Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Cheapest decent VPS's for Tor exits?

Hello LET!

What are the most affordable decent VPS's for Tor exit nodes?

Thanked by 2forest itzsenu

Comments

  • olokeoloke Member, Host Rep

    @forest may have some experience :D

    From the top of my head, I believe @Fourplex had rather reasonable offers recently, but they already run a lot of tor exits themselves on their network.

  • SKRIMESKRIME Member, Patron Provider

    Hey @serverenthusiast,

    Tor exits are fine with us. If abuse reports come in we look into them rather than suspending first and asking later, so you won't lose a node over a single complaint.

    Our EPYC 1G is 1.49€/mo with 1 core on AMD EPYC Zen 3 Milan with ECC DDR4, 1 GB RAM, 10 GB NVMe in RAID 1, one IPv4 plus an IPv6 /64, in Eygelshoven, NL. Traffic has no monthly allowance at all, no counter and no per-GB overage, on a 10 Gbps shared port, which is the part that usually matters for an exit.

    If you want more headroom, the configurator sets cores, RAM and storage independently, so 2 cores with 2 GB and 20 GB comes to 4.69€/mo, or 4.22€/mo with code LET10.

    Order: skri.me/epyc
    Configurator: skri.me/epyc-config
    Looking Glass: skrime.eu/network / AS215365

  • Note: the Tor project prefers not to have hundreds of exits on the same few networks - they would rather have more different networks for diversity.

  • JoshRJoshR Member, Patron Provider

    @serverenthusiast said:
    Hello LET!

    What are the most affordable decent VPS's for Tor exit nodes?

    Keep an eye out for restock of a RPi!
    https://lowendtalk.com/discussion/216357/rpiservers-2-0-3-14-always

    We welcome tor / i2p!

    Heres our AUP https://mysticdev.io/aup.php
    Section 3.1

  • @SKRIME said:
    Hey @serverenthusiast,

    Tor exits are fine with us. If abuse reports come in we look into them rather than suspending first and asking later, so you won't lose a node over a single complaint.

    Our EPYC 1G is 1.49€/mo with 1 core on AMD EPYC Zen 3 Milan with ECC DDR4, 1 GB RAM, 10 GB NVMe in RAID 1, one IPv4 plus an IPv6 /64, in Eygelshoven, NL. Traffic has no monthly allowance at all, no counter and no per-GB overage, on a 10 Gbps shared port, which is the part that usually matters for an exit.

    If you want more headroom, the configurator sets cores, RAM and storage independently, so 2 cores with 2 GB and 20 GB comes to 4.69€/mo, or 4.22€/mo with code LET10.

    Order: skri.me/epyc
    Configurator: skri.me/epyc-config
    Looking Glass: skrime.eu/network / AS215365

    Are you sure? You're a German provider, are you sure you'd be fine with potentially hundreds of spam reports, DMCA reports, etc.?

  • @serverenthusiast said:

    @SKRIME said:
    Hey @serverenthusiast,

    Tor exits are fine with us. If abuse reports come in we look into them rather than suspending first and asking later, so you won't lose a node over a single complaint.

    Our EPYC 1G is 1.49€/mo with 1 core on AMD EPYC Zen 3 Milan with ECC DDR4, 1 GB RAM, 10 GB NVMe in RAID 1, one IPv4 plus an IPv6 /64, in Eygelshoven, NL. Traffic has no monthly allowance at all, no counter and no per-GB overage, on a 10 Gbps shared port, which is the part that usually matters for an exit.

    If you want more headroom, the configurator sets cores, RAM and storage independently, so 2 cores with 2 GB and 20 GB comes to 4.69€/mo, or 4.22€/mo with code LET10.

    Order: skri.me/epyc
    Configurator: skri.me/epyc-config
    Looking Glass: skrime.eu/network / AS215365

    Are you sure? You're a German provider, are you sure you'd be fine with potentially hundreds of spam reports, DMCA reports, etc.?

    Plenty of EU providers even huge ones handle this most notably online.net, as long a you reply even templated it's totally fine.

  • @LEBUserJoe said:

    @serverenthusiast said:

    @SKRIME said:
    Hey @serverenthusiast,

    Tor exits are fine with us. If abuse reports come in we look into them rather than suspending first and asking later, so you won't lose a node over a single complaint.

    Our EPYC 1G is 1.49€/mo with 1 core on AMD EPYC Zen 3 Milan with ECC DDR4, 1 GB RAM, 10 GB NVMe in RAID 1, one IPv4 plus an IPv6 /64, in Eygelshoven, NL. Traffic has no monthly allowance at all, no counter and no per-GB overage, on a 10 Gbps shared port, which is the part that usually matters for an exit.

    If you want more headroom, the configurator sets cores, RAM and storage independently, so 2 cores with 2 GB and 20 GB comes to 4.69€/mo, or 4.22€/mo with code LET10.

    Order: skri.me/epyc
    Configurator: skri.me/epyc-config
    Looking Glass: skrime.eu/network / AS215365

    Are you sure? You're a German provider, are you sure you'd be fine with potentially hundreds of spam reports, DMCA reports, etc.?

    Plenty of EU providers even huge ones handle this most notably online.net, as long a you reply even templated it's totally fine.

    (Not for tor, but same goes for torrenting)

  • advinserversadvinservers Member, Patron Provider
    edited September 21

    We allow TOR Exit Nodes, but we're a bit expensive (https://advinservers.com/cloud)

  • Copied from a guide I wrote on hosting Tor exits:

    • iHostArt (https://ihostart.com) - Romanian host. A bit pricey and uptime isn't ideal, but very lenient. Accepts payments in the form of Bitcoin, fruits, and vegetables.
    • Maxko Hosting by @MAXKO_Hosting (https://maxko-hosting.com) - A host with locations in some obscure locations including Serbia and South Africa. Allows exits on all their locations and is actively pro-privacy. Use promo code "TOR10" for 10% off any service intended as a relay (exit or non-exit). You have to ask them to enable host CPU passthrough in a ticket, otherwise you won't have AES-NI and performance will suffer.
    • Aluy by @aluy (https://aluy.net) - Pro-privacy host with a few nice locations including Bulgaria, Finland, and even Hong Kong. The owner is very friendly and active on LET.
    • Advin Servers by @advinservers (https://advinservers.com): American. A bit pricey, but they're premium. Very fast CPUs. Requires written approval for exits.
    • Trabia by @trabia (https://www.trabia.com) - Moldovan host. Exits are allowed but mail-related ports should be blocked. They'll notify you if they are getting too many complaints and may request that you change your exit policy. If I recall, they want you to use a reduced exit policy (described later).
    • Pfcloud UG (https://pfcloud.io) - Slovenian host. Occasionally suspends for abuse, but all you have to do is tell them that you're running an exit relay and they'll unsuspend you.
    • IncogNET by @MannDude (https://incognet.io) - Radically pro-privacy host with servers in Sweden. Exits are allowed, but you have to follow their specific exit policy to reduce abuse complaints.
    • No Ack Hosting (https://noackhosting.se) - Has a dedicated subnet for exits in Sweden. Does not enable host CPU passthrough (boo!). You have to ask them explicitly to run an exit so they assign you to the right subnet on the right node. It's pricey but reliable. They run their own DNS resolver.

    I also plan to set up an exit shortly on a Pi from @JoshR. :)

    Happy to share a YABS and more detailed pricing information if you want to use that to make a choice. And if you happen to get on the same subnet as me, I'd also be happy to let you use my resolver so you don't have to buy a second IPv4 or use a centralized resolver.

  • @forest do you think it's a good idea to be as anonymous as possible when running tor exits? there was a LET that got arrested in 2012 for running a tor exit node if I recall correctly.
    makes you wonder how many vpn services have no issues.

  • forestforest Member
    edited September 21

    @serverenthusiast said: @forest do you think it's a good idea to be as anonymous as possible when running tor exits? there was a LET that got arrested in 2012 for running a tor exit node if I recall correctly.

    It depends on your jurisdiction. @William got arrested for running a node but 1) was doing other illegal things at the time so the arrest could have been pretextual and 2) was arrested at a time that Tor was very new and law enforcement was not familiar with it.

    Now days, everyone knows what Tor is. You'll never have someone saying "He's claiming some application called 'Tor' sent the traffic automatically and it wasn't actually him behind it? Preposterous!" anymore.

    It's still not a great idea to run it on a residential connection though, but on a server is fine.

  • @forest said: @William got arrested for running a node but

    Did He ?

    @forest said: Now days, everyone knows what Tor is. You'll never have someone saying "He's claiming some application called 'Tor' sent the traffic automatically and it wasn't actually him behind it? Preposterous!" anymore.

    there are still countries where people don't even know what Tor is.

    @forest didn't you get some spam emails? i just opened my mail and there are 20 spam emails.
    damn, now there are LET email scrapers too.

  • forestforest Member
    edited September 21

    @itzsenu said: Did He ?

    Years and years ago. There's a LEB blog post about it I think.

    @itzsenu said: @forest didn't you get some spam emails? i just opened my mail and there are 20 spam emails.
    damn, now there are LET email scrapers too.

    LET requires people to log in before seeing email. I have mine visible but I very rarely get spam. You must have signed up to something.

  • @forest said: Years and years ago. There's a LEB blog post about it I think.

    oh i found it: https://lowendbox.com/blog/man-found-guilty-of-child-porn-because-he-ran-a-tor-exit-node-the-story-of-william-weber/

    damn, i’ve seen this case so many times on youtube and other platforms too. @William is pretty popular, i think.

    @forest said: LET requires people to log in before seeing email. I have mine visible but I very rarely get spam.

    then, a “logged in” scraper

  • edited September 21

    @serverenthusiast said:
    @forest do you think it's a good idea to be as anonymous as possible when running tor exits? there was a LET that got arrested in 2012 for running a tor exit node if I recall correctly.
    makes you wonder how many vpn services have no issues.

    The Tor project doesn't want you to be anonymous - they'd rather you have a reputation as someone trustworthy - but still accepts anonymously run nodes.

    An anonymous exit node paid in crypto is going to scream red flags to any provider. They're basically taking on the legal risk themselves. But some are willing to do that or don't even know it's a risk.

    The William Weber case was long before things like the Digital Services Act. This was in a German-speaking country back when the law was that the owner of the connection was liable for everything on it, no exceptions (which made it illegal to offer public wifi at a coffee shop because you'd be punished for any torrenting or child porn). That got loosened up around 2018, I think, and the EU Digital Services Act (applicable from 2024) deliberately limits liability for "mere conduits", although I think officially, you still have to register with the authorities that you are a mere conduit.

    The William Weber case is unusual. Although a few exit node operators have been charged with things like child porn, the vast majority have not, even though every node probably has that sort of traffic going through it.

    William himself said (according to the linked LEB article) that the law in 2011 was supposed to protect him but it was only written to protect companies, but they changed it a few weeks later and he got convicted anyway.

    Much more recently the BND (German NSA) traced the operator of an onion site through the Tor network without arresting any node operators (but one is known to have been wiretapped).

    Conclusion: it's not zero risk but it seems more like the risk of crossing the street, than the risk of BASE jumping. And don't do anything illegal while you have an exit node, because the police found this guy's drugs during the exit node raid.

  • ObelousObelous Member
    edited September 21

    @OpaqueRegistrant said: The Tor project doesn't want you to be anonymous - they'd rather you have a reputation as someone trustworthy - but still accepts anonymously run nodes.

    They care about reputation in terms of your nodes being good. They don't really care who you are, other than you preferably giving them an email so they can contact you if there are issues.

    @OpaqueRegistrant said: An anonymous exit node paid in crypto is going to scream red flags to any provider.

    Not really. Anonymous crypto orders do, depending on the provider, not specifically "anonymous" exits.

    @OpaqueRegistrant said: They're basically taking on the legal risk themselves.

    We need a fact check on that, please cite some laws. I don't see how the customer being "anonymous" transfers the risk to the service provider. Of course, it will also differ depending on the country, but I can't think of a non-shithole country with service provider protections where that kind of exemption exists.

  • LeviLevi Veteran

    @itzsenu said:

    @forest said: @William got arrested for running a node but

    Did He ?

    @forest said: Now days, everyone knows what Tor is. You'll never have someone saying "He's claiming some application called 'Tor' sent the traffic automatically and it wasn't actually him behind it? Preposterous!" anymore.

    there are still countries where people don't even know what Tor is.

    @forest didn't you get some spam emails? i just opened my mail and there are 20 spam emails.
    damn, now there are LET email scrapers too.

    Will is on ofac list, so he is documented terrorist. LETs very own terrorist :)

  • edited September 21

    @OpaqueRegistrant said: An anonymous exit node paid in crypto is going to scream red flags to any provider. They're basically taking on the legal risk themselves. But some are willing to do that or don't even know it's a risk.

    There are plenty of anonymity-friendly providers, even here. And even if they have a red flag, who cares? They're cheap servers.

    According to the law in many democratic countries, you're not breaking the law by running a tor exit. But if you're a random guy and you have no money for lawyers, who will protect you if the government starts prosecuting you?

    Even TorGuard and Windscribe were charged in Greece for alleged activities on their services.

    https://www.tomsguide.com/computing/vpns/windscribes-no-logs-policy-examined-in-court-as-greek-authorities-attempt-to-prosecute
    https://torrentfreak.com/greece-prosecutes-owner-of-american-vpn-service-over-fraudulent-user-transactions-220707/

    This is 100% a legitimate concern. Can you guarantee a prosecutor will check if your IP is in fact a Tor exit before charging you with child porn distribution?

    Thanked by 1rpqu
  • @serverenthusiast said: Even TorGuard and Windscribe were charged in Greece for alleged activities on their services.

    A detail you didn't mention is that both were acquitted.

  • edited September 21

    @Obelous said:

    @serverenthusiast said: Even TorGuard and Windscribe were charged in Greece for alleged activities on their services.

    A detail you didn't mention is that both were acquitted.

    i didn't say they weren't and it was still a headache

    well actually perhaps it also help the brands but anyway, it did cost them resources

  • forestforest Member
    edited September 21

    @Obelous said: They care about reputation in terms of your nodes being good. They don't really care who you are, other than you preferably giving them an email so they can contact you if there are issues.

    Exactly.

    What they really care about is that you participate and aren't a ghost. They don't care about your real name, but they'd rather a valid contact email, maybe participation in the mailing list from time to time, etc. It matters more for large-scale operators though. One or two exits won't worry them, but if you spin up 20 and they have no way of contacting you, they'll get nervous.

    When I started running more than just a few relays, a Tor dev contacted me and asked a few questions, offered to chat if I wanted, etc. I suspect he was just feeling me out because I had suddenly started running I think 5 exits out of the blue. The questions were pretty much what you'd expect: What got you into Tor? Do you pay out of pocket for the relays? Etc.

  • JohnFilch123JohnFilch123 Member
    edited September 21

    @forest said: a Tor dev contacted me

    I am only getting investment opportunity emails :lol:

    Thanked by 1itzsenu
  • @JohnFilch123 said:

    @forest said: a Tor dev contacted me

    I am only getting investment opportunity emails :lol:

    I get those on occasion but they arrive directly in spam.

  • forestforest Member
    edited September 21

    @OpaqueRegistrant said: An anonymous exit node paid in crypto is going to scream red flags to any provider. They're basically taking on the legal risk themselves. But some are willing to do that or don't even know it's a risk.

    That's why you should only run it with a provider who is willing, otherwise they'll terminate you when the complaints start rolling in. The actual legal risk for the provider themselves is zero in most jurisdictions where Tor exits exist, but there's still a risk of IP or even subnet blacklisting, of having to deal with angry upstreams, of IP "cleaning" fees from upstreams, and of course the administrative burden of responding to complaints. That's the main reason why most providers are weary of exits.

    @OpaqueRegistrant said: Much more recently the BND (German NSA) traced the operator of an onion site through the Tor network without arresting any node operators (but one is known to have been wiretapped).

    What happened, assuming it's the case I'm thinking of, is that the operator also used a chat client that turned his own PC into an onion service, but used an outdated version of Tor that did not include Vanguards, which are designed to make guard discovery attacks harder. It took BND two years and full cooperation of a major German telecom just to find a guy using an outdated Tor that lacked modern guard discovery attack mitigations.

    Once you pull off a guard discovery attack, all you need to do is subpoena the hosting provider and ask for a list of connected sessions. In his case, he was, by chance, using a guard which had very, very few other clients connected, so he was found out more easily when the guard discovery attack succeeded.

    The fact that it took so long and took so many measures to catch a guy who wasn't even using up-to-date Tor and who was running a chat client that turned his own system into an onion service (onion services are notably easier to perform guard discovery attacks against than clients) shows how robust Tor is.

    Thanked by 1rpqu
  • forestforest Member
    edited September 22

    @serverenthusiast said: Can you guarantee a prosecutor will check if your IP is in fact a Tor exit before charging you with child porn distribution?

    If by "your IP" you just mean an IP on a VPS that you've purchased, it's not possible to guarantee it, but if they're American, they'd probably lose their job if that was the only evidence they had and it wasn't pretextual anyway. To find out who owns the account, they'd need to subpoena the provider. At that point, they will have done enough research that they would know it's an exit. Even if they didn't, the chances of conviction are zero. The law may change in the future, but thank god ex post facto laws are prohibited in the US. And Europe too: Nulla poena sine lege praevia.

    But if by "your IP" you mean your home residential connection, then that's risky because they could easily claim that running an exit was merely cover for other illegal activities and that you were the actual person uploading the material.

    There are a lot of exit operators and prosecutors don't want to waste their time going after them. For them to actually go after you specifically for running an exit could only realistically happen if you were doing something else that pissed them off to the point that they're just looking for any excuse to arrest you.

    Thanked by 1serverenthusiast
Sign In or Register to comment.