Researchers and law enforcement have documented several methods for tracing Tor users:
- Traffic correlation attacks: An adversary who can observe both the Tor entry and exit points can correlate timing and volume patterns to link traffic to a user. This requires monitoring large portions of the internet (ISP-level or nation-state capability). Academic research shows this is theoretically possible but extremely difficult at scale.
- JavaScript/browser exploits: The FBI used a zero-day JavaScript exploit ("Network Investigative Technique" or NIT) to de-anonymize users of a Tor-hosted service in 2015. The exploit ran code in Tor 瀏覽器 that reported the user's real IP 位址. This is why disabling JavaScript (最安全 mode) is critical.
- Operational security failures: Most Tor users who were identified made mistakes: logging into personal accounts, reusing usernames, sending identifiable information, or downloading files that connected outside Tor. User error is the primary cause of de-anonymization.
- 中繼-level attacks: Running a large number of Tor 中繼 allows traffic analysis. A 2014 attack confirmed that Tor 中繼 run by the same entity could correlate users with hidden services. The Tor 計畫 implemented defenses against this.