Hacking / Opsec

concerns regarding vanguards not being in the latest tor, debian 13 and whonix 18 release - could lead to deanon of users and hidden service seen in boystown forum case

Started by dontguessaskquestions · Jun 26, 2026

#1682
↳ Replying to @dontguessaskquestions
This only applies to vanguards full. There is vanguards lite, which is enabled in Tor by default. It also has nothing to do with Whonix or Debian. Vanguards is incompatible with current Tor and the project is dead, so there was no reason to keep the package.

Maybe read more than the first sentence on the docs page.

https://gitlab.torproject.org/tpo/core/tor/-/work_items/40892

https://github.com/mikeperry-tor/vanguards

Another day, another reason to hate the Tor project. Actual shit.

>This is a problem because hidden services without vanguards can be found really easily, this could have been the reason archetyp market was found (god knows how they got the admin too)

This is nothing but FUD. You can name a thousand and one things that could have been it given that it's not currently public knowledge.
#1683
↳ Replying to @Selenium
You're right sorry and thanks for the reality check. Let's turn this thread into a discussion of a safe way to connect to the internet so in case tor connections are traced, its harder to find who connected.
#1684
↳ Replying to @dontguessaskquestions
It's easy for ISPs to see who is using Tor, when they connect and disconnect, and the timing and size of their Tor traffic.

It's not easy to determine what they are connected to or if it's a hidden service.
#1685
↳ Replying to @coincidencedetector
Thanks for reply and I didn't mean to spread any FUD. Guard node discovery is a possibility as to how a technically advanced admin would be caught. Especially if German feds are involved because I think they might have the best darknet cybercrime team. My post was dedicated to informing users that tor isn't unbreakable because a lot of people might think it is as a result of admins like pharoah and ross ulbricht being caught as a result of basic opsec mistakes. A few extra measure need to be taken if someone were to use it for illegal activity. Someone confirmed that tforum servers are always on the move so I guess to run a hidden service and retire peacefully before seizure (or exit scams but darknet admins might panic and exit scam), maybe moving the frontend servers every month and backend every year might be necessary. I am going to make another post regarding a failsafe setup for tor connections.

EDIT: I will just post my thought here.
#1686
↳ Replying to @dontguessaskquestions
Would connecting to mullvadVPN on your device before you connect to tor work as a fail-safe? Mullvad VPN is known to be open-source & no logs. I haven't seen any official news reports of this but mullvad claims swedish police raided servers and left empty-handed because there are no logs.

So if timing attacks or guard discovery attacks work, mullvad might just save your ass. Does anyone know from reading docs or source code whether someone's real IP can be determined from mullvad's exit IPs? If I am using a crowded server, speed may be slower but it would be harder to tell who exactly is responsible for the tor connection.
#1687
↳ Replying to @dontguessaskquestions
>Especially if German feds are involved because I think they might have the best darknet cybercrime team.

What are you basing your thoughts on?

Time and time again, they had to rely on information from external agencies, often from the US.
#1688
↳ Replying to @dontguessaskquestions
You need to decide for one thing and clearly differentiate it for a discussion. Clients or long-term hidden services.

And no, I wouldn't bet on this saving your ass. If someone is after you that has the capability to discover your guard, chances are monitoring traffic on a higher level is within the capabilities too. With this capability and time, they will find the source of the traffic, sooner or later. But it always depends.
#1689
↳ Replying to @Selenium
What if you genuinely forgot your password though?

I've lost bitcoin before that I could not remember even for $60k USD remember the password. I don't think being locked up would jar it back into memory if an average person's years' salary couldnt.

Basically you can get life for not being able to remember something ?
#1690
↳ Replying to @Ghwbushsr
Convince the judge.

It's going to be a hard sell if the computer was clearly being used recently.
#1691
↳ Replying to @Selenium
Merica, how bout that freedom.

LWOP for not properly remembering a 25 word passphrase with $&)_#)&

Members-only continuation

This discussion contains more posts.

Create an account or sign in to continue reading the full conversation. 6 additional posts await inside.

Create an accountSign in