FINDING · EVALUATION
Tor's built-in country-exclusion mechanism is unreliable: circuits configured to exclude US Tor nodes only actually bypassed the US 12% of the time, motivating provably-avoidant circuit construction.
From 2023-arora-detor-onion — Provably Avoiding Geographic Regions for Tor's Onion Services · §1 · 2023 · Financial Cryptography and Data Security
Implications
- Do not rely on Tor's native ExcludeNodes/ExcludeExitNodes for geographic avoidance guarantees — treat any exclusion as a best-effort hint, not a provable bound.
- Tools requiring jurisdiction avoidance must implement out-of-band proof mechanisms (speed-of-light alibi proofs or equivalent) rather than trusting the Tor path-selection algorithm.
Tags
Extracted by claude-sonnet-4-6 — review before relying.