Nym Mixnet: privacy theater

I’ve been seeing Nym* shilled somewhere - on usenet and blog posts comparing it to tor.

The pitch: 5hop mixnet (your traffic is split into fixed-size packets, encrypted in layers, and bounced through five nodes), Poisson delays, cover traffic, economic “Sybil” resistance, 684 nodes in 74 countries.

So I tried it. Built nym-socks5-client from source, initialized the client, picked exit gateways from the explorer. Pointed curl at the local SOCKS5 proxy.

Nothing. Every time: “Starting proxy for example.com:80” in the logs, then silence. Zero bytes. Timeout. Tried --fastmode, tried HTTP, tried waiting 3 minutes. Dead.

The client logs say “disabled credentials mode” and “managed to claim testnet bandwidth” so I assumed it was working. It wasn’t. I didn’t catch this at first, but it turns out exit gateways now require zk-nym credentials - which you only get through a paid subscription.

So the packets go into the mixnet fine, but the exit node just drops them. The socks5 binary still compiles and still “connects” it just doesn’t actually reach the internet anymore.

Then I started reading more about the project and it got sad. I don’t have a problem with paying for privacy - privacy isn’t free, someone has to run the infrastructure. The problem is the structure itself. The code is GPL-3, the nodes are run by the community, the research was funded with EU grants and public universities (KU Leuven, EPFL).

But one Swiss company backed by a16z and Binance Labs controls the only working access point. They raised ~$18M in VC, sold $25M in tokens, set up a $300M “innovation fund” - and the token went from $5.88 to $0.02 while node operators keep staking and paying for electricity.

What bothers me isn’t the ~$2/month. It’s that a single corporation can gate the entire network. If Nym Technologies SA decides tomorrow to change their terms, raise prices, comply with a court order, or just shut down - all those 684 community-run nodes become useless overnight. I’m not a cryptographer but I suspect there are privacy implications too, when all credentials flow through one entity.

2 Likes

Welcome to the modern Internet, where decentralized actors operate under the illusion of decentralized power.

1 Like

Nym nodes are there to make a profit, they are not “community-run nodes” as you said, Nym operators run them to make money, do not worry, if they make a profit and Nym shuts down they will quickly find a solution, profitable businesses rarely close.

1 Like

A single company does not control all the access points. First, the mixnet via the API and SOCKS should be free to use and should not check credentials, which seems to be fine. There may be a problem with your exit node, have you tried another one? Or one of your command line options? If you send an email to get in touch we can debug if the docs don’t answer your question, we should fix the docs: Nym Docs: Privacy Network Documentation .

While it’s true a single company is doing most of the dev work, and we were spun out lots of the universities like KU Leuven and EPFL, it’s not true that we control or gate the entire network. Anyone can pay a smart contract to get credentials, see here: Pay as You Go: Decentralized Access to the Nym Network | Nym . And you ONLY need the credentials for “fast mode” that looks like and is used like a normal VPN - for the mixnet we keep it open and free, as anyone that uses it increases anonymity for others, and the more people that more anonymity, the better!

Anyways, hope you can get it working and feel free to reach out, we’re always happy to debug and make sure the docs are clear. We WANT more people to use the mixnet.

8 Likes

That’s all well and good, but how do you expect to attract high-risk clients when your website is a total mess not to mention your behavior, to put it mildly?

I imagine working at your company would be like running “red team” and “blue team” simultaneously, it would probably improve things significantly.

Even so, if I were to recommend your product, people would likely say something like this: Nym is operating at a lower level internally, so it’s not trustworthy at all, you just have to look at the reality of the situation.

And you’re still using misleading advertising on your website, while the description is completely vague:

-> The words that say: “Shield your personal data from all surveillance”

- What exactly does that mean? The basics of an ISP? Just to sell subscriptions? Etc.

The day you face reality, Harry, and actually start caring about your company since, according to you, you’re the CEO, you’ll either run it with an iron fist or it’ll go under (it’ll destroy itself); it’s up to you.

I don’t know who runs the company, but one thing is clear: it’s far too suspicious at the very highest levels.

1 Like

I always wonder what the benefit of a project like this is, over just using Tor. It (Tor) is incredibly reliable (for what it is). The problem of node capture is more or less solved by just having more people participate (getting easier as fiber rolls out to more homes).

I am kind-of asking a real question here: why do people keep trying to reinvent Tor with different configurations? Why not just work to improve what’s already there?

For $5/month one might have 2GB/20GB 1 vcpu VPS with unmetered 10G connection, which, with debian and little swap (2GB) can run relay node…

Tor is known not to defend against “global passive adversaries” (such as, IIRC, governments). The Tor Project admit this themselves. However, mixnets such as Nym do aim to.

Also, I have no idea what we’re supposed to do in Tor in case of a directory authority compromise. Am I missing something obvious?

1 Like

I’m going to give you two tips (not recommendations) based on what you haven’t mentioned, but which are still valuable:

1. Tor and Nym are useful for basic tasks, such as:

- Searching for a VPN service and downloading it; the reasons may vary. It’s true that some people prefer a VPN with fast speeds for such purposes, rather than one as slow as a turtle like Tor and Nym. These are basic things like watching movies, etc.

- It’s useful for basic communication via messaging apps like Signal and others; it’s ideal for discussing important matters via text messages. It’s not suitable for emergencies where you need to send large files, research collaborations among investigators, or other such situations. Tor and Nym aren’t suitable for the latter.

- Among other options.

2. You need to know what you’re doing.

- Note that Harry from the Nym company is striving for accuracy, but their website has not yet been updated to truly reflect the product as it is. Despite Tor, they acknowledge certain limitations on what they cannot do, including:

- Tor has actual military support from the United States; it would be contradictory to solve the real problems that exist by going against the NSA, for example. In contrast, Nym goes a little further but is limited and requires a subscription.

- If you need either of these two, you have to choose which one is right for you.

- Nym is based in Europe; however, just because it’s in Europe doesn’t mean there aren’t real problems, such as chat monitoring, for example. You have to keep in mind that online security and personal privacy are becoming increasingly, how should I put it, more restricted and harder to protect against. Tools help to a certain extent, but how long will they continue to help?

--

Think about this: Is Nym worth using? If you’re already familiar with what I’ve shared here on Privacy Guides and understand the facts, then you probably already know the answer, along with the context.

My arguments go beyond the technology, the technology is secondary. In other words, I analyze people’s behavior rather than the technology itself. I also analyze what they don’t say. That’s why I’ve shared these insights with you, so you can make your own decision.