[Paper Review] OSINT Analysis of the TOR Foundation
This OSINT study investigates the operational independence and security of the Tor Foundation and Tor Network, revealing deep U.S. government involvement through funding, technical influence, and control of critical infrastructure like directory authorities. The research demonstrates that the foundation's claimed neutrality is questionable, as key nodes are managed by unverified individuals, and custom code can be injected into the network without oversight, undermining the network's anonymity guarantees.
This research paper is a study on the TOR Foundation and the TOR Network. Due to the blind confidence over this network and this foundation we have collect data and gather information in open sources to understand how it is organized. We discovered that the US government is very active through the financial aspect and development aspect. Furthermore, we discovered that some critical points of the TOR network are running by unknown people who have special nodes and the foundations never talks about them.
Motivation & Objective
- To investigate the alleged independence of the Tor Foundation and its relationship with U.S. government entities.
- To analyze the governance and technical control of Tor's directory authorities and bridge nodes.
- To assess the security implications of accepting custom node software without code review.
- To evaluate the financial dependence of the Tor Project on U.S. government funding.
- To expose structural vulnerabilities in the Tor network that compromise user anonymity.
Proposed method
- Conducted open-source intelligence (OSINT) analysis on Tor Project documentation, version control history, and public logs.
- Tracked changes in directory authority configurations across Tor software versions since inception.
- Mapped ownership of directory authorities using IP addresses, fingerprints, and historical changelogs.
- Performed financial analysis of Tor Foundation funding sources, identifying U.S. government contributions.
- Conducted a controlled experiment by deploying a modified Tor node to test registration and consensus inclusion processes.
- Analyzed Tor source code and configuration policies, particularly the family policy and node registration mechanisms.
Experimental results
Research questions
- RQ1To what extent is the Tor Foundation financially and technically dependent on U.S. government funding?
- RQ2Who actually controls the directory authorities and bridge nodes in the Tor network?
- RQ3How does the Tor network handle unverified or custom node software, and what are the security implications?
- RQ4What evidence exists for U.S. government influence in the design and development of the Tor protocol?
- RQ5How does the lack of transparency in node ownership and governance affect the trustworthiness of Tor’s anonymity guarantees?
Key findings
- The U.S. government has provided over 80% of Tor Project funding in some years, primarily through the Department of State and Department of Defense.
- Directory authorities are managed by individuals with no public accountability, including Jacob Applebaum, who continues to operate a directory authority node (Urras) despite being fired from the Tor Foundation.
- A custom Tor node was automatically registered as a bridge node without user consent, due to misconfiguration in the consensus file system.
- The Tor network accepts custom node software without code review, violating the principle of source code uniformity that underpins its security model.
- One directory authority, Urras, continues to accept and register nodes despite no longer being an official directory authority since 2015.
- The Tor Project’s source code has been heavily influenced by the U.S. Naval Research Laboratory, particularly through Paul Syverson, the original designer of the Tor protocol.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.