Perhaps because your ISP can't see Tor usage (though bridges do that better), but now the VPN provider knows your real identity and that you're on Tor, a correlation choke point with payment records attached. Plain Tor never asks who you are. This is negated with some VPN provider though as not all require KYC. If you're using a private VPN and then from their connecting to Tor, you're most likely fine.
If you're connecting to Tor and then a VPN, that's bad. You're essentially negating Tor's random exit node. Tor exits rotate per circuit, a VPN exit doesn't, so the VPN becomes one persistent observer of all your traffic, defeating Tor Browser's per site circuit isolation.
It's also technically fragile: Tor only carries TCP, so UDP based WireGuard/OpenVPN won't tunnel over it without special config.
And this special configuration is very complicated for the average person that just what's some privacy.
My two sats.
That said, three letter agencies absolutely run Tor exit nodes. Why wouldn't they? They'd be terrible at their jobs if they didn't.
Login to reply
Replies (3)
Lots of good points although raw dogging Tor is far worse imo
This would be no different to an ISP? ISP can absolutely see tor traffic so this only stands if for some reason your ISP is retarded? Which in the US is likely to be one of 4-5 major companies, all of which have state-of-the-art traffic detection for their ad's business. And we cannot simply forget about Room 641A.
A primary (and my opinion only) purpose of a VPN is to shield traffic from your ISP, which has the added benefit of hiding your physical location from servers. Because ISPs publish your IPaddress location information for legal reasons, and because they get advert money from it.
Then, you must vet your VPN the same way we don't trust our ISPs because we simply shifted the watching to the VPN opposed to our ISP. However the VPN provider has been proven to be much less likely NOT to share your traffic information NOR your personally identifiable information on the public internet to find in milliseconds like ISPs do.
> Tor only carries TCP, so UDP based WireGuard/OpenVPN won't tunnel over it without special config.
Don't think this is true at all. Tor works just fine being tunneled over wireguard out of the box ime. So not sure which setting people are leaving off that breaks this.
If were worried about the alphabet bois none of these are a solution, and I would consider them equally a problem. Tor traffic is identifiable, and can be time-correlated well enough by the alphabet bois that you're pretty boned using tor at all if they care enough about you.
Correct.
Your ISP can see:
That you use Tor. Your first hop connects to a guard relay, and all relay IPs are on a public list. The traffic is fully encrypted, but "connected to known Tor relay" = "this customer uses Tor."
Volume and timing, how much, when.
Your ISP cannot see:
Content. Thanks to three layers of encryption, peeled one hop at a time. No single party holds both ends, by design.
Destination. The guard knows you but not where you're going. DNS also resolves inside the circuit, so no DNS leaks (unlike a sloppy VPN setup).