Lucky Green, one of Tor’s earliest participants, has decided to leave the Tor Project.

Lucky’s move may reflect a significant shift at Tor. The project is getting bigger and more diverse, as well as more complicated, and that is resulting in a number of changes across the initiative.

There has been a lot of flux at the Tor Project as of late. The newest director has shaken some trees during her tenure, and members of the board were replaced a few weeks ago. With all the confusion, perhaps Lucky simply decided it was the right time to leave.

Unknown Factors

According to Softpedia, Lucky wrote a message that was then sent to the Tor mailing list.

“Given recent events, it is no longer appropriate for me to materially contribute to the Tor Project either financially, as I have so generously throughout the years, nor by providing computing resources,” he wrote. “I feel that I have no reasonable choice left within the bounds of ethics but to announce the discontinuation of all Tor-related services hosted on every system under my control. Most notably, this includes the Tor node Tonga, the Bridge Authority, which I recognize is rather pivotal to the network.”

He added that Tonga will be shut down for good on Aug. 31, 2016. The delay is to allow Tor developers time to create and implement a substitute. Lucky Green also noted that he will be ending several Tor relays as well, although that should not cause as much disruption.

He gave the project his well wishes and doesn’t seem to be leaving on bad terms, but the move will leave Tor in the lurch.

Tonga Terminated by Lucky Green

Tonga is critical to Tor functionality since the address is hardcoded into the Tor browser. This is done to prevent ISP blocking. It seems Lucky had a secret part of the Tor network hiding in his metaphorical basement.

We may never know why Lucky Green changed his status with the anonymity network. But we do know that Tor must create another bridge authority quickly to avoid further turmoil — and to avoid losing customers who were dependent on Lucky’s tools.

More from

Emotional Blowback: Dealing With Post-Incident Stress

Cyberattacks are on the rise as adversaries find new ways of creating chaos and increasing profits. Attacks evolve constantly and often involve real-world consequences. The growing criminal Software-as-a-Service enterprise puts ready-made tools in the hands of threat actors who can use them against the software supply chain and other critical systems. And then there's the threat of nation-state attacks, with major incidents reported every month and no sign of them slowing. Amidst these growing concerns, cybersecurity professionals continue to report…

RansomExx Upgrades to Rust

IBM Security X-Force Threat Researchers have discovered a new variant of the RansomExx ransomware that has been rewritten in the Rust programming language, joining a growing trend of ransomware developers switching to the language. Malware written in Rust often benefits from lower AV detection rates (compared to those written in more common languages) and this may have been the primary reason to use the language. For example, the sample analyzed in this report was not detected as malicious in the…

Why Operational Technology Security Cannot Be Avoided

Operational technology (OT) includes any hardware and software that directly monitors and controls industrial equipment and all its assets, processes and events to detect or initiate a change. Yet despite occupying a critical role in a large number of essential industries, OT security is also uniquely vulnerable to attack. From power grids to nuclear plants, attacks on OT systems have caused devastating work interruptions and physical damage in industries across the globe. In fact, cyberattacks with OT targets have substantially…

Resilient Companies Have a Disaster Recovery Plan

Historically, disaster recovery (DR) planning focused on protection against unlikely events such as fires, floods and natural disasters. Some companies mistakenly view DR as an insurance policy for which the likelihood of a claim is low. With the current financial and economic pressures, cutting or underfunding DR planning is a tempting prospect for many organizations. That impulse could be costly. Unfortunately, many companies have adopted newer technology delivery models without DR in mind, such as Cloud Infrastructure-as-a-Service (IaaS), Software-as-a-Service (SaaS)…