New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Cheapest decent VPS's for Tor exits?
in Requests
Comments
@forest may have some experience
From the top of my head, I believe @Fourplex had rather reasonable offers recently, but they already run a lot of tor exits themselves on their network.
Hey @serverenthusiast,
Tor exits are fine with us. If abuse reports come in we look into them rather than suspending first and asking later, so you won't lose a node over a single complaint.
Our EPYC 1G is 1.49€/mo with 1 core on AMD EPYC Zen 3 Milan with ECC DDR4, 1 GB RAM, 10 GB NVMe in RAID 1, one IPv4 plus an IPv6 /64, in Eygelshoven, NL. Traffic has no monthly allowance at all, no counter and no per-GB overage, on a 10 Gbps shared port, which is the part that usually matters for an exit.
If you want more headroom, the configurator sets cores, RAM and storage independently, so 2 cores with 2 GB and 20 GB comes to 4.69€/mo, or 4.22€/mo with code LET10.
Order: skri.me/epyc
Configurator: skri.me/epyc-config
Looking Glass: skrime.eu/network / AS215365
Note: the Tor project prefers not to have hundreds of exits on the same few networks - they would rather have more different networks for diversity.
Keep an eye out for restock of a RPi!
https://lowendtalk.com/discussion/216357/rpiservers-2-0-3-14-always
We welcome tor / i2p!
Heres our AUP https://mysticdev.io/aup.php
Section 3.1
Are you sure? You're a German provider, are you sure you'd be fine with potentially hundreds of spam reports, DMCA reports, etc.?
Plenty of EU providers even huge ones handle this most notably online.net, as long a you reply even templated it's totally fine.
(Not for tor, but same goes for torrenting)
We allow TOR Exit Nodes, but we're a bit expensive (https://advinservers.com/cloud)
Copied from a guide I wrote on hosting Tor exits:
I also plan to set up an exit shortly on a Pi from @JoshR.
Happy to share a YABS and more detailed pricing information if you want to use that to make a choice. And if you happen to get on the same subnet as me, I'd also be happy to let you use my resolver so you don't have to buy a second IPv4 or use a centralized resolver.
@forest do you think it's a good idea to be as anonymous as possible when running tor exits? there was a LET that got arrested in 2012 for running a tor exit node if I recall correctly.
makes you wonder how many vpn services have no issues.
It depends on your jurisdiction. @William got arrested for running a node but 1) was doing other illegal things at the time so the arrest could have been pretextual and 2) was arrested at a time that Tor was very new and law enforcement was not familiar with it.
Now days, everyone knows what Tor is. You'll never have someone saying "He's claiming some application called 'Tor' sent the traffic automatically and it wasn't actually him behind it? Preposterous!" anymore.
It's still not a great idea to run it on a residential connection though, but on a server is fine.
Did He ?
there are still countries where people don't even know what Tor is.
@forest didn't you get some spam emails? i just opened my mail and there are 20 spam emails.
damn, now there are LET email scrapers too.
Years and years ago. There's a LEB blog post about it I think.
LET requires people to log in before seeing email. I have mine visible but I very rarely get spam. You must have signed up to something.
oh i found it: https://lowendbox.com/blog/man-found-guilty-of-child-porn-because-he-ran-a-tor-exit-node-the-story-of-william-weber/
damn, i’ve seen this case so many times on youtube and other platforms too. @William is pretty popular, i think.
then, a “logged in” scraper
The Tor project doesn't want you to be anonymous - they'd rather you have a reputation as someone trustworthy - but still accepts anonymously run nodes.
An anonymous exit node paid in crypto is going to scream red flags to any provider. They're basically taking on the legal risk themselves. But some are willing to do that or don't even know it's a risk.
The William Weber case was long before things like the Digital Services Act. This was in a German-speaking country back when the law was that the owner of the connection was liable for everything on it, no exceptions (which made it illegal to offer public wifi at a coffee shop because you'd be punished for any torrenting or child porn). That got loosened up around 2018, I think, and the EU Digital Services Act (applicable from 2024) deliberately limits liability for "mere conduits", although I think officially, you still have to register with the authorities that you are a mere conduit.
The William Weber case is unusual. Although a few exit node operators have been charged with things like child porn, the vast majority have not, even though every node probably has that sort of traffic going through it.
William himself said (according to the linked LEB article) that the law in 2011 was supposed to protect him but it was only written to protect companies, but they changed it a few weeks later and he got convicted anyway.
Much more recently the BND (German NSA) traced the operator of an onion site through the Tor network without arresting any node operators (but one is known to have been wiretapped).
Conclusion: it's not zero risk but it seems more like the risk of crossing the street, than the risk of BASE jumping. And don't do anything illegal while you have an exit node, because the police found this guy's drugs during the exit node raid.
They care about reputation in terms of your nodes being good. They don't really care who you are, other than you preferably giving them an email so they can contact you if there are issues.
Not really. Anonymous crypto orders do, depending on the provider, not specifically "anonymous" exits.
We need a fact check on that, please cite some laws. I don't see how the customer being "anonymous" transfers the risk to the service provider. Of course, it will also differ depending on the country, but I can't think of a non-shithole country with service provider protections where that kind of exemption exists.
Will is on ofac list, so he is documented terrorist. LETs very own terrorist
There are plenty of anonymity-friendly providers, even here. And even if they have a red flag, who cares? They're cheap servers.
According to the law in many democratic countries, you're not breaking the law by running a tor exit. But if you're a random guy and you have no money for lawyers, who will protect you if the government starts prosecuting you?
Even TorGuard and Windscribe were charged in Greece for alleged activities on their services.
https://www.tomsguide.com/computing/vpns/windscribes-no-logs-policy-examined-in-court-as-greek-authorities-attempt-to-prosecute
https://torrentfreak.com/greece-prosecutes-owner-of-american-vpn-service-over-fraudulent-user-transactions-220707/
This is 100% a legitimate concern. Can you guarantee a prosecutor will check if your IP is in fact a Tor exit before charging you with child porn distribution?
A detail you didn't mention is that both were acquitted.
i didn't say they weren't and it was still a headache
well actually perhaps it also help the brands but anyway, it did cost them resources
Exactly.
What they really care about is that you participate and aren't a ghost. They don't care about your real name, but they'd rather a valid contact email, maybe participation in the mailing list from time to time, etc. It matters more for large-scale operators though. One or two exits won't worry them, but if you spin up 20 and they have no way of contacting you, they'll get nervous.
When I started running more than just a few relays, a Tor dev contacted me and asked a few questions, offered to chat if I wanted, etc. I suspect he was just feeling me out because I had suddenly started running I think 5 exits out of the blue. The questions were pretty much what you'd expect: What got you into Tor? Do you pay out of pocket for the relays? Etc.
I am only getting investment opportunity emails
I get those on occasion but they arrive directly in spam.
That's why you should only run it with a provider who is willing, otherwise they'll terminate you when the complaints start rolling in. The actual legal risk for the provider themselves is zero in most jurisdictions where Tor exits exist, but there's still a risk of IP or even subnet blacklisting, of having to deal with angry upstreams, of IP "cleaning" fees from upstreams, and of course the administrative burden of responding to complaints. That's the main reason why most providers are weary of exits.
What happened, assuming it's the case I'm thinking of, is that the operator also used a chat client that turned his own PC into an onion service, but used an outdated version of Tor that did not include Vanguards, which are designed to make guard discovery attacks harder. It took BND two years and full cooperation of a major German telecom just to find a guy using an outdated Tor that lacked modern guard discovery attack mitigations.
Once you pull off a guard discovery attack, all you need to do is subpoena the hosting provider and ask for a list of connected sessions. In his case, he was, by chance, using a guard which had very, very few other clients connected, so he was found out more easily when the guard discovery attack succeeded.
The fact that it took so long and took so many measures to catch a guy who wasn't even using up-to-date Tor and who was running a chat client that turned his own system into an onion service (onion services are notably easier to perform guard discovery attacks against than clients) shows how robust Tor is.
If by "your IP" you just mean an IP on a VPS that you've purchased, it's not possible to guarantee it, but if they're American, they'd probably lose their job if that was the only evidence they had and it wasn't pretextual anyway. To find out who owns the account, they'd need to subpoena the provider. At that point, they will have done enough research that they would know it's an exit. Even if they didn't, the chances of conviction are zero. The law may change in the future, but thank god ex post facto laws are prohibited in the US. And Europe too: Nulla poena sine lege praevia.
But if by "your IP" you mean your home residential connection, then that's risky because they could easily claim that running an exit was merely cover for other illegal activities and that you were the actual person uploading the material.
There are a lot of exit operators and prosecutors don't want to waste their time going after them. For them to actually go after you specifically for running an exit could only realistically happen if you were doing something else that pissed them off to the point that they're just looking for any excuse to arrest you.