I know it's popular in tech circles these days to hate on Comcast, and I'm not saying they don't deserve the hate or that they wouldn't do something like this, but I'm not buying this one just yet. This is all supposedly statements by 2 telephone support people.
The actual source article seems to be confusing running a connection to Tor and the Tor browser with running a Tor relay node or exit node. Prohibiting the Tor browser would be a bad move on the part of any ISP who isn't part of a police state, but none of their document suggest that they're doing that. I can understand them prohibiting running a Tor node on your residential internet connection though. Almost all residential ISPs officially prohibit running servers, though it usually isn't enforced as long as you aren't pushing too much traffic. A Tor node can easily fall on those lines. I think even the Tor project doesn't recommend running nodes on your home connection rather than actual servers with server-class connections.
Thank you for this. This may be a stupid question, but how would your ISP know you were actively running a Tor (non-node) connection?
Obviously I need to read up on all the back-end tech but I would assume that if it was easy to identify someone using Tor, it would no longer provide the anonymity / security because it would clearly identify outliers.
It makes sense to ban someone running a node off their Comcast connection (not because it's logical but because of their high traffic / server banning track record) but for Comcast to detect a browsing session? Seems odd.
Using DPI or even just flow analysis (sizes, port numbers, destination addresses, protocol (TCP/UDP) bits, and timings of packets), it should be possible to distinguish between encrypted TOR and other encrypted protocols with ease.
The actual source article seems to be confusing running a connection to Tor and the Tor browser with running a Tor relay node or exit node. Prohibiting the Tor browser would be a bad move on the part of any ISP who isn't part of a police state, but none of their document suggest that they're doing that. I can understand them prohibiting running a Tor node on your residential internet connection though. Almost all residential ISPs officially prohibit running servers, though it usually isn't enforced as long as you aren't pushing too much traffic. A Tor node can easily fall on those lines. I think even the Tor project doesn't recommend running nodes on your home connection rather than actual servers with server-class connections.