the last time you looked at where it was connected to and did not see a flag within either 5 eyes, 9 eyes or 14 eyes countries? While that maybe isn't the proof you want, it sure is a meaty coincidence and another reason on top of who funds it and what its purpose is for.