# Bisq uses TOR. Is this safe from Man in the Middle Attacks?

**URL:** <https://bisq.community/t/bisq-uses-tor-is-this-safe-from-man-in-the-middle-attacks/3308>\
**Category:** Support\
**Created:** [October 31, 2017, 6:27am UTC](https://bisq.community/t/bisq-uses-tor-is-this-safe-from-man-in-the-middle-attacks/3308 "2017-10-31T06:27:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gilson](https://bisq.community/letter_avatar/gilson/32/5_5575768a8748004e209b776fc1b2916d.png) [@Gilson](https://bisq.community/u/Gilson)\
**Post date:** [October 31, 2017, 6:27am UTC](https://bisq.community/t/bisq-uses-tor-is-this-safe-from-man-in-the-middle-attacks/3308/1 "2017-10-31T06:27:50Z")

</div>

I was just wondering if this was the case, since TOR nodes are not as safe as they once were.

I was looking at [LocalBitcoins.com](http://LocalBitcoins.com) and their FAQ page shows:

"If you are not a tech-savvy user we recommend avoid using a Tor browser when purchasing Bitcoins. When using a **Tor browser you are at risk for man-in-the-middle-attacks by malicious Tor exit nodes**. A malicious Tor exit node intercepts the traffic between your computer and LocalBitcoins and then steals your Bitcoins.

If you want to maintain safety and privacy we recommend purchasing Bitcoins on LocalBitcoins using a normal web browser. After the purchase send Bitcoins to a desktop application wallet from where you can make further payments. "

How does Bisq prevent a similar scenario?

Thanks!

---

<div class="post-metadata">

**Author:** ![shrike](https://bisq.community/letter_avatar/shrike/32/5_5575768a8748004e209b776fc1b2916d.png) [@shrike](https://bisq.community/u/shrike)\
**Post date:** [October 31, 2017, 7:46am UTC](https://bisq.community/t/bisq-uses-tor-is-this-safe-from-man-in-the-middle-attacks/3308/2 "2017-10-31T07:46:23Z")

</div>

You are connecting to other bisq users from within the tor network using hidden services and not using exit nodes.

In general, use HTTPS on all sites. Not using https is maybe how you can get spit roasted. I dont follow local bitcoins recommendation.

Im sure others can provide more complete info.

---

<div class="post-metadata">

**Author:** ![Nolaan](https://bisq.community/user_avatar/bisq.community/nolaan/32/1100_2.png) [@Nolaan](https://bisq.community/u/Nolaan)\
**Post date:** [October 31, 2017, 10:57am UTC](https://bisq.community/t/bisq-uses-tor-is-this-safe-from-man-in-the-middle-attacks/3308/3 "2017-10-31T10:57:12Z")

</div>

Exit nodes are the servers that gives you access to the “normal web”. By definition they can spy on your traffic and deanonimyze you.

Bisq is running is own network within tor, so there’s no exit nodes involved thus providing us better anonymity and security.

Cf this :

> **[Most people who say Tor is insecure and should not be used, cite exit nodes...](https://www.reddit.com/r/TOR/comments/4jddca/most_people_who_say_tor_is_insecure_and_should/)**
>
> 34 points and 29 comments so far on reddit

---

<div class="post-metadata">

**Author:** ![alexej996](https://bisq.community/user_avatar/bisq.community/alexej996/32/491_2.png) [@alexej996](https://bisq.community/u/alexej996)\
**Post date:** [October 31, 2017, 3:49pm UTC](https://bisq.community/t/bisq-uses-tor-is-this-safe-from-man-in-the-middle-attacks/3308/4 "2017-10-31T15:49:09Z")

</div>

As already said, Bisq traffic doesn’t get to exit nodes. However, exit nodes only have access to the same information that website you are using already has, that is if the https is not used and if it is that they only have access to the webpage you are requesting.

---

<div class="post-metadata">

**Author:** ![shrike](https://bisq.community/letter_avatar/shrike/32/5_5575768a8748004e209b776fc1b2916d.png) [@shrike](https://bisq.community/u/shrike)\
**Post date:** [November 1, 2017, 5:35am UTC](https://bisq.community/t/bisq-uses-tor-is-this-safe-from-man-in-the-middle-attacks/3308/5 "2017-11-01T05:35:26Z")

</div>

This is where i was hoping someone would chime in with more info 😉  
My understanding is, price feed/exchange data is via exit nodes.  
If you have tor ticked for bitcoin network, you are using exit nodes to get to them. (Consider setting up a [bitcoin.org](http://bitcoin.org) node on your own network)  
bisq user to bisq user is via .onion hidden services.  
Happy to be wrong on the first 2 points.

---

<div class="post-metadata">

**Author:** ![ManfredKarrer](https://bisq.community/user_avatar/bisq.community/manfredkarrer/32/26_2.png) [@ManfredKarrer](https://bisq.community/u/ManfredKarrer)\
**Post date:** [November 1, 2017, 10:17pm UTC](https://bisq.community/t/bisq-uses-tor-is-this-safe-from-man-in-the-middle-attacks/3308/6 "2017-11-01T22:17:14Z")

</div>

All P2P network stuff is using hidden services. The only area where exit nodes are in play are as you said the Bitcoin network connections if the node is not a hidden service (we try to get a good mix) [1]. But also here you are better off as the exit nodes cannot see from where the request comes opposed to when you would use Bitcoin in non-Tor mode.  
There have been some critics regarding Bitcoin using Tor but as far I have followed that, it was not well reasoned. The mix with hidden service Bitcoin nodes should at reduce risks with malicious exit nodes (they could theoretically hold back transactions).

[1] I just checked and at my nodes there was no hidden service bitcoin nodes. That’s strange, maybe something got broken there in the last release, will check that out for the next release…
