Privacy Tips

Why don't our ISPs report our TOR usage to LE? [USA]

Started by bobo9999 · Jul 15, 2025

#9180
↳ Replying to @bobo9999
I don't think it's against the law to be curious, but there are moral lines and you shouldn't cross them.

There are people/sites on the darknet that LE need to get rid of completely, but the war on drugs must rage on.

Hardly ever used a bridge though. I always found it to be more sluggish.
#9181
↳ Replying to @bobo9999
Here is the problem.

You are assuming they do not report tor usage. They do not report Tor usage (because the block it a lot) but they share all your data with at minimum the government anyways. The government then takes that data and determines it is tor usage and analyzing it further.

I have said this in my posts but assume your ISP knows you are using Tor easily because it is not hard to determine. Also bridges are okay but there are many methods to detect bridges. Yes they can obfuscate the traffic but they are unable to obfuscate the destination. You can make bridges but when I discover you destination address it does not matter if you obfuscate the traffic I know you are communicating on Tor.

Be aware of companies like team cymru who pay ISP's for newflow/pcap data for this exact purpose. Use a VPN before Tor to blend in. Your ISP is a for profit business who is selling your data to the high bidder.
#9183
↳ Replying to @bobo9999
It is not most times and I understand why. At the end, you have to trust your VPN. You do not have the ability to log in and verify their claims are true, but rely on audits and mostly their word. The problem is that ISP's are the same way and their business model is not on protecting your traffic, a VPN does have a business interest in protecting you even if we can argue some have proven not to do so. It is just another layer in my opinion and you have to research if it fits your thread model.
#9184
↳ Replying to @rmrf
Do you think this is why some people get love letter eventually from being active on Tor for such a long period of time over the years even if they order high stealth packages and domestic only? The government got so many report from our ISP that they investigate our USPS packages and they find out?

Would it be safer to be active on tor maybe once a week as opposed to every day? Or the risks are pretty much the same? I know this is all speculation and we can't know, I just want to get your opinion on it.
#9185
↳ Replying to @bobo9999
there are million ISPs in the world with willion different managers and they care only about profit of company and if tor is not forbidden by the law, it is not their job to report anything to the cops.

cops also dont have legal permission to spy you just because of using tor, judge will not give them permission to do it.

but spies dont give a shit for the law or any permission, they spy everybody, unofficially.... and to spy individuals they get permission from the head of spying agency and judge, they just say any story that you are potential terrorist or extremists and they must monitor your activities. they are political police not criminal, as long as you kiss president/Gov in the ass, you can sell drugs how much you want or anything else, spies even use criminals to do some job outside of legal framework, spies must respect the law but they employ criminals to finish job for them. in my country, 98% of criminals work for the secret service.
#9186
↳ Replying to @bobo9999
I can only speak from my knowledge and there is no guarantee I am correct.

I do not think in your scenario this is the result of love letters. If there is an ability to unmask tor users, those who are just doing small drug buys, that would risk a very strong capability for only a little value. Remember they do not want you to know what they can do and activity like that would make that a mistake on their part.

The ISP is not able to see what you are doing on Tor just that you are using it. It would make no sense for them to report your activity. As I said there is more likely they are providing pcap/netflow data to whatever government they are required to do so for. Basically an API directly to all traffic. The government with all that data can then choose what is interesting and what is not. Also this type of correlation does not hold up in many courts (but some do allow it) because it is digital evidence which is not seen as true because many people will originate from the same IP address if you are using Tor.

My opinion if you think the surveillence is that deep is to move to the you >>> vpn >>> tor model and use this even if you are not actively doing anything seen as criminal. Browse the news, watch youtube, it does not matter. That way when you do your actual activity it does not stray from you usual activity. The risk you have by limiting such activity actually makes correlation attacks much stronger. If you only login once a week to buy drugs then they can take the timing of that and how specific it is to show that it might be you and get a warrant for you. If it is too ambigious they would not chance it. They need facts not speculation (mostly).

Do not forget there are so many other ways they deanonymize users that thinking they are using big techniques to get you is overthinking. Pick the simple solutions that get you caught, fix them, then move on to the harder problems.
#9187
↳ Replying to @rebelmouse
This is good point. Also ISP you sign away your rights to a business. Government can not spy on you but a company can because you agreed to it.

And intelligence agencies often do not care about laws. If they are breaking a law they will not use how they got you in court. They can give the lead to law enforcement who can then build a case on you from that little bit of information and then go after you.
#9188
↳ Replying to @rmrf
What are some basic methods they use to deanonymize users? Can you list some for me? Thank you.

Members-only continuation

This discussion contains more posts.

Create an account or sign in to continue reading the full conversation. 1 additional post awaits inside.

Create an accountSign in