Multiple Tor Path

Hi, I performed a tor session, specifically I visited an onion search engine (onion v3 domain) in which I searched for the word “hello” and visited a couple of results that came out, I did that with both Tor browser and the system tor service by setting a socks5 proxy with foxiproxy on my default browser. In both sessions I sniffed the traffic with wireshark and in both sessions I noticed the presence and communication with 2 different Entry Guard, the communication did not happen first with one entry and then with the other but at the same time with both entries alternating them in a “pseudo-causal” way (to me, it seems random, but surely there must be a motivation behind it). Why am I communicating with 2 entries?

I don’t think it could be Conflux because I don’t use the second path only when the first one is congested, I don’t also use the same exit in both the paths, but it changes every time. I don’t think it could be the padding system because the second path is used to send real data to and not dummy traffic (from Tor Browser path view I can see both the guards).

There exists a protection system to prevent Session Correlation attack that split the traffic in more than one path in order to prevent that all traffic can be seen from the attack if it takes control of nodes?

1 Like