Tor's chief architect, Nick Mathewson, explains what happened with Carnegie Mellon attack and what Tor has done to fix it
The attack that broke the Dark Web—and how Tor plans to fix it — Law enforcement has been complaining for years about the Web “going dark,” … Tweets: @kashhill Tweets: Kashmir Hill / @kashhill : Tor's chief architect explains exactly what happened with Carnegie Mellon attack & what Tor has done to fix it. http://fusion.net/...
Context & Ripple Effects
Two weeks before Nick Mathewson's explanation, Carnegie Mellon denied the FBI paid for the Tor-breaking research and implied a legal subpoena may have compelled its release — leaving open who directed the attack and why. This piece closes the technical half of that question: the Tor chief architect details what the attack actually did to the network and what has already been changed to mitigate it.
It lands amid a broader squeeze on Tor documented across this coverage: the FBI later deployed malware built by an ex-Tor Project employee, and executive director Shari Steele would soon discuss rebuilding public perception and diversifying the project's funding sources.
First-order effects
- Hidden-service users — the group the Carnegie Mellon attack deanonymized — get concrete protocol fixes from Tor, changing what volunteer relay operators run on the network today.
- Law enforcement loses a working technique: whatever combination of research access and legal compulsion produced the attack is now publicly understood enough to be patched against.
Second-order effects
- Universities become a contested vector for surveillance work — if subpoenaed or funded academic research can be turned into network attacks, other institutions face pressure to firewall such projects, chilling future government-academic collaboration on anonymity systems.
- The FBI's reliance on insiders continues separately: the Matt Edman malware shows the agency attacking Tor through former employees even as the project patches the academic route.
Third-order effects
- If state pressure keeps arriving through every channel — subpoenas, insiders, exit-node hijacking like the 2020 SSL-stripping campaign — Tor's structure shifts toward hardened relays, diversified funding, and censorship-resistance tooling, the direction Steele and the Russia bridge-sharing effort both point to.
- The deeper pattern is that anonymity infrastructure becomes a standing battleground between state adversaries and distributed volunteer networks rather than a research curiosity — with each disclosed attack hardening the network for the next adversary.
The trend: State actors are attacking anonymity networks through every available intermediary — universities, insiders, and hostile relays — and each exposed attack pushes Tor further toward hardened protocols, diversified funding, and explicit censorship-resistance.