Tor relay rejection policies have limited impact on user anonymity and security

Sociotechnical Aspects of Tor Relay Rejection

Cryptography and Security

Summary

Tor, a network used for anonymous internet browsing, rejects old relay servers to keep the system safe and up-to-date. The authors studied how these rejections affect the people running the relays and the security for users. They found that while some relay operators didn’t always know about the policy, most think it’s a good idea. Removing old relays only slightly helps bad actors, and other factors like relay changes have a bigger effect on anonymity. The authors suggest ways to improve these policies to avoid problems.

What this means in practice

  • For network operators: Optimize relay maintenance policies to balance security improvements with minimal impact on user anonymity in Tor.
  • For cybersecurity teams: Assess the effects of relay exclusion to better understand and mitigate risks against surveillance adversaries in privacy networks.

Authors

Jules Dejaeghere, Lionel Goffaux, Pierre Luycx, Hosam Elkoulak, Florentin Rochet

Abstract

In 2019, the Tor Project enforced an end-of-life (EoL) policy for Tor versions, leading to the rejection of outdated relays, amounting to a notable fraction of consensus weight. While this policy aids network maintenance, reduces backporting efforts, and shortens vulnerability exposure, its sociotechnical implications remain unstudied. A user study ($N=26$) reveals that relay operators, though not universally aware of the EoL policy, generally view it favorably. Operational practices vary, occasionally excluding newly installed relays from the network. Network simulations, grounded in historical data, assess the policy's immediate impact on Tor clients against common adversaries. Results indicate a marginal adversarial advantage, with network churn (i.e., relays entering and exiting) exerting a more pronounced effect on user anonymity. Security metrics are introduced to evaluate relay contributions against two adversary models, enabling ranking by individual utility and security. Analysis of four exclusion rounds shows that a minority of rejected relays typically account for over 50% of the security provided by all excluded relays. Recommendations for EoL policy implementation are proposed to mitigate potential drawbacks.