Tor’s Developer Leaves After Lurid Sexual Allegations

Tor is free software that channels internet traffic through a series of relays to anonymize its users. 

The Tor Project confirmed recently that one of its prominent developers, Jacob Appelbaum, stepped down in response to what it called “public allegations of sexual mistreatment.” 

In addition to his security research at the Tor Project, Appelbaum is a journalist who worked on WikiLeaks and the Edward Snowden disclosures. 

The Tor Project, which develops the Tor browser and network, had previously only acknowledged Appelbaum’s departure in a one-sentence statement, but went into further detail about his resignation after rumors of assault emerged online.

Rolling Stone called him the “public face of the Tor Project” in a 2010 profile that detailed his involvement with Tor and WikiLeaks. Before joining Tor, Appelbaum worked on security for Greenpeace and the Rainforest Action Network.

Tor Project executive director Sherri Steele said in a statement that allegations of sexual assault had followed Appelbaum for quite some time. “These types of allegations were not entirely new to everybody at Tor; they were consistent with rumors some of us had been hearing for some time. That said, the most recent allegations are much more serious and concrete than anything we had heard previously.”

Steele added that The Tor Project had heard allegations from several victims about Appelbaum’s behavior towards them. The Tor Project has hired a legal firm to investigate the statements, but Steele said she did not expect that the results of the investigation would be made public.

Steele initially announced Appelbaum’s resignation in a simple statement: “Long time digital advocate, security researcher, and developer Jacob Appelbaum stepped down from his position at The Tor Project on May 25, 2016,” she wrote.

Despite the terse announcement, the backstory of Appelbaum’s resignation quickly emerged online.

Andrea Shepard, a Tor developer, tweeted the decoded version of a message she’d originally posted on May 24, one day before Appelbaum stepped down. “It seems one rapist is one rapist too many,” she wrote. (SHA-256 references the hash used to encode the original message.)

Alison Macrina, the founder of The Library Freedom Project, also referenced the allegations on Twitter, saying she had spoken to several victims. The Library Freedom Project is an organization that educates librarians about privacy and collaborates with the Tor Project to establish Tor exit nodes in libraries. “no more open secrets, no more missing stairs. you’re not alone. you were never alone. and I’m pretty sure things are just getting started,” Macrina tweeted.

Steele said the Tor Project would work to foster a safer environment. “Going forward, we want the Tor community to be a place where all participants can feel safe and supported in their work. We are committed to doing better in the future. To that end, we will be working earnestly going forward to develop policies designed to set up best practices and to strengthen the health of the Tor community.”

TechCrunch: http://tcrn.ch/1S5d0vw

« How To Define Cyberwar
Harvard Business School Wants To Know How To Win At Cybersecurity »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Evok

Evok

EVOK is an IT Service provider specialized in installing, maintaining and supporting IT infrastructures for SMB's in Switzerland.

JPCERT/CC

JPCERT/CC

JPCERT/CC is the first Computer Security Incident Response Team (CSIRT) established in Japan.

Raytheon Technologies

Raytheon Technologies

Raytheon Intelligence & Space delivers solutions that protect every side of cyber for government agencies, businesses and nations.

Future of Cyber Security Europe

Future of Cyber Security Europe

Future of Cyber Security Europe is a European wide event examining the latest cyber security strategies and technologies.

Custodio Technologies

Custodio Technologies

Custodio Technologies was established as a Singaporean R&D Centre of Israel Aerospace Industries (IAI) in order to spearhead R&D activities in the field of cyber early warning.

Data61

Data61

Data61 is Australia’s leading digital research network offering the research capabilities, IP and collaboration programs to unleash the country’s digital & data-driven potential.

G DATA CyberDefense

G DATA CyberDefense

G Data developed the world's first antivirus software. We now ensure the security of small, large and medium-sized companies all over the world.

NJVC

NJVC

NJVC delivers IT automation, optimization and security to empower mission-enabling IT for customers with secure requirements.

Vigilant Technology Solutions

Vigilant Technology Solutions

Vigilant is a global cyber security technology company offering solutions to manage entire IT & cyber security lifecycles.

Cyber Insurance Academy

Cyber Insurance Academy

Cyber Insurance Academy was founded to provide insurance professionals with the knowledge needed to work in cyber-insurance and cyber-related insurance fields.

Lucata

Lucata

Lucata solutions support groundbreaking graph analytics and improved machine learning for organizations in financial services, cybersecurity, healthcare, pharmaceuticals, telecommunications and more.

Zama

Zama

Zama - pioneering homomorphic encryption. We believe people shouldn't care about privacy. Not because it doesn't matter, but because it shouldn't be an issue!

B2Bcert

B2Bcert

B2BCERT one of the top companies offering ISO 9001, ISO 14001, ISO 45001, ISO 22000, ISO 27001, ISO 20000,CE Marking, HACCP, and other globally accepted standards and Management solutions.

Intraframe US

Intraframe US

Intraframe US is a cybersecurity company in Memphis, specializing in Digital Forensics Incident Response and Managed IT services. We provide SMBs with a 24/7 SOC for proactive Cyber Threat Management.

Tuskira

Tuskira

Tuskira is a Preemptive Cyber Defense & Response Platform powered by Agentic AI, designed to go beyond traditional vulnerability management.

QRC Assurance & Solutions

QRC Assurance & Solutions

QRC is a PCI QSA, QPA, ISO accredited, CPA and CERT-IN empanelled organization with vast experience in conducting certification, regulatory audits, pen testing services, training and more.