20
OpSec shower thought
(lemmy.dbzer0.com)
Welcome! This is a community for all those who are interested in protecting their privacy.
PS: Don't be a smartass and try to game the system, we'll know if you're breaking the rules when we see it!
Some of these are only vaguely related, but great communities.
People who are seriously invested in OpSec absolutely do control their nodes. There's a few settings in the Tor conf that allow you to exclude countries out of exit (and entry) nodes.
But given their resources and the knowledge that people they want data the most will avoid exit nodes in their home countries, how likely do you think agencies might have just rented some room in Albania and Morocco, or just got a room in their own country embassies, and put their exit nodes there instead? (if they can't just "VPN" an IP from other country)
I've drunk too much conspiracy juice this morning.
That might be, but if they've choose their nodes carefully that will make correlation attacks very difficult.
Is it relatively straightforward to blacklist countries just based on IP address? I've seen it discussed before, and I swear it was never described as uncomplicated.
You don't need to blacklist based on IP. You can specify the country directly.
See
man 5 tor.conf:ExcludeNodesandExcludeExitNodesas well as the node definition underNodeFamily: